Header illustration for "The real threat model for buying privacy hardware online"

"The real threat model for buying privacy hardware online"

The real threat model for buying privacy hardware online

Most people shopping for privacy hardware worry about the wrong thing. They imagine an adversary intercepting their parcel, or a vendor selling their order history. Those are possible, but they are not the threats that actually burn people. The real risk lives in the gap between what a vendor claims is on the device and what is actually on the device.

Why the parcel is not the problem

Postal interception is expensive, targeted, and rare. Supply chain substitution is cheap, scalable, and documented. NIST's Mobile Threat Catalogue lists wholesale counterfeit firmware substitution during shipping channels as a recognised threat class — an adversary with access to the shipping channel swaps or reflashes devices in bulk, not one at a time. (NIST SPC-8)

That means the question to ask a vendor is not "will you spy on me?" It is "can I verify what you shipped, independently of what you say?"

What a trustworthy vendor provides

Before you buy any pre-flashed phone, SBC, or security gadget, the vendor should be able to hand you, without being asked twice:

  1. A signed build or image hash for the exact firmware installed, with the signing key published somewhere you can verify (keybase-style fingerprint or a PGP-signed release page).
  2. Chain of custody notes — who flashed it, on what host, on what date. "We ordered it from the official installer" is a claim; a hash you can check is evidence.
  3. A clean-start procedure. For phones this is the big one: GrapheneOS's own guidance is that a verified install from a trusted host beats trusting any middleman's flash. A good vendor tells you to reflash and gives you the steps rather than insisting you trust theirs.
  4. An attestation record — for supported devices, actual documented verification at intake, not a marketing badge.
  5. Payment paths that don't de-anonymise the claim. A privacy vendor that only accepts card payments tied to your full legal name is making a statement about their threat model, not yours.

The 10-minute verification ritual

You do not need to be a pentester to do this:

What we do differently

StealthOz ships degoogled phones built with the official installer only, and every unit ships with an attestation record and the firmware hash you should expect to verify after your own clean install. We would rather you not trust us than trust us wrongly — verification is a feature, and it costs us nothing to give you the tools to check.

Common failure modes we see

Build the habit, not the paranoia

None of this means every vendor is an adversary. It means your security posture shouldn't depend on anyone's good behaviour — including ours. The right frame is: default to verify, and treat a vendor who makes verification easy as table stakes rather than a bonus.

That's also why we publish the flash procedure and the expected hashes with every order instead of keeping them as internal documents. If you're comparing vendors right now, use the checklist above as your scoring sheet — it takes about ten minutes per vendor and it disqualifies the sloppy ones fast.

If you're choosing between custom builds, start with the StealthDeck Lite — a budget degoogled phone that ships with exactly this documentation pack.

← All posts