On 11/12/2016 03:21 AM, Sec Tester wrote:
> SELinux or AppArmor.

SELinux would be absofuckinglutely great.  Confined apps like Firefox
would run much more securely.

I got one DispVM owned by an attacker at Defcon in 2014.  Isolation was
nice to have because the machine didn't get owned, but the VM would have
never been owned if SELinux had been active.


