> During our research, we explored several components, including Broadcom’s Wi-Fi firmware, the DART IOMMU, and Apple’s Wi-Fi drivers […] We’ve also seen how the iPhone utilises hardware security mechanisms, such as DART, in order to provide isolation between the host and potentially malicious components.
Companies like NSO Group are certainly capable of developing exploits of this complexity, as Google's team has shown. Their analysis of NSO's FORCEDENTRY exploit showed NSO building a mini-VM from scratch within a little-known image codec used by the iMessage PDF engine: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
It is extremely difficult to defend against teams that have this amount of skill and dedication.
Very happy that book on NSO has made the waves it has in my political circles. Everyone needs to be aware of the security/safety climate journalists, and anyone who wants to challenge governments/capital in any meaningful way are facing.
Any more links like those? Fantastic stuff. Should I just be reading Google Project Zero's blog? I've recently found offensiveCon thanks to hackernews.
Time and money. These groups are funded 8 hours a day, 40 hours a week, per person, to dig into your code and find problems to exploit. Unless your place of work has an even bigger security team, you have no chance.
Being certified against the SKPP required a multi-month NSA penetration test with full source code and design specifications to discover zero deficiencies [4] so qualifies against the standard you are proposing. The certification was done at the behest of the DoD for the F-22 and the F-35, so you can be reasonably certain it was not a false certification by the NSA to make sure the premier fighter jets of the US are vulnerable.
You can also look at some of the other certified systems linked here [5] though I am not sure which of them are still commercially viable or even functional on modern hardware.
[1] https://www.nist.gov/system/files/documents/2016/09/15/aesec...
[3] https://www.commoncriteriaportal.org/files/epfiles/st_vid103...
[4] https://www.commoncriteriaportal.org/files/ppfiles/pp_skpp_h... Page 116
If you want enough infrastructure to, say, run a browser on one of thousands of undocumented processor models built by some company you've never heard of? Not gonna happen.
There are question marks over much of available RISC-V chips due to chinese producers, so maybe OpenPower based hardware?
Plus, the entire system (motherboard, etc) would need to be manufactured using a good supply chain.
Hmmm, this has probably all been thought through in depth before by others. :)
Educating and motivating users to use the features of such an OS in order to maximize its security (e.g., capability bits)?
So much harder. This is, in my opinion, the more insurmountable problem. Most users have no idea what a window manager is, much less how to change their window manager. Security requires someone to set the capabilities allowed based on what's needed, with fine grained security controls. That takes more time and effort. How many of you have deny all on site permissions in your browser, and only enable the ones you need for the sites you need them for? And we are the technical audience.
So step one of your new OS engineering process is to build a whole new software engineering paradigm, and all of the engineering tools to go with it, from the ground up, based only on research from like a dozen people that mostly ended around 1990.
The move to remove one ring level in intel chips was touted as to decrease complexity of the CPU chip and OS start times. That is not the only reason, there is a security reason as well.
Security is about making it hard on all surfaces to attack if feasible. If an OS hardens kernel to attack, then the attack moves to userland. See how virus and other attacks on BSD kernels work.
So the correct question is in the systems realm, can we come together to hardened both the Kernel and Userland equally?
There already exists some very secure operating systems, however that only solves the software part of the equation. Systems need hardware to run, and they come with firmware. Often the firmware itself is compromised, such as the firmware coming with most CPU’s, for example Intel Management Engine[^1], and the AMD Platform Security Processor[^2].
[1]: https://en.wikipedia.org/wiki/Intel_Management_Engine
[2]: https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo...
And how do you know you're running it?
"The firmware is open source" doesn't help. Can it securely attest it's running what you think it is?