5 ms·
> Every single day there’s a zero day practically released Yeah, people need to stop using memory unsafe languages. They choose not to. > A single slip up wil
by staticassertion 5y ago
> Every single day there’s a zero day practically released
Yeah, people need to stop using memory unsafe languages. They choose not to.
> A single slip up will lead to you being compromised.
Not if you add multiple layers of security. Like sandboxing. Or mTLS. It's not hard to do that.
edit: Let me clarify. Security isn't hard generally, but it's hard individually, because you're drowning under everyone else making it artificially 10000x harder.
- lanstin 5y agoLog4j was memory safe. Tho I agree on mTLS and even would like most valuable networks to be connected only via an allow list of safe-ish destinations. It would make things a lot harder, and the logs of denied hosts would also be a nice warning.
- staticassertion 5y agoYep, after memory safety there's still work to be done. But it'll be a lot less work.
- Closi 5y agoConverting the entire stack to memory-safe languages to save work is definitely in the “easier said than done” bracket.
- int0x2e 5y agoActually, the fact that memory safety bugs are more difficult to exploit seems to have increased the rate of vulnerabilities discovered and exploited, and the fact that these are now often higher-level bugs (think insecure feature design bugs rather than low level implementation bugs) - means that once something is discovered, it can often be exploited in a way that is either much more pervasive or far harder to detect. So no - safer languages won't stop security from being an issue. Secure design, implementation, configuration, and frequent red-teaming exercises are the only way to reduce your risk, and even then - expect to reduce the rate by some %, but never reach zero.
- hnthrowaway0315 5y agoJust curious, what about the exploits targeting say Java VM?
- rank0 5y ago> Yeah, people need to stop using memory unsafe languages. They choose not to. Golang and Rust are not magic bullets that makes systems automatically secure. Flaws in application logic have little to do with language choice. Also consider the effort and money it takes to rewrite a multi million LOC system with several dependent apps. The new trendy languages introduce breaking changes, switch paradigms, and have less mature ecosystems.