update "How to remain Anonymous during a protest" #142

Merged
nihilist merged 11 commits from nanoanon/blog-contributions:main into main 2024-10-10 13:50:22 +02:00
Contributor

check/tell if more content is needed

otherwise I will start with the proper illustration/flowchart

check/tell if more content is needed otherwise I will start with the proper illustration/flowchart
nanoanon added 4 commits 2024-10-09 16:16:48 +02:00
Owner
  1. Phones are tracking devices for Law Enforcement:
    -typo "there exists a permanent record of where phone has"
    rest seems OK

  2. Prevention - staying Anonymous. >> change it to "Prevention - staying Anonymous outdoors."

  • "Internet and you" > just keep the "leave your phone activated at home" and explain it. move the rest (openwifimap and farady bags) )to the part below in 3)
  1. Guides -> change it to "How to have a phone for anonymous use"
  • add a disclaimer at the top: the safest and simplest is to keep your phone at home, as explained above, this is for deniability, where you can claim that you stayed at home during the protest. Proceed only if you need connectivity for communications while doing anonymous outdoor activities

Preparation - Indoors:

  • Get yourself a grapheneOS phone. >> change the url to be "../graphene/index.html" use your mainpc to flash the grapheneOS on the pixel phone
  • from your mainpc, in your whonix VM: purchase the eSIM on silent.link (it gives you a qr code), note down the activation code as you'll need to use it to activate it when you are outdoors where there's a public wifi, (mention what exactly you need to note down and why)

/!\ WARNING: leave your primary phone indoors and activated before going outdoors., the 2 phones that you carry must never be powered on and at the same location at any point in time. /!\

Outdoors: (actually you don't even need public wifi to activate the eSIM)

  • go outdoors, in your anonymous gear, in a place that is not affiliated with you.
  • activate the eSIM you got from silent.link >> actually show the screenshots for it too (steps are in https://silent.link/faq)
  • eSIM activated while remaining unindentified, now power off the phone and put it back into the faraday bag.

"Anonymous communications" >> can be simplified, as it will be covered in #129 just say that on that secondary phone with the eSIM, you can install SimpleX (will be covered in this future tutorial)

  1. Physical Opsec:
  • Create a pseudonym for every group/contact. >> mention that the pseudonym can be the randomly generated pseudonym given to you by simplex upon joining group chats in incognito mode

  • Do NOT talk about protest at home, especially with phones, home assistants, and TVs nearby >> mention that the only place where you can talk about it, is in the simplex chatroom

  • Do NOT reveal anything more than necessary. >> can be removed, included in the statement above

  • "When questioned by the Law Enforcement, remember to" >> this part can be removed, it can be addressed in #63 (tutorial on when protests go wrong)

  • "When going outside to safely access services like eSIM or tor" say explicitely afterward where you can take out the phone out of the faraday bag, in reference to the graph below

1) Phones are tracking devices for Law Enforcement: -typo "there exists a permanent record of where phone has" rest seems OK 2) Prevention - staying Anonymous. >> change it to "Prevention - staying Anonymous outdoors." - "Internet and you" > just keep the "leave your phone activated at home" and explain it. move the rest (openwifimap and farady bags) )to the part below in 3) 3) Guides -> change it to "How to have a phone for anonymous use" - add a disclaimer at the top: the safest and simplest is to keep your phone at home, as explained above, this is for deniability, where you can claim that you stayed at home during the protest. Proceed only if you need connectivity for communications while doing anonymous outdoor activities Preparation - Indoors: - Get yourself a grapheneOS phone. >> change the url to be "../graphene/index.html" use your mainpc to flash the grapheneOS on the pixel phone - from your mainpc, in your whonix VM: purchase the eSIM on silent.link (it gives you a qr code), note down the activation code as you'll need to use it to activate it when you are outdoors where there's a public wifi, (mention what exactly you need to note down and why) /!\ WARNING: leave your primary phone indoors and activated before going outdoors., the 2 phones that you carry must never be powered on and at the same location at any point in time. /!\ Outdoors: (actually you don't even need public wifi to activate the eSIM) - go outdoors, in your anonymous gear, in a place that is not affiliated with you. - activate the eSIM you got from silent.link >> actually show the screenshots for it too (steps are in https://silent.link/faq) - eSIM activated while remaining unindentified, now power off the phone and put it back into the faraday bag. "Anonymous communications" >> can be simplified, as it will be covered in https://git.nowhere.moe/nihilist/blog-contributions/issues/129 just say that on that secondary phone with the eSIM, you can install SimpleX (will be covered in this future tutorial) 4) Physical Opsec: - Create a pseudonym for every group/contact. >> mention that the pseudonym can be the randomly generated pseudonym given to you by simplex upon joining group chats in incognito mode - Do NOT talk about protest at home, especially with phones, home assistants, and TVs nearby >> mention that the only place where you can talk about it, is in the simplex chatroom - Do NOT reveal anything more than necessary. >> can be removed, included in the statement above - "When questioned by the Law Enforcement, remember to" >> this part can be removed, it can be addressed in https://git.nowhere.moe/nihilist/blog-contributions/issues/63 (tutorial on when protests go wrong) - "When going outside to safely access services like eSIM or tor" say explicitely afterward where you can take out the phone out of the faraday bag, in reference to the graph below
Author
Contributor

Yep changes made

Also you do infact need internet to download/add the eSIM in grapheneOS. Just not directly. Added it.

removed the unnecessary parts.

Also I did not understand what you meant in the last point "...say explicitely afterward where you can take the phone of the faraday bag."

Yep changes made Also you do infact need internet to download/add the eSIM in grapheneOS. Just not directly. Added it. removed the unnecessary parts. Also I did not understand what you meant in the last point "...say explicitely afterward where you can take the phone of the faraday bag."
Owner

ok let me know when i can review it again

"say explicitely afterward where you can take the phone of the faraday bag."" in reference to this graph you added at the end:
image

ok let me know when i can review it again "say explicitely afterward where you can take the phone of the faraday bag."" in reference to this graph you added at the end: ![image](/attachments/914b8dc4-e65f-48c8-a018-6cd3b66d80c1)
nanoanon added 1 commit 2024-10-09 21:47:50 +02:00
update security measures in index.html
update physical opsec documentation for better anonymity
Author
Contributor

ok let me know when i can review it again

"say explicitely afterward where you can take the phone of the faraday bag."" in reference to this graph you added at the end:
image

yep check now

> ok let me know when i can review it again > > "say explicitely afterward where you can take the phone of the faraday bag."" in reference to this graph you added at the end: > ![image](/attachments/914b8dc4-e65f-48c8-a018-6cd3b66d80c1) > yep check now
nanoanon added 1 commit 2024-10-09 22:27:54 +02:00
Owner

I was wondering if I should add sdr rf receiver to hear the cops walkie to alert ourselves and others beforehand

nah offtopic (as this would be a surveillance tutorial) + too sensitive to put into a tutorial, and anyway its too complex as you'd require to know their RF frequencies that they keep hidden on purpose.

  • Leave your phone ACTIVATED at YOUR home >> Leave your public use phone ACTIVATED at YOUR home

  • home leaves no digital trace of you ever being affiliated with the protestors. >> also mention that all the adversary needs, is to see that your personal phone was at that exact place at that time where the protest occured. all they need is a public camera filming the scene, since they know the location of phones that have been there. (and if yours is there, then you're toasted)

  • Setting up orbot >> to be justified : link back to https://blog.nowhere.moe/opsec/torthroughvpn/index.html you need to remind that if the ISP does not allow tor use in their country, then they need to hide it with a VPN, such as Mullvad (dont showcase it just link to https://blog.nowhere.moe/opsec/vpn/index.html, it will updated to include how to setup mullvad on phones later on in #81)

  • for the orbot part, don't set it up as a VPN, just keep it in power user mode, where there is only the local socks port on loclahost port 9050. as we're targeting communications here it's fine. SimpleX has the socks connection built in to accept Tor.

  • SimpleX chat with disappearing turned on >>> SimpleX chat with disappearing messages turned on, because in case if the authorities seize your phone, they musn't be able to find anything incriminating on it, for deniability.

  • under surveillence (CCTV). >>> under surveillence (CCTV) without being unindentifiable.

for the last 2 lines of text, only put the key words in bold, rather than the whole line, as its unreadable

> I was wondering if I should add sdr rf receiver to hear the cops walkie to alert ourselves and others beforehand nah offtopic (as this would be a surveillance tutorial) + too sensitive to put into a tutorial, and anyway its too complex as you'd require to know their RF frequencies that they keep hidden on purpose. - Leave your phone ACTIVATED at YOUR home >> Leave your public use phone ACTIVATED at YOUR home - home leaves no digital trace of you ever being affiliated with the protestors. >> also mention that all the adversary needs, is to see that your personal phone was at that exact place at that time where the protest occured. all they need is a public camera filming the scene, since they know the location of phones that have been there. (and if yours is there, then you're toasted) - Setting up orbot >> to be justified : link back to https://blog.nowhere.moe/opsec/torthroughvpn/index.html you need to remind that if the ISP does not allow tor use in their country, then they need to hide it with a VPN, such as Mullvad (dont showcase it just link to https://blog.nowhere.moe/opsec/vpn/index.html, it will updated to include how to setup mullvad on phones later on in https://git.nowhere.moe/nihilist/blog-contributions/issues/81) - for the orbot part, don't set it up as a VPN, just keep it in power user mode, where there is only the local socks port on loclahost port 9050. as we're targeting communications here it's fine. SimpleX has the socks connection built in to accept Tor. - SimpleX chat with disappearing turned on >>> SimpleX chat with disappearing messages turned on, because in case if the authorities seize your phone, they musn't be able to find anything incriminating on it, for deniability. - under surveillence (CCTV). >>> under surveillence (CCTV) without being unindentifiable. for the last 2 lines of text, only put the key words in bold, rather than the whole line, as its unreadable
Author
Contributor

should I show the stuff with the socks proxy?
I think that'll be better covered in some other article

should I show the stuff with the socks proxy? I think that'll be better covered in some other article
Author
Contributor

btw when the in-progress articles are ready and you need changes in this article, just dm me and I'll pr the update

btw when the in-progress articles are ready and you need changes in this article, just dm me and I'll pr the update
nanoanon added 1 commit 2024-10-09 23:54:35 +02:00
Owner

should I show the stuff with the socks proxy?
I think that'll be better covered in some other article

nah just orbot in power user mode (not the vpn device mode)

mullvad vpn on mobile will be for another tutorial, and simplex using socks proxying also for another tutorial

> should I show the stuff with the socks proxy? > I think that'll be better covered in some other article nah just orbot in power user mode (not the vpn device mode) mullvad vpn on mobile will be for another tutorial, and simplex using socks proxying also for another tutorial
nanoanon added 1 commit 2024-10-10 00:17:48 +02:00
nanoanon added 1 commit 2024-10-10 00:41:10 +02:00
nanoanon added 1 commit 2024-10-10 01:08:48 +02:00
Owner

close to being good, thanks for the quick changes

  • mention in this graph where the personal (public use) phone can be used, and where the secondary (anonymous use) phone can be used: public use phone = at home, anonymous use phone = protest area. meaning there are no overlapping places where both phones are active
    image

  • Put your uniform in a bag (1) and put the bag (1) in another bag (2). Go to a subway washroom/restroom and wear the uniform making sure no cameras are watching you. Make sure to now put the bag (2) in bag (1) and proceed with your work as shown in the below diagram >>> replace Bag 1 with Bag A and Bag 2 with Bag B to follow the graph

  • move the graph above the "put your uniform in a bag" line

  • remove "An extensive guide on how to use and why to use PGP encryption in messengers can be found here." as simplex meets the need below

  • Look the same:
    add a picture of a protest where everyone is dressed in black (to highlight that it's very hard to fingerprint anyone in that scenario)

closing:

  • for each hyperlink to another tutorial, instead of doing "opsec/tutorial/index.html" do "../tutorial/index.html"
  • edit the footer to contain your xmr address and your links if you have any
  • edit the top of the blogpost page to have your pseudonym instead of "nihilist" along with the date
close to being good, thanks for the quick changes - mention in this graph where the personal (public use) phone can be used, and where the secondary (anonymous use) phone can be used: public use phone = at home, anonymous use phone = protest area. meaning there are no overlapping places where both phones are active <img width="863" alt="image" src="attachments/e8c23ad6-2405-47d0-9047-a52b2ab4c4dd"> - Put your uniform in a bag (1) and put the bag (1) in another bag (2). Go to a subway washroom/restroom and wear the uniform making sure no cameras are watching you. Make sure to now put the bag (2) in bag (1) and proceed with your work as shown in the below diagram >>> replace Bag 1 with Bag A and Bag 2 with Bag B to follow the graph - move the graph above the "put your uniform in a bag" line - remove "An extensive guide on how to use and why to use PGP encryption in messengers can be found here." as simplex meets the need below - Look the same: add a picture of a protest where everyone is dressed in black (to highlight that it's very hard to fingerprint anyone in that scenario) closing: - for each hyperlink to another tutorial, instead of doing "opsec/tutorial/index.html" do "../tutorial/index.html" - edit the footer to contain your xmr address and your links if you have any - edit the top of the blogpost page to have your pseudonym instead of "nihilist" along with the date
400 KiB
nanoanon added 1 commit 2024-10-10 12:38:18 +02:00
add image to better illustrate uniform
remove unnecessary Lines
add editor details
Owner

looking good thanks, will send payment and merge it shortly
#32

looking good thanks, will send payment and merge it shortly https://git.nowhere.moe/nihilist/blog-contributions/issues/32
nihilist merged commit 6fd7c96368 into main 2024-10-10 13:50:22 +02:00
Author
Contributor

Yep
txn on the way, Thanks

Let me know if you need any help editing this article later, I'll help

Yep txn on the way, Thanks Let me know if you need any help editing this article later, I'll help
Sign in to join this conversation.
No reviewers
No Milestone
No project
No Assignees
2 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: nihilist/blog-contributions#142
No description provided.