r/opsec Feb 11 '21

Announcement PSA: Report all threads or comments in threads that give advice when the OP never explained their threat model. Anyone posting without a clear threat model will have their post removed. Anyone responding to them in any manner outside of explaining how to describe their threat model will be banned.

125 Upvotes

r/opsec 15h ago

Countermeasures The secret-hygiene gap on your own dev box: AI coding agents log every API key you paste, in plaintext

6 Upvotes

An opsec gap I keep running into as more devs adopt AI coding agents: the agents keep local session history in plain text, and people routinely paste API keys, tokens, and .env values straight into prompts. Those secrets then sit on disk in the agent's history, outside the coverage of repo and CI secret-scanning. Claude Code keeps them under ~/.claude/projects, Codex under ~/.codex/sessions, and about 30 other agents do the same.

Your threat model probably already covers keys in git and CI. The workstation copy is the part that gets missed: a stolen laptop, a synced backup, or a shared machine exposes months of pasted credentials in readable logs.

I built a small MIT tool for the cleanup half of this, agent-sweep. It scans those local history files, reports what leaked, and can redact the values in place while keeping the file byte-for-byte so old sessions still resume. It makes zero network calls, so nothing about the scan leaves the machine. Detection is an Aho-Corasick pre-filter, then 193 regex rules plus a BIP-39 seed-phrase check.

One caveat so it is not oversold: this is residue cleanup, not a substitute for rotating a key that already hit a hosted model. Rotate first, then sweep the local trail.

Disclosure: this is my own project. Repo (MIT): https://github.com/Ishannaik/agent-sweep

Mostly I want to know how others here treat the workstation as part of the secret-scanning perimeter, or whether agent logs are still a blind spot in your setup.

I have read the rules.


r/opsec 2d ago

Advanced question I would need some advice

10 Upvotes

“I have read the rules”

Threat Model
My priorities are:
Data brokers (highest priority)
Government/law enforcement (secondary concern)
Regarding law enforcement or government agencies, my concern isn’t about hiding illegal activity. Rather, I don’t want files that I keep privately to be discovered through investigations that originate from third-party services or providers. Since I have certain personal files that I’d prefer not to have seized or accessed, my goal is simply to keep them stored securely in a protected environment.
As for data brokers, I want to minimize the amount of personal information that is collected, profiled, bought, and sold about me.
I understand that almost everything you do online generates some amount of data, even if you reject tracking cookies. Just looking at the removal requests handled by services like Incogni shows how much information data brokers already collect. My goal is to reduce that exposure as much as realistically possible.
I currently use Apple devices in the EU, and I’m already familiar with several privacy tools and concepts, including VPNs, browser privacy settings, encryption, and Apple’s Hide My Email.
I’m looking for additional advice. Assume I’m still a beginner, so I’d appreciate detailed explanations rather than just product recommendations.
In particular:
Which browser would you recommend for everyday use, and why?
Are there other privacy practices or tools that you think are essential?
I also have a small need to keep certain personal files separate from everything else. Would using Tails with persistent storage on an encrypted USB drive make sense if my concern is someone physically stealing the USB drive?
Is there any practical way to discover old online accounts that I may have created as a minor, even if I no longer have the credentials, so I can request their deletion?
If you need more information about my threat model or my goals, feel free to ask.
Thanks in advance to everyone who takes the time to help.


r/opsec 2d ago

Beginner question have to do a security clearance

0 Upvotes

I have read the rules , so my threat level is this , i want to join a university owned by the atomic commission of our country , it says on their web after admission they will investigate me , so what should i do to quickly cover my tracks(they arent good at all) , any chance i could delete / mask away enough data to pass the clearance


r/opsec 3d ago

Beginner question How to move forward ? Here's what i already know , suggest me what else to do

13 Upvotes

"I have read the rules"

So i have been in this space for a while . Now i feel like i'm stuck

I'm a 16yo with good knowledge about the basics . IP addresses , adBlockers , VPNs etc . I work for an organization that i want to keep private . Can't reveal much here . I use simplexchat to talk to the members of that organization . We paste our QR codes on street lamps and other places to let new random unknown people connect with us

Recently i have been feeling stuck . I want to surf the web without my multiple identities on different websites being linked . What i mean is that i can easily be tracked by the government at one location even if i life 4 or 5 different lives on the internt

I have been using similar usernames , passwords here and there . So i'm planning make new gmail accounts and then live different lives more like different personalities for each website/genre of websites

MY ISSUE

i create gmail accounts without phone numbers and with VPN . But what can i add to this ? how can i make sure that these different lives i live on the internet can't be linked to on IP address or my actual address

is there a way i can make sure that the several lives i'm living online can have several locations and by any means they can't be tracked down to me


r/opsec 4d ago

Beginner question Can device encryption protect against law enforcement?

31 Upvotes

Hello, I would like to learn more about cases involving full-disk encryption and law enforcement access. My understanding is that when a device is protected with a strong, high-entropy password and the encryption recovery keys are not stored to a Microsoft account or any other third party, recovering the data through brute-force or direct decryption is generally considered computationally infeasible. However, I am aware that, in theory, there may be vulnerabilities that could potentially circumvent or weaken the security of an encrypted device. I would like to understand the real-world cases in which law enforcement has successfully or unsuccessfully accessed encrypted devices, the techniques reportedly used, and the practical limitations of those approaches.

i have read the rules


r/opsec 4d ago

Vulnerabilities Location tracking for 2 years, cannot figure it out!

119 Upvotes

Hello! I have been divorced for almost 2 years now and somehow my ex still knows where I am at. He will send texts letting me know that he knows where I’m at and has even shown up to the same location multiple times recently. He sends the texts while I’m at the location, so he is tracking me in real time.

I feel like I have investigated every possible option and still cannot figure it out. At first I thought it could be my phone, so I changed my Apple ID multiple times and bought a new phone. I have checked all my settings to make sure I have no unknown devices. Then I thought it was Google Maps, so I changed all of my Google passwords and now use a Gmail account that I did not have when I was married for Google Maps. I have checked all of my accounts to make sure I’m not sharing my location. Then I thought maybe somehow he was able to get a Uconnect subscription on my Jeep GC, but was told there was no active account. I have installed tracking trackers, constantly check my Bluetooth connections, have turned on/off Bluetooth, FindMy, and created a new Life360 account with a new email address. I downloaded the Tile app and scanned as well. The only thing I have been able to narrow down for sure is that he does not know where I’m at if my vehicle not with me. It is my vehicle that is being tracked.

I assume it must be some sort of physical tracking device, but I have looked everywhere and have not found one. And, it has now been almost 2 years… how would it still be working? Any ideas I have not thought of???

I am not sure if this is the best place to ask this, but it was recommended to me. I have read the rules.


r/opsec 9d ago

Beginner question Need a Tamper-Evident Desktop for Human Rights Casework in a Surveillance State. Any Suggestions?

54 Upvotes

Hi there,

I live in Bangladesh which is a highly surveillance state with sophisticated surveillance apparatus (Pegasus level spyware, deep packet inspection, real time location monitoring of all mobiles etc) and broad legal powers to security forces and no oversight.

I am a human rights activist doing advocacy at the UN. My work has been shared by international organizations. My threat level is very high and may include intelligence agencies. In fact, I think I could be under surveillance (which would obviously be unlawful as per international human rights law on surveillance) because there have been several digital security incidents. In one case, a sketch I was doing for a legal court case on Tails, on my current laptop, with Tails connected to the internet and no persistence enabled, was sent back to me by fake facebook accounts.

I live by the letter and spirit of the law and always have. I have always lived by my human rights ethics. But it is impossible to do human rights legal casework without security. If the adversary knows that you know something, they can retaliate or cover up evidence. There is a reason attorney-client privilege and confidential legal work product exists, whether for a lawyer or for someone representing themselves.

My requirements:

I think my laptop could have been compromised at the hardware-firmware level. It is from 2016, and I have been wanting to buy a new computer anyway. I need a device primarily for human rights legal casework:

  • Doing OSINT online.
  • Working with and storing evidence in the form of audio, photos, videos, documents, and other file types.
  • Extracting clips from CCTV systems and editing final videos for court.
  • Doing legal research online.
  • Consulting lawyers in Geneva over video calls, sending emails, evidence files, etc.

In other words: basic computing.

Optionally: gaming as well! But that is just optional.

Now, the standard advice given is this: buy a cheap second-hand laptop for around USD 200 from a random store, use glitter nail polish on the screws and photograph them, store the laptop in a transparent container filled with a mosaic of lentils and take photos when leaving home, and have a CCTV system that sends remote motion alerts if someone enters your house (so they cannot simply delete the logs afterward). Also, use Heads with a USB key for firmware attestation.

Now, I do not trust laptops. As someone who is not skilled with hardware, I cannot open a laptop without risking breaking it. Also, if an implant or hardware tampering is found, the whole laptop has to be thrown away, which is expensive. On a desktop, you can visually inspect components for hardware tampering and swap out individual parts without replacing the entire system, which is much less expensive.

Also, given that I am out of the house for my day job, and my workplace does not allow laptops, I cannot carry one with me at all times. So please do not suggest laptops. Instead, tell me how I can make a desktop tamper-evident and secure.

My situation:

I am out of the house for about 16 hours a day. I live in a shared home. My family, their guests, and our maid all come through my room and rummage through belongings. If anyone has been to South Asia, they will understand the culture of having very little privacy at home.

I also like to use my computer while lying in bed or on the couch. I do not know how I can do that with a desktop. I have a neck problem and need to relax my neck after work. Sitting at a desk for long periods only makes it worse.

Ideally, it would be best if I had a separate room with a computer protected by access control and CCTV, but that is not realistic. We have to work with what we have. I have to keep the computer in my bedroom. I can keep it inside a cabinet or on a separate desk, but I obviously cannot install a camera in my bedroom because it would also record my family, and I do not want to risk their privacy.

Now, given all this, tell me, in order of importance:

  • How to make a desktop (including CPU casing, monitor and other peripherals) tamper-evident so that I know if it has been tampered with.
  • If it has been tampered with, how to determine which part was tampered with.
  • If possible, how to determine who came in to tamper with it.
  • How to use a desktop comfortably while lying down.

Some other information:

Importing from Amazon costs around 300% in taxes on electronics where I live. I have tried, trust me. So please suggest only things that are commonly available worldwide, not uncommon electronics.

Given the economics, USD 200 is what an MBA graduate supporting a family of four earns a month, after a year. So please keep that in mind and do not suggest expensive items.

Please do not have a defeatist mentality. Even under extreme surveillance, journalists (such as those working on the Snowden files), human rights researchers, lawyers, and others have been able to work and publish. So it is doable. Please think positively and think in terms of practical solutions. If we do not do the work, there will never be justice. I am not someone who will abandon human rights work because of fear of a powerful adversary. If I (or other human rights activists or lawyers) had that mentality, I (or we) would have stopped doing human rights casework long ago.

PS: I have read the rules.
Edit: If anyone would like to discuss this with me one-on-one to help me create a secure desktop setup, please send me a DM.


r/opsec 12d ago

Beginner question GrapheneOS on main phone

19 Upvotes

Hey everyone, just a quick question. I was thinking on downloading GrapheneOS on my main phone. I only have one phone, which is a Pixel 9. Is it a good idea? Or should I wait to buy another one to make it my privacy phone?

I have read the rules


r/opsec 12d ago

Beginner question Looking for a secure OS alternative to Tails that runs on Raspberry Pi. Any suggestions?

29 Upvotes

Hi everyone,

I am a human rights activist living in Bangladesh. I collect evidence of human rights abuses for human rights reporting, media reporting, and court purposes (including abuses by the public, security forces, etc.—you know the usual human rights work). Without going into details, I have had digital security incidents in the past, so I have a legitimate need for strong security given I work with evidence and on accountability of security forces including intelligence agencies who conduct enforced disappearances, extrajudicial killings, torture, surveillance etc. Someone has to do this work.

I do not trust laptops because they cannot be easily opened to check for physical implants. Since I cannot afford a desktop right now, I am thinking of buying a Raspberry Pi. The main benefit for me is that I can easily check the components visually for any signs of physical tampering.

Since Tails does not officially support the Raspberry Pi, are there any secure operating system alternatives to Tails that can run on it?

Thanks.

PS: I have read the rules. Edit: Threat model is the highest. Intelligence agencies.


r/opsec 13d ago

Beginner question Ghost alter ego

6 Upvotes

I want to start talking with some activists from a political movement to organize something. But for obvious reasons, I don't want those conversations or contacts to be linked to me.

Right now, I live a normal life. I use different social media platforms and other online services, although I'm not very active. That's why I'd like to create a "ghost" alter ego that cannot be connected to me in any way

I'm completely new to this, and I'm not in a hurry because I want to do it properly.

How could I get started?

I have read the rules


r/opsec 13d ago

Beginner question I want to purchase a refurbished laptop but don't know how secure they are regarding privacy

9 Upvotes

So i plan to get a refurbished Thinkpad from eBay, watched some videos on Youtube about it and they were mentioning how some laptops can have software preloaded onto them to spy on you. Would this be an issue if i were to get one that was certified eBay refurbished?

I plan to install linux on it too, so would that help at all? Like if there was any software installed onto it would it get removed after installing linux?

And please feel free to let me know any other security measures i should take to ensure privacy on a refurbished laptop.

i have read the rules


r/opsec 13d ago

Beginner question What can people know about me ?

7 Upvotes

Hi everyone,

So I have read the rules and I'm a normal person without any immediate threats. I'm just concerned about my privacy, especially since I'm involved politically. I also hate the idea that data brokers know about me and I'd like to get less spam calls.

What simple hygiene do you recommend for a beginner in order to delete/stop leaving breadcrumps behind me on the Internet ?

In particular do I need to stop using anything Google and anything Microsoft ?

I also heard about GrapheneOS that apparently gets quite a lot of praise but don't have a Pixel for the foreseeable future. My phone is also not compatible with LineageOS or DivestOS. What are the best practice.to limit my exposure to data brokers

Also I'm curious about how much one can know about me simply from my Reddit. If you're interested, you can DM me with any open source info you found about me, if anything, In particular I'd like to know if someone can link my real identity to my reddit posts.

Thanks in advance !


r/opsec 14d ago

Beginner question I do human rights work, write, and act. Should I use a pen name, stage name, and distinct appearance to maintain my privacy?

18 Upvotes

Hi everyone,

I am mid 30s male, and I live in Bangladesh and I'd appreciate some advice on balancing privacy with public-facing work.

For the past few years, I've been involved in international human rights advocacy. I keep a very low public profile: there's only one photo of me on my website and LinkedIn. My submissions to the UN do not include my photo, and when I was asked to record a video presentation, I declined. However, my full name and email address appear on UN publications because that is part of their submission requirements, so my name is publicly searchable.

I've always admired how, in earlier times, many well-known authors, actors, politicians, and activists could still move around in everyday life without being recognized. The example that comes to mind is Goethe and the Duke of Saxe-Weimar, who reportedly traveled through the countryside dressed as ordinary people without anyone knowing who they were. I'd like to preserve something similar—the ability to enjoy the privacy and anonymity of an average person, someone who is unrecognizable in public other than to their friends and family.

Separate from my human rights work, I've always wanted to become an author and actor. I mainly write poetry, short stories, and I'm currently working on a play. I'm also involved with a theatre group. At the moment, I've largely ruled out film acting because it seems difficult to reconcile with my privacy goals.

I'd love to hear your thoughts on a couple of questions:

  1. Would it make sense to use a separate pen name/stage name for my writing and acting, keeping it distinct from my human rights work?
  2. Is there any practical value in consistently wearing something distinctive but ordinary—such as a beanie, cap, glasses, or similar—to make myself less recognizable in everyday life? You know similar to Superman or Hannah Montana. Or does that really not work?

Thanks in advance.

Also if someone could talk to me over chat and give me a tailored suggestion on how to design my public life for privacy I would be grateful.

PS: I have read the rules.


r/opsec 14d ago

Beginner question Opsec nissan armada location off

8 Upvotes

2026 Nissan Armada , I want to be sure location tracking with in the vehicle stays off, I don’t want it tracked through the app due to safety issues. i understand it can be if switched on by someone else in the app. I have already turned the tracking off on the vehicle in settings but I understand it can easily be turned on via an app that someone else has a hold of. My ex husband was listed as the owner and since the divorce I got the vehicle but the app has him as owner and it sent him and email when I tried to get access through the app. it’s not as simple as a call to Nissan, is it? “I have read the rules”


r/opsec 15d ago

Countermeasures Someone has old files of mine

24 Upvotes

EDIT: So it seems this person had honest intentions while I was assuming the worst. They found something they thought might have sentimental value and reached out to return it to me. Let this be a public reminder to wipe your devices and storage media before throwing them away!

Original post follows below.

--------------------------------

I have read the rules. I’m dealing with a strange situation involving very old personal files and would appreciate advice from people who understand security better than I do.

Last week I received an email from someone using a fake name claiming they had old files of mine from around fifteen years ago. I assumed it was a scam/phishing attempt and basically told them to get lost. Today they sent proof: a text file and a zip containing the name and contents of a long since deleted shared Dropbox folder. Both the text file and the zip appear legitimate and match things I would have stored in Dropbox at the time. They claim to have other files which would track with what I was doing at the time.

They claim they aren’t trying to hack me or get money, but obviously I don’t trust that. I replied once asking who they were, and now I’m waiting.

My threat model:

  • I’m not rich, not a public figure, not involved in activism or journalism.
  • I have no active social media besides LinkedIn (which I don't use) and Reddit.
  • I can't think of anyone I know personally who would want to do this to me.
  • I haven’t used Dropbox in years, and the shared folder in question was deleted long ago.
  • I don’t see any suspicious activity in Dropbox, Gmail, or my password manager.
  • All my passwords are long, unique and randomly generated. I use 2FA everywhere I can.
  • I have changed all my passwords within the last three years.
  • The files they sent are extremely old, so I suspect the breach is also old. I am struggling to understand how they got access in the first place. Maybe through an old device or hard drive that I had thrown away long ago?
  • There are some sensitive personal photos from that era which I would have shared in that particular shared Dropbox folder. I don’t have evidence they have those, but it’s a realistic possibility given the folder they accessed. In terms of threat modeling I guess the biggest risk is that those photos get spread around where people in my personal life can see them.

I have already reached out to the person with whom I shared that folder to let them know this happened. I have no intention of paying or doing anything else to satisfy the attacker. What I want to know now is where to go from here: do I just stop responding to the attacker entirely? I realize I have already made some mistakes but the least I can do is keep it from getting worse. Any help is greatly appreciated.

(Apologies for double-posting. My last post got removed by Reddit's filters. I am not sure why.)


r/opsec 15d ago

Beginner question built my opsec around tech. forgot data brokers bypass all of it.

47 Upvotes

i have read the rules vpn, encrypted email, burner numbers, separate devices. felt pretty locked down. then i googled my name and city out of curiosity. first result was whitepages with my current address. second had my phone number. third showed my workplace.

i get that these are public records but still. all the tech layers dont matter if the government sells your data to these broker sites and anyone can look it up for free.

manual opt outs are a joke. some sites want you to call a number and leave a voicemail. others want a signed letter. in 2026. and even when you get removed, they relist you after a few months.

i started using iolo to handle removals automatically. not a silver bullet but saves time.

curious if anyone here actually got completely removed from all these sites or if physical address exposure is just something you accept and focus on other threats.


r/opsec 17d ago

Countermeasures Surveillance Capitalism is Boring: A Minimalist’s Guide to Dark-Web OpSec

Thumbnail medium.com
12 Upvotes

r/opsec 18d ago

Countermeasures OnionIRC OPSEC Guide (2016)

Thumbnail
github.com
10 Upvotes

A guide from Anonymous' OnionIRC server in spring 2016 distilled from a number of live sessions. Covers Tor usage, VPNs, and behavioral fingerprints that lead to identifying operators. Includes the original log files

I have read the rules


r/opsec 18d ago

Advanced question Selling laptops/motherboards with Intel me disabled plus secure bios

8 Upvotes

Hey everyone, I was wondering if anyone had thoughts on my new idea. I've really been wanting to somehow sell tech in the security/opsec typa sphere. What do you guys think about supply/demand? I know there plenty selling the same thing on eBay, but a website that takes monero payment and card would surely be better? Is this something you guys think could do good? Thanks! (I have read the rules)


r/opsec 18d ago

Beginner question Is there way to protect our secret information from LLMs (claude-code, codex) living in our systems?

16 Upvotes

Is it possible to have a way to encrypt information from an LLM? Not the traditional encryption but some way that text is not visible to an LLM even if it is readable to a human. Is that even possible?

The usecase I'm considering is when I have claude-code running in my system, how can I protect it from accessing my tokens, secret keys etc.

I have read the rules!


r/opsec 19d ago

How's my OPSEC? Air-gapped QR messaging to keep message content off a remote scanned or compromised phone

10 Upvotes

I have read the rules.

Threat model: an adversary who can read remotly what is on your phone through targeted spyware, client-side scanning, or forensic access after a device seizure. This is for people whose message content is worth extracting: journalists, activists, lawyers, people in coercive jurisdictions. The outcome to avoid is your plaintext being pulled off the device and used against you or your contacts.

The point: the attacker reads the content on the endpoint, before or after encryption. So E2EE does not help. Signal, SimpleX, PGP all encrypt after the content already sits in plaintext on a device that can be scanned remotly.

The approach: keep the readable content off the device that gets scanned. You write and encrypt on a separate phone that is permanently offline (a Google Pixel with GrapheneOS, no SIM, no Wifi, no Bluetooth). Your normal online phone only ever sees the ciphertext, transferred as a QR code from the offline device and forwarded over whatever messenger you already use. The receiver has the same offline phone and scans the QR code from the online device. Plaintext and keys never touch a device that is online or likely to be inspected.

The nice part is it does not matter if your online phone is fully compromised or seized. The plaintext was never on it, so all they get is an encrypted blob. The plaintext is out of reach on the offline device

Honest limits:

  • it does not hide metadata (who talks to whom and when is still visible depending on the messenger from the online devices)
  • text only, around 2000 characters per message
  • both sides need the same two device setup

What it is: open source (GPLv3), reproducible builds, standard crypto via libsodium (X25519, Ed25519, ChaCha20-Poly1305). Full architecture in the whitepaper.

Full disclosure: I build this (Monolith), but the approach matters more than the tool. Tinfoil Chat does the same idea with a hardware data diode, and you can do a manual version with an offline laptop and gpg.

So, how's my opsec? Where does this break in real life operations and what did I miss?

Whitepaper: https://monolith-sec.com/assets/whitepaper.pdf
Code: https://github.com/Monolith-sec/Monolith
Demo: https://youtu.be/ygndzqdVJAQ


r/opsec 19d ago

Beginner question Alter ego opsec

4 Upvotes

Hola a todos, soy nuevo por acá y recién me estoy interesando en esto de opsec

Es posible crear un alter ego irrastreable mientras mantengo mi perfil normal para mi vida diaria?

Muchas gracias

I have read the rules


r/opsec 20d ago

Solved locked down my digital life. forgot about my physical address being public.

34 Upvotes

i have read the rules

been working on my opsec for a while now. VPN, encrypted email, burner numbers, the whole thing felt pretty good about it . friend sent me a screenshot of my name on whitepages. full address phone number even my wifes name all just sitting there.

i never posted my address anywhere. but data brokers scrape public records like property tax and voter registration. doesn't matter how many layers of privacy you have online if someone can just look up where you sleep.

tried the opt out route. whitepages took me like 15 minutes and a phone verification. then i realized i need to do this for about 30 other sites. and even after all that, they relist you a few months later anyway because the public records never change.

been using iolo to automate the removals and monitor for new listings. not a complete solution but better than spending hours on it myself.

anyone else here deal with this? feels like no matter how tight your opsec is, data brokers just bypass the whole thing.


r/opsec 24d ago

Threats EU Chat Control - how to circumvent with today’s available tools?

60 Upvotes

Hello Everyone,

As many will already have seen, it appears that some idiots in the EU are back on track to try and push the Chat Control regulation to pass. While chances that it passes as is appear slim, one is never safe from human brainmush moments.

I’d like to ask this sub what their suggestions may be regarding the matter.
There are still many ways to make one’s communications impossible to understand to an outsider, but i’d nonetheless like to keep as much layers between me and gov/hackers/malicious actors etc.

i have read the rules, i’m not someone who personally needs much OPSEC, my personal situation is just using macOS’s security, malwarebytes, a network filter (Little Snitch) and my routers security features. All my email is or privately hosted, not directly associated to my name, i have one nominative account for administrations with a well-known privacy focused company. All i do, i do over vpn.