|
|
|
|
|
by UncleMeat
1072 days ago
|
|
Of course. But these issues will remain near the top of the list indefinitely if people just leverage traditional analysis tools. I love static analysis. I did my PhD in it. But we'll still be talking about use after free in 2073 if we just try to chase higher K in our analysis implementations. |
|
The main issue is the community sub-culture of not adopting tooling as it isn't perfect 100% of the time.
Many of the C++ security conscious folks end up being polyglot, as this subculture eventually wears one out.