4 ms·
> Carcinize existing C and C++ X.509 users. This could be game-changing for a lot of open source software. I spent years avoiding X.509 (and ASN.1, for that m
by tob_scott_a 3y ago
> Carcinize existing C and C++ X.509 users.
This could be game-changing for a lot of open source software.
I spent years avoiding X.509 (and ASN.1, for that matter) in my designs because every time someone I trust poked it, a remotely exploitable bug fell out. Most often, it was a Denial of Service issue rather than Remote Code Execution. Moving to Rust would demonstrably improve the security of the entire Internet.
You might be tempted to ask, "What about BouncyCastle?" (or similar queries).
Sure, you're not overwriting the EIP in most Java X.509 bugs, but check the release notes for X.509 and ASN.1 mentions: https://www.bouncycastle.org/releasenotes.html https://www.bouncycastle.org/releasenotes.html
When I worked for Amazon, we disclosed a few X.509-related vulnerabilities to projects that we almost found by accident.
- otabdeveloper4 3y ago> Moving to Rust would ... ... do absolutely nothing to fix denial of service attacks.
- tob_scott_a 3y agoBy itself? No. The other details covered in the blog post, however, would absolutely do something to fix denial of service attacks. To wit: x509-limbo
- woodruffw 3y agoI don't think this is true. Rust cannot prevent all possible forms of denial of service, but there are plenty of underlying DoS causes that Rust either outright eliminates (such as memory corruption without further control) or mitigates through stronger types. A recent example of this is CVE-2024-0567 in GnuTLS: an invariant that otherwise would likely have been noticed at the type level is instead checked with an assert, leading to a remotely trigger-able DoS.
- saurik 3y agoNor the other myriad of logic and parsing bugs that led to incorrect behavior (more than just denial of service) in the Java library that was somehow not as good as Rust :/.
- bagels 3y agoExploiting a memory safety crash, leading to a downed service, is the first class of DOS that Rust can help with.
- blibble 3y agohow would rust fix most of those issues? they're logic bugs
- tob_scott_a 3y agowoodruffw already wrote an excellent comment for this question: https://news.ycombinator.com/item?id=39131723 https://news.ycombinator.com/item?id=39131723 Rust isn't just memory-safety. The type system also coaxes developers towards eliminating some types of logic bugs. Not all, granted, but it does move the needle.
- blibble 3y agoI think that attitude vastly underestimates the complexity of a typical TLS implementation (and I say this as someone who grew up on SML)
- woodruffw 3y agoThis reasoning doesn't make sense. If TLS is astonishingly complex, which it is, then we absolutely want the strongest type system that can simultaneously represent its complexity and afford developer ergonomics. TLS's complexity is a good reason for types that reflect invariants, not a good reason to give up.
- blibble 3y agoThis reasoning doesn't make sense. I didn't say it didn't help at all, I said I wouldn't expect it to make a significant improvement over Java (and it's hardly the strongest type system with "developer ergonomics")
- k8svet 3y agoI'm not even that good at writing Rust and even I recognize that countless libs I'm using are written in a way, with Rust types, that prevent serious mis-use. In ways that would be infeasible and unergonomic in other languages, or require internal library invariant assertions that are prone to bugs. Sometimes the errors wind up being nasty, but I've also gotten better at trusting that the compiler is giving me helpful info, even if it's a huge message. And usually those errors indicate some library invariant that I've missed that the type system is enforcing.