Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> What happens if there's a long-play social engineering attack (like the attempted XZ takeover) of something upstream of a core tool (or its dependencies) for formal verification and we have no trusted computing base?

I don't really think the current LLMs have enough context window to plan and execute something like XZ takeover without a human carefully guiding it.

But if they do, formal verification is the least thing we need to worry about. Formally verifying pure math problems will generate negative financial value once A and O get IPOed. Plus Lean is a quite small project (thus the name 'lean'). It has virtually no dependency besides a C compiler.

 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: