3 ms·
Maybe it wouldn't matter either way if people stopped putting untrusted executable code into basic build processes. You could get rid of a huge portion of the
by numbsafari 2mo ago
Maybe it wouldn't matter either way if people stopped putting untrusted executable code into basic build processes.
You could get rid of a huge portion of the go standard library and have a massive ecosystem of leftpads, but the fact that `go build` can easily be run in off-line mode and doesn't execute any code other than the go toolchain itself, means you have a fundamentally more trustworthy ecosystem overall.
Rust, on the other hand, might keep you from a subset of buffer overruns, but it will gladly run obfuscated, untrusted code in your name when you wouldn't otherwise expect it to.
As an industry, we need to somehow stop making this mistake.
- kibwen 2mo ago> the fact that `go build` can easily be run in off-line mode and doesn't execute any code other than the go toolchain itself You can trivially run Cargo in offline mode, via the --offline flag. Nothing about this capability, in either Go or Rust, results in a more particularly trustworthy ecosystem.
- uecker 2mo agoI do not think this is a "mistake". This is the result of different priorities. Rust has done nothing to make me safer (although I agree that memory safety is desirable) and the supply chain issues make me less safe. Still parts of the industry want it. If your business is putting locked down app stores and media-consuming devices in everybody pockets, than memory safety is much more important than for the rest of us.