Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When most code is Objective-C it hardly matters anyway.


Plenty of mobile code, especially at large companies like this, rely on a ton of C code. It makes it easier to support features on both Android and iOS. I’m sure there are more benefits I’m not aware of.


Benefits that security researchers appreciate as job security.


You only need a bug in a single line of code of your dependency to compromise the whole app. Most of the code doesn’t matter for security.


The usual argument that safer languages are needless, because bugs happen anyway, yet Apple is going Swift, and adopting hardware mitigations to fix these kind of issues.


Hardware mitigations which you can’t use?


I'm pretty sure they're talking about things like PAC, which are are definitely available to apps (and I think even required?).


Not for third party apps, the ABI is not stable yet.


Regardless of the actual usage surface, its need is seen as relevant enough for Apple management to release the necessary budget to spend in engineering to make it happen across the whole stack.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: