Perhaps there is a misunderstanding. I was speaking of security researchers who look for flaws without having been prompted to do so (the "money" in "fame, money and ego" was the money that you can get when running a well-organized botnet, not the money you get for a honest job well done. Sorry for the confusion). Is this what you do, in the case of safety? If so, this is interesting and I would like to know more. What do you do with your results, publish them? What is your affiliation? Where can I find a list of such publications? Or do you have a contract with someone who is paying you to assess the code under NDA, in which case, where does Open Source come into this model? Would you do your job for free if the code was open? Under a deadline?
> DO-178B is a process, and not a "certification"
I used the words "DO-178B certified". As a Google search will confirm, I am not the first one to use this idiom. Since respectable actors are using it and have gone as far as buying it as Google AdWords, I stand by my use of these words.
> Static analysis is merely a tool, and is not a solution to this problem. You should be well aware of the limitations of Static analysis.
I didn't make any claims one way or the other. It is not unusual to meet people who have strong ideas on the subject, and I avoid this sterile discussion whenever I can.
What always strikes me, when I read reports such as this, is the self-correcting attitude displayed by the relevant authorities. The question, when analyzing an incident, is always, "how do we make sure the same mistake is not made again?". The reason why I think public domain critical code will not happen is that there is no answer to this question
(you can't make it more public domain the next time).
Again, I wish it was different. I just don't think it will happen in the foreseeable future.
> All safety critical systems will ultimately be "public domain" for this very reason.
Do you want to bet this practice has not been adopted in a single domain where it could apply by 2020?
It seems to me, but forgive me if I misunderstood your arguments, that you are saying "Testing is not perfect. Static analysis is not perfect. Therefore, critical code has to be made public domain". I'm not sure it follows. Whatever solution you are rooting for does not necessarily win by default because the other solutions are not perfect. Open source could win if it had something tangible to bring to the table. It wouldn't be automatic, and I am not even sure that the tangible advantages exist. Plane designers have been making software more and more complex because they could. If it turns out they can't complexify it any more, they can also just stop complexifying it. I can assure you that a company such as Boeing or Airbus would rather scale back on the new features used to promote new models than expose their designs to their competitors three years in advance (the code has to be verified before the first flight, right?).
At the risk of repeating myself, I am only describing the situation as I see it, not the way it would be convenient to me for it to be.
Perhaps there is a misunderstanding. I was speaking of security researchers who look for flaws without having been prompted to do so (the "money" in "fame, money and ego" was the money that you can get when running a well-organized botnet, not the money you get for a honest job well done. Sorry for the confusion). Is this what you do, in the case of safety? If so, this is interesting and I would like to know more. What do you do with your results, publish them? What is your affiliation? Where can I find a list of such publications? Or do you have a contract with someone who is paying you to assess the code under NDA, in which case, where does Open Source come into this model? Would you do your job for free if the code was open? Under a deadline?
> DO-178B is a process, and not a "certification"
I used the words "DO-178B certified". As a Google search will confirm, I am not the first one to use this idiom. Since respectable actors are using it and have gone as far as buying it as Google AdWords, I stand by my use of these words.
> Static analysis is merely a tool, and is not a solution to this problem. You should be well aware of the limitations of Static analysis.
I didn't make any claims one way or the other. It is not unusual to meet people who have strong ideas on the subject, and I avoid this sterile discussion whenever I can.
I made clear in which sense I meant "perfect safety record". There were no casualties in Qantas' Flight 72. The report at http://www.onderzoeksraad.nl/docs/rapporten/Rapport_TA_ENG_w... is new to me. Thanks for the reference.
What always strikes me, when I read reports such as this, is the self-correcting attitude displayed by the relevant authorities. The question, when analyzing an incident, is always, "how do we make sure the same mistake is not made again?". The reason why I think public domain critical code will not happen is that there is no answer to this question (you can't make it more public domain the next time).
Again, I wish it was different. I just don't think it will happen in the foreseeable future.
> All safety critical systems will ultimately be "public domain" for this very reason.
Do you want to bet this practice has not been adopted in a single domain where it could apply by 2020?
It seems to me, but forgive me if I misunderstood your arguments, that you are saying "Testing is not perfect. Static analysis is not perfect. Therefore, critical code has to be made public domain". I'm not sure it follows. Whatever solution you are rooting for does not necessarily win by default because the other solutions are not perfect. Open source could win if it had something tangible to bring to the table. It wouldn't be automatic, and I am not even sure that the tangible advantages exist. Plane designers have been making software more and more complex because they could. If it turns out they can't complexify it any more, they can also just stop complexifying it. I can assure you that a company such as Boeing or Airbus would rather scale back on the new features used to promote new models than expose their designs to their competitors three years in advance (the code has to be verified before the first flight, right?).
At the risk of repeating myself, I am only describing the situation as I see it, not the way it would be convenient to me for it to be.
Pascal