The creator of C++ criticized the imposition of safe programming languages

Bjarne Stroustrup, creator of the C++ language, published objections to the conclusions made in the NSA report, which recommended organizations to move away from programming languages like C and C++, which place memory management on the developer, in favor of languages such as C#, Go, Java, Ruby, Rust, and Swift that provide automatic memory management or perform safe memory checks at compile time.

In Stroustrup's opinion, the safe languages mentioned in the NSA report do not actually surpass C++ in important applications from his perspective. In particular, the core guidelines for using C++ developed in recent years (C++ Core Guidelines) cover methods of safe programming and prescribe the use of tools that guarantee safe handling of types and resources. At the same time, developers who do not require such strict safety guarantees are allowed to continue using older development methods.

Stroustrup believes that a good static analyzer that conforms to C++ Core Guidelines can provide the necessary safety guarantees for C++ code, requiring significantly less effort than switching to new safe programming languages. For example, most of the Core Guidelines recommendations are already implemented in the static analyzer and memory safety profile included in Microsoft Visual Studio. Some of the recommendations are also considered in the Clang tidy static analyzer.

The NSA report's focus solely on memory management issues was also criticized, as it overlooked many other programming language problems that affect safety and reliability. Stroustrup views safety as a broader concept, with various aspects achieved through a combination of coding style, libraries, and static analyzers. To manage the inclusion of rules that ensure safety in handling types and resources, it is proposed to use annotations in the code and compiler options.

În aplicațiile în care performanța este mai importantă decât securitatea, o astfel de abordare oferă posibilitatea de a aplica selectiv măsuri care garantează securitatea doar acolo unde este necesar. Instrumentele de îmbunătățire a securității pot fi de asemenea aplicate parțial, de exemplu, la început să ne limităm la reguli de verificare a intervalelor și inițializării, iar apoi să adaptăm treptat codul pentru cerințe mai stricte.

Sursa: opennet.ro

Cumpără un hosting fiabil pentru site-uri cu protecție DDoS, servere VPS VDS 🔥 Cumpără un hosting fiabil pentru site-uri cu protecție DDoS, servere VPS VDS | ProHoster