The problem isn't the employee or the hiring process. It's the security infrastructure! One compromised account, supposedly from sales, shouldn't bring down the whole company.
The idea has been discussed. The main problem is that Mastodon is a zero-trust environment, and we can't trust the other server to send us the correct preview.
Question, Why encryption after quic. Well I know that quic 8s not adopted yet. But let's say if it does do we need the encryption provided inside webrtc. And whouldn't that be redundant. Spatially considering the whole point of RTC is to get a stream of data from one point to other as fast as possible.
The point is not to produce semiconductor that goes against the likes of TSMC but to decoupe the supply lines for critical application (military, governments) from one source. The same reason they and every other country is building a gps replacement
Not all linux kernel leak to host. Docker security is way better than nefore. And there also projects like podman and docker unprivileged that don't require any root intraction to set up a kernel