Live data from Hacker News

Parallel Python or Ruby?

news.ycombinator.com

11–20 of 21 posts

Re: Parallel Python or Ruby?

#12
post #7
post #5

Earlier quoted context omitted.

I'm not a Ruby fan, but wouldn't finding those buffer overflows make it more secure ? Now that they've been found, they're fixed. (Sure, it could be indicative of overall careless design, but I don't think that's the case here. A few silly mistakes, now no longer a problem.) Finally, Ruby has more than one implementation. Finding a hole in one implementation says nothing about the language overall.

The mistakes are so amateurish that it should raise questions about the rest of the codebase (i.e. the defects which are yet to be found)...

should raise questions about the rest of the codebase (i.e. the defects which are yet to be found)

It has.

Re: Parallel Python or Ruby?

#13
post #11

Hello randomhack, Have you heard of Stackless Python? That might be what you are looking for. http://www.stackless.com/

I have read a bit about stackless. Neat implementation but it still suffers from GIL? You can launch thousands of microthreads but apparently they still run on single core?

Re: Parallel Python or Ruby?

#16
post #4

Haven't you heard about the egregious buffer overflow vulnerabilities found recently in Ruby? Not a good idea to use it for anything serious in light of those, IMO.

Haven't you heard about JF's talk at PH-Neutral and the memory corruption vulns they found in Python and Perl? Not a good idea to use those for anything serious either. I guess we're all stuck with Erlang.

Re: Parallel Python or Ruby?

#17
post #7

Earlier quoted context omitted.

The mistakes are so amateurish that it should raise questions about the rest of the codebase (i.e. the defects which are yet to be found)...

should raise questions about the rest of the codebase (i.e. the defects which are yet to be found) It has.

By who? Cite someone who matters.

Re: Parallel Python or Ruby?

#18
post #5
post #4

Haven't you heard about the egregious buffer overflow vulnerabilities found recently in Ruby? Not a good idea to use it for anything serious in light of those, IMO.

I'm not a Ruby fan, but wouldn't finding those buffer overflows make it more secure ? Now that they've been found, they're fixed. (Sure, it could be indicative of overall careless design, but I don't think that's the case here. A few silly mistakes, now no longer a problem.) Finally, Ruby has more than one implementation. Finding a hole in one implementation says nothing about the language overall.

Yes. Everyone else: find a large C codebase that has shipped without an integer overflow. Go ahead. I'm waiting.

Re: Parallel Python or Ruby?

#19
post #18
post #5

Earlier quoted context omitted.

I'm not a Ruby fan, but wouldn't finding those buffer overflows make it more secure ? Now that they've been found, they're fixed. (Sure, it could be indicative of overall careless design, but I don't think that's the case here. A few silly mistakes, now no longer a problem.) Finally, Ruby has more than one implementation. Finding a hole in one implementation says nothing about the language overall.

Yes. Everyone else: find a large C codebase that has shipped without an integer overflow. Go ahead. I'm waiting.

Want some help? Don't bother with qmail. Daniel J. Bernstein managed to ship a version of qmail with an integer overflow.

(That's the only vulnerability ever found in qmail, and it wasn't exploitable --- Postfix has had much worse).

Re: Parallel Python or Ruby?

#20
post #19
post #18

Earlier quoted context omitted.

Yes. Everyone else: find a large C codebase that has shipped without an integer overflow. Go ahead. I'm waiting.

Want some help? Don't bother with qmail. Daniel J. Bernstein managed to ship a version of qmail with an integer overflow. (That's the only vulnerability ever found in qmail, and it wasn't exploitable --- Postfix has had much worse).

Too bad the original qmail is nearly useless these days. (I had a class with DJB in college, and used qmail for quite a while. Eventually I got overrun with spam and switched to something that would reject messages immediately after virus/spam scanning them.)

The point is that writing simple software in C is possible. But writing complex software is very very hard.

Post reply on HN