> Neither of them requires trusting application code, nor depending on its correctness.
I'm not speaking about trusting the application code. This is obviously not safe. I'm talking about trusting as few lines of code as possible, including the OS itself.
In other words, security-critical code should be minimized. For GNU/Linux, it's tens of millions of lines of code. You rely on their correctness. For Qubes it's about 100000: https://www.qubes-os.org/doc/security-critical-code.
I'm not speaking about trusting the application code. This is obviously not safe. I'm talking about trusting as few lines of code as possible, including the OS itself.
In other words, security-critical code should be minimized. For GNU/Linux, it's tens of millions of lines of code. You rely on their correctness. For Qubes it's about 100000: https://www.qubes-os.org/doc/security-critical-code.