How Design Works (2012)
startupsthisishowdesignworks.com
startupsthisishowdesignworks.com
I found the typography was too big, there were too many bold/italics/font sizes and the actual elements of what makes good design made me click in order to reveal what the elements are.
I can confidently say I wasn't a big fan of the design, though.
This website does the opposite of what two former fellow students did: In a seminar they held a talk about aesthetics in software development. At the beginning, they told us that they couldn't agree on what makes good aesthetics, so they simply designed their slides with the worst aesthetics they came up with.
However, their slides still contained black-on-white text, upright, in readable size. Moreover, as they continued their presentation, we noticed that all slides had exactly that same "bad" style. They were consistent! Although those students strived for something different, they subconciously applied good common sense and did all important things right. It was good design, after all.
Reminds me of a magazine layout.
Personally I make it clear in website design conversations that design is not graphic design or anything to do with drawing pretty pictures in Photoshop. I then explain that design is in the information architecture used to specify the products, the etymology of how the information is structured and the customer interaction and that we need to get that up to back-of-napkin sketch before we need worry ourselves with artistic interpretations of social network buttons.
Maybe I go a bit far in not wanting people fiddling with graphic design, I talk of that as 'theming' or 'styling the frontend'.
I kind of liked that part. If you already know about a term, you can skip over it, but if you don't, you get more info without leaving the page.
(Same for "unstoppable" later down the page)
Further, the stuff that's easier to verify and more diverse is on the older process nodes. They deliver less transistors and use more power in the same space. However, they're cheaper in mask costs, open-source tools can semi-handle them, still diverse in number of fabs, and easier to reverse engineer. So, once again, high confidence and low design/development cost = not environmentally friendly.
For high confidence systems, it's best to just forget about the environment entirely. As if those smartphones weren't manufactured from very polluting processes anyway. Their users are just as guilty: just more judgemental. ;)
The stuff on the bottom, esp hardware, usually need either faster hardware or extra hardware to isolate functions on dedicated chips/boards. Except in most brilliant designs, the more things you counter the more chips or energy you must use.
An example is a VPN where you have one node for trusted side (Red), one for crypto component, and one for untrusted side (Black). This is called Red-Black separation: used by many high-assurance, crypto devices. Having a node/chip/board each lets you make separation work to your advantage. The Red and Black nodes will each handle transport, input validation, conversion from complicated (i.e. standard) interfaces to simpler ones (esp non-DMA), and administration to a degree. The crypto node, running state machines for just security part, can be built on all kinds of hardware, have minimal onboard software, and use about as much security as you like. Such a combo of physical isolation, interface protection, and implementation simplicity lets you have confidence that even strongest attackers hitting Black node won't steal data from Red. That's three pieces of hardware at a minimum with more if you isolate crypto node's logical functions (esp I/O).
Another angle comes from an approach I advocate against nation-states called Security through Diversity. The risk is that markets converge on a small number of hardware, peripherals, OS's, etc. Nation-state resources are large & necessary targets are small. High odds of 0-day development. Also, increasing worries that modern stuff might be subverted by NSA, China, Russia, etc. Easiest way of dealing with this is to diversify one's hardware (even processor types) and use portable software that cares not what it runs on. Plus lots of randomization and obfuscation. All this makes the job of getting from known software issue to working, stealth exploit harder. The best hardware choices are all old hardware or embedded which takes more hardware (i.e. servers, boards) to equal modern performance. Will use more space and energy.
Combining these two models will certainly use more space and energy. Plus, a lesson established by criminals and spooks alike is to treat all the equipment as disposable: constantly changing it. Sure someone might use it if you erase it and drop it off at a pawn shop, etc. The trend still causes more hardware manufacturing and waste, though.
So, there's a few ways that security against High Strength Attackers trades against the environment. There's some tradeoffs that can be made with MCU's/CPU's on low-power process nodes but development costs are prohibitive. New projects will likely combine existing ASIC's onto boards with redundant, power-using components. That power usage itself is a security hole (eg side channel attacks) guarantees this.
If you're a bootstrapped startup, you should probably consider a bootstrap template. There are a lot out there, and it allows you to leverage a designers thoughts, ideas and work that they've already done, and adopt them to your own, all to the tune of $9. Unless you absolutely know what you're doing, or unquestionably need a designer, its better to pay for something prefab and build out from there.
Who needs that, amiright?