Disclaimer: I am strongly aware of the OP’s situation so none of my messages should be considered as suggestions, but just as contemplation.
It is obvious that the OP ignores it persistently and consistently, and @kuhbs was faster than me but I completely agree with him. There is no better way but to (try to) blend in, and nothing is more common then to generate internet traffic with Android, while behind its usb-tethereing is whatever the one would want to.
Here is how I would do it to further secure it.
Namely, I’d use a separate (old?) machine with a minimal Linux installation which would serve as a gateway, rather than a router because of a better manageability, to USB tether to with my phone.
Then, I’d connect Qubes machine to the first machine directly with ethernet cable, then setting IPs of the two manually or using dnsmasq, setting IP forwarding, setting up NAT with nftables (or iptables) and this should work well.
Why this? Well, further security is consisted in a fact that we are expected USB controller to be poisoned by and via Android, so we spare our Qube’s controller, and have it at our disposable, especially when modern laptops mostly have a single USB controller, and all other devices attached to it then would be endangered in a direct-to phone connection. On a gateway machine, when USB controller is poisoned, it is still needed malicious attack to escape to ehternet NIC, which is not that feasible, at least not yet without Mythos (this reference to anthoer topic is intended
).
Now, how would I further secure this setup? I still couldn’t find a way to run usb-tethering in it but I would without doubt use Second space. And when the OP lives where we all think he lives, then Xiaomi should be accessible to him too, in order to get this more than cool feature.
Since I couldn’t be able to use usb-tethering there, then I would move all of my apps there, and would strip my main space to a bare minimum needed for a phone to function properly. Of course, not being logged into a Google account on a phone and using only F-Droid and Aurora Store is a must as I see it.
When you don’t have ethernet card on your Qubes machine, or when the one would like to isolate hardware from sys-net (like we do with audio and VGA controllers via sy-sudio and sys-gui-gpu), the one could try something like this:
but the one then would have to rely on the USB to ethernet device itself not being malicious.
WiFi? Well even when I live in a country which ISP I am happy with (which I do - the least evil of all), I simply ever, never do use WiFi. That’s like my basic, general rule. No devices in my environments with WiFi, or WiFi enabled.
When I could live with WiFi, then I’d use phone’s Second space cleaned from all possible apps and connect the first machine to it via WiFi, and forward traffic to the second one via ethernet again.
I’d happy to further contemplate this setup to hear what do you think of it, and why you find it interesting or not.