Comment on CISA: Most critical open source projects not using memory safe code
onlinepersona@programming.dev 4 months ago
First of all, yes CVE generating languages have been here a while, unfortunately. They are very ingrained and difficult to root out.
But most importantly
Ultimately, CISA recommends that software developers write new code in memory-safe languages such as Rust, Java, and GO and transition existing projects, especially critical components, to those languages.
Fucking pay them or write them yourselves. Y’all have endless money. You can of course wait and hope the situation resolves itself, or really it along if you rely on it so much.
BrikoX@lemmy.zip 4 months ago
This. Refactoring the whole code is insanely time intensive, even if developers know multiple languages. All these critical components you rely on, you use without any compensation or support and then dare to complain it’s not your security standards. Fix it, or pay for it to be fixed.
cybersin@lemm.ee 4 months ago
What do you mean? We have our summer intern rewriting the entire Linux kernel in Rust with the help of ChatGPT. They are set to submit the PR by Friday night.
/s