One of the medium-term possibilities we’re seriously considering for NTPsec is moving the entire codebase out of C into a language with no buffer overruns, and in general much stronger security and correctness guarantees. This would have been a crazy pipe dream starting from the codebase we inherited in 2015, which was 231KLOC of grubby, portability-shim-laden C. But NTPsec is a lot smaller and cl