OPSEC Basics
Operational security (OPSEC) is the habit of asking what an observer could learn from your actions before you take them ā and separating what must stay hidden from what can be exposed. The principles below apply across every other security guide on this site.
Know What You're Defending Against
Your defenses should match your actual adversary. A nosy acquaintance, a marketplace scammer, and a resourced law-enforcement investigation are three different threats ā each looks for different evidence and has different reach.
Treating every precaution as equally urgent against every threat leads to one of two failures: fatigue-driven sloppiness from maintaining impossible paranoia, or complacency that leaves real gaps because you assumed a casual threat model when the actual risk was higher. Before adopting a practice, ask who it protects you from and whether that threat is realistic for your situation.
Key Principles
- Compartmentalization
- Minimize digital footprint
- Never mix identities
- Use dedicated devices
- Trust no one completely
What compartmentalization actually means
Compartmentalization is keeping each identity's identifying details in separate buckets so that leaking one does not expose the rest. What actually gets compartmentalized:
- Username ā unique per identity, never reused on clearnet or across two darknet personas
- Password ā unique per account; a reused password links every account that shares it the moment one is breached
- Writing style ā vocabulary, punctuation habits, recurring typos, and sentence rhythm can link two supposedly separate accounts to the same person
- Active hours ā consistent online times reveal timezone and daily routine
- Payment method ā the same wallet or exchange account funding two personas ties them together on the blockchain
- Device ā browser fingerprints, installed software, and local files on one machine cross-contaminate every identity that uses it
Reusing any one of these across your darknet identity and your real identity ā or across two separate darknet identities ā breaks compartmentalization. A different display name alone does not fix that.
For footprint-reduction tactics (metadata, account separation, behavioral patterns), see the Digital Footprint guide. For how to physically separate devices and harden them, see Secure Devices.
Common Mistakes
- Using real personal information
- Reusing usernames/passwords
- Accessing without Tor
- Discussing on clearnet