{"id":1236120,"date":"2025-03-01T10:34:00","date_gmt":"2025-03-01T15:34:00","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1236120"},"modified":"2025-03-01T10:34:00","modified_gmt":"2025-03-01T15:34:00","slug":"google-calls-for-measurable-memory-safety-standards-for-software","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1236120","title":{"rendered":"Google Calls for Measurable Memory-Safety Standards for Software"},"content":{"rendered":"<div>Memory safety bugs are &#8220;eroding trust in technology and costing billions,&#8221; argues a new post on Google&#8217;s security blog \u2014 adding that &#8220;traditional approaches, like code auditing, fuzzing, and exploit mitigations \u2014 while helpful \u2014 haven&#8217;t been enough to stem the tide.&#8221; <\/p>\n<p>So the blog post calls for a &#8220;common framework&#8221; for &#8220;defining specific, measurable criteria for achieving different levels of memory safety assurance.&#8221; The hope is this gives policy makers &#8220;the technical foundation to craft effective policy initiatives and incentives promoting memory safety&#8221; leading to &#8220;a market in which vendors are incentivized to invest in memory safety.&#8221; (&#8220;Customers will be empowered to recognize, demand, and reward safety.&#8221;) <\/p>\n<p>In January the same Google security researchers helped co-write an article noting there are now strong memory-safety &#8220;research technologies&#8221; that are sufficiently mature: memory-safe languages (including &#8220;safer language subsets like Safe Buffers for C++&#8221;), mathematically rigorous formal verification, software compartmentalization, and hardware and software protections. (With hardware protections including things like ARM&#8217;s Memory Tagging Extension and the (Capability Hardware Enhanced RISC Instructions, or &#8220;CHERI&#8221;, architecture.) Google&#8217;s security researchers are now calling for &#8220;a blueprint for a memory-safe future&#8221; \u2014 though Importantly, the idea is &#8220;defining the desired outcomes rather than locking ourselves into specific technologies.&#8221; <\/p>\n<p>Their blog post this week again urges a practical\/actionable framework that&#8217;s commonly understood, but one that supports different approaches (and allowing tailoring to specific needs) while enabling objective assessment:<\/p>\n<p>At Google, we&#8217;re not just advocating for standardization and a memory-safe future, we&#8217;re actively working to build it. We are collaborating with industry and academic partners to develop potential standards, and our joint authorship of the recent CACM call-to-action marks an important first step in this process&#8230; This commitment is also reflected in our internal efforts. We are prioritizing memory-safe languages, and have already seen significant reductions in vulnerabilities by adopting languages like Rust in combination with existing, wide-spread usage of Java, Kotlin, and Go where performance constraints permit. We recognize that a complete transition to those languages will take time. That&#8217;s why we&#8217;re also investing in techniques to improve the safety of our existing C++ codebase by design, such as deploying hardened libc++. <\/p>\n<p>This effort isn&#8217;t about picking winners or dictating solutions. It&#8217;s about creating a level playing field, empowering informed decision-making, and driving a virtuous cycle of security improvement&#8230; The journey towards memory safety requires a collective commitment to standardization. We need to build a future where memory safety is not an afterthought but a foundational principle, a future where the next generation inherits a digital world that is secure by design.<br \/>\nThe security researchers&#8217; post calls for &#8220;a collective commitment&#8221; to eliminate memory-safety bugs, &#8220;anchored on secure-by-design practices&#8230;&#8221; One of the blog post&#8217;s subheadings? &#8220;Let&#8217;s build a memory-safe future together.&#8221; <\/p>\n<p>And they&#8217;re urging changes &#8220;not just for ourselves but for the generations that follow.&#8221;<\/p>\n<div class=\"share_submission\" style=\"position:relative;\">\n<a class=\"slashpop\" href=\"http:\/\/twitter.com\/home?status=Google+Calls+for+Measurable+Memory-Safety+Standards+for+Software%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F02%2F28%2F0340214%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter\"><img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2025\/03\/twitter_icon_large-2.png\"><\/a><br \/>\n<a class=\"slashpop\" href=\"http:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F02%2F28%2F0340214%2Fgoogle-calls-for-measurable-memory-safety-standards-for-software%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook\"><img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2025\/03\/facebook_icon_large-2.png\"><\/a><\/p>\n<\/div>\n<p><a href=\"https:\/\/developers.slashdot.org\/story\/25\/02\/28\/0340214\/google-calls-for-measurable-memory-safety-standards-for-software?utm_source=rss1.0moreanon&amp;utm_medium=feed\">Read more of this story<\/a> at Slashdot.<\/p>\n<p><iframe src=\"https:\/\/slashdot.org\/slashdot-it.pl?op=discuss&amp;id=23623127&amp;smallembed=1\" style=\"height: 300px; width: 100%; border: none;\"><\/iframe><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Memory safety bugs are &#8220;eroding trust in technology and costing billions,&#8221; argues a new post on Google&#8217;s security blog \u2014 adding that &#8220;traditional approaches, like code auditing, fuzzing, and exploit mitigations \u2014 while helpful \u2014 haven&#8217;t been enough to stem &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1236120\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[101,44,110],"tags":[],"class_list":["post-1236120","post","type-post","status-publish","format-standard","hentry","category-slashdot","category-technology","category-unfiltered-rss"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1236120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1236120"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1236120\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1236120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1236120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1236120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}