- Since all the components we purchase are kept air-gapped, you'd need to already be on a machine in the air-gapped system (which isn't assembled and powered on except when we need to deal with key material) to exploit a vulnerability
- We're keeping things as minimal as possible in what we trust from coming out a store, for example if we purchase a Laptop we gut it of most of its components before it goes near our key material, Laptop's dont need batteries (or even CMOS batteries) to run basic live systems so they're going out.
- Compromising one part of the system won't let you sneak private key materials out on its own by-design, the part we've tried to make the hardest is exfiltration, the only material that leaves the air-gapped system leaves either as QR codes on a screen or on CD-R drives that we keep for years in a safe in their own tamper evident bags. This is all part of an effort to try and make sneaking private material out (even if you had full control of the system) as difficult as possible to do without being detected.
There's also projects to guess keystrokes based on sound which don't even require you to be on the host device https://news.ycombinator.com/item?id=29266783
Totally understandable if you can't/don't want to answer obviously.
I also suggest using at least dvdisaster (I suggest it's RS03 codec in augumented-image mode) or equivalent (if you come across a proper competitor to dvdisaster RS03, please let me know).
What that hardware will be is still an open question, but probably BD-R HTL.
Also worth noting (I think it's in the script too from memory) we make at least 3 identical copies of each CD in case of CD failure.