City
Epaper

US NSA tells developers to shun C and C++ programming language

By IANS | Updated: November 12, 2022 17:00 IST

San Francisco, Nov 12 The US National Security Agency (NSA) has requested developers worldwide to shun old programming ...

Open in App

San Francisco, Nov 12 The US National Security Agency (NSA) has requested developers worldwide to shun old programming languages like C and C++ which are more prone to hackers to shift to new, memory safe languages.

Microsoft, Google and others have flagged vulnerabilities in codes due to memory safety issues and malicious cyber actors can exploit these vulnerabilities for remote code execution or other adverse effects, which can often compromise a device and be the first step in large-scale network intrusions.

"NSA advises organisations to consider making a strategic shift from programming languages that provide little or no inherent memory protection, such as C/C++, to a memory safe language when possible. Some examples of memory safe languages are C#, Go, Java, Ruby, and Swift," the agency said in a new document.

Commonly used languages, such as C and C++, provide a lot of freedom and flexibility in memory management while relying heavily on the programmer to perform the needed checks on memory references.

Simple mistakes can lead to exploitable memory-based vulnerabilities.

"Software analysis tools can detect many instances of memory management issues and operating environment options can also provide some protection, but inherent protections offered by memory safe software languages can prevent or mitigate most memory management issues," said the NSA.

Even with a memory safe language, memory management is not entirely memory safe.

"Several mechanisms can be used to harden non-memory safe languages to make them more memory safe. Analysing the software using static and dynamic application security testing (SAST and DAST) can identify memory use issues in software," said the NSA.

"The compilation and execution environment can be used to make it more difficult for cyber actors to exploit memory management issues. Most of these added features focus on limiting where code can be executed in memory and making memory layout unpredictable," the agency suggested.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: National Security AgencyNSA
Open in App

Related Stories

InternationalUS President Donald Trump Fires NSA Chief Timothy Haugh Amid Cyber Threats

InternationalNSA Under Scrutiny After Leaked Sex Chats Expose Inappropriate Conversations on Kink and Gender Surgery

OpinionsTwo priceless gems of India!

NationalMP urination case: Pravesh Shukla's wife moves HC, challenges NSA

International7th Deputy NSA Meeting of Colombo Security Conclave held in Maldives

Technology Realted Stories

TechnologyGitHub Copilot surpasses 15 million users, India a bright spot

TechnologyIncreasing urban vegetation can save over 1.1 mn lives from heat-related deaths: Study

TechnologyStudy shows young adults not as happy as before

TechnologyGovt aims to develop northeast into India’s growth region: Jyotiraditya Scindia

TechnologyS. Korea wins $18.2 bn deal to build nuclear reactors in Czech power plant