Secure Device Configuration
Hardware and OS choices that reduce the forensic link between your darknet activity and your everyday identity.
What "Dedicated Device" Actually Means
A dedicated device is one that has never been logged into with any personal account ā email, social media, banking ā and never will be. It is not merely "a separate laptop" you also use for work; it is a device with no crossover history at all.
Even a single prior personal login can create a forensic link: saved cookies, sync tokens, device identifiers, or account recovery metadata that ties the hardware back to you. A machine bought used and wiped still carries risk if it was ever associated with someone's identity. For high-stakes access, a device with a clean history from first boot is the target.
Full Disk Encryption, Concretely
Full disk encryption scrambles everything on the drive behind a passphrase. Common tools: LUKS on Linux, VeraCrypt cross-platform, or the encryption built into Tails and Whonix by design.
What it protects against: if the device is seized or physically stolen while powered off, the data is unreadable without the passphrase. What it does not protect against: data while the device is powered on and unlocked. An attacker with physical access to a running session can read memory and open files. Pair encryption with a short auto-lock timeout so an unattended machine does not stay exposed.