some random hot take: qubes' biggest security feature isn't encryption or sandboxing. it's that it assumes your software will get _compromised_ and stops trying to prevent that. apps run in isolated qubes, so a compromise is contained by the hypervisor instead of giving the attacker access to the host's kernel. that boundary is enforced by Xen (there will be a reply guy saying "but what about Xen CVEs" lol) and _not_ by the app behaving itself. most OSes trust the kernel and everything running on it (and yes, this is fucking retarded). qubes assumes everything is hostile by default. that's the right threat model to work with. it moves the trust boundary one layer down. qubes is cool and secure. try it.