The cypherpunks won the right to strong encryption. This is the companion question: given that you have it, what does actually using it look like in hardware, and - more importantly - what does each piece of kit not do?
Most "privacy setup" guides are useless because they skip the only question that matters: secure against whom?A measure that defeats a phishing crook is theatre against a nation-state, and a measure that frustrates a nation-state is pointless overkill against a jealous ex reading your unlocked phone. There is no such thing as "secure." There is only secure against a specific adversary doing a specific thing.
So this is a field guide with the marketing removed. Every item says what it stops, and every item says what it does not. If a section sounds less impressive than the box copy, that is the section doing its job.
//Start With the Threat Model, Not the Gear
Before any purchase, answer four questions honestly:
Who is your adversary - an opportunist, someone who knows you personally, local law enforcement, or a state intelligence service? What do they want - your accounts, your location, your messages, your identity? What can they do - guess a password, seize the device, compel a company, run a fake cell tower? And what does it cost you if they succeed?
The honest answer for most people is the first tier: opportunists and people who know them. That tier is cheaply and completely defeated by boring measures - a password manager, hardware-backed two-factor, full-disk encryption, a lock screen. If that is your threat model, you can stop after the next two sections and you will have solved your actual problem. The exotic gear below is for higher tiers, and it comes with tradeoffs most people should not pay.
//The Account Layer: Hardware Security Keys
The single highest-value piece of hardware for almost everyone is a FIDO2 / WebAuthn security key - a small USB or NFC device (YubiKey and similar).
What it stops:phishing, comprehensively. A hardware key signs a challenge that is cryptographically bound to the real site's domain. A phishing page on a lookalike domain gets a signature that is useless to it, because the browser will not release a valid response to the wrong origin. This is the property that SMS codes and authenticator-app TOTP do not have - both can be typed into a fake site by a fooled user, and phishing kits relay them in real time. A hardware key cannot be relayed, because the domain check happens in the protocol, not in the user's judgement.
This connects directly to the phishing and credential-theft campaigns covered elsewhere on this site. The reason attackers still get MFA codes is that most MFA is phishable. This is the MFA that is not.
What it does not do: nothing for a compromised device that is already unlocked and authenticated. Nothing for data at rest. Nothing if the service lets you fall back to SMS recovery - which many do, quietly reopening the hole. It protects the login, not the machine.
//The Device Layer: A De-Googled Phone
GrapheneOS is a hardened, de-Googled Android that runs on Google Pixel hardware - which it uses specifically because of the Pixel's security chip and long guaranteed firmware support.
What it stops: a great deal of the commercial data-collection layer. No Google Play Services by default; apps run without the ambient telemetry baked into stock Android. Strong verified boot and full-disk encryption tied to hardware, per-app permission controls including network and sensors, and a strong defence against physical device-extraction tools of the kind law enforcement uses, because of how it handles encryption at rest and PIN-guessing throttling.
What it does not do, and this is the part the enthusiast guides skip: it does nothing about the cellular baseband or your carrier. The modem is a separate processor running its own closed firmware, and GrapheneOS sandboxes it from the main system but cannot rewrite what it is. Your carrier still sees which towers you connect to, which is a continuous record of roughly where you are. That is metadata, it is generated by the act of having a working phone, and no phone OS fixes it. GrapheneOS narrows the software attack surface dramatically; it does not make you invisible to the network.
One live caveat: the hardware dependency is real and fragile. Coverage tracks specific Pixel models and their security-chip generations, and reporting through 2026 has flagged uncertainty around newer devices as hardware changes. Check current supported-device status before buying anything for this purpose.
//The Radio Layer: What Actually Leaks
A powered phone is a set of radios announcing themselves: cellular to towers, Wi-Fi probing for known networks, Bluetooth beaconing, GPS receiving (and often feeding location back through apps). Each is a separate tracking surface.
Faraday bags block all of it by putting the device in a metal-lined enclosure that radio cannot cross. Inside a good bag, the phone is off the grid: no cell, no Wi-Fi, no Bluetooth, no GPS.
What they stop: live tracking and remote access for exactly as long as the device is inside and the bag is sound. Genuinely useful for a specific meeting, a border crossing, a protest - a bounded window where you want a device to exist but not to be locatable.
What they do not do:anything once the phone comes out. The moment it leaves the bag it reconnects, re-registers with the network, and the location gap is itself visible in the carrier's records - a phone that vanished for two hours and reappeared is not invisible, it is conspicuous. A bag is a tool for a window, not a way of life. And a cheap or worn bag can leak; the seal is the whole product.
Detecting the fake tower: Rayhunter
The threat in the other direction is the cell-site simulator - an IMSI catcher or "Stingray," a device that impersonates a cell tower so nearby phones connect to it, revealing their identifiers and sometimes getting downgraded to weak 2G so their traffic can be intercepted.
In March 2025 the EFF released Rayhunter, an open-source detector that runs on a cheap Orbic mobile hotspot - about $20 of hardware. Rather than trying to decode anyone's traffic, it watches the control channel between the hotspot and the tower and flags the tells of a simulator: a base station trying to downgrade the connection to 2G, or requesting your IMSI under suspicious circumstances. It works on modern 4G, where older detectors only handled the largely-retired 2G network.
What it does: gives an ordinary person, for the first time cheaply, evidence that a cell-site simulator may be operating nearby. That is a real shift - this capability used to require expensive specialist gear.
What it does not do: it detects, it does not protect. It flags suspicious tower behaviour; it cannot stop your phone connecting, and a flag is a heuristic, not proof. It is an early-warning sensor, and worth understanding as exactly that.
//The Lesson The Cypherpunks Already Knew: Metadata Wins
Every layer above runs into the same wall, and it is the one the cypherpunks named thirty years ago. Encryption protects content. It does almost nothing for metadata - who talked to whom, when, from where, how often, for how long.
Signal encrypts your messages so well that Signal itself cannot read them. But the fact that your phone maintains a data connection, connects to specific towers, and lights up at specific times is generated by the infrastructure and is not yours to encrypt. Metadata is frequently more revealing than content: you do not need to read the messages to learn a great deal from a record of a series of calls between a journalist, a government office, and a law firm at 2am.
This is why the honest version of "going dark" is modest. You can make your content unreadable. You can narrow your device's attack surface. You can blind a live tracker for a window. What you cannot do, as an individual using the normal network, is stop generating the metadata that comes from participating in it at all. Tor and mixnets attack exactly this problem and are the right tool when metadata is the threat - and they come with their own costs and their own limits, which is a piece of its own.
//What To Actually Do
Everyone: a password manager, a hardware security key on your important accounts, full-disk encryption on, a real lock screen. This defeats the threat that actually applies to almost everybody, and it is cheap and boring. Do this first, and be honest that for most people it is also last.
If your threat model is genuinely higher - you are a journalist, an activist, a target - then a de-Googled phone, compartmentalised devices, a Faraday bag for bounded windows, and an understanding of the metadata problem all start to earn their cost. But adopt them because you named a specific adversary and a specific capability, not because the gear feels serious.
Never confuse tools with a threat model. The most secure-looking kit in the world, bought without knowing who you are defending against, protects nothing in particular. Start with the who. The gear is downstream of the answer.
//Sourcing and Uncertainty
FIDO2 / WebAuthn's origin-binding anti-phishing property is a documented feature of the standard. GrapheneOS capabilities and its Pixel hardware dependency are from the project's own documentation and 2026 device-status reporting; treat the specific supported-device list as the thing most likely to have changed since writing. Rayhunter's detail - EFF, released March 2025, Orbic hotspot at roughly $20, control-channel analysis for 2G-downgrade and IMSI-request tells, 4G-native - is from EFF's own announcement and project documentation.
The interpretation is mine: the insistence on threat modelling before hardware, the tiering of adversaries, the framing of a Faraday-bag location gap as conspicuous rather than protective, and the argument that metadata is the wall every layer hits. The metadata point itself is not mine - it is the cypherpunks', and it has aged extremely well.
Deliberately not covered: specific product recommendations by brand beyond naming the reference implementations, and step-by-step configuration, both of which date fast and belong in maintained documentation rather than an article. The threat-modelling method does not date, which is why it is the spine of this piece.