Dependability through redundancy?
n
Good in its place
n
But need independent failures
o
Can’t usually get it for software
▬
Example:
Arian
e
5
o
Even harder for specs
▬
The unavoidable price of reliability is simplicity
—Hoare
n
And a way to combine the results