

Absolutely in favour, the non-free blobs are a persistent thorn in my side. I myself have always been tempted to replace all the fedora and debian templates with alpine or OpenBSD to get smaller VMs (and without systemd), built as many things as unikernels as possible (e.g. the MirageOS firewall), and I’d love if X11 got replaced with Wayland (that one is hard, the X11 modifications are kind of the core of what Qubes provides).





I personally go with QubesOS which uses VMs to compartmentalize. It doesn’t reduce the risk of a supply chain attack itself (fedora & debian by default), but if your VMs only contain the bare minimum for a given task the risk of having a compromised package installed is lower than in a full-featured system and any compromise is also contained to that VM.