#OPSEC365 047/365
Your smart TV shares a network with your laptop, phone, and NAS. That's a compartmentalization failure.
ACR runs by default on Vizio, Samsung, and LG โ fingerprinting your viewing. A TV with a vulnerable update path is a lateral pivot into your LAN.
Cronk's SEPARATE strategy: partition contexts with different trust levels. Your TV needs internet. It has no need to see your other devices.
VLAN your IoT tier. Your TV doesn't need to know your NAS exists.
Implementation: create an isolated IoT VLAN with internet-only egress, no routing to your primary LAN. A smart TV's legitimate function requires only outbound streaming access โ zero visibility into personal devices.
Sam Bent
contact@sambent.com
npub1y7rv...d0r3
Agorist. Counter-economist. Privacy maximalist. Student of OPSEC. Anti-authoritarian. Free speech absolutist. Logician. Ex-Darknet Vendor. Youtuber.
Secure means your funds can't be seized without your keys,
private means no one sees your balance or transactions,
untraceable means chain analysis is useless,
Monero is the only cryptocurrency that delivers all three by default.


Monero devs spent years quietly building FCMP++
while Zcash devs spent years lobbying regulators and tweeting about compliance
one project shipped privacy,
the other shipped press releases.


"No money in the budget" only applies to things that help you.


Happy birthday to the only 12-year-old the FBI, IRS, Chainalysis, and Europol
all failed to groom into an informant.
$XMR


#OPSEC365 021/365
OPSEC Step 2 is threat analysis: research your adversary's actual collection capabilities. Public records, court databases, social media aggregators, data brokers, and reverse image search form a surveillance infrastructure anyone can access for under $50/month.
Your adversary doesn't need hacking skills. They need patience.
NTTP 3-13.3 lists adversary collection as HUMINT, SIGINT, OSINT, GEOINT, and MASINT. For most civilians, HUMINT and OSINT are the primary threats. Digital countermeasures alone fail if your adversary collects via human contact.
Ken Thompson's acceptance speech for the Turing Award on security thinking.
"The moral is obvious. You can't trust code that you did not totally create yourself."
- ๐๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ถ๐ป ๐๐ต๐ฒ ๐ฅ๐ฒ๐ฎ๐น ๐ช๐ผ๐ฟ๐น๐ฑ by Butler Lampson (2004)
https://www.microsoft.com/en-us/research/wp-content/uploads/2004/06/Computer-Security-in-the-Real-World.pdf


Monero has survived ten years on donations and volunteer labor while VC-backed "privacy" projects burned through millions building compliance tools,
turns out you don't need a marketing budget when the product actually works.


Congress forced telecoms to build surveillance backdoors in 1994.
Chinese hackers found them.
The government's response is to ban your router.


Anon, Feds hate you, it's not just a meme.
๐๐น๐ถ๐ฐ๐ฒ ๐ ๐ฎ๐ฟ๐ถ๐ฒ ๐๐ผ๐ต๐ป๐๐ผ๐ป | ๐๐ถ๐ณ๐ฒ ๐๐ถ๐๐ต๐ผ๐๐ ๐ฝ๐ฎ๐ฟ๐ผ๐น๐ฒ + ๐ฎ๐ฑ ๐๐ฒ๐ฎ๐ฟ๐
Relaying phone messages in a cocaine conspiracy.
First arrest ever.
๐ช๐ฒ๐น๐ฑ๐ผ๐ป ๐๐ป๐ด๐ฒ๐น๐ผ๐ | ๐ฑ๐ฑ ๐๐ฒ๐ฎ๐ฟ๐
Three sales of $350 worth of marijuana with an alleged ankle holster.
No prior record.
๐๐ถ๐ฐ๐ธ๐ ๐๐ผ๐ฒ ๐๐ฎ๐ฐ๐ธ๐๐ผ๐ป | ๐๐ถ๐ณ๐ฒ ๐๐ถ๐๐ต๐ผ๐๐ ๐ฝ๐ฎ๐ฟ๐ผ๐น๐ฒ
Transported meth on his truck route to pay for his dying toddler's $250,000 bone marrow transplant after insurance dropped them.
๐๐ฒ๐ผ๐ฟ๐ด๐ฒ ๐ ๐ฎ๐ฟ๐๐ผ๐ฟ๐ฎ๐ป๐ผ | ๐๐ถ๐ณ๐ฒ ๐๐ถ๐๐ต๐ผ๐๐ ๐ฝ๐ฎ๐ฟ๐ผ๐น๐ฒ
Pleaded guilty to drug charges expecting 40-54 months per the prosecution's own recommendation.
The judge gave him the maximum to pressure him into snitching on the Philly mob.
๐ง๐ถ๐บ๐ผ๐๐ต๐ ๐ง๐๐น๐ฒ๐ฟ | ๐๐ถ๐ณ๐ฒ ๐๐ถ๐๐ต๐ผ๐๐ ๐ฝ๐ฎ๐ฟ๐ผ๐น๐ฒMailed LSD to a Grateful Dead concert friend.
Two prior nonviolent drug offenses triggered the federal three-strikes provision.
๐๐ฎ๐๐ฒ ๐ช๐ถ๐ป๐๐น๐ผ๐ | ๐๐ถ๐ณ๐ฒ ๐๐ถ๐๐ต๐ผ๐๐ ๐ฝ๐ฎ๐ฟ๐ผ๐น๐ฒ
Acted as a $5 middleman in a $20 crack sale to an undercover cop in Shreveport, Louisiana.
๐๐ผ๐ฟ๐๐ฎ๐ถ๐ป ๐๐ผ๐ผ๐ฝ๐ฒ๐ฟ | ๐๐ถ๐ณ๐ฒ ๐๐ถ๐๐ต๐ผ๐๐ ๐ฝ๐ฎ๐ฟ๐ผ๐น๐ฒ
Federal marijuana conspiracy.
Never touched the product, no violence.
Sentenced under the federal three-strikes drug law.
๐ฃ๐ฎ๐๐ฟ๐ถ๐ฐ๐ธ ๐ ๐ฎ๐๐๐ต๐ฒ๐๐ | ๐๐ถ๐ณ๐ฒ ๐๐ถ๐๐ต๐ผ๐๐ ๐ฝ๐ฎ๐ฟ๐ผ๐น๐ฒ
Stole tools from a shed in Slidell, Louisiana.
Enhanced by prior nonviolent convictions under habitual offender laws.
Monero devs have never once suggested building backdoors for law enforcement,
Zcash's founder suggested it publicly then asked you to memory-hole his own words.


#OPSEC365 006/365
Posting vacation photos while you're still on vacation tells everyone exactly when your home is unoccupied.
The timestamp, the location tag, and the caption all confirm you're hundreds of miles away and won't be back for days.
Save the photos. Post them when you're home. See if you can resist the urge to broadcast your absence in real time.
If you have to post during travel, strip location data and avoid revealing details that pin down your specific location or how long you'll be gone. General photos without landmarks are harder to geolocate than a poolside shot with a resort logo visible in the background.
The enemy is at the gates.
Do you see where this is going?
Red = Removing


Dylan, useful idiot with commit access, pushed age verification PRs to systemd, Ubuntu & Arch,
got 2 Microslop employees to merge it, called it 'hilariously pointless' in the PR itself,
then watched Lennart personally block the revert after community outrage.
Unpaid compliance simp.


Sam Bent
The Engineer Who Tried to Put Age Verification Into Linux
Dylan, useful idiot with commit access, pushed age verification PRs to systemd, Ubuntu & Arch, got 2 Microslop employees to merge it, called it 'hi...

Europol didn't say "difficult to trace" or "challenging"....
they said can't, and that word choice matters.


Motorola is building a phone specifically for GrapheneOS.
The Pixel monopoly on mobile privacy is over.


Apple's Mandatory ID... GrapheneOS is the Exit
Apple requires your government ID to use your own phone.
Decline and you lose app access.
The "age check" company already got breached and is funded by the co-founder of Palantir.


A botnet that broke DDoS records at 31.4 terabits per second accidentally crippled I2P's anonymity network
while trying to use it as a backup command infrastructure, and the developers responded with post-quantum cryptography enabled by default.


Sam Bent
I2P 2.11.0 Ships Post-Quantum Crypto After Botnet Siege
A botnet that broke DDoS records at 31.4 terabits per second accidentally crippled I2P's anonymity network while trying to use it as a backup comma...
Ubuntu Thinks You're Retarded, and That Checkboxes Are Dangerous...


Sam Bent
Ubuntu Thinks You're Retarded, and That Checkboxes Are Dangerous
Canonical pulled the Software & Updates GUI from Ubuntu 26.04 because they decided the checkboxes were "dangerous" for you, a person who somehow ma...

The I2P Ecosystem Explodes: Multiple
New Router Implementations Signal a Privacy Revolution.


Sam Bent
The I2P Ecosystem Explodes: Multiple New Router Implementations Signal a Privacy Revolution
The Invisible Internet Project (I2P) just announced something remarkable: multiple new, fully-functioning I2P router prototypes have emerged, marki...
