Hacker News
Compiler Can Undo Your Security Checks
Security researcher Chris Domas demonstrates at Black Hat that legal compiler optimizations can strip memory-clearing code, introduce TOCTOU bugs, and turn otherwise safe C programs into vulnerable binaries, with tiny size differences (e.g., 17 vs 33 bytes) affecting exploitability. He shows AI analysis of 500 million open-source lines uncovered 300 risky patterns, and advises developers to enable compiler warnings, use sanitizers, inspect optimized builds, and test the exact shipped binary.