[Info-vax] Next release of OpenVMS x86

Arne Vajhøj arne at vajhoej.dk
Fri Jul 17 11:48:36 EDT 2020


On 7/10/2020 5:21 PM, johnwallace4 at yahoo.co.uk wrote:
> "I have formally verified this program but I have not tested it."
> 
> ... time passes ...
> 
> "I have tested this formally verified program and its behaviour
> is erroneous and there may be security vulnerabilities as a
> result."
> 
> ... time passes ...
> 
> (formal verification falls even more out of fashion; x86 or
> Windows or MacOS doesn't have it therefore nobody needs it.
> VIPER [verifiable integrated processor for enhanced reliability]
> did have it and it was wrong.)

The size of modern software and the speed of change due to
changing business requirements may explore more than
just trend.

> ASLR has been readily defeatable in the real world. Is it smoke
> and mirrors, or is it snake oil. It certainly isn't the panacea
> it is often claimed to be.

Modern security is very much defense in depth. ASLR is one element
helps.

Arne




More information about the Info-vax mailing list