▲ | Spooky23 2 days ago | ||||||||||||||||||||||||||||||||||||||||
Lots of espionage and surveillance within government and contractors. Lots of body shop contractors are fake people anyway. Pretty easy to imagine placing a compromised person in a low sensitivity area, then moving laterally. | |||||||||||||||||||||||||||||||||||||||||
▲ | impossiblefork 2 days ago | parent [-] | ||||||||||||||||||||||||||||||||||||||||
But why you hire consultants to solve core security problems? Furthermore, surely it would just be one guy who knows OS and FPGA stuff and another guy to check it? What I'm arguing for is that a sensible solution to security problems is to avoid complexity, so that things can be obviously secure. Carefully defined interfaces designed to be clear, impossible to misinterpret and which are designed to be parsed and implemented without doing anything requiring some kind of fiddly parsing that can lead difficulties, and small enough that someone can implement them in an afternoon; and then you combine that with a machine inherently robust to things like buffer overflows such as Harvard architecture type things, and it's easy even for a single engineer to program something like that up on an FPGA. | |||||||||||||||||||||||||||||||||||||||||
|