> There's no security model for desktops that works well.
Qubes OS works quite well, if you need security on desktop.
Seconded. Been daily driving it on ThinkPads now for something like two years. I will never go back, and one of the few things which might draw me off Qubes OS is if OpenBSD cleanroom reimplemented Qubes OS with their own OS and hypervisor. (OpenBSD because nobody beats their long term code quality and consistency.)
Qubes has an excellent security model and should a top choice (if not _the_ top choice) for security-minded and technologically sophisticated users.
I used Qubes for a year or two, and then realized that my main use case was to isolated the browser, which to me was the greatest threat vector compared to everything else I use. Then I thought, if I just wanted a system with the browser isolated from my main Linux environment, wasn't that exactly what ChromeOS provided?
So I switched to ChromeOS and have stayed on it ever since.