3 ms·
> Designing Safe Software Systems Part 2 https://www.digitalmars.com/articles/b40.html https://www.digitalmars.com/articles/b40.html > Dual Path Hmm there's s
by KajMagnus 5y ago
> Designing Safe Software Systems Part 2 https://www.digitalmars.com/articles/b40.html https://www.digitalmars.com/articles/b40.html
> Dual Path
Hmm there's something similar in the SRS book by Google, they call it "failure domains" (I haven't read all of it though).
> Monitors: If the output is outside some preset bounds, the system is shut down
Maybe in software, becoming read-only can be a similar good idea, when something looks weird
> Deadman: A deadman is a hardware timer switch added to a computer system that shuts it down if it isn’t regularly reset.
This is something I'm planning to add to the software I'm developing :- )
It's forum / blog-comments software, and, in case the admins have been away for too long (maybe vacation for some weeks), the forum would become read-only, maybe even retroactively hide some risky comments & discussions, until they're back — so there's always humans around that can remove toxic troll comments and such things.
> Safe Systems from Unreliable Parts https://www.digitalmars.com/articles/b39.html https://www.digitalmars.com/articles/b39.html
> Improving the quality of that component by a factor of 10 will get us there, but at a cost explosion of 10 times the price. But suppose we add in a backup component B, that also has a 10% failure rate. The odds of A and B both simultaneously failing are 10% of 10%, or 1%. This is achieved by a mere doubling of the cost instead of an order of magnitude increase
I think it's interesting that this at the same time, doubles the attack surface, for hackers? Although the failure risk gets down to 1%, now the hackers can try to break in into both A and B? Hmm. I wonder if there're any ways to avoid this tradeoff, ... Maybe there aren't, in the same way as it's going to be 2 x expensive, too