White House urges developers to avoid C and C++, use 'memory-safe' programming languages

The White House
(Image credit: Pexels)

Update: 2/29/2024 08:28 PT

The NSA list of memory safe programming languages has been updated to reflect v1.1 of the information sheet.

Latest Videos FromTom's Hardware
Les Pounder
Associate Editor

Les Pounder is an associate editor at Tom's Hardware. He is a creative technologist and for seven years has created projects to educate and inspire minds both young and old. He has worked with the Raspberry Pi Foundation to write and deliver their teacher training program "Picademy".

  • COLGeek
    Please focus on the technical aspects of the article and leave the political commentary for other sites. Thank you.
    Reply
  • vijosef
    Sure, come here and take undefined behavior out of my cold hands!

    union{} for the win!
    Reply
  • bigdragon
    Alternatively, you could just hire developers that are aware of and care about memory utilization. I'm aware those skills are very expensive and hard to find. They do exist in older workers.

    The market has been flooded with developers who have degrees or certifications with only a single semester of Java programming. As someone who went through an intense technical program where algorithm designs, run times, memory optimizations, sequencing, threading, and other important things were taught, it pains me to encounter people who exclusively rely on libraries/frameworks and think the compiler will fix everything for them.
    Reply
  • RichardtST
    Doesn't matter how "memory safe" the language is. With the incredulously low standard for programmers these days, they are all a threat. Plus they all have built-in back doors anyway. Everyone knows that. I'll never give up C. Malloc() and free() and I have been best buddies for decades... Stop blaming the language. It's the people that are the problem. KISS Principle rules!
    Reply
  • USAFRet
    bigdragon said:
    The market has been flooded with developers who have degrees or certifications with only a single semester of Java programming.
    I saw this 20+ years ago.

    "Certified Oracle Consultant" - totally clueless.

    This is not new.
    Reply
  • JamesJones44
    Java or any of the other VM based runtime based languages are not viable replacements for most C/C++ projects. Developers typically use C/C++ for two reasons. Resource sensitivity (speed, memory, etc.) and/or cross language interoperability. Java will not work for either of those use cases.

    Rust is the most viable alternative.
    Reply
  • 35below0
    So the US government is considered responsible and their response is to offer a recommendation?
    Sounds like a slow news day for cybersecurity, government, and conspiracy theories. That is just about as run-of-the-mill as it gets.

    It's not an attack on C/C++, more of a call to pay attention to vulnerabilities that have grown in importance enough to become national security and government business. It may provoke bickering but it is objectively a fair assesment.

    Ultimately the responsibility of government is not to enforce coding best practises, and government should never have power to do so. They most they could and should do is issue recommendations and guidelines such as this.
    Reply
  • ekio
    Only Rust is really memory safe in their list…

    A world of Rust and RISC-V based tech is coming ❤️
    Reply
  • homeyKrogerSage
    Rust. That's literally what they're saying without saying it. "Memory Safe", "Close(r) to the kernel". There's literally only one language that fits that description.
    Reply
  • Eximo
    Yeah, some of the comp sci majors I know are vastly knowledgeable. Just depends on the person's willingness to learn and what they end up doing. Also have the whole EE group who still do a lot of bare metal programming in assembly.

    As I recall with one of old acquaintances, actually had to build an OS from scratch for a project.

    I work in the public sector and we pretty much have to follow US Government security regulations. I would say any off the shelf package certified for use would need to be reviewed. Internal development is always going to be impossible to manage without proper internal processes, which may or may not be followed. So many rogue projects.
    Reply