Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Oh I'm sure bad acting does occur. That is not the question at hand.

The question at hand is: Is a recommendation to use memory-safe programming languages evidence that those languages are less safe than we previously thought?

There are two competing notions:

A. This being announced now is evidence that the NSA has recently succeeded in finding a way to subvert the security guarantees of rust.

B. This being announced now is evidence that the good actors (or actors who want to appear good) in the NSA have finally gotten through the red tape to do what is nominally their jobs.



And to be able to discern between the two possibilities, you just have to ask yourself the question: has specific NSA technology recommendation consistently been provided in our best interest?

Their track record is spotty at best, and has only gotten worse over time. So to the extent that they are recommending using memory safe languages, that's great...it's advice that would be corroborated by other institutions, researchers, and practitioners. But the moment they recommend a specific set of technologies to use, that should give you pause.

That being said, the report doesn't specifically recommend just those specific languages, and merely provides them as examples...so as long as I'm not in charge of securing an adversarial nation/state's infrastructure, I'm not gonna worry about the potential nefariousness of this recommendation.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: