http://forums.w5j6stm77zs6652pgsij4awcjeel3eco7kvipheu6mtr623eyyehj4yd.onion/t/block-browser-startup-in-template-vms/71
The update proxy is a minimal mitigation that requires applications to be configured to use the proxy but it is very easy to circumvent that. It is the bare minimal to avoid using a browser on the template as stated in that page. What I am thinking is that if this is done in Kicksecure then later moved to qubes package to templates, qubes-template-browser-block , they can remove the update proxy that does not guard much against anything besides the browser, the templates will be networked...