Re: j-core vs RISC-V
Ivan Sergio Borgonovo <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.svlug |
|---|---|
| Organization | http://www.WebThatWorks.it |
| Message-ID | <[email protected]> |
On 05/10/2017 01:08 AM, Rob Landley wrote: > Oh there's all sorts of fun if you dig down a bit. There are > fabrication-time attacks you can do just by tweaking dopant and not even > moving wires (so taking your chip apart with Taiwan's > reverse-engineering equipment and examining it won't spot the changes): Thanks for sharing. I had the suspect it could be done, but seeing it in full technicolor is different. > The most surprising email I got back when I was maintaining busybox was > from the administrator of the big wargames-style display at Cheyenne > Mountain (which was still open at the time) saying it was running > busybox. When I went "dear FSM _why_" he said they had to audit every > line of code that goes into those systems and they'd rather audit 1 > megabyte of busybox than 110 megabytes of equivalent gnu crap. (Can't > argue...) > > (My opinion is you don't secure a system by _adding_ stuff. You secure a > system by _removing_ stuff.) You want a very simple system of defence... build up a big wall. You can spend billions on that wall alone, will it get perfect? Will it work? For the same reason I'm not completely sold on the role of j-core in security. If you're going down that rabbit hole, you're going to play in the same league as NSA and NSA probably knows how Intel or AMD are really made. Now if you feel threatened by your secret services, you'd better buy a ticket to Moscow, one way. Probably my fault but if you don't mind I'd really curious to know what kind of applications are you thinking about. As a humble developer I understand the value of being open "turtles all the way down". But some things have higher costs than just submitting a patch to the a project and can't be so easily shared. It would make more sense if companies where used to share VHDL source but I couldn't see any sign you're involving anyone else from the site or the ML (it seems you've few time left for marketing, or anything else). That's because I think the main advantage of an open architecture for a humble developer like me would be a common ISA with no surprise, more competition, more "specialization" and probably once things start rolling faster innovation. Near monopoly in the x86 market and NDA, licenses, ARM veto on "improvements" when the margin in gaining performance from silicon and the ROI are shrinking don't look as a good premise for innovation. > What was his query? (I pointed at Jeff's talk, did that not cover it?) Do you think there is any chance to see large deployment of Linux on a new architecture? BTW this is one of the many times I'm astonished about how such a small team can come up with such a complicated project. Kudos. It was a nice detour from my current usual interests. More than 20 years ago, my first real job as a developer was paid in a bunch of books on solid state physics. -- Ivan Sergio Borgonovo http://www.webthatworks.it http://www.borgonovo.net