Opsec Measures
Recommended Measures
Here you will find resources that will help you from a technological operational security perspective. OPSEC is much more than simply what networks and technology you use.
Make sure that you use a separate and fully encrypted computer to work from. This can be a virtual machine, USB, external drive or a throw away laptop. All of your network traffic should be routed entirely over Tor (whonix is the best for this). See Phineas Fishers operational security practices for hackers OPSEC.
Residential proxies over Tor (Tor -> Proxy). Though not applicable for most OPSEC concerns and shouldn't be used as an operational security measure to stay safe, if you're going to be hacking then using Tor directly won't be very effective. Tor is great for our OPSEC foundations but for using different tools on your VPS and logging into different services on your target using residential proxies in areas close to your target (City, State, etc) won't raise as many red flags on the defensive side and if your IP gets blocked you can just rotate to another residential proxy. Proxies coming from residential areas will look less suspicious as opposed to data center hosted proxies. Using Tor going into the proxy will ensure any subpoenas or investigations won't de-anonymize you.
OPSEC Tools
There is no silver bullet when it comes to protecting yourself, staying safe and anonymous. It's important to know how to use the tools we rely on to keep us safe and free. Below you will find industry standard tools that will help keep your hacktivity private and secure.
When communicating with journalists or other hackers it's important to keep all communication end-to-end encrypted, network connection over Tor and to not use aliases or emails that lead back to your real world identity.
- https://www.qubes-os.org
- https://www.whonix.org
- https://tails.boum.org
- The whonix wiki has lots of great info on anonymity even if you're not using whonix: https://www.whonix.org/wiki/Documentation
- Custom: https://gitlab.torproject.org/legacy/trac/-/wikis/doc/TransparentProxy
- Use veracrypt to encrypt your virtual machines and hard drive. Make sure to save your hacktivity inside of a hidden volume for plausible deniability. https://veracrypt.fr
- Tor browser: https://www.torproject.org
- Disable javascript (set Security Level to "Safest" in Tor Browser)
- If you plan on transacting you should always start from monero and swap your XMR to another coin. This reduces traceability (over Tor) and will defeat standard blockchain investigations. https://www.getmonero.org
Know your enemy
Cyber investigators will use many techniques to uncover your identity to facilitate in a successful arrest. Books as seen below help us see and understand some of the tactics they use, even trying to infiltrate groups to collect information.
Always be aware, know your enemy!
- (Book) Hunting Cyber Criminals: A Hacker's Guide to Online Intelligence Gathering Tools and Techniques 1st Edition
- (Book) Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency