3 ms·
This was specifically focusing on privilege separation---we don't provide any protection against timing or other side channels, though this work could be combin
by bkettle 3y ago
This was specifically focusing on privilege separation---we don't provide any protection against timing or other side channels, though this work could be combined with existing work around constant-time crypto, etc to get some assurance about side channels.
No specific thought about firmware updates. In the brainstorming phase we were thinking about a multi-application model indeed---something like the Ledger Nano but using Wasm for isolation between applications instead of their OS. For this project we decided to try out the privilege separation angle, but I think the multi-application idea would be interesting to explore too.