If one is that concerned about someone exploiting an OS level security flaw to exfiltrate their online banking credentials (wildly unlikely), they should just be doing that stuff in a VM or similarly isolated environment anyways.
For a while, yes, but the browser being up-to-date doesn't make an EOL OS safe to expose to the Internet.
> If one is that concerned about someone exploiting an OS level security flaw to exfiltrate their online banking credentials (wildly unlikely), they should just be doing that stuff in a VM or similarly isolated environment anyways.
Just doing sensitive stuff in a VM isn't good protection at all, since a malicious host can trivially compromise the guest.
It can, Ubuntu runs just fine on it