4 ms·
woodruffw already wrote an excellent comment for this question: https://news.ycombinator.com/item?id=39131723 https://news.ycombinator.com/item?id=39131723 Rus
by tob_scott_a 3y ago
woodruffw already wrote an excellent comment for this question: https://news.ycombinator.com/item?id=39131723 https://news.ycombinator.com/item?id=39131723
Rust isn't just memory-safety. The type system also coaxes developers towards eliminating some types of logic bugs.
Not all, granted, but it does move the needle.
- blibble 3y agoI think that attitude vastly underestimates the complexity of a typical TLS implementation (and I say this as someone who grew up on SML)
- woodruffw 3y agoThis reasoning doesn't make sense. If TLS is astonishingly complex, which it is, then we absolutely want the strongest type system that can simultaneously represent its complexity and afford developer ergonomics. TLS's complexity is a good reason for types that reflect invariants, not a good reason to give up.
- blibble 3y agoThis reasoning doesn't make sense. I didn't say it didn't help at all, I said I wouldn't expect it to make a significant improvement over Java (and it's hardly the strongest type system with "developer ergonomics")
- k8svet 3y agoI'm not even that good at writing Rust and even I recognize that countless libs I'm using are written in a way, with Rust types, that prevent serious mis-use. In ways that would be infeasible and unergonomic in other languages, or require internal library invariant assertions that are prone to bugs. Sometimes the errors wind up being nasty, but I've also gotten better at trusting that the compiler is giving me helpful info, even if it's a huge message. And usually those errors indicate some library invariant that I've missed that the type system is enforcing.
- blibble 3y agoyes, hence my comment on SML while it's nice that the rest of the world is slowly waking up to type systems functional programmers have been bleating on about for the past four decades ... having read through the first couple of pages of bc vulns: even a much stronger type system than rust provides wouldn't appear to help very much in this specific example however if someone wants to rewrite OpenSSL in Rust that would be a massive massive improvement
- tob_scott_a 3y ago> I think that attitude vastly underestimates the complexity of a typical TLS implementation If you ever get the impression that I'm underestimating the complexity of a typical TLS implementation, I promise you that I'm not. I speak to improvements, not panaceas. Until the end of last year, I was one of the security engineers that the s2n team at AWS consulted on potential security issues. You will never hear me say anything will magically fix all our problems. Especially with TLS. However, Rust does bring a lot to the table, so I feel I'm allowed to be excited about not reviewing another X.509 library written in C.