Some people recommend running any essential windows applications under a severely restricted user account, just for wine. Using chroot too would make an even more restricted environment that can be disposed of, if malware is suspected.
Has anyone come up with a systematic method for determining the absolute minimum of files and hardware access required by an application? You guys creating extensions must have a method. Surely there is more to it than just looking at file access timestamps? How would you tell what hardware access is required?