Earlier quoted context omitted.
I've addressed a good chunk of what it takes for system and hardware security in at least two places: http://pastebin.com/y3PufJ0V https://news.ycombinator.com/item?id=10468624 There won't be 100% security because underlying physics fights you and our field is too new. Best we can hope for is making attacks hard and physical . There's great work in secure HW/SW architectures that should knock out about all SW stuff w…
Ok. Maybe that may work. But what about legal risks? extra-legal risks(like vanishing in the dead of night) ? soft risks - how would the wife of someone who is just the customer will respond when guys in black suits will come to her home ? Or if you're method will work so well, are you sure TSMC/Samsung will even accept you as a customer ? Because it doesn't seem like something that could scale without the legal/poli…
The Chinese have an interest in having a hardware platform that doesn't have NSA code baked into it; the US government and major US corporations likewise want hardware that doesn't phone home to Unit 61398. The Russians don't want either but probably have their own ambitions. Etc.
I think that in the next few decades it will become quite accepted that you choose your platform based on who your perceived "adversary" is. If you're concerned about the NSA, you buy a system that's Chinese from soup to nuts. If you're concerned about the PLA, you buy from a vendor with the US Government seal of approval.
It remains to be seen -- and in truth, I am somewhat pessimistic -- about the availability of a hardware/software ecosystem that doesn't require compromise. Hardware fabrication is a capital intensive industry, and capital intensive industries are pretty vulnerable to coercion by the governments in which all their capital equipment sits. ("That's a real nice chip fab you have there. It'd be a shame if something...happened...to it. Maybe you want to reconsider your offer to help us out?")
An open architecture that you could get from any number of vendors, and perhaps use to keep the vendors honest, would be a huge step in the right direction, though. But the underlying problem is extremely hard.