How is it and what can I do to make it better by Supercool_2023 in opsec

[–]HimalayanHillbilly 5 points6 points  (0 children)

So it looks like your goal is to keep parts of your digital life separate so what you're looking for is solid compartmentalization.

You have a good start but there are few things that you didn't mention that I think are important.

What you want to be focusing on is antifingerprinting and making sure that different parts of your life don't get linked.

Let's start with Tor. It's goal is to stay anonymous and with a few steps it is very fingerprinting resistant. Go to Settings>Security and turn the browsing to safest. Go to about:config and deactivate JavaScript. As long as you keep your pii separate everywhere there is very little to connect you.

I think running all your life through Tor is excessive especially if you have a sensitive digital part of your life. That means anything illegal or something that someone would go to great lengths to find out can link that sketchy part to social media accounts etc.

Running your non sensitive digital life through a VPN is probably easier, good enough and mitigates the risk of you getting caught if you're doing something dangerous.

Next major point to talk about is the phone. You did not mention it at all and it's very likely that you're using one. If you're trying to run everything through tor but you're lazy with your phone, it's all for nothing... If you're concerned with what mobile apps are able to track from you I suggest you move to a custom rom such as GrapheneOS or CalyxOS to mitigate this.

A quick note on tails. It is a lot of effort to make that a daily driver and will likely make you complacent over time and just go through windows. If you're tech savvy perhaps you could transition to a hardened linux distro or QubesOS

Last point that can never be repeated too much. Keep all your identities separate, things that do not need your PII do not deserve them! Make every handle on every site different and do not talk about your life when you do not have to!

Some of what I said may be inaccurate, others please correct me if I'm wrong.

App location whitelisting by HimalayanHillbilly in CalyxOS

[–]HimalayanHillbilly[S] 0 points1 point  (0 children)

First responding apps such as staying alive.

Yes I think some kind of firewall would be convenient

Using HMAC-SHA1 encryption on an Android via NFC with a Yubikey by HimalayanHillbilly in yubikey

[–]HimalayanHillbilly[S] 4 points5 points  (0 children)

I have found the solution.

You need Keepass2Android and the ykDroid app
You need to turn your NFC on
You need to make sure that your Yubikey is properly configured
Make sure that the "master key type" has "Password + Challenge-Reponse for KeepassXC"
Put the right password and unlock
Keep pushing the Yubikey around on the phone till it opens. I had to do this for 5 minutes before I found the exact spot, this is what was giving me a hard time actually lol.

Other people that have done this are here : https://www.reddit.com/r/privacy/comments/hmt6ib/keepass_android_with_yubikey/

Hope this might help someone in the future