> I believe Qubes OS followed that approach but it was awkward, limited, had major performance problems, and yet never managed to fully prevent circumvention.
Not sure what you are talking about. Qubes offers reliable protection with decent performance, unless you work with graphics. See also: https://news.ycombinator.com/item?id=49678250
De-jure it's against the ToS, but it's not being enforced besides "don't be an asshole, don't abuse the network and be careful with Signal branding". Technically, you can use Whisperfish on SailfishOS, Flare on mobile-linux-of-the-day or even signal-cli as a primary device.
I don't believe that they will use this against me. But I do believe in the right to use devices without backdoors for everyone, so I support something else instead.
Qubes can be used together with Heads and a hardware key to verify the boot integrity. Works for me. This is more than good enough for most users, unless you think that your device can be captured while being on by a state adversary I guess. Also it doesn't remove control from the user unlike with GrapheneOS.
The lack of root is only significant because unlike in other vendors the built-in backup doesn't work reliably, and you can't use third party software.
But I'm very hopeful, recently they released this Messages update, they're working on introducing native RCS somehow (no idea how but I wish them well), and they recently made a first-class automated call recording.
reply