logoalt Hacker News

amlutoyesterday at 5:32 PM1 replyview on HN

IMO the obvious answer is formally verified security.

We can do this today for user mode, and we can mostly do it for ARM64 virtualization. It will be a while and would require substantial assistance from Intel or AMD to achieve it for x86 virtualization because the hardware is Too Darn Complicated and Too Poorly Specified.

Formal verification of the hardware should also be possible.


Replies

pixl97yesterday at 8:41 PM

Are people willing to pay the cost of this formal verification. Especially when it needs done at the hardware, firmware, and kernel levels.

show 1 reply