Post #1460849
2025-12-28 01:33 UTC
@bob_zim @cwg1231 I don't want to rain on the formal verification parade. I think it could be an important piece of the puzzle! But I don't think it's a silver bullet.
Plus it doesn't solve the human communication piece of things, which is where this thread started.
Replies (1)
-
@bob_zim@infosec.exchange 2025-12-28 04:26
@deliverator @cwg1231 I guess my point with that digression is that engineering is characterized by exactly two things—ethics and rigor—neither of which is practiced by the overwhelming majority of programmers. Formal verification isn’t a total solution. A specification can still be bad in plenty of ways, but the software built to meet that specification can be correct. It’s difficult to do, but every real engineering discipline is difficult, and they don’t have correct solutions.