4 ms·
Promoting Rust might feel good, but it does not have the desired effect. Promoting action that would have the desired effect would tend more to have the desired
by ncmncm 4y ago
Promoting Rust might feel good, but it does not have the desired effect. Promoting action that would have the desired effect would tend more to have the desired effect, even though less personally gratifying. Your choice, but being seen to choose reveals.
- deleted 4y ago[deleted]
- pjmlp 4y agoRust isn't the only game in town moving into safer lands. > Swift adoption continues its exponential climb and surpassed C++ this year. From https://blog.timac.org/2022/1005-state-of-swift-and-swiftui-ios16/ https://blog.timac.org/2022/1005-state-of-swift-and-swiftui-... > I propose that we start requiring an existing Swift compiler to build the Swift compiler. This opens the door to non-optional (mandatory) parts of the compiler to be implemented in Swift. From https://forums.swift.org/t/implementing-parts-of-the-swift-compiler-in-swift/59524 https://forums.swift.org/t/implementing-parts-of-the-swift-c...
- fsflover 4y ago> Rust isn't the only game in town moving into safer lands. No, it's not. Only security through isolation is a viable approach, see https://qubes-os.org https://qubes-os.org.
- pjmlp 4y agoWhile much better, and also a reason why plugins should go back to OS IPC instead of shared libraries when security is a priority, it also isn't bullet proof. How does QubeOS prevent black box attacks? Meaning, finding a sequence of process interactions that eventually lead to data corruption on the process in-memory data structures, which might enabled a specific execution sequence to do B instead of the expected A? Process is still inside its sandbox, no way to own it via an exploit, however that sequence (if achieved) has enabled the attacker to influence its execution behaviour.
- fsflover 4y agoQubes provides security through compartmentalization: https://www.qubes-os.org/faq/#how-does-qubes-os-provide-security https://www.qubes-os.org/faq/#how-does-qubes-os-provide-secu.... It does not care about a single compromised VM. It is designed with the assumption that any VM might be compromised. If you suspect a compromise, you recreate the VM from a trusted template. You also use a disposable VM for untrusted operations and offline VMs for security-critical things. See also: http://www.qubes-os.org/news/2017/04/26/qubes-compromise-recovery/ http://www.qubes-os.org/news/2017/04/26/qubes-compromise-rec....
- pjmlp 4y agoThanks for the overview.
- marcosdumay 4y agoWhat do you mean? Keeping it on the kernel but written in Rust is certainly safer than keeping it on the kernel and written in C. In particular, Rust tends to catch bugs like exactly this one being exploited here (although the kernel developers may decide to turn this check off). But, anyway, up to now there has been no project for rewriting the network stack. So you are arguing against a strawmen, and interestingly, losing.
- tgsovlerkhgsel 4y ago> Promoting Rust might feel good, but it does not have the desired effect. Why not? I don't have a bone in the fight (never written any Rust), but memory safe languages seem like such a no-brainer to me.