Cool. Is this going to require phasing out systems written in C/C++ with horrible security track records like Linux and Windows? Or are they going to get a "too critical to be improved" exemption?
Do you have an OS written in a memory safe language with a good security track record we can switch to? If we start building now we might have a prototype by 2030.
There are plenty with good security track records, formal specifications, formal proofs of various security properties, and decades of deployments.
SCOMP, GEMSOS, INTEGRITY-178, seL4.
god seL4 everywhere would be awesome.
Don’t forget Temple OS
> Eschew flamebait. Avoid generic tangents. Omit internet tropes.
seL4 is far more rigorous that the others. The problem today is a widespread lack of understanding of software engineering approaches and tools for formal verification of source model verification, compiler toolchains, and binaries, and also a lack of diligence and effort in implementing rigorous practices.
This is the most HN comment I’ve seen in recent memory.