Author Topic: The OPSEC Reading List  (Read 1742 times)

Trevor

  • Sr. Member
  • ****
  • Posts: 255
  • Karma: +80/-35
  • We all love drink and drugs, pal.
    • View Profile
    • Personal Message (Offline)
The OPSEC Reading List
« on: October 15, 2013, 06:26:16 am »
I think it'd be a valuable resource if we create and maintain a detailed reading list - compiled for the benefit of all. I realized that we, as a community, lack this kind of resource.

Please provide constructive criticism, and try not to be a dick.

You are more than welcome to post an item, and provide a critique (probably the best method IMHO) - this way, you've read it and thought about the contents. Alternatively (for those already well-read in the area) you can just compile lists of your own.

I'll start:
INFOSEC PRO GUIDE: CRYPTOGRAPHY, by Sean-Philip Oriyano

'Information Security: The Complete Reference', by Mark Rhodes-Ousley

« Last Edit: November 08, 2013, 12:42:05 pm by Trevor »
OPSEC: Collection of Tutorial & Research Info:
http://silkroad5v7dywlc/index.php?topic=494.0

The OPSEC reading list:
http://silkroad5v7dywlc/index.php?topic=696.0

OperationsSecurity(OPSEC)

  • Jr. Member
  • **
  • Posts: 94
  • Karma: +11/-3
  • Learn OPSEC
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #1 on: October 15, 2013, 07:07:55 am »
All the resources in my sig http://grugq.github.io/resources/
The Ruckus Society keeps some good guides: http://www.ruckus.org/
The Grugq's video on OPSEC http://youtu.be/9XaYdCdwiWU
Ohrodr's quick talk on OPSEC from Toorcon http://youtu.be/Pw5MiZcsiQM 
The IRA green book if you can find it online (part 1 and 2)
The original OVDB productions guide "Art of Smuggling" had some good Tradecraft

Follow all those and you will learn how to avoid indicators (patterns), learn not to talk too much if you're running a major illegal operation like anti gov resistance or narco dealing, learn counter-surveillance to avoid police tails or rival G's looking to jack you like how to employ SDR (surveillance detection routes) on the way to a stash house, and to sweep your vehicle for GPS tags. Too many people have gone down dropping off drugs in mailboxes while their car is GPS tagged and feds are following them watching.



« Last Edit: October 15, 2013, 07:40:12 am by OperationsSecurity(OPSEC) »
Learn Counter Surveillance, CI, OPSEC and Tradecraft
http://grugq.github.io/resources/

Trevor

  • Sr. Member
  • ****
  • Posts: 255
  • Karma: +80/-35
  • We all love drink and drugs, pal.
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #2 on: October 15, 2013, 12:46:40 pm »
What is OVDB productions guide "Art of Smuggling" and where could I find it?
OPSEC: Collection of Tutorial & Research Info:
http://silkroad5v7dywlc/index.php?topic=494.0

The OPSEC reading list:
http://silkroad5v7dywlc/index.php?topic=696.0

Serendipity

  • Newbie
  • *
  • Posts: 43
  • Karma: +16/-3
  • multi-entheogen connoisseur
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #3 on: October 15, 2013, 05:59:13 pm »
Thanks for your great contributions OPSEC. This is my new favorite subject. Hopefully one I can study for a long time.
Just what the truth is, I can't say anymore

orange

  • Jr. Member
  • **
  • Posts: 90
  • Karma: +3/-6
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #4 on: October 15, 2013, 06:03:51 pm »
What is OVDB productions guide "Art of Smuggling" and where could I find it?

It's on pastebin:
(CLEARNET) http://pastebin.com/DDJShs9f
As usual: Just saying.

OperationsSecurity(OPSEC)

  • Jr. Member
  • **
  • Posts: 94
  • Karma: +11/-3
  • Learn OPSEC
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #5 on: October 16, 2013, 01:39:45 am »
OPSEC - Unmasking Miscreants (DerbyCon Oct 2013)
http://youtu.be/2NjBvFda4NI

If you run a hidden service, would want to look at this. They tell you how they break through cloudflare and other ddos protection to identify servers, same tactics would work on a hidden service if you set it up incorrectly. Also great lolz on the many fools selling booters that have zero opsec skills.
« Last Edit: October 16, 2013, 02:59:52 am by OperationsSecurity(OPSEC) »
Learn Counter Surveillance, CI, OPSEC and Tradecraft
http://grugq.github.io/resources/

Jeks

  • Full Member
  • ***
  • Posts: 155
  • Karma: +12/-2
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #6 on: October 16, 2013, 02:56:56 am »
sub,  good topic
OPSEC: Collection of Tutorial & Research Info: PGP, Tails, Whonix, Data, + more
http://silkroad5v7dywlc/index.php?topic=494.0

oracle

  • Full Member
  • ***
  • Posts: 203
  • Karma: +64/-36
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #7 on: October 16, 2013, 07:13:45 am »
dieAntwoord has posted some useful OPSEC information as well as links. He was kind enough to PM a few useful links a few days back.

Here (clearnet):

http://grugq.github.io/blog/2013/10/09/it-was-dpr/ is the orig post
http://grugq.github.io/resources/ has good info too


Well written and thought out.
if this account of my goes "incommunicado" - I can be reached at oracles@safe-mail.net

kittenfluff

  • Full Member
  • ***
  • Posts: 176
  • Karma: +19/-12
  • Turn on, tune in, drop out...
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #8 on: October 16, 2013, 11:11:03 am »
subbing for a proper perusal later. Great topic, would +1 if I could...
I often take breaks from smoking weed - some days I don't even spark up until I get home from work.

Give to Eris and receive great BJs from the universe - 1N78Ma9DgiwtyhPFDjWgchFXW9uhD3Aqhf

cyanspore

  • Vendor
  • Newbie
  • *****
  • Posts: 36
  • Karma: +5/-0
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #9 on: October 16, 2013, 01:39:22 pm »
I did start a thread very similar to this already and posted a bunch of articles, but if you want this thread it's fine with me

http://silkroad5v7dywlc/index.php?topic=394.0
best shrooms on the planet - psilocybe cyanescens

http://silkroad6ownowfk.onion/items/1-gram-psilocybe-cyanescens-very-potent

Joe

  • Newbie
  • *
  • Posts: 1
  • Karma: +0/-0
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #10 on: October 20, 2013, 08:18:02 am »
sub

anontoker

  • Hero Member
  • *****
  • Posts: 713
  • Karma: +125/-19
  • Resident Anonie
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #11 on: October 20, 2013, 01:43:08 pm »
Good reading. Thanks for posting. Subbed.
If you see someone wearing a "I'm the real Dread Pirate Roberts" shirt, smile and wave, but make sure to look inconspicuous.
"Officer, that's not my PENIS, it's Nw Nugz Purple Hog Train! Grown by Alien Hillbillies!"

Kaiho

  • Newbie
  • *
  • Posts: 1
  • Karma: +0/-0
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #12 on: October 21, 2013, 06:02:38 pm »
http://shadowlife.cc/
or
http://shadow7jnzxjkvpz.onion/


Tradecraft, privacy, anonymity, amazing awesome site overall.

weather420

  • Full Member
  • ***
  • Posts: 246
  • Karma: +28/-7
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #13 on: October 21, 2013, 10:02:52 pm »
Sticky this thread.

99herps

  • Full Member
  • ***
  • Posts: 133
  • Karma: +17/-4
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #14 on: October 22, 2013, 02:26:33 am »
http://shadowlife.cc/
or
http://shadow7jnzxjkvpz.onion/

Tradecraft, privacy, anonymity, amazing awesome site overall.
Not impressed. No meat.

jacob1234

  • Jr. Member
  • **
  • Posts: 79
  • Karma: +7/-1
  • Atomic Physicist
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #15 on: October 22, 2013, 06:09:42 am »
OPSEC nice stuff. Subbed to this bad boy. Gonna take time tomorrow to watch those videos and get those books.

ManInTheMirror

  • Sr. Member
  • ****
  • Posts: 273
  • Karma: +45/-10
  • No FE, 4096 bit PGP, Tumble BTC
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #16 on: October 22, 2013, 08:35:02 am »
This, the real shit, subbed.
Remember Remember, the 6th of November.
Cocaine-Powder, MDMA and Pot.
I see no reason why Silk Road,
should ever be forgot.

jacob1234

  • Jr. Member
  • **
  • Posts: 79
  • Karma: +7/-1
  • Atomic Physicist
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #17 on: October 22, 2013, 05:58:03 pm »
Not sure if this is exactly OPSEC, but it's good info:
Don't Talk to Police: http://youtu.be/6wXkI4t7nuc
How to Cop Proof Your Phone: http://youtu.be/vVCROjpgCB0

wholepyo

  • Newbie
  • *
  • Posts: 9
  • Karma: +2/-0
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #18 on: October 23, 2013, 04:52:50 am »
Alright yall dont laugh too hard but whats OPSEC?

jacob1234

  • Jr. Member
  • **
  • Posts: 79
  • Karma: +7/-1
  • Atomic Physicist
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #19 on: October 23, 2013, 07:55:10 am »
Alright yall dont laugh too hard but whats OPSEC?

Operational Security ***CLEARNET***http://en.wikipedia.org/wiki/Operations_security***CLEARNET***

notpersonallyidentifiable

  • Newbie
  • *
  • Posts: 8
  • Karma: +0/-0
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #20 on: October 23, 2013, 05:51:20 pm »

Parts 1 and 2 of this are excellent

****CLEARNET****
https://lilithlela.cyberguerrilla.org/?p=3060  (Encryption For Beginners In an Era of Total Surveillance )
https://odinn.cyberguerrilla.org/index.php/2013/08/12/darknet-for-beginners/ (Darknet for Beginners: Nightweb, I2P, Tor over Meshnet)
****CLEARNET****

I'd probably start with the grugq's video though.



Stay safe. Avoid revealing personal information.

https://odinn.cyberguerrilla.org/index.php/2013/08/12/darknet-for-beginners/

Peace.

Steve Jobs

  • Newbie
  • *
  • Posts: 21
  • Karma: +10/-4
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #21 on: October 23, 2013, 07:07:47 pm »
Agree: Sticky this topic... could save your life.

astonmarteen

  • Vendor
  • Jr. Member
  • *****
  • Posts: 55
  • Karma: +0/-5
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #22 on: October 26, 2013, 10:35:11 pm »
subbed

hopelessanarchist

  • Newbie
  • *
  • Posts: 33
  • Karma: +1/-0
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #23 on: October 26, 2013, 11:33:05 pm »
also agree this topic shoud be sticky

stabpen

  • Newbie
  • *
  • Posts: 19
  • Karma: +1/-1
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #24 on: October 27, 2013, 12:10:12 am »
Good stuff. Thanks!

Trevor

  • Sr. Member
  • ****
  • Posts: 255
  • Karma: +80/-35
  • We all love drink and drugs, pal.
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #25 on: November 02, 2013, 02:25:44 pm »
Finished reading 'INFOSEC PRO GUIDE: CRYPTOGRAPHY, by Sean-Philip Oriyano' a couple days ago, was not impressed. It's entry level to say the least, and contained very little substantial information. This is a huge drawback in fields as diverse and fast moving as 'infosec' and cryptography. Basically it'll be useful for someone who has no notion of what cryptography even is. If you know the basics of that,then don't even bother with this book. It also included all these childish exercises.

It may be an ok background read, but it is not specific enough for our perposes.

Also, can anyone post some in depth analysis of secure OS setups for anonymity. I recall a really good thread from the old forums started by Astor that basically had a top 10 of configurations (tails was listed at number 7). OPSEC what are your thoughts on using Tails? Astor said they aren't as anonymous as everyone claims.   
OPSEC: Collection of Tutorial & Research Info:
http://silkroad5v7dywlc/index.php?topic=494.0

The OPSEC reading list:
http://silkroad5v7dywlc/index.php?topic=696.0

TheOGroader

  • Jr. Member
  • **
  • Posts: 56
  • Karma: +6/-1
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #26 on: November 02, 2013, 02:37:25 pm »
Finished reading 'INFOSEC PRO GUIDE: CRYPTOGRAPHY, by Sean-Philip Oriyano' a couple days ago, was not impressed. It's entry level to say the least, and contained very little substantial information. This is a huge drawback in fields as diverse and fast moving as 'infosec' and cryptography. Basically it'll be useful for someone who has no notion of what cryptography even is. If you know the basics of that,then don't even bother with this book. It also included all these childish exercises.

It may be an ok background read, but it is not specific enough for our perposes.

Also, can anyone post some in depth analysis of secure OS setups for anonymity. I recall a really good thread from the old forums started by Astor that basically had a top 10 of configurations (tails was listed at number 7). OPSEC what are your thoughts on using Tails? Astor said they aren't as anonymous as everyone claims.
All I can say on Astor's behalf is whonix whonix whonix.
Did I mention whonix? Tails leaks like a motherfucker.
Of coarse this is just paraphrase from Astor's many pages on this

Trevor

  • Sr. Member
  • ****
  • Posts: 255
  • Karma: +80/-35
  • We all love drink and drugs, pal.
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #27 on: November 02, 2013, 03:11:32 pm »
Yes Astor discussed many whonix configurations. Starting from a base level, how does one construct a secure config? I daresay tails' proliferation lies in its ease of use.
OPSEC: Collection of Tutorial & Research Info:
http://silkroad5v7dywlc/index.php?topic=494.0

The OPSEC reading list:
http://silkroad5v7dywlc/index.php?topic=696.0

TheOGroader

  • Jr. Member
  • **
  • Posts: 56
  • Karma: +6/-1
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #28 on: November 02, 2013, 05:18:41 pm »
Yes Astor discussed many whonix configurations. Starting from a base level, how does one construct a secure config? I daresay tails' proliferation lies in its ease of use.
Tails is miles more complicated then whonix, even if your setting physical isolation boots its more simple.

Jeks

  • Full Member
  • ***
  • Posts: 155
  • Karma: +12/-2
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #29 on: November 03, 2013, 06:43:48 am »
Astor had Qubes up at 1 but see here:

http://silkroad5v7dywlc/index.php?topic=173.msg1635#msg1635

OPSEC: Collection of Tutorial & Research Info: PGP, Tails, Whonix, Data, + more
http://silkroad5v7dywlc/index.php?topic=494.0

Trevor

  • Sr. Member
  • ****
  • Posts: 255
  • Karma: +80/-35
  • We all love drink and drugs, pal.
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #30 on: November 03, 2013, 08:04:02 am »
Yes Astor discussed many whonix configurations. Starting from a base level, how does one construct a secure config? I daresay tails' proliferation lies in its ease of use.
Tails is miles more complicated then whonix, even if your setting physical isolation boots its more simple.

It's complexity is one of it's major flaws, no?
Yeah, I meant ease of use to encapsulate this- everything bundled together and easily booted.

>So, whonix in a VM? What should the VM be placed in? A linux based OS? And what kind of PGP is strong, I was using GPG4Win for a long time and was only just advised against it.

Another question, how does one use "an internet link that cannot be traced to you", as advised by the gruqg in one of his articles?
« Last Edit: November 03, 2013, 02:20:08 pm by Trevor »
OPSEC: Collection of Tutorial & Research Info:
http://silkroad5v7dywlc/index.php?topic=494.0

The OPSEC reading list:
http://silkroad5v7dywlc/index.php?topic=696.0

Trevor

  • Sr. Member
  • ****
  • Posts: 255
  • Karma: +80/-35
  • We all love drink and drugs, pal.
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #31 on: November 03, 2013, 08:08:28 am »
Also, I'm putting
'Information Security: The Complete Reference', by Mark Rhodes-Ousley on the list.

It's got strong and varied reading on a range of relevent (for SR users) topics.

I havn't got all the way through, but definitely worth your time to familiarise yourself with good CI habits.
OPSEC: Collection of Tutorial & Research Info:
http://silkroad5v7dywlc/index.php?topic=494.0

The OPSEC reading list:
http://silkroad5v7dywlc/index.php?topic=696.0

MrTerrific

  • Vendor
  • Jr. Member
  • *****
  • Posts: 75
  • Karma: +6/-3
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #32 on: November 03, 2013, 09:50:29 am »
Subbed, It'd probably be a good Idea to Sticky this as well
"Is freedom anything else than the right to live as we wish? Nothing else." - Epictetus

jacob1234

  • Jr. Member
  • **
  • Posts: 79
  • Karma: +7/-1
  • Atomic Physicist
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #33 on: November 04, 2013, 04:40:18 am »
Never Get Busted Again: http://www.youtube.com/watch?v=ZyAjLkBCWKI
Never Get Raided: http://www.youtube.com/watch?v=InJHDLNCRzc

holog1n

  • Sr. Member
  • ****
  • Posts: 274
  • Karma: +121/-21
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #34 on: November 05, 2013, 11:37:25 am »
brutal thread, cant sub yet, crap... thanks for sharing
Death is just another point of view
b4kerluna@safe-mail.net
torchat > 5fupjdb6xvispoyr

Agent

  • Sr. Member
  • ****
  • Posts: 337
  • Karma: +34/-8
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #35 on: November 06, 2013, 03:41:12 pm »
Yes Astor discussed many whonix configurations. Starting from a base level, how does one construct a secure config? I daresay tails' proliferation lies in its ease of use.
Tails is miles more complicated then whonix, even if your setting physical isolation boots its more simple.

It's complexity is one of it's major flaws, no?
Yeah, I meant ease of use to encapsulate this- everything bundled together and easily booted.

>So, whonix in a VM? What should the VM be placed in? A linux based OS? And what kind of PGP is strong, I was using GPG4Win for a long time and was only just advised against it.

Another question, how does one use "an internet link that cannot be traced to you", as advised by the gruqg in one of his articles?

Yes Whonix running in a VM is one of the better options out there, running it on a *nix based operating system is again the better option than running it on Windows unless you know how to really harden down a system like that.

VM's are a tricky option because you just don't know what information is being left behind on the OS that it's being run on and what security holes it may have that will leak any information of yours.

As for which PGP you should head over to the thread that talks about the difference PGP versions out there.

Also that last question I am not to sure about, did you mean a link that CAN track you throughout the internet ?
Knowledge is power and as a community that knowledge can be used as a tool to aid the community, as I am only human if anything I submit on these forums is incorrect please contact me directly or quote the noted error and I can learn from my mistakes and minimize any form of misinformation.

Hijinx

  • Full Member
  • ***
  • Posts: 234
  • Karma: +45/-6
  • "Silence Means Security."
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #36 on: December 12, 2013, 06:42:58 am »
sub
"Some tourists think Silk Road is a website of sin, but in truth it is a website of freedom. And in freedom, most people find sin."
"Does this smell like cocaine to you?"

tra!nsTra!nsTRA!NS

  • Full Member
  • ***
  • Posts: 123
  • Karma: +18/-5
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #37 on: December 12, 2013, 12:21:40 pm »
me likey, thanks and subbed
;)

DanDanTheIceCreamMan

  • Sr. Member
  • ****
  • Posts: 278
  • Karma: +61/-7
    • View Profile
    • Personal Message (Offline)
Re: The OPSEC Reading List
« Reply #38 on: December 13, 2013, 07:16:46 pm »
subbed
Have you joined The Hub yet? I have! It's an impartial community for all members of the Deep Web marketplaces to chat, review markets, and even regroup in the event of a market's closure. Join me here: http://thehubaoydxrommh.onion