On desktop, use a recent Windows Secured-core PC, MacBook running on an Apple SoC or Chromebook. These all have numerous security advantages
such as good verified boot, a strict IOMMU, etc.
My personal recommendation is to acquire a Lenovo ThinkPad X1 Carbon.
The desktop security model is very broken. It was not designed with security in mind — security is only a poorly implemented
afterthought but there are some operating systems that are less bad in this regard. If you can, stay away from desktop and
stick to mobile devices.
Use Windows 11 Pro, macOS Tahoe, ChromeOS or QubesOS. Generally, these operating systems have made substantial progress on adopting modern exploit mitigations, verified boot, sandboxing, memory safe languages and so on.
Some of these operating systems do have some privacy invasive telemetry but it can usually be disabled in the settings and
verified with a network analyzer tool like Wireshark if you wish to be certain.
The security of QubesOS depends entirely on how you use it. The security within the virtual machines matter a lot — don't
neglect it. Make sure that you use secure guest operating systems and split everything between as many virtual machines as
possible. Virtualization can be a very strong security boundary but it is not magic. I'd recommend reading Brad Spengler's criticisms of QubesOS to understand some of its limitations.
Use Linux if you want an open-source, privacy-focused desktop operating system alternative.
There are some notable security concerns with Linux which you should be aware of. Despite these drawbacks, desktop Linux distributions are still great for most people who want to:
Mobile operating systems were designed with security as a foundational component. They were built with sandboxing, verified boot,
modern exploit mitigations and more from the start. They are far more locked down than other platforms.
Use either the stock operating system or preferably, GrapheneOS on a Pixel. Do not root your device, do not keep your bootloader unlocked and stay away from alternative operating systems like LineageOS as they substantially worsen the security model. Read
https://madaidans-insecurities.github.io/android.html for elaboration.
Alternatively, use an iPhone that receives the latest software updates. Do not jailbreak your phone.
Stay away from Linux phones.
Use Chromium based browser and avoid Firefox based browsers whenever you can. These recommendations allow auto-update and does it in a timely manner.
For secure browsing, use Vanadium. Available only for GrapheneOS. A hardened Chromium-based browser. One of its biggest benefits is that it disables JIT by default and since many browser exploits rely on it. You're more resistant to browser exploits. You can use this browser to login to your most sensitive accounts.
For anonymous browsing, use Tor Browser. It's preferable to use desktop for anti-fingerprinting. Android doesn't have the same kind of privacy protections as desktop and is best used for censorship circumvention.
For standard general browsing with a content blocker built-in and the same level of anti-fingerprinting protection as Tor Browser. Use Mullvad Browser (Best combined with a trustworthy VPN).
Use Brave if you want a privacy-respecting alternative to Google Chrome. It has built-in content blocker, auto-redirect tracking URLs, cross-platform and has fingerprinting protections that can fool naive scripts.
For iOS and iPadOS users, if you're outside the EU, you should only use Safari since the operating system uses WebKit framework for all browsers.
Use Signal, preferably with a VOIP number. If you're American or Canadian you can use Google Voice for free.
Turn on RCS messaging in Google Messages or iMessage as backup. Avoid using messaging apps that do not use end-to-end encryption by default.
Use Proton Mail or Tuta Mail. They both use zero-access encryption to protect data at rest, ensuring that even if servers are compromised, the provider cannot access the content. Whenever you can, avoid using email for sensitive communications and use a secure messenger.
Use a cloud-based password manager. These privacy-friendly options are
Proton Pass and
Bitwarden. These options are user-friendly, however you can still use Google Password Manager and iCloud Keychain if you're still in the Google and Apple ecosystem. A password manager is better than none.
Generate six words diceware passphrase for your password vault to make it random, strong and unique. Type it with repetition until it becomes muscle memory or write in a notebook stored securely.
if you want a local offline options; KeePassXC (Desktop), KeePassium (iOS, iPadOS & macOS) and KeePassDX (Android) are three good options. You're responsible for this data, so keep good backups.
Use a passkey if the website you login to allows the removal of passwords. Always have 2 or more passkeys for that website so you don't get locked out of your account. These are phishing-resistant and resistant to account takeovers since they cannot obtain your private key on the server when a service gets a data breach.
Use a dedicated TOTP authenticator app like Ente Auth (Cloud/Offline) or Aegis (Offline/Android). Do not use SMS for 2FA as it is vulnerable to simjacking and man-in-the-middle attacks.
Avoid whenever you can.