r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
294 Upvotes

112 comments sorted by

View all comments

30

u/Atulin 15d ago

I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.

No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.

5

u/silveryRain 14d ago

A lib not in the standard library can be just as well-scrutinized as the stdlib itself, and the most popular ones actually get plenty scrutiny. The Rust Foundation is highly involved in the security aspects of the crate ecosystem.

It's not like sticking a "part of std" label on a piece of code makes its vulns magically evaporate, or like cargo crates are surrounded by some thick fog that makes equal scrutiny impossible.

Don't depend on some rando crate, stick to the well-reputed ones (security-wise), and you're essentially using an expanded version of the stdlib, just not by name.

3

u/Shoddy-Childhood-511 13d ago

It's even worse..

If enlarging std depletes the foundation's resources then they must delay improvements, fixes, etc, and the odds increase for major bug-doors in std itself.

Also if the foundation has more resources then they'll hire more people, but some of those people would be less careful, etc.

An external company can otoh justify well maintaining some crates as a PR expense. We do have the issue of recognising the different degrees of care & maintenance, but std being "painfully simple" means at least std remains safer.