I have a sliding scale of devices I trust more or less (I trust nothing completely).
At the top of the trust scale is a self built desktop running fedora then way further down is my apple devices (iPads) and then even further down is my android phone.
Open source on hardware you control is the least worst option but since the hardware comes from abroad/countries I don’t trust much (including the US) not perfect.
This is in no way a solution to the population-scale problem of a belligerant nation having root on the citizenry's mobile phones/cameras/GPS units/network scanners
Soon thanks to Digital ID all your important business will have to go through the devices you trust the least.