On Sunday, November 13, 2016 at 7:51:09 PM UTC-8, Manuel Amador (Rudd-O) wrote:
> On 11/12/2016 03:21 AM, Sec Tester wrote:
> > SELinux or AppArmor.
> SELinux would be absofuckinglutely great.  Confined apps like Firefox
> would run much more securely.
> I got one DispVM owned by an attacker at Defcon in 2014.  Isolation was
> nice to have because the machine didn't get owned, but the VM would have
> never been owned if SELinux had been active.
Why not grsecurity/PaX? especially with Qubes 4 switching to HVM (or PVHv2 or 
whatever it's called now), it will apparently work fine.

