Wednesday, April 30, 2014

IE critical zero-day exploit. Solution: Browser VM?

Windows XP Critical zero-day exploit - Internet Explorer all versions affected & no fix in sight - Stabley Times:

It may be time to "virtual-ise" web browsing.
The browser could run in a "thin" OS VM
with no access to local file system.

Windows 7 (pro) and newer already comes with HyperV,
and there are other free tools like VirtualBox.

This could be an opportunity to make ChromeOS or FirefoxOS
as a VM, essentially minimum Linux (or WinRT) kernel and a web browser.

Windows already had ability to run "compatibility mode" VM for single program.
It may be possible to make make similar for IE...

