Java Creator: Huge Security Hole in .Net

SYDNEY, Australia – James Gosling, developer of the Java programming language, said this week that Microsoft’s .NET development platform suffers from “a security hole big enough to drive many, many large trucks through.”

Speaking to developers at a programming event, Gosling commented that, “The Microsoft folks made a big deal of being able to support C and C++ on the [common language runtime], and that, to my mind, is one of the stupidest, most offensive things they could have done.”

The problem, said Gosling, is that several features of C and C++ are not consistent with or bounded by tight memory model integrity.

“C++ allowed you to do arbitrary casting, arbitrary adding of images [and] pointers, and converting them back and forth between pointers in a very, very unstructured way,” said Gosling, who currently serves as chief technology officer of Sun’s developer products group.

Gosling went on to compare .NET’s security model to that of Java, saying, “A lot of things in [Java’s] exception handling, they depend really critically on the fact that there is some integrity to the properties of objects. So if somebody gives you an object and says, This is an image,’ then it is an image. It’s not like a pointer to a stream, where it just casts an image.”

Also on hand at the event was Microsoft developer Charles Sterling, who defended his company’s product by pointing out that .NET requires additional permission to execute C and C++, so developers have the freedom to decide for themselves whether to use older, unsafe code in their applications.

Sterling added that of more than one thousand developers using .NET frameworks, he knows of only one who is implementing C and C++ in his applications.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Missouri AG Announces Age Verification Rule to Take Effect Nov. 30

Newly appointed Missouri Attorney General Catherine Hanaway announced Friday that the state's recently approved age verification regulation for adult websites will go into effect on Nov. 30.

Aylo, Woodhull Freedom Foundation to Host 'Online Censorship' Event

Aylo and Woodhull Freedom Foundation will co-host a virtual panel addressing online censorship on Sept. 30.

Severe Sex Films Relaunches Site Through YourPaysitePartner

Severe Sex Films has relaunched its official website through YourPaysitePartner (YPP).

Judge Awards Plaintiffs Over $400K in Attorneys Fees in Derek Hay Civil Case

California Superior Court Judge Gail Killefer has awarded former clients of LA Direct Models over $400,000 in attorneys fees and court costs, to be paid by agency founder Derek Hay.

ChickPass Rebrands as 'ChickPass Cinematic Universe'

ChickPass has announced that it has rebranded its network of sites as ChickPass Cinematic Universe.

Brazilian Adult Industry Association ABIPEA Launches

Brazilian Association of the Adult Entertainment Industry and Professionals (ABIPEA) has officially launched its organization.

New Adult Social Media Platform 'Havven' Opens Beta Phase

Havven, a new adult social media platform, has opened its beta phase and will officially launch Oct. 5.

Former Backpage CEO Carl Ferrer Sentenced to 3 Years Probation, $40,000 Fine

Former Backpage.com CEO Carl Ferrer was sentenced in federal court today to three years' probation and a $40,000 restitution fine for a conspiracy conviction related to money laundering through the defunct website.

Pineapple Support to Launch 'Wellbeing by PS' Initiative

Pineapple Support has announced its Wellbeing by PS initiative, naming new team member Amber Madden to head the project.

Playboy Wins $81 Million Judgment in Chinese Licensing Arbitration

Playboy Inc. was awarded $81 million in damages on Monday by the Hong Kong International Arbitration Centre, in a licensing dispute with former partner New Handong Investment (Guangdong) Co. Ltd.

Show More