Out of bounds write and read are more prevalent then UAF. There are multiple types of bugs that can produce OOB read or write though.
759 karma · joined July 5, 2013
Out of bounds write and read are more prevalent then UAF. There are multiple types of bugs that can produce OOB read or write though.
That said, education certainly needs major reforms. I like how Sweden is going full Luddite for learning: https://www.theguardian.com/world/2023/sep/11/sweden-says-ba...
Other parts of infosec are the same, but often with less well-quantified measures of effectiveness. E.g. memory hardening techniques like FORTIFY_SOURCE and MTE are effective in raising the difficulty of exploiting memory vulnerabilities, but under some conditions the vulnerabilities may still be exploitable.
Before using labels like "security through obscurity" one has to first answer: how much does the technique raise the cost for attackers? This is what articles about security systems (including this one) should focus on. In the end, hacking, like most things, comes down to economics.
> We need your contacts to provide the service, but don’t share your contacts with Meta.
I'm frustrated that people even at HN allow themselves to indulge in conspiracy theories that would be immediately whistle-blowed or reported on. There are thousands of people that work on or with WhatsApp and related products within Meta who would notice, not to mention all the data separation audits that happen.
> We need your contacts to provide the service, but don’t share your contacts with Meta.
Leave hot loading to local/development environments, not production deploys.
Loading configs on the fly can also have some of this risk, but it is much easier to reason about typically.
Some degree of device pragmatism is inevitable of course. But I don't think my kids will need a smartwatch until high school, or a phone till very late HS. In other words, I think there is a balance of these options possible.
Jonathan Haidt gives a lot of hope here, as depressing as "Anxious Generation" usually is.
HTTP has been around since 1991, 33 years ago. We really pushed things faster in the second half of HTTP's life so far.
Rust eliminates these bugs and it results in fewer security issues in Rust code than C/C++. See https://security.googleblog.com/2022/12/memory-safe-language...
Additionally, even in brilliant soloist projects like curl, Linux, etc., you still get plenty of memory safety CVEs. The best still don't get it right.
> Are there any studies that show excluding memory overrun bugs...
Why exclude memory safety from the argument? That's the whole point -- to fix those significant fraction of vulnerabilities.
No, the data doesn't show this. This is the "anger" response to being confronted with the reality of the inherent insecurity of C and C++. https://www.usenix.org/conference/enigma2021/presentation/ga...