Hacker News new | ask | show | jobs
by microtonal 2550 days ago
So better (as said) is to use a separate VM to access trusted domains (and yes, also VMs aren't these days so trustable).

I would use the VM for accessing untrusted domains. If an exploit has your host system, then it also has the trusted VM.

ciphering on-disk sensitive info

If an exploit has root-kitted your system, encryption does not help much. Presumably you have the unencrypted volume mounted, moreover, the attacker could log keystrokes.

If your machine is compromized, it is basically game over. Change all your bank accounts, e-mail, etc. credentials immediately, wipe the disk. By suspicious about any file the malware may have touched.