News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Caution regarding my opsec : OpSec | Torhoo darknet markets

This post is about my opsec, and opsec in general.
For the moment, I have a classic laptop, on which I've only installed Qubes OS. To browse the classic darkweb (dread, dnm), I use the default option: whonix workstation via whonix gateway. I also access the clear web via a separate whonix station, on which I've managed to install a vpn (over tor) to raise as few red flags as possible.
I also use a parrot os vm, which I've managed to get to work with whonix gateway, so as never to expose my ip in the clear. In this vm, which is amnesiac, I have no information stored (obviously since it resets itself every time I run it), I do my hacking stuff which is not the subject here. I have all my credentials stored in a vm without internet access, and my PGP keys.
My opsec is pretty basic, I've always thought it better to trust those who are experts in the field rather than do everything myself (I don't think I'd be able to get better opsec by building my own operating system, qubes is the best for me).

Also, I plan to host services on the darkweb, so I may need a much better opsec than I have now. I have enough knowledge to do it. I don't want to use tails, I need to have persistence.

I have several questions:
- Is my current configuration sufficient to become a darknet operator? I obviously won't talk about what I plan to do, but if I were a dnm operator (which I'm not), would I need better opsec? What should I improve?
- Is parrot OS the best OS for hacking AND opsec? Give me other options if you can. At the moment, my connection is VERY VERY slow because of tor.
- Is tor 100% secure? For now, I base my opsec on tor, if tor doesn't protect me, I'm dead.

But my main concern right now is my opsec, what do I need to improve, is it good enough, what do people in general do better than me?
/u/meatt 🍼
1 points
1 hour ago
>I also access the clear web via a separate whonix station, on which I've managed to install a vpn (over tor) to raise as few red flags as possible.
That's not really how it works on qubes, you should create a separate appvm for the vpn instead of running it on the appvm you use for browsing

>I have all my credentials stored in a vm without internet access, and my PGP keys
Make sure its dispvm is set to (none) as well

>Is my current configuration sufficient to become a darknet operator?
yes

>but if I were a dnm operator, would I need better opsec?
yes

>What should I improve?
First off, you need to have a threat model to base your opsec on

>Is parrot OS the best OS for hacking AND opsec?
you don't really need parrot OS to do that tbh

>Is tor 100% secure? For now, I base my opsec on tor, if tor doesn't protect me, I'm dead.
depends on how you use it