Night of a cascading failure
rachelbythebay.com
rachelbythebay.com
We use multiple bastion hosts with user accounts provisioned by Ansible. There is one in each data center, plus a "shell" box at AWS that lives outside the firewall and also has SSH access to everything we need. All the bastions can access every server.
Plus, some of the mission-critical boxes actually have SSH exposed to the public internet. I would much rather take the security risk with (key-only) OpenSSH than the risk that I get locked out of PROD when I need to fix things after a 2am page.
It is entirely possible to make a box so secure that you yourself cannot access it, while not actually doing much to defend against more "reasonable" security risks, like typo-squatting and spear-phishing. It's all about the threat model.
I'm confused, did you mean lesson?
This doesn't apply if you are using unsized for bit twiddling, but then you shouldn't be using minus anyway.
It’s sort of like a dependent type which ensures you cannot represent invalid values.
if (new_len > child.length())
As stated in the article, checking if an unsigned is less than 0 is a silly logic error but obviously one that is understandable to make. Still it's the sort of thing you'd expect automated tools would be able to catch.The pitfalls of signed arithmetic are much more insidious. Left shift a negative value? UB. Negate a negative value: maybe it's still negative. INT_MIN / -1? Crash!
Even basic arithmetic operations, e.g. the average of two integers, is unreasonably hard with signed arithmetic.
What do you have in mind? I understand that the addition can overflow, but that can happen with unsigned as well.
But it's only guaranteed to be 16 bits anyway, the same guarantee you have for size_t.
C makes it hard to have anything bigger than 32-bit int. The standard integer types are char, short, int, long, and long long, and if int is 64-but then you’ll lack a standard type for 8, 16, or 32 bit integers, which is inconvenient. Nothing says you have to have those, or that you can’t make some implementation-specific type to fill the gap, but it’s messy.
You should almost always use unsigned types unless you must use a signed type. And you need to think about these kinds of overflow and underflow cases.