I would care less if i am running as unpriv. user on a system that is not network connected. I didn't mention that i'd never use a host with actual user data on it. I thought that would be clear because i was replying to Dabs' "frozen sysimage" approach. I would definitely not use a guest VM but a dedicated box that i can reset via dd or similar disc imaging tools, i wasn't clear on that, as i just recognize while typing this.
And yes, it's part of the very basics: there is no 100% security, only 100% security against certain (and therefor known) attack vectors.
I’m gonna say this one last time. Your postulated recovery is weaksauce against anything other than a disk-resident vector.
dd ain’t gonna do nothing for you if malware-containing USB infects the BIOS.
my bios has a reset to default button for times it all goes wrong. dont conflate things to 2 options when there are many more possibilities