Toward Unseating the Unsafe C Programming Language

Paul C. van Oorschot · IEEE Security & Privacy · 2021

Reflecting on content that I taught in a recent security course about software-based vulnerabilities, I wondered: Am I giving too much focus to the C programming language? C-based examples get straight to the point, allowing compact illustrations of the concepts underlying stack-and heap-based buffer overruns and return-oriented programming, aside from integer-based vulnerabilities, related to arithmetic underflow, conversions between signed and unsigned values, and errors due to the compiler promotion of short-integer data types in arithmetic expressions.1 But are these relevant for today's students, given the wide availability of modern languages with strong language safety properties? Unfortunately, the answer is still yes.

Read the paper · More papers on PaperTik