Hacker News new | ask | show | jobs
by quotheth 3067 days ago
I feel strongly that you do not understand the performance implications of the mentioned mitigation techniques.
1 comments

These specific ones? Yeah, not that big a deal, but my post is about a development mindset, not the specific implementation. A few vulnerabilities show up in otherwise really great software and the idiots who browse this joint literally say the guy needs an intervention.
I don't get what you're arguing - this has nothing to do with the developer mindset. He just has to flip a compiler switch and vulnerabilities won't be trivially exploitable anymore.

It's totally irresponsible.

Well, HTTPS and high-confidence builds are popular concepts here, given that this forum is frequented by people on both side of the security fence.

At least I would assume it is. There are lots of white-hat reports, so...

No kidding. The authoritarian security cargo-culting irritates me too.

The fact that 7-zip bugs are rare enough that they make news when they are discovered already says a lot about the overall quality of the code. Many other projects with all the bloaty mitigations and other ostensibly "for security" cruft still manage to create severe bugs on a regular basis.

I read posts like this and it's just so clear to me why we're so fucked.