Best solution to me is to start a separate VM for removeble media and
let
it run as an unique "computer". Such a "computrer" would be visible
and
accessible through a "network".
This way we get a perfect "sandbox", of course.
(All of this is quite far from being implemented in curr. code,
though.)