The only difference between open-source and closed source is the fact that you KNOW about such things, mostly even before they happen, as they’re fixed right away…with closed source you’re reading silent articles like “oh yeah, btw there were NSA backdoor in M$ Windows for 20 years, now it’s fixed! ”
Despite the fact that the engineer that discovered the vulnerability is employed by M$, it is highly unlikely (I would say almost no chance) that he planned, or was in on some sort of conspiracy, to produce good PR for M$ by reporting the vulnerability. (As far as repairing M$'s reputation is concerned, this would barely register as a drop in the bucket.) In that situation, wouldn’t he tell M$ about it first for an official press release instead?
Isn’t it more plausible that maybe he thought this would look really good on his own résumé/CV?
Agreed on all points here. The Drake Equation immediately comes to mind. We all have a purpose on this world, and in this life; nothing good comes out of the nihilism that ruminates in one’s perceived insignificance within the incomprehensible vastness of the universe (for we are not gods or supernatural beings).
Hard question to answer definitively.
It’s fixed in cargo, who knows when it will be fixed downstream in distros for all packages and dependencies that have used it, perhaps all rust packages rebuilds would be necessary to be on a safe side…
And also rust devs who do this locally are on their own…also AUR…
So yeah, it’s a mess.
P.S. Also, just logically if it’s ended up in cargo, i’m sure there are a lot of chances it will also be in pypi and npm as well…coz all those language-centric package systems are vulnerable to all kinds of crap.
the world should have listened to disgraced creator Lasse in his blog of 3-29 where he basically considered that whole libizXXX-library compromised. you article was from 4-12.
Wonder why they (linux world) waited on this so long?
What kind of question is thst? Of course Rust isn’t necessary. What do you even mean by “necessary”? Computers aren’t necessary, in a certain sense.
A better, more meaningful, question is: does Rust deliver what it promises? Of course it doesn’t, it’s all just feel-good nonsense. Memory unsafety is only a serious issue when it affects the security of software. Yet software written in Rust has plenty of security issues unrelated to memory safety, mostly due to dependency bloat and cargo, which is an inherently unsafe, unsecure system.