> I can write a safe C++ app on my own
>> But only if you don't use any external libraries
using an external library is not "on your own"
using an external library is not "on your own"
Therefore, language features to prevent a class of exploits should be a high priority when considering a project.
Do many people really use the kernel syscall interface directly?