Hacker News new | ask | show | jobs
by fsflover 1584 days ago
It depends on which sandbox you are using. In Qubes OS on desktop, you rely on hardware virtualization, which is virtually unbreakable.
1 comments

I thought Spectre and Meltdown also allowed host data leakage from a compromised guest?
Yes, microcode vulnerabilities is a problem indeed. Hopefully Qubes Air (next version 5.0) will compartmentalize even that by using separate devices as qubes: https://www.qubes-os.org/news/2018/01/22/qubes-air/.