Skip to content

Security1 publisher3 min readPublished

Black Duck's Boris Cipot names Microsoft, Google, Amazon and Cloudflare as Rust adopters in production

A year on from the CISA and NSA memory-safety report, the adoption evidence is still provider roadmaps and practitioner judgement about C and C++ code that nobody proposes to rewrite wholesale.

The Watch · Security desk

Illustration accompanying Black Duck's Boris Cipot names Microsoft, Google, Amazon and Cloudflare as Rust adopters in production

What happened

  • CISA and NSA released their report on the state of memory-safe languages just over a year ago, and ReversingLabs credits the period since with building momentum among major providers and AI coding tools.
  • The report leaned on a 2019 study that attributed 66 percent of CVEs in iOS 12 and 71 percent of CVEs in macOS Mojave to memory safety issues.
  • Jeff Williams of Contrast Security said adoption suits new development, because rewriting software that already works is a massive undertaking with an uncertain payoff.
  • Jason Soroko of Sectigo said migration stays gradual because teams must learn new tools, preserve compatibility and verify that replacements meet performance requirements.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A migration budget cannot be sold as removing exploited-vulnerability risk in general: on Google's own 2021 sample, roughly 19 of 58 exploited zero days sat outside the class a memory-safe language closes.
  • contradiction Cipot's production list and Williams's foothills estimate come from the same article, so a defender reading "Rust in production" learns nothing about the share of their own deployed code that changed.
  • decision On this evidence, a memory-safety road map commits to new work in Rust and interop with existing C and C++. The old code stays in scope for the same bug class for years.
  • capability Cheaper AI-assisted migration is the one variable that could change the economics of touching decades-old code. ReversingLabs gives no figures on how far it has moved.

A memory-safe rewrite would not have closed about 19 of the zero days Google counted being exploited in 2021. Sixty-seven percent of 58 is roughly 39, and the remaining 19 were something other than memory-safety bugs [5][19]. The other Google figure carried in the CISA and NSA report, 75 percent of the CVEs used in detected in-the-wild exploits, comes from a different sample, so the share cited moves 8 points depending on which set is quoted [4][20].

The article's own sources do not agree on how far adoption has gone. "Major technology providers such as Microsoft, Google, Amazon, Cloudflare, and parts of the Linux ecosystem are actively adopting Rust or other memory-safe approaches in production systems," said Boris Cipot, a security engineer at Black Duck Software [7]. Jeff Williams, chief technology officer and co-founder of Contrast Security, measured the installed base instead: "There is an entire mountain range of software built in non-memory-safe languages. And there is a tiny amount of action in the foothills to switch" [11]. The two statements use different denominators, production systems at a few large providers against deployed C and C++ everywhere else.

Cipot says the question put to defenders has changed. "The recent NSA and CISA guidance reflects this shift by focusing not on whether memory-safe languages are beneficial, but on how organizations can realistically adopt them," he said [8]. John Strand, owner of Black Hills Information Security, dates the turn to the kernel: "When you started seeing Rust incorporated into the Linux kernel, that was kind of the opening shot in the race to see this become more mainstream. And I think we're just going to see it become more mainstream moving forward" [10].

Dmitry Polyakovsky, a lead principal platform software engineer at Oracle, expects Rust to gain ground while legacy C and C++ stays in place [15]. "Rust can be a bridge for integrating new features into existing complex C/C++ codebases. As more developers become comfortable with Rust, new projects will be started in Rust from the beginning," Polyakovsky said [14].

A customer cannot check any of that. The adoption evidence here is supplier roadmaps and practitioner assessment, and the article does not report a procurement requirement, a contract term or an attestation that would let a buyer confirm which language shipped in a binary [21]. Practitioners quoted in the same piece warn that memory-safe languages address one category of vulnerability and that legacy C and C++ is too deeply embedded to replace wholesale [17]. Williams said eliminating one class of vulnerability is likely to introduce others, and that organizations have no reason to abandon versions already proven in production [13]. The report itself asked for road maps, and framed strategic MSL adoption as an investment in a secure software future [6].

What to watch

  • A named federal solicitation or customer contract requiring a memory-safety road map would move language choice from supplier roadmap to purchasable attribute.
  • Published migration figures, such as lines converted per quarter or AI-assisted rewrite cost, would test Williams's foothills claim against Cipot's production list.
  • Whether the next CISA or NSA update refreshes an evidence base whose newest exploit sample is from 2021.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories