The Cheapest Insurance in Software

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

The CrowdStrike outage of July 2024 — the largest IT outage in history, costing $5.4 billion — was caused by a bug that fuzzing would have caught. Fuzzing was invented in 1988. This piece examines four decades-old, nearly free verification techniques — fuzzing, crash injection, deterministic simulation, and formal specification (TLA+) — that are spectacularly effective yet almost universally ignored. Using SQLite's 92-million-line test suite, FoundationDB's deterministic simulator, and Amazon's TLA+ adoption as existence proofs, the author argues the neglect is economic: software correctness is invisible at the point of sale, sellers don't bear the cost of failure, and the patch button set the perceived price of failure near zero. With AI now generating code at machine speed, human review is no longer a viable gate, making these automated verification techniques not just valuable but necessary.

8m read timeFrom codegood.co
Post cover image
Table of contents
The evidence is not subtleThe economics of unbought insuranceThe bill arrives with the machines
6.1K Impressions