Quantitative analysis of issues found by afl in mandoc
undeadly.org
undeadly.org
Does anyone know what he's talking about?
assert() is usually used in debug builds to verify internal invariants of the code: "if this is false, something has gone horribly, terribly wrong; we've gone crazy and we should abort to avoid further hurting ourselves or others". It shouldn't be used to verify that user input is well-formed, since this happens under normal circumstances.
It is absolute madness to use C or C++ in a security-critical system.
(Hmm, perhaps I'm making your point for you? ...)
One thing I have noticed though is that replacing manual with automatic memory management often doesn't help as much as one might think. The bugs just tend to shift to other areas (e.g. memory corruption -> command execution, XSS or XXE etc).
I think this is because with a more forgiving language, developers tend to naturally create more complex systems. Like how car drivers go faster when they feel safer in their car.