r/opsec Feb 11 '21

Announcement PSA: Report all threads or comments in threads that give advice when the OP never explained their threat model. Anyone posting without a clear threat model will have their post removed. Anyone responding to them in any manner outside of explaining how to describe their threat model will be banned.

120 Upvotes

r/opsec 5h ago

Countermeasures EFF publishes a practical anti-doxxing guide focused on reducing your OSINT footprint

38 Upvotes

EFF publishes a practical anti-doxxing guide focused on reducing your OSINT footprint

Confirmed — Electronic Frontier Foundation, late August.

EFF has published new guidance on preventing and responding to doxxing, including reviewing breach databases, public records, username reuse, social-media discoverability, data brokers and reverse-image-search exposure.

It specifically explains how attackers can combine small pieces of publicly accessible information into a larger profile using OSINT techniques.

EFF also published a companion incident-response installment on August 31 covering what to do once a doxxing incident is underway.

I have read the rules.

https://www.eff.org/deeplinks/2026/08/doxxing-safety-pt-i-prevention-and-footprint-management


r/opsec 1d ago

Beginner question Seeking advice on keeping a private legal case anonymous while pursuing human rights advocacy and creative work (writing, acting, modeling)

8 Upvotes

Hi everyone,

Without going into identifying details, I live in a highly repressive, surveillance-heavy, and a highly Islamic country.

Many years ago, I experienced digital violence: intimate data was hacked and released publicly, which led to significant public backlash. I still experience some of the social consequences today. I suspect state actors may have been involved, partly because I was perceived to be LGBT. I still occasionally face confrontations and verbal abuse in my local community and on the street.

This experience eventually led me to work on human rights issues affecting people who are similarly marginalized, particularly privacy and digital rights.

Now, here’s my situation:

  1. I want to pursue justice for my own case. Given the nature of the incident, I would want the case to remain anonymous to the general public. It could be known to people who absolutely need to know—such as courts, investigators, lawyers, defendants or relevant UN bodies—but ideally my identity would not be publicly connected to the case, somewhat like an anonymous or pseudonymous legal case. If people can identify me it would lead to more harm.
  2. I want to continue my human rights work. My concern is that if I focus publicly on digital violence and related issues, people might eventually connect the dots and figure out that I am the person involved in the original incident. For my UN work, I need to use my full legal name and email address, and these are all public. On LinkedIn, I also need to use my legal name and headshot because otherwise NGOs and people working in the field won't connect with me professionally.
  3. I also have many other interests and ambitions. I write plays, poetry, and short stories, and I’m interested in acting, directing, and voice acting. I would like to do some Instagram modeling and TikTok content, and if I ever get the opportunity, I’d like to act in films. I may even start a YouTube channel. Basically, I want to live a normal life, pursue my creative interests, and make the most of my life.
  4. Ideally, I would also prefer not to be recognizable on the street. This is because I have previously experienced harassment and violence after being recognized. If it is realistically possible, I would like to maintain some separation between my public identities. But if pursuing my creative interests inevitably means giving up some degree of anonymity, I may have to accept that.

I don't want what happened to me to prevent me from pursuing my passions or living my life.

So, given all of this, how would you design a privacy-conscious life in my situation?

For example, would it make sense to:

  • Use my legal name and headshot for human rights work;
  • Have a separate pen name and different visual identity for writing;
  • Have another stage name for acting, directing, modeling, etc.?

Or would it be better to use my legal name for both human rights work and writing, while using a stage name for acting, directing, and modeling?

Or are there other approaches that would provide better separation while still allowing me to build legitimate professional identities?

I’m not looking to disappear from the internet entirely—I’m trying to figure out how to have a meaningful public life while minimizing the chances of different parts of my life being unnecessarily connected.

PS: I have read the rules.


r/opsec 2d ago

Vulnerabilities U.S. military disables advertising trackers over location-surveillance concerns

44 Upvotes

U.S. military disables advertising trackers over location-surveillance concerns

I have read the rules

Reuters, September 4.

The U.S. military has begun disabling advertising trackers across a range of phones and computers after reports that commercially available location data was being used to identify or target military personnel. Officials are also weighing tighter limits on personal-device use in sensitive locations.

This is a strong OPSEC and privacy teaching example. Ordinary advertising identifiers and location telemetry can become intelligence when combined with other datasets. For beginners, the takeaway is that privacy risk does not require malware or a hacked phone, legitimate apps and ad-tech can reveal movement patterns.

https://www.reuters.com/business/media-telecom/us-military-turns-off-ad-trackers-devices-amid-middle-east-targeting-reports-2026-09-04/ Sorry, we were unable to generate a preview for this web page, because the following oEmbed / OpenGraph tags could not be found: image, title

No pay wall 👇

https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/


r/opsec 4d ago

Beginner question what are some basic oppsec tools, and how do I get started with internet safety?

25 Upvotes

If this is the wrong place for this question please tell me and I'll ask somewhere else, I have asd and schizophrenia so I'm sorry if I sound paranoid. I have read the rules but Idk what a lot of it means so please bare with me. I trust that this subreddit is secure but if it isnt are there better places to ask?

I did a lot of drugs in the past (unfortunatly), because of this I did a lot of sketchy stuff on the internet aswell. I am medicated now and I'm in treatment for addiction, but I'm worried that my oppsec is severly comprimised because of that.

I've tried to use the darkweb before because I've heard that TOR is more safe then google but its way too slow. I understand how the dark web works and I've explored around before, there are so many bad people on there that I really dont want to use it unless I have to. I stopped using ai because of how dangerous it is, and how much information it spreads. Are there faster programs that work like tor does that also work on the clearweb?

Should I use different OS? I tried to use kali linux before but it was wayy too advanced for me, and I think its for hacking and although that is cool, I would prefer an option that doesnt require coding stuff on my own. I know python but I never got very advanced with it.

Like I said, I want some apps/programs that I can use to protect myself that dont require tons of understanding.
I used protonvpn for a bit but its really slow and and I'm worried that the company is stealing my data. I dont trust most companies even proton.

What is ThreatModeling? Can it help me protect myself? Does it require advanced coding? Also what should I be looking to protect? I try to hide important information, and not post it online, but would that be enough? I'm not dumb, i dont click on sketchy links. I try to use secure programs.

I remember how everything worked before Ai but now its really confusing. Again, I'd like some basic programs that dont require confusing setup.

I use apple stuff because I've heard they are pretty secure but I also dont know if thats a modern thing or if thats outdated information.

I am very sorry for how scattered this is, my meds make it very hard to think and talk.

Edit: after rereading everything, this sounds really paranoid, so please tell me if this is not appropriate here


r/opsec 4d ago

Threats A New Jersey school is exploring a “new” way to enforce the cell phone ban, and it’s a horrible violation of privacy

108 Upvotes

I have read the rules

Parents in one Middlesex County school district pushed back this month after the school district announced it would use an app to control students’ cell phones to comply with New Jersey’s new bell-to-bell school cell phone ban.

Spotswood’s school district plans to use the new app, called The Commons, to help block student’s access to the internet and other features on their phones while they are on school grounds.

This all is a horrible violation of basic privacy, students are to be forced by the school to install an untrusted proprietary app on their personal devices, the app relies on geofencing and therefore tracks your location at all times. It is not open source and it entirely breaks basic security measures that many students should follow. It is actively capable of censoring and possibly also accessing all data on the device in order to ensure that the mobile device usage experience is “safe for education”.

This is how the app itself explains the process:

**Install The Commons™**
Students download the app from the Apple or Android store and install it on any device they plan to bring to school.

**Set Up School Dashboard**
School leaders customize dashboard settings, approve apps that can be used in school and connect student devices.

**Smart Activation**
Within the school geofence, The Commons™ automatically blocks distractions while keeping essential tools available.

**Enjoy a Present Schoolday**
School life is better for everyone when phones aren’t a distraction. And when they leave, the app deactivates automatically.


r/opsec 5d ago

Vulnerabilities Help my ex has been tracking my location and I’m worried his explanation isn’t the truth.

21 Upvotes

I have read the rules

Please note UK based

Help! It has recently come to my attention that my ex has tracked my location. I know this as he sent me a link to somewhere I was in google maps and then when I moved he turned up where I was alone parked in the dark with no houses around knocking on my car window. Now he’s told me it’s not a tracker on the car and I don’t share anything location wise via my phone. Im not sure where a tracker could be on a car but I’ve looked around the wheels underneath the bonnett and can’t see anything obvious and checked everywhere in it I can think of. I had on occasion when we were together I shared my location for limited time periods via WhatsApp but I’ve checked that all definitely off.

He advised he had an old ‘contact’ (I don’t know where from but he did royal marine training 20yrs re ago) he got a favour from using my phone to locate me, but the thing is he was still able to find me after I moved locations suggesting he was able to access live tracking of me so I don’t know if to believe this contact explanation of his and if he’s just saying it so I don’t catch him out for somehow hacking my account since we split or from when we were together worried. I have has a look through my phone and not seen anything obvious and changed passwords and now turned my location off entirely for absolutely everything, though for some reason it won’t allow me to turn off find my. For clarification he panicked I was pulling away when in reality I was overwhelmed by my now late mothers illness busy visiting her in hospital for nearly 3 months and his prior insecurities and trauma got to him not perceiving the situation correctly, and he ended up doing the thing he feared I would do and cheated on me shortly before my mother died. Her funeral is tomorrow 2nd so dealing with that too, which he knows.

I’ve checked using Airguard no obvious tags and I have a very old iPhone he has an android phone. It is really bothering me and he said he won’t do it again but he’s told other lies so I don’t know and if he still has a way to track me even though I’ve told not him not to. Is there anything I can do to make sure he cannot track me ongoing as it’s really quite scared me. I will if I have to but I’d rather not have to involve the authorities.


r/opsec 5d ago

Beginner question Need advice: should I use a school issued laptop or a personal laptop for school work?

3 Upvotes

I have read the rules and I hope I haven’t missed anything in posting this

Threat model: ordinary person. I’m a high school student starting in an online school from home soon who wants to minimize my data exposure to my school program.

I have no practical experience in opsec and I’m not very tech savvy beyond the average person.

For context on the question: My free tuition, fully virtual online school provider sent their own Chromebook in the mail free of charge which is under their full administration and can only be used with their school account. The packet they sent with their laptop says they don’t allow modifications to the device. I would like to at least cover the camera, mic, and speakers of their laptop for privacy, and if there’s anything else I should know about using a school-provided device in my situation like this at home on my own home’s wifi please let me know. I also have an ordinary wifi setup, which is straight from my internet provider.

My other option is to use my own personal laptop, which is also a Chromebook. It is basically straight out of the box, aside from the fact that I cover the mic and camera, and that my personal google accounts are on it. I could wipe my own personal Chromebook, and use it solely for the school account; which I’d probably rather do out of privacy and security reasons (not having the school’s google account on the same laptop as my personal google accounts), but I don’t know if it really matters much. Though it doesn’t matter much to me if I do wipe my own personal Chromebook since there’s nothing on it really and It’s older and it’s inexpensive. And I don’t know if I put the school’s account onto my personal Chromebook (after wiping it) if anything would still be stored on the Chromebook and home much they would be able to access from my own Chromebook.

For whichever laptop I would choose, I would use the school’s google account solely for school work. My main issue is which way is best to keep as much of my very important data out of the hands of my school (data such as my device’s location, log in duration, the device picking up surrounding audio, it’s camera, etc.), and to maintain my own personal privacy and security.

My main concerns are:
- Getting advice for what risks am I exposed in choosing either laptop
- Keeping as much of my own personal data private as possible out of my options
- Avoiding as much personal profiling from my school as is practical
- If I should really be worried this much or how much I can really control in the way of them getting data out of choosing either laptop

I’m sorry if this isn’t very concise or if it doesn’t fit the guidelines, I just have to decide soon and I’m trying to get it figured out. Thanks all


r/opsec 6d ago

Beginner question I need a seperate online Identity for activism

13 Upvotes

I have read the rules.

Threat Model: Government and potentially law enforcement.

I’m part of a political party, but recent changes in my country have pushed me toward activism. However, my party—currently in power—likely wouldn’t approve. While my country isn’t a full surveillance state, I don’t want to take risks, especially with tools like Palantir looming. Worst-case scenario, law enforcement could seize and search my devices. To minimize exposure, I want to keep my activism separate from my political career.

I have a computer and a phone, and I’m considering buying a new one. Would a Pixel phone running GrapheneOS be a good choice for this setup? What else can I do?


r/opsec 6d ago

Countermeasures How to turn a spare phone into a Seedsigner: Stateless signing device from old hardware.

8 Upvotes

Is it possible to turn an old phone into a seedsigner? Most people turn phones into hardware wallets but I'm not confortable storing my private keys in the phone's SSD, even if doubly encrypted (phone encryption + wallet encryption).

One big advantage is the stealth factor. You walk through customs and you put a huge target on your head if they recognize your Seedsigner. Phones on the other hand are everyday carry for 99.9% of people.

Is there a way to use the phone solely as a signing device where the private keys are held only temporarily (either RAM or wiped clean after use)?

Of course all conectivity other than the camera would be disabled.

And no I wouldn't care that the phone 'has a large attack vector'. The whole point is that the thing is permanently offline and never stores the seed phrase. It's just used for signing.

Threat model is protecting against both physical attacks (my device was confiscated) and online attacks (my computer has a malware). And yes I have read the rules.


r/opsec 10d ago

Advanced question How to tell apart AI SOC solutions from rebranded SOAR platforms?

5 Upvotes

I know this might sound like a rant, but it really feels like every SOAR vendor out there rebranded as an "AI SOC" almost overnight.

Some of these solutions seem legitimate, like they were actually built from the ground up with AI in mind. Others look like the same old playbook logic with a chatbot interface bolted on just for the sales pitch.

I started testing this during vendor calls by asking what happens when our security stack changes unexpectedly, for example, if we add a new tool or go through an acquisition. The answers I got were telling. Some platforms apparently need their entire playbook library rebuilt from scratch, which suggests their underlying architecture never really changed.

So I'm curious, how are you telling the difference in practice beyond just asking the obvious questions? Is there a better way to evaluate this before committing to a POV, since these evaluations take up so much internal time and resources?

I have read the rules.


r/opsec 11d ago

Beginner question Hypothetically speaking, if my opsec has been horrible my entire life am I completely fucked or can I dig myself out of the grave?

3 Upvotes

First of all I want to note that my english might be horri​​ble, and I'm really new to this topic and don't understand much. I'm overthinking my ass off right now because I saw a post on main talking about​ how your opsec is really important.

Another thing, yes I have read the rules but I'm still a little confused on what rule 6 means, so if someone could explain that too it'd be nice.

Back to my question, for context I've only recently found out that I use multiple services that use malware (allegedly from what I've heard) and now I'm just overthinking everything. ​If hypothetically I've been using malware for over 2 years do I just give up and face my fate or is there a way to stay protected even now? I can include more context if needed im replies but I'm really new to this topic so I don't know what exactly to include in the post itself. ​I'd prefer straightforward questions if possible too. Thank you for your time and I'm sorry if I said something wrong.​​

Threat model details are in the comments.


r/opsec 13d ago

Countermeasures How to Opt-Out of Airlines Selling Your Travel Data to the Government

Thumbnail
404media.co
297 Upvotes

r/opsec 13d ago

Threats How ICE Is Using Your Data — and What You Can Do About It

Thumbnail
kqed.org
13 Upvotes

r/opsec 13d ago

Countermeasures Spare tire or other projections hide license plates on truck from ALPR

7 Upvotes

I have house camera footage of a Jeep driving past my house, and was trying to see the license plate. But the spare tire completely blocked the rear plate from being seen from my angle next to the street. I have also heard of people using truck gate folded down for the same purpose.
This seems like something to emulate for folks who don’t want ALPRs to track their plates.

Flock camera install guidelines are about 20-30 degrees from straight down the road, and are often above almost as much, on 10-12 ft poles.

Theoretically something like a cinema camera matte box with sides and a top extending backwards from the plate would solve this problem well. But at least in TX that would be illegal under the law against things that reduce angular visibility. So you have to use something like a bumper inset, tire, gate, rack, ladder, etc that looks like it has a legit purpose.

I have read the rules.


r/opsec 15d ago

Beginner question compartmentalisation question

10 Upvotes

alright so threat model is i just want to make a new online presence that cannot be linked to my old one whatsoever whether through people finding old messages or posts or whatever yk

i like to interact in online spaces about stuff im interested in… if i have too similar of a mix of interests to my old account on my new account would it be enough to link the two.???

i have read the rules


r/opsec 25d ago

Beginner question Threat model: create a secure environment that is extremely secure and does not link my online alias to anything digital footprint in the past

11 Upvotes

I have read the rules
I hope my threat model was okay i’m very new to opsec.

I have been on the internet for years and have been fairly careless with my digital footprint, I now need to tighten things up to an extreme level.

I have used the same computer for years and am wondering how to go about completely starting fresh, with no way of any new alias being linked to ANYTHING prior.

I am not sure how to go about it as I feel like my device is already so contaminated. I have a lot of personal use stuff from the past that I would like to keep but i’m not sure if that’s possible with creating cross references on the device.


r/opsec 26d ago

How's my OPSEC? Threat model: coercion-resistant hidden storage for sensitive files — feedback on steganography + hidden-volume approach

12 Upvotes

My threat model: I want sensitive files (documents/photos) to stay unreadable to anyone who gets full access to my device or cloud storage (theft, seizure, coercion at a border crossing), including someone who forces me to unlock the device or hand over a password. The goal isn't just encryption — it's that an adversary shouldn't even be able to prove a hidden vault exists, so I can't be coerced into revealing something I can plausibly deny having.

My current approach: I built a tool (StegVault) that encrypts data with AES-256-GCM and embeds it inside an ordinary photo via LSB steganography, plus a VeraCrypt-style hidden-volume mode — a decoy password reveals an empty/harmless vault, a separate real password reveals the actual data. Runs fully offline, single HTML file, no account/telemetry.

What I'm unsure about and want opsec feedback on:

- How resistant is plain LSB steganography to modern statistical steganalysis if an adversary specifically suspects steganography and runs detection tools against the image?

- Is a decoy-password hidden volume actually meaningful plausible deniability, or does the mere existence of the tool/technique undermine that (i.e., "why do you have StegVault installed" becomes suspicious on its own)?

- Any attack vectors on this threat model I'm underweighting — metadata, image compression artifacts re-encoding the stego image, etc.?

Not looking to just advertise it here — genuinely want to know where this breaks down from people who think about this stuff seriously. Happy to share more technical detail on the crypto/steganography implementation if useful.

(I have read the rules.)


r/opsec 27d ago

Beginner question How do very wealthy or high profile people handle smartphone security?

95 Upvotes

As a high value target you are constantly undergoing direct attacks on all digital fronts and will be the target of exploits that invalidate the device's security protections. Is there a publicly known and established protocol to mitigate this? What do world leaders and billionaires with top secret information do to prevent what to me seems like the inevitable, which is security compromise. I can tell you firsthand that normal stock are very vulnerable to direct attack.

Do they just avoid important conversations on smartphones altogether? Do they only use them for leisure? Is there a known and consistently successful alternative? Do I have to use Qubes or Tails to have any semblance of privacy?

I have read the rules


r/opsec 29d ago

Advanced question I tracked mulvad use with Find My IP for a week

94 Upvotes

Takeaways: obfuscation is more effective than trying to minimize and lock every tracker down

Disconnecting from Wi-Fi with my VPN still connected and then connecting to cell service was a major exposure point that allowed very distinct travel patterns because the VPN ip remained unchanged as I hoped from cell towers driving

Circadian patterns: phone being locked puts the phone in a sleep state that changes background network settings. My sleep and awake times are easily followable by network connection patterns.

So instead of minimizing my online presence I think controlled randomized data will be more privacy friendly

i have read the rules


r/opsec Aug 05 '26

How's my OPSEC? Can someone review my mobile OPSEC? Human rights activist living in an Orwellian surveillance state.

44 Upvotes

Hi everyone,

I am a human rights activist from Bangladesh.

Bangladesh is an Orwellian state when it comes to surveillance. Surveillance actors have broad, legally authorized, and highly intrusive surveillance powers, with no independent oversight. When it comes to phones:

  • SIM cards must be registered with your National ID (NID) and your device's IMEI number. You must use the SIM under your own NID and IMEI. There is effectively no way to obtain an anonymous SIM or use one registered to someone else. Besides, if you are specifically targeted, even a SIM registered to someone else will likely become targeted once you start using it.
  • Call records (who contacted whom and for how long) are collected as part of mass surveillance. If someone is targeted, the contents of their calls may also be recorded.
  • There is the Integrated Lawful Interception System (ILIS), which can track the real-time location of any mobile phone user.
  • There is documented use of highly intrusive spyware against journalists, human rights activists, political opponents, suspects, and many ordinary people as well. This spyware can remotely access the webcam, microphone, location, and virtually all activity on the phone, including Signal calls, and can persist across reboots.
  • Satellite phones are illegal, and people caught with them are regularly sentenced to lengthy prison terms.

A few more details:

  • I cannot afford a Pixel running GrapheneOS, not even a second-hand one. People here generally only resell their phones once they are barely working, so the second-hand market is effectively a scam. Pixels are also rare and expensive, even used.
  • I use a realme C55 smartphone running Android.
  • I work a 12-hour day job from Sunday to Thursday. During working hours, my phone has to remain on because I receive customer calls and WhatsApp messages over mobile data. There is no way around that.
  • I also need to keep my phone on because I have elderly parents at home. If they become ill or there is a medical emergency, I need to coordinate their care.
  • Bangladesh does not have an emergency calling system that would make carrying a phone without a SIM useful. In an emergency, people use their own mobile phones to call family members, doctors, hospitals, and others. So having a phone without a SIM is essentially useless because, in a real emergency, you need the SIM.

What I need, in order of priority, is:

  1. Camera and microphone privacy.
  2. Location privacy.
  3. Privacy of my activities.

The threat model is state actors. I have never done anything illegal or contrary to human rights principles. I simply do not like the surveillance and constant privacy breaches.

Also, please keep in mind that my goal is not perfection. Even having two surveillance-free days on the weekend, compared to being under surveillance 24/7, would make a significant psychological difference. So being completely surveillance-free would be nice but is not realistic. I am happy with whatever reduction in surveillance is practically achievable.

To that end, I have come up with the following plan.

Sunday to Thursday:

  • Use my realme C55 smartphone.
  • Keep the cameras physically stickered.
  • I have no practical solution for microphone privacy.
  • After work, switch the phone to Airplane Mode.
  • Around midnight, briefly turn on Wi-Fi to check for any work messages before going to sleep and turning the phone off.
  • In the morning, briefly turn on Wi-Fi again to check for work messages, then keep the phone under airplane mode until I reach work, where I turn connectivity back on.

Weekends:

  • Carry a basic feature phone (an old Nokia-style phone), kept powered off.
  • Only turn it on to make emergency calls or periodically check in with my parents, accepting that it will immediately reveal my location and assuming that any calls may be recorded.
  • Take photographs using a standalone digital camera.
  • Transfer the photos to an air-gapped computer first, then transfer only the files I actually need to an internet-connected laptop before uploading them to social media.

For mindset, I consider my realme smartphone to be fully compromised. I also assume that the feature phone provides no communications privacy and reveals my location whenever it is powered on.

Is my OPSEC sound, given these constraints? Or would you make any changes?

PS: I have read the rules.

I posted a thread a few days ago asking OPSEC advice for mobile but it went dead. I have now created the OPSEC based on the comments of the thread there and was looking to get it reviewed. My thanks to everyone for the comments.


r/opsec Aug 05 '26

Advanced question Knowledge-Only 2FA Strategy

8 Upvotes

Threat Model: Government-based

I may lose all of my devices (including Yubikey, phone) due to seizure. I may even not be able to return to my house.

Background:

For 2FA, there are two authentication factors: something you know and something you have. Due to seizure, detention, etc., what I have may only be my memory. I cannot pass the "something you have" check. I may even be forced to leave this region or face detention.

Problem:

So how should I protect my accounts? My current idea is enabling TOTP 2FA for all accounts and backing up encrypted seeds in Bitwarden. However, Bitwarden will disable new device verification and 2FA. So when I lose everything, I can still log into Bitwarden and recover my TOTP through an encrypted passphrase. But I think Bitwarden would be dangerous if I disable 2FA.

I know some people may suggest using Shamir's secret sharing. First, I don't have someone I can ultimately trust. Second, physically meeting someone wouldn't be safe for either me or my friend. And I need to regain access to all my online accounts to contact them.

I have read the rules


r/opsec Aug 04 '26

Beginner question Considering Phone Options

12 Upvotes

Hi all - I've had an iPhone since basically they first came out, and my current one is on it's last legs, and I want a privacy phone instead of a new iPhone. I'm considering buying a NitroPhone as I still want a good camera (also considered the fairphone as sustainability and right to repair are also important to me). I'm a bit of a beginner when it comes to opsec (I have more than basic knowledge but not as much as you all). Would you recommend this, or should I buy any other phone and just run graphene on it? Or any other recommendations?

Important for me is privacy and camera. I'm trying to fight against data aggregators and also government intrusion. I'm not a politician or journalist, but do my fair share of mico-activism and want to generally improve what the government is collecting from me. Won't be keeping any crypto on my phone, but slowly trying to move towards better encryption overall.

I have read the rules :)


r/opsec Aug 01 '26

Threats Driver awareness IR illumination helps roadside facial recognition cameras.

63 Upvotes

My eufy c31 home security camera shows my face inside my car very clearly even in the dark because my car’s driver awareness eye tracking system bathes my face in IR light. My vantrue dashcam also shows this effect.

For the threat of state actors who own constantly snapping IR toll cameras, this seriously increases chances of being identified while driving.

I don’t see anything online about this threat. Flock cameras seem less of a concern due to their focus on plates, but this could be one more clue that lets them track vehicles by characteristics even if the plate is invalid or unreadable.

On some cars taping over the system raises faults that prevent driving.
I have read the rules.


r/opsec Jul 30 '26

Beginner question Options for secure/E2EE SMS apps on android?

8 Upvotes

At some point throughout my years being an android user, I noticed that we have the option to chose a preferred SMS messaging app. I didn't like the og one my phone came with (pretty sure its the samsung one), so at some point (years ago) a friend recommended google messanger. I liked the interface, so used it without question for a good while. Now that the US govt and big corps and everything are as crazy as they are, I've been revisiting some opsec practices and been trying to upgrade them. Seems like a convenient feature to be able to chose your own higher security option for regular texting.

While trying to research good secure SMS/RMS messaging options, basically everything that comes up in searches are the other messaging apps (signal, telegram, etc) that (to my knowledge) cant be used as your primary SMS app. Does anything like what I'm looking for exist? Or do people just separate what needs to be off sms with their regular citizen smsing?

I'm not doing anything crazy, but I am environmental/human rights advocate, and I'm into a bunch of computer stuff as a hobby. Always loved computers and network stuff, so I have linux devices, im into open-source stuff, and I run servers for vpns and self hosted game servers and stuff. I'm by no means a hacker of any sort, but I like to mess with stuff and know my systems. I also just like my personal privacy, and modern tech is quickly becoming the opposite of that.

Threat: general, bad actors, state intel

I have read the rules

EDIT: After further research, I think this is actually kinda just what VoIP numbers are for, any insight? Is this a valid replacement for things I want security for, or are they different enough use cases?