Sure. That was the vulnerability I was thinking about too. I think the biggest knock I've heard against what Prossimo is doing --- and I respect & admire the people working on that project! --- from exploit-dev types is, they're picking targets that nobody thinks are likely to cough up more meaningful memory corruption vulnerabilities. I agree: 2021-3156 is a good argument for memory safety. Memory safety is a good argument! But if you're ranking "next things to make memory safe", sudo is, maybe counterintuitively, a little unattractive.
What's your ranking for "next things to make memory safe"? I'm going to guess the TLS stack would be #1, considering fly.io's sponsorship of rustls. Eager to hear the rest of the list.
Comments
Sure. That was the vulnerability I was thinking about too. I think the biggest knock I've heard against what Prossimo is doing --- and I respect & admire the people working on that project! --- from exploit-dev types is, they're picking targets that nobody thinks are likely to cough up more meaningful memory corruption vulnerabilities. I agree: 2021-3156 is a good argument for memory safety. Memory safety is a good argument! But if you're ranking "next things to make memory safe", sudo is, maybe counterintuitively, a little unattractive.
What's your ranking for "next things to make memory safe"? I'm going to guess the TLS stack would be #1, considering fly.io's sponsorship of rustls. Eager to hear the rest of the list.