Hacker News new | ask | show | jobs
by serf 523 days ago
hardware key and physical attestation mechanism -> fde via key -> hosted encrypted userland or per-user virtualization.

it's not perfect and it's a lanky chain to keep maintaining, but it's not un-doable.