I haven't had that problem. There's no GPU acceleration, so anything heavy on the GPU is a problem, but in terms of general use, I don't find it slower than Linux on the iron.
> and to make it usable you have to keep relaxing the security to the point where it is probably less secure than regular OS.
How so? What settings? I don't run with a USB Qube all the time for just my HID devices, but I light it up when I'm doing anything else on USB. I haven't had issues with having to turn down a bunch of security settings either.
> And don't even bother if you have to use scaling other than 100%, sure you can scale the DOM0 but the rest of the VMs are not scaled and there is no documentation on how to do it.
Yes there is. https://github.com/Qubes-Community/Contents/blob/master/docs...
> What we need are simple sandboxes that isolate GUI applications into chroot environment and keep them away from other applications and documents.
The history of local root exploits ("Cheap and easy!") would argue that doing such a thing and relying on the kernel is just security theater.
it may not be perfect but surely its better than nothing. it wouldn't protect you from a sophisticated nation state attacker, but most people don't have that in their threat model. surely it would be good enough to prevent google chrome from snooping through your home directory and other such things.
You want firejail, I think; this is one of its headline features. (Or possibly bubblewrap.)
Bubblejail is an acceptable alternative https://github.com/igo95862/bubblejail
Also, bubblejail ships all of 8 profiles; I'm skeptical of its claim to be a full replacement.