Skip to content

Ask HN: Would any code analysis tools have caught have caught heartbleed?

1 pointmacarthy123 comments
On HN

If not, why not? Is this kind of issue something that a language feature could avoid?

Comments

This blog post demonstrates how OpenSSL's unsafe C code can be migrated to a safe programming language called ATS (Applied Type System):

http://bluishcoder.co.nz/2014/04/11/preventing-heartbleed-bu...

See http://blog.regehr.org/archives/1125 (Heartbleed and Static Analysis)

Looks like the FLOSS community needs to start exploring these kind of tools.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.