The cake is a lie
Sergey Bratus, Peter C. Johnson, Ashwin Ramaswamy, Sean W. Smith, Michael E. Locasto · 2009
Components of commodity OS kernels typically execute at the same privilege level. Consequently, the compromise of even a single component undermines the trustworthiness of the entire kernel and its ability to enforce separation between user-level processes. Reliably containing the extent of a compromised kernel component is a problem to which few practical solutions exist.