What is your threat model?
Are you the next Edward Snowden? A Russian doing drug deals on dark markets? A clerk at a locally run convenience store? Some tech worker in the Bay Area? A journalist in Western Europe? A Wal-Mart employee organizing to form a union? A free-software proponent and developer?
The answer here is to do some threat modeling. What activities are you involved with that may be interesting to those with power and capabilities? Are you concerned with powerful state or corporate actors? Are you concerned with the run-of-the-mill privacy invasions in typical Android apps?
* Navigate to Settings -> Apps -> Config -> App Permissions, and disable permissions in each category.
* When you install a new application, only those targeting Android 6.0 or later will prompt you for permissions, so go in and edit the permissions for newly installed applications before you run them.
* Depending on your cellular provider, it may be helpful to setup a forward-all VPN through either your own server or a trusted VPN provider (feel free to read about Verizon X-UIDH supercookies). I don't trust VPN providers, so I do this myself.
* Enable device encryption, and use a sufficiently complex password. Assume when your device is powered on that all data on the device can be obtained.
* Set Firefox to your default browser, and install relevant extensions like uBlock Origin.
I got my 6p yesterday and still learning my way around it. Overall I'm impressed but feel like such a noob and not sure what to do to stay safe. There's a decent checklist here: https://security.utexas.edu/handheld-hardening-checklists/an...
It's a bit generic and not specifically to Android 6.0, but helps point in the general direction of how to think about securing android.