People who are more cryptography-literate than I am: is this a real thing? My immediate inclination is to be skeptical of anything claiming to be hacker-proof, but I don't have the math skills to back it uphttps://twitter.com/QuantaMagazine/status/1152299326481358849 …
-
-
We use verification techniques
@trailofbits to eliminate categories of flaws + more efficiently focus our time on logical or more abstract risks. Verifying code also necessitates conversations with developers about their intent, sometimes the single most important outcome. -
Being forced to write out the critical security properties for your code in a machine-parseable format, then using a tool to watch your back for failures of them is never a bad thing!
End of conversation
New conversation -
-
-
Indeed, also considering the technology has become more approachable lately. The regular knee jerk reactions to formal methods like quoting Knuth are still there but people are generally more interested lately? Might also just be my skewed perception...
-
Yes! Verification is not the exclusive domain of academics. We're trying to lower the bar even further with tools like DeepState that let developers write tests in a familiar format then backhaul test generation to a symbolic execution engine:https://github.com/trailofbits/deepstate …
- 1 more reply
New conversation -
-
-
agreed. My editorializing was to the article's hed "hacker-proof cryptography", though I suspect most people in the thread didn't actually read the story. Also I don't think industry observers realize how much has already been done on high-value code, by eg AWS, Azure, GCP, Apple
-
Not only industry observers but within the industry. I will include myself.
End of conversation
New conversation -
-
-
Not so much a naysayer, but cautious about the implementation from a management point of view. Often times managers see it as a panacea and cut corners elsewhere -often in places where bad things
are certain to happen.Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.