So, folks adopt the (admittedly ridiculous, but, in the strict sense, necessary) 0-trust step of running everything in QubesOS, then in a VM, and maybe then in Docker.
Essentially each application gets its own fresh OS to fuck up or not...as it goes.
I get this (but I don't condone it). It's not practical for dev purposes, only if you are endlessly testing the waters for each little thing. But, prolly, eventually we will be wowed by a shiny-thing that achieves infinity-virtualization with bare metal performance but perfect isolation so we can easiily run
infinvm run github.com/malware/repo
And all will be right with the world.We ain't there yet tho. Hahaha :)
You probably instead should use a throwaway computer (or VM if you trust them), and not do anything personal on that computer, and then burn it.