my point was to limit access to tokens, segregate with different accounts for different apps, different computers or ISP if need be.

wall it off and dont trust VMs either. if you have something of value they can escape it.