H
highefforthreads
Send me a guide and i'll rep + comment
- Joined
- Aug 28, 2026
- Posts
- 274
- Reputation
- 319
A beginners guide to privacy on the internet
sudo apt install opsec
sudo apt install opsec
Introduction:
Alright so its been a few days since I made a beginners guide to osint, and I wanted to make a counter to protect yourself from those techniques. I struggle to use the word "Opsec" in this guide because it seems like its becoming another tiktok buzzword because believe it or not, some people think they are a super scary anonymous hacker by installing arch. But in all seriousness, Opsec (operational security) is essentially doing everything you can online (and sometimes offline) to keep your private information safe from bad actors/threats. Now, by no means am I an expert in this, but as a beginner I want to share with you guys what I have learned over the past few months or so. Also this guide isn't as in-depth as some of the other guides, the only reason i'm making this is because I go more in depth into the behavioral side so if I would pay attention to that section mainly. This is like 5000 words so if your too lazy to read I have a TLDR at the bottom.
01 - Identifying Threats (Threat Modeling)
You want to ask yourself "who am I hiding from?" hiding from your average joe who is mad at you for stealing their egirl is going to be much more simple and a more straight forward approach than hiding from government agencies or Interpol. This guide is mainly basic security/habitual improvements and anti-corporate surveillance rather than a schizos guide to hide from the government.
You want to ask yourself "who am I hiding from?" hiding from your average joe who is mad at you for stealing their egirl is going to be much more simple and a more straight forward approach than hiding from government agencies or Interpol. This guide is mainly basic security/habitual improvements and anti-corporate surveillance rather than a schizos guide to hide from the government.
02 - Mindset:
When practicing, its important you make the following considerations:
Ask yourself, what information is currently out there. If a threat actor were to find that information, what would they be able to find next?
Think back to your day to day conversations with your friends or even in a discord server/old forum. What are you revealing about your personal life? Are you revealing even subtle hints that you may be unaware about?
General Rules of Thumb:
1. If the Government wants you bad enough, they will find you with almost 100% certainty. No mater the tools. Think about all the 150+ IQ prodigies that the government has working for them that would gladly do the work to get a sweet bonus.
2. Trust nothing. Assume everything is backdoored and act accordingly. Don't think that because your using a VPN your safe. Assume the government has every tool imaginable to crack into anything.
3. Set up many safety nets. For example, your first line for your IP address defense is your vpn, then proxies, etc. Always protect the first safety net so you never end up getting to the second net and so on.
When practicing, its important you make the following considerations:
Ask yourself, what information is currently out there. If a threat actor were to find that information, what would they be able to find next?
Think back to your day to day conversations with your friends or even in a discord server/old forum. What are you revealing about your personal life? Are you revealing even subtle hints that you may be unaware about?
General Rules of Thumb:
1. If the Government wants you bad enough, they will find you with almost 100% certainty. No mater the tools. Think about all the 150+ IQ prodigies that the government has working for them that would gladly do the work to get a sweet bonus.
2. Trust nothing. Assume everything is backdoored and act accordingly. Don't think that because your using a VPN your safe. Assume the government has every tool imaginable to crack into anything.
3. Set up many safety nets. For example, your first line for your IP address defense is your vpn, then proxies, etc. Always protect the first safety net so you never end up getting to the second net and so on.
03 - Browsers:
Choosing the right browser can help, as it allows for an extra layer of security. However, don't expect it to do all the heavy lifting. Some good browsers are:
Tor:
Tor normally routes your connection through three relays. Each relay only knows limited information about the connection, so no single relay normally knows both what your real IP address is and where you're connecting. "But highefforthreads, whats stopping someone from working backwards? Well, the relays are handling thousands of users at once. This makes a huge messy web that makes it hard to track the original IP. Tor is good for obvious reasons, as it essentially masks your IP address with better encrpytion than a standard VPN as well as search history (but isp can see your connecting to tor) As you all probably know, tor is notoriously slow and has those fucking annoying captcha's that even when you get them right, it rejects you like 100 times before finally letting you browse. This makes everyday tasks feel like hell on earth. Also, tor cannot protect you if you reveal PII (Personal identifying info) such as your name, address, email, etc
Brave:
Unlike tor, brave does not hide your IP address (although you can use the built in VPN which I do not recommend) but it does block trackers to build an advertising profile on you. It has an inbuilt feature allowing you to access "tor" much quicker, but I believe its not as safe as using tor itself. It also has much higher speed on the regular browser than tor which is a positive, but then again, it still has it's limitations and isn't really built for anominity. Also, its chromium based which is another potential down side cuz its made by google.
Honorable Mentions:
Mullvad
Hardened Firefox - Haven't looked into this much, still be cautious
Opera Gx - True opsec tool, best on the market!!!!!!!! (Just kidding, this is chinese spyware

)
Choosing the right browser can help, as it allows for an extra layer of security. However, don't expect it to do all the heavy lifting. Some good browsers are:
Tor:
Tor normally routes your connection through three relays. Each relay only knows limited information about the connection, so no single relay normally knows both what your real IP address is and where you're connecting. "But highefforthreads, whats stopping someone from working backwards? Well, the relays are handling thousands of users at once. This makes a huge messy web that makes it hard to track the original IP. Tor is good for obvious reasons, as it essentially masks your IP address with better encrpytion than a standard VPN as well as search history (but isp can see your connecting to tor) As you all probably know, tor is notoriously slow and has those fucking annoying captcha's that even when you get them right, it rejects you like 100 times before finally letting you browse. This makes everyday tasks feel like hell on earth. Also, tor cannot protect you if you reveal PII (Personal identifying info) such as your name, address, email, etc
Brave:
Unlike tor, brave does not hide your IP address (although you can use the built in VPN which I do not recommend) but it does block trackers to build an advertising profile on you. It has an inbuilt feature allowing you to access "tor" much quicker, but I believe its not as safe as using tor itself. It also has much higher speed on the regular browser than tor which is a positive, but then again, it still has it's limitations and isn't really built for anominity. Also, its chromium based which is another potential down side cuz its made by google.
Honorable Mentions:
Mullvad
Hardened Firefox - Haven't looked into this much, still be cautious
Opera Gx - True opsec tool, best on the market!!!!!!!! (Just kidding, this is chinese spyware


)04 - Operating Systems:
Tails:
Tails OS runs from the memory while booting from a USB drive and routes all internet traffic to tor and after your done it wipes the data once it shuts down. Like all the other operating systems, it comes with useful tools that can help. The only down sides is the set-up, as some can find it annoying especially if on a device without USB ports.
Qubes:
Qubes OS is basically an operating system that lets you separate your different activities. You can have one section for personal stuff, another for school, another for random browsing, etc. If something happens in one section, it stays separated from the others. This is good because you aren't putting everything in the same place. It also has disposable sections that you can use for things you don't want to keep around. The downside is that Qubes can be confusing and needs a pretty decent computer.
Whonix:
Whonix is an operating system made to use Tor. It basically separates your internet connection from the computer you are actually using, so your programs go through Tor instead of directly connecting to the internet. Whonix is useful if you want the benefits of Tor without having to set everything up yourself. But of course, the main issue is the learning barrier and the usability so you won't see your average joe using it.
GrapheneOS: (MOBILE)
GrapheneOS is basically a privacy version of Android. It gives you more control over what apps can access and lets you separate different apps and accounts more easily. It's also designed to collect less unnecessary information than normal Android. It's good because your phone usually has a ton of personal information on it, so having more control over what apps can access can make a big difference. The downside is that it's mainly made for Google Pixel phones, and some apps may not work exactly the same as they do on normal Android.
There are other operating systems but these are the ones I know cuz i'm less experienced with operating systems.
Tails:
Tails OS runs from the memory while booting from a USB drive and routes all internet traffic to tor and after your done it wipes the data once it shuts down. Like all the other operating systems, it comes with useful tools that can help. The only down sides is the set-up, as some can find it annoying especially if on a device without USB ports.
Qubes:
Qubes OS is basically an operating system that lets you separate your different activities. You can have one section for personal stuff, another for school, another for random browsing, etc. If something happens in one section, it stays separated from the others. This is good because you aren't putting everything in the same place. It also has disposable sections that you can use for things you don't want to keep around. The downside is that Qubes can be confusing and needs a pretty decent computer.
Whonix:
Whonix is an operating system made to use Tor. It basically separates your internet connection from the computer you are actually using, so your programs go through Tor instead of directly connecting to the internet. Whonix is useful if you want the benefits of Tor without having to set everything up yourself. But of course, the main issue is the learning barrier and the usability so you won't see your average joe using it.
GrapheneOS: (MOBILE)
GrapheneOS is basically a privacy version of Android. It gives you more control over what apps can access and lets you separate different apps and accounts more easily. It's also designed to collect less unnecessary information than normal Android. It's good because your phone usually has a ton of personal information on it, so having more control over what apps can access can make a big difference. The downside is that it's mainly made for Google Pixel phones, and some apps may not work exactly the same as they do on normal Android.
There are other operating systems but these are the ones I know cuz i'm less experienced with operating systems.
05 - Social Media
Social media is very powerful when it comes to digging up information on a person. (by social media I mean all social platforms including gaming, communications, etc.) There are a few straight forward methods you can use to keep your social medias clean:
Sign up using a completely new burner email/phone number:
I have a more detailed section below, but this is self explanatory. If your credentials are all dead ends, it gives individuals false signals when using OSINT tools based on your username.
Username hygiene:
Set your username to something completely different and non-identifiable to cover yourself from username lookups (one of the most common methods of OSINT) But I really want to put an emphasis on making it completely different which means having no interests or commonly talked about things in your username. Good examples include: random characters username, generic usernames not related to interests, or random numbers. try not to reuse usernames.
Private Accounts:
Probably the most self-explanatory part, set your account to private on all platforms and remove any personal identifying info. However, on platforms like instagram, setting your account to private isn't enough due to the suggested accounts feature which essentially bypasses and allows you to see followers/following. To prevent this, go Settings >> Edit Profile >> Show account suggestions on profiles (toggle off)
Removing PII:
Remove everything that can potentially give away emails, friends, schools, workplace, etc. Even a private account can showcase the bios. If you are staying public and have posts, wipe all PII as well. don't forget to wipe include GPS coordinates of photos.
Being mindful of followers/friends:
Be mindful of who tries to follow you. Only allow friends you 100% know and trust well and be aware of any suspicious accounts. Also, know that a smart attacker won't try to find you directly. They will go through your friends to eventually find you through correlation (good reason not to reuse usernames/profile pictures0. So be mindful of that as well
Social media is very powerful when it comes to digging up information on a person. (by social media I mean all social platforms including gaming, communications, etc.) There are a few straight forward methods you can use to keep your social medias clean:
Sign up using a completely new burner email/phone number:
I have a more detailed section below, but this is self explanatory. If your credentials are all dead ends, it gives individuals false signals when using OSINT tools based on your username.
Username hygiene:
Set your username to something completely different and non-identifiable to cover yourself from username lookups (one of the most common methods of OSINT) But I really want to put an emphasis on making it completely different which means having no interests or commonly talked about things in your username. Good examples include: random characters username, generic usernames not related to interests, or random numbers. try not to reuse usernames.
Private Accounts:
Probably the most self-explanatory part, set your account to private on all platforms and remove any personal identifying info. However, on platforms like instagram, setting your account to private isn't enough due to the suggested accounts feature which essentially bypasses and allows you to see followers/following. To prevent this, go Settings >> Edit Profile >> Show account suggestions on profiles (toggle off)
Removing PII:
Remove everything that can potentially give away emails, friends, schools, workplace, etc. Even a private account can showcase the bios. If you are staying public and have posts, wipe all PII as well. don't forget to wipe include GPS coordinates of photos.
Being mindful of followers/friends:
Be mindful of who tries to follow you. Only allow friends you 100% know and trust well and be aware of any suspicious accounts. Also, know that a smart attacker won't try to find you directly. They will go through your friends to eventually find you through correlation (good reason not to reuse usernames/profile pictures0. So be mindful of that as well
06 - Metadata
Metadata searching is one of the oldest tricks in the book. Essentially images contain data within them such as camera details, camera settings, time and date, and even gps coords. Fortunately there are many tools to remove metadata and most major platforms wipe it. (Do be cautious on xenoforo forums as i'm pretty sure most do not wipe although this site does I believe)
Tools to remove:
https://www.metadata2go.com/delete-metadata
https://www.privmeta.com/
best option is to use inbuilt tools in OS
Metadata searching is one of the oldest tricks in the book. Essentially images contain data within them such as camera details, camera settings, time and date, and even gps coords. Fortunately there are many tools to remove metadata and most major platforms wipe it. (Do be cautious on xenoforo forums as i'm pretty sure most do not wipe although this site does I believe)
Tools to remove:
https://www.metadata2go.com/delete-metadata
https://www.privmeta.com/
best option is to use inbuilt tools in OS
07 - VPNs
VPN's mask the IP address, but don't expect complete safety considering pretty much all VPN services are backdoored + they can be supeanoed
Mullvad VPN:
Good because you don't have to sign up with an email. It's also quite cheap and you can pay in many safer ways like mailing physical money.
Proton VPN:
Decent if you are trying to avoid sites collecting information but bad if you are trying to go for anominity cuz proton is probably backdoored like many of the other VPN services. (not sure)
Law enforcement can issue something known as suponeas which are basically requests to the vpn provider to give over your real IP address so keep that in mind.
VPN's mask the IP address, but don't expect complete safety considering pretty much all VPN services are backdoored + they can be supeanoed
Mullvad VPN:
Good because you don't have to sign up with an email. It's also quite cheap and you can pay in many safer ways like mailing physical money.
Proton VPN:
Decent if you are trying to avoid sites collecting information but bad if you are trying to go for anominity cuz proton is probably backdoored like many of the other VPN services. (not sure)
Law enforcement can issue something known as suponeas which are basically requests to the vpn provider to give over your real IP address so keep that in mind.
08 - Signing Up to Sites
This section mainly touches on how to sign up for platforms effectively and for privacy:
1. Use a secure operating system and browser (either tor) or vpn + brave + javascript DISABlED FROM TOR on a burner laptop.
2. Get a short/long term temporary email service like tempmail or proton depending on your needs ready
3. Choose a non-identifiable username + profile picture
4. Set password to randomly generated password (Or js smash ur keyboard or smth if you worry about randomness)
5. Store these passwords in a password manager and a paper notebook hidden somewhere if ur that paranoid
6. Verify email and your set.
This section mainly touches on how to sign up for platforms effectively and for privacy:
1. Use a secure operating system and browser (either tor) or vpn + brave + javascript DISABlED FROM TOR on a burner laptop.
2. Get a short/long term temporary email service like tempmail or proton depending on your needs ready
3. Choose a non-identifiable username + profile picture
4. Set password to randomly generated password (Or js smash ur keyboard or smth if you worry about randomness)
5. Store these passwords in a password manager and a paper notebook hidden somewhere if ur that paranoid
6. Verify email and your set.
09 - Behavior
When a threat actor is trying to correlate informatiton accross platforms, they will often pay attention to behavior:
Language:
This is quite important. Using similar language/dialogue unique to you is a very strong correlation tool for threat actors. Do you have a specific saying or group of things you say? Do you capitalize every first word of a sentence (sometimes people can use this to detect whether your using a phone/pc cuz autocorrect) do you type formally or do you use a lot of specific slang words. Do you use vocabulary specific to certain space on the internet (for example LM vocabulary could hint to outsiders your familiar with the lm space) Do you say language specific things (for example certain languages omit "the" or "a" so if someone consistently forgets to say those thtings, it could hint they are of different nationalities. Do you use country-specific slang words such as "mate" or "bruv" The point is, try to become aware of your speaking pattern. For example, you probably are now familiar with my speaking tendencies, so use the pattern recognition you've developed to identify your uniquely identifying language patterns.
Interactions:
This section is mainly to touch on who you interact with and how to navigate it. Like threat modeling, its important to assess your surroundings and who you interact with on a daily basis. If you choose to interact with someone in a poor way you know is bad news (such as an egangster on discord) you got 1 more thing to worry about even if the individual cannot do harm to your privacy. It's very important to pick your interactions wisely is the main point and don't put a big red target on your back.
Friends:
Be weary of what you send to your online friends. Not because they would do anything, but because a threat actor can sometimes target your close friends in order to find social medias or other platforms where you have shared with friends. Now i'm not saying don't send your socials to friends, instead follow the social media hygiene guide above to have a good chance of avoiding this route.
Activity patterns:
One of the most efficent ways to find someones general location and daily routine is through activity mapping which is essentially identifying when the individual talks most and when they seem to slow down talking. Simply talk at random times throughout the day on a random basis: for example, monday you talk 3 times, at 3 hour intervals, next day you talk 10 times at 1 hour intervals, and the next you only talk at night to make it more difficult to pinpoint routine/location. However, if it becomes obvious you are trying to mislead individuals, (like for example if people know your privacy focused and you put in your bio your going to sleep) that will become a character trait in of itself.
Attributes:
Chances are, your username/profile picture have some sort of meaning. For instance, my name is highefforthreads because I make high effort threads like this one! But to be real for a sec, your username likely has meaning to it and a potential threat actor could take note of this and try to correlate smaller clues. Same with your profile picture. For instance, if you have a profile picture of a model, people can assume your in the LM space, and thats where people will start searching to get more leads.
Sharing awareness:
Probably one of the most valuable parts of this guide. I cannot stress this enough. Every detail, big or small, compounds over time. Remember that seemingly harmless screenshot showing your current time you shared? That's a problem, as later in an investigation a threat actor can correlate your timezone and the clue to determine if it's a valuable lead or not.
Compartmentalization/Identity:
Think of Compartmentalization as many different boxes where you store different identities such that each have their own unique color and appearance. Try to keep each online persona seperate with different activity patterns, vocabulary, story, etc. and sealed off completely from your other online identities.
When a threat actor is trying to correlate informatiton accross platforms, they will often pay attention to behavior:
Language:
This is quite important. Using similar language/dialogue unique to you is a very strong correlation tool for threat actors. Do you have a specific saying or group of things you say? Do you capitalize every first word of a sentence (sometimes people can use this to detect whether your using a phone/pc cuz autocorrect) do you type formally or do you use a lot of specific slang words. Do you use vocabulary specific to certain space on the internet (for example LM vocabulary could hint to outsiders your familiar with the lm space) Do you say language specific things (for example certain languages omit "the" or "a" so if someone consistently forgets to say those thtings, it could hint they are of different nationalities. Do you use country-specific slang words such as "mate" or "bruv" The point is, try to become aware of your speaking pattern. For example, you probably are now familiar with my speaking tendencies, so use the pattern recognition you've developed to identify your uniquely identifying language patterns.
Interactions:
This section is mainly to touch on who you interact with and how to navigate it. Like threat modeling, its important to assess your surroundings and who you interact with on a daily basis. If you choose to interact with someone in a poor way you know is bad news (such as an egangster on discord) you got 1 more thing to worry about even if the individual cannot do harm to your privacy. It's very important to pick your interactions wisely is the main point and don't put a big red target on your back.
Friends:
Be weary of what you send to your online friends. Not because they would do anything, but because a threat actor can sometimes target your close friends in order to find social medias or other platforms where you have shared with friends. Now i'm not saying don't send your socials to friends, instead follow the social media hygiene guide above to have a good chance of avoiding this route.
Activity patterns:
One of the most efficent ways to find someones general location and daily routine is through activity mapping which is essentially identifying when the individual talks most and when they seem to slow down talking. Simply talk at random times throughout the day on a random basis: for example, monday you talk 3 times, at 3 hour intervals, next day you talk 10 times at 1 hour intervals, and the next you only talk at night to make it more difficult to pinpoint routine/location. However, if it becomes obvious you are trying to mislead individuals, (like for example if people know your privacy focused and you put in your bio your going to sleep) that will become a character trait in of itself.
Attributes:
Chances are, your username/profile picture have some sort of meaning. For instance, my name is highefforthreads because I make high effort threads like this one! But to be real for a sec, your username likely has meaning to it and a potential threat actor could take note of this and try to correlate smaller clues. Same with your profile picture. For instance, if you have a profile picture of a model, people can assume your in the LM space, and thats where people will start searching to get more leads.
Sharing awareness:
Probably one of the most valuable parts of this guide. I cannot stress this enough. Every detail, big or small, compounds over time. Remember that seemingly harmless screenshot showing your current time you shared? That's a problem, as later in an investigation a threat actor can correlate your timezone and the clue to determine if it's a valuable lead or not.
Compartmentalization/Identity:
Think of Compartmentalization as many different boxes where you store different identities such that each have their own unique color and appearance. Try to keep each online persona seperate with different activity patterns, vocabulary, story, etc. and sealed off completely from your other online identities.
10 - Identifying/Removing Information Online
This section mainly focuses on identifying potentially revealing information and removing it before it becomes an issue. However, as you probably know, everything you do/say on the internet stays forever in some server or something, so this is to protect against surface level threats. (Be minfdul cause Wayback machine and past data leaks exists)
Step 1: Search yourself
The main goal of this step is to see what your vunerabilities are so you can patch them later. I made an in-depth OSINT guide which you can use to see your major vunerabilities. Please keep in mind my guide is from a beginner, so its not perfect at covering all angles and uncovering deeper information. I'd suggest going through each module seperately one at a time and really drilling the tools.
Step 2: Map out vunerabilities
Make a list of every single vunerability. Then categorize them based on the difficulty of the removal process. You could also categorize them based off threat level as well, but considering a vunerability implies something that can lead to harm, they should all be taken care of equally imo. Also, make this map somewhere private, as it would be a shame if you accidentally pasted it somewhere for the whole internet to see.
Step 3: Removal of vunerabilities:
Now that you have a solid list of vunerabilities, there are various ways to go about removing them. I would begin by tackling the easiest ones first like reused usernames, profiles, bios, PII, or any similarities across platforms that you have access to, then changing emails, passwords, privating accounts completely etc (keep in mind if your data was leaked before it will show the email address at the time it was leaked) Then if you want, do a pimeyes search just to be sure your face isn't on any platforms. Then, to tackle people searches there is an option to opt out of having that information public. Also, you can request removal of your personal data from search engines (however i'm pretty sure it can be accessed via wayback machine) Any data you cannot remove try to mask it as much as possible.
This section mainly focuses on identifying potentially revealing information and removing it before it becomes an issue. However, as you probably know, everything you do/say on the internet stays forever in some server or something, so this is to protect against surface level threats. (Be minfdul cause Wayback machine and past data leaks exists)
Step 1: Search yourself
The main goal of this step is to see what your vunerabilities are so you can patch them later. I made an in-depth OSINT guide which you can use to see your major vunerabilities. Please keep in mind my guide is from a beginner, so its not perfect at covering all angles and uncovering deeper information. I'd suggest going through each module seperately one at a time and really drilling the tools.
Step 2: Map out vunerabilities
Make a list of every single vunerability. Then categorize them based on the difficulty of the removal process. You could also categorize them based off threat level as well, but considering a vunerability implies something that can lead to harm, they should all be taken care of equally imo. Also, make this map somewhere private, as it would be a shame if you accidentally pasted it somewhere for the whole internet to see.
Step 3: Removal of vunerabilities:
Now that you have a solid list of vunerabilities, there are various ways to go about removing them. I would begin by tackling the easiest ones first like reused usernames, profiles, bios, PII, or any similarities across platforms that you have access to, then changing emails, passwords, privating accounts completely etc (keep in mind if your data was leaked before it will show the email address at the time it was leaked) Then if you want, do a pimeyes search just to be sure your face isn't on any platforms. Then, to tackle people searches there is an option to opt out of having that information public. Also, you can request removal of your personal data from search engines (however i'm pretty sure it can be accessed via wayback machine) Any data you cannot remove try to mask it as much as possible.
12 - Payments/Financial Security
Privacy Cards:
Using a privacy card can help mask your credentials to companies when buying things online, but it should only be used when you don't want the company seeing credentials as there are better options.
Cryptocurrency:
**Using cryptocurrency is a decent option, but it's important you choose the right brokers/currency to avoid transperancy laws/KYC and such. A good option is Monero because when you send the currency to someone else, your transcation address is mixed with many decoy addresses making it hard to know where it came from.
Gift Cards:
If you want to something online but don't want to put details anywhere, you can buy gift cards in person using cash. This helps because gift-cards can be activated without personal details meaning you can input a bunch of BS and be fine. Just know not to buy gift-cards with credit cards.
Cash:
Probably the best option and pretty self explanatory. However, do be mindful of surveillance when buying items using cash so if you don't want to be tied to what you are buying, buy a gift-card with the cash to purchase things online.
Privacy Cards:
Using a privacy card can help mask your credentials to companies when buying things online, but it should only be used when you don't want the company seeing credentials as there are better options.
Cryptocurrency:
**Using cryptocurrency is a decent option, but it's important you choose the right brokers/currency to avoid transperancy laws/KYC and such. A good option is Monero because when you send the currency to someone else, your transcation address is mixed with many decoy addresses making it hard to know where it came from.
Gift Cards:
If you want to something online but don't want to put details anywhere, you can buy gift cards in person using cash. This helps because gift-cards can be activated without personal details meaning you can input a bunch of BS and be fine. Just know not to buy gift-cards with credit cards.
Cash:
Probably the best option and pretty self explanatory. However, do be mindful of surveillance when buying items using cash so if you don't want to be tied to what you are buying, buy a gift-card with the cash to purchase things online.
13 - Honorable Mentions
Supeonas "EDR's"
Supeonas, more informally known as "EDR's (emergency data requests) are one of the most popular methods of doxxing. There isn't really anyway to prevent someone from EDRing you, the only way you could theoretically get around this is by using operating system which routes tor automatically with javascript disabled and a temp email when signing up for platforms with a non-identifable password, but realistically no one is doing allat plus most major sites will ask for ID verification if your a ukcel, plus this site has our IP's anyways. On KYC platforms i've seen people use specalized faceswap softwares for verification.
Webcam Taping
Some people take it wayyy to far and will as far as to gain entry to your webcam. Now this is a bit overkill, but you can get around this by putting tape on the webcam, but not just any tape. Most webcams use near-infared waves which pass right through normal tape so you have to use something like alluminum (I know it sounds dumb) but i'm sure the CIA can still see through your webcam regardless :lul
Supeonas "EDR's"
Supeonas, more informally known as "EDR's (emergency data requests) are one of the most popular methods of doxxing. There isn't really anyway to prevent someone from EDRing you, the only way you could theoretically get around this is by using operating system which routes tor automatically with javascript disabled and a temp email when signing up for platforms with a non-identifable password, but realistically no one is doing allat plus most major sites will ask for ID verification if your a ukcel, plus this site has our IP's anyways. On KYC platforms i've seen people use specalized faceswap softwares for verification.
Webcam Taping
Some people take it wayyy to far and will as far as to gain entry to your webcam. Now this is a bit overkill, but you can get around this by putting tape on the webcam, but not just any tape. Most webcams use near-infared waves which pass right through normal tape so you have to use something like alluminum (I know it sounds dumb) but i'm sure the CIA can still see through your webcam regardless :lul
14 - Conclusion
Conclusion:
So why should you even give two shits about privacy? If you got nothing to hide, why would you even need privacy? Well there are actually many reasons such as current/future social credit systems, freedom of speech without the risk of persecution, political or social activism, avoidance of targetted profiling based on corporate data collections, anti-govenrment surveillance and the obvious reasons. (illegal activity) You could go the schizo route and have a fucking VM in india bought from cash while wearing a fully detailed human face mask but that's impractical and unless your running from interpol or something is not neccesary at all. If you take away one thing from this guide, try to find a balance between being functional but also being secure. And also remember, unless your the GTA6 leaker, the government could probably care less about you and isn't coming after you and the government most likely has files on all of us anyways which is unfortunate.
(Remember, I am NOT claiming to be some expert in this (in fact quite the opposite) I just wanted to make this guide to help out fellow beginners like myself, so if I get anything in this guide wrong, please correct me and i'll change it swiftly!
Conclusion:
So why should you even give two shits about privacy? If you got nothing to hide, why would you even need privacy? Well there are actually many reasons such as current/future social credit systems, freedom of speech without the risk of persecution, political or social activism, avoidance of targetted profiling based on corporate data collections, anti-govenrment surveillance and the obvious reasons. (illegal activity) You could go the schizo route and have a fucking VM in india bought from cash while wearing a fully detailed human face mask but that's impractical and unless your running from interpol or something is not neccesary at all. If you take away one thing from this guide, try to find a balance between being functional but also being secure. And also remember, unless your the GTA6 leaker, the government could probably care less about you and isn't coming after you and the government most likely has files on all of us anyways which is unfortunate.
(Remember, I am NOT claiming to be some expert in this (in fact quite the opposite) I just wanted to make this guide to help out fellow beginners like myself, so if I get anything in this guide wrong, please correct me and i'll change it swiftly!
TL;DR ***Intermediate***
- Use an operating system like qubes, whonix, graphene etc (Only use this if your actually need the tools, please don't larp it, it just makes your life harder)
- Seperate laptops/phones
- Use brave, tor maybe hardened firefox?? (I don't know much about operating systems and browsers i'm rocking safari like a true opsec god)
- LARP your identity. Tell people your 6'5 ripped, blue eyed, whatever.
- Sign up to platforms using short term temp mails not linking to IP or VPN address and only use that account for the specific task
- use a vpn + backup proxies
- Burn bridges: Create a seperate username for every platform you use, set all accounts to private, remove all IRL stuff in general
- Find vunerabilities in your privacy and remove that information from databrokers
- Pay using crypto (prob monero) on non KYC brokerages; use gift-cards for other transcations
- Don't interact with shitty people who you know are going to be a problem/Don't make yourself a target
- Scrub Metadata, change file names using in-built OS features
- use VM's for risky downloads
- Be mindful of what you reveal and who you reveal it to.
- Try to find a balance between functional privacy and absolute privacy
TL;DR Beginner
- Set all accounts to private + scrub every account
- Request data broker removal of your data
- Don't reuse passwords/usernames/etc
- Use a VPN (For holy opsex trust)
- Use a privacy card or crypto currency
- Use Brave or hardened firefox, tor for more sensitive things
- try to seperate your online life from your offline life
- don't make yourself a target (for the love of god, please don't interact with discord egangsters)
- Remove metadata + change file names
- If you have an instagram, turn the "account suggestions" part off"
- Remember that all of our IP's are registered to this forum which is unfortunate, so don't say anything that could get you in trouble
- If being threatened, block immediately, report it or go to police station if being threatened with swatting.
Remember, I am NOT claiming to be some expert in this (in fact quite the opposite) I just wanted to make this guide to help out fellow beginners like myself, so if I get anything in this guide wrong, please correct me and i'll change it swiftly!






