Yeah, there's definitely a happy middle ground. I'm a firm believer in gaining a good understanding of your threat model before taking steps to protect it -- quite a surprising amount of people use Qubes, Graphene, Kicksecure and such without really understanding what they want to protect themselves against. In a lot of cases, that just adds unnecessary friction and overcomplexity that ends up doing more harm than good. I was guilty of this myself.
On paper, I'm sure Windows does have stronger userspace and kernel-space protections against intrusion and such, though I most certainly wouldn't use it.
Yeah, there's definitely a happy middle ground. I'm a firm believer in gaining a good understanding of your threat model before taking steps to protect it -- quite a surprising amount of people use Qubes, Graphene, Kicksecure and such without really understanding what they want to protect themselves against. In a lot of cases, that just adds unnecessary friction and overcomplexity that ends up doing more harm than good. I was guilty of this myself.
On paper, I'm sure Windows does have stronger userspace and kernel-space protections against intrusion and such, though I most certainly wouldn't use it.