5 ms·
If Rust is the language that finally overwhelms the resistance to memory safe languages, that's good. I think it's also important not to centre Rust alone. In
by nick_ 1y ago
If Rust is the language that finally overwhelms the resistance to memory safe languages, that's good.
I think it's also important not to centre Rust alone. In the larger picture, Rust has a combo of A) good timing, and B) the best evangelism. It stands on decades of memory safe language & runtime development, as well as the efforts of their many advocates.
- tptacek 1y agoI think it's important to keep the scope of the debate well-defined, because memory-safe languages completely stomped out memory-unsafe languages more than 20 years ago; almost all new code is written in languages that are unshowily memory safe (like Java and Python). We're really talking about resistance to memory safety in the last redoubts of unsafety: browsers and operating systems.
- Ar-Curunir 1y agoand cryptographic code.
- wglb 1y agoMy favorite crypto bug was not a memory safety issue: https://i.blackhat.com/us-18/Wed-August-8/us-18-Valsorda-Squeezing-A-Key-Through-A-Carry-Bit-wp.pdf https://i.blackhat.com/us-18/Wed-August-8/us-18-Valsorda-Squ... Was a fascinating detective story to illustrate it.
- olarm 1y ago> We're really talking about resistance to memory safety in the last redoubts of unsafety: browsers and operating systems. And control systems, c++ (along with PLCs ofcourse) dominates in my experience from developing maritime software and there doesnt appear to be much inclination towards change.
- zahlman 1y agoTo be fair, there's a pretty clear difference between achieving memory safety with a garbage collector and run-time type information, versus achieving it through static analysis.
- fiddlerwoaroof 1y agoStatic analysis is worse and limits the programs you can write in annoying ways?
- zahlman 1y agoI like dynamic typing, but the point wasn't about holy warring. The point is simply that it's different.
- tuveson 1y ago> browsers and operating systems And the VMs for the two languages that you mentioned above (edit: though to be fair to your comment, I suppose those were initially written 20+ years ago).
- chubot 1y agoThere’s also google, yandex, baidu, and bing, which are incredible amounts of c++ code And probably lots of robotics, defense, and other industries Granted, those aren’t consumer problems, but I would push back on the “last redoubts”. We should absolutely move toward memory safe languages, but I also think there are still things to be tried and learned
- npalli 1y ago> We're really talking about resistance to memory safety in the last redoubts of unsafety: browsers and operating systems. .. and other performance critical areas like Financial applications (HFT), High Performance Computing (incl. AI/ML), embedded, IoT, Gaming/Engines, Databases, Compilers etc.. Browsers and OS are highly visible, but there is a gigantic ton of new C++ code written everyday in spite of the availability of memory safe languages.
- tptacek 1y agoPeople keep coming up with all these examples of things still written in C/C++. Sure. So are most AAA games. But so far nothing that's been identified --- maybe excepting databases, but vulnerabilities there are still rare --- that is a meaningful component of insecurity, which is what "memory safety" addresses.
- spacechild1 1y ago> that is a meaningful component of insecurity, which is what "memory safety" addresses. There are plenty of people, though, who argue that everything must be memory safe (and therefore rewritten in Rust :) I personally don't agree with that sentiment and it seems like you don't agree either.
- tptacek 1y agoIt would be better for everyone if everything on a forwardgoing basis was written in a memory-safe language.
- spacechild1 1y agoWhat difference does it make for a video editor or DAW?
- adgjlsfhk1 1y agoiphones have already CVEs from memory safety issued in image formats. is entirely plausible that a similar issue could exist in video or audio codecs
- noelwelsh 1y agoRust also didn't give up, whereas earlier languages like Cyclone did. This is a problem with the different incentives in research; once you've shown it works there is no funding for further development.
- jandrewrogers 1y agoThis statement seems imprecise. We've had memory-safe languages for decades and they are the primary programming languages used today e.g. Java and Python. There is no meaningful resistance to them. If you look at what unsafe languages are used for, it mostly falls into two camps (ignoring embedded). You have legacy code e.g. browsers, UNIX utilities, etc which are too expensive to rewrite except on an opportunistic basis even though they could be in principle. You have new high-performance data infrastructure e.g. database kernels, performance-engineered algorithms, etc where there are still significant performance and architectural advantages to using languages like C++ that are not negotiable, again for economic reasons. Most of the "resistance" is economic reality impinging on wishful thinking. We still don't have a practical off-ramp for a lot of memory-unsafe code. To the extent a lot of evangelism targets these cases it isn't helpful. It is like telling people living in the American suburbs that they should sell their cars and take the bus instead.
- HideousKojima 1y ago[flagged]
- odyssey7 1y agoI don’t buy the economic argument favoring memory-unsafe languages. There are fast memory-safe options. Legacy codebases can eventually become more expensive to maintain than to rewrite. What is the economic cost of an Achilles’ heel when critical systems are destroyed? There are critical systems today that are essentially Prince Rupert’s drops. Mightily impressive, but with catastrophic weaknesses in the details.
- wglb 1y ago> Legacy codebases can eventually become more expensive to maintain than to rewrite I'm wondering what the cost would be of rewriting Chrome, at 20 to 30 million lines of code, in Rust? I suspect that despite the memory unsafety, the cost of maintaining it in its current form is vastly lower than this. Plus, any rewrite will certainly introduce new bugs, some of them temporarily serious. Did you see the post years back about a Rust program that exhibited the Heartbleed bug? These new bugs need to be taken into account when estimating the cost of rewrite.
- jekwoooooe 1y agoGo is fast and memory safe. It has some data race protections built in but doesn’t go as far as rust. This has its benefits like not having to deal with borrow checker insanity (or rust syntax for that matter) Unlike python or java, it’s both compiled and fast
- haimez 1y agoJava is both compiled (first to bytecode, then to machine code by the JIT) and fast (once JIT compiled).
- Raidion 1y agoJava is "fast" but not fast. Most of the time if performance is a true concern, you are not writing code in Java.
- frollogaston 1y agoI have yet to run a Java program that I haven't had to later kill due to RAM exhaustion. I don't know why. Yeah an Integer takes 160 bits and that's without the JVM overhead, but still. Somehow it feels like Java uses even more memory than Python. Logically you'd point the finger at whoever wrote the software rather than the language/runtime itself, but somehow it's always Java. It's like the Prius of languages. Ok, just glanced at my corp workstation and some Java build analysis server is using 25GB RES, 50GB VIRT when I have no builds going. The hell is it doing.
- AlotOfReading 1y agoMore of a historical footnote than a serious example, but you've never had to kill the Java applications running on your SIM card (or eSIM).
- frollogaston 1y agoI don't know about that, my flip phone used to crash quite often. And it displayed a lot of Java logos.