If the workstation vm is pwned what stops it from hitting the usual home router internal network address and/or changing the route?
Is there some network isolation going on which prevents that?
Is there some network isolation going on which prevents that?
Is this some kind of 'vm specific' virtual network which can't talk on the real lan? Is that implemented on the hypervisor?
Edit: I forget that I'm writing on HN. When I say VM, I'm referring to full OS-level VMs, not namespace, Java, etc VMs.
That's a bit of a nonstarter for a few of.
We probably aren't the target base for the project though so maybe it doesn't matter...
Years ago, I created a LiveDVD with VirtualBox plus Whonix gateway and workstation VMs. I had to hack at both Whonix VMs to reduce size and RAM requirements. But I got a LiveDVD that would run with 8GB RAM. It took maybe 20 minutes to boot, but was quite responsive.