Tailored exploitation is a good point though.
Admittedly RPi isn’t any current advice except for outdated hobbyist advice. If I cared to defend against nation state I’d avoid gen purpose CPU’s altogether and focus on in house manufactured minimal circuits, possibly fpga’s and printers or some other trusted peripherals. I’d build my own keyboards too.
The poster was concerned about video being hacked. This would be hard to hide, at least for being owned in real-time, if one were keeping track of the packets coming and going. If you’re whitelisting all your outbound and disallowing inbound, and if your decoupled passive nids is set up right you at least have the physical network layer covered.
If you’re targeted for tailored exploitation then you’d be considering a scif anyway if you really have something that important to hide. In a pinch, a faraday cage would probably be a good idea if you can set it up right. Don’t trust any devices that come in or out.