I would not be sacrificing the sexiness of Apple hardware and software 😉 Yup, you heard me right; I admit I'm an Apple fangirl.
This more or less destroyed credibility. I find it very difficult to take seriously someone calling themselves a security expert who use's(ed) a Mac. Mac's are horribly insecure, Apple broke much of the BSD code to get the "it just works" feel.
Everything she described has already been done by Sun with the source code released to the world as OpenSolaris (prior to the Oracle purchase). You run a single global zone that manages hardware and user sparse root child zones to run your applications and servers. My job is basically to work with and design these Sun systems 40~60 hours a week and know how they work in and out. And they will accomplish everything she described. Have your internet applications inside one zone, and any other software inside another zone, you can even run Virtual Box and run Windows 7 inside it's own zone. All hardware is controlled by the Global zone with child zones only getting small bubbles to play in and a read only kernel file system (/usr, /lib, /platform, ect..) to use.