Opsec Measures: Difference between revisions

From Enlace Hacktivista
Jump to navigation Jump to search
mNo edit summary
(10 intermediate revisions by the same user not shown)
Line 2: Line 2:
Here you will find resources that will help you from a technological operational security perspective. OPSEC is much more than simply what networks and technology you use.
Here you will find resources that will help you from a technological operational security perspective. OPSEC is much more than simply what networks and technology you use.


Make sure that you use a separate and fully encrypted computer to work from. This can be a virtual machine, USB, external drive or a throw away laptop. All of your network traffic should be routed entirely over Tor (whonix is the best for this). See [https://enlacehacktivista.org/images/6/69/Hack_back1.txt Phineas fishers operational security practices].
Make sure that you use a separate and fully encrypted computer to work from. This can be a virtual machine, USB, external drive or a throw away laptop. All of your network traffic should be routed entirely over Tor (whonix is the best for this). See [https://enlacehacktivista.org/images/6/69/Hack_back1.txt Phineas Fishers operational security practices].


== OPSEC Tools ==
== OPSEC Tools ==
There is no silver bullet when it comes to protecting yourself, staying safe and anonymous. It's important to know how to use the tools we rely on to keep us safe and free. Below you will find industry standard tools that will help keep your hacktivity private and secure.
There is no silver bullet when it comes to protecting yourself, staying safe and anonymous. It's important to know how to use the tools we rely on to keep us safe and free. Below you will find industry standard tools that will help keep your hacktivity private and secure.


When communicating with journalists or other hackers it's important to keep all communication end-to-end encrypted, network connection over Tor and to not use aliases or emails that lead back to your real world identity.
When communicating with journalists or other hackers it's important to keep all communication end-to-end encrypted, network connection over Tor and to [https://www.wired.com/2015/05/silk-road-2/ not use aliases or emails that lead back to your real world identity].


* https://www.qubes-os.org
* https://www.qubes-os.org
Line 13: Line 13:
* https://tails.boum.org
* https://tails.boum.org
* The whonix wiki has lots of great info on anonymity even if you're not using whonix: https://www.whonix.org/wiki/Documentation
* The whonix wiki has lots of great info on anonymity even if you're not using whonix: https://www.whonix.org/wiki/Documentation
* https://gitlab.torproject.org/legacy/trac/-/wikis/doc/TransparentProxy
* [https://www.whonix.org/wiki/Comparison_with_Others Custom]: https://gitlab.torproject.org/legacy/trac/-/wikis/doc/TransparentProxy
* Use veracrypt to encrypt your virtual machines and hard drive. https://veracrypt.fr
* Use veracrypt to encrypt your virtual machines and hard drive. Make sure to save your hacktivity inside of a [https://veracrypt.eu/en/Hidden%20Volume.html hidden volume] for plausible deniability. https://veracrypt.fr
* Tor browser: https://www.torproject.org
* Tor browser: https://www.torproject.org
* Disable javascript (set Security Level to "Safest" in Tor Browser)
* Disable javascript (set Security Level to "Safest" in Tor Browser)
* If you plan on transacting you should always start from monero and swap your XMR to another coin. This reduces traceability (over Tor). https://www.getmonero.org
* If you plan on transacting you should always start from monero and swap your XMR to another coin. This reduces traceability (over Tor) and will defeat standard blockchain investigations. https://www.getmonero.org


== Know your enemy ==
== Know your enemy ==
Line 25: Line 25:


* (Book) Hunting Cyber Criminals: A Hacker's Guide to Online Intelligence Gathering Tools and Techniques 1st Edition
* (Book) Hunting Cyber Criminals: A Hacker's Guide to Online Intelligence Gathering Tools and Techniques 1st Edition
* (Book) Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency

Revision as of 10:57, 22 April 2023

Recommended Measures

Here you will find resources that will help you from a technological operational security perspective. OPSEC is much more than simply what networks and technology you use.

Make sure that you use a separate and fully encrypted computer to work from. This can be a virtual machine, USB, external drive or a throw away laptop. All of your network traffic should be routed entirely over Tor (whonix is the best for this). See Phineas Fishers operational security practices.

OPSEC Tools

There is no silver bullet when it comes to protecting yourself, staying safe and anonymous. It's important to know how to use the tools we rely on to keep us safe and free. Below you will find industry standard tools that will help keep your hacktivity private and secure.

When communicating with journalists or other hackers it's important to keep all communication end-to-end encrypted, network connection over Tor and to not use aliases or emails that lead back to your real world identity.

Know your enemy

Cyber investigators will use many techniques to uncover your identity to facilitate in a successful arrest. Books as seen below help us see and understand some of the tactics they use, even trying to infiltrate groups to collect information.

Always be aware, know your enemy!

  • (Book) Hunting Cyber Criminals: A Hacker's Guide to Online Intelligence Gathering Tools and Techniques 1st Edition
  • (Book) Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency