So, the problem with USB tokens that we basically have two choices: - Unauditable black boxes built on *supposedly* more secure ICs that require NDAs to develop for - Open and auditable, but definitely pwnable off the shelf microcontrollers. Which poison do you prefer?
Great for those who want to write maintainable and safe code efficiently. You do you, but I still won't hire you. You're not superhuman, your assembly has exploitable bugs. The only way to write safe code is to use tools that reduce the chances of mistakes.
-
-
I agree with what you said. It's what I advocate for as a crypto-anarchist. But I have the skills, loooooong experience & knowledge of many coding constraints & tricks in assembly language, starting by coding everything in FSM's, and much more, that can lead to results that
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
would surprise you. Again, I agree with you, because not everybody has my skills & experience in assembly language, but don't pretend that Rust is the only way.
-
Rust is not the only way, it's just a better way. What doesn't make sense is saying that "skillz+asm" is better. Truly skilled individuals know to use the tools that best help them achieve their goals, and asm is never going to be on your side when writing secure code.
- Show replies
New conversation -
-
-
I am working more that you think with other crypto-anarchist friends on secure coding tools, and I strongly believe it's the future, but just don't say secure code can't be done manually in assembly language with specific coding constraints and rules.
-
Of course secure code *can* be done in asm (e.g. just take the output of a Rust compiler, it's asm), but the point is that it's a lot *harder* and you're a lot more *likely* to have bugs in asm and thus it's almost impossible for a huge pile of asm written by a human to be secure
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.