Just wanted to share my setup and see if anyone has suggestions or feedback. Also share yours.
Phone : GrapheneOS(pixel 7a)
- 
No google play service on my main profile. Rethink DNS (NextDNS DoH) blocks ads, trackers, and all Google & Facebook DNS (except WhatsApp). 
- 
Some FOSS apps like Aurora Store & NewPipe need Google servers, so I have excluded them in rethink dns. 
- 
Work Profile (with Island) with GrapheneOS’ sandboxed Play Services, but I use it maybe once or twice a month only for apps that absolutely need it. It stays turned off most of the time. If an app works on main profile without any issues, will use it. If not, will try to use it in firefox (as lack of play services doesn’t matter). If only app is available (and not web version) and it doesn’t work on main profile, will use it in work profile. 
- 
Hardened Firefox fork(Ironfox) for private browsing. Main Firefox for a few services where I have to stay logged in and don’t have apps or want to use their apps. 
- 
Network & Sensor Restrictions: If an app works offline, I block its internet access. Also, disabled sensors for apps that don’t need them. 
- 
Mostly use foss apps from f-droid(droidify). 
- 
Email: moved from gmail to protonmail 
PC/laptop: Arch linux kde on pc and fedora kde on laptop.
- Not much to say. Most used apps are firefox and Zed. I allow data collection on kde as I want them to improve it.
Home Server: Raspberry Pi 4B
- SSH hardening: Non standard ssh port(yes, I opened the port externally because I depend on my home server and need to access it remotely). SSH keys or password+totp, Fail2Ban, ufw.
- Services running: Arr setup(jellyfin, prowlarr, radarr,sonarr, qbittorrent), pihole, Immich, Authelia(for now). All data sensitive services behind authelia with totp.
- Nginx Geo-blocking: Only allows access from my country IPs
- Weekly backups because data loss sucks.
Network & Router: OpenWRT (TP-Link)
- Not much to say: Running default firewall rules with network-wide ad/tracker blocking via pihole and some ports opened.


Not much
I mean, there is a 2FA app and the few mandatory apps I must have access to (finance, and banking) and that is it. No social, no games, no nothing. Not even email is configured on that trash piece of corporate spyware. I sincerely consider it a threat to our privacy so I don’t trust it beside what I have no option to trust it with. I also suppose that this device, even though I deactivated the setting, is constantly listening to what we say nearby. So, when I don’t need it, I store it in a thick box to reduce whatever it may be recording.
Another use case for your phone: encrypted backup for docker containers ! Nowadays they come with a lot of spare space (over 120 GB). Encrypted, scrambles file/directory names and archived !
I wouldn’t backup any critical data this way though ! It’s more an “in case” emergency backup for docker database and config volumes !
I’ve heard the name, but don’t know what a docker is used for. Kinda like a vm? Not really a geek, I’m afraid ;)
Ohhhh ! Docker container are awesome. If you have an old spare laptop lying around (or you know someone who has) give it a try it’s fantastic ! It similar to a virtual machine but different ! It solves the big issue virtual machine have: fast, portability, lightweight, memory efficient… It shares the underling OS !
I have a 10 years old laptop which is going strong with over 21 docker containers which couldn’t be possible with VMs ! You can host any imaginable service (if available as docker image) in seconds, behind a reverse proxy and access it through your LAN (or externally over a Wireguard connection).
Let’s take a media workflow example, if you want to get rid of something like YouTube music, spotify, deezer… and maintain your music library and own your music:
You can self-host:
Install NewPipe (Hope you’re on Android :s) and HTTP-shortcuts to glue everything together ! HTTP-shortcuts allow to communicate with your self-hosted MeTube service via POST/GET requests and send directly your files to your MeTube instance via NewPiped. You can than have a background script on your server which: Removes and changes the pesky YouTube metadata, send your files to your Navidrome service !
This is a rather “complex” workflow but just to say it’s possible. Sure depending your skills with your OS it will take some time to get accustomed to docker containers and the like ! It took me approximately 1 year to really get accustomed to all this new workflow (and get the hang of linux), but now it’s only a matter of minutes !
Thx a lot for the explanation :)
I’d wrap it in a towel inside the box. Have you considered making a DIY Faraday cage? I’ve been thinking about it but my physics isn’t very good
I may consider doing that, thx.
Lul why downvotes? Seems like a good setup
Either someone randomly downvoted (ok, bye). Or someone thinks downvoting me is punishing me in some way for daring say something they don’t agree with (no idea how that could be punishing me, but hey). Or someone is too lazy to explain their reasoning. In any case, I don’t think it’s worth much consideration.
And, yep, as far as I’m concerned I consider this an OK approach. Not faultless, but usable ;)