• iopq@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    16 hours ago

    Let’s not get too abstract. Just because Rust made its own mistakes doesn’t mean it didn’t fix the mistakes I pointed out

    Serious projects have huge memory safety issues that don’t exist in Rust. More than half of security CVEs are due to the nature of C. Rust just has fewer bugs like Heartbleed because it doesn’t let you do a buffer overrun

    • Nalivai@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      11 hours ago

      that don’t exist in Rust

      That’s because serious projects basically don’t exist in Rust. Yet, probably, Rust seem to be a good language that people like, so those are to follow, but for now they’re rare.
      Or don’t, if we discover that Rust has some other issue that only happens when the project grows old enough.
      Personally, I’m sticking to the devil I know, the one that has almost 60 years of accumulated knowledge and best practices.

      • iopq@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        6 hours ago

        Rustls can already replace OpenSSL, but maybe that’s not serious enough for you. Sure, the ring backend embeds assembly for the crypto operations, but that’s the point:

        You can have a safe interface for interacting with potentially unsafe code. Do all of the memory allocation and string manipulation stuff in Rust and call out to crypto in assembly

        • Nalivai@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          6 hours ago

          Yeah, it’s not serious enough for me. It will become serious if it actually replaces openssl, or at least actually is in use by any significant numbers. Until then, it’s a project that can potentially maybe sometimes be used by someone maybe, which by definition isn’t serious. Like any other project, it needs time under pressure, it needs to mature with use, be supported for some time, accept patches and changes, and sustain constant prodding by people who would like to break your stuff.
          OpenSSL is a standard for almost 3 decades, Rustls is cautiously maybe being pushed in experimental branches.
          It’s like that with everything Rust related really. We are at a phase where enthusiasts enthusiastically trying to convince someone to consider their new toy, which means we can’t really compare it with decades old projects that were scrutinized and stress-tested by millions of people.