I would guess the best approach is to try to have as small an attack surface as possible, meaning as few applications etc, and the simplest possible operating system.
Like for example a minimalist build of the PinePhone with software that literally never updates unless there is a security issue. Maybe something like a stripped down Slackware, or I was gonna say OpenBSD where even the proprietary hardware drivers are re-written to be open source (and free), but I guess for the PinePhone, the hardware is already open anyways.
Like for example a minimalist build of the PinePhone with software that literally never updates unless there is a security issue. Maybe something like a stripped down Slackware, or I was gonna say OpenBSD where even the proprietary hardware drivers are re-written to be open source (and free), but I guess for the PinePhone, the hardware is already open anyways.
edit: A stripped down Slackware I should say