1,460 karma · joined December 2, 2013
See: https://en.wikipedia.org/wiki/Post-quantum_cryptography
However, I think for describing actual build toolchains this way of implementing things might end up being significantly more complicated (and require even more arcane end-user cognitive load) than the Starlark/Python-based build rule / toolchain / constraint approach for actually assembling libraries, binaries, and other compiled artifacts. There are a combinatorial number of backends, conditional options settings, etc. which will be hard to capture with a purely declarative system. For instance, a C++ binary might needs platform-specific compiler flags, or some #ifdef nonsense. YAML doesn't have a clean way of implementing conditionals based on some constraint. So for heterogenous ecosystems (C/C++, Python, container assembly, GPU development, microcontrollers, etc.) this pushes a ton of complexity into the build rules themselves which may be opaque to end users (and thus introduce a ton of cognitive load, steep learning curves, hard-to-debug errors, etc.).
As I understand it, the primary reason these build systems leverage these Python-variants is so that the build rules, toolchains, constraints, and build definitions can all be written in the same language (since build rules often require some programmatic behavior). Perhaps with a future vision of them being totally interoperable across build systems.
For instance, a camera sensor could be designed such that every image that is captured on the sensor gets signed by the sensor at the hardware level, with a certificate that is embedded by the manufacturer. Then any video released could be verified against a certificate provided by the manufacturer. Of course, you have to trust the manufacturer, but that’s an easier pill to swallow (and better supported by our legal framework) than having to try and authenticate each video you watch independently.
There are issues that can arise (what if I put a screen in front of a real camera??, what if the CIA compromises the supply chain???), but at the end of the day it makes attacks much more challenging than just running some deepfake software. So there are things that can be done, we’re not destined for a post truth world where we can’t trust any media we see.
CS is certainly an outlier in terms of salaries, but ANY person capable of landing a postdoc in a STEM field at a competitive school in the US is capable of figuring out a way to get a job as a software engineer in Big Tech (the grind of leet code is nothing compared to the grind of doing a PhD, full stop). This is why >60% of PhD grads in CS across top schools are ending up in industry, and I knew a TON of PhDs from physics, math, chemistry, etc. who left research immediately after graduating and are now SWE.
So not only is it NOT a free market (MASSIVE long-term investment plus enormous warranted regulatory burden), but we don’t want it to be one! Because we don’t ever ever want Boeing or Airbus to fail because that would be devastating to national security and safety etc.
All this is to say that “a race to the bottom” in this context is maybe more harmful than in other markets, because there really isn’t much backpressure (outside regulatory oversight) to keep standards high.