I use the two with uBlock Origin instead (so I can choose to go there still), and there were some sites that does have proper information blocked there.
isn't it possible to configure it so that only one of my machines is able to connect to the target machine (and not the other way around)? not sure how that's problematic.
i never used rustdesk so can't comment on that..
i also use reverse ssh to forward the target machine's port to mine when i can't use tailscale.
true, but it's hard to diagnose chromeos when things go wrong, also can't use ublock origin or any random ancient windows software one may need. (that usually works fine with wine)
have tailscale installed on their machine, and ssh/vnc(x0vncserver or x11vnc) daemon running on it. when they call you for help you can just login directly and navigate them through stuff.
i root with magisk and use afwall and adaway to block stuff. maybe not the most secure but it's pretty private, at least i know there's no weird network connection happening without me knowing.
it all depends on your threat model, but IMO your idea is decent. personally i'd rather have another lineageos phone for calls, since the iPhone's phone app sucks (no call recording) and it being connected to the internet means it can be tracked by apple. also it's impossible to install any apps on iOS without an apple account. (unless you jailbreak, which is a pretty different story. your iphone 7 can be jailbroken with checkra1n which is good tho)
the iphone 4s at that time was pretty good tbh except for that shitty glass cover (which was extremely easy to replace unlike recent iphones), galaxy s2 was awesome tho
phones were fun and good until about 2015, then only went worse since. SD808 happened and phones got extremely hot and bulky. also glass back and headphone jack, removable batteries..
I use the two with uBlock Origin instead (so I can choose to go there still), and there were some sites that does have proper information blocked there.