I found that quite humbling. I thought I was a lot better at writing secure code than that.
I found that quite humbling. I thought I was a lot better at writing secure code than that.
The statement was about the difficulty of creating _correct_ code. Agreed security is important. So is performance, memory usage, etc - and we're not talking about those either.
Original comment said that "Producing correct code is insanely difficult". I agree with them.
And not all code is the same. To a huge degree - most things are pretty straightforward, and the hard stuff is usually a minority of the whole.
Correct code might not be sufficiently tested, it might waste memory, it might do dumb things with the wrong data structures, it might be terribly factored, it might be commented in sanskrit - and yet it can still be "correct". Don't muddy the waters by bringing in all these other factors. Those are not correctness, even though it might be something that you (and I) strongly desire, or things that are necessary to ship with. Correctness is not "done".
And I agree that any code released into the wild should be as secure as you can make it. Though a scientist running a sim on their desktop might not be remotely concerned at how secure their fortran code is.
Isn’t the admittance that “of course most products are highly imperfect” more supportive of writing correct code as being difficult than not?