Assume at all times that the box is toxic waste and that is an entry point into your network. Leave it isolated. No port forwards, you already have tunnels for that, don’t use it for DNS don’t use it for DHCP, Don’t allow You’re network users or devices to see ARP traffic from it.
I used to have a separate box, but the only thing it did was port forwarding
Specifically i don’t really understand the topology of this setup, and how do i set it up
I personally don’t use anything of google, browsing and trying apps from fdroid, and have obtainium for the ones I usually use
But Graphene’s approach is all about security, and privacy only after it So they recommend the most secure options first, and don’t recommend minor options So, their current opinion on fdroid that it’s less secure than googlag’s store, so a more secure option would be googlag, or that second store that has 3 apps in it
But it’s for “marketplace” apps, so obtainium not in the scope, but kinda should be (we just need to rethink where we get our apps from)
Some people say it’s your IP, but actually IP is rarely used for tracking
On the way to privacy there are some things you should know:
Companies know who are your friends, especially if you communicate on the same messaging apps, etc
Also they have your location
And it seems like apps and Instagram are always listening (so if you say “pizza, pizza, pizza, I really like pizza, I really want to buy pizza now around me” you will get an ad with pizza)