Sel :
Prefacing this by saying that this comment is not meant to be rude in the slightest. I just want to correct and point out things.
QubesOS is cool. It isolates apps in VMs, which is better isolation than what most other desktop OSes do. QubesOS still has several problems, though. The VMs are only as secure as the operating systems within them; the user has to know how to separate apps for the best security manually. On Android, for example, apps are sandboxed automatically. QubesOS also has poor boot security.
For OpenBSD i'll just point to this website: https://isopenbsdsecu.re/ with criticisms about OpenBSDs security. The main talk is from 2019, but the mitigations page still gets updated every now and then. The quotes page is also worth to check out.
Tails OS has no actual hardening. It just routes things through Tor and that's it. Nothing stops a compromise of a running Tails system. It's good for forensics though.
Secureblue (I actually use this fun fact). It does not make core system files read only and apply enterprise grade hardening. That's just not it. That's a benefit from being atomic, which is because it's based on Fedora, it's not a Secureblue feature. It's also entirely false. Malware can modify system files as long as root can do it. Malware also doesn't need to modify system files to be dangerous. Being atomic isn't a security benefit, it's a reliability benefit. Secureblue has other security features, and you mentioned none of them.
I have nothing special about Alpine, I just don't think it's hardened. It's just... Linux.
Whonix: it's not "mathematically impossible" for an exploit to discover your IP. Your IP is protected by the isolation between Gateway and Workstation, not math. (Well, I guess all tech is math in some way). It also removed a lot of the hardening it used to have. They had a hardened memory allocator and other features, but the main security engineer left, so now it's kind of meh.
2026-08-03 14:16:20