PC isolation from every connections : OpSec | Torhoo darknet markets
Hello guys,
I'm trying to isolate my PC from every tipe of connection such as internet, bluetooth, ecc... At this moment i'm using a Tails in a USB pen and I selct "Disable all networks" at start.
Is that enough?
Is there something that I have to check at the hardware level?
Is there a guide that i can follow to achieve this?
I assume you wish to setup an offline computer. Start with ripping out the WiFi-chip, loudspeakers, microphone and web-camera. Don't connect anything to the Ethernet connector (you can plug in a dummy connector so you don't connect any Ethernet cable by mistake).
Do not use any Bluetooth keyboard or mouse, only cables or even better the laptop keyboard and mouse pad.
Safest way to exchange files with your is by burning DVD-disks, however, it's clumsy. If you use SD-cards or USB-sticks the risk for spreading virus is somewhat higher.
Connect a dedicated monitor if needed, never connect to any smart-TV or similar.
Use an UPS to ensure that your power lines are not transferring data. The UPS needs to be "dumb" and not connected to Internet.
Watch out for all IoT gadgets, don't have any of them close to your computer.
Keep all your personal devices at distance from your offline computer.
The room needs to be prepared as well, look Internet for Faraday cages.
Lastly, you need some type of security system so you know if someone been in your computer room. Do not install any cloud based standard systems. Use open source surveillance systems with cable connected cameras (no WiFi).
Power lines are a potential risk. Some IoT gadgets and some Ethernet adapters use power lines for communication, and with bad luck your power adapter has such capability without your knowledge.
Therefore it's necessary to consider how you power your DN tools (this is valid both for offline computing and for Internet connected).
Thank you very much. Your advice are very interesting and useful. Those advice are targeted for a notebook. I'm thinking to use an old desktop PC for this. Maybe it is more simple to obtain the result becuase there are no microphone and webcamera and I will have more control on the hardware.
For most of the cases the software disabling is enough but it depends on your adversaries and how far they are keen to go to get you.
For higher tier operations you should not have any communication module in the laptop and use only the external cards if needed. For the DNM level this should be the basic setup.
Be careful here, software disabling is not the way to go, it simply leaves attack vectors unattended due to the assumption of disablement.
Monthly, if not Weekly we get security updates of Linux, OpenBSD, BIOS/UEFI, Tails, Qubes, Whonix, Tor Browser and so on. These core software's are not safe to use, thousands of patches. To make things little more safe, one must reduce hardware and isolate the rest.
Absolutely agree that there are some good practices, but I would hesitate to recommend it to everyone.
It is nice to have the IME disabled, have the measured boot on a laptop delivered with anti-interdiction measures or built by yourself with the HW riced deeply....but the measures should not disable the user but at the same time offering reasonable resistance to his real world threats.
But if one is doing something where his compromise leads to significant damages, he needs to have a real-world-situation-based-OpSec anyway. No amount of general advice will help there, just because the adversaries will not be attacking him with general approaches, but the ones tailored to his specific situation. And this would most probably include the above and much more to stay happy, sleep well and be able to enjoy the fruits of one own actions once the project ends.
This holistic approach is largely omitted for the bad of everyone.
Do not use any Bluetooth keyboard or mouse, only cables or even better the laptop keyboard and mouse pad.
Safest way to exchange files with your is by burning DVD-disks, however, it's clumsy. If you use SD-cards or USB-sticks the risk for spreading virus is somewhat higher.
Connect a dedicated monitor if needed, never connect to any smart-TV or similar.
Use an UPS to ensure that your power lines are not transferring data. The UPS needs to be "dumb" and not connected to Internet.
Watch out for all IoT gadgets, don't have any of them close to your computer.
Keep all your personal devices at distance from your offline computer.
The room needs to be prepared as well, look Internet for Faraday cages.
Lastly, you need some type of security system so you know if someone been in your computer room. Do not install any cloud based standard systems. Use open source surveillance systems with cable connected cameras (no WiFi).
Therefore it's necessary to consider how you power your DN tools (this is valid both for offline computing and for Internet connected).