Hacker News new | past | comments | ask | show | jobs | submit login

I think the main thing to discuss here is how, 25 yrs later, we're still getting overflow bugs.



It's a bit disappointing to still see overflows around, but at least blindly smashing the stack is no longer usually exploitable for modern systems with basic security.


I seem to recall there being some efforts to standardize "fixes" for C, and they never got adopted by anybody important, so the C development community kind of just failed hardcore to prevent it. IMHO it was never about the tools, it was about how we used them and the interfaces for common conventions.

Actually, I take that back: it is also the tools' fault. GCC should just refuse to compile any reference to strcpy().




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: