Are we defaulting to VM-level sandboxing before understanding the threat model? | Hacker News Reader