SIGPwny @ UIUC
Intro to Opsec
Spring 2017
Announcements
News of the week
Disclaimers
What is Opsec?
Part One: Comsec
Tenets
Real Gs move in silence, like lasagna
Concealment
I got two phones, one for the plug and one for the load
Compartmentalization
I’mma look fresh as hell if the feds watchin’
Threat Modeling
“There is no such thing as tiger self-defence. You can’t just ‘train harder!’ and fight tigers one day.”
Why You Threat Model
“I don’t have to outrun the bear - I just have to outrun you!”
This is the worst analogy ever.
The Bear is LEO. With care and attention we can beat LEO, and we want to be in the woods ( where there are bears ), because the woods are full of heroin money… or honey or whatever metaphor thing everyone wants.
1. None of you can outrun the bear. Bears run at 60kph
2. The first person that gets caught by the bear won’t get eaten. They will snitch.
3. Next, the bear runs you all down, one by one, at 60kph, and kills you
4. The snitch will never do jail time, get a million dollars for their life story, and party at VICE.
So the moral, if anything, is “run slowly and learn to speak bear”
tl;dr
In the long run, CCC > CIA
Tools
Disposable Hardware
Cash rules everything around me
Random Talking Points
Part two: Opsec rules
Required Reading
Have a Believable Legend
If the devil’s in the details, then I’m satanic
Compartmentalize Harder
Mo’ People, Mo’ Problems
Breakin' the law with no codefendant
Go to jail, I get a lesser sentence
Go with the Flow
STFU
Trust No One
Be Disciplined
Prepare Chaos
Need to Know
Know which Channels are Open
Leave no Trace
Hide Compromising Material
Coast Guard come, a hundred going overboard
Know the Landscape
Don’t Snitch
Assume Snitches
https://www.youtube.com/watch?v=avsqkevmCIM
Challenge