For anyone confused:
- Make sure you know exactly what "compiler" and "backdoor" mean. With that, you can probably skip the rest of this comment.
- aubeynarf seems to be framing things in a way that might make you think C is immune to compiler backdoors, and might also make you think we're in agreement on that point. That's based on absolutely nothing. C has no special resistance to compiler backdoors. I hear Rust introduces new risk here, but I don't see any reason to reframe that as all the risk with C being in other areas.
- aubeynarf seems to be framing things in a way that might make you think security exploits all have similar levels of severity. Like, if you make a list of 100 exploits, it will be about the same severity as any other list of 100 exploits. That is not true. Scoring would be based on what damage the exploits can do, not how many there are.
- If aubeynarf's framing makes it seem like known exploits are scored by sheer quantity, that would also imply security experts put a lot of focus on "scoring" known exploits at all. We don't. We might put a lot of energy into counting and scoring unknown exploits if we could, but we can't, so this is again not an honest mistake or a slight twist from reality - it's completely made up from nothing. Not only would quantity be unrelated if we did have a big use for scoring known exploits, but we don't. Known exploits are not unknown exploits. We're trying to expose unknown exploits, and fix them. Counting and scoring the known ones is just something that happens along the way. We would never weigh the entire concept of compiler backdoors by counting the ones we've identified.
- aubeynarf seems to be framing things to set an impression of "oh this guy knows what he's talking about and he thinks compiler backdoors are no big deal, so they must be no big deal." If you fall for that, there's not much I or anyone can do for you.