rosmxi I’m in a situation where I’ve been a specific target for some pretty tech-savvy, aggressive people in the past before moving to GrapheneOS.
I guess we are excluding state actors and/or equivalent.
I am trying to infer your threat model based on what you wrote.
Excluding expensive exploits and 0days, usually the most practical attack vector relies on user interaction.
There is a reason if phishing (as broad and umbrella term) is so popular in cyber attacks.
This basically means that whatever OS with security updates you are going to use, should prevent most of the attacks you might get.
Of course, this is OS level and doesn't include the applications you install on top of it.
To put it simple: if you install a webserver on your laptop, you get all the webserver weaknesses and vulnerabilities, especially true if you expose it on internet.
There is some more nuance on this topic, but as rule of thumb: security updates -> secure system.
This means you should avoid EOL devices/OSes ad all those OSes that don't have a good stance.
If you use a system that doesn't enforce security patches, make sure you opt-in (like security preview releases on GOS).
rosmxi is regular Android or stock Pixel 8 effectively useless against a determined adversary?
If your enemies are "some pretty tech-savvy, aggressive people" they shouldn't be able to undermine Android security model by themself. It is very unlikely (even if not impossible) that a determined group of few guys with no important budget can bring down a world wide OS like Android.
A rogue app can make damage, but again, this relies on user interaction.
Being an attentive user will protect you from a lot of attacks you might receive.
There are some common sense rules you can follow, like good password hygene, verifying links before opening pages and/or logging in, the usual stuff...
GOS + desktop mode is an interesting idea.
Just keep in mind that some applications will behave differently (a simple example might be Signal having screen sharing on PC, but not on Android) or somw things being not doable at all (a simple example might be an advanced nmap scan using root).
I read someone trying to make the most from Android Native Terminal, but it seems there are some critical differences that will prevent you from leveraging the whole Linux environment.
Honestly, didn't test it that much myself, so I can't give a full opinion on this.
Generally speaking, a system might be secure and not privacy friendly (like iOS), and never the opposite (no security -> data is easily compromised).
rosmxi Would using the Pixel 8 in desktop mode be a safer bet than a standard Linux desktop/Macbook, or am I just moving the target to a different device?
I would say that any modern mobile OS is better at security than most of the desktop cousins.
Maybe SecureBlue is better than LineageOS (?)
Hard to compare, if you think about firmware and/or how different their security models are.