Remix.run Logo
daitangio 42 minutes ago

We need to be prepared to write less software, with a smaller attack surface. Less is more.

Bloated code is the critical problem. Once upon a time, I read C function

> char gets(char str);

is the first buffer overflow entry point, because it does not check the size of the destination buffer.

Sadly we cannot remove it from standard-C yet AFAI Know.

The success of Rust versus other languages is its secure-by-compile-time promise.

Also a lean java could help, but Java is so verbose/slow to start it bumps you away.

legulere 7 minutes ago | parent [-]

Memory unsafety in C/C++ is a big portion of security issues, but it's not everything there is.