Is Memory Safety In the Room With US?

No ratings

Presented at DistrictCon 2025 by

The vast majority of historical vulnerabilities were related to memory unsafety. Nowadays, we have two sorts of ways of achieving memory safety - either going the way of garbage-collected languages, or by way of a type system with a borrow checker. What does this buy us? What does this mean in the context of a browser with a JIT? What does this mean for trust boundaries such as the userspace-kernel boundary? What does this mean for communication between different compute cores in a modern system, as we are moving more towards heterogeneous compute? The talk will discuss what memory safety can and cannot achieve for security in modern systems, and where a good amount of room-for-error remains.