The secure copy and paste feature always seemed to address the wrong threat model or use case for me. Sure, it's great that it keeps things isolated and compartmentalized across VMs, but it doesn't help much if you accidentally paste it into a phishing site. I wish there was just better browser integration for it, so you could have a password manager that could only access secrets on-demand + also automatically verify the domain or site you're trying to enter credentials into.
Anyway, still very cool stuff. I used Qubes for a few years before I made the mistake of purchasing a laptop that wasn't fully supported, but I often think about picking it back up or trying to install it again.