Hacker News new | past | comments | ask | show | jobs | submit login

For bugs in general sure, but I specifically said "exploitable bugs" which is a different story. I don't think it's going too far to say that the probability of a Rust compiler bug, or a bug in unsafe Rust library code, leading to an exploitable issue in the Rust demangler, is low.



The implication being that it's impossible to write exploitable code without using unsafe? First, that's not a claim I've heard made, second, I'm far too conservative (having been around long enough) to believe Rust code in general can't be exploited, given enough time and effort by smart people, even if that's the current belief. Whole new classes of exploits occasionally pop up, and you can't reliably protect from that which you know nothing about.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: