Bjarne Stroustrup defended contemporary C++ safety work after the White House’s Office of the National Cyber Director (ONCD) urged software developers to reduce cyber risk by moving toward memory-safe languages. His point was that C++ has safety practices and ongoing proposals worth considering—not that C++ provides the same default memory-safety guarantees as languages designed to prevent many such errors.
What Stroustrup said about the warning
In a response to an InfoWorld inquiry on March 15, 2024, C++ creator Bjarne Stroustrup objected that the government documents appeared to overlook progress in contemporary C++ and efforts to strengthen its safety guarantees. InfoWorld published his response on March 18.
“I find it surprising that the writers of those government documents seem oblivious of the strengths of contemporary C++ and the efforts to provide strong safety guarantees.”
Stroustrup also acknowledged that language design alone cannot secure software:
Recommended Free Tools
#1 Best Overall
“On the other hand, they seem to have realized that a programming language is just one part of a tool chain, so that improved tools and development processes are essential.”
He identified a practical problem: much existing C++ does not follow modern guidelines, and developers do not always agree on which safety properties matter most. He said he and the C++ standard committee were working to address those issues. These statements are reported in InfoWorld’s March 18, 2024 account.
What the ONCD warning recommended
The ONCD report, published February 26, 2024, called for reducing cyber risk by moving toward memory-safe programming languages. InfoWorld’s coverage described C and C++ as examples of languages with memory-safety vulnerabilities and Rust as an example of a memory-safe language. This was a policy recommendation, not a legal prohibition: the White House did not ban C++.
Language labels should be understood as broad guidance, not a claim that every project written in a given language has identical security properties. InfoWorld’s February 27 context report said a November 2022 National Security Agency information sheet listed C#, Go, Java, Python, and Rust as memory-safe languages. The same InfoWorld report summarized the ONCD recommendation and its context in its February 27, 2024 article.
How Stroustrup says C++ can improve safety
Stroustrup’s defense centered on using contemporary C++ features and disciplined practices to reduce risks. Those practices can make C++ code safer, but their effectiveness depends on how code is written, reviewed, analyzed, and maintained.
RAII and resource management
RAII, short for Resource Acquisition Is Initialization, ties a resource’s lifetime to an object’s lifetime. Used well, it helps ensure resources such as memory are released when their owning objects leave scope. Stroustrup pointed to resource-management pointers as an alternative to conventional C-style pointer practices.
Containers instead of manual handling
Standard containers can manage collections and their storage, reducing the need for programmers to handle raw memory directly in common cases. They are useful tools, not a guarantee that every operation is safe: correctness still depends on how a program uses them and handles references, iterators, and object lifetimes.
Profiles as proposed, incremental safeguards
Stroustrup described C++ Profiles as a framework for stating what guarantees code requires and allowing implementations to check those requirements. In his account, Profiles could strengthen guarantees incrementally, help reduce range errors, and bring safeguards into large codebases through local static analysis and limited runtime checks.
Best Value
Profiles should not be mistaken for a finished, standardized, broadly deployed solution. InfoWorld’s report presents them as part of ongoing C++ safety work, not as an already established guarantee available across C++ implementations.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Safer C++ practices versus memory-safe language guarantees
The key distinction is where safety comes from. Some languages are designed to prevent classes of memory errors by default or make unsafe operations explicit. In C++, many protections come from choosing safer idioms, using appropriate tools, and enforcing project rules; conventional unsafe patterns remain possible.
| Question | Safer C++ practices and Profiles | Languages classed as memory-safe in government guidance |
|---|---|---|
| What provides protection? | Programmer practices, libraries, analysis tools, and proposed or evolving checks. | Language-level design intended to prevent many memory-safety errors; classification does not mean every program is free of vulnerabilities. |
| Can an existing codebase change gradually? | Stroustrup described Profiles as a way to introduce checks incrementally; broad implementation is not established by the reporting. | Migration usually requires adapting code, dependencies, and development workflows rather than changing a label or compiler setting. |
| What is the evidence status here? | RAII, containers, and resource-management pointers are established C++ techniques; Profiles were described as ongoing work. | The ONCD and NSA guidance identify language categories, but those classifications alone do not compare deployment outcomes for a particular project. |
Why replacing C++ is not an overnight decision
Experts quoted by InfoWorld said practical alternatives exist, while cautioning that migration away from C and C++ takes time. Dan Grossman, a University of Washington computer science professor, noted that the transition would be especially difficult in embedded systems. Josh Aas, executive director and co-founder of the Internet Security Research Group, described it as a long, difficult effort requiring sustained resources and leadership.
For a team deciding how to reduce risk, the useful comparison is not simply “C++ or a safe language.” It includes the guarantees needed, the ability to change existing code, platform and performance constraints, available libraries, and the cost of migration. A project can improve C++ practices while evaluating whether new components or future development should use a language with stronger default memory-safety protections.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →What the reported vulnerability estimate does—and does not—show
InfoWorld’s February 27 article attributed the estimate that “about 70 percent of all security vulnerabilities are caused by memory-safety issues” to studies from Microsoft and Google. The article did not identify the underlying studies, their years, datasets, or definitions. Treat the figure as a secondary-source-reported estimate, not a verified current percentage that applies to every organization or all software vulnerabilities worldwide.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

