For now. If someone makes a practical quantum computer, pretty much every asymmetric primitive we use at the start of a cryptographic protocol to make a shared secret for symmetric encryption will be breakable.
Looking for a nice, solid, well-documented library to do something is difficult for most stuff. There are some real gems out there, but usually you end up having to roll your own thing. And Lisp generally encourages rolling your own thing.
I'm interested in knowing how they achieve requirements traceability to code and the requisite level of code coverage (certain SILs require MC/DC coverage, which usually requires expensive tooling). Also which hazards they identified and their mitigations.
I believe that software-related college degrees are mainly there to get the horrible first few tens of thousands of lines of code out of people before they go into industry.
This reminds me of Joe Kennedy (JFK's father) getting out of the 1920s stock market right before the Depression because his shoe-shine boy was giving him stock tips.
"The same thing will happen if you're running a startup, of course. If you do everything the way the average startup does it, you should expect average performance. The problem here is, average performance means that you'll go out of business. The survival rate for startups is way less than fifty percent. So if you're running a startup, you had better be doing something odd. If not, you're in trouble."
There may be a security advantage to using a separate non-bypassable network appliance that puts your traffic on Tor, since then it would be much harder to break into a Tails machine and make it leak your location. However, given that it's meant to be easy to use, I think they probably picked the right balance by having the Tor redirecting occur in the same address space as the computing environment.
Aviation safety for FAA airworthiness generally follows SAE ARP4761, which requires risks of Catastrophic severity to have a quantitative failure rate of 10^-9 incidents per hour or less. The Air Force follows MIL-STD 882E, which generally requires risks of Catastrophic severity to have a quantitative failure rate of 10^-6 incidents per hour or less. In short, the military accepts more risk than commercial aviation. That being said, military aircraft usually are also rated to ARP4761 levels of safety so they can fly in US airspace.