18 ms·
"No way to prevent this" say users of only language where this regularly happens
- consp 2y agoOh no ... a bug in a C program. This easy bashing on existing C programs is getting boring and annoying. Write a new userspace program? Use anything else, all language shave flaws so pick one which supports the features you need. Want to quickly write something because you are not allowed to rewrite the entire ecosystem you need into a new language since the project will go massively over budged: Use what you can and what's available and accept the risks, which is the 99th percentile of software.
- Simon_O_Rourke 2y agoPrince Marcel O'Keefe must be C royalty!
- nubinetwork 2y ago> a vulnerability in HTTP parsing code that allows for heap corruption and arbitrary code execution by making a HTTP GET request with a megabyte of the letter 'A' in its body You mean a buffer overflow? Why write so technical then dumb down something that's pretty obvious.
- SSLy 2y agobuffers are stored on heap.
- akoboldfrying 2y agoSome of the HN discussion about whether "new projects in C should be allowed" is moot: Fluent Bit was imported into git in 2015 [0] (a few months before Rust's first public release), and may be considerably older than that for all I know. I suppose incidents like this actually do give a reason to "rewrite it in Rust", when "it" is "widely deployed infrastructure written in C". OTOH, I'm sure there were plenty of non-memory-safety bugs introduced and later fixed over the years, and rewriting in Rust will recapitulate that subset of bugs. [0] https://github.com/fluent/fluent-bit/commit/49269c5ec3c74411943e362cfef85052665ae97f https://github.com/fluent/fluent-bit/commit/49269c5ec3c74411...
- nullc 2y agoPeople slipping backdoors into stuff are no doubt super enthusiastic about Rust both for the opportunity for new anonymous nobodies to rewrite long stable and proven tools as well as the dependency ecosystem that tends to blindly pull in multiple different entire HTTPS/TLS stacks into anything but the most trivial software.
- tialaramex 2y agoI don't buy it. Rust has a really good track record on attracting more people to read and modify the code, which isn't what you want if you're hiding backdoors in the code. In decades of writing C (sometimes as a hobby, often for a lot of money) I'd guess I thought "These errors when I wrote bugs in my program are crap, somebody should fix it" maybe once per month on average. But a C compiler is very intimidating code, subtle and hard to even build from scratch let alone contribute to, so I never attempted to make such changes. In only a few years of writing Rust (none of that paid) exactly twice I've thought "Man this compiler error diagnostic isn't very good, somebody should fix it". The first time I asked on Reddit, and I was informed that I wasn't the first to notice, the fixed diagnostic was in nightly Rust already. The second time I found the diagnostic and I just fixed it, compiled first time, wrote a new unit test, checked that passed, wrote a pull request. Landed it. Then I wrote a HN comment, a reader found a bug in my diagnostic, so I fixed the original code, and wrote a new PR which also landed. If Rust has told you that instead of 'X' when you needed a byte, you should write b'X' because just 'X' is a char not a byte - that's me, that's my small fix. [Before the fix 'X' wasn't legal here, of course, but the diagnostic wouldn't suggest what to write instead]
- nullc 2y agoI'm not sure how modifying the compiler is relevant to the point. I think it's the general trend that early in languages lives its much easier to contribute to the tools, after decades of amassing improvements (such as yours!) they tend to become less accessible. But regardless, the "rewrite in rust" advocacy has created a significant opportunity for projects created by single people, without outside review and often without significant domain expertise (at least where they are slavish re-implementations of existing code), to be proposed as replacements for longstanding stable tools. Whatever the merits of that chance it's also dream for someone looking to introduce new vulnerabilities. Even where the replacement itself is reviewed it will usually come with a massively expanded dependency footprint which isn't.
- subjectsigma 2y agoI bet this person felt really smart posting about this problem that surely nobody has ever thought of before
- web007 2y agoA) "surely nobody has ever thought of [this] before]" says person who hasn't read https://xeiaso.net/shitposts/no-way-to-prevent-this/ https://xeiaso.net/shitposts/no-way-to-prevent-this/ B) It's a spin on The Onion headline about school shootings.
- subjectsigma 2y agoA) I know, it still sounds smug and condescending B) I know, it still sounds smug and condescending
- Hock88sdx 2y ago[dead]
- mikewarot 2y agoFree Pascal and Lazarus which is a GUI built on it support strings that don't require manual allocation and are counted and reference counted. A huge amount of grief would go away if that library could be supported in the Linux kernel somehow, and all of the string parameters in system calls ported.
- 1vuio0pswjnm7 2y agoTerrible analogy. School shootings are not the result of mistakes. They are intentional acts.
- mjevans 2y agoThe headline is misleadingly focusing on a soundbite out of the full quote. "It's a shame, but what can we do? There really isn't anything we can do to prevent memory safety vulnerabilities from happening if the programmer doesn't want to write their code in a robust manner." -- Some (uncredited?) C programmer. Does C have more footguns as a low level language? Of course. That's part of the freedom of bringing only the baggage a project needs. Sadly, like many dangerous or sharp tools, incorrect use will lead to harms. If someone has a choice, a safer more modern language can accommodate less skilled practitioners.
- ChrisMarshallNY 2y ago> a safer more modern language can accommodate less skilled practitioners. That’s really what it’s all about. SV is absolutely obsessed with hiring bad programmers, treating them like crap, so they don’t stick around, and somehow, magically, forcing them to write good code. We have this belief that if we just use the “right” tool (in this case, a particular programming language), all of our products will be good. Couple that, with the belief that we should be able to build our stuff on someone else’s code, for free, and you have a recipe for disaster. People like Linus Torvalds are living proof that it is quite possible to write amazing stuff, in old languages (he is a C guy), but people like that, are rare as hen’s teeth, and may be difficult for today’s tech managers to handle. There really is no substitute for running a good shop, hiring good people, training them well, treating them well, paying them well, and keeping them around for significant lengths of time. Also, we need to be able to hold ourselves accountable for the Quality of our own work -regardless of the tools we use. Torvalds is notorious for being a tough taskmaster, because he’s serious about the Quality of his work, and casts that onto others. “Treating people well” does not mean using kid gloves. It can mean expecting people to act like grown-ups, produce grown-up work, and not accepting less. I worked in an environment like that for decades. It was often quite stressful, but was also personally rewarding. It isn’t the tools that are broken; it’s the management culture, and no one wants to fix that.
- voidUpdate 2y agohttps://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_Says_Only_Nation_Where_This_Regularly_Happens https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_...
- fnordian_slip 2y agoJust in case someone needs the reference, the onion uses '"no way to prevent this" says only nation where this regularly happens' as a reoccurring article at every major school shooting[0], to highlight the frequency of such events and the fact that nothing has really changed since the last one. [0] https://www.theonion.com/no-way-to-prevent-this-says-only-nation-where-this-r-1848971668 https://www.theonion.com/no-way-to-prevent-this-says-only-na...
- Supermancho 2y agoThe oversimplification is part of the joke.
- nailer 2y ago[flagged]
- predang 2y ago[flagged]
- ThunderSizzle 2y agoWell, I'm glad that you volunteered to go live in Soviet Russia or Fascist Germany, or a disarmed Native American tribe. Disarming population leads to tyranny without consequences.
- tecleandor 2y agoOr most of the EU countries as of today? ¯\_(ツ)_/¯
- ghnws 2y agoTIL almost every european country is in a state of tyrnanny. Also Yemen which is one of the only countries with somewhat similar gun ownership compared to usa (bit less than half as many guns per capita) must be the epitome of freedom and safety.
- KaiserPro 2y agoNeeds more furries.
- blueflow 2y agoYeah, was about to note that the link is unexpectedly SFW.
- darkwater 2y agoWhy? Furries are NSFW because they look cartoonish and "unprofessional"? I don't like them but what a boring workplace would that be.
- xena 2y agoThey're being satirical. People usually berate my posts because I have cartoon characters for Socratic exchanges to teach people things like Kubernetes, claiming that is "unprofessional" or something. These people are sarcastically berating my post for NOT using that Socratic system.
- darkwater 2y agoIMO GGP wasn't being sarcastic, but GP maybe was. Anyway I keep my thought: if a workplace, especially if in Tech or Tech-adjacent, sees furries as NSFW, it's a very boring workplace and I would run away from it at the first possibility.
- blueflow 2y agoNo I'm not. I expected that there is some furry or anime girl visible when i click on that link. This is the stuff i do not want to have on my screen when there are coworkers nearby.
- xena 2y agoHave this: https://xeiaso.net/notes/2024/ai-hype/ https://xeiaso.net/notes/2024/ai-hype/
- cookiengineer 2y agoAlternative headline should be "But I have been taught that using C++ makes me the better programmer" because the stereotypes of echo chambers on the internet raised a lot of unreflected programmers to be this way. There is a place for C, where there's no alternative. But that place is where 99% of programmers never work, because they are not doing kernel nor firmware development (which, in the meantime, also has a lot of support by and for memory safe VMs and languages). The issue I have with this narcisstic fatigue (similar to the author's point I assume) is that there is no reflection when they fuck up a codebase. The best code is the code that is safe and easy to read, and doesn't need to use "clever tricks" that beginners cannot understand. If you are using some tricks for type casting to implement your ideas into code, you probably should not write code. Code should be dumb and easily maintainable. If it is not, you made the wrong choice for the programming language.
- pjmlp 2y agoKernels have been developed in safer languages already before C became widespread outside Bell Labs, it is a myth that C is even required for that, other than historical baggage.
- p_l 2y agoEspecially when one adds how many "low level programming" idioms for C are, as far as I understand, undefined behaviour in C. Like assigning an address to then use as pointer to physical memory... Which is extra visible when one looks at original UNIX sources and its many short assembly bits in separate files to handle bits of direct hw manipulation.
- lpribis 2y ago> Like assigning an address to then use as pointer to physical memory... What do you mean by this? Like writing to a specific integer address? *((volatile unsigned *)(0x20001000)) = 0x12345678; That's not UB and is also the only way to write to memmapped registers.
- davedx 2y agoThoughts and prayers
- isoprophlex 2y agoMaybe C programmers need some more thoughts and prayers at deployment time?
- bigiain 2y agoBut the 2nd amendment guarantees their right to insecure code!
- Beretta_Vexee 2y agoNo, the only way to stop a bad dev with a strcpy() is a good dev with a strcpy().
- snovv_crash 2y agoBasically fuzzing then?
- isoprophlex 2y agoC doesn't overflow and spill your memory contents, your RAM modules do!
- devjab 2y agoYou obviously need to perform the correct rites and pay your homage to the blessed machine spirit or the Omnissiah will not permit your code to compile.
- ramon156 2y agoWe can learn a lot from terry davis
- nomilk 2y agoMore broadly: > "No way to prevent $THIS" say users of only language where $THIS regularly happens A weird psychological quirk I've noticed (of myself, and others) is we'll often exhibit a sort of 'programming language xenophobia', where we apathetically accept (or don't even notice) unpleasantries of our language of choice, yet be quite averse to the unpleasantries of other languages. Maybe it's due to sunk cost; time/effort has already been spent finding work arounds for or adapting to the warts of our native tongue, whereas doing so for unfamiliar languages would require additional effort.
- BoxOfRain 2y agoThis is definitely a thing I recognise in myself, a year and a half of writing Scala daily has made me much more prejudiced against Java than I was before.
- bsza 2y agoI would rather have unpleasantries that make the language safer vs unpleasantries that make it more vulnerable. Especially when the unpleasantries in question don’t even make the language easier to use.
- quectophoton 2y agoC standard: "Undefined behavior means such a situation can't happen." Me: "If it can't happen then it would be fine to just crash on those situations, right? Because such a crash would never be reached. Can we get that?" C compilers: "No. Would you want to crash on signed integer overflow, for example?" Me: "Yes? Would be safer than the current situation at least." C compilers: "What, no, that would make your programs imperceptibly slower. Would you even like that?" Me: "Yes, I'll be able to live with that." C compilers: "Well, the answer is still no."
- nullc 2y agoIt would have taken you less time to look up -fwrapv / -ftrapv / -fsanitize=signed-integer-overflow + -fsanitize-undefined-trap-on-error than write out that misleading dialog. :)
- diego_sandoval 2y agoI thought it was going to be about JS and npm, given some of their fiascos [1][2][3] [1] https://qz.com/646467/how-one-programmer-broke-the-internet-by-deleting-a-tiny-piece-of-code https://qz.com/646467/how-one-programmer-broke-the-internet-... [2] https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/ https://www.bleepingcomputer.com/news/security/dev-corrupts-... [3] https://www.sonatype.com/blog/everything-matters-why-the-npm-package-sparked-controversy https://www.sonatype.com/blog/everything-matters-why-the-npm...
- draw_down 2y ago[dead]
- minikomi 2y ago`this` was mostly prevented in JS with the introduction of arrow function expressions
- alternatex 2y agoI had someone on Reddit r/webdev try to convince me that 'this' was not a mistake but a powerful language feature. A small glimpse into the mind of JS fans.
- orf 2y agoIt kinda is a powerful language feature But with great power comes great responsibility, and that doesn’t mean it was a good idea in hindsight.
- _old_dude_ 2y agoYes, it's functions vs methods. You can make this explicit like in Python, you can make it implicit but have two kinds of methods, instance methods and static methods like in C++/C#/Java. And you have JavaScript were all functions have an implicit this ...
- 2y ago
- pdimitar 2y agoI've been doing programming for ~31 years in total and ~22 years professionally and at this point I have lost all hope that programmers at large will ever gain these mythic qualities called "self-reflection" and "introspection". Truth is, these people are simply afraid for their cozy jobs, that's all there is to it. Derivative states of mind like Stockholm Syndrome and Sunk Cost Fallacy are quite normal to appear in these conditions. On OP: I could not agree more. People always downplay their fuck-ups, that's sadly part of being a Homo Sapiens, but the lack of awareness is still both despairing and hilarious to watch. And finally, C/C++'s niches have decreased but these people will not adapt, of course. Almost anything I've done with those languages 15-20 years can today be done with Rust. Or if you are on a tight time budget -- Golang, and you still won't lose too much speed. But sure, "nothing can be done, these things sometimes happen". Sigh.
- Xeamek 2y agoEh, Rust would be fine if not for the fact that it's too opinionated. Unfortunately you can't just have Rust's safety checks, without opting into restrictions that Rust designers force onto You that aren't inherent to safety checks, but more because 'that's a better practice (according to us)'. And also, easy and fast iteration just isn't there, both because of borrow checker restrictions and compile times
- eterevsky 2y agoUnfortunately you have to pick 2 out of: - Lack of restrictions - Safety - Performance If you choose safety and no restriction, you pay the price in performance (for GC etc.)
- Xeamek 2y agoAgain, restrictions that are forced you for a price of safety are one thing. But what I'm complaining about are restrictions that don't have to be there to get borrowchecker working, but rather are there because designers arbitrary decided "it's better this way".