Skip to content
Carolina Code Conference
Served by TypeScript (node:http) in 35ms

2025 speaker

Redvers Davies

Redvers Davies

Polyglot, Professional InfoSec Troubleseeker, and diaeresis activist.

and diaeresis activist.

Charlotte, NC

Red is a full-time InfoSec Troubleseeker who started his professional life building ISPs, when the only interview questions were: “Do you know what a Web-Browser is?”, and “Do you think you can get NCSA httpd to compile on AIX?”.

After scaling an ISP from a few thousand users to millions, Red wrote award winning network discovery software and promptly had his IP stolen by a company with more Lawyers than developers.

Red now works in Information Security doing “AllTheThings”™, and spends his spare time playing with family, designing electronic badges for Security Conferences, exploring languages (both human and computer), and trying to squeeze every single cycle of performance out of his systems.

Visit website

2025 · intermediate

Fast, Concurrent, Secure, Correct Actors… and a pony!

Concrurenyc is hard.

Allowing multiple threads or Actors to access the same resources at the same time results in race conditions, non-deterministic behaviour, and inevitable data corruption.

Different systems mitigate these risks in different ways.

Databases use locks to limit access by time.

The BEAM copies messages to limit access in space.

Python has the Global Interpreter Lock to serialize all access.

Introducing Pony: An open-source, cross-platform, object-oriented, actor-model, capabilities-secure, high-performance programming language… and a pony.

Pony was originally designed to sniff market trades off a network and make very fast decisions based on what it saw. It had to be ridiculously fast, and above all - correct.

Processors aren't getting faster, they're getting wider. Pony was designed from the ground up to implement fast and safe data sharing between actors.

All variables in pony are strongly typed, and tagged with a "reference capability" which describes how that data may (or may not) be shared.

These compile-time only "reference capabilities" implement a mathematically proved model for safe data concurrency. Quickly.

To mitigate the dangers of supply-chain attacks, Pony implements "object capabilities", which are extensible unforgeable tokens which permit external operations such as file, environment, shell, or network access.

You can confidently download a hypothetical "left-pad" package. If you do not provide a token to the package, the package cannot do evil things™.

Pony has no locks.

Pony has no blocks.

Pony is memory-safe.

Pony is type-safe.

Pony has no runtime exceptions.

A program that compiles should never crash. If it crashes for anything other than memory exhaustion, it is likely a compiler or runtime bug that should be reported.

From the talk