logoalt Hacker News

dasyatidprimeyesterday at 7:53 PM2 repliesview on HN

I've considered this for consolidating core hardware, but dual-boot doesn't do trust boundaries well. The Windows kernel still has full block access to the other device, so if it gets admin-level malware, it has free rein to infect the other system. At one point several years ago I got partway through a plan involving having most disks be externally pluggable (and assuming that firmware-level malware persistence is unlikely, which I'm not as sure about these days) but gave up for unclear reasons. I think if I were to try that again (and if I had the hardware for it) I'd try some kind of NAS approach to separate storage credentials from the OS.


Replies

Neikiusyesterday at 8:28 PM

You could run windows in the VM. Pcie passthrough is a thing just be careful with the Mobo.

show 1 reply
kogiryesterday at 8:09 PM

With secure boot, full disk encryption, and robust backups, this risk should be largely mitigated, right?

That’s what I’m personally banking on. I think anyone with the resources to bypass these would first just use a rubber hose.

show 2 replies