logoalt Hacker News

jopsentoday at 5:49 AM1 replyview on HN

The specification doesn't have to be.

But yeah, writing specs is usually harder than reviewing the code 4 times :)


Replies

walnut_watertoday at 6:53 AM

It kinda does.

See WPA2 KRACK, you could've had a formally verified WPA2 implementation and it still would've been exploitable because the flaw was the specification itself.