11 ms·
"No way to prevent this" say users of only language where this regularly happens
- KaiserPro 2y agoNeeds more furries.
- blueflow 2y agoYeah, was about to note that the link is unexpectedly SFW.
- darkwater 2y agoWhy? Furries are NSFW because they look cartoonish and "unprofessional"? I don't like them but what a boring workplace would that be.
- xena 2y agoThey're being satirical. People usually berate my posts because I have cartoon characters for Socratic exchanges to teach people things like Kubernetes, claiming that is "unprofessional" or something. These people are sarcastically berating my post for NOT using that Socratic system.
- darkwater 2y agoIMO GGP wasn't being sarcastic, but GP maybe was. Anyway I keep my thought: if a workplace, especially if in Tech or Tech-adjacent, sees furries as NSFW, it's a very boring workplace and I would run away from it at the first possibility.
- blueflow 2y agoNo I'm not. I expected that there is some furry or anime girl visible when i click on that link. This is the stuff i do not want to have on my screen when there are coworkers nearby.
- xena 2y agoHave this: https://xeiaso.net/notes/2024/ai-hype/ https://xeiaso.net/notes/2024/ai-hype/
- blueflow 2y agoBismuth crystals are less edgy.
- selfmodruntime 2y agoI also used to think I had this issue when reading your blogs at work. Turns out, nobody really cares and if they do, a quick explanation suffices entirely. I no longer care as well. Your imagery is part of who you are as a writer, and it's part of your work. People need to take it or leave it.
- llm_trw 2y agoIt's gross because I don't want to think about your sex life when at work, but I guess this type of exhibitionism is fine.
- Zecc 2y agoWhy did you jump from 'cartoon characters having Socratic conversations' to 'sex life'? Good grief.
- llm_trw 2y agoBecause those cartoon characters always look like the fursuits of the person writing the article.
- subjectsigma 2y agoBeing a furry is and always has been a sex thing for the majority of the fandom. Some furries will vehemently deny this but we have receipts going all the way back to the 1970’s: https://en.wikifur.com/wiki/Vootie https://en.wikifur.com/wiki/Vootie Anime is not inherently sexual as a medium but has a well-deserved reputation for being associated with creeps and perverts. Don’t talk about either in professional settings.
- KaiserPro 2y ago> Being a furry is and always has been a sex thing I mean you could argue that about Emos, or Goths. Its not really true. I'm sure sex is a large motivator, but you can't be doing sex all the time. When a Goth is dressed up all Goth-y its not because they are horny right now. They are just wanting to look good. I imagine its the same with the furries, but the difference is, the furries are the butt of most jokes
- subjectsigma 2y agoYou can’t just say “No, you’re wrong.” And expect me to change my mind?? Both being a goth and being a furry are about way more than clothing and appearance. Goths don’t really have anything to do with furries. I don’t know why you’re bringing them up. Every furry I have met in real life thought it was a sex thing. Every normal person from the outside looking in thinks it’s a sex thing. Just look at the history of furry magazines and subculture and it is mind-numbingly obvious that it is a sex thing. Even if it wasn’t a sex thing, would you want to discuss it at work knowing 99% of people will think of it that way?
- KaiserPro 2y agoNo No No, I genuinely love both your Socratic exchanges and the furries characters that illustrate them. (although this is article is firmly Aristophanes, again, top notch work) I don't hold with the "I'm not going to open a link on HN from Xe at work" bollocks, because I know its going to be a gem, moreover, I'm not a fucking prude. If one can, at work, open the daily mail, "listen" to music videos, or read celeb gossip sites at work, then you can 100% look at computer using anthropomorphic animals. Plus ever since I read your article about abusing S3 into a message queue, I've started using 18th century engravings of gargoyles, statues and classic sculpture to aid my presentations. In summary, I love you work, I wish you to continue making it, and please don't take my comment as sarcastic. As I said before many months ago, this is what the internet was designed for, long may it continue.
- mjevans 2y agoThe headline is misleadingly focusing on a soundbite out of the full quote. "It's a shame, but what can we do? There really isn't anything we can do to prevent memory safety vulnerabilities from happening if the programmer doesn't want to write their code in a robust manner." -- Some (uncredited?) C programmer. Does C have more footguns as a low level language? Of course. That's part of the freedom of bringing only the baggage a project needs. Sadly, like many dangerous or sharp tools, incorrect use will lead to harms. If someone has a choice, a safer more modern language can accommodate less skilled practitioners.
- benjaminl 2y agoThe story is satire. But the satire is illustrating true problems and attitudes.
- voidUpdate 2y agohttps://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_Says_Only_Nation_Where_This_Regularly_Happens https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_...
- croes 2y agoA safer language accommodates every programmer. Nobody writes flawless code.
- tialaramex 2y agoIt's a deliberate echo of the famous Onion headline about America's absolutely disgraceful pretence that it couldn't do anything about all the shootings. https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_Says_Only_Nation_Where_This_Regularly_Happens https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_... > If someone has a choice, a safer more modern language can accommodate less skilled practitioners. This is the usual mistake. It's not a "skill issue". Footguns are a design mistake, they're much more dangerous than necessary hence the name. As a result the practitioners accomodated by a better language are all those capable of mistake ie all humans.
- 2y ago
- fnordian_slip 2y agoJust in case someone needs the reference, the onion uses '"no way to prevent this" says only nation where this regularly happens' as a reoccurring article at every major school shooting[0], to highlight the frequency of such events and the fact that nothing has really changed since the last one. [0] https://www.theonion.com/no-way-to-prevent-this-says-only-nation-where-this-r-1848971668 https://www.theonion.com/no-way-to-prevent-this-says-only-na...
- voidUpdate 2y agoThis is also an ongoing series on that blog, if you look at previous entries there's lots with the same title, also about C having buffer overflows
- xena 2y agohttps://xeiaso.net/shitposts/no-way-to-prevent-this/ https://xeiaso.net/shitposts/no-way-to-prevent-this/ Generated by exactly 69 lines of Go every time: https://github.com/Xe/site/blob/main/cmd/no-way-to-prevent-this/main.go https://github.com/Xe/site/blob/main/cmd/no-way-to-prevent-t...
- TeMPOraL 2y agoKudos for faithfully reproducing the joke then.
- xena 2y agoThanks, I've had thoughts about making it a bit more elaborate (possibly involving large language models somehow to help synthesize what's going on into the right format, and so that it's not literally the same thing every time), but there's a charm in making it literally the same thing every time with the details swapped out. It points out the repetition to the level that all you need to do is swap out the details next time. This is all so preventable, but sometimes these things just happen and there's not anything anyone can do about them.
- 2y ago
- cookiengineer 2y agoAlternative headline should be "But I have been taught that using C++ makes me the better programmer" because the stereotypes of echo chambers on the internet raised a lot of unreflected programmers to be this way. There is a place for C, where there's no alternative. But that place is where 99% of programmers never work, because they are not doing kernel nor firmware development (which, in the meantime, also has a lot of support by and for memory safe VMs and languages). The issue I have with this narcisstic fatigue (similar to the author's point I assume) is that there is no reflection when they fuck up a codebase. The best code is the code that is safe and easy to read, and doesn't need to use "clever tricks" that beginners cannot understand. If you are using some tricks for type casting to implement your ideas into code, you probably should not write code. Code should be dumb and easily maintainable. If it is not, you made the wrong choice for the programming language.
- yetihehe 2y ago> Code should be dumb and easily maintainable. We now have enough resources to do this. When C was created, we had to do those tricks to have good performance. Currently C is best used for constrained devices, where sometimes you need those tricks. > If it is not, you, yes ... you, made the wrong choice for the programming language. Or your project manager or CTO, or some other stakeholder.
- phoe-krk 2y ago> There is a place for C, where there's no alternative. Alternatives to C have started appearing for a long while, and they are quite mature now. > because they are not doing kernel development FluentBit, where this error occurred, is a userspace application. > there is no reflection when they fuck up a codebase C does not support runtime reflection, that is correct. It's one of the reasons why it's a programming and debugging nightmare. > If you are using some tricks for type casting to implement your ideas into code There seem to be no casting issues involved in https://www.tenable.com/security/research/tra-2024-17 https://www.tenable.com/security/research/tra-2024-17. > The best code is the code that is safe and easy to read, and doesn't need to use "clever tricks" that beginners cannot understand. It's just a pile of truisms. Is your whole post even related to this article?
- davedx 2y agoThoughts and prayers
- isoprophlex 2y agoMaybe C programmers need some more thoughts and prayers at deployment time?
- devjab 2y agoYou obviously need to perform the correct rites and pay your homage to the blessed machine spirit or the Omnissiah will not permit your code to compile.
- ramon156 2y agoWe can learn a lot from terry davis
- bigiain 2y agoBut the 2nd amendment guarantees their right to insecure code!
- Beretta_Vexee 2y agoNo, the only way to stop a bad dev with a strcpy() is a good dev with a strcpy().
- isoprophlex 2y agoC doesn't overflow and spill your memory contents, your RAM modules do!
- snovv_crash 2y agoBasically fuzzing then?
- nomilk 2y agoMore broadly: > "No way to prevent $THIS" say users of only language where $THIS regularly happens A weird psychological quirk I've noticed (of myself, and others) is we'll often exhibit a sort of 'programming language xenophobia', where we apathetically accept (or don't even notice) unpleasantries of our language of choice, yet be quite averse to the unpleasantries of other languages. Maybe it's due to sunk cost; time/effort has already been spent finding work arounds for or adapting to the warts of our native tongue, whereas doing so for unfamiliar languages would require additional effort.
- JimDabell 2y agoThere’s probably a large selection bias at work as well – people who care about those specific unpleasantries will avoid that language in the first place.
- deleted 2y ago[deleted]
- jstimpfle 2y agoNo way to prevent "this", says C++ programmer.
- from-nibly 2y agoJust use Python it uses 'self'
- jstimpfle 2y agoIn Python, you can easily just not type "self" (or whatever you named the 1st arg). In C++, you can not not type "this", at least if you don't, "this" will be looked up anyway.
- immibis 2y agosee also https://wiki.c2.com/?BlubParadox https://wiki.c2.com/?BlubParadox
- 2y ago
- diego_sandoval 2y agoI thought it was going to be about JS and npm, given some of their fiascos [1][2][3] [1] https://qz.com/646467/how-one-programmer-broke-the-internet-by-deleting-a-tiny-piece-of-code https://qz.com/646467/how-one-programmer-broke-the-internet-... [2] https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/ https://www.bleepingcomputer.com/news/security/dev-corrupts-... [3] https://www.sonatype.com/blog/everything-matters-why-the-npm-package-sparked-controversy https://www.sonatype.com/blog/everything-matters-why-the-npm...
- draw_down 2y ago[dead]
- minikomi 2y ago`this` was mostly prevented in JS with the introduction of arrow function expressions
- alternatex 2y agoI had someone on Reddit r/webdev try to convince me that 'this' was not a mistake but a powerful language feature. A small glimpse into the mind of JS fans.
- orf 2y agoIt kinda is a powerful language feature But with great power comes great responsibility, and that doesn’t mean it was a good idea in hindsight.
- _old_dude_ 2y agoYes, it's functions vs methods. You can make this explicit like in Python, you can make it implicit but have two kinds of methods, instance methods and static methods like in C++/C#/Java. And you have JavaScript were all functions have an implicit this ...
- 2y ago
- pdimitar 2y agoI've been doing programming for ~31 years in total and ~22 years professionally and at this point I have lost all hope that programmers at large will ever gain these mythic qualities called "self-reflection" and "introspection". Truth is, these people are simply afraid for their cozy jobs, that's all there is to it. Derivative states of mind like Stockholm Syndrome and Sunk Cost Fallacy are quite normal to appear in these conditions. On OP: I could not agree more. People always downplay their fuck-ups, that's sadly part of being a Homo Sapiens, but the lack of awareness is still both despairing and hilarious to watch. And finally, C/C++'s niches have decreased but these people will not adapt, of course. Almost anything I've done with those languages 15-20 years can today be done with Rust. Or if you are on a tight time budget -- Golang, and you still won't lose too much speed. But sure, "nothing can be done, these things sometimes happen". Sigh.
- Xeamek 2y agoEh, Rust would be fine if not for the fact that it's too opinionated. Unfortunately you can't just have Rust's safety checks, without opting into restrictions that Rust designers force onto You that aren't inherent to safety checks, but more because 'that's a better practice (according to us)'. And also, easy and fast iteration just isn't there, both because of borrow checker restrictions and compile times
- eterevsky 2y agoUnfortunately you have to pick 2 out of: - Lack of restrictions - Safety - Performance If you choose safety and no restriction, you pay the price in performance (for GC etc.)
- Xeamek 2y agoAgain, restrictions that are forced you for a price of safety are one thing. But what I'm complaining about are restrictions that don't have to be there to get borrowchecker working, but rather are there because designers arbitrary decided "it's better this way".
- consp 2y agoOh no ... a bug in a C program. This easy bashing on existing C programs is getting boring and annoying. Write a new userspace program? Use anything else, all language shave flaws so pick one which supports the features you need. Want to quickly write something because you are not allowed to rewrite the entire ecosystem you need into a new language since the project will go massively over budged: Use what you can and what's available and accept the risks, which is the 99th percentile of software.
- Simon_O_Rourke 2y agoPrince Marcel O'Keefe must be C royalty!
- nubinetwork 2y ago> a vulnerability in HTTP parsing code that allows for heap corruption and arbitrary code execution by making a HTTP GET request with a megabyte of the letter 'A' in its body You mean a buffer overflow? Why write so technical then dumb down something that's pretty obvious.
- SSLy 2y agobuffers are stored on heap.
- akoboldfrying 2y agoSome of the HN discussion about whether "new projects in C should be allowed" is moot: Fluent Bit was imported into git in 2015 [0] (a few months before Rust's first public release), and may be considerably older than that for all I know. I suppose incidents like this actually do give a reason to "rewrite it in Rust", when "it" is "widely deployed infrastructure written in C". OTOH, I'm sure there were plenty of non-memory-safety bugs introduced and later fixed over the years, and rewriting in Rust will recapitulate that subset of bugs. [0] https://github.com/fluent/fluent-bit/commit/49269c5ec3c74411943e362cfef85052665ae97f https://github.com/fluent/fluent-bit/commit/49269c5ec3c74411...
- nullc 2y agoPeople slipping backdoors into stuff are no doubt super enthusiastic about Rust both for the opportunity for new anonymous nobodies to rewrite long stable and proven tools as well as the dependency ecosystem that tends to blindly pull in multiple different entire HTTPS/TLS stacks into anything but the most trivial software.
- tialaramex 2y agoI don't buy it. Rust has a really good track record on attracting more people to read and modify the code, which isn't what you want if you're hiding backdoors in the code. In decades of writing C (sometimes as a hobby, often for a lot of money) I'd guess I thought "These errors when I wrote bugs in my program are crap, somebody should fix it" maybe once per month on average. But a C compiler is very intimidating code, subtle and hard to even build from scratch let alone contribute to, so I never attempted to make such changes. In only a few years of writing Rust (none of that paid) exactly twice I've thought "Man this compiler error diagnostic isn't very good, somebody should fix it". The first time I asked on Reddit, and I was informed that I wasn't the first to notice, the fixed diagnostic was in nightly Rust already. The second time I found the diagnostic and I just fixed it, compiled first time, wrote a new unit test, checked that passed, wrote a pull request. Landed it. Then I wrote a HN comment, a reader found a bug in my diagnostic, so I fixed the original code, and wrote a new PR which also landed. If Rust has told you that instead of 'X' when you needed a byte, you should write b'X' because just 'X' is a char not a byte - that's me, that's my small fix. [Before the fix 'X' wasn't legal here, of course, but the diagnostic wouldn't suggest what to write instead]
- subjectsigma 2y agoI bet this person felt really smart posting about this problem that surely nobody has ever thought of before
- web007 2y agoA) "surely nobody has ever thought of [this] before]" says person who hasn't read https://xeiaso.net/shitposts/no-way-to-prevent-this/ https://xeiaso.net/shitposts/no-way-to-prevent-this/ B) It's a spin on The Onion headline about school shootings.
- subjectsigma 2y agoA) I know, it still sounds smug and condescending B) I know, it still sounds smug and condescending
- Hock88sdx 2y ago[dead]
- mikewarot 2y agoFree Pascal and Lazarus which is a GUI built on it support strings that don't require manual allocation and are counted and reference counted. A huge amount of grief would go away if that library could be supported in the Linux kernel somehow, and all of the string parameters in system calls ported.
- 1vuio0pswjnm7 2y agoTerrible analogy. School shootings are not the result of mistakes. They are intentional acts.