5 ms·
“BCHS is a stable, developer-oriented platform. Get used to minimalism and security” With all the memory-safety issues you can introduce by improperly using C,
by pgraf 3y ago
“BCHS is a stable, developer-oriented platform.
Get used to minimalism and security”
With all the memory-safety issues you can introduce by improperly using C, is this page meant to be taken sarcastically or are they really serious about this claim?
- chrsw 3y agoThey're serious. C doesn't have to be insecure.
- wyldfire 3y agoIt's just extraordinarily difficult to make it so, and to convince yourself that you've made it so.
- loeg 3y agoOften easier to convince yourself you've made it secure than to actually do so. Which is part of the problem.
- Mikhail_Edoshin 3y agoIf Python is considered secure yet CPython is written in C, then, perhaps, it is not that difficult?
- rychco 3y agoWhy wouldn’t it be serious? C has been used to write safe, stable, & portable software for decades. Compiler warnings & static analysis tools have come a long way to preventing the vast majority of safety issues in (new) C projects.
- rollcat 3y agoKristaps is an OpenBSD developer. These guys are notorious for having five heads each - two remote holes in 30 years, OpenSSH, PF, etc. That said, the actual secret is to write simpler code. (And maybe use pledge+unveil, if your OS has it.)
- formerly_proven 3y agoZero network services with open ports by default (not even sshd) also helps for that number.
- rollcat 3y agoYes, "simpler" often means "don't do things you don't have to". A laptop doesn't really need sshd, and OpenBSD makes for an OK laptop OS.
- throwawaaarrgh 3y ago[flagged]
- nequo 3y agoA response with substance would be something we could learn from but a meme isn’t.
- User23 3y agoYou might want to take a few dozen hours to dig through John Regehr’s work to understand the current state of the art of C programming.
- nequo 3y agoIs there a particular entry point into his work that you would recommend?
- acuozzo 3y agoAny of his articles covering undefined behavior.
- User23 3y agoHis work on fuzzing and test case reduction is really interesting too.
- User23 3y agoThis[1] is one possible start. Bear in mind though his approach is academic so don’t expect a tidy list of what the working C programmer needs to know. [1] https://blog.regehr.org/archives/1520 https://blog.regehr.org/archives/1520
- WhereIsTheTruth 3y agoThe illusion of security start by believing your software is "safe" because written in a new "safe" language https://nvd.nist.gov/vuln/detail/CVE-2023-22466 https://nvd.nist.gov/vuln/detail/CVE-2023-22466
- tialaramex 3y agoI don't really see a connection here. Rust doesn't magically solve all problems, it just makes lot of them less likely, which means we can successfully build larger systems.
- bsdpufferfish 3y agoIf that’s the case then @safety” isn’t binary it’s a gradient and debating C++ vs Rust is a matter of degree instead of a moral imperative.
- WhereIsTheTruth 3y agoYou don't because you are not competent enough, nothing wrong with that C has the same tools, they however do not run with the compiler, but accomplish the same goal Both, are still not immune to incompetence, the user is often the issue, hence the link