9 ms·
C: A Technological Landmine
- dryicerx 17y agoC is used for low level libraries for it's lean and mean performance. It sacrifices checks and safety features for this, and allows the programmer full control. Do you see professional race cars with ABS and Automatic Stabilization? No, you give the Driver FULL and TOTAL control, same with C and other low level languages. C has only a few data types that are as basic as you can get, I mean what do you expect use something like STL strings? If you start having type checking and various other easy-to-code and child-safety features, you are bloating and giving up performance in the low level libraries, if this happens imagine what the performance on the higher up application level would be.
- praptak 17y ago"For example, professional cooks don't use consumer grade safe knifes, they use hardcore deadly knives for their performance." They also wear cut-resistant gloves.
- dryicerx 17y agoheh, just did a ninja edit and replaced with the race car analogy after realizing that. HN comments need to be ACID
- berglundma 17y agoI think the cooking analogy holds. Sure, those people DO use knife-proof gloves and for good reason. They need to be able to cut through things of the same basic structure as human meat! So it goes with code: if you are working on a low level libs and languages you should be protecting yourself with well thought out data and exception handling. If you don't, you might just cut your hand, I mean, data off!
- nkurz 17y agoI suppose that butchers might use cut-resistant gloves, but in the professional kitchens I've shared I've never seen them worn by a chef.
- deleted 17y ago[deleted]
- krschultz 17y agoI'd prefer my libraries be rock solid secure even if I lose some (or even a lot of) performance for it. Hardware is always getting cheaper. Losing data integrity and the trust/confidence of your users is extremely expensive, and can be fatal for a startup. Performance is not the most important metric for a lot of applications. I'd prefer the safe but slow 5 star crash test rated sedan with a good alarm over the race car that is going to blow up after a few races, in library terms.
- pyre 17y ago> Hardware is always getting cheaper. This is a poor justification. A few years ago a house was a good investment because 'housing prices will always be going up.'
- bmj 17y agoThat, and not every program runs on ever-faster hardware.
- evgen 17y agoPlease provide even a single deluded fantasy in which the price/performance ratio for a particular piece of hardware or component in the hardware stack will not continue to trend in the direction of more bang for the buck.
- tow21 17y agoI don't know if this counts as "deluded", but how about: resource exhaustion of raw materials required in hardware manufacture. See, for example: http://blogs.wsj.com/informedreader/2007/05/25/a-metal-scare-to-rival-the-oil-scare/ http://blogs.wsj.com/informedreader/2007/05/25/a-metal-scare... which talks primarily about LCD displays (we're fast running out of Gallium/Hafnium/Indium), but points out that copper is likely to get significantly more expensive throughout this century. That's going to increase the price/performance ratio of practically everything.
- 17y ago
- tumult 17y agoprofessional race cars absolutely have ABS. in fact ABS systems are so effective that their use has been restricted in the likes of formula 1 etc.
- jrockway 17y agoActually, c-strings are a speed-for-memory trade-off. At the expense of saving a few bytes of memory per string, most operations are O(n) time (strlen, for example). If c-strings were in the form of <length><data> instead of <data><\0>, this bug would be avoided. This is not a performance issue, only bad design and convention. (The other problem was using memcpy and strcmp on the same data. You can't treat blocks of memory as strings; a type system would eliminiate this confusion at no runtime cost.)
- plinkplonk 17y agoUgh, this is close to being a troll post. Yes C has its weaknesses and domains appropriate to it's use. But sentences like "Lacking a strong and expressive type system, C not only permits but encourages its programmers to sacrifice correctness, safety, robustness, testability, and maintainability in favor of some highly underdeveloped and ill-measured ideas about “performance”. Much of the infrastructure of the Internet is built out of this garbage." and especially words like "garbage" only exposes the author as someone who doesn't know what he is writing about. (ok i could have used the shorter word "fool" here, but ..). The "infrastructure of the internet" (including the underlying operating systems) is one of the domains in which C shines. There is good reason that even today, large chunks of "infrastructure" code is written in C/C++. "anybody who considers C for high-level application development at this point in history, is in a grievous state of sin" With "high level" being conveniently undefined and without any examples, that statement means next to nothing. What a terrible, ill thought out article.
- jacquesm 17y agoC is advanced assembler. It is an absolutely great language for system level stuff, especially because everything is explicit, no relying on side effects or stuff hidden from view. The thread of execution is extremely easy to follow. The only thing I would change if we could revisit the past is that I would add a string primitive to the language with a half decent set of string operators. That would have made my life a lot easier at some point in the past. The funny thing is that most languages that people use that criticize 'C' are usually at the core levels written in C. There is probably a good case to be made for the claim that Unix would not exist if it weren't for the C language.
- evgen 17y ago> The funny thing is that most languages that people use that criticize 'C' are usually at the core levels written in C. The difference is that the people using these higher level languages only depend on a single set of maintainers who need to get the primitives right once instead of every random coder needing to manage buffers, garbage collecting unused memory, threading, and a host of other landmines on each and every project.
- sophacles 17y agoOne thing this guy doesn't mention, that I would think relevant to the discussion: Every language currently used by more than 4 people has a notion of FFI via C. This is nice as it allows for the old "profile it and write the slow bits in C" type programming. I particularly like that style of programming, because in the end, you only need to do C style intensity for a small bit of code. Over time, the number of these small, but useful bits accumulates, and the result is a decent, bottom up style library, without the pain of having started in C. (It also helps avoid the cruft...).
- psyklic 17y agoIronically, the article referenced by the author does not blame the C language for this problem. Instead, it blames the CA for issuing the certificates in the first place: "Marlinspike said since there is no legitimate reason for a null character to be in a domain name, it’s a mystery why Certificate Authorities accept them in a name."
- olefoo 17y agoYes, and there's no reason for browsers to accept more than one domain name in a CN field. However a quick look through rfc3280 and an ASN.1 reference make me think it is a less than trivial task to figure out what would and would not be a legal termination for a string encoded in the Subject field of a certificate. But it is perfectly reasonable to expect the CA to check for that.
- TallGuyShort 17y agoThe reason I like C is that every action is so specific. Yes, that means it's not suited for "high level" applications, like web apps, and situation in which development time needs to be cut. But that specificity and control over every action is exactly why it's good for network and hardware programming. I haven't seen C used outside of those realms in a long time. edit: Furthermore, it's low-levelness makes it very versatile. It centers around the universal abstractions used in Unix - the ability to open, read, write, and close files. That, combined with structs, unions, and it's basic data types allow you to use it for virtually ANY protocol.
- pavlov 17y agoI haven't seen C used outside of those realms in a long time. For an example of modern high-level C, check out GTK+. It's a sprawling cross-platform GUI library that provides the foundation for the arguably most popular Linux desktop environment (GNOME). Although GNOME apps are frequently written in higher-level languages using bindings, GTK+ itself is plain C.
- creachadair 17y ago> That, combined with structs, unions, and it's basic data types allow you to use it for virtually ANY protocol. Sadly, when you use C to implement low-level binary wire protocols, you quickly discover that structs, bit-fields, and unions are nearly useless because they are incompletely defined. Byte order is undefined. Structure layout is mostly undefined -- you pick field order, but you can't choose packing, alignment, or padding rules. The sizes of the integer types vary by platform and compiler. Bit field layout, packing, and alignment are almost completely undefined. What you're left to work with are unsigned characters, pointers, and bitwise operations. You have to pack and unpack everything manually, or your code won't port. It's enough to get the job done, but it's like using a wrench to pound in screws. I could do with a little less specificity of action, myself.
- hemancuso 17y agoFor a long time people built huge buildings with very very thin measures in place for worker safety. Buildings cost a lot less and went up a lot faster - but it came at the cost of workers lives. OSHA's rules make it much more expensive and tedious for American cities to grow - but the growth isn't coming on the backs of construction workers. It's a trade off we've decided to make because we value safety and we value not getting our pants sued off for negligence. You can write some well designed quick-and-dirty C code that does what you want, and does it fast. But once in a while you'll make a mistake that you probably won't notice and might cost you your company.
- tarkin2 17y agoAnyone care to guess at what he means by a strong and expressive type system?
- slackerIII 17y agoThis article in particular crystallized a thought I've had about this site, and sites like this in general. I would love to see a wiki-editable block attached to each submission that tries to describe, in as few words as possible, what information the article contributes. Think of it as compression, where a basic knowledge of computing is assumed. More interesting articles would have a lower compression ratio, which might be a fun thing to filter on. This article might go down to, "C is generally unsafe, and you probably aren't skilled enough to make it safe, so don't use it". Or maybe, "I needed to write something for my company blog, so I found a recent security hole and added some vaguely related platitudes".
- jwhitlark 17y agoUse the right tool for the job. C is the right tool for some jobs; if you jam it into a place where it doesn't belong, you probably don't have a deep enough understanding of it to use it safely. There are two groups you find misusing something. Those that really know what they are doing, have weighed the risks/rewards, and have decided that misusing the tool to get the job done is worth the associated risk. Then you have people who don't know what they are doing. They are going to have problems, but don't blame the tool.
- zandorg 17y agoI wrote my own sprintf handler which checks string length and truncates if necessary. unsigned long lsprintf(unsigned long max_length,char [asterisk]dest,char [asterisk]fmt, ...) char buffer[1024]; lsprintf(1024,buffer,format); Slightly overkill.
- parenthesis 17y agoC99 has snprintf() for this.