One additional one:
- "Hardening". IIRC, Fedora is now/will shortly compile its
distribution with optional, compile-time hardening in effect by default.
This should provide improved protection for network and firewall appvms
which, in my case, may be up and running for days - meaning a compromise
may be in effect for days. Also, as they are appvms (and not dispvms),
any changes (e.g. additions) to the user side will be retained after
shutdown.
My ideal would be hardened microkernels running as dispvms - including
microkernel dispvms replacing network, firewall, whonix/TOR appvms. I'm
presuming that a minimal Fedora template is closer than Debian to this
ideal.
Regarding maintenance:
- IIUC Fedora remains the primary development OS for ITL, and therefore
the safest for newbies like me. The short maintenance period is a pita.