http://treasurechest.i2p/setup.html
This gives me two key advantages: the host machine can filter network traffic to and from the VM, and thus continue to protect other machines, even if the VM is breached a virtual machine's state can be easily rolled back, to undo the effects of a breach Specifically, I'm using qemu with the '-snapshot' option, which keeps changes made to the VM in memory only. When I restart the VM, it's always back to its original state (this has the happy side-effect of making permanent logs impossible,...