Speaker
Abstract
Building correct distributed systems takes thinking outside the box, and the fastest way to do that is to think inside a different box. One different box is "formal methods", the discipline of mathematically verifying software and systems. Formal methods encourages unusual perspectives on systems, models that are also broadly useful to all software developers. In this talk we will learn two of the most important FM perspectives: the abstract specifications behind software systems, and the property they are and aren't supposed to have.
Topics
QCon London 2026 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.
Part of the track
Architecting for Resilience Hosted by Jonathan Magen Computer Scientist, Distributed Systems Specialist, 20+ Years in Software DevelopmentFrom the same track
Wednesday 18 March
10:35 Whittle (3rd Fl.) Session resilience How to Find Resilience Bugs in Systems that Don't Exist Hillel Wayne Author of "Logic for Programmers" and "Learn TLA+" Building correct distributed systems takes thinking outside the box, and the fastest way to do that is to think inside a different box. One different box is "formal methods", the discipline of mathematically verifying software and systems. 11:45 Whittle (3rd Fl.) Session decentralized Spritely: Infrastructure for the Future of the Internet Christine Lemmer-Webber, David Thompson Let's take back the internet! Learn about Spritely's work to re-decentralize the net with new foundational technologies that put users in control. 13:35 Churchill (Ground Fl.) Session architecture Understanding Progressive Collapse: How To Avoid A Cascading Failure Sam Newman Microservice, Cloud, CI/CD Expert, Author of "Building Microservices" and "Monolith to Microservices", 20+ Years Experience as a Developer Small things going wrong can quickly snowball. The cascading failure is often a nightmare scenario for any system. An initial problem, which in isolation seems like such a minor problem, can kick off a chain reaction of ever-increasing failures, potentially leading to catastrophic results. 14:45 Churchill (Ground Fl.) Session Keeping the Nation On-Air: How We Think About Resilience at the BBC Tom Everest Head of Department for Architecture and Supply Chain @BBC At the heart of the BBC is delivering value to all, serving audiences across the UK and the world on TV, radio, and online with trusted and impartial news and high-quality British content. 15:55 Churchill (Ground Fl.) Session Shielding the Core: Architecting Resilience with Multi-Layer Defenses Anderson Parra Staff Software Engineer @SeatGeek High-demand events can cause sudden traffic spikes that overwhelm even well-designed systems. In ticketing platforms, millions of users — alongside increasingly sophisticated automated agents — may arrive simultaneously, placing extreme pressure on backend services.