> The ISRG estimates ~80% of the vulnerabilities exploited in the wild are memory safety bugs.<p>Okay, but 1. How many vulnerabilities has openssh shipped, and 2. How many of those were memory issues? I would usually be tentatively on board, but you're competing with the OpenBSD folks, who have a shockingly good track record regardless of using C. No offense, but you could write in a formally verified Ada subset and I'd <i>still</i> hesitate to replace my SSH daemon.<p>(FWIW, I say all of this hoping to be wrong; an alternative implementation, if equally secure, would be great to have.)