#MemorySafety

2026-01-30

WhatsApp migrated 160,000 lines of C++ to Rust to eliminate memory-safety bugs. Here’s how compiler-level security changed its threat model.

More details here: ostechnix.com/why-whatsapp-mig

#Whatsapp #Rust #C++ #Meta #MemorySafety #Security

2026-01-27

"Rust is much more type safe than C is. And so if you have a void pointer, what does that mean in Rust? There's no translation for it. And that's how TrapC is fundamentally different because it actually remembers what that void pointer actually is."

#programming #MemorySafety

theregister.com/2026/01/26/tra

N-gated Hacker Newsngate
2026-01-04

Oh, joy! 🎉 Another ode to the almighty null pointer, where we learn that catching them is as easy as catching a cold in winter 🌨️. But wait, the "Billion Dollar Mistake" is just a misunderstood little rascal 🙄, because, really, who needs memory safety when you have "individualelement mindsets" to blame? 😂👨‍💻
gingerbill.org/article/2026/01

N-gated Hacker Newsngate
2026-01-01

Ah yes, the age-old quest for a Rust paradise without the meddling borrow checker—because clearly, who needs memory safety when you can live on the edge? 😂🔪 Why bother with the pesky details of secure coding when you can just throw caution to the wind and your way through software development? 🙈💻
github.com/buyukakyuz/rustmm

2025-12-29

This week on #OpenSourceSecurity I chat with @djc and @ctz about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety

opensourcesecurity.io/2025/202

#TLS #Rustls #Rust #MemorySafety

N-gated Hacker Newsngate
2025-12-17

Oh no! 🙈 The invincible code has been dethroned by a pesky in the Linux Kernel. 🚨 Guess the "memory-safe" bragging rights were too good to be true! 😂
phoronix.com/news/First-Linux-

Trifecta Tech Foundationtrifectatech@fosstodon.org
2025-12-17

The joint statement “Improving Europe's cybersecurity posture through memory safety”, has now been published: trifectatech.org/blog/calling-

It calls for stronger #MemorySafety incentives in EU cybersecurity policies.

It is endorsed by industry leaders like Infineon Technologies, and industry and academic experts, including experts from Signify, Volvo Cars, Radboud University and Delft University of Technology.

We look forward to presenting it to national and EU policymakers in 2026.

#security

2025-11-27

Are you using std::ranges in your C++ code? If not, what is stopping you?

Ranges introduced a huge paradigm shift in the way we can write our C++ code. They can make the code way shorter, way better separated, and what's best - way more resilient to both logical and memory-related bugs. 🐞

If you haven't yet dabbled in ranges yourself, I've prepared a kind of cheatsheet reference article exploring many everyday use cases and how they can be improved by using the std::ranges library. 📏

You can read the article for free on my Medium:
medium.com/@nerudaj/you-need-t

What are your experiences with this library? Tell me in the comments 👇

#cpp #softwareengineering #memorysafety #cpp23

2025-11-26

"#Exclaves land in MacOS

Nobody is really surprised that the MacOS 26.0.1 firmware image of the about to be released MacBook Pro #M5 reveals that Memory Integrity Enforcement (#MIE) on top of the ARM64 Enhanced Memory Tagging Extension (#EMTE) is used. Extremely surprising is however that Apple is now shipping the Secure Kernel (#SK) and #ExclaveCore / #ExclaveOS with MacOS. This means Apple's newest security boundary #Exclaves has finally arrived in MacOS."

linkedin.com/posts/stefan-esse

#MTE #MemorySafety #ExploitMitigation

a linkedin post stating: "#Exclaves land in MacOS

Nobody is really surprised that the MacOS 26.0.1 firmware image of the about to be released MacBook Pro #M5 reveals that Memory Integrity Enforcement (#MIE) on top of the ARM64 Enhanced Memory Tagging Extension (#EMTE) is used. Extremely surprising is however that Apple is now shipping the Secure Kernel (#SK) and #ExclaveCore / #ExclaveOS with MacOS. This means Apple's newest security boundary #Exclaves has finally arrived in MacOS. This release perfectly coincides with our upcoming Deep dive into #SPTM, #TXM, #SK and #Exclaves training course in December."
रञ्जित (Ranjit Mathew)rmathew
2025-11-23

The article is too verbose & the discussions flame out, but some good references in both:

“Memory Safety For Skeptics”, ACM Queue (queue.acm.org/detail.cfm?id=37).

Via HN: news.ycombinator.com/item?id=4

On Lobsters: lobste.rs/s/mytmnl/memory_safe

Paolo Fabio Zaino ☮️🌍💻🎸🎮☕️🍩🍕DarkL0rd@mastodon.online
2025-11-22

💻 Weekend project: I finally got time to update the #MerlinOS presentation with the newest features.

Highlights:

* Source level debugging for ROM and flash images in MS VSCode
* UART debugging features that support source symbols, showing the module and line number in the source that triggered a panic
👇
paolozaino.wordpress.com/portf
#OperatingSystem #KernelDevelopment #SystemsProgramming #EmbeddedSystems #MemorySafety #FormalVerification #OpenSource #SoftwareEngineering #LowLevelProgramming

Luís de Sousaluis_de_sousa
2025-11-20

" has disclosed that the company's continued adoption of the programming language in has resulted in the number of memory safety vulnerabilities falling below 20% of total vulnerabilities for the first time."

thehackernews.com/2025/11/rust

2025-11-17

Rust continues to reshape Android’s security posture.

Google reports memory-safety bugs are now under 20%, backed by:
• 1000× reduction in memory-safety bug density vs C/C++
• 4× fewer rollbacks
• Faster reviews + fewer revisions
• Rust moving deeper into kernel, firmware & Android’s security-sensitive apps
A recent “near-miss” RCE (CVE-2025-48530) in unsafe Rust was mitigated by Scudo before reaching public release.

Thoughts from the AppSec community?
Follow @technadu for more unbiased cybersecurity reporting.

#RustLang #MemorySafety #AndroidSecurity #AppSec #InfoSec #DevSecOps #SecureCoding #TechNadu

rust adoption android
रञ्जित (Ranjit Mathew)rmathew
2025-11-12

Very impressive:

“InvisiCaps: The Fil-C Capability Model”, Filip Pizlo (fil-c.org/invisicaps).

See Also: “Fil's Unbelievable Garbage Collector”, Filip Pizlo (fil-c.org/fugc).

N-gated Hacker Newsngate
2025-11-10

🧠💥 "Memory Safety for Skeptics" is here to convince you that worrying about your software's memory safety is just as thrilling as watching paint dry. 🎨😴 Despite being hailed as the knight in shining armor for this cause, it's really just a hipster language trying to make buffer overflows feel passé. 🛡️📉
queue.acm.org/detail.cfm?id=37

N-gated Hacker Newsngate
2025-11-07

Ah, the mesmerizing world of FilC—a groundbreaking addition that promises to make your coding life safer than a padded room. 🤦‍♂️ Because, of course, what every developer dreams of is yet another layer of memory safety bureaucracy to babysit their already flawless code. 🎉
graydon2.dreamwidth.org/320265

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst