- 280comments
- 78comments
- 92comments
- 170comments
- 19comments
- 33comments
- 300comments
- 440comments
- 110comments
- 15comments
- 261comments
- 2comments
- 384comments
- 26comments
- 30comments
- 16comments
- 519comments
- 1comments
- 14comments
- 8comments
- 38comments
- 102comments
- 15comments
- 9comments
- 38comments
- —discuss
- 19comments
- 2comments
- 118comments
- 160comments
[Coq, VST, CompCert]
Formal methods: https://en.wikipedia.org/wiki/Formal_methods
Formal specification: https://en.wikipedia.org/wiki/Formal_specification
Implementation of formal specification: https://en.wikipedia.org/wiki/Anti-pattern#Software_engineer...
Formal verification: https://en.wikipedia.org/wiki/Formal_verification
From "Why Don't People Use Formal Methods?" https://news.ycombinator.com/item?id=18965964 :
Can there still be side channel attacks in formally verified systems? Can e.g. TLA+ help with that at all?
Formal methods could be used to prevent side channel attacks. However preventing each type of attack requires specifying properties which needs to be proven to assure it is is not possible. I am not very famililiar with TLA+, but I think in general it is not guaranteed to provide side channel attacks, such as based on timing, CPU state, etc.