The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published research looking into 172 key open-source projects and whether they are susceptible to memory flaws.
Rewriting something in rust could create more vulnerabilities. You would be throwing away your well tested code and starting over from scratch in a language you may be less familiar with. A memory safe language doesn’t protect against everything.
onlinepersona@programming.dev 4 months ago
First of all, yes CVE generating languages have been here a while, unfortunately. They are very ingrained and difficult to root out.
But most importantly
Fucking pay them or write them yourselves. Y’all have endless money. You can of course wait and hope the situation resolves itself, or really it along if you rely on it so much.
Anti Commercial-AI license
BrikoX@lemmy.zip 4 months ago
This. Refactoring the whole code is insanely time intensive, even if developers know multiple languages. All these critical components you rely on, you use without any compensation or support and then dare to complain it’s not your security standards. Fix it, or pay for it to be fixed.
cybersin@lemm.ee 4 months ago
What do you mean? We have our summer intern rewriting the entire Linux kernel in Rust with the help of ChatGPT. They are set to submit the PR by Friday night.
/s