‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. daitangio · · focus · HN ↗
    We need to be prepared to write less software, with a smaller attack surface. Less is more.

    Bloated code is the critical problem. Once upon a time, I read C function

    > char gets(char str);

    is the first buffer overflow entry point, because it does not check the size of the destination buffer.

    Sadly we cannot remove it from standard-C yet AFAI Know.

    The success of Rust versus other languages is its secure-by-compile-time promise.

    Also a lean java could help, but Java is so verbose/slow to start it bumps you away.

    1. nazgulsenpai · · focus · HN ↗
      obligatory <a href="https:&#x2F;&#x2F;github.com&#x2F;kelseyhightower&#x2F;nocode" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;kelseyhightower&#x2F;nocode
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.