An Open Dialogue on Truly Disposible Qubes

1. Isn’t implementing rules for BleachBit shred in dom0 an easier solution?

The challange is the in-system data sanitization (not the whole disk). Can the DISCARD command (fstrim) also mark Logical Block Addressing as unused without the inconvenience of deleting all data?



2. Regarding memory encryption, something that protects against memory corruption vulnerabilities may already be a step forward in Qubes:

Hardened Malloc