#opsec

dredmorbius@joindiaspora.com

OpSec is overrated. What you want is impunity

This is inference based on years of observation.

I also didn't lay OpSec is mostly useless. I'm not convinced that's true, though it may be.

OpSec alone is useful but brittle. If it's all you've got, you'll probably eventually have a bad day. Looking at entities considered "masterminds", what I often find is ... some intelligence, yes, but a lot of shielding from, or disregard of, risk. Impunity is actual or belief of freedom from consequence.

There are a few categories:

  • The proficient: extremely good at their game. Effective, so long as it works. Covert.

  • The well-protected -- friends in high places. State actors and their contractors, generally. Often under diplomatic covered. "Too big to jail" and politically-conneccted (Brock "Stanford Rapist" Turner). The Mossad team assassinating Mahmoud Al-Mabhouh (though most of the team were effectively burnt). May include some non-state actors: warlords, terrorists, narcotics gangs, though most of these fall into categories below. Covert, but can retreat quickly to safety, or are at low risk if caught.

  • The brazen. Operations with overwhelming force, whether shown or used. Military campaigns, many criminal organisations, warlords, militias. Overt.

  • The uncaring: those who have no care whether they live or die. Most suicide attacks, 9/11 bombers, the original "hashīshīn", etc. 2008 Mumbai attacks Overt or covert.

  • The ignorant: Simply unaware of the risks. Child soldiers, the Boxers (China), "wrong way 'round" Pan Am flight 18602 landing at Surabaya, Dutch East Indies, unknown to the pilot, in a heavily-mined harbour.

  • The expendable: Assets who need only be used once, whether burnt (retired) or killed afterwards. This includes a segment of the consulting or management workforce, who have a certain ablative funtion. Martin "Pharma Bro" Shkrel.

The relatively recently disclosed Crypto AG case, where the Swiss manufacturer of a widely-used manufacturer of communications encoding equipment was shown to be a CIA-owned front is a case in point. Signals intelligence relied not so much on exceptional decryption capabilities, but on the widespread use of a backdoored technology. The strong focus of US intelligence policy on similarly backdooring networking hardware (Cisco), telecoms switches (Greece), computing hardware, operating systems, and software, speaks to the probable usefulness of this method.

It's not OpSec but influence and immunity that enables this.

#OpSec #immunity #impunity

tiptopshop@diasp.org

OnionShare


OnionShare is a great tool that makes it easy for families or anyone who needs or would like to send important files or documents directly between persons, securely and anonymously with no third-party services or servers in between.


OnionShare is available as a package in #Debian stretch-backports as well as #MacOS, #Windows, and other #Linux versions.


#security #opsec #onionservice #tor #torbrowser #anonymity #communications #privacy #fedora #ubuntu #onionshare #infosec