3 ms·
What got me interested in Rocket was from this talk (a great talk btw): https://youtu.be/lBQHrj6vwAo?feature=shared&t=1934 https://youtu.be/lBQHrj6vwAo?feature=
by ecmascript 3y ago
What got me interested in Rocket was from this talk (a great talk btw):
https://youtu.be/lBQHrj6vwAo?feature=shared&t=1934 https://youtu.be/lBQHrj6vwAo?feature=shared&t=1934 (A Case for Oxidation)
The main selling point for me was that Rocket made security threats (XSS, SQL injection etc) impossible by guarantees which was a bit mind blowing imo. It is a bit like database guarantees which is insanely useful as an application grows. Is this still the case with Rocket and if so, how come it's not all over their web page as the unique selling point? I mean, security is getting more and more important and if we can solve many preventable security threats permanently by a technical choice this seems like the obvious way to go for the future.
I mean, Rust is fast and secure and makes my software "unhackable" for the price of a bit slower development? Seems like an obvious choice then.
When I browse their website, I don't understand if this is still the case and coming from a php/node background this would be the main driver for me since the language performance is very rarely a concern of mine and coding rust is.. slow and requires a lot of learning because of the weird syntax that makes me think about memory when I don't really care.
What I also really, really like about Rust, Go and other similar languages is that the deployment option that becomes available. Just deploy a single binary file. That is super simple and awesome. But the one thing that made me look away from Rust is the foundations weird rules and new draft that you cannot use the word Rust in urls, courses etc and if you like guns?
I don't know how it's been developing so far but the Rust foundation seems to do some crazy stuff that makes it hard to trust.
- estebank 3y ago> I mean, Rust is fast and secure and makes my software "unhackable" for the price of a bit slower development? Seems like an obvious choice then. Something being written in Rust doesn't mean it's unhackable. It lowers the likelihood of memory safety errors to the point of them being negligible, and a lot libraries will have APIs that encourage correct usage by default. But your application can still have a bug, and that big can still be exploitable. For example, if you're making a file transfer application where the sender has control over the path to be written, and you don't make an explicit check for path traversal on the receiver, a malicious sender can overwrite any file the receiver process has write access to in the entire filesystem. Rust didn't protect you there from an exploitable bug. You could make an API where that won't happen unless you opt into arbitrary path traversal, but that is not what most libraries, including std, do. I don't say this to mean "Rust bad", but rather "don't be mislead by imprecise language about what Rust gives you". You can write bugs in any language. The extent of the blast radius is different per language.
- ecmascript 3y agoI know, I think you misread what I meant. I mean that even if it isn't unhackable due to bugs you can do in runtime, that it can guarantee stuff like no SQL Injection and possible no XSS if it compiles is pretty amazing. But maybe that is pretty much the same as other frameworks in other languages provide also but the difference is that it's not guaranteed by the compiler.