>>129 (OP)
Good post. Basically for an everyday driver system the best the world has right now is an x230 i7 laptop, with the bios flashed with heads which also removes intel management engine. Which you should do all yourself with your own flasher once you have the physical device. https://osresearch.net/x230-maximized-flashing/
Also buying parts such as ram and SSD should be in person with cash to buy stuff not tampered with. Flash the firmware of the SSD as well. So buy an ssd with updates available to be sure you're overwriting any funny business. But the laptop itself may be okay to buy online, again just flash it when you get it: https://osresearch.net/Vendors/ and https://www.qubes-os.org/doc/certified-hardware/
Once you receive the laptop part it out completely. X230s are only about 20 screws. Look for IO implants mainly on the video and keyboard lines https://en.wikipedia.org/wiki/ANT_catalog. Peel back all the EMF shielding and plastic on the board. Refer to schematics. Google for schematics to double check if there are any strange chips not accounted for in schematics and board photos available with image search on search engines. Need help: https://matrix.to/#/#OSFW-Heads:matrix.org
All good? Install qubes os. Preferably having traveled without a phone. Double check you weren't followed: Surveillance Countermeasures https://library.frenschan.org/book/8512 and Left of Bang for body language https://library.frenschan.org/book/8522 Don't watch youtube about body language those people are charlatans, even real glowies are pretty bad at body language and full of shit when you hear them speak about it, it's in their nature to lie to civilians so they pretty much omit important details or just make shit up on the fly because they think you won't understand regardless if it's truth or a lie. So, not followed? Pick up several USB sticks cash from random stores. Going to library. Verify the isos. Install tails. Reboot the library computer using your fresh tails iso.
Then use your verify tails sessions through a tor bridge to download your qubes iso. Going through the verification process: https://www.qubes-os.org/security/verifying-signatures/ Takes a ton of work, so take your time. Post on the forums.qubes-os.org for help. Then install your qubes. So about the iso problem? Your DNS was probably fucked with. Hacked system. So in qubes choose "update all qubes through whonix tor network" during installation GUI. I've actually seen tor installs fucked because glowies were on the network pushing false updates for the fedora templates which update through clearnet. So always do your updates through whonix. Also disable the clock sync qube sys-net to none. So it forces you to update the time manually. This is another trick the glowies use. Fuck with your time zone server, and push you out of date updates which have exploits as the first link in an attack chain. I've seen this happen in the wild as well.
So what about network? Qubes is pretty good in that it was designed assuming that our network is already hacked. But you want to secure your network anyways. Update all your switches to openwrt VLAN supporting switches. And heres the key. Convert them to serial only disabling ssh, and your http web gui after your setup. How do you setup? Do it through qubes. Mirror the repos in whonix https://openwrt.org/user/yeti/mirror-opkg-repositories , set you qubes as the server, use an extea USB NIC, change the settings in your openwrt to use your qubes as your repo server. do your plugins and setup. Then lock down the device to serial only. Which forces you to physically connect to the device. Can't get serial through ethernet.
The last but not least, want to be sure your network isn't hacked or get alerts when something is amiss? First look into https://en.wikipedia.org/wiki/RED/BLACK_concept and https://openwrt.org/docs/guide-user/security/security_guide_for_the_paranoid Requires your to have several switches and firewalls and out of band connections through serial. So basically if the first 1 or 2 layers of firewalls fails it will shut down your inner layer. For firewalls use OPNSense https://opnsense.org/ again with an extra x230 with two nics or buy dasharo devices with coreboot and install opnsense on these protectli devices with dasharo coreboot: https://docs.dasharo.com/unified/protectli/overview/ Cheap 2 ports are fine, use your switches to add more ports: https://protectli.com/vault-2-port/
Also add a few layers of hardware VPNS also using Openwrt between each layer of switch. Perhaps 1 VPN in front of everything, then a VPN behind your 1st firewall, so that your third vpn is software on Qubes, which also sits before your whonix connection. Look to Nanopi for cheap and powerful. Incorporate this into your red black engineering concept by programming your firewalls to detect VPN failure and to shut down the network and alert you. The opnsense and openwrt forums will help you get setup. Lainchain won't talk about Red black concept, among other atomic propagation. Because they're pathetic.
Last but not least, this is the glowies favorite PSYOP and that is KOMPROMAT https://en.wikipedia.org/wiki/Kompromat and how do you protect against it? Keep an out of band management auditing system on top of everything. Lest one of your devices gets hacked and started downloading illegal shit. So just an extra pi with wireshark or snort, little snitch or perhaps kali purple watching over as a last line for your legal defense at the front of your network using a passive network tap: https://hackaday.com/2008/09/14/passive-networking-tap/ so if all your defense fails and something transmits in plaintext, you have a record it wasn't you. Have a defense strategy with your lawyer. Explain prior to all these that you're doing research on extremism or ethnic religious groups. Explain your network setup, so that it would be impossible for anything to traverse to the ISP in plaintext, and if it did, you were hacked. By who? By everyone who hates white people. Simple as.
Again keep a timelog when you see CP on a thread. Report it. This is not illegal. It's not your fault. Don't let these glowies scare you. Anyways, so yea. When glowies say shit can't be secure... Actually I often thought this was a psyop. But I've actually come to find out most glowies networks are also very insecure, and so they're simply hoping you believe everything is insecure, but at the same time they don't really know shit themselves. And they leak shit like crazy. It's hilarious. Don't get me started on Indian Intelligence the new IDF lap dog by direction of US DoD. These people are a joke. That's why Hamas won. That's why Taliban won. Don't let them scare you. Instead prepare to enjoy watching them die when they try to bait China and the Middle East. Stock up on the popcorn boys. It's going to be a blast.
Also, these assholes shilling for telegram, that's a major red flag. They can debate all they want why telegram is better than XMPP or IRC and omit Simplex Chat, Cwtch or Mumble in their rebuttals, but at the end of the day, screenshot this post, that none of these people are on this level, and when somebody here says Telegram is okay, just know the experts have warned you, that they're fucking lying to you. And when they say nothing can be secure, well then why do SCIFs exist? What's the point of red black engineering? Why don't we get Tony blinkins emails leaked everyday? What about that senile fuck Biden, surely he would've fucked up once and we'd have a few of his emails by now? Why doesn't every single credit card transaction we do online get our money stolen? Truth is things can be secure. God I can't wait to watch these people die. They make me sick. Lies after lies after lies. Stay frosty boys \o