Java Creator: Huge Security Hole in .Net

SYDNEY, Australia – James Gosling, developer of the Java programming language, said this week that Microsoft’s .NET development platform suffers from “a security hole big enough to drive many, many large trucks through.”

Speaking to developers at a programming event, Gosling commented that, “The Microsoft folks made a big deal of being able to support C and C++ on the [common language runtime], and that, to my mind, is one of the stupidest, most offensive things they could have done.”

The problem, said Gosling, is that several features of C and C++ are not consistent with or bounded by tight memory model integrity.

“C++ allowed you to do arbitrary casting, arbitrary adding of images [and] pointers, and converting them back and forth between pointers in a very, very unstructured way,” said Gosling, who currently serves as chief technology officer of Sun’s developer products group.

Gosling went on to compare .NET’s security model to that of Java, saying, “A lot of things in [Java’s] exception handling, they depend really critically on the fact that there is some integrity to the properties of objects. So if somebody gives you an object and says, This is an image,’ then it is an image. It’s not like a pointer to a stream, where it just casts an image.”

Also on hand at the event was Microsoft developer Charles Sterling, who defended his company’s product by pointing out that .NET requires additional permission to execute C and C++, so developers have the freedom to decide for themselves whether to use older, unsafe code in their applications.

Sterling added that of more than one thousand developers using .NET frameworks, he knows of only one who is implementing C and C++ in his applications.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Pre-Nominations Now Open for 2026 TEAs

The pre-nomination period for the 2026 Trans Erotica Awards (TEAs) is now open.

FSC Releases Updated Age-Verification Toolkit

The Free Speech Coalition (FSC) has announced the release of its updated age verification toolkit.

Duke Tax Joins Pineapple Support as Supporter-Level Sponsor

Duke Tax has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

UK Moving Ahead with Plan to Outlaw 'Choking' Content

The U.K. government has announced its intent to follow through on criminalizing “choking” content, a plan that was announced earlier this year.

Italy to Require Age Verification for Adult Sites

Italian media regulator AGCOM has announced that all sites and platforms hosting adult content will be required to implement age verification systems starting Nov. 12 to prevent access by users under 18.

'MILFlicious' Launches Through YourPaysitePartner

MILFlicious.com has officially launched through YourPaysitePartner (YPP).

Op-Ed: The Guardian's XBIZ Amsterdam Podcast Dismisses Creators' Experiences

British newspaper The Guardian’s podcast coverage of XBIZ Amsterdam 2025 purports to investigate the power dynamics of today’s online adult industry. Instead, it ignores creators’ voices, airs tired and outdated preconceptions about the business, and rehashes the unsupported claims of anti-pornography crusaders.

Eva Maxim, BranditScan Launch 'Killer' Promo

Eva Maxim and BranditScan have partnered for the Killer Creator Giveaway promotion.

2026 XBIZ Exec Awards Nominees for Online Industry Announced

XBIZ is pleased to announce the nominees for the online industry edition of the 2026 XBIZ Exec Awards, set to be presented as part of the annual XBIZ Honors ceremony on Wednesday, Jan. 14 in conjunction with the XBIZ 2026 digital media conference.

AEBN Publishes Report on POV Trends

AEBN has published a report on POV and gonzo categories from its straight and gay theaters.

Show More