Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The whole problem is that you only need one mistake in all those billions/trillions of LOC's, and your systems get 0wned. I'm pretty sure that "our standards for C programmers" don't include "programmer is guaranteed not to make any mistake, EVAR", whereas that's an entirely appropriate standard for automated, language-based security.


See the related article posted from Microsoft today; Microsoft: 70 percent of all security bugs are memory safety issues

  https://news.ycombinator.com/item?id=19138602
If we could get rid of that 70% that would be great, but it still leaves programmers doing other stupid shit in the other 30% of cases.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: