The vast majority of historical vulnerabilities were related to memory unsafety. Nowadays, we have two sorts of ways of achieving memory safety - either going the way of garbage-collected languages, or by way of a type system with a borrow checker. What does this buy us? What does this mean in the context of a browser with a JIT? What does this mean for trust boundaries such as the userspace-kernel boundary? What does this mean for communication between different compute cores in a modern system, as we are moving more towards heterogeneous compute? The talk will discuss what memory safety can and cannot achieve for security in modern systems, and where a good amount of room-for-error remains.