Hacker News new | ask | show | jobs
by Reddit_MLP2 139 days ago
but if the host OS is already comprised, what is the point of sandbox inside of it?
1 comments

Maybe we need secure attestation for sandbox to be protected against compromised host :)

It does sound hard, and might need to employ homomorphic encryption with hw help for any memory access after code has been also verifiably unaltered through (uncompromised) hw attestation.