Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Is one programming language more secure than the rest?

52 views
Skip to first unread message

Juha Nieminen

unread,
Mar 25, 2019, 6:50:22 AM3/25/19
to
https://resources.whitesourcesoftware.com/blog-whitesource/is-one-language-more-secure

I'm actually honestly surprised how low C++ ranks in the
amount-of-reported-vulnerabilities list. I would have guessed it would
have ranked much higher (perhaps even second, after C).

I love C++, but that doesn't make me blind to the ways to easily shoot
yourself in the foot with it, especially with the millions of inexperienced
C++ programmers out there. That's why I'm truly surprised how well C++
fares in that list.

--- news://freenews.netfront.net/ - complaints: ne...@netfront.net ---

Paavo Helde

unread,
Mar 25, 2019, 9:19:58 AM3/25/19
to
On 25.03.2019 12:50, Juha Nieminen wrote:
> https://resources.whitesourcesoftware.com/blog-whitesource/is-one-language-more-secure
>
> I'm actually honestly surprised how low C++ ranks in the
> amount-of-reported-vulnerabilities list. I would have guessed it would
> have ranked much higher (perhaps even second, after C).

Do not take that this report too seriously, it's basically about
advertizing their company and their tools. Apparently they have not
weighed those numbers by *anything*, so the results cannot be really
used for comparing languages, despite the click-bait headlines.

David Brown

unread,
Mar 25, 2019, 10:25:04 AM3/25/19
to
That was my thoughts. There is no scaling by project sizes or numbers.
Do the leaps in Ruby vulnerabilities come from problems with Ruby,
problems with common Ruby libraries, hoards of Ruby newbies who can't
code correctly, a high growth rate for the latest fad language, or that
there are now more security researchers who understand Ruby and are
checking these projects? This report tells us /nothing/ of use or interest.

André Luis Pereira dos Santos

unread,
Mar 26, 2019, 1:25:41 PM3/26/19
to
C and C++ are languages with a mature standard library, very well tested with decades of use.
This makes a difference in the security reports.

----------------------------------------------------------------------
André Luis Pereira dos Santos
C/C++ Development and Consultancy
www.andreconsult.tk
blog.andreconsult.tk
+55 16 98830-7133
> --- news://freenews.netfront.net/ - complaints: news@ne---

0 new messages