Thread by @colmmacc: "Thursday tweet thread time! This one is all about what we do in Amazon s2n to prevent security issues similar to this week's libssh problem. […]"
Advice on how to write state machines and verify their correctness. It’s a lot of work and it isn’t easy. There’s more code to test and verify than their is in the implementation.
