Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. F-Droid 2.0 (f-droid.org)
    276comments
  2. Show HN: Make cursed fonts like Times New Bastard (mitpit.com)
    77comments
  3. Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design (github.com/devdotfast)
    85comments
  4. Why is the liver so weirdly regenerative? (dynomight.substack.com)
    165comments
  5. 2DWillNeverDie (2dwillneverdie.com)
    14comments
  6. Fearless SIMD v1.0 (linebender.org)
    32comments
  7. Rails World 2026 Opening Keynote [video] (youtube.com)
    291comments
  8. Toyota is taking the Corolla electric (electrek.co)
    430comments
  9. Using LLMs to trace alchemical knowledge and decode 17th century letters (resobscura.substack.com)
    14comments
  10. My weird new hobby: Wandering around Tokyo on Google Maps (ahmedhossamdev.com)
    107comments
  11. Writing Parquet files using Haskell (datahaskell.org)
    3comments
  12. Google’s Project Suncatcher to put ML infrastructure in space (blog.google)
    250comments
  13. Two-tier encryption in the UK (macanorak.com)
    380comments
  14. California is chasing wealth that has feet (landeconomics.org)
    481comments
  15. Book review: Is parallel programming hard, and, if so, what can you do about it? (ahelwer.ca)
    30comments
  16. The Board Game of the Alpha Nerds (2014) (grantland.com)
    26comments
  17. The Bayeux Tapestry: Woven by the Victors (historytoday.com)
    —discuss
  18. Show HN: Air-gapped file encryption as self-decrypting HTML page (apeleg.com)
    14comments
  19. Show HN: Koi.rest – watch some fish and regain your balance (koi.rest)
    38comments
  20. Sourcehut account takeover via build logs (XSS in ansi2html) (blog.arusekk.pl)
    13comments
  21. Opus 5.5 is good at explainer videos (launchvideo.io)
    98comments
  22. Security auditing in the age of (good enough) AI (trailofbits.com)
    8comments
  23. The forgotten battle of East Lansing (eastlansinginfo.news)
    14comments
  24. Forging 1024-bit RSA signatures in nearly SNFS time [pdf] (iacr.org)
    9comments
  25. Stable (YC W20) Is Hiring Product Engineers (usestable.com)
    —discuss
  26. Geothermal heat map of US hot springs (soakingsprings.com)
    37comments
  27. WaveDigger: Dig into wireless signals to discover their physical locations (github.com/christianrowlands)
    19comments
  28. Tutoring company tells parents to save their money and 'use AI instead' (afr.com)
    154comments
  29. Nokia Design Archive (2025) (aalto.fi)
    118comments
  30. Motor Characterization for Small Running Robots (2016) (robot-daycare.com)
    1comments

Discover and Prevent Linux Kernel Zero-Day Exploit Using Formal Verification

3 pointsby 5y agodigamma.ai
3 comments
5y agoHN ↗

[Coq, VST, CompCert]

Formal methods: https://en.wikipedia.org/wiki/Formal_methods

Formal specification: https://en.wikipedia.org/wiki/Formal_specification

Implementation of formal specification: https://en.wikipedia.org/wiki/Anti-pattern#Software_engineer...

Formal verification: https://en.wikipedia.org/wiki/Formal_verification

From "Why Don't People Use Formal Methods?" https://news.ycombinator.com/item?id=18965964 :

Which universities teach formal methods?

- q=formal+verification https://www.class-central.com/search?q=formal+verification

- q=formal+methods https://www.class-central.com/search?q=formal+methods

Is formal verification a required course or curriculum competency for any Computer Science or Software Engineering / Computer Engineering degree programs?

5y agoHN ↗

Can there still be side channel attacks in formally verified systems? Can e.g. TLA+ help with that at all?

5y agoHN ↗

Formal methods could be used to prevent side channel attacks. However preventing each type of attack requires specifying properties which needs to be proven to assure it is is not possible. I am not very famililiar with TLA+, but I think in general it is not guaranteed to provide side channel attacks, such as based on timing, CPU state, etc.