

Yes, this part is intentional to raise questions and remark :)
The certificate on my website is not valid using the WebPKI standard, but is valid using the DANE standard. It is related to my comment for this project https://sr.ht/~yukikoo/dane_without_root/ .
My issue with the WebPKI model is that any government or big company on the planet could do a MITM on your connection, generate a certificate valid for any website, and get a read/write access to all your webpki TLS communications. The DANE model is an improvement over webpki because instead of the “anyone (every ca / intermediate certificate) can generate a certificate valid for anyone” model, it bring a hierarchical trust structure.
I haven’t know that time. It is indeed now way less chunky than your screenshot. By default it use XFCE, but support also KDE, i3 and other. Before starting to use QubesOS I was on arch with i3, and I kept using i3 on QubesOS