3 ms·
> This is analagous to World War 2 bomber design (bear with me). What follows that sentence has to be a contender to win the prize for the most tortured analog
by codeflo 3y ago
> This is analagous to World War 2 bomber design (bear with me).
What follows that sentence has to be a contender to win the prize for the most tortured analogy in a programming language discussion. You see, safe languages are bad because they slow you down, and if you're slow, the Nazi anti-air guns (that is, security vulnerabilities) can catch you. You need to code faster to dodge those bullets! Write in C to stop the Nazis!
Earlier in the article, there's a lot of hand-waving that there's a lot of secure software out there that's written in unsafe languages, so memory safety isn't needed. No proof of this. If you make a claim like this, at least be specific and enumerate examples of software for which that's the case. Then we can verify this claim against published vulnerability lists from the past few years. Spoiler: every significant C program has had memory vulnerabilities.
But maybe those aren't important compared to other security issues, which is another a common claim and one that's hinted at here? Maybe C allows you to code fast enough to dodge other kinds of Nazi bullets/vulnerabilities, and that's worth it? Well, people do enumerate stuff like that, and despite most programming nowadays happening on the web, a memory safety issue is still at the top of this list, for example: https://cwe.mitre.org/top25/archive/2023/2023_top25_list.html https://cwe.mitre.org/top25/archive/2023/2023_top25_list.htm...
Perhaps those metaphorical airplanes were still to slow, and the programs that were counted in this should actually have been coded in assembly to be even more secure, what do I know.
- justincredible 3y ago[dead]