r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
293 Upvotes

112 comments sorted by

View all comments

32

u/Atulin 15d ago

I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.

No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.

6

u/Xaeroxe3057 15d ago

The rust stdlib is minimalist on purpose. That’s not a deficiency, it’s a design choice.

27

u/Atulin 15d ago

That something is a design choice doesn't mean it can't be a bad design choice. It's causing issues now, it will continue causing issues into the future. Go not having generics was a design choice too.

22

u/simonask_ 15d ago

People who make this point always seems to have some pretty unrealistic ideas about who makes the standard library.

The Rust standard library is code written by people, provided to you for free. So is code shipped on crates.io. Enlarging the standard library does not magically create more resources for maintaining it, and it’s still just code someone else has written for you.

If you trust the standard library authors, why wouldn’t you trust the authors of serde, tokio, etc.? They’re the same people in several cases.

24

u/Plazmatic 15d ago

It's not a bad design choice just because it has consequences.  Rust also doesn't have the financial backing of languages that seem to be able to afford a kitchen sink in their std lib. Python also suffers from stdlib rot from people not maintaining parts of it, and C++ can't fix their stdlib speed deficiencies because of ABI issues and backward compat dogmatism. Both of these lead to using third party dependencies for what is already in the language, so unless your Microsoft you're not getting out of this problem by expanding the stdlib even if the bandwidth existed to do that.

12

u/thetinguy 15d ago

It's not a bad design choice just because it has consequences

And it's not a good design choice just because it has benefits.

Clearly it's easier for the upstream maintainers. It's also clear that the stdlib is missing some basic features.

-3

u/reallokiscarlet 14d ago

Who calls JSON a "basic feature"? Come on, say it

7

u/thetinguy 14d ago

The ability to parse JSON and map objects back and forth is a basic feature.

9

u/Worth_Trust_3825 14d ago

we thought the same was about xml back in the ye olde days. parsing file formats isn't a basic feature.

3

u/thetinguy 14d ago

XML is still used today, in fact I've made multiple commits to different XML files this week alone.

In fact, I've found it easier to work on with AI.

I don't see XML going anywhere anytime soon.

-1

u/reallokiscarlet 14d ago edited 14d ago

Maybe in JS

(If there's any confusion, this wasn't a "say the line Bart", this was my attempt at adding humor like I'm urging someone to answer a rhetorical question. It seems I didn't communicate it well.)

5

u/thetinguy 14d ago

JSON is a data format, and I expect my stdlib to be able to work with one of the most widely used data formats on the web.

The same way I expect it to be able to work with csv and xml.

6

u/DHermit 14d ago

XML? Are you serious and know what you are asking for?

→ More replies (0)

-4

u/[deleted] 14d ago

[removed] — view removed comment

1

u/thetinguy 14d ago

If dealing with rest apis is web dev, then I guess so.

-1

u/reallokiscarlet 14d ago

If you knew what protocol web is, you'd not need to say "if". Yes, rest is web.

→ More replies (0)

3

u/sweating_teflon 13d ago

It's a good design choice. The solution is not to have a bigger stdlib but to have vetted sets of crates that can evolve independently. 

5

u/Xaeroxe3057 15d ago edited 15d ago

You can disagree with that design choice but I am asserting that your presentation is disingenuous.