A shitpost about languages that generate CVEs

  • 0x0@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    3 months ago

    The “C is bad trope” is getting way too old. I’m surprised the author didn’t plug Rust.

    the only programming language in the world where these vulnerabilities regularly happen

    Maybe because it’s one of the most widely used languages in the world…

    • BatmanAoD@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      3 months ago

      The trope will be “old” once the mainstream view is no longer that C-style memory management is “good enough”.

      That said, this particular vulnerability was primarily due to how signals work, which I understand to be kind of unavoidably terrible in any language.

        • BatmanAoD@programming.dev
          link
          fedilink
          arrow-up
          0
          ·
          3 months ago

          I’m not totally clear on why signals are used here in the first place. Arguably most C code doesn’t “need” to use signals in complex ways, either.