3 ms·
Constructing bug-free code is infeasible. Even the most skilled programmers write code with bugs in, and most programmers, including many who work on browsers c
by retroshit 4y ago
Constructing bug-free code is infeasible. Even the most skilled programmers write code with bugs in, and most programmers, including many who work on browsers components, are only moderately skilled, often writing buggy code.
Perhaps the longer-term solution is to use languages that are memory safe by design, such as Rust, to avoid that class of bugs. But there will still be a huge deal of legacy C++ code to contend with in the meantime, so we do still need exploit mitigations.
- fefe23 4y agoI wrote construct instead of write for a reason. Clearly you can't expect programmers to just write secure code. If that worked, we would have seen evidence for it working by now. By construct I mean: follow a clear method or path, that is a) feasible to follow and b) will lead to bug-free code. Maybe not bug free in all respects but I posit it should be possible to construct code without memory safety issues (just look at Perl or Rust). My point is: It should not be up to the programmer to "simply not make mistakes". The method should be clear and have little ambiguity, and it should be obvious to see if code actually follows it or not. I can't be more concrete or specific than that because I think we still need to find that method. We should be working on it, though.