I find it extremely plausible that there is no sandbox which can prevent programs from escaping, and that the same is not true of physical separation. (Obviously even physically separated machines are prone to problems too; but I believe it is possible to resolve them.)
Regarding 'don't be nihilistic', I really don't think that's what I'm doing; I'm suggesting a path forward, a different course of action. It doesn't seem any more nihilistic to say 'let's move away from shared hardware' than to say 'let's move away from md5'.
> I'm suggesting a path forward, a different course of action.
It's not a practical path for most people. It's expensive and very cumbersome. You effectively suggest to give up. Good sandboxing is much, much better than physical separation, because it's actually doable. I run Qubes as my daily driver. I can't imagine managing a bunch of machines.
Also, Intel ME is disabled and neutralized on my machine, Spectre is patched (and hyper-threading is disabled on Qubes). Such things are also extremely rare.
I don't really buy the arguments given there. All but the first of the 'cons' listed regarding physical separation apply equally well to virtual machines. There is a link to a longer paper; I will read it later; perhaps it has more compelling arguments.
> expensive
Most people are using phones and computers that cost hundreds of dollars. The cheapest raspberry pi is, what, $5? Getting a few of those would not be prohibitive for many people.
> very cumbersome
That is true, but we can do something about it. How cumbersome was it to habitually run software in vms, before qubes?
> The cheapest raspberry pi is, what, $5? Getting a few of those would not be prohibitive for many people
I have been informed that raspberry pis are hard to come by and are now retailing for close to $50. They have historically been cheap, and many other electronics are currently also quite expensive due to extenuating global factors; it seems likely that they will return to historical prices within low 1s of years.