Working Draft

This guide is in development. The steps below are sound, and the verified full release, checked line by line against current settings the way the removal guide was, ships here when ready.

PDN-G02 / Guide

Phone Hardening Checklist.

One hour with a charger nearby, and the richest node in your exposure web goes quiet.

Time
About one hour
Difficulty
Easy
Cost
Free
Threads cut
Phone / Photos / Purchases

Your phone is the richest single source in the exposure web. It knows where you sleep and who you talk to, what you buy and what you photograph, and by default it shares more of that than most people would ever agree to out loud. This checklist closes the leaks in one sitting. Work top to bottom. Menu names shift slightly between iOS and Android versions, so where a path differs from what you see, search the settings app for the term in bold.

Before You Start

Set aside one uninterrupted hour with your phone and a charger. Nothing here breaks your apps. A few steps trade a little convenience for a lot of exposure, and each one tells you the trade so you can decide.

Section 01

The lock and the account behind it

Everything else fails if the front door is open or the account above the phone is weak.

Set a strong screen lock
Use a six-digit PIN at minimum, an alphanumeric passcode if you can live with it. Fingerprint or face unlock on top is fine for daily use.
Why / Four digits fall to guessing and shoulder surfing. The passcode also encrypts the phone.
Lock down the account above the phone
Your Apple ID or Google account controls the device. Give it a long unique password, turn on two-factor authentication, and review the list of signed-in devices and sessions, removing anything you do not recognize.
Why / Whoever holds this account can track the phone and read its backups, or reset it outright.
Silence the lock screen
Turn off notification previews on the lock screen, and disable access to the voice assistant, wallet, and control panels while locked.
Why / A locked phone that reads your messages aloud to anyone holding it is locked in name only.
Set a SIM PIN and a carrier account PIN
Add a PIN to the SIM card in phone settings, then call or log in to your carrier and put a security PIN or port-freeze on the account itself.
Why / SIM-swap attacks move your number to a stranger’s phone and catch your texted login codes with it.
Turn on automatic updates
Enable automatic system and app updates.
Why / Most real-world phone compromises exploit holes that a patch already fixed.
Section 02

Location

Location is the most valuable thing your phone leaks and the reason a weather app can know where you sleep. The Fog Reveal case study on this site shows where that trail ends up.

Audit location permission app by app
Open the location permissions list and set every app to While Using or Never. Almost nothing needs Always. Turn off Precise Location for any app that only needs your general area, like weather.
Why / Apps with background location build a diary of your movements, and some sell it.
Shut off the system location logs
On iPhone, find Significant Locations in privacy settings and turn it off. On Android, find Timeline or Location History in your Google account settings. Turn it off, then delete the history.
Why / These features keep a long-term map of everywhere you go, stored under your identity.
Strip location from your camera
In camera or photo settings, turn off location tagging for new photos. On iPhone this is the camera’s location permission; most Android cameras have a location toggle in the camera app settings.
Why / Coordinates ride inside the image file. The photo metadata read on this site shows how one picture located a fugitive.
Check location before you share
When sharing an existing photo from an iPhone, tap Options at the top of the share sheet and switch location off. On Android, use the share or edit menu’s remove-location option where offered.
Why / Old photos already carry coordinates even after you fix the camera going forward.
Section 03

The advertising identity

Your phone carries an ID number built for advertisers. It is the thread that ties your app activity into one sellable profile, and you can cut it.

Refuse app tracking requests
On iPhone, set Allow Apps to Request to Track to off, which auto-denies every app. Deny any that already asked.
Why / This blocks apps from tying your activity to the cross-app advertising identifier.
Delete or zero the advertising ID
On Android, find Ads in privacy settings and choose Delete advertising ID. On iPhone, turn off Personalized Ads in the Apple advertising settings.
Why / Location and habit data is matched to you through this ID. Removing it breaks the join.
Cull the data-seller apps
Delete apps you do not use, and be ruthless with free flashlights, weather apps, coupon apps, and games that demanded location or contacts.
Why / Free utility apps are a classic front for location harvesting. Fewer apps, fewer leaks.
Section 04

Permissions and radios

Beyond location, every permission and radio is a channel. Give each app the minimum and make your phone quieter on networks.

Run a full permission audit
Open the privacy or permission manager and review microphone, camera, contacts, photos, Bluetooth, and local network access app by app. Where offered, grant photo access to Selected Photos only.
Why / An app with your contacts uploads your friends. An app with full photo access can read every image and its metadata.
Randomize your Wi-Fi address and stop auto-joining
Confirm Private Wi-Fi Address (iPhone) or MAC randomization (Android) is on per network, and turn off auto-join for public hotspots.
Why / A fixed hardware address lets stores and sensors recognize your phone as it moves through the world.
Turn off analytics sharing
Disable the share-analytics, diagnostics, and personalization toggles in privacy settings for both the operating system and, where present, the browser.
Why / Telemetry is another quiet channel describing how and where you use the device.
Section 05

Messages and codes

What you say and the codes that guard your accounts deserve better than the defaults.

Move sensitive conversations to Signal
Install Signal and use it for anything you would mind being read. It is free and open source, end-to-end encrypted by default, and both EFF and Privacy Guides rate it the standard.
Why / Ordinary texts cross the network readable, and carriers keep records.
Get login codes out of your text messages
Wherever an account offers it, switch two-factor authentication from SMS to an authenticator app or a hardware key.
Why / Codes over text fall with your phone number in a SIM swap. App-based codes do not.
Encrypt your cloud backup
On iPhone, turn on Advanced Data Protection for iCloud. On Android, confirm device backup is on with a screen-lock-protected encryption, which is the modern default.
Why / An unencrypted backup is a complete copy of your phone held where a password reset can reach it.
Verify

Prove it worked.

Take a fresh photo and share it to yourself by email, then check the file for location data with any metadata viewer: it should show none. Open your location permission list: nothing should say Always that you did not consciously choose. Ask your carrier to attempt an account change without the PIN: they should refuse. Put a quarterly reminder on your calendar to re-run Sections 02 and 04, since app updates quietly re-ask for ground.

Go Deeper

Where this knowledge comes from.

This checklist draws on the public work of the Electronic Frontier Foundation’s Surveillance Self-Defense and Privacy Guides, whose tool recommendations informed ours, alongside Darkveil practice. The threat-modeling mindset throughout is adapted from EFF’s Surveillance Self-Defense, published under a Creative Commons Attribution license. Both are worth your time, and both are free. Everything above is written by PDN in our own structure and words, verified against current practice.

Past the DIY Line

This guide covers what you can do yourself. When the situation is a stalker or a public role, a threat that stays, that is Darkveil's work.

Talk to Darkveil