r/opsec

▲ 5 r/opsec

Threat model: create a secure environment that maintains complete announymitty from adversaries

I have read the rules

I am currently creating my setup and have decided I would like to run OS strictly from a external ssd in case of emergency.

it is very confusing looking through the options but I have narrowed down to 3 options - Whonix, Kicksecure, snd Tails.

my plan is two run one external with tails for high risk ops and kicksecure for everyday use.

I need some insight on if my setup sounds good, and i’m just not sure if running kicksecure with whonix on a vm would be enough.

reddit.com
u/Secret-Highlight-776 — 6 days ago
▲ 10 r/opsec

Threat model: create a secure environment that is extremely secure and does not link my online alias to anything digital footprint in the past

I have read the rules
I hope my threat model was okay i’m very new to opsec.

I have been on the internet for years and have been fairly careless with my digital footprint, I now need to tighten things up to an extreme level.

I have used the same computer for years and am wondering how to go about completely starting fresh, with no way of any new alias being linked to ANYTHING prior.

I am not sure how to go about it as I feel like my device is already so contaminated. I have a lot of personal use stuff from the past that I would like to keep but i’m not sure if that’s possible with creating cross references on the device.

reddit.com
u/Secret-Highlight-776 — 7 days ago
▲ 94 r/opsec

How do very wealthy or high profile people handle smartphone security?

As a high value target you are constantly undergoing direct attacks on all digital fronts and will be the target of exploits that invalidate the device's security protections. Is there a publicly known and established protocol to mitigate this? What do world leaders and billionaires with top secret information do to prevent what to me seems like the inevitable, which is security compromise. I can tell you firsthand that normal stock are very vulnerable to direct attack.

Do they just avoid important conversations on smartphones altogether? Do they only use them for leisure? Is there a known and consistently successful alternative? Do I have to use Qubes or Tails to have any semblance of privacy?

I have read the rules

reddit.com
u/Bannedtt — 9 days ago
▲ 75 r/opsec+8 crossposts

agentsweep: a CLI that finds & redacts the secrets your AI coding agent (Codex, etc.) saved to disk in plaintext

Every time you paste an API key, DB URL, .env file, or (worst case) a crypto wallet seed phrase into Codex, Cursor, Claude Code, Cline, Aider, etc., it gets written to a local history file in plaintext.

And it doesn't just sit there — these agents re-read their own history as context, so that plaintext key keeps getting fed back to the model and can resurface in a later file, command, or reply. Most people never even look.

agentsweep is an open-source CLI that:

• Scans those history files with ~191 secret-detection rules (ported from gitleaks) plus a dedicated BIP-39 seed-phrase detector

• Supports ~30 agents out of the box (Codex, Cursor, Claude Code, Cline, Aider, Windsurf, and more)

• Redacts in place with atomic writes, .bak backups, post-write validation, and a full undo

Read-only by default; nothing destructive happens without a typed confirmation, and every redaction is reversible.

Install: pipx install agentsweep (then run: agentsweep)

Disclosure: I'm the author. It's free and MIT-licensed (not selling anything). Repo: https://github.com/Ishannaik/agent-sweep

Happy to answer questions or take PRs for more agents.

u/Ishannaik — 10 days ago
▲ 11 r/opsec

Threat model: coercion-resistant hidden storage for sensitive files — feedback on steganography + hidden-volume approach

My threat model: I want sensitive files (documents/photos) to stay unreadable to anyone who gets full access to my device or cloud storage (theft, seizure, coercion at a border crossing), including someone who forces me to unlock the device or hand over a password. The goal isn't just encryption — it's that an adversary shouldn't even be able to prove a hidden vault exists, so I can't be coerced into revealing something I can plausibly deny having.

My current approach: I built a tool (StegVault) that encrypts data with AES-256-GCM and embeds it inside an ordinary photo via LSB steganography, plus a VeraCrypt-style hidden-volume mode — a decoy password reveals an empty/harmless vault, a separate real password reveals the actual data. Runs fully offline, single HTML file, no account/telemetry.

What I'm unsure about and want opsec feedback on:

- How resistant is plain LSB steganography to modern statistical steganalysis if an adversary specifically suspects steganography and runs detection tools against the image?

- Is a decoy-password hidden volume actually meaningful plausible deniability, or does the mere existence of the tool/technique undermine that (i.e., "why do you have StegVault installed" becomes suspicious on its own)?

- Any attack vectors on this threat model I'm underweighting — metadata, image compression artifacts re-encoding the stego image, etc.?

Not looking to just advertise it here — genuinely want to know where this breaks down from people who think about this stuff seriously. Happy to share more technical detail on the crypto/steganography implementation if useful.

(I have read the rules.)

reddit.com
u/Better_Ad_4652 — 9 days ago
▲ 23 r/opsec

Not a Coincidence

“I have read the rules.”

Hi everyone, I have an extremely narcissistic parent (I know it’s a buzzword rn but he truly is) that I unfortunately, live with. For context, my parents are divorced. During the divorce process, he installed a tracking device on my mom’s car which she eventually found (it wasn’t very conspicuous but he concocted some story about how it was something needed for the car). Also for context, his routine is extremely consistent For many years, my siblings and I have had many discussions about how we think there are hidden cameras somewhere in/around our family home.

I have noticed for some time that he will show up at weirdly coincidental times; for example, I leave for work (he leaves the house for a period of time each day as well; again, SUPER predictable routine), but I get off early and come home. Minutes later, he pulls in the driveway, and if I ask what he’s doing back, he’ll say something like “oh I forgot ABC” or some other excuse. There’s been so many odd incidents, it’s hard to put into words. One other thing I’ve noticed is that sometimes he has knowledge of things that he could not possibly know unless something was recording me.

He also loves to put on a big show of how technologically inept he is; asking my sibling that was a computer science major for help, and saying bs like “I’m just not good with this stuff!!” It is extremely theatrical; it makes me sick.

My mom lives near to him, and recently, while I was out of town, I asked if she could go to the house and do something for me (while he wasn’t there of course). Shocker, he shows up within minutes, which really unsettled my mom and made her upset, because she was certain he had left for the day.

Is there some way I can find out if there are listening devices or hidden cams without spending an arm or a leg? I am beyond tired of not only dealing with his abusive, toxic behavior; but also being low-key paranoid that I’m being watched and listened to in my own home. Any advice would be greatly appreciated. Thanks y’all.

** One other, less important comment. He is weirdly insistent on my siblings and I being on his cell plan because it “saves him money.” The thing is, we’re all grown and he typically abhors paying for anything for us. I want to get off of his plan but because he’s the administrator, or whatever, my provider won’t even let me out of the contract without his approval. It’s insane. Is there some way for me to leave his plan? I really want to keep my current number. Is his insistence on us staying on his plan just run of the mill controlling behavior or is he somehow gleaning info on us from it?

Sorry for the novel.

reddit.com
u/Ok-Analysis-9296 — 10 days ago
▲ 97 r/opsec+1 crossposts

I tracked mulvad use with Find My IP for a week

Takeaways: obfuscation is more effective than trying to minimize and lock every tracker down

Disconnecting from Wi-Fi with my VPN still connected and then connecting to cell service was a major exposure point that allowed very distinct travel patterns because the VPN ip remained unchanged as I hoped from cell towers driving

Circadian patterns: phone being locked puts the phone in a sleep state that changes background network settings. My sleep and awake times are easily followable by network connection patterns.

So instead of minimizing my online presence I think controlled randomized data will be more privacy friendly

i have read the rules

reddit.com
u/bilbywilby — 12 days ago