logoalt Hacker News

nickpsecuritytoday at 2:56 AM1 replyview on HN

You've never seen the full power of static analysis, dynamic analysis, and test generation. The best examples were always silo'd, academic codebases. If they were combined, and matured, the results would be amazing. I wanted to do that back when I was in INFOSEC.

That doesn't even account for lightweight, formal methods. SPARK Ada, Jahob verification system with its many solvers, Design ny Contract, LLM's spitting this stuff out from human descriptions, type systems like Rust's, etc. Speed run (AI) producing those with unsafe stuff checked by the combo of tools I already described.


Replies

saagarjhatoday at 8:23 AM

Silo’d, academic codebases are not under the kind of attacks that commodity software is