|
|
|
|
|
by abrawill
1257 days ago
|
|
If the hardware is exotic I guess you’d have no choice.
But for security critical don’t you run the risk of relying on obscurity rather than security due to the niche-ness of your stack? What does a vendor compiler do or do better than a compatible generic one? |
|
With a vendor supplied compiler you can say, "We're using version 11.2". A year or two later an issue is discovered, the vendor will backport a fix to 11.2 giving you 11.2.1 which is much less effort for recertification. You aren't depending on the kindness of strangers (a terrible strategy) because you're actually paying someone to do the work.