Live data from Hacker News

Microsoft is creating a new Rust-based programming language for secure coding

zdnet.com

61–70 of 207 posts

Re: Microsoft is creating a new Rust-based programming language for secure coding

#61
post #58

Earlier quoted context omitted.

Big companies are not autonomous and do not make their own decisions, individual people working at those companies do. I think it’s safe to say that anyone working there today has nothing to do with the time periods you’re referencing, so I don’t know why you would consider decades old issues to be relevant today.

As part of the BSA, they still lobby for software patents today . The OOXML Office format they used to continue pushing Office lock-in is very recent: https://wiki.documentfoundation.org/LibreOffice_OOXML They tried their best to keep the list of their Android patents secret, so that they could not be worked around, and they abused their patent on the FAT filesystem as recently as 2012: https://www.howtogeek.com/1837…

Less propaganda that the whole "do no evil" stuff.

Windows 10 telemetry is a child's game compared how much Google and FB spy on people's lives, yet most MS haters just jump of joy to use any tech that comes out from them.

Legions of US parents just put their kids under Google surveillance getting them Chromebooks.

Re: Microsoft is creating a new Rust-based programming language for secure coding

#62
post #58

Earlier quoted context omitted.

Big companies are not autonomous and do not make their own decisions, individual people working at those companies do. I think it’s safe to say that anyone working there today has nothing to do with the time periods you’re referencing, so I don’t know why you would consider decades old issues to be relevant today.

As part of the BSA, they still lobby for software patents today . The OOXML Office format they used to continue pushing Office lock-in is very recent: https://wiki.documentfoundation.org/LibreOffice_OOXML They tried their best to keep the list of their Android patents secret, so that they could not be worked around, and they abused their patent on the FAT filesystem as recently as 2012: https://www.howtogeek.com/1837…

https://azure.microsoft.com/en-us/blog/microsoft-joins-open-...

Re: Microsoft is creating a new Rust-based programming language for secure coding

#63
post #55

Earlier quoted context omitted.

So how does a process boundary protect against Heartbleed?

Process boundaries help you when you start jumping through a ROP chain that spawns a shell because your process doesn't have access to things that it shouldn't, even when compromised. Calling Heartbleed an example of a process "changing its behavior" doesn't really make sense in the context of exploits that can cause arbitrary code execution.

You don't have to spawn a shell as a seperate process. Injecting and executing code inside a vulnerable process has been done for a long time.

Re: Microsoft is creating a new Rust-based programming language for secure coding

#64
post #46
post #45

Earlier quoted context omitted.

Having rust as the only low level language with ownership concept isn't ideal either.

Sure, it's just that right now it's trying to bootstrap that category in the first place

I understand the frustration but this is from Microsoft Research. There is a long way before they validate the concept (or not).

If you're looking for a memory-safe language today or in the next couple of years, I don't think anybody will ditch Rust for Verona.

Re: Microsoft is creating a new Rust-based programming language for secure coding

#65
post #63

Earlier quoted context omitted.

Process boundaries help you when you start jumping through a ROP chain that spawns a shell because your process doesn't have access to things that it shouldn't, even when compromised. Calling Heartbleed an example of a process "changing its behavior" doesn't really make sense in the context of exploits that can cause arbitrary code execution.

You don't have to spawn a shell as a seperate process. Injecting and executing code inside a vulnerable process has been done for a long time.

A shell spawned in an unprivileged process is not very useful.

Re: Microsoft is creating a new Rust-based programming language for secure coding

#66
post #49
post #42

Earlier quoted context omitted.

As a big proponent of F# it annoys me how much one still needs to fight "but M$" arguments if I point out a thing that F# does well. The same thing seems to happen when discussing Haskell with people who know just enough to recognise the influence MSR employees have on it. It almost makes me wonder how they/we can work around that sentiment now. Either hope for generational shift to eventually kill it, or perhaps hav…

“Fool me once, shame on you. Fool me twice, shame on me” I try to be objective as much as possible, but having witnessed almost all of Microsoft’s behavior through history, we have been fooled 100s if not 1000s of times. How many times do you let the fox back into the hen house? The only thing I think when I read recent “Microsoft is so great” comments is that the person is either too young to have any real knowledge…

All those people who worked at Microsoft in the 90's and 2000's now work for at hundreds of other companies throughout the industry. And a whole bunch of people who weren't even born in those times now work for Microsoft.

I don't think your opinion is objective at all. It's based on treating a collective as a single mind.

Re: Microsoft is creating a new Rust-based programming language for secure coding

#67
post #46

Earlier quoted context omitted.

Sure, it's just that right now it's trying to bootstrap that category in the first place

I understand the frustration but this is from Microsoft Research. There is a long way before they validate the concept (or not). If you're looking for a memory-safe language today or in the next couple of years, I don't think anybody will ditch Rust for Verona.

Fair enough

Re: Microsoft is creating a new Rust-based programming language for secure coding

#68
post #42
post #22

For the hating Microsoft crowd, here are the projects where they are also using Rust, https://msrc-blog.microsoft.com/?s=rust And the talks done about the internal adoption, https://www.youtube.com/watch?v=qCB19DRw_60 https://www.youtube.com/watch?v=o01QmYVluSw And the author from C++/WinRT is now working on Rust/WinRT. https://kennykerr.ca/2019/11/05/rust/ So lets wait a bit before going to the castle with the pitch…

As a big proponent of F# it annoys me how much one still needs to fight "but M$" arguments if I point out a thing that F# does well. The same thing seems to happen when discussing Haskell with people who know just enough to recognise the influence MSR employees have on it. It almost makes me wonder how they/we can work around that sentiment now. Either hope for generational shift to eventually kill it, or perhaps hav…

My only beef right now with Microsoft is their insistence on having creepy telemetry in everything. As someone _very_ interested in F#, I encountered this recently with both Visual Studio Code and .NET Core.

https://github.com/dotnet/cli/issues/3093

Re: Microsoft is creating a new Rust-based programming language for secure coding

#69
post #49
post #42

Earlier quoted context omitted.

As a big proponent of F# it annoys me how much one still needs to fight "but M$" arguments if I point out a thing that F# does well. The same thing seems to happen when discussing Haskell with people who know just enough to recognise the influence MSR employees have on it. It almost makes me wonder how they/we can work around that sentiment now. Either hope for generational shift to eventually kill it, or perhaps hav…

“Fool me once, shame on you. Fool me twice, shame on me” I try to be objective as much as possible, but having witnessed almost all of Microsoft’s behavior through history, we have been fooled 100s if not 1000s of times. How many times do you let the fox back into the hen house? The only thing I think when I read recent “Microsoft is so great” comments is that the person is either too young to have any real knowledge…

Name me any other big company with great ethics and all nice and fluffy. For example look at how Google had started and what it has become.

Not really trying to protect Microsoft here but them companies are all the same, just different degree of "success".

Re: Microsoft is creating a new Rust-based programming language for secure coding

#70
post #42
post #22

For the hating Microsoft crowd, here are the projects where they are also using Rust, https://msrc-blog.microsoft.com/?s=rust And the talks done about the internal adoption, https://www.youtube.com/watch?v=qCB19DRw_60 https://www.youtube.com/watch?v=o01QmYVluSw And the author from C++/WinRT is now working on Rust/WinRT. https://kennykerr.ca/2019/11/05/rust/ So lets wait a bit before going to the castle with the pitch…

As a big proponent of F# it annoys me how much one still needs to fight "but M$" arguments if I point out a thing that F# does well. The same thing seems to happen when discussing Haskell with people who know just enough to recognise the influence MSR employees have on it. It almost makes me wonder how they/we can work around that sentiment now. Either hope for generational shift to eventually kill it, or perhaps hav…

Microsoft is actively collecting billions of dollars by patent suing (or threatening to) Android providers despite contributing nothing to Android. That's what kind of company they are. They also make some great stuff, esp MS Research. I'm hesitant to use anything made by a company that patent trolls other companies, though. I don't feel safe in long term.
Post reply on HN