#OPSEC365 124/365
RFID chips in your wallet and pocket can be scanned without your knowledge.
Transit cards, hotel keycards, office badges, and many credit cards hold RFID or NFC chips readable at short range with a $30 reader. Walk past one and the unique ID gets logged with no visible interaction.
US e-passports differ: shielded in a metal cover, locked by an optical key printed inside, unreadable while closed. The rest of your pocket isn't.
#OPSEC365
Sam Bent
contact@sambent.com
npub1y7rv...d0r3
Agorist. Counter-economist. Privacy maximalist. Student of OPSEC. Anti-authoritarian. Free speech absolutist. Logician. Ex-Darknet Vendor. Youtuber.
Put your tax bill next to what you actually got for it and tell me that's a fair deal with a straight face.


Hindsight hits different when you're reading your own transaction history in a federal indictment.


#OPSEC365 123/365
Parking tickets create timestamped records of where you parked.
Municipal databases log your license plate, location, time, and vehicle description. This data is searchable by city employees and sometimes by law enforcement across jurisdictions. Unpaid tickets follow your registration and become liens in some states.
Parking tickets have been used to place defendants at crime scenes they denied visiting.
#OPSEC365
Acoustic cryptanalysis. Extracting keys by listening to CPUs.
"Different operations produce different acoustic signatures that can reveal secret keys."
RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis by Daniel Genkin et al. (2013)

Acoustic cryptanalysis

Buy direct from the rancher and everyone between you and him loses their cut. That's why they made it difficult.


#OPSEC365 122/365
Private jets and most aircraft can be tracked in real time by anyone.
ADS-B transponders broadcast location data that hobbyist receivers capture and publish on sites like FlightAware and ADS-B Exchange. Elon Musk's jet, Taylor Swift's jet, and probably the aircraft you flew on last week are all trackable by anyone curious enough to look.
Search a tail number on flightaware.com and see where that plane has been.
#OPSEC365
#OPSEC365 121/365
Federal political donations over two hundred dollars become permanent public records.
The FEC database lists your name, address, employer, and occupation alongside every federal political contribution you make above the threshold. This data is searchable by anyone and often integrated into data broker profiles.
Federal political donations above $200 are permanently public record: name, address, employer, and amount, searchable by anyone.
#OPSEC365
Monero's privacy is only as decentralized as its node network, and every node you don't run
is one more opportunity for a honeypot operator to correlate metadata,
be the infrastructure you want to exist.


The Downfall of the EFF is sad to see.


#OPSEC365 120/365
Photos of your pets often reveal your location and routine.
That daily walk photo has metadata showing your neighborhood route. The vet check-in confirms your area. The microchip registration contains your address. Pet accounts geotagged at dog parks reveal where you spend weekends.
Pet photos carry the same GPS metadata as anything else you post, plus the pattern of your walking routes and vet schedule.
#OPSEC365
#OPSEC365 119/365
Home security companies know when your alarm is armed, which doors open, and when motion is detected.
ADT, Ring, SimpliSafe, and others store activity logs on their servers. Employees can access footage and sensor data. Law enforcement requests it regularly.
One ADT technician accessed 220 customers' camera feeds over 9,600 times before anyone noticed. A single insider at a single vendor.
#OPSEC365
Opening port 18080 lets you seed the blockchain like a torrent, and the network gets stronger every time someone does.


Evil maid attacks on full-disk encryption systems.
"Physical access to a powered-down laptop allows an attacker to modify the bootloader and capture encryption keys."
Evil Maid Goes After TrueCrypt by Joanna Rutkowska (2009)

Evil Maid goes after TrueCrypt! | The Invisible Things Blog
From time to time it’s good to take a break from all the ultra-low-level stuff, like e.g. chipset or TXT hacking, and do something simple, yet st...

#OPSEC365 118/365
Every time someone runs your credit, that inquiry appears on your report.
Hard pulls for credit applications stay visible for two years. Soft pulls happen when companies pre-screen you for offers or when you check your own credit. The pattern of inquiries reveals when you're shopping for loans, applying for apartments, or seeking new cards.
The record of who's been pulling your credit maps your financial activity precisely.
#OPSEC365
#OPSEC365 117/365
Your elementary school records might still exist somewhere.
FERPA (Family Educational Rights and Privacy Act) gives institutions wide latitude to retain records indefinitely. Disciplinary files, psychological evaluations, IEP documents, and test scores can resurface in background checks, legal proceedings, or data breaches decades later.
Most people have no idea what their schools kept or whether those systems are secure.
#OPSEC365
First they KYC'd your bank.
Then your crypto.
Now they want to KYC your phone line.


DMA attacks through Firewire and Thunderbolt ports.
"Direct Memory Access ports allow attackers to bypass all OS security and read/write arbitrary memory."
Hit by a Bus: Physical Access Attacks with Firewire by Adam Boileau (2006)
https://www.security-assessment.com/files/presentations/ab_firewire_rux2k6-final.pdf


#OPSEC365 116/365
Hadnagy documents it directly: offering information in a conversation almost compels the target to reply with equally useful information. You share a complaint about your org, a comment about personnel, and obligation kicks in.
The other person feels the pull to match it. HUMINT collectors call this mutual disclosure and use it to pull specific information out of a conversation that feels casual.
#OPSEC365 115/365
Prescription discount cards like GoodRx sell data about what medications you take.
GoodRx settled with the FTC for sharing health information with Facebook and Google for advertising. Every prescription you run through a discount card gets logged. The logs build a health profile tied to your identity.
GoodRx paid $1.5 million to settle FTC charges for sharing health data with Facebook and Google.
#OPSEC365