6896 shaares
Does anyone want to tell Linus Torvalds? No? I didn't think so. //
The report on Product Security Bad Practices warns software manufacturers about developing "new product lines for use in service of critical infrastructure or [national critical functions] NCFs in a memory-unsafe language (eg, C or C++) where there are readily available alternative memory-safe languages that could be used is dangerous and significantly elevates risk to national security, national economic security, and national public health and safety."
In short, don't use C or C++. Yeah, that's going to happen.
If this sounds familiar, it's because CISA has been preaching on this point for years.