4 ms·
Perhaps it’s about responsibility. It’s not the compilers fault if you chose to compile and run malware. But you could blame the compiler if it ran malware duri
by daedalus_f 4y ago
Perhaps it’s about responsibility. It’s not the compilers fault if you chose to compile and run malware. But you could blame the compiler if it ran malware during the compilation process.
- iudqnolq 4y agoAll else equal I'd agree. But I'm perplexed why people spend a lot of effort on what seems to me like a purely philosophical benefit.
- rnk 4y agoIt's just address part of the problem, which of course is why it seems somewhat pointless. I need to: 1. Install packages/deps/libraries etc safely 2. Run code that includes those libraries that limits their capabilities centrally.
- WalterBright 4y ago> It's just address part of the problem, which of course is why it seems somewhat pointless I cut my teeth in the aviation industry, where the idea is to address every part of the problem. No one part will fix everything. Every accident is a combination of multiple failures.
- WalterBright 4y agoIt's not philosophical. All people who write programs that consume untrusted data should be actively trying to prevent compromise by malware.
- iudqnolq 4y agoIn general, I agree. I think developer tools are a special exception because there are so many gaping vulnerabilities inherent to it it's meaningless. I think of that kind of thing as the equivalent of "your laptop won't be vulnerable on odd-numbered days". That'd be a great plan if there was a pathway to going from there to no vulnerability. If that was the low-hanging fruit and you're stopping there it's a complete waste of time.