Again, I reiterate: it's not humanly possible to make performant, general purpose CPU that is 100% safe from instruction level attacks. Untrusted code execution must go, that's the only way. The genie is out of the bottle now. There will be more and more practical instruction level attacks with each year now.
> Untrusted code execution must go, that's the only way. This is how you get corporate rule over what can and can't run on machines you own. Safer architectures can be developed, without handing over control to a third party.
He isn't necessarily talking about the "untrusted by corporates" situation, maybe just "untrusted by the user".
(Personal pet peeve about "trusted" and "untrusted" --- never neglecting to mention the by who!?)