Google is funding a project at the Internet Security Research Group to port a critical component of the Apache HTTP web server project from the error-prone C programming language to a more secure alternative called Rust.

The module in question is called mod_ssl and is the module responsible for supporting the cryptographic functions required to create HTTPS connections on an Apache web server.
ISRG says it plans to develop a new module called mod_tls that will do the same thing but using the Rust programming language instead of C.
The module will be based on Rustls, an open source Rust library developed as an alternative to the C-based OpenSSL project.
To lead this project, ISRG management assigned Stefan Eissing, the founder of software consulting firm Greenbytes, and one of the Apache HTTP Server code maintainers , to lead the mod_tls project
The ISRG hopes that once work , the Apache HTTP web server team will adopt mod_tls as the default and replace the old and insecure mod_ssl component.
According to W3Techs, the Apache HTTP web server is the leading web server technology, used by 34.9% of all websites whose web server technology is known.
In recent years, Rust has become one of the most popular programming languages.
Both Google and Microsoft are experimenting with using Rust in both Chrome and Windows. Microsoft has even gone so far in its recent experiments as to create an entirely new Rust-like programming language called Verona.
With such statistics from both Google and Microsoft, and with nearly two-thirds of all websites now redirecting to HTTPS, porting Apache's mod_ssl module to Rust is a simple and quick way to ensure that billions of users are kept secure for years to come.
Information source: zdnet.com
