4 ms·
Such 'hacker-proof code' can only be as secure as the underlying hardware. If such a cure already existed, we wouldn't be subjected to the current hacking/phish
by walter_bishop 10y ago
Such 'hacker-proof code' can only be as secure as the underlying hardware. If such a cure already existed, we wouldn't be subjected to the current hacking/phishing epidemic.
"these malfunctions could be as simple as a buffer overflow"
No amount of 'formal verification' will detect or prevent buffer overflows, which are a defect in how the hardware allocates memory. The cure must also be found in the hardware.
"Back in the 20th century, if a program had a bug, that was bad, the program might crash, so be it,”
It must of been on a different planet, cause I can remember using networked computers in college way back in 1984. and the first Internet worm occurred in 1988.
- marcoperaza 10y agoHardware bugs are NOT the major source of widely-exploited vulnerabilities in practice. They're a tiny fraction of exploits being used in the wild, and certainly of the ones being used to target the general population. Further, a buffer overflow is absolutely not a defect in how hardware allocates memory. It's a logical flaw in the software that reads/writes beyond the limits of the memory the programmer intended to access.
- mistaken 10y agoIt's also worth noting that some critical hardware components (e.g. CPUs since the infamous division bug) are formally verified as well, so manufacturing defects should be the largest concern for them.
- AstralStorm 10y agoOnly a tiny fraction of the CPU is formally verified. There are frequent errata. And plenty of undefined behaviour as well as races you can hit if you really try.