If the behaviors (bus timing logic and such) that are being used to spill information across process and privilege boundaries actually were fully documented, wouldn’t the liability fall on the people who used these chips to write multi-user environments without knowing or understanding the implications of the technical details?