How Memory Safety CVEs Differ Between Rust and C/C++
Why do we continue to measure a language's security by the number of CVEs when we know that number depends as much on the size of the installed base as on any property of the language itself? It took years of debate and a couple of papers from the NSA and CISA for the ecosystem to take the question seriously—and even then, the answer circulating in most threads is too simplistic to be useful. …
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
How Memory Safety CVEs Differ Between Rust and C/C++
Why do we continue to measure a language's security by the number of CVEs when we know that number depends as much on the size of the installed base as on any property of the language itself? It took years of debate and a couple of papers from the NSA and CISA for the ecosystem to take the question seriously—and even then, the answer circulating in most threads is too simplistic to be useful. …