Blog

Built in Rust: Why ZeroTier Quantum Starts With Memory Safety

Share on:
A rusty wheel to indicate the Rust memory safe code that keeps ZeroTier Quantum moving.

The TL;DR

ZeroTier Quantum is built in Rust because security-critical networking software needs memory safety without sacrificing performance. Rust gives ZeroTier Quantum compiler-enforced memory safety, a lightweight processing footprint for routers, embedded devices, drones, and other edge hardware, and the performance needed for data-center environments. Those requirements rule out most other languages because managed runtimes can’t match Rust’s compile-time guarantees, making Rust the clear choice for building quantum-secure networking software.

Want a deeper breakdown of the terminology used in this article? Check out our complete networking, cybersecurity and cyberwarfare glossary.

Every systems team eventually asks the same question: What language do you build a security product in? For us, the stakes are specific: ZeroTier Quantum has to protect data against a future, quantum-capable adversary. The answer turned out to be less about developer preference and more about arithmetic. Once you list the actual engineering requirements, the field of viable languages collapses fast. Rust is what’s left standing.

Requirement One: Memory Safety Isn’t Optional Anymore

Memory safety used to be a nice-to-have feature. Now it’s security-critical, and close to mandatory for new systems software. Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have been pushing the industry in this direction for good reason. Buffer overflows, use-after-free, double-free, and out-of-bounds reads are still among the most common root causes of exploitable vulnerabilities, and every one of them is a memory-safety bug. The numbers back that up. Microsoft has reported that about 70% of the vulnerabilities it assigns CVEs to are memory-safety issues.1 Google’s Chromium team found the same share among serious security bugs in Chrome. That risk compounds fast in a product whose whole job is safeguarding cryptographic material against next-generation threats. A memory-safety bug in a VPN client is bad. A memory-safety bug in the code guarding your post-quantum key material is a different category of bad.

While C and C++ are common, standard languages in many industries for good reason, the need for airtight memory-safety immediately eliminates them from contention. That leaves two major camps. One: managed or scripting languages, like Python, JavaScript, Java, and C#, which get memory safety from a runtime. Two: modern “post-C” systems languages, like Rust, which get it from the compiler instead. A third option sits closer to the second camp than it looks at first glance: Go, which also leans on a runtime for its safety guarantees, and is common enough in networking infrastructure that it deserves its own answer. So, the first real cut isn’t “why Rust.” It’s “why not a runtime-managed language, Go included.”

Requirement Two: Small Footprint, Big Performance

That’s where ZeroTier Quantum’s second requirement comes in. ZeroTier Quantum has to run everywhere, including routers, embedded devices, drones, robots, and cameras. All of that demands a small footprint and tightly constrained resources. On the other end of the deployment spectrum, ZeroTier Quantum has to scale up to data-center-level performance capable of maximizing throughput on the underlying link.

That combination, tiny devices and high-throughput performance, rules out garbage-collected and otherwise managed languages. Runtime overhead, unpredictable latency, and memory footprint all work against the goal. The requirement becomes “secure by construction, fast, and free of any mandatory runtime.” That shrinks the field to two real options, Rust, or a heavily restricted, strictly linted subset of C++.

The C++ path is the harder road. Safety there is discipline-dependent: linting and subsetting mitigate risk. They don’t guarantee it the way a compiler-enforced model does. It also demands more mature tooling to enforce consistently across a team. And it carries a higher long-term maintenance cost.

Why Not Go?

Go deserves a straight answer, because it’s the language most likely to come up next in this conversation. It’s fast to write, it has a garbage collector instead of manual memory management, and a huge amount of networking infrastructure is already built in it. Compared to C and C++, Go is a real step forward: bounds-checked slices and automatic memory management rule out the classic buffer overflow and use-after-free bugs that a compiled, unmanaged language leaves wide open.

But Go’s safety comes from a runtime watching memory while the program executes, not from a compiler proving safety before it ships. Two consequences follow directly from that, and both work against what ZeroTier Quantum needs.

First, footprint and predictability. Go ships a garbage collector and a scheduler with every binary, and that runtime has to run somewhere. On a data-center server, that’s a rounding error. On a router, an embedded controller, or a battery-powered drone, it’s real memory and real, occasionally unpredictable pause time, exactly where ZeroTier Quantum can least afford either.

Second, and more fundamentally: Go’s concurrency model is a convention, not a guarantee. “Share memory by communicating” is good advice, and channels are a clean way to follow it, but nothing in the compiler stops a goroutine from reaching into memory another goroutine is touching at the same time. Tools like the race detector catch some of those bugs at test time, after the fact, if the racy code path happens to run during testing. Rust’s ownership model rules out data races by construction, at compile time, before the code ever ships. For a networking stack juggling concurrent sessions and the key material that moves between them, that’s not a nice-to-have. It’s the same category of guarantee ZeroTier Quantum needs for memory safety in the first place, applied to concurrency instead.

Go clears the bar C and C++ can’t. It just doesn’t clear the one Rust does.

Why Rust Wins

Rust satisfies both requirements at once, and it does it with the strongest security posture of any candidate on the list. Its ownership and borrow-checker model enforces memory safety by construction, at compile time, and rules out data races the same way. There’s no garbage collector, and none of the runtime overhead that comes with one. That’s the rare case where a security property and a performance property point the same direction, instead of trading off against each other.

Beyond the safety model, Rust brings a mature ecosystem where ZeroTier Quantum needs it: async networking, netlink and routing-table access on Linux, and serialization that’s deterministic enough to hash and sign. Its compiler and tooling let ZeroTier Quantum cross-compile to the architectures and operating systems it has to run on.

It matters even more for post-quantum cryptography (PQC). Post-quantum primitives are new, with less real-world battle-testing than the classical algorithms they complement. For the primitives themselves, ZeroTier Quantum uses NIST-approved algorithms from an established, independently vetted cryptographic library rather than a freshly written implementation.

The primitives are only part of the risk. Historically, protocol implementations fail in the code around them: the handshake state machine, key derivation and ratcheting, session lifecycle, packet parsing, and every buffer that carries key material between steps. In ZeroTier Quantum that layer gets the borrow checker’s guarantees. Buffer overflows, use-after-free, and data races are ruled out at compile time.

That is a different posture than bolting memory-safety checks onto a C or C++ codebase after the fact, and a stronger one than leaning on a garbage collector to catch mistakes at runtime. The library does the math and Rust guarantees the plumbing around it.

What Rust Rules Out: Lessons From Real Exploits

This isn’t a theoretical risk. Some of the most damaging vulnerabilities of the last decade were memory-safety bugs in exactly the kind of software ZeroTier Quantum is: crypto libraries, network protocol handlers, and VPN gateways.

Heartbleed (2014) – OpenSSL’s TLS heartbeat handler trusted a length field sent by the client. An attacker could send a few bytes, ask for up to 64 KB back, and get whatever was sitting in memory next to the buffer: private keys, session cookies, passwords. It was an out-of-bounds read in a cryptographic library. That’s the failure mode that matters most for a product guarding post-quantum keys. In Rust, a slice carries its own length and every access is checked against it. A request for more bytes than the buffer holds fails instead of reading into nearby memory. The worst outcome is a rejected packet, not leaked key material.

Citrix Bleed (2023) – A buffer over-read in Citrix NetScaler ADC and Gateway let attackers pull session tokens out of appliance memory without logging in. With those tokens they could take over authenticated sessions and skip multi-factor authentication entirely. Ransomware groups exploited it at scale. It’s the same bug class with the same Rust answer: safe Rust has no way to read past the end of a buffer.

EternalBlue and WannaCry (2017) – A size-calculation error in the way Windows handled SMBv1 packets led to a buffer overflow that let attackers run code remotely without credentials. WannaCry turned it into a worm that hit hundreds of thousands of machines worldwide. The underlying pattern shows up in network parsers everywhere: math on untrusted packet fields feeds directly into a memory write. In Rust, even if a length calculation goes wrong, the write is still bounds-checked. A bad number can’t become a memory overwrite.

VPN gateway overflows (2022–2025) – Fortinet’s FortiOS SSL-VPN (CVE-2022-42475, CVE-2023-27997) and Ivanti Connect Secure (CVE-2025-0282) all shipped buffer overflows. Each let attackers run code remotely, without logging in, on the device meant to be the network’s front door. All three were exploited in the wild, either before disclosure or shortly after. Rust’s bounds and ownership rules remove the bug class each exploit depended on.

There’s evidence at scale, too. Google reports that as Android wrote new code in memory-safe languages like Rust, memory-safety bugs fell from 76% of Android’s vulnerabilities in 2019 to 24% in 2024. That happened without rewriting the existing codebase.

The Obvious Choice, Once You List the Requirements

Rust wasn’t a trend-driven choice. It was the language that best matched what ZeroTier Quantum needed to do: protect sensitive data, rule out data races along with memory-safety bugs, run efficiently across constrained devices and high-performance environments, and reduce entire classes of memory-safety risk before code ships. Go gets partway there. Linted C++ gets partway there from the other direction. Only Rust clears every bar at once. When you put those requirements together, Rust becomes the obvious fit.

ZeroTier Quantum brings compiler-enforced memory safety and post-quantum protection to every device on your network, from the data center to the edge. See how it fits your environment. Contact our team to learn more about ZeroTier.

Citations:
1. Microsoft Security Response Center, “We Need a Safer Systems Programming Language,” 2019

Related Posts

Sign Up for Our Newsletter

Don’t miss a single update. Sign up to receive occasional networking content and news.

By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it’s awesome!

Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.