{"id":1502,"date":"2018-08-13T13:00:43","date_gmt":"2018-08-13T18:00:43","guid":{"rendered":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/?p=1502"},"modified":"2018-08-23T05:53:10","modified_gmt":"2018-08-23T10:53:10","slug":"security-programming-languages-issue","status":"publish","type":"post","link":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/","title":{"rendered":"Software Security is a Programming Languages Issue"},"content":{"rendered":"<p>This is the the last of three posts on the course I regularly teach, <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/class\/spring2018\/cmsc330\/\">CS 330, Organization of Programming Languages<\/a>. The first two posts covered <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/07\/24\/teaching-programming-languages\/\">programming language styles<\/a> and <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/02\/teaching-programming-languages-part-2\/\">mathematical concepts<\/a>. This post covers the last 1\/4 of the course, which focuses on software security, and related to that, the programming language <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.rust-lang.org\/\">Rust<\/a>.<\/p>\n<p>This course topic might strike you as odd: Why teach security in a programming languages course? Doesn&#8217;t it belong in, well, a <em>security<\/em> course? I believe that if we are to solve our security problems, then we must build software with security in mind right from the start. To do that, <em>all<\/em> programmers need to know something about security, not just a handful of specialists. Security vulnerabilities are both enabled and prevented by various language (mis)features, and programming (anti)patterns. As such, it makes sense to introduce these concepts in a programming (languages) course, especially one that all students must take.<\/p>\n<p>This post is broken into three parts: the need for security-minded programming, how we cover this topic in 330, and our presentation of Rust. The post came to be a bit longer than I&#8217;d anticipated; apologies!<\/p>\n<div id=\"attachment_1513\" style=\"width: 310px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1513\" class=\"size-medium wp-image-1513\" src=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720-300x200.jpg\" alt=\"Software source code\" width=\"300\" height=\"200\" srcset=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720-300x200.jpg 300w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720-768x512.jpg 768w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720.jpg 960w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-1513\" class=\"wp-caption-text\">Security is a programming (languages) concern<\/p><\/div>\n<p><!--more--><\/p>\n<h2>The Status Quo: Too Much Post-hoc Security<\/h2>\n<p>There is a lot of interest these days in securing computer systems. This interest follows from the highly publicized roll call of serious data breaches, denial of service attacks, and system hijacks. In response, security companies are proliferating, selling computerized forms of spies, firewalls, and guard towers. There is also a <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.csoonline.com\/article\/3247708\/security\/research-suggests-cybersecurity-skills-shortage-is-getting-worse.html\">regular call for more &#8220;cybersecurity professionals&#8221;<\/a> to help man the digital walls.<\/p>\n<p>It might be that these efforts are worth their collective cost, but call me skeptical. I believe that a disproportionate portion of our efforts focuses on adding security to a system <em>after it has been built<\/em>. Is your server vulnerable to attack? If so, no problem: Prop an <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/en.wikipedia.org\/wiki\/Intrusion_detection_system\">intrusion detection system<\/a> in front of it to identify and neuter network packets attempting to exploit the vulnerability. There&#8217;s no doubt that such an approach is appealing; too bad <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/en.wikipedia.org\/wiki\/Intrusion_detection_system#Limitations\">it doesn&#8217;t actually work<\/a>. As computer security experts have been saying since at least the 60s, if you want a system to actually be secure then it must be designed and built with security in mind. Waiting until the system is deployed is too late.<\/p>\n<h3>Building Security In<\/h3>\n<p>There is a mounting body of work that supports building secure systems from the outset. For example, the <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.bsimm.com\/\">Building Security In Maturity Model (BSIMM)<\/a> catalogues the processes followed by a growing list of companies to build more secure systems. Companies such as <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.synopsys.com\/software-integrity.html\">Synopsys<\/a> and <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.veracode.com\/\">Veracode<\/a>\u00a0offer code analysis products that look for security flaws. Processes such as Microsoft&#8217;s <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.microsoft.com\/en-us\/sdl\">Security Development Lifecycle<\/a> and books such as <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.garymcgraw.com\/\">Gary McGraw<\/a>&#8216;s <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.swsec.com\/\">Software Security: Building Security In<\/a>, and <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/samisaydjari.com\/\">Sami Saydjari<\/a>&#8216;s recently released <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.engineeringtrustworthysystems.com\/\">Engineering Trustworthy Systems<\/a>\u00a0identify a path toward better designed and built systems.<\/p>\n<p>These are good efforts. Nevertheless, we need even <em>more<\/em> emphasis on the &#8220;build security in&#8221; mentality so we can rely far less on necessary, but imperfect, post-hoc stuff. For this shift to happen, we need better education.<\/p>\n<h2>Security in a Programming Class<\/h2>\n<div id=\"attachment_1515\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/jumping-off-1966997_960_720.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1515\" class=\"size-medium wp-image-1515\" src=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/jumping-off-1966997_960_720-300x198.jpg\" alt=\"Running off of a cliff\" width=\"300\" height=\"198\" srcset=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/jumping-off-1966997_960_720-300x198.jpg 300w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/jumping-off-1966997_960_720-768x508.jpg 768w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/jumping-off-1966997_960_720.jpg 960w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-1515\" class=\"wp-caption-text\">Choosing performance over security<\/p><\/div>\n<p>Programming courses typically focus on how to use particular languages to solve problems efficiently. Functionality is obviously paramount, with performance an important secondary concern.<\/p>\n<p>But in today&#8217;s climate shouldn&#8217;t security be at the same level of importance as performance? If you argue that security is not important for every application, I would say the same is true of performance. Indeed the rise of slow, easy-to-use scripting languages is a testament to that. But sometimes performance is very important, or becomes so later, and the same is true of security. Indeed, many security bugs arise because code originally written for a benign setting ends up in a security-sensitive one. As such, I believe <em>educators should regularly talk about how to make code more secure<\/em> just as we regularly talk about how to make it more efficient.<\/p>\n<p>To do this requires a change in mindset. A reasonable approach, when focusing on correctness and efficiency, is to aim for code that works under expected conditions. But expected use is not good enough for security: Code must be secure under <em>all<\/em> operating conditions.<\/p>\n<p>Normal users are not going to input weirdly formatted files to to PDF viewers. But adversaries will.\u00a0As such, students need to understand how a bug in a program can be turned into a security vulnerability, and how to stop it from happening.\u00a0Our two lectures in CS 330 on security shift between illustrating a kind of security vulnerability, identifying the conditions that make that vulnerability possible, and developing a defense that eliminates those conditions. For the latter we focus on language properties (e.g., type safety) and programming patterns (e.g., validating input).<\/p>\n<h3>Security Bugs<\/h3>\n<p>In our <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/class\/spring2018\/cmsc330\/lectures\/software-security.pdf\">first lecture<\/a>, we start by introducing the high-level idea of a <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/en.wikipedia.org\/wiki\/Buffer_overflow\">buffer overflow<\/a> vulnerability, in which an input is larger than the buffer designed to hold it. We hint at how to exploit it by <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/insecure.org\/stf\/smashstack.html\">smashing the stack<\/a>. A key feature of this attack is that while the program intends for an input to be treated as data, the attacker is able to trick the program to treat it as <em>code<\/em>\u00a0which does something harmful. We also look at\u00a0<a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.owasp.org\/index.php\/Command_Injection\">command injection<\/a>, and see how it similarly manifests when an attacker tricks the program to treat data as code.<\/p>\n<div id=\"attachment_1516\" style=\"width: 310px\" class=\"wp-caption alignright\"><a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/34852913554_4c401f98ca_b.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1516\" class=\"size-medium wp-image-1516\" src=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/34852913554_4c401f98ca_b-300x220.jpg\" alt=\"SQL injection analogy to Scrabble\" width=\"300\" height=\"220\" srcset=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/34852913554_4c401f98ca_b-300x220.jpg 300w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/34852913554_4c401f98ca_b-768x564.jpg 768w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/34852913554_4c401f98ca_b.jpg 1024w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-1516\" class=\"wp-caption-text\">SQL injection: malicious code from benign parts<\/p><\/div>\n<p>Our <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/class\/spring2018\/cmsc330\/lectures\/web-security.pdf\">second lecture<\/a> covers vulnerabilities and attacks specific to web applications, including <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.owasp.org\/index.php\/SQL_Injection\">SQL injection<\/a>, <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)\">Cross-site Request Forgery (CSRF)<\/a>, and <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.owasp.org\/index.php\/Cross-site_Scripting_(XSS)\">Cross-site scripting (XSS)<\/a>. Once again, these vulnerabilities all have the attribute that untrusted data provided by an attacker can be cleverly crafted to trick a vulnerable application to treat that data as code. This code can be used to hijack the program, steal secrets, or corrupt important information.<\/p>\n<h3>Coding Defenses<\/h3>\n<p>It turns out the defense against many of these vulnerabilities is the same, at a high level:\u00a0<em>validate any untrusted input before using it<\/em>, to make sure it&#8217;s benign. We should make sure an input is not larger than the buffer allocated to hold it, so the buffer is not overrun. In any language other than C or C++, this check happens automatically (and is generally needed to ensure <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2014\/08\/05\/type-safety\/\">type safety<\/a>).<\/p>\n<p>For the other four attacks, the vulnerable application uses the attacker input when piecing together another program. For example, an application might expect user inputs to correspond to a username and password, splicing these inputs into a template SQL program with which it queries a database. But the inputs could contain SQL commands that cause the query to do something different than intended. The same is true when constructing shell commands (command injection), or Javascript and HTML programs (cross-site scripting). The defense is also the same, at a high level: user inputs need to either have potentially dangerous content removed or made inert by construction (e.g., through the use of <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/en.wikipedia.org\/wiki\/Prepared_statement\">prepared statements<\/a>).<\/p>\n<p>None of this stuff is new, of course. Most security courses talk about these topics. What is unusual is that we are talking about them in a &#8220;normal&#8221; programming languages course.<\/p>\n<p>Our <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/github.com\/anwarmamat\/cmsc330spring18-public\/tree\/master\/p6\">security project<\/a> reflects the defensive-minded orientation of the material. While security courses tend to focus on vulnerability exploitation, CS 330 focuses on <em>fixing<\/em> the bugs that make an application vulnerable. We do this by giving the students a web application, written in Ruby, with several vulnerabilities in it. Students must fix the vulnerabilities without breaking the core functionality. We test the fixes automatically by having our auto-grading system test functionality and exploitability. Several hidden tests exploit the initially present vulnerabilities.\u00a0The students must modify the application so these cases pass (meaning the vulnerability has been removed and\/or can no longer be exploited) without causing any of the functionality-based test cases to fail.<\/p>\n<h2>Low-level Control, Safely<\/h2>\n<p>The most dangerous kind of vulnerability allows an attacker to gain <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/en.wikipedia.org\/wiki\/Arbitrary_code_execution\">arbitrary code execution<\/a>\u00a0(ACE): Through exploitation, the attacker is able to execute code of their choice on the target system. Memory management errors in type-unsafe languages (C and C++) comprise a large class of ACE vulnerabilities. Use-after-free errors, double-frees, and buffer overflows are all examples. The latter is still the <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/nvd.nist.gov\/general\/visualizations\/vulnerability-visualizations\/cwe-over-time#vuln-type-total-by-year-title\">single largest category of vulnerability<\/a> today, according to <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/cwe.mitre.org\/\">MITRE&#8217;s Common Weakness Enumeration (CWE)<\/a> database.<\/p>\n<p>Programs written in type-safe languages, such as Java or Ruby,[ref]Ruby is dynamically typed, but <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2014\/08\/05\/type-safety\/\">arguably type-safe<\/a>.[\/ref] are immune to these sorts of memory errors. Writing applications in these languages would thus eliminate a large category of vulnerabilities straightaway.[ref]This is not strictly true as parts of these languages&#8217; implementations are written in C\/C++, and programs in type-safe languages can call out to C\/C++ via a foreign function interface. Even so, eliminating C\/C++ as a normal source programming language would dramatically reduce the attack surface.[\/ref] The problem is that type-safe languages&#8217; use of abstract data representations and <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/en.wikipedia.org\/wiki\/Garbage_collection_(computer_science)\">garbage collection<\/a> (GC), which make programming easier, remove low-level control and add overhead that is sometimes hard to bear. C and C++ are essentially the only game in town[ref]And even if it is not <em>needed<\/em>, <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/spectrum.ieee.org\/at-work\/innovation\/the-2018-top-programming-languages\">C\/C++ is still used quite a bit<\/a> anyway. Old habits, and legacy code, die hard.[\/ref] for operating systems, device drivers, and embedded devices (e.g., <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/en.wikipedia.org\/wiki\/Internet_of_things\">IoT<\/a>), which cannot tolerate the overhead and\/or lack of control.\u00a0And we see that these systems are regularly and increasingly under attack. What are we to do?<\/p>\n<h3>Rust: Type safety without GC<\/h3>\n<p>In 2010, the <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.mozilla.org\/\">Mozilla<\/a> corporation (which brings you Firefox) officially began an ambitious project to develop a safe language suitable for writing high-performance programs.\u00a0The result is <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/www.rust-lang.org\/\">Rust<\/a>.[ref]Rust development began in 2006, but was not officially supported by Mozilla until later.[\/ref] In Rust, type-safety ensures (with various caveats) that a program is free of memory errors and free of data races. In Rust, type safety is possible <em>without<\/em> garbage collection, which is not true of any other mainstream language.<\/p>\n<div id=\"attachment_1517\" style=\"width: 160px\" class=\"wp-caption alignright\"><a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/rust-logo.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1517\" class=\" wp-image-1517\" src=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/rust-logo-300x300.png\" alt=\"Rust language logo\" width=\"150\" height=\"150\" srcset=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/rust-logo-300x300.png 300w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/rust-logo-150x150.png 150w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/rust-logo-768x768.png 768w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/rust-logo-1024x1024.png 1024w, https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/rust-logo.png 2000w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a><p id=\"caption-attachment-1517\" class=\"wp-caption-text\">Rust, the programming language<\/p><\/div>\n<p>In CS 330, we <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/class\/spring2018\/cmsc330\/lectures\/00-rust-introduct.pdf\">introduce Rust<\/a> and its <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/class\/spring2018\/cmsc330\/lectures\/02-rust-basics.pdf\">basic constructs<\/a>, showing how Rust is arguably closer to a functional programming language than it is to C\/C++. (Rust&#8217;s use of curly braces and semi-colons might make it seem familiar to C\/C++ programmers, but there&#8217;s a whole lot more that&#8217;s different than is the same!)<\/p>\n<p>We spend much of our time talking about Rust&#8217;s use of <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/class\/spring2018\/cmsc330\/lectures\/03-ownership.pdf\"><em>ownership<\/em> and <em>lifetimes<\/em><\/a>. Ownership (aka <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/en.wikipedia.org\/wiki\/Substructural_type_system#Linear_type_systems\">linear typing<\/a>) is used to carefully track pointer aliasing, so that memory modified via one alias cannot mistakenly corrupt an invariant assumed by another. Lifetimes track the scope in which pointed-to memory is live, so that it is freed automatically, but no sooner than is safe. These features support managing memory without GC. They also support sophisticated programming patterns via <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/class\/spring2018\/cmsc330\/lectures\/\/08-smart-pointers.pdf\">smart pointers<\/a>\u00a0and <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/class\/spring2018\/cmsc330\/lectures\/05-traits.pdf\">traits<\/a> (a construct I was unfamiliar with, but now really like). We provide a <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/github.com\/anwarmamat\/cmsc330spring18-public\/tree\/master\/p5\">simple programming project<\/a> to familiarize students with the basic and advanced features of Rust.<\/p>\n<h3>Assessment<\/h3>\n<p>I enjoyed learning Rust in preparation for teaching it. I had been wanting to learn it since my <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2015\/06\/09\/interview-with-mozillas-aaron-turon\/\">interview with Aaron Turon<\/a> some years back. The <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/doc.rust-lang.org\/book\/\">Rust documentation<\/a> is first-rate, so that really helped.<\/p>\n<p>I also enjoyed seeing connections to my own prior research on the <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/cyclone.thelanguage.org\/\">Cyclone programming language<\/a>. (I recently reflected on Cyclone, and briefly connected it to Rust, in a <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/cs.anu.edu.au\/cybersec\/issisp2018\/assets\/slides\/cyclone-overview.pdf\">talk at the ISSISP&#8217;18 summer school<\/a>.) Rust&#8217;s ownership relates to Cyclone&#8217;s unique\/affine pointers, and Rust&#8217;s lifetimes relate to Cyclone&#8217;s regions. Rust&#8217;s smart pointers match patterns we also implemented in Cyclone, e.g., for reference counted pointers. Rust has taken these ideas much further, e.g., a really cool integration with traits handles tricky aspects of polymorphism. The Rust compiler&#8217;s error messages are also really impressive!<\/p>\n<p>A big challenge in Cyclone was finding a way to program with unique pointers without tearing your hair out. My impression is that Rust\u00a0programmers face the same challenge (as long as you don&#8217;t resort to frequent use of <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/doc.rust-lang.org\/book\/second-edition\/ch19-01-unsafe-rust.html\"><strong>unsafe<\/strong> blocks<\/a>). Nevertheless, <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/insights.stackoverflow.com\/survey\/2018\/#technology\">Rust is a much-loved programming language<\/a>, so the language designers are clearly doing something right! Oftentimes facility is a matter of comfort, and comfort is a matter of education and experience. As such, I think Rust fits into the philosophy of CS 330, which aims to introduce new language concepts that are interesting in and of themselves, and may yet have expanded future relevance.<\/p>\n<h2>Conclusions<\/h2>\n<p>We must <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2015\/09\/30\/penetrate-and-patch-to-building-security-in\/\">build software with security in mind from the start<\/a>. Educating all future programmers about security is an important step toward increasing the security mindset. In CS 330 we illustrate common vulnerability classes and how they can be defended against by the language (e.g., by using those languages, like Rust, that are type safe) and programming patterns (e.g., by validating untrusted input). By doing so, we are hopefully making our students more fully cognizant of the task\u00a0that awaits them in their future software development jobs. We might also interest them to learn more about security in a subsequent security class.<\/p>\n<p>In writing this post, I realize we could do more to illustrate how type abstraction can help with security. For example, abstract types can be used to increase assurance that input data is properly validated, as explained by <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/secdev.ieee.org\/2017\/keynote\/\">Google&#8217;s Christoph Kern in his 2017 SecDev Keynote<\/a>. This fact is also a consequence of <em>semantic<\/em> type safety, as argued well by <a href=\"https:\/\/fd.xuwubk.eu.org:443\/https\/popl18.sigplan.org\/event\/popl-2018-papers-keynote-milner-lecture\">Derek Dreyer in his POPL&#8217;18 Keynote<\/a>. Good stuff to do for Spring&#8217;19 !<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is the the last of three posts on the course I regularly teach, CS 330, Organization of Programming Languages. The first two posts covered programming language styles and mathematical concepts. This post covers the last 1\/4 of the course, &hellip; <a href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"Software Security is a Programming Languages Issue","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[12,3,31],"tags":[179,182,181,180],"class_list":["post-1502","post","type-post","status-publish","format-standard","hentry","category-education","category-softsec","category-types","tag-rust-language","tag-secure-coding","tag-type-safety","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/fd.xuwubk.eu.org:443\/https\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Software Security is a Programming Languages Issue - The PL Enthusiast<\/title>\n<meta name=\"description\" content=\"Software security must be addressed by all programmers, not just security experts. So we teach it in CS 330, a programming (languages) class.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Software Security is a Programming Languages Issue - The PL Enthusiast\" \/>\n<meta property=\"og:description\" content=\"Software security must be addressed by all programmers, not just security experts. So we teach it in CS 330, a programming (languages) class.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/\" \/>\n<meta property=\"og:site_name\" content=\"The Programming Languages Enthusiast\" \/>\n<meta property=\"article:published_time\" content=\"2018-08-13T18:00:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-08-23T10:53:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720-300x200.jpg\" \/>\n<meta name=\"author\" content=\"Michael Hicks\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Michael Hicks\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/#article\",\"isPartOf\":{\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/\"},\"author\":{\"name\":\"Michael Hicks\",\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/#\\\/schema\\\/person\\\/7d875a015cb2e83e9cd476df91028d5d\"},\"headline\":\"Software Security is a Programming Languages Issue\",\"datePublished\":\"2018-08-13T18:00:43+00:00\",\"dateModified\":\"2018-08-23T10:53:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/\"},\"wordCount\":2293,\"commentCount\":45,\"image\":{\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/code-1839406_960_720-300x200.jpg\",\"keywords\":[\"rust language\",\"secure coding\",\"type safety\",\"vulnerability\"],\"articleSection\":[\"Education\",\"Software Security\",\"Types\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/\",\"url\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/\",\"name\":\"Software Security is a Programming Languages Issue - The PL Enthusiast\",\"isPartOf\":{\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/#primaryimage\"},\"image\":{\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/code-1839406_960_720-300x200.jpg\",\"datePublished\":\"2018-08-13T18:00:43+00:00\",\"dateModified\":\"2018-08-23T10:53:10+00:00\",\"author\":{\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/#\\\/schema\\\/person\\\/7d875a015cb2e83e9cd476df91028d5d\"},\"description\":\"Software security must be addressed by all programmers, not just security experts. So we teach it in CS 330, a programming (languages) class.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/#primaryimage\",\"url\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/code-1839406_960_720.jpg\",\"contentUrl\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/code-1839406_960_720.jpg\",\"width\":960,\"height\":640,\"caption\":\"Security is a programming concern\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/2018\\\/08\\\/13\\\/security-programming-languages-issue\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Software Security is a Programming Languages Issue\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/#website\",\"url\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/\",\"name\":\"The Programming Languages Enthusiast\",\"description\":\"Developments in PL, and why they matter\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/#\\\/schema\\\/person\\\/7d875a015cb2e83e9cd476df91028d5d\",\"name\":\"Michael Hicks\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dd0371ad9a0cb821df683b5d6a6cccc911e6e2af1778f28b77e8c90b0c319d14?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dd0371ad9a0cb821df683b5d6a6cccc911e6e2af1778f28b77e8c90b0c319d14?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dd0371ad9a0cb821df683b5d6a6cccc911e6e2af1778f28b77e8c90b0c319d14?s=96&d=mm&r=g\",\"caption\":\"Michael Hicks\"},\"sameAs\":[\"http:\\\/\\\/www.cs.umd.edu\\\/~mwh\\\/\"],\"url\":\"http:\\\/\\\/www.pl-enthusiast.net\\\/author\\\/mwh\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Software Security is a Programming Languages Issue - The PL Enthusiast","description":"Software security must be addressed by all programmers, not just security experts. So we teach it in CS 330, a programming (languages) class.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/","og_locale":"en_US","og_type":"article","og_title":"Software Security is a Programming Languages Issue - The PL Enthusiast","og_description":"Software security must be addressed by all programmers, not just security experts. So we teach it in CS 330, a programming (languages) class.","og_url":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/","og_site_name":"The Programming Languages Enthusiast","article_published_time":"2018-08-13T18:00:43+00:00","article_modified_time":"2018-08-23T10:53:10+00:00","og_image":[{"url":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720-300x200.jpg","type":"","width":"","height":""}],"author":"Michael Hicks","twitter_misc":{"Written by":"Michael Hicks","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/fd.xuwubk.eu.org:443\/https\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/#article","isPartOf":{"@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/"},"author":{"name":"Michael Hicks","@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/#\/schema\/person\/7d875a015cb2e83e9cd476df91028d5d"},"headline":"Software Security is a Programming Languages Issue","datePublished":"2018-08-13T18:00:43+00:00","dateModified":"2018-08-23T10:53:10+00:00","mainEntityOfPage":{"@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/"},"wordCount":2293,"commentCount":45,"image":{"@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/#primaryimage"},"thumbnailUrl":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720-300x200.jpg","keywords":["rust language","secure coding","type safety","vulnerability"],"articleSection":["Education","Software Security","Types"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/","url":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/","name":"Software Security is a Programming Languages Issue - The PL Enthusiast","isPartOf":{"@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/#primaryimage"},"image":{"@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/#primaryimage"},"thumbnailUrl":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720-300x200.jpg","datePublished":"2018-08-13T18:00:43+00:00","dateModified":"2018-08-23T10:53:10+00:00","author":{"@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/#\/schema\/person\/7d875a015cb2e83e9cd476df91028d5d"},"description":"Software security must be addressed by all programmers, not just security experts. So we teach it in CS 330, a programming (languages) class.","breadcrumb":{"@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/#primaryimage","url":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720.jpg","contentUrl":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-content\/uploads\/2018\/08\/code-1839406_960_720.jpg","width":960,"height":640,"caption":"Security is a programming concern"},{"@type":"BreadcrumbList","@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/2018\/08\/13\/security-programming-languages-issue\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/"},{"@type":"ListItem","position":2,"name":"Software Security is a Programming Languages Issue"}]},{"@type":"WebSite","@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/#website","url":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/","name":"The Programming Languages Enthusiast","description":"Developments in PL, and why they matter","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/#\/schema\/person\/7d875a015cb2e83e9cd476df91028d5d","name":"Michael Hicks","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fd.xuwubk.eu.org:443\/https\/secure.gravatar.com\/avatar\/dd0371ad9a0cb821df683b5d6a6cccc911e6e2af1778f28b77e8c90b0c319d14?s=96&d=mm&r=g","url":"https:\/\/fd.xuwubk.eu.org:443\/https\/secure.gravatar.com\/avatar\/dd0371ad9a0cb821df683b5d6a6cccc911e6e2af1778f28b77e8c90b0c319d14?s=96&d=mm&r=g","contentUrl":"https:\/\/fd.xuwubk.eu.org:443\/https\/secure.gravatar.com\/avatar\/dd0371ad9a0cb821df683b5d6a6cccc911e6e2af1778f28b77e8c90b0c319d14?s=96&d=mm&r=g","caption":"Michael Hicks"},"sameAs":["https:\/\/fd.xuwubk.eu.org:443\/http\/www.cs.umd.edu\/~mwh\/"],"url":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/author\/mwh\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/posts\/1502","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/comments?post=1502"}],"version-history":[{"count":10,"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/posts\/1502\/revisions"}],"predecessor-version":[{"id":1550,"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/posts\/1502\/revisions\/1550"}],"wp:attachment":[{"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/media?parent=1502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/categories?post=1502"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fd.xuwubk.eu.org:443\/http\/www.pl-enthusiast.net\/wp-json\/wp\/v2\/tags?post=1502"}],"curies":[{"name":"wp","href":"https:\/\/fd.xuwubk.eu.org:443\/https\/api.w.org\/{rel}","templated":true}]}}