#OPSEC365 175/365
Password reset emails create a trail of your account activity.
Every password reset request generates an email in your inbox and a log entry at the service. That trail shows when you got locked out, accounts you have, and roughly how you use them. Someone with access to your email sees a map of your online presence through reset history.
Delete password reset emails after using them and review your email for old reset requests.
#OPSEC365
Sam Bent
contact@sambent.com
npub1y7rv...d0r3
Agorist. Counter-economist. Privacy maximalist. Student of OPSEC. Anti-authoritarian. Free speech absolutist. Logician. Ex-Darknet Vendor. Youtuber.
The difference between a drug dealer and a pharmaceutical company is the pharmaceutical company donates to campaigns.


#OPSEC365 173/365
Financial aggregator apps have read access to all your bank accounts.
Mint, YNAB, Copilot, and similar budgeting apps use Plaid or direct bank credentials to pull your complete transaction history. Every purchase, every deposit, every transfer goes through their servers. Some sell anonymized data, others have been breached.
Plaid, the infrastructure behind most budgeting apps, aggregates transaction data from hundreds of millions of accounts.
#OPSEC365
#OPSEC365 169/365
Smart home platforms log every command and interaction.
Lights turned on, locks engaged, thermostats adjusted. The complete history of your home automation sits in the cloud. When you went to bed, when you left, how long you were gone. These patterns are open to the platform provider and to law enforcement.
When you turned off the lights, locked the door, and left, it's all recorded with a timestamp.
#OPSEC365
#OPSEC365 168/365
Your dash cam records audio inside your car.
Many dash cams default to recording both video and interior audio. Conversations about work, arguments with passengers, phone calls on speaker, and anything else said in the car gets captured alongside the footage.
Most dash cams default to recording interior audio. Every phone call on speaker and every argument with a passenger is captured alongside the footage.
#OPSEC365
Monero transactions look exactly like this to every government, corporation, and surveillance company watching.


Did you get hit by the Rust supply-chain attack?
Here's how to check in 5 seconds.
Paste this:
find "${CARGO_HOME:-$HOME/.cargo}/registry/cache" \( -name 'arrayref-0.3.10.crate' -o -name 'internment-0.8.7.crate' -o -name 'append-only-vec-0.1.9.crate' -o -name 'proc-macro1-*.crate' \) | grep . || echo CLEAN
Says CLEAN?
Your machine's cache is clear.
Prints a filename?
You built it.
Rotate your creds and rebuild on clean infra.
Win users: you are already cool with spyware on the box, chill.
Harmful to the banking system sounds like the best investment thesis available.


Researchers pulled a 256-bit key out of a device by filming its power LED. The status light flickers with the chip's power draw, and that leaks the key. A full ECDSA key was recovered from 16m away through a window via a hijacked camera. https://www.nassiben.com/video-based-crypta
To reach your IP the attacker needs:
a thousand high speed Tor relays plus five thousand fake Monero nodes,
all aimed at one person,
and the paper still only gives
them a 46 percent shot.
If your money came with a nutrition label you'd stop using it.


People reach the service without ever learning where it lives.
That is the hidden part of hidden service.
Every paper published against Monero makes the next version harder to break.
The attacks are free auditing.
#OPSEC365 151/365
Streaming recommendations reveal your household's viewing patterns.
Netflix, Hulu, and Disney+ build detailed profiles of what your family watches, when, and for how long. These recommendations are based on viewing data that gets shared with advertisers and partners. Your guilty pleasure binge sessions are documented.
Netflix, Hulu, and Disney+ retain complete viewing history tied to your account. That data is producible under subpoena.
#OPSEC365
The same people who call Monero shady will defend a coin that reports them to four agencies before breakfast.
Darknet vendors figured out Bitcoin was a honeypot around 2017, the rest of crypto is still catching up.


The government cannot tell you how many federal laws exist.
The Justice Department spent two years trying and stopped.
You are not following all of them.
Nobody broke Monero's cryptography.
They found a node that talked too much,
and the devs fixed it in December 2024.
#OPSEC365 140/365
Phones in gym locker rooms are recording devices everyone ignores.
People scroll their phones while changing, and those phones have cameras. Gym mirror selfies often capture other people in the background. The social norm against locker room recording doesn't prevent it from happening constantly.
Be aware of who has a phone out when you're in spaces where you expect privacy.
#OPSEC365