Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

All that has changed but we still got the libcue code execution bug.

I could not find an open-source static analyzer (including -analyzer) that would actually pick up the flaw before someone tries to exploit it.

And that's a simple example.

We can't tame the dragon C is, empirically nobody can.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: