Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Elephant in the room is that the vast majority of real-world privilege escalation and RCE is through buffer over-reads. Type errors are costing billions in damage.

Hacks like WannaCry don't exist because of the NSA, or consumers failing to update, they exist because programmers use languages that freely compile buffer over-reads in the first place.

The ugly truth is WannaCry and 90% of RCE is the fault of the programming industry for taking zero responsibility for their processes. Programmers choose to use extremely unsafe languages and it's costing the world billions in damage.

The only way we've gotten away with this is the public is largely ignorant to how culpable programmers actually are. They think hackers are demi-gods when it's really just the same damn buffer exploit over and over again.



You make some good points but it is lost in the rant.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: