I apologise for any misunderstandings I may have caused. Many thanks for all your explanations.
Again, I don’t doubt kuhbs. (I read the kuhbs page and looked at the github repo the first time I saw your topics hinting on it.) I doubt the possibility to set general ‘secure’ defaults for a general user base, preferably so called ‘newcomers’.
As a background notice: To some extent, I deal with people who are at risk of being duped (and help them). Most of them are what I would call ‘perpetual novices’ who only know how to press buttons, type on a keyboard, move a mouse, and swipe on a screen. They are not stupid. They just see computers and smartphones as tools. They are not interested in the technology itself. They just want to use their devices. So, when I talk about newcomers, I imagine them.
I would love to tell them something different, but that ‘newcomer’ attitude must stop if you are in the process of getting divorced or are serious about protecting your core business. (Just two examples of the situations I try to help with.)
Of course, better protect yourself against malicious e-mail attachments, better parse PDFs in a disposable. Storage protection by encryption is brilliant. Compartmentalisation all the way!
But a system with local access by an ‘unsuspecting’ (to put it politely) newcomer as the main user that’s when the real fun begins…
If newcomers/novices are really newcomers (or ‘noobs’, as mentioned above), there is no way to make anything more secure by simply using QubesOS without some training and additional learning. Even the most secure QubesOS setup could be easily compromised by a newcomer with admin rights if they are tricked into opening the gates.
“The manual said it was secure.”