Opsec foundations: the beginner's guide to not getting linked
read enough takedown affidavits and a pattern emerges that surprises newcomers: almost nobody is caught by breaking tor or cracking encryption. cases are built from a phone number written on a parcel, a photo reused across accounts, coins bought through an exchange that kept id scans, a notebook left in a kitchen drawer. operational security fails at the seams between identities, not in the middle of them. this guide lays the foundations: how to think about threats, which habits carry most of the weight, and what the boring baseline looks like.
start with a threat model, not a shopping list
security advice handed as a universal checklist - password manager, vpn, tor everything, encrypt all disks - optimizes for looking diligent rather than being safe. a threat model inverts the order. before choosing any tool, write down four things in plain language:
- assets: what would genuinely hurt if leaked, destroyed or forged - credentials, correspondence, financial records, location history, identities of people you talk to
- adversaries: who might realistically come after those assets
- capabilities: what your adversaries can actually do - opportunistic thieves want resale value, phishing crews want volume, employers want compliance, state agencies can subpoena providers and wait years
- acceptable losses: which exposures you can tolerate, because no protection is absolute
the payoff is proportionality. once your adversary has a name and a budget, you stop buying defenses against movie-plot villains and start fixing the exposures a real attacker would walk through. the electronic frontier foundation built its surveillance self-defense project around exactly this exercise, because everyone's threat model is genuinely different. our deeper walkthrough of threat-model thinking applies it step by step with worked examples.
separation of identities
compartmentalization is the foundation everything else stands on. a pseudonymous identity deserves its own email, its own usernames, its own photos, and its own writing habits, with zero overlap with anything attached to your legal name.
the two details that most often quietly link accounts are photos and phone numbers - both feel harmless, both are fingerprint-grade identifiers. usernames are worse: reuse across platforms lets anyone pivot from your pseudonym to your decade-old forum account. and writing style is a fingerprint you cannot rotate; stylometry matched punctuation quirks and pet phrases between a market persona and a public social account in a documented federal case.
practical rules:
- never log both identities into the same browser session, app, or device account
- generate distinct handles mechanically if needed, and never recycle them
- assume every joke phrase you type repeatedly is a biometric identifier
device basics that decide real outcomes
start with disk encryption protected by a long passphrase - not a four-digit pin - and keep operating systems updated. never sync the pseudonymous profile to cloud accounts tied to your name; autosave and photo backup have ended more pseudonymities than any hacker. a seized device should reveal as little context as possible.
physical separation beats clever software. a cheap dedicated device used for exactly one identity eliminates an entire class of cross-contamination mistakes, which is why privacy guides recommend compartmentalizing by machine or virtual machine. if you run isolated environments, our tails versus whonix guide maps which anonymous operating system fits which situation.
payment discipline
payment trails convict more reliably than any traffic analysis. blockchain records are permanent and public; exchanges in most jurisdictions collect and surrender customer identity data under subpoena. the landmark welcome-to-video takedown traced bitcoin through the public chain, subpoenaed exchanges, and arrested hundreds of users across dozens of countries without advanced forensics - sloppiness did all the work.
the working assumptions: every hop between your fiat on-ramp and any destination is recorded forever; wallet reuse is identity linkage because analysts treat it as such; and address hygiene is part of the job. validate destination addresses carefully before sending - our bitcoin and monero validators catch malformed or mistyped addresses locally - and read the broader picture in our wallet hygiene checklist.
passwords and passphrases
unique logins per site remain the cheapest massive win: credential stuffing feeds on reuse, and our notes on password hygiene cover the mechanics. for anything guarding keys or disks, prefer multi-word passphrases with real entropy - memorable for you, brutal for guessing attacks. our passphrase generator produces them from crypto-grade randomness and shows the entropy honestly.
what actually appears in court files
distill a hundred complaints and the recurring exhibits are:
- contact numbers written on parcels or handed to couriers
- cryptocurrency exchanged through identity-verified personal accounts
- usernames, photos or writing style reused across clearnet profiles
- unencrypted phones and laptops full of saved logins and messages
none of it required breaking encryption. it required patience and paperwork - which is worth internalizing before trusting any tool that promises anonymity while your daily-driver phone sits logged into everything.
putting the foundations together
- write your threat model in one paragraph: assets, adversaries, capabilities, tolerable losses. revisit it quarterly.
- build hard separation around your pseudonymous identity: dedicated email, handles, device or VM, and payment flow.
- encrypt devices with generated passphrases and enable updates everywhere.
- treat every payment as a permanent record; plan coin flows accordingly and verify addresses before sending.
- practice verification habits - fingerprints, signatures, address checksums - so they survive boredom, the state where most opsec dies.
opsec is not doing everything; it is doing the right few things on purpose. define what you protect and from whom, then close the boring gaps first - those are the ones that show up in indictments.
metadata and the leaks you cannot see
photos deserve their own warning because they feel harmless and leak systematically. exchangeable image file data can carry device model, timestamps and sometimes gps coordinates; screenshots are cleaner but embed screen dimensions that narrow down your hardware. the safe pattern for any image crossing between identities: strip metadata, crop uniquely, never reuse a photo across accounts, and reverse-image-search your own pictures occasionally to find where they have already traveled.
documents behave the same way. pdf exports embed author names from office software, torrent clients report client versions, and even text files carry editor fingerprints. before anything leaves an identity boundary, ask what the application stamped into it. the habit costs seconds; undoing a leaked real name inside a pseudonymous history is rarely possible at all.
delivery and contact details
physical logistics produce some of the bluntest evidence in court files: names on parcels, phone numbers handed to couriers, doorbell camera footage near drop locations. without going deeper into methods than a public safety guide should, the foundational principles are settled: contact information attached to your legal identity should never touch a pseudonymous supply chain, and every physical detail you expose - handwriting, packaging habits, timing patterns - is a signature someone can compare across shipments.
- a phone number is an identity anchor in most jurisdictions; treat giving it out as an identity decision, not a formality
- consistency across orders helps investigators more than any single order does - patterns live in aggregates
- anything written by hand links handwriting the way usernames link accounts
communication discipline
the channel you choose sets the ceiling for everything else. end-to-end encrypted messengers protect content but not membership: the fact that two accounts talk, when they talk, and how often is visible to the provider. moving sensitive conversations onto infrastructure designed for anonymity changes the exposure from "who talks to whom, forever" to "encrypted blobs exist". within whatever channel you use, discipline means keeping content minimal - no real names, no photos of identifiable places, no scheduling details that correlate with your public life.
availability heuristics matter too. accounts that only ever act during hours matching one time zone describe their owner's geography passively. so do replies that always pause on weekends. none of this requires a subpoena to collect, which is why disciplined personas introduce deliberate noise or simply accept slower response rhythms.
sustainability: why opsec fails slowly
the uncomfortable truth about operational security is that it degrades through success rather than failure. after twenty clean transactions, the rituals feel absurd; the note-taking stops, the second device becomes convenient, the old username resurfaces because it was easier. investigations run on exactly this decay - they wait, correlate older data with newer sloppiness, and let time do the work that hacking could not.
- write your rules down while motivated, as a short checklist you can re-read in two minutes.
- schedule a quarterly review: threat model current? devices patched? identities still separated?
- automate what can be automated - generated passphrases instead of invented ones, validators instead of eyeballs.
- define your exit ahead of time: which signs mean a persona gets retired, and what retirement looks like when executed calmly rather than mid-panic.
- treat boredom and convenience as the adversaries they are; most opsec dies by shortcut, not breach.
start with the threat model paragraph from the top of this guide, then work downward: separation first, devices second, payments third, communication fourth. each layer done roughly beats every layer done perfectly except the one you skipped - and the skipped layer is reliably the boring one.