But most companies that get hacked fail in much dumber ways - like failing to update chrome long after a bug like this has been fixed. Or using stupid, guessable passwords.
Of course we should have sympathy for the 1% of companies who fall victim to 0days from state level attackers. But I have no sympathy for the other 99% of data leaks where the devs forgot to put a password on a public mongodb instance, or let their login cookies be enumerable or something equally ridiculous. Just because we can’t make security perfect doesn’t mean we shouldn’t make it good.
When I first started paying attention to computer security I was at a start-up and tasked to rewrite their PCI infrastructure for credit card processing, so I did some research into the state of the art. That week news of a casino hack came out. Billionaire casino/media magnate and conservative donor Sheldon Adelson gave a speech in October 2013 about how the US should threaten to use nuclear weapons to destroy Iran's nuclear program. In February 2014 a 150 line VB virus was installed on his casino's network which wiped all of the hard drives it could find, costing the Sands hundreds of millions of dollars. This was at a casino, some place which absolutely cares about their computer security and presumably spends a lot on that security, and they failed to successfully protect themselves against a nation-state level threat.
So whatever the hell startup I was working at had no chance if someone at that level wanted it. We could stop the five year olds. Just not the nation-states.
Formal verification is often thrown around but my understanding is it can't scale to the complexity of something like an optimizing compiler.