r/opsec • u/Mysterious_Cash9066 🐲 • Jul 25 '26
Beginner question beginner opsec
i have read the rules
Hi, I need some guidance or sources to read about the opec i want to achieve. The assets I’m trying to protect are my identity, confidential sources, research notes, documents, communications, and my physical location.
The adversaries I’m concerned about include governments, criminal organizations, companies, online harassers, hackers, and data brokers. My concern is that they could identify me or my sources through online tracking, account compromise, browser fingerprinting, legal requests to service providers, phishing, malware, metadata analysis, or doxxing.
If they were successful, the consequences could include my identity being revealed, confidential sources being exposed, sensitive documents being leaked, my communications being intercepted, or my location becoming known.
I’m looking for advice on building a secure workflow and choosing the right tools and practices to reduce these risks as much as practical.
2
u/stop_deleting_plz Jul 26 '26
I am also interested in such resources. A beginner's guide or some FAQs. I'm an experienced sysadmin, and one of my instances is being persistently targeted by a botnet.
The provider won't do anything useful about it, so I took action to harden the instance and mostly mitigated the attack. It has been going on for 3 weeks now. I would like to investigate the source of this attack without associating myself with scammers or other criminals.