Hacker News new | ask | show | jobs
by beagle3 3986 days ago
but why do you trust your hypervisor? QEMU had a floppy controller escape bug published last month. Xen has one today.
1 comments

By doing this the chain of things that have to be broken for an exploit to escape is getting longer.
So the best thing you can do is to nest different kind of VM hypervisors with different OS guests and read the pdf in the innermost machine.