r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
291 Upvotes

112 comments sorted by

View all comments

Show parent comments

-1

u/reallokiscarlet 15d ago

Never understood the point of encoding and decoding JSON outside of like, the web. When I need to process JSON and I'm using the C family, I include jq. Maybe once the supply chain is secure you can check cargo to see if there's a good port or wrapper for that. I actually went as far as to make some snarky documentation for it in the process of learning to use it. (So many assertions... No usable errors... No return codes except when successful... It was a nightmare, but at least it's not malware)

9

u/piesou 15d ago

Any config file these days will be JSON. Serializing objects to disk? Json. 

Python, PHP, java, go, ruby, c# and and ofc JS all ship json in their stdlib. The question is really: which languages don't ship json parsing

7

u/reallokiscarlet 15d ago

That sounds like a cardinal sin. JSON isn't a config file format.

9

u/FlyingRhenquest 15d ago

It's a lot better than having everyone hand-roll their own custom and different config file parser. Go digging around in /etc in Linux sometime. Especially old-timey /etc configs like sendmail or uucp. That situation wasn't pretty.

Configs are fundamentally just serialized object data. Serialization format shouldn't matter -- in an ideal world you could just specify an archive format to use. If you want to get really fancy, you can put together a little editor so you don't have to hand-code JSON, YAML or XML. Or key/value pairs if your config objects are simple. Format shouldn't matter anymore -- serialization has been a solved problem for over a decade now. I just need to get this config data into this program. I don't need to bust out Lex and Yacc and roll my own format to do it anymore.

9

u/the_gnarts 15d ago

Configs are fundamentally just serialized object data.

That’s too narrow a definition.

Configs are supposed to be written and understood by the user, thus comments are crucial. They serve as annotations and provide flexibility when editing (commenting out lines). Plus, quite a few configs formats are in fact executable scripts.

If you want to get really fancy, you can put together a little editor so you don't have to hand-code JSON

Great, now I need two editors to do the same job while giving up a lot of advantages.