>People forget that only a few years ago have we decided that the kernel now has to protect userspace programs from malicious hardware. That's a major shift in thinking, now data that we used to blindly trust can not be trusted at all.
How come this wasn't being done already? Wouldn't you want drivers to do safety checks on everything, in case of a hardware failure? Or does this refer to something else, besides safety checks?