Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Heartbleed was not a side-channel attack. It was not a subtlety of the TLS specification. It was the single most well-known, common C-based security flaw. Better languages may not solve everything but they are absolutely the solution to this class of errors.


Similar could be said for Goto Fail and the GnuTLS bug. I wonder how something like Coq could handle the Debian random number bug, though. Still, 3 out of 4 ain't bad.

Do any functional or logic programming languages or libraries have a concept of entropy, and entropy generating/reducing operations?


Well-said!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: