Use Intel SGX for better isolation
Originally created by @cypherpunks on #10484 (Redmine)
Intel SGX is a hardware-assisted technology for isolation, allowing processes to keep secrets from each other and even from rootkit/antivirus/OS/hypervisor and ensure integrity. In fact it is highly bound with Intel keypair (Intel can break the REMOTE ATTESTATION because it has private key), but you don’t need to use remote attestation, that’s why this is unrelevant for our case.
The disadvantage is that you would have to change design of all the applications to make use of this technology.