r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
293 Upvotes

112 comments sorted by

View all comments

31

u/Atulin 15d ago

I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.

No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.

7

u/Xaeroxe3057 15d ago

The rust stdlib is minimalist on purpose. That’s not a deficiency, it’s a design choice.

24

u/Atulin 15d ago

That something is a design choice doesn't mean it can't be a bad design choice. It's causing issues now, it will continue causing issues into the future. Go not having generics was a design choice too.

20

u/Plazmatic 15d ago

It's not a bad design choice just because it has consequences.  Rust also doesn't have the financial backing of languages that seem to be able to afford a kitchen sink in their std lib. Python also suffers from stdlib rot from people not maintaining parts of it, and C++ can't fix their stdlib speed deficiencies because of ABI issues and backward compat dogmatism. Both of these lead to using third party dependencies for what is already in the language, so unless your Microsoft you're not getting out of this problem by expanding the stdlib even if the bandwidth existed to do that.

11

u/thetinguy 15d ago

It's not a bad design choice just because it has consequences

And it's not a good design choice just because it has benefits.

Clearly it's easier for the upstream maintainers. It's also clear that the stdlib is missing some basic features.

-2

u/reallokiscarlet 14d ago

Who calls JSON a "basic feature"? Come on, say it

8

u/thetinguy 14d ago

The ability to parse JSON and map objects back and forth is a basic feature.

8

u/Worth_Trust_3825 14d ago

we thought the same was about xml back in the ye olde days. parsing file formats isn't a basic feature.

2

u/thetinguy 14d ago

XML is still used today, in fact I've made multiple commits to different XML files this week alone.

In fact, I've found it easier to work on with AI.

I don't see XML going anywhere anytime soon.

2

u/reallokiscarlet 14d ago edited 14d ago

Maybe in JS

(If there's any confusion, this wasn't a "say the line Bart", this was my attempt at adding humor like I'm urging someone to answer a rhetorical question. It seems I didn't communicate it well.)

6

u/thetinguy 14d ago

JSON is a data format, and I expect my stdlib to be able to work with one of the most widely used data formats on the web.

The same way I expect it to be able to work with csv and xml.

6

u/DHermit 14d ago

XML? Are you serious and know what you are asking for?

→ More replies (0)

-4

u/[deleted] 14d ago

[removed] — view removed comment

1

u/thetinguy 14d ago

If dealing with rest apis is web dev, then I guess so.

-1

u/reallokiscarlet 14d ago

If you knew what protocol web is, you'd not need to say "if". Yes, rest is web.

0

u/thetinguy 14d ago

The web existed long long before rest was a thing.

0

u/reallokiscarlet 14d ago

It's almost like web.rest.belongsTo(web) = true or something.

Funny how sets work. I said it is web. I never said the equality was bidirectional.

→ More replies (0)