Comment by Brian_K_White

2 days ago

There will always be one, so "it only takes one" is meaningless and invalid. That leaves less is better than more, and any form of less is as good as any other form of less.

This is pretty hard to argue since for example: WireGuard is a finished piece of software. It gets: no feature updates, was designed in-full before a single line of code was written and has stood the test of time. You cannot compare that to some desktop application that has a thousand features with 100's more added every year.

  • And its transition to post-quantum cryptography is going to be a migration challenge.

Some Rust programs also had RCE CVEs.

  • Some is doing heavy misrepresentation.

    Latest batch of LLM's Linux had 423 vulnerabilities. Out of which 10 were Rust*. Would you prefer more or less CVEs?

    But it's like seat belt analogy. It's a helper not a panacea.

    * Granted Rust isn't in the entire kernel yet. D