Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
nullagent
@nullagent@partyon.xyz  ·  activity timestamp last week

Was just going on a grey-beard rant about how Rust give developers a false sense of security.

I didn't even notice the TARMageddon vulnerability until now and well this grey beard really only can say "told you so".

This is -precisely- the class of bugs I was describing, and -exactly- due to the reasons I outlined.

The blast radius of this thing is also freaking epic, almost anything that used tar in Rust is vulnerable to possible RCEs lmao.

https://edera.dev/stories/tarmageddon

#Rust #Cybersecurity #tar

  • Copy link
  • Flag this post
  • Block
nullagent
@nullagent@partyon.xyz replied  ·  activity timestamp last week

So what were my cautions about Rust?

1. Be careful re-writing old stuff. You will repeat all the 30yr old logic bugs bc Rust is memory safe NOT provable correct.

2. Ppl-power. Lots of rewrites IS dividing our ppl-power. Be mindful of unmaintained core components

3. Vibe coded Rust is just as dangerous as any other language

4. Rust still can be used in memory unsafe ways. You actually have to audit the code to know if they did Rust right.

#Rust

  • Copy link
  • Flag this comment
  • Block
nullagent
@nullagent@partyon.xyz replied  ·  activity timestamp last week

I've coded in C / C++ / Java / Python / JS and anything else needed to get the job done.

I have never heard any group of devs so quickly dismiss security concerns about their ecosystem as rapidly as Rust devs.

YES the language IS type safe and that's a big value add.

But that value add can quickly be cancelled out without significant attention to detail.

The EXACT same attention to detail I code with in C / C++ / Java / Python / JS etc.

This time, is not different.

#Rust

  • Copy link
  • Flag this comment
  • Block
Perma
@Prma@genserver.social replied  ·  activity timestamp last week
@nullagent Where have you seen in rust community security concerns about this being dismissed?
  • Copy link
  • Flag this comment
  • Block
Alex with the Temper
@holsta@mastodon.art replied  ·  activity timestamp last week

@Prma The preferred install method of rust/cargo is still curl output piped to a shell.

@nullagent

  • Copy link
  • Flag this comment
  • Block
Nate Cox
@natecox@tilde.zone replied  ·  activity timestamp last week

@nullagent I don’t know man, I’ve been around the block a few time in the dev community and I feel like dismissing legitimate concerns in favor of vaporware hype is really status quo across the board.

I love rust, it’s what I write when I want to have fun, but as always there’s gonna be a group that can’t seem to distinguish hype from reality.

  • Copy link
  • Flag this comment
  • Block
nullagent
@nullagent@partyon.xyz replied  ·  activity timestamp last week

You ain't wrong. I kinda forget how exciting the new language/tech hype train can be.

@natecox

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login