5 ms·
I'm the person driving this. NTP is worth moving to a memory safe language but of course it's not the single most critical thing in our entire stack to make me
by jaas 2y ago
I'm the person driving this.
NTP is worth moving to a memory safe language but of course it's not the single most critical thing in our entire stack to make memory safe. I don't think anyone is claiming that. It's simply the first component that got to production status, a good place to start.
NTP is a component worth moving to a memory safe language because it's a widely used critical service on a network boundary. A quick Google for NTP vulnerabilities will show you that there are plenty of memory safety vulnerabilities lurking in C NTP implementations:
https://www.cvedetails.com/vulnerability-list/vendor_id-2153/NTP.html https://www.cvedetails.com/vulnerability-list/vendor_id-2153...
Some of these are severe, some aren't. It's only a matter of time though until another severe one pops up.
I don't think any critical service on a network boundary should be written in C/C++, we know too much at this point to think that's a good idea. It will take a while to change that across the board though.
If I had to pick the most important thing in the context of Let's Encrypt to move to a memory safe language it would be DNS. We have been investing heavily in Hickory DNS but it's not ready for production at Let's Encrypt yet (our usage of DNS is a bit more complex than the average use case).
https://github.com/hickory-dns/hickory-dns https://github.com/hickory-dns/hickory-dns
Work is proceeding at a rapid pace and I expect Hickory DNS to be deployed at Let's Encrypt in 2025.
- landmarker10 2y ago[flagged]
- kaql 2y ago[flagged]
- devwastaken 2y agoIt's not censorship to be downvoted for low quality posts. Please reference "intellectual honesty" and research how to have legitimate conversations. Reddit/Twitter/4chan esque communication is not appropriate for serious spaces.
- lasjhdh 2y ago[flagged]
- dmix 2y ago> Intellectual honesty would be to point out the memory safety issue CVE of Postfix in the past decade. this thread isn't about Postfix, you brought up Postfix as a counterpoint to a wider topic where such a anecdote doesn't hold up nearly as well in a broader scope. Don't purposefully narrow the topic and move goalposts just to win internet fights.
- dequan 2y agoWhat an interesting coincidence that all three of these accounts were created within 15 minutes of each other. I'm sure all "three" users are being "intellectually honest" here.
- stouset 2y agoDownvoting isn’t censorship. It’s disagreement. “What about this one C project that hasn’t been a mess of exploitable vulnerabilities” is thoroughly unconvincing in a world where networked C programs are an unending source of severe vulnerabilities.
- VancouverMan 2y agoWhen even a very small number of downvotes here can result in a comment's text being coloured in a way that makes it harder to read, or even nearly impossible to read in extreme cases, I think it's reasonable to equate downvoting with censorship. Censorship doesn't require content to be completely hidden or blocked; even just partially obscuring the content in some way is still censorship.
- stouset 2y agoI disagree that this is equivalent to censorship, but it sure sounds like a really good incentive to make more convincing comments than “Then how do you explain this single counterexample? Checkmate, Rustaceans.” Plenty of reasonable disagreement happens here without getting downvoted into obscurity. Substantive points are generally upvoted even when they’re controversial opinions. So I don’t feel too upset when borderline-trolling or bad-faith arguments get hidden by consensus. Ironic counterexample: It looks like you may have gotten downvoted despite having a fundamentally reasonable perspective.
- kelnos 2y agoI wouldn't call it "censorship", but sure, let's say it is. There's a reason why "this is the exception that proves the rule" is a common saying. Picking out one exceptional example of something, and using that to argue against a general point, is at best lazy, and at worst actively dishonest. I'm fine with those kinds of comments being "censored". They -- and the comments calling people out for doing this -- are boring and don't further discussion.
- kelnos 2y agoI wouldn't call it "censorship", but sure, let's say it is. There's a reason why "this is the exception that proves the rule" is a common saying. Picking out one exceptional example of something, and using that to argue against a general point, is at best lazy, and at worst actively dishonest. I'm fine with those kinds of comments being "censored". They -- and their replies that call people out for doing this -- are boring and don't further discussion.
- jaas 2y agoPeople bring up postfix all the time in this context because supposedly nobody has ever found a memory safety vulnerability in it. Presumably this is supposed to make the point that it is possible to write complex programs in C safely. The reason people know this about postfix and keep bringing this one specific example up is because it's so unusual! It's an example that almost stands alone, it's extraordinary. I don't think this is making the point about the safety of C that you think it is. There is a mountain of evidence suggesting that C is dangerous, particularly for network services, and one possible example to the contrary doesn't change that.
- landmarker11 2y ago[dead]
- maxbond 2y agoThat's a bummer honestly, I would encourage you not to let Internet flamewars color your decisions about what languages you might learn. The well is seriously poisoned with regards to Rust in this community. That's more of a reflection on HN than the value of Rust as a technology or even the Rust community. Don't learn Rust if you aren't interested, it's not a one true language, but don't cheat yourself on engaging with an interest because HN struggles to discuss it amicably.
- stouset 2y agoHN is capable of discussing it just fine. Low-effort, bad faith posts getting downvoted into oblivion is the system working as intended. GP is obstinately failing to grasp the difference between “can” and “should”. Networked services can be securely written in C. Networked services should not be written in C. There are people who can operate motor vehicles safely at speeds regularly in excess of 100mph. People should not do so on public roads.
- asdask 2y ago[flagged]
- twothreeone 2y agoIt continues to astonish me how little people care (i.e., it triggers the $%&@ out of me). I really appreciate the professionalism and cool rationale when faced with absolute ignorance of how shaky a foundation our "modern" software stack is built upon. This is a huge service to the community, kudos to you and many others slowly grinding out progress!
- vmfunction 2y agoLol, shaky indeed. A business person once said, "can you imagine if machine engineer (like auto makers) behave like software engineering?". Seems no digital system is truly secure. Moving foundational code to memory safe seems like a good first step.
- twothreeone 2y agoThat's because there is no such thing as "truly secure", there can only be "secure under an assumed threat model, where the attacker has these specific capabilities: ...". I agree that software engineering is getting away with chaos and insanity compared to civil or other engineering practices, which have to obey the laws of physics.
- nick238 2y agoRemind me of the One World Trade Center rebuild, and "if you want a 747-proof building, you're building a bunker". Translate the internet to the real world, and basically every building (IP address) is getting shot at, hit by planes, nuked, bioweapons are stuffed into the mail slot, and lock-picked all day, every day.
- dheera 2y agoWhy are C and C++ all of a sudden unsafe? Did I miss something? What is safe now? JavaScript? PyTorch?
- dequan 2y agoAll of a sudden? They've been unsafe for decades, it's just that you had less of a choice then.
- ghshephard 2y agoOne of the major drivers (if not the driver) for the creation of Rust the fact that C is not a memory-safe language. This has been known for decades, but it wasn't until 2010 that a serious attempt at writing a new system-language that was memory safe was attempted and got traction - Rust. https://kruschecompany.com/rust-language-concise-overview/#:~:text=Rust%20was%20released%20in%202010,did%20and%20Rust%20was%20born https://kruschecompany.com/rust-language-concise-overview/#:....
- dheera 2y agoHow is C not memory safe? If I access memory I didn't allocate the OS shuts the program down. Is that not memory safety? (Unless you're running it on bare metal ...)
- rictic 2y agoMemory errors can be exploited by a clever adversary to control your process in a variety of unpleasant ways, see: https://en.wikipedia.org/wiki/Memory_safety#Types_of_memory_errors https://en.wikipedia.org/wiki/Memory_safety#Types_of_memory_...
- deleted 2y ago[deleted]
- hot_gril 2y agoThat's not what memory safety refers to.
- 2y ago