Jacob,

Randy Bush wrote:
> > why do you guys use the FT232 (or consider a MPU-based USB interface)
> 
> this is a security device.

Here everyone agrees.


> usb is a big hole.

That's Randy's opinion. I have a different opinion - maybe because I
have a good decade of experience with the protocol, maybe because I
am a hipster, as Randy put it. :)


> we want i/o to go through as small a hole as possible.

I maintain that this philosophy is flawed for security devices as
well as for others.

I prefer structured low-level communication over byte stream parsers
in all my security devices, because it removes a large portion of
error-prone code not only in the device, but also in the host. I do
admit that I too have fun writing such code, but that's not an
argument, and I do not consider it more secure.


//Peter
_______________________________________________
Tech mailing list
Tech@cryptech.is
https://lists.cryptech.is/listinfo/tech

Reply via email to