Hacker News

Favorites Setup
Comment by sdcfgy | original | Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
[−]sdcfgy · 2026-08-30 Sun 13:33 UTC · link
I think it's pretty much spot on myself and applies to more than virtualization based on the last point. It really suggests that further complexity and abstraction is not a good security posture. And I agree with this from extensive experience (embedded, defence).

Regarding the two decades since and the numerous exploitable x86-64 and hypervisor bugs suggests he wasn't wrong and that the tone was appropriate for the severity of the problem.