|
|
|
|
|
by ethbr1
1 day ago
|
|
You can't have full general purpose computing on a system and perfect isolation for free. By definition, the latter implies limits on the former. Either you have complete freedom to run whatever you want, however you want, or you enforce limits to guarantee system behavior and enforce isolation. And if you do the latter... then you don't have the former. |
|
Last VM escape in VT-d was discovered in 2006 by the Qubes founder, so I really feel safe on Qubes, https://en.wikipedia.org/wiki/Blue_Pill_(software)