would rust definitely prevent bugs like https://googleprojectzero.blogspot.com/2019/02/the-curious-case-of-convexity-confusion.html … ?
-
-
-
Yes, bugs like that are the ones I have in mind. To be clear, they could panic the renderer, but it shouldn’t be exploitable.
End of conversation
New conversation -
-
-
Well, for things like browsers, timing attacks or accidentally providing access to data you are not supposed to through logic error (passing wrong handle, forgetting to clear memory, etc.) are real sources of sec problems. But yeah, mem safety is a big deal and rust really helps.
-
Having to run filters in constant time with respect to input color for example is a pain in the arse.
- 6 more replies
New conversation -
-
-
How can we rearchitect our systems so that more of our code is in such a position?
-
Everything that doesn’t deal with access control, permissions, and isolation of untrusting content, should be separated out. Then you just have code dealing with untrusted input, and writing it in safe Rust gives you security.
- 1 more reply
New conversation -
-
-
Is that a fact or sarcasm?
-
That’s a fact
- 2 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.