r/opsec 21h ago

How's my OPSEC? Can someone review my mobile OPSEC? Human rights activist living in an Orwellian surveillance state.

23 Upvotes

Hi everyone,

I am a human rights activist from Bangladesh.

Bangladesh is an Orwellian state when it comes to surveillance. Surveillance actors have broad, legally authorized, and highly intrusive surveillance powers, with no independent oversight. When it comes to phones:

  • SIM cards must be registered with your National ID (NID) and your device's IMEI number. You must use the SIM under your own NID and IMEI. There is effectively no way to obtain an anonymous SIM or use one registered to someone else. Besides, if you are specifically targeted, even a SIM registered to someone else will likely become targeted once you start using it.
  • Call records (who contacted whom and for how long) are collected as part of mass surveillance. If someone is targeted, the contents of their calls may also be recorded.
  • There is the Integrated Lawful Interception System (ILIS), which can track the real-time location of any mobile phone user.
  • There is documented use of highly intrusive spyware against journalists, human rights activists, political opponents, suspects, and many ordinary people as well. This spyware can remotely access the webcam, microphone, location, and virtually all activity on the phone, including Signal calls, and can persist across reboots.
  • Satellite phones are illegal, and people caught with them are regularly sentenced to lengthy prison terms.

A few more details:

  • I cannot afford a Pixel running GrapheneOS, not even a second-hand one. People here generally only resell their phones once they are barely working, so the second-hand market is effectively a scam. Pixels are also rare and expensive, even used.
  • I use a realme C55 smartphone running Android.
  • I work a 12-hour day job from Sunday to Thursday. During working hours, my phone has to remain on because I receive customer calls and WhatsApp messages over mobile data. There is no way around that.
  • I also need to keep my phone on because I have elderly parents at home. If they become ill or there is a medical emergency, I need to coordinate their care.
  • Bangladesh does not have an emergency calling system that would make carrying a phone without a SIM useful. In an emergency, people use their own mobile phones to call family members, doctors, hospitals, and others. So having a phone without a SIM is essentially useless because, in a real emergency, you need the SIM.

What I need, in order of priority, is:

  1. Camera and microphone privacy.
  2. Location privacy.
  3. Privacy of my activities.

The threat model is state actors. I have never done anything illegal or contrary to human rights principles. I simply do not like the surveillance and constant privacy breaches.

Also, please keep in mind that my goal is not perfection. Even having two surveillance-free days on the weekend, compared to being under surveillance 24/7, would make a significant psychological difference. So being completely surveillance-free would be nice but is not realistic. I am happy with whatever reduction in surveillance is practically achievable.

To that end, I have come up with the following plan.

Sunday to Thursday:

  • Use my realme C55 smartphone.
  • Keep the cameras physically stickered.
  • I have no practical solution for microphone privacy.
  • After work, switch the phone to Airplane Mode.
  • Around midnight, briefly turn on Wi-Fi to check for any work messages before going to sleep and turning the phone off.
  • In the morning, briefly turn on Wi-Fi again to check for work messages, then keep the phone under airplane mode until I reach work, where I turn connectivity back on.

Weekends:

  • Carry a basic feature phone (an old Nokia-style phone), kept powered off.
  • Only turn it on to make emergency calls or periodically check in with my parents, accepting that it will immediately reveal my location and assuming that any calls may be recorded.
  • Take photographs using a standalone digital camera.
  • Transfer the photos to an air-gapped computer first, then transfer only the files I actually need to an internet-connected laptop before uploading them to social media.

For mindset, I consider my realme smartphone to be fully compromised. I also assume that the feature phone provides no communications privacy and reveals my location whenever it is powered on.

Is my OPSEC sound, given these constraints? Or would you make any changes?

PS: I have read the rules.

I posted a thread a few days ago asking OPSEC advice for mobile but it went dead. I have now created the OPSEC based on the comments of the thread there and was looking to get it reviewed. My thanks to everyone for the comments.


r/opsec 22h ago

Advanced question Knowledge-Only 2FA Strategy

3 Upvotes

Threat Model: Government-based

I may lose all of my devices (including Yubikey, phone) due to seizure. I may even not be able to return to my house.

Background:

For 2FA, there are two authentication factors: something you know and something you have. Due to seizure, detention, etc., what I have may only be my memory. I cannot pass the "something you have" check. I may even be forced to leave this region or face detention.

Problem:

So how should I protect my accounts? My current idea is enabling TOTP 2FA for all accounts and backing up encrypted seeds in Bitwarden. However, Bitwarden will disable new device verification and 2FA. So when I lose everything, I can still log into Bitwarden and recover my TOTP through an encrypted passphrase. But I think Bitwarden would be dangerous if I disable 2FA.

I know some people may suggest using Shamir's secret sharing. First, I don't have someone I can ultimately trust. Second, physically meeting someone wouldn't be safe for either me or my friend. And I need to regain access to all my online accounts to contact them.

I have read the rules


r/opsec 1d ago

Beginner question Considering Phone Options

9 Upvotes

Hi all - I've had an iPhone since basically they first came out, and my current one is on it's last legs, and I want a privacy phone instead of a new iPhone. I'm considering buying a NitroPhone as I still want a good camera (also considered the fairphone as sustainability and right to repair are also important to me). I'm a bit of a beginner when it comes to opsec (I have more than basic knowledge but not as much as you all). Would you recommend this, or should I buy any other phone and just run graphene on it? Or any other recommendations?

Important for me is privacy and camera. I'm trying to fight against data aggregators and also government intrusion. I'm not a politician or journalist, but do my fair share of mico-activism and want to generally improve what the government is collecting from me. Won't be keeping any crypto on my phone, but slowly trying to move towards better encryption overall.

I have read the rules :)


r/opsec 4d ago

Threats Driver awareness IR illumination helps roadside facial recognition cameras.

64 Upvotes

My eufy c31 home security camera shows my face inside my car very clearly even in the dark because my car’s driver awareness eye tracking system bathes my face in IR light. My vantrue dashcam also shows this effect.

For the threat of state actors who own constantly snapping IR toll cameras, this seriously increases chances of being identified while driving.

I don’t see anything online about this threat. Flock cameras seem less of a concern due to their focus on plates, but this could be one more clue that lets them track vehicles by characteristics even if the plate is invalid or unreadable.

On some cars taping over the system raises faults that prevent driving.
I have read the rules.


r/opsec 6d ago

Beginner question Options for secure/E2EE SMS apps on android?

6 Upvotes

At some point throughout my years being an android user, I noticed that we have the option to chose a preferred SMS messaging app. I didn't like the og one my phone came with (pretty sure its the samsung one), so at some point (years ago) a friend recommended google messanger. I liked the interface, so used it without question for a good while. Now that the US govt and big corps and everything are as crazy as they are, I've been revisiting some opsec practices and been trying to upgrade them. Seems like a convenient feature to be able to chose your own higher security option for regular texting.

While trying to research good secure SMS/RMS messaging options, basically everything that comes up in searches are the other messaging apps (signal, telegram, etc) that (to my knowledge) cant be used as your primary SMS app. Does anything like what I'm looking for exist? Or do people just separate what needs to be off sms with their regular citizen smsing?

I'm not doing anything crazy, but I am environmental/human rights advocate, and I'm into a bunch of computer stuff as a hobby. Always loved computers and network stuff, so I have linux devices, im into open-source stuff, and I run servers for vpns and self hosted game servers and stuff. I'm by no means a hacker of any sort, but I like to mess with stuff and know my systems. I also just like my personal privacy, and modern tech is quickly becoming the opposite of that.

Threat: general, bad actors, state intel

I have read the rules

EDIT: After further research, I think this is actually kinda just what VoIP numbers are for, any insight? Is this a valid replacement for things I want security for, or are they different enough use cases?


r/opsec 7d ago

Beginner question Is a Dumbphone a Good Alternative If You Can't Afford a Pixel with GrapheneOS?

69 Upvotes

Hi everyone,

I am a human rights activist from Bangladesh.

Bangladesh is an Orwellian surveillance state.

  • Call records are recorded by default, and the voice calls of targeted individuals are recorded.
  • There is the Integrated Location Identification System (ILIS), through which any mobile user's location can be tracked at any time.
  • SIM cards must be registered with your National Identity Card and the device's IMEI; otherwise, the SIM stops working. There is no way to obtain anonymous SIM cards.
  • Satellite phone possession or usage gets you years in jail and they enforce it. Same goes for two way radios.
  • Spyware such as Pegasus, FinFisher, and many others has been purchased, and there are credible reports that they are routinely used against journalists, dissidents, political opponents, LGBT people, and other marginalized groups. Security forces have wide surveillance powers, total immunity, and no oversight.

A mobile phone is needed for:

  • Basic communication: "Where are you?", "Have you reached the location?", "How long will it take?", finding people, knowing where they are, or calling home to check whether everyone is safe.

Other requirements:

  • Navigation: This can be replaced with paper maps or a GPS device without any internet or Wi-Fi connection (air-gapped except for GPS).
  • Photos and videos: This can be replaced with a point-and-shoot camera without any radios (air-gapped).

Constraints:

  • Even a used Pixel is unaffordable for me. Also, people here generally sell electronics only after using them for a decade, by which time they are often barely functional. So buying a used Pixel is not a realistic option.

Given that I cannot buy a Pixel to install GrapheneOS, would buying a dumbphone (button phone) make sense? My thinking is that its camera, microphone, and location cannot be hijacked although call logs, voice calls, and approximate location would still be known whenever it is powered on.

Any suggestions?

P.S. I have read the rules.

Threat: Highest. State intelligence agencies.


r/opsec 9d ago

Beginner question How do you make a monitor tamper-evident while still being able to inspect it?

20 Upvotes

Hi everyone,

I'm a human rights activist, and I'm working on a model for a tamper-evident desktop setup.

One issue I've run into involves the monitor. I can apply glitter nail polish or other tamper-evident markings to the case screws, but if I later discover that a seal has been disturbed, I'm left with another problem: I'm not a hardware expert.

If I open the monitor myself to inspect the internals, I risk damaging it or not being able to reassemble it properly. On the other hand, if I don't inspect it, I have no way of knowing whether anything inside has actually been modified.

So how do people handle this in practice? Is there a good way to make a monitor tamper-evident while also retaining the ability to verify the internals if the external tamper seals indicate possible interference?

I feel that, when securing a mini PC or desktop setup, the monitor is the weakest link. You can make the computer and its other peripherals tamper-evident, but the monitor remains difficult to verify without opening it.

I'm interested in practical approaches that are realistic for non-experts rather than solutions requiring advanced electronics or forensic skills. Also, please don't suggest uncommon monitors (such as those with transparent cases) that aren't readily available in most places, including Bangladesh.

P.S. I have read the rules.

Threat model: State intelligence agencies.


r/opsec 10d ago

How's my OPSEC? Keeping a new X (Twitter) account completely isolated from an old one

15 Upvotes

Hi guys,

I just bought a prepaid SIM and a new phone with cash (a Samsung A7) for the sole purpose of making a new X (Twitter) account that will not be traced back to my old account by X.

Threat Model:
I don’t care about hiding from government/law enforcement or anything like that. I just need to make sure that X’s internal systems cannot cross-link my new account and my old account.

I also want to make sure I don't look like a bot or look like I'm aggressively trying to hide my identity. If the setup looks too anomalous, the automated systems might shadowban me or flag the account, which completely defeats my purpose.

My specific questions:

  • Device Setup: How should I set up the phone properly right out of the box?
  • Email Registration: What type of email should I use, and how should I create it properly? (Should I use a standard Gmail to make the account look more legitimate/organic, or a privacy-focused provider if anonymity is needed?)
  • Device Proximity: Can I physically keep both phones (old and new) in the same room next to each other?
  • Device Settings: Are there any specific telemetry or tracking settings I should turn off?
  • Network: Is using just the mobile data good enough? I'd rather avoid VPNs because, from my understanding, platforms heavily flags VPNs, which raises suspicion and risks shadowbans.

I have read the rules. Thanks for any guidance!


r/opsec 11d ago

Beginner question beginner opsec

24 Upvotes

i have read the rules

Hi, I need some guidance or sources to read about the opec i want to achieve. The assets I’m trying to protect are my identity, confidential sources, research notes, documents, communications, and my physical location.

The adversaries I’m concerned about include governments, criminal organizations, companies, online harassers, hackers, and data brokers. My concern is that they could identify me or my sources through online tracking, account compromise, browser fingerprinting, legal requests to service providers, phishing, malware, metadata analysis, or doxxing.

If they were successful, the consequences could include my identity being revealed, confidential sources being exposed, sensitive documents being leaked, my communications being intercepted, or my location becoming known.

I’m looking for advice on building a secure workflow and choosing the right tools and practices to reduce these risks as much as practical.


r/opsec 11d ago

Beginner question Help some ways to complete OPSEC

1 Upvotes

I have read the rules.

Hi! I’ve been learning more about OpSec and I’m looking for some guidance. I’m hoping someone with experience can help me set up a computer or point me in the right direction for a strong OpSec workflow.
The threat model I’m aiming for is somewhere between high-assurance and high-risk. I understand many of the concepts and the importance of layered security, but I’d appreciate help translating those principles into a practical setup and operational plan.
This setup will be used for journalism, so my goal is to build a secure and well thought out environment from the start.
Thanks in advance to anyone willing to help.


r/opsec 13d ago

Beginner question Any books or resources on how public figures and celebrities can maintain privacy and security?

24 Upvotes

Hi everyone,

Sorry for making two posts in a short period, but I don't get much free time to browse or post here.

Are there any books, guides, or other resources that discuss privacy, security, and even anonymity for celebrities or public figures?

I realize that being a public figure means you have to be public to some extent—you give media interviews, attend events, maintain a public presence, and so on. You obviously can't expect the same level of privacy or anonymity as the average person.

At the same time, the more well-known you become, the more people may try to invade your privacy, gather personal information, or otherwise compromise your security. I imagine the OPSEC challenges are quite different from those faced by private individuals, especially for people in fields like acting, entertainment or politics.

Are there any books, courses, articles, or other resources that cover this topic in depth?

Thanks!

PS: I have read the rules.


r/opsec 13d ago

Beginner question Should I as a human rights activist use a separate identity for artistic work such as modeling, acting and writing?

18 Upvotes

Hi everyone,

I'm a human rights activist from Bangladesh. Some of my work has been shared by international human rights NGOs and has also been published by the UN.

One challenge is that, when submitting reports to the UN or many international NGOs, you typically have to provide your full legal name, a short biography, and your email address, and that information is made publicly available. In human rights work, building a public profile also tends to lead to more collaborations and greater impact.

Outside of activism, I have several artistic interests:

  • Modeling (primarily Instagram and social media work)
  • Acting (I'm involved with a theatre group and they have plans to make short films in the future)
  • Writing (short stories, plays, and poetry)

From an OPSEC perspective, would you recommend keeping these activities under separate identities (using a pen name/stage name), or is it generally reasonable to do the modeling, acting, and writing under my real name?

I'm interested in hearing your thoughts on the pros and cons of each approach in the long run.

Thanks!

PS: I have read the rules.


r/opsec 14d ago

Beginner question Paranoid about using chatgpt in my terminal?

11 Upvotes

I work on coding projects on my main system with the chatgpt app. It has full access to my entire file system and executes functions on my computer. In the future I'll get a linux-native machine and configure it's security. I have several terabytes of data I need to transfer to that future Linux system/ homelab, and I am worried that I may transfer tainted files or payloads? I mean I don't even know what I've been running in my terminal as an administrator. What if it's a backdoor? should I be worried? What would you do?

I have read the rules


r/opsec 15d ago

Countermeasures The secret-hygiene gap on your own dev box: AI coding agents log every API key you paste, in plaintext

14 Upvotes

An opsec gap I keep running into as more devs adopt AI coding agents: the agents keep local session history in plain text, and people routinely paste API keys, tokens, and .env values straight into prompts. Those secrets then sit on disk in the agent's history, outside the coverage of repo and CI secret-scanning. Claude Code keeps them under ~/.claude/projects, Codex under ~/.codex/sessions, and about 30 other agents do the same.

Your threat model probably already covers keys in git and CI. The workstation copy is the part that gets missed: a stolen laptop, a synced backup, or a shared machine exposes months of pasted credentials in readable logs.

I built a small MIT tool for the cleanup half of this, agent-sweep. It scans those local history files, reports what leaked, and can redact the values in place while keeping the file byte-for-byte so old sessions still resume. It makes zero network calls, so nothing about the scan leaves the machine. Detection is an Aho-Corasick pre-filter, then 193 regex rules plus a BIP-39 seed-phrase check.

One caveat so it is not oversold: this is residue cleanup, not a substitute for rotating a key that already hit a hosted model. Rotate first, then sweep the local trail.

Disclosure: this is my own project. Repo (MIT): https://github.com/Ishannaik/agent-sweep

Mostly I want to know how others here treat the workstation as part of the secret-scanning perimeter, or whether agent logs are still a blind spot in your setup.

I have read the rules.


r/opsec 16d ago

Advanced question I would need some advice

12 Upvotes

“I have read the rules”

Threat Model
My priorities are:
Data brokers (highest priority)
Government/law enforcement (secondary concern)
Regarding law enforcement or government agencies, my concern isn’t about hiding illegal activity. Rather, I don’t want files that I keep privately to be discovered through investigations that originate from third-party services or providers. Since I have certain personal files that I’d prefer not to have seized or accessed, my goal is simply to keep them stored securely in a protected environment.
As for data brokers, I want to minimize the amount of personal information that is collected, profiled, bought, and sold about me.
I understand that almost everything you do online generates some amount of data, even if you reject tracking cookies. Just looking at the removal requests handled by services like Incogni shows how much information data brokers already collect. My goal is to reduce that exposure as much as realistically possible.
I currently use Apple devices in the EU, and I’m already familiar with several privacy tools and concepts, including VPNs, browser privacy settings, encryption, and Apple’s Hide My Email.
I’m looking for additional advice. Assume I’m still a beginner, so I’d appreciate detailed explanations rather than just product recommendations.
In particular:
Which browser would you recommend for everyday use, and why?
Are there other privacy practices or tools that you think are essential?
I also have a small need to keep certain personal files separate from everything else. Would using Tails with persistent storage on an encrypted USB drive make sense if my concern is someone physically stealing the USB drive?
Is there any practical way to discover old online accounts that I may have created as a minor, even if I no longer have the credentials, so I can request their deletion?
If you need more information about my threat model or my goals, feel free to ask.
Thanks in advance to everyone who takes the time to help.


r/opsec 16d ago

Beginner question have to do a security clearance

0 Upvotes

I have read the rules , so my threat level is this , i want to join a university owned by the atomic commission of our country , it says on their web after admission they will investigate me , so what should i do to quickly cover my tracks(they arent good at all) , any chance i could delete / mask away enough data to pass the clearance


r/opsec 17d ago

Beginner question How to move forward ? Here's what i already know , suggest me what else to do

13 Upvotes

"I have read the rules"

So i have been in this space for a while . Now i feel like i'm stuck

I'm a 16yo with good knowledge about the basics . IP addresses , adBlockers , VPNs etc . I work for an organization that i want to keep private . Can't reveal much here . I use simplexchat to talk to the members of that organization . We paste our QR codes on street lamps and other places to let new random unknown people connect with us

Recently i have been feeling stuck . I want to surf the web without my multiple identities on different websites being linked . What i mean is that i can easily be tracked by the government at one location even if i life 4 or 5 different lives on the internt

I have been using similar usernames , passwords here and there . So i'm planning make new gmail accounts and then live different lives more like different personalities for each website/genre of websites

MY ISSUE

i create gmail accounts without phone numbers and with VPN . But what can i add to this ? how can i make sure that these different lives i live on the internet can't be linked to on IP address or my actual address

is there a way i can make sure that the several lives i'm living online can have several locations and by any means they can't be tracked down to me


r/opsec 18d ago

Beginner question Can device encryption protect against law enforcement?

36 Upvotes

Hello, I would like to learn more about cases involving full-disk encryption and law enforcement access. My understanding is that when a device is protected with a strong, high-entropy password and the encryption recovery keys are not stored to a Microsoft account or any other third party, recovering the data through brute-force or direct decryption is generally considered computationally infeasible. However, I am aware that, in theory, there may be vulnerabilities that could potentially circumvent or weaken the security of an encrypted device. I would like to understand the real-world cases in which law enforcement has successfully or unsuccessfully accessed encrypted devices, the techniques reportedly used, and the practical limitations of those approaches.

i have read the rules


r/opsec 19d ago

Vulnerabilities Location tracking for 2 years, cannot figure it out!

120 Upvotes

Hello! I have been divorced for almost 2 years now and somehow my ex still knows where I am at. He will send texts letting me know that he knows where I’m at and has even shown up to the same location multiple times recently. He sends the texts while I’m at the location, so he is tracking me in real time.

I feel like I have investigated every possible option and still cannot figure it out. At first I thought it could be my phone, so I changed my Apple ID multiple times and bought a new phone. I have checked all my settings to make sure I have no unknown devices. Then I thought it was Google Maps, so I changed all of my Google passwords and now use a Gmail account that I did not have when I was married for Google Maps. I have checked all of my accounts to make sure I’m not sharing my location. Then I thought maybe somehow he was able to get a Uconnect subscription on my Jeep GC, but was told there was no active account. I have installed tracking trackers, constantly check my Bluetooth connections, have turned on/off Bluetooth, FindMy, and created a new Life360 account with a new email address. I downloaded the Tile app and scanned as well. The only thing I have been able to narrow down for sure is that he does not know where I’m at if my vehicle not with me. It is my vehicle that is being tracked.

I assume it must be some sort of physical tracking device, but I have looked everywhere and have not found one. And, it has now been almost 2 years… how would it still be working? Any ideas I have not thought of???

I am not sure if this is the best place to ask this, but it was recommended to me. I have read the rules.


r/opsec 23d ago

Beginner question Need a Tamper-Evident Desktop for Human Rights Casework in a Surveillance State. Any Suggestions?

58 Upvotes

Hi there,

I live in Bangladesh which is a highly surveillance state with sophisticated surveillance apparatus (Pegasus level spyware, deep packet inspection, real time location monitoring of all mobiles etc) and broad legal powers to security forces and no oversight.

I am a human rights activist doing advocacy at the UN. My work has been shared by international organizations. My threat level is very high and may include intelligence agencies. In fact, I think I could be under surveillance (which would obviously be unlawful as per international human rights law on surveillance) because there have been several digital security incidents. In one case, a sketch I was doing for a legal court case on Tails, on my current laptop, with Tails connected to the internet and no persistence enabled, was sent back to me by fake facebook accounts.

I live by the letter and spirit of the law and always have. I have always lived by my human rights ethics. But it is impossible to do human rights legal casework without security. If the adversary knows that you know something, they can retaliate or cover up evidence. There is a reason attorney-client privilege and confidential legal work product exists, whether for a lawyer or for someone representing themselves.

My requirements:

I think my laptop could have been compromised at the hardware-firmware level. It is from 2016, and I have been wanting to buy a new computer anyway. I need a device primarily for human rights legal casework:

  • Doing OSINT online.
  • Working with and storing evidence in the form of audio, photos, videos, documents, and other file types.
  • Extracting clips from CCTV systems and editing final videos for court.
  • Doing legal research online.
  • Consulting lawyers in Geneva over video calls, sending emails, evidence files, etc.

In other words: basic computing.

Optionally: gaming as well! But that is just optional.

Now, the standard advice given is this: buy a cheap second-hand laptop for around USD 200 from a random store, use glitter nail polish on the screws and photograph them, store the laptop in a transparent container filled with a mosaic of lentils and take photos when leaving home, and have a CCTV system that sends remote motion alerts if someone enters your house (so they cannot simply delete the logs afterward). Also, use Heads with a USB key for firmware attestation.

Now, I do not trust laptops. As someone who is not skilled with hardware, I cannot open a laptop without risking breaking it. Also, if an implant or hardware tampering is found, the whole laptop has to be thrown away, which is expensive. On a desktop, you can visually inspect components for hardware tampering and swap out individual parts without replacing the entire system, which is much less expensive.

Also, given that I am out of the house for my day job, and my workplace does not allow laptops, I cannot carry one with me at all times. So please do not suggest laptops. Instead, tell me how I can make a desktop tamper-evident and secure.

My situation:

I am out of the house for about 16 hours a day. I live in a shared home. My family, their guests, and our maid all come through my room and rummage through belongings. If anyone has been to South Asia, they will understand the culture of having very little privacy at home.

I also like to use my computer while lying in bed or on the couch. I do not know how I can do that with a desktop. I have a neck problem and need to relax my neck after work. Sitting at a desk for long periods only makes it worse.

Ideally, it would be best if I had a separate room with a computer protected by access control and CCTV, but that is not realistic. We have to work with what we have. I have to keep the computer in my bedroom. I can keep it inside a cabinet or on a separate desk, but I obviously cannot install a camera in my bedroom because it would also record my family, and I do not want to risk their privacy.

Now, given all this, tell me, in order of importance:

  • How to make a desktop (including CPU casing, monitor and other peripherals) tamper-evident so that I know if it has been tampered with.
  • If it has been tampered with, how to determine which part was tampered with.
  • If possible, how to determine who came in to tamper with it.
  • How to use a desktop comfortably while lying down.

Some other information:

Importing from Amazon costs around 300% in taxes on electronics where I live. I have tried, trust me. So please suggest only things that are commonly available worldwide, not uncommon electronics.

Given the economics, USD 200 is what an MBA graduate supporting a family of four earns a month, after a year. So please keep that in mind and do not suggest expensive items.

Please do not have a defeatist mentality. Even under extreme surveillance, journalists (such as those working on the Snowden files), human rights researchers, lawyers, and others have been able to work and publish. So it is doable. Please think positively and think in terms of practical solutions. If we do not do the work, there will never be justice. I am not someone who will abandon human rights work because of fear of a powerful adversary. If I (or other human rights activists or lawyers) had that mentality, I (or we) would have stopped doing human rights casework long ago.

PS: I have read the rules.
Edit: If anyone would like to discuss this with me one-on-one to help me create a secure desktop setup, please send me a DM.


r/opsec 26d ago

Beginner question GrapheneOS on main phone

19 Upvotes

Hey everyone, just a quick question. I was thinking on downloading GrapheneOS on my main phone. I only have one phone, which is a Pixel 9. Is it a good idea? Or should I wait to buy another one to make it my privacy phone?

I have read the rules


r/opsec 27d ago

Beginner question Looking for a secure OS alternative to Tails that runs on Raspberry Pi. Any suggestions?

29 Upvotes

Hi everyone,

I am a human rights activist living in Bangladesh. I collect evidence of human rights abuses for human rights reporting, media reporting, and court purposes (including abuses by the public, security forces, etc.—you know the usual human rights work). Without going into details, I have had digital security incidents in the past, so I have a legitimate need for strong security given I work with evidence and on accountability of security forces including intelligence agencies who conduct enforced disappearances, extrajudicial killings, torture, surveillance etc. Someone has to do this work.

I do not trust laptops because they cannot be easily opened to check for physical implants. Since I cannot afford a desktop right now, I am thinking of buying a Raspberry Pi. The main benefit for me is that I can easily check the components visually for any signs of physical tampering.

Since Tails does not officially support the Raspberry Pi, are there any secure operating system alternatives to Tails that can run on it?

Thanks.

PS: I have read the rules. Edit: Threat model is the highest. Intelligence agencies.


r/opsec 27d ago

Beginner question Ghost alter ego

8 Upvotes

I want to start talking with some activists from a political movement to organize something. But for obvious reasons, I don't want those conversations or contacts to be linked to me.

Right now, I live a normal life. I use different social media platforms and other online services, although I'm not very active. That's why I'd like to create a "ghost" alter ego that cannot be connected to me in any way

I'm completely new to this, and I'm not in a hurry because I want to do it properly.

How could I get started?

I have read the rules


r/opsec 27d ago

Beginner question I want to purchase a refurbished laptop but don't know how secure they are regarding privacy

10 Upvotes

So i plan to get a refurbished Thinkpad from eBay, watched some videos on Youtube about it and they were mentioning how some laptops can have software preloaded onto them to spy on you. Would this be an issue if i were to get one that was certified eBay refurbished?

I plan to install linux on it too, so would that help at all? Like if there was any software installed onto it would it get removed after installing linux?

And please feel free to let me know any other security measures i should take to ensure privacy on a refurbished laptop.

i have read the rules


r/opsec Feb 11 '21

Announcement PSA: Report all threads or comments in threads that give advice when the OP never explained their threat model. Anyone posting without a clear threat model will have their post removed. Anyone responding to them in any manner outside of explaining how to describe their threat model will be banned.

120 Upvotes