CFI can make attacks harder, but not a panacea. However, I believe all future defenses should build upon CFI, since, as @yuange1975 points out, "security is condition + statement". CFI just ensures that the condition is always executed before the statement.展开全文 原微博
Free open source software might bring less security than commercial: 1. they both expose vulnerabilities; 2. most free software has exactly NO warranty and you will not be compensated once it's attacked.展开全文 原微博