Bonum Certa Men Certa

Rust is Starting to Seem More Like Microsoft-hosted "Digital Maoism", Not a Legitimate Effort to Improve Security

posted by Roy Schestowitz on May 07, 2025,
updated May 08, 2025

Rust in QEMU

Today in IRC someone mentioned GCHQ in relation to what's happening in Ubuntu this year [1, 2]. Ubuntu is removing (piecewise at least) the GPL/copyleft and outsourcing everything to Microsoft (GitHub), i.e. back doors must be assumed at all times, you're in control of nothing and the NSA is in charge (the security chief of GitHub is a decades-long NSA man).

In case it is not obvious, removing the GPL would mean more "blackboxes" (proprietary blobs) based on Ubuntu, where there's zero obligation to show code or reveal what's running. GNU/Linux can more or less become proprietary, just like IBM wants it to. They already push Rust (Microsoft GitHub) into the Linux kernel; some Microsoft staff does this. It also keeps throwing tantrums and public shaming at the project's leader, Linus Torvalds (Microsofters love doing that, it's like a ritual of theirs and he doesn't seem to get it, maybe because the Linux Foundation won't allow him to [1, 2]).

Jim, are you sure Microsoft and Google don't want to sabotage Linux with Rust polygamy?

Rust is always being sold as "Security" (apparently immature and barely tested coded is "secure") and pretty much nothing else!

Sometimes they talk about "Performance", but C can be optimised and they likely compare apples to oranges.

Is the "great replacement" (of free as in freedom) going to spread further? "Perhaps forcing this into Qemu is why their founder is being attacked," a reader said, pointing to this month's communications [1, 2] from Paolo Bonzini (IBM), "a contributor and submaintainer for QEMU."

IBM pays the salary and this is what it wants:

It's been roughly three months since my previous update on the Rust in
QEMU project.  Support for Rust remains experimental, with most of the
past three months spent cleaning up the bindings and making more
functionality available from safe Rust.

As before, this mostly covers what I have looked at, which is making it possible to write devices in safe Rust. Topics such as QAPI and async (block devices) are missing for this reason.
Overall, I'd say the progress is good: most of the missing features mentioned in the previous update have been fixed or at least have a plan for the next few months.

Do we really want experimental code at this crucial/critical level/layer? What is there to gain when the employer does not value security in the first place? It's just some buzzword it uses. It is for sales and lobbying, nothing else.

The official QEMU site says: "Rust in QEMU is a project to enable using the Rust programming language to add new functionality to QEMU. Right now, the focus is on making it possible to write devices that inherit from SysBusDevice in *safe* Rust. Later, it may become possible to write other kinds of devices (e.g. PCI devices that can do DMA), complete boards, or backends (e.g. block device formats)."

Maybe this is very innocent, but they seem to have taken a solid, stable program from a high-profile Frenchman and looked for ways to marry/glue it with GitHub, i.e. Microsoft/NSA. It caused a lot of problems when they did this to Linux, much as we expected all along.

There are already politely-expressed concerns out in the open, for example: "Well, I don't actually have an opinion about which is better: I don't know enough Rust to have a sense of what's more idiomatic or otherwise preferable. My point is the more general one, that we should decide (in all of these cases) which approach is going to work better for us and apply that consistently, now that we have the benefit of having written a couple of device models so we can see what each path looks like."

"These initial devices are going to be the models that other people (perhaps less familiar with Rust) are going to use as patterns when they write other device models. Converging on a consistent structure and way of writing devices now will help those future device authors (including me!), I think."

We already know what this did to Linux. The best known Linux developers openly complained about it, but it was probably "too late" already. Of course the Microsoft people engaged in public outbursts against those developers (e.g. Theodore Ts'o). Watch out, BSD people.

"Rust developers and C developers are generally different people," an associate notes. "Forcing in Rust is one way of forcing out the C developers, and thus the senior project members, or at least reducing their influence and wresting control away from the founders."

Also see:

"the second link is so-so," the associate says, "but the point is that Rust neither helps nor hurts security in and of itself. However, as you already point out, new code means new bugs which is a problem inherent in all new code. So replacing old, secure, polished code with new untested code is going to actually introduce security holes and general bugs."

It should be noted that "Rust people" (which is what they call themselves) cull informed critics and censor them, even when the criticism is about technical and legal issues, nothing even remotely political or abrasive or impolite. In GitHub, many Microsoft critics get censored or even permanently banned/deplatformed (we covered examples in the past). So when one chooses GitHub for a project's hosting one already eliminates many people sceptical of Microsoft or the Microsoft way of "thinking".

Related: Sami Tikkanen Explains Rust Language and Its Goals

It's "the quest of Rusting everything for Total Control" by none other than Microsoft, says someone in IRC today.

How Rust’s standard library was vulnerable for years and nobody noticed

Other Recent Techrights' Posts

Inviting the Founder of GNU/Linux to Events (It Only Costs His Travel Expenses) and Recalling the True Origins
It's reassuring to see belated recognition
The Microsofters Have Just Shared Privileged Trial Data With Microsoft
There are serious ramifications for liability accountability as Microsoft salaries sponsor these SLAPPs
Trolls With LLM Slop Are Disrupting Communications About Mass Layoffs at IBM
LLM slop to drown out the signal
 
Links 17/05/2025: Microsoft Kills "Surface Laptop Studio" (More Canceled Products/Units), Groups Caution About Harms of Social Control Media
Links for the day
Gemini Links 17/05/2025: Sympathy Algorithm and SSH on Alternative Ports
Links for the day
Slopwatch: Microsoft's Anti-Linux Propaganda and Cover-up, Slopfarms Clogging Up Google News
slop-tracking activities that observe googlebombing of "Linux"
AstroTurfing by IBM in thelayoff.com is Highly Risky (and Likely Outsourced)
Microsoft did this in Reddit (and got caught), so why won't IBM too?
Links 17/05/2025: Stabber of Salman Rushdie Sentenced to 25 Years in Prison
Links for the day
Gemini Links 17/05/2025: Happier on Gemini and Manipulating Reddit
Links for the day
ComEd and Microsoft: A Mess of Spaghetti Held Together By Circus Clowns
Reprinted with permission from Ryan Farmer
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 16, 2025
IRC logs for Friday, May 16, 2025
Links 16/05/2025: Microsoft Sacks Pregnant Women, People Fired on Their Birthday; Adobe Censorship Failing
Links for the day
Gemini Links 16/05/2025: "Repairing Our Way out of Commodity Fetishism" and Pre-librebooted Computers
Links for the day
[Video] IBM Shakes Hands of Prince Mohammed bin Salman
handshake of loyalty
The SLAPPs From Microsofters Distract From Serious Copyright Infringement by Microsoft and Apparent Business Crimes
Aside from other issues, such as strangling women
Enshittification is Everywhere: You Pay More, the Services Get Worse
"Enshittification" is a term coined by an online friend; I increasingly use this term to describe what's happening even outside the realm of technology (which it was adopted to describe)
Microsoft Reduces Office Space Ahead of More Waves of Mass Layoffs
"The Gerstnerisation of Microsoft"
Anti-Linux FUD Produced by Microsoft LLMs to Blame "Linux" for Microsoft's Own Failures
We call out some of the worst culprits
Gemini Links 16/05/2025: Hoking GPS, Grabovac, and Tanana
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 15, 2025
IRC logs for Thursday, May 15, 2025
Microsoft WARN Notices Proliferate in the United States
From what we've seen, this wave was more than 3% (a lot more) and the next wave/s will be even bigger (possible as imminent as weeks from now), based on insider leaks
Links 15/05/2025: Google Betrays Publishers Again, Openwashing by Sysdig
Links for the day
Richard Stallman Still Respected by Many in the Libre Graphics Community
Richard Stallman and Professor Moglen never harmed anyone
If You Read Techrights, Then You Probably Want to Read Tux Machines as Well
That site is more active than this one
Gemini Links 15/05/2025: Forced Music in Publicly Accessible Space and ~silv is Online
Links for the day
Links 15/05/2025: KOSA Censorship (USA Becomes More Like KSA) and More National Cuts
Links for the day
Bing Might Shut Down - Just Like Skype Did - Some Time in the Coming Months/Years (Parts of It Already Shut Down)
they try to bring the losses under control
Your Real Ally Would Not Defend the Company of SLAPP and Strangling of Women
who's left to tell us what's true?
Breakdown of Microsoft Layoffs Shows It's About Cost, Not Performance or Hype (Like "AI")
MSN (Microsoft) reposted this with some unnecessary spin
The Lawyers Working for the Serial Strangler From Microsoft on SLAPPing Techrights Have Apparently Lost Their Voice
the moment we mentioned that their media lawyer is leaving they went all quiet in social control media
At IBM, Relocation Can be a Trick or a Trap (IBM Gets Rid of Staff Under the Guise of "Relo")
IBM is not being honest with employees
Microsoft Rumours: This Week's Scale of Layoffs "Higher Than Reported" and More Coming Soon ("A Lot More Severe" Than May's)
The "3%" figure is false
Slopwatch: Sloppy Brian, Brittany Slop, and General Observations
Creative people don't need slop; there's just nothing good about it, slop appeals to lazy people careless about quality
Over at Tux Machines...
GNU/Linux news for the past day
Beyond Mass Layoffs at Microsoft: Entire Units Shut Down for Good
And it's far from over
Links 15/05/2025: Crikvenica, Analog Computer, and Slop 'Hallucinations'
Links for the day
IRC Proceedings: Wednesday, May 14, 2025
IRC logs for Wednesday, May 14, 2025