|
|
|
|
|
by DCKing
3368 days ago
|
|
I do get a vibe of tone deafness coming from such a reply. 1) You're stating that automated tools are a solution in a thread in a blogpost for a heavily scrutinized tool that has a zero tolerance policy for Coverity problems, uses Valgrind and address sanitizers and still owes more than half of its CVE's to various language and memory safety issues. 2) "The responsibility is in the hands of the programmer" - I think we have argued enough that putting this responsibility in the hands of very imperfect programmers is precisely the problem and we should do the best we can to stop it. You're minimizing C's security issues again, please stop doing that. |
|