Toward Unseating the Unsafe C Programming Language
Paul C. van Oorschot · IEEE Security & Privacy · 2021
Reflecting on content that I taught in a recent security course about software-based vulnerabilities, I wondered: Am I giving too much focus to the C programming language? C-based examples get straight to the point, allowing compact illustrations of the concepts underlying stack-and heap-based buffer overruns and return-oriented programming, aside from integer-based vulnerabilities, related to arithmetic underflow, conversions between signed and unsigned values, and errors due to the compiler promotion of short-integer data types in arithmetic expressions.1 But are these relevant for today's students, given the wide availability of modern languages with strong language safety properties? Unfortunately, the answer is still yes.