For servers, a lot of these vectors go away, and if you're theoretically deploying 10k servers, you can spec the controllers, microcode, etc.
I gave up on PC desktops for security a long time ago; just use mobile, tablets, and things like ChromeOS for that. ARM with TrustZones should be enough to fairly easily build something.
What I'd really like is a physically tamper-responding tablet. i.e. the touchscreen, physical enclosure, and all ports sealed in an HSM-like enclosure, such that if you tamper with it, it zeroizes a platform security key, which can be used to remotely attest "I haven't been tampered yet" to servers before communicating. You would then do some kind of physical enclosure size/seals/standards to protect from skimmers layered outside the trusted device, and then some kind of device to user authentication to prove it's a valid device before entering information on it. You could pretty much build this on Android today.
Comments
For servers, a lot of these vectors go away, and if you're theoretically deploying 10k servers, you can spec the controllers, microcode, etc.
I gave up on PC desktops for security a long time ago; just use mobile, tablets, and things like ChromeOS for that. ARM with TrustZones should be enough to fairly easily build something.
What I'd really like is a physically tamper-responding tablet. i.e. the touchscreen, physical enclosure, and all ports sealed in an HSM-like enclosure, such that if you tamper with it, it zeroizes a platform security key, which can be used to remotely attest "I haven't been tampered yet" to servers before communicating. You would then do some kind of physical enclosure size/seals/standards to protect from skimmers layered outside the trusted device, and then some kind of device to user authentication to prove it's a valid device before entering information on it. You could pretty much build this on Android today.