3 ms·
I often wonder why c did not deprecate the bad bits, like the dodgy string functions should at least be behind a switch to enable, like --enable-strcat or somet
by tails4e 4y ago
I often wonder why c did not deprecate the bad bits, like the dodgy string functions should at least be behind a switch to enable, like --enable-strcat or something. Even the printf bug when passing a single argument is easily fixed by requiring two arguments at a minimum, etc. Then leveling up the std library to force the use of bounds checked strings and buffers, again hiding the unsafe ones behind switches or unsafe keywords. This woukd allow backwards compatability, while making newer code safer by default.
- stephc_int13 4y agoThe C language and the C stdlib are not the same things. You can use C without the stdlib. You simply have to build or use a different framework offering similar or better APIs.
- tails4e 4y agoYes, of course. But making the stdlib more sane would dramatically improve things. Deprecating the dangerous methods and requiring unsafe keywords to use them coukd still be done
- pjmlp 4y agoWG14 never cared that much about security, as simple as that.