Replies (4)

For desktops/laptops your best bet is the fastest one you can get is an i5 Thinkpad T480. Ideally flashed by yourself and all that. for modern computers. Coreboot firmware with ME_cleaner, but with weaker ME disabling guarantees than libreboot. I wouldn't put my most sensitive stuff on these, but a great use case for something like QubesOS where you need lots of threads to maintain performance. Phones are mostly a lost cause until we can get free and open source firmware SoCs. GrapheneOS has great privacy guarantees on a software side, but the Titan chip is a major black box, same with the modem and the SoC as a whole.
Note too that when you get into firmware backdoors, you're getting into expensive targeted attack territory. Mainly with compromised trusted execution environments and trusted encryption chips. Passive surveillance is nearly impossible at this level and thus, for most threat models, a spyware free Linux distro and GrapheneOS is more than sufficient for extremely strong privacy guarantees for most. If you're hiding thousands of Monero from state actors then you're going to want Libreboot + Kicksecure live mode + Veracrypt hidden volume for wallet files or something similar. As your threat model decreases you can compromise on these measures.