Microsoft is creating a new Rust-based programming language for secure coding
zdnet.com
zdnet.com
Slides: https://www.slideshare.net/KTNUK/digital-security-by-design-...
- Need to keep old insecure code around, too much money to rewrite the world from scratch in Rust, C#, or whatever safe language makes your day
- They are just starting the project, so far only interpreter and runtime model
- It is based on CHERI CPU research (https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/), which has memory tagging
- They are planning to open source the existing work in a couple of months
- Looking for collaboration
That's what process boundaries are for. (As a bonus, you get protection from any Spectre-like issues arising in the old code.)
If you are able to force a process to change its behaviour, the process boundaries become useless.
Let’s be a little more accurate here. Rust is an actively developed language, Cyclone was a research project that I don’t believe has received an update since 2006.
Rust also is explicit that it borrowed its lifetime concept from Cyclone. Rust is in use and gaining popularity in a way that Cyclone didn’t.
This is a bit like the debate between Apple and Xerox in terms of the beginnings of the desktop/mouse/GUI environment. Apple was the first to make it popular, xerox park invented it. Rust has a similar relationship with Cyclone.
It wasn't until today I did a search on it, and it reached 1.0!
Why wasn't Cyclone being used or continue to be developed?
The big breakthrough with Rust was ownership, and Microsoft seems to agree on that. Rust has a lot of other baggage that could be dispensed with. Of course, Microsoft has their own baggage.
Microsoft has a huge problem: thousands of coders who aren't disciplined enough to write reliable code. They need a language to provide the needed discipline. They tried making their own language, and now understand that they are not good enough at that, either. Rust, or a fork of Rust, might suffice.
They are not interested in displacing Rust from wherever it is being used. They just need something for their things, that their customers can also use. Lock-in is exercised farther up the chain.
https://www.slideshare.net/KTNUK/digital-security-by-design-...
Talks about sandboxing C/C++ libraries that interact with Rust. Kinda make a safe unsafe sandbox Rust interface ("less unsafe?") if I understand it correctly (I likely don't).
The actual linked article is all over the place, I cannot make heads or tails of it and seems to be conflating multiple security issues/mitigations together into a mish mash.
Typical ZDNet.
Basically a new language for system software and containers that allow to tame existing software, due to the expenses of rewriting everything into safe languages.
It is based on the CHERI tagged architecture.
https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/
Just starting now, they have done the ground work, will open source it and are looking for collaborators.
The substitution macros aren't that much fun either since they lack certain capabilities (like introducing a new variable into the current scope without having to specify the name redundantly).
Without a lot of external libraries, procedural macros are almost impossible to write in my experience.
Neither of them allows one to properly code onto the type system or replace it and neither is properly supported by the IDEs (or RLS).
The closest thing to this I can think of is Racket. It's supposedly powerful enough to embed Haskell in it https://lexi-lambda.github.io/hackett/
Racket is special because its designers provide dedicated support of language-oriented programming. But that is about ecosystems, not typesystems.
The high-level-variant is a dynamic language with optional typing, which is good for scripting, fast prototyping, fast time-to-market, etc.
The low-level-variant is similar to the high-level-variant (same syntax, same features mostly, same documentation), but it has no garbage collector, typing is mandatory and it runs fast like C/C++/Rust. Compiled packages that are written in the low-level-variant can be used from the high-level-variant with minimal effort or without additional effort at all. The tooling to achieve this comes with the language.
The one major wart with Julia is reliance on GC, I'm interested to hear what workarounds exist. If no common usage patterns rely on the GC, it should be possible to write "recycling" code that doesn't incur GC pauses and hence, unpredictable latency.
I really enjoy using Julia, it's a great balance of concision, expressiveness, and performance.
I think it will also rocket up Julia's popularity and usage not just for ML but as a general purpose language
Is some concept of language support for traits/ interfaces and/or static typing part of this effort?
Also, would there be different levels of leanness for the static compile? I can see some people wanting binaries that use a minimal runtime or GC, but no heavy JIT etc so that a larger set of programs can be distributed but at some tradeoff.
We also have an example of something more similar to what you are asking with Javascript+wasm (or better Typescript+wasm). I think they are both a fertile ground for future growth.
As it stands, it is forced to follow some of Java design mistakes by not integrating modern features and then being forced to actually adopt them in a half-baked way due to market pressure, while striving not to break backwards compatibility with existing code.
Modern C++ also uses GC, even it is opt-in.
And several modern C++ features actually originated in D.
D has the benefit of not being constrained by C copy-paste compatibility like C++.
But yeah, it suffers from having a tiny community.
[0] - https://en.wikipedia.org/wiki/Oberon_(programming_language)
[1] - https://en.wikipedia.org/wiki/Limbo_(programming_language)
And feature bloat.
Modern languages can be bloated.
If Go's design was perfect, its eco-system wouldn't feel like Java 1.0, full with libraries to replicate what should be language features to start with.
The first time I saw "go generate" it was on Borland C++ 2.0 for MS-DOS, released around 1990.
Some of us care about advancing the state of art, instead of being stuck into the ways of the past.
I believe it's still in the roadmap for Go 2.0
Love the idea that a Netscape-legacy language has traction there. I hope they don’t return to their pre-Nadella practices.
[1]: https://github.com/rust-lang/rust/issues/53488
[2]: http://smallcultfollowing.com/babysteps/blog/2018/04/16/rust...
There are also Microsoft teams starting to use Rust, e.g.,
https://msrc-blog.microsoft.com/2019/11/07/using-rust-in-win...
One reason of why I'm using Rust is because it's built by a group of people that I like, and Microsoft is not on that list.
However, I always keep a open-mind, I mean, I don't see anybody will be hurt if Microsoft become a direct contributor of Rust language itself. In fact, I could like Microsoft a bit if they did invest in Rust. I hope they do that <delete>instead of trying to fork things/build something alike (if that's the case here)</delete> (I watched their intro, their design is different than Rust and I somehow like what they did there).
If someone had told me ten years ago that my favourite code editing environment on the Linux desktop ten years later would be browser-tech-based, MIT-licensed, and made by Microsoft, I'd have stared at them like they had just grown a second head. But here we are. Interesting times, man.
Cool that MS is using something Ruat based. In no way does that opinion lead to a conclusion of ongoing support.
Windows on ARM is probably fine. Windows Phone and the like eventually lost (losing? I haven’t kept up) support, but phones are traditionally a 2ish year supported device and then they’re not targeted (specifically in the Android OEM arena). Windows proper they have business clients and if they don’t support it for a reasonable amount of time, Microsoft is basically hosed. It is, I imagine, why once they decided to kill off older IEs everything prior to latest and greatest was killed at the same time: they had supported them for far too long and it required killing them all Off in one move.
I’m pretty sure you’ve got your history backwards. GCC was created specifically to fill the need for a free C compiler for GNU. By that time C was already popular by association with Unix.
https://www.slideshare.net/KTNUK/digital-security-by-design-...
It seems like they want to do something like Rust, but with a new focus on regionalized memory management.
I'm not saying they're like that today, but that's why some people get all on-edge when Microsoft does things like this.
Microsoft has become better in the last years, but they still do bad things. So why should people trust the wholeheartly?
Remember Microsoft tried to kill the internet and could have succeeded if it wasn't for the efforts of many, the US DOJ included, to prevent them from obtaining total control through their operating system monopoly.
You can't go through that and not be skeptical.
But if it simply means they are making a new language using lessons from Rust - then why not.
Though I didn't quite get what problem they found with using the idea of scope based lifetimes per object, that they needed to redefine it in context of groups.
I guess shipping Windows API cargo crates makes too much sense. Does anyone have any context for gaps in Rust they are addressing?
In TFA it mentions that ownership will be based on groups of objects, but I’m not sure I understand what this solves that a struct doesn’t.
I haven't finished digging through the OP, but it looks like a bunch of Microsoft employees (already aware of Rust's safety benefits) have started recognizing the commitment to FFI as well. My last project had a feature that depended on a bind to win32, which turned out to be the most time consuming aspect - as it demanded a bunch of tooling that was otherwise unnecessary (valgrind, etc). If they were to take stewardship of that interface, lots of unsafe{} would disappear overnight.
Linux tools run on Windows 10 just fine. WSL 2 even uses an actual Linux kernel.
https://msrc-blog.microsoft.com/?s=rust
And the talks done about the internal adoption,
https://www.youtube.com/watch?v=qCB19DRw_60
https://www.youtube.com/watch?v=o01QmYVluSw
And the author from C++/WinRT is now working on Rust/WinRT.
https://kennykerr.ca/2019/11/05/rust/
So lets wait a bit before going to the castle with the pitchforks and torches.
It almost makes me wonder how they/we can work around that sentiment now. Either hope for generational shift to eventually kill it, or perhaps have them make a point of landing projects outside of MS and hoping nobody notices(GitHub R++ or whatever).
Tips on how others approach these discussions with Microsoft haters greatly appreciated!
I try to be objective as much as possible, but having witnessed almost all of Microsoft’s behavior through history, we have been fooled 100s if not 1000s of times. How many times do you let the fox back into the hen house?
The only thing I think when I read recent “Microsoft is so great” comments is that the person is either too young to have any real knowledge, or they have simply not been paying attention for the past few decades.
For anyone who has seen what they have done through all of history, it will take decades to believe they have truly changed.
The OOXML Office format they used to continue pushing Office lock-in is very recent: https://wiki.documentfoundation.org/LibreOffice_OOXML
They tried their best to keep the list of their Android patents secret, so that they could not be worked around, and they abused their patent on the FAT filesystem as recently as 2012: https://www.howtogeek.com/183766/why-microsoft-makes-5-to-15...
They also still lobby against open standards: https://www.computerweekly.com/blog/Public-Sector-IT/Microso... https://www.theguardian.com/technology/2015/may/22/microsoft...
And lets not forget all the spying in Windows 10.
MS is as hostile as ever - it's a fantastic success of propaganda to make people think it's limited to "decades old issues".
Windows 10 telemetry is a child's game compared how much Google and FB spy on people's lives, yet most MS haters just jump of joy to use any tech that comes out from them.
Legions of US parents just put their kids under Google surveillance getting them Chromebooks.
The OS is also theoretically able to watch what you do in other services by monitoring keystrokes etc, where Facebook merely dreams of such things
As for your question - Cloudfront springs to mind - they're pretty loud about going after patent trolls, which implies they might not use patents aggressively. I'm sure there are many others, but a company not using patents to extract payment isn't something you hear about, so it's hard to tell. That said, despite filing for many patents, I haven't heard of Facebook actually using them against others. Which isn't to say they haven't done so (and possibly, like MS, kept the agreement confidential), and of course Facebook is hardly ethical itself.
Another poster says Microsoft joined the Open Invention Network, so perhaps in that area, they've reformed. Though they could still be lobbying for patents, which does much more damage to user freedom.
1. https://onezero.medium.com/speaking-truth-to-power-reflectio...
One example: "Microsoft is killing it. Revenue is up. Stock is up. Industry stature is up. The places where Microsoft finds itself thriving all have one thing in common: key made-men were pushed aside for better people."
The original argument was: "Microsoft still has the elements of its previous bad behaviour in its DNA." The counter claim was: "No one from Microsoft during that time is still in the company". The article clearly supports the first claim and shows the second claim is at its face false. I encourage everyone to read the article and not to take speculations and misleading quotes as support for false ideas.
The article demonstrates that Microsoft is a complex organization with both good and bad and is changing for the better even if it has a way to go.
Supporting the good and praising Microsoft for what they're doing well is going to make Microsoft better. Crapping on what they're doing well because of actions from 20 years is not rational or helpful.
That does not change the fact that Microsoft is a risk. Google is a risk since they have a habit of shutting down projects. Oracle is a risk due to their insane licensing and consulting fees. Open Source is a risk since the contributors can just decided to drop support. Everything has elements of risk. I guess I just won't back down from someone claiming there is no risk in Microsoft because all the bad people are gone. That is an absurd claim that also happens to be false.
As demonstrated, people working during the time periods he referenced are still working for Microsoft, contrary to this claim. This also addresses why someone should consider the risk of "decades old issues" when making decisions today.
I don't think your opinion is objective at all. It's based on treating a collective as a single mind.
Not really trying to protect Microsoft here but them companies are all the same, just different degree of "success".
The argument is that if a language is developed/mainly contributed by a single company there is an inherent risk of that language being suddenly discountinued or lacking features that are needed by other people/companies.
At least that's how I understand the critics against microsoft in this case.
Funny how nobody seems to give pile on Google for how it handles Go here...
Thanks goodness for Linux and the web (and later mobile computing which MS failed to dominate) to pull us away from the brink of an MS monoculture.
Microsoft didn't change out of charity or ethics. They were forced by the direction industry was heading as a whole. Cloud, opensource software, Google, AWS started making Microsoft irrelevant unless they changed.
The telemetry scandal which has been reported on everywhere proves that Microsoft just changed into another Google. They're still collecting telemetry today, in spite of all the protests. A few hours isn't a long time in our line of work...
Are you referring to this?
https://www.infosecurity-magazine.com/infosec/atom-community...
The telemetry in windows is ongoing so I’m just wondering if I missed something new
OCaml cannot do that. I say this as someone who currently is finishing a year of F# study with plans to study Rust in 2020 and OCaml in 2021.
From my perspective, the issue ultimately is - why? What do I gain from using Microsoft software?
I worked at a Microsoft shop for a short period. All of the 'new MS' stuff I've personally worked with has certainly been Windows first.
Take C#. It might work on Linux, sure, but you have stuff like the .NET runtime taking forever to start, the reliance on Visual Studio, .NET Framework isn't open source because.... why?
Or perhaps you have Microsoft Teams - for which, despite it effectively being a web app - there is no Linux client and in Firefox half the features are disabled. Even on Windows it's literally a shit version of Slack which presumably exists solely because it's bundled with other Microsoft stuff or because the name has appeal to some PHBs.
For the most part from what I can tell it's all still either Windows first, or a crap version of something else, or both. There might be some minor researchy fun bits, but anything that seems to actually see wide use is all Windows stack.
What's the point? I read the article, and it pretty much feels like they want to Windowsify Rust. Why should I care about that?
Literally everything I read about Microsoft seems to be from people who want an excuse to use Windows, or something. I want Windows to burn and die in a fire; so what is there for me?
"The ownership model in Verona is based on groups of objects, not like in Rust where it's based on a single object.
If you're looking for a memory-safe language today or in the next couple of years, I don't think anybody will ditch Rust for Verona.
I dont agree. Proliferation of languages has it's down side. Very few are self hosting, with most being built with C++. Rust is a safe C++ replacement. We dont need a bunch of those.
It is objectively worse for there to be two such languages, one of which is poorly funded and the other funded by Microsoft than have one such language that is cross platform.
Also the Java oxygen is sucked out of the room by C#. All the OCaml oxygen is sucked out of the room by F#. A world where all the rust oxygen is sucked out of the room by R# and tied to the windows ecosystem is a bad one.
They've tried this shit with a dozen other languages and besides C# being better than Java, (even though the .NET ecosystem sucks) it's always ended terribly. C++/CLR, IronPython, IronRuby, J#, etc.
Having your tech embraced by Microsoft is the kiss of death.
"IronRust" would be amusing
(And this is just the most obvious and clear way that they support Rust, it’s not limited to that.)
> plenty of Wnd handles to be thrown around
That is not really a language issue, is it?