> Designing a properly authenticated way to allow doing so would be an interesting challenge.
Qubes OS solved this problem. I don't see any flaws in their security model relying on vurtualization.