Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> A method to reliably produce vulnerability-free software is not invented yet.

I beg to differ. We have formal methods, ranging from type systems to full blown verification. This isn't a technical problem, it's an economic one.



Had these methods been applied to security aspect of software development? Any examples?


On the lower end of the spectrum, sound type systems prevent a class of vulnerabilities including buffer overflows. On the upper end, https://sel4.systems/, a formally verified microkernel, is used in security-critical systems.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: