-
I would go even further: verifiable code makes the most sense on hardware that is itself intentionally simple so as to be more resistant to hardware failure. And that requires a small TCB to be workable. Trusted parts need to minimized in hardware AND software terms. @matthew_d_green/1106311212952895488