My first post here, and I am sorry if this has already been discussed but I like this comment: DisposableVMs: support for in-RAM execution only (for anti-forensics) · Issue #904 · QubesOS/qubes-issues · GitHub
FWIW, I really like the idea of encrypting volatile.img with a one-time key and then throw it away after the DispVM shutdown. Can we ensure the dm will never write the key to dom0 fs anywhere? Do we need to disable swap in dom0 for that?
There was another post here about running Qubes-VMs from a second encrypted SSD
hmm… and then wiping that partition? Seems better than the whole dom0 LIVE based approach which to me is overkill.