A shitpost about languages that generate CVEs

You are viewing a single thread.
View all comments
2 points

… the only language where 90% of the world’s memory safety vulnerabilities have occurred in the last 50 years

Yeah… That’s a shit post alright.

I’m not a C developer myself, but that’s just a low blow. Also, uncited ;).

permalink
report
reply
9 points
*

This is an overstatement, definitely. C is one of the few (mainstream) languages where memory safety vulnerabilities are even possible. So if you batch C and C++ together, they probably cover more than 90% of all the memory unsafe cove written in last 50 years, which is a strong implication that they will contribute to 90% of memory vulnerabilities.

All that said, memory vulnerabilities are about 65% of all high implact vulnerabilities on Chromium project[1] and about 70% of vulnerabilities at Microsoft [2].


  1. https://www.chromium.org/Home/chromium-security/memory-safety/ ↩︎

  2. https://github.com/microsoft/MSRC-Security-Research/blob/master/presentations/2019_02_BlueHatIL/2019_02 - BlueHatIL - Trends%2C challenge%2C and shifts in software vulnerability mitigation.pdf ↩︎

permalink
report
parent
reply
1 point

So we’d only fix 70% of vulnerabilities by switching to rust? Not enough! Better keep writing C/C++!

permalink
report
parent
reply
6 points

Yeah the only way it would be that high is if it lumps C and C++ together. But at that point it may be an underestimate.

permalink
report
parent
reply

Programmer Humor

!programmer_humor@programming.dev

Create post

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics

Community stats

  • 7K

    Monthly active users

  • 730

    Posts

  • 11K

    Comments