The term "hardened" phone is a misnomer because when some OS claims to be hardened, you assume it is safe from all threats. But this is false as it depends on the threat.
For the average person, it may not even be a good idea to be using what is advertised today as a hardened phone since it is typically anti-government and will be in device blacklists in some countries.
Privacy hardened is a different animal so understand the differences and you don't need to make it too complicated. We will discuss who we need to harden against and what the solutions are for those threats.
Something very basic that the average person does not care about even if they knew about it. Your every click on a website is tracked. Every single one. How does this work? Surprisingly easy enough to understand yet apparently no one wants to explain this.
There are ways around this for the privacy conscious but the mechanics of the tracking has to be fully understood.
A rant. The most irritating thing for those of us who are privacy conscious are comments like "what are you hiding?" or "as long as you follow the law who cares?" or "you're paranoid".
I'm sure I'm not alone on this. Well, if you get irritated by this, then there is nothing wrong with you. Ignore these NPCs but you also need a smart understanding of why you do need to care and why these NPCs are the ones who are wrong.
The intent to scan content to counter end-to-end encryption is no longer theoretical with the passing of the UK Online Safety Bill.
How would the OS makers then build in client-side scanning? Let's tackle a theoretical project to do this on your favorite operating system (Windows, MacOS, iOS, Android).
This would be how I would do it.