"The real threat model for buying privacy hardware online"
The real threat model for buying privacy hardware online
Most people shopping for privacy hardware worry about the wrong thing. They imagine an adversary intercepting their parcel, or a vendor selling their order history. Those are possible, but they are not the threats that actually burn people. The real risk lives in the gap between what a vendor claims is on the device and what is actually on the device.
Why the parcel is not the problem
Postal interception is expensive, targeted, and rare. Supply chain substitution is cheap, scalable, and documented. NIST's Mobile Threat Catalogue lists wholesale counterfeit firmware substitution during shipping channels as a recognised threat class — an adversary with access to the shipping channel swaps or reflashes devices in bulk, not one at a time. (NIST SPC-8)
That means the question to ask a vendor is not "will you spy on me?" It is "can I verify what you shipped, independently of what you say?"
What a trustworthy vendor provides
Before you buy any pre-flashed phone, SBC, or security gadget, the vendor should be able to hand you, without being asked twice:
- A signed build or image hash for the exact firmware installed, with the signing key published somewhere you can verify (keybase-style fingerprint or a PGP-signed release page).
- Chain of custody notes — who flashed it, on what host, on what date. "We ordered it from the official installer" is a claim; a hash you can check is evidence.
- A clean-start procedure. For phones this is the big one: GrapheneOS's own guidance is that a verified install from a trusted host beats trusting any middleman's flash. A good vendor tells you to reflash and gives you the steps rather than insisting you trust theirs.
- An attestation record — for supported devices, actual documented verification at intake, not a marketing badge.
- Payment paths that don't de-anonymise the claim. A privacy vendor that only accepts card payments tied to your full legal name is making a statement about their threat model, not yours.
The 10-minute verification ritual
You do not need to be a pentester to do this:
- Hash the firmware image the vendor names and compare it to the published (ideally signed) hash.
- On GrapheneOS devices, use the Auditor app to check hardware attestation after install.
- Boot the device with radios off and watch what it tries to contact. Odd beaconing to unexplained domains is a dealbreaker.
- Keep the box, the invoice, and the hash printout together. If anything is ever wrong, that's your evidence trail.
What we do differently
StealthOz ships degoogled phones built with the official installer only, and every unit ships with an attestation record and the firmware hash you should expect to verify after your own clean install. We would rather you not trust us than trust us wrongly — verification is a feature, and it costs us nothing to give you the tools to check.
Common failure modes we see
- The unverified flash. Customer buys a "GrapheneOS phone" from a marketplace reseller, installs nothing themselves, and later finds a microG build instead. No hash was published, so there's nothing to argue with. This is the single most common problem in the pre-flashed phone market, and it's why the attestation record matters more than the price difference.
- The mystery dongle. Accessories included "for free" that weren't part of the original bill of materials. Extra hardware in the box is either goodwill or something else; you can't tell which without documentation.
- The trust-me vendor. Any seller who responds to "what's the firmware hash?" with irritation has answered your question. Vendors who welcome verification are telling you something about how they run their operation.
Build the habit, not the paranoia
None of this means every vendor is an adversary. It means your security posture shouldn't depend on anyone's good behaviour — including ours. The right frame is: default to verify, and treat a vendor who makes verification easy as table stakes rather than a bonus.
That's also why we publish the flash procedure and the expected hashes with every order instead of keeping them as internal documents. If you're comparing vendors right now, use the checklist above as your scoring sheet — it takes about ten minutes per vendor and it disqualifies the sloppy ones fast.
If you're choosing between custom builds, start with the StealthDeck Lite — a budget degoogled phone that ships with exactly this documentation pack.