> I am not so sure I would want a JavaCard VM on the very heart of my TCB.
> BTW, I think nCipher is/will be selling a device that supports Java[Card?].
> You might want to look into that.
Right, at RSA I spoke with someone from ncipher who said they'd be
exporting their raw hardware interface in an upcoming product, but
it probably won't be out until he summer.
I wouldn't necessarily trust a javacard vm at the core of my TCB, but I'd
be a LOT happier verifying a tiny javacard vm myself, then writing java
(which is comparatively hella easy to verify), than having to audit
C code anew for CP/Q on the IBM, something else elsewhere, etc.
--
[EMAIL PROTECTED]
http://www.venona.com/rdl/
1024D/4096g 0xD2E0301F B8B8 3D95 F940 9760 C64B DE90 07AD BE07 D2E0 301F