Hacker News new | ask | show | jobs
by Pooge 2 days ago
> I can't remember a single incident where somebody I knew was directly affected by a memory safety issue

That doesn't mean the issue is nonexistent. See this article by Microsoft that shows the percentages of fixed CVEs that are related to memory safety.[1]

[1]: https://www.microsoft.com/en-us/msrc/blog/2019/07/we-need-a-...

1 comments

The percentage of fixed CVE at Microsoft is an irrelevant number. It is heavily biased by 1) what gets assigned a CVE in the first place (a usability issue or a weak supply chain usually does not even though far more relevant for users), 2) what gets found and fixed (memory safety issues are relatively easy to find and verify), 3) and also by how Microsoft operates (e.g. certainly not using any modern C).

So I think looking at this with regard to what actually matters for users is completely misleading. Rust fans running around touting memory safety as the most critical thing that overrides all other considerations, but having several hundred of dependencies in statically compiled software and teaching users to do "curl | bash" is actually a disaster for security. I am not saying that memory safety is not a good thing, but this distortion of reality is harmful.