I’ve seen a recent uptick in requests for more security in domUs (templates, mainly), but most if not all have been vague and uninformed. I’d like this, but the first step in asking them to work on this is to present clear, concrete goals.
If you want more template security, then give your reasons here.
Since I don’t see anything else that could be additionally protected against of that’s not already included in the stock minimals and Qubes as general, and I can’t imagine anything else beside compartmentalizing as much as possible the templates for the purposes m threat model is defined of, Iam all eager to hear what I’m missing.