Opsec: A Deep Dive Into Becoming Boring
Every account is a sensor. Every legal name is a confession. Here is how we pull the wires out — the stack we actually run, tradeoffs included.
Nobody drags you into the panopticon. You subscribe, one terms-of-service at a time. Every account you keep is a sensor pointed at your life — a name here, a phone number there, a "sign in with Google" everywhere. The data gets joined, profiled, sold, subpoenaed, and eventually leaked, because that's what databases do. Opsec is the practice of pulling those wires back out.
This is the deep dive. It's the stack we actually run, not a brochure. But before you copy it, a warning: don't cargo-cult it. Start with a threat model.
You are probably not hiding from intelligence agencies. They have budgets you can't outspend. You're hiding from data brokers, SIM swappers, whoever inherits the next big breach, chain-analysis firms whose entire business is reading your money — and increasingly, the people who skip the software and go straight for the body. The recent wave of kidnappings and violent assaults in France, targeted at people known or suspected to hold bitcoin, is the reminder nobody wanted: once your wealth and your location are joinable, a spreadsheet becomes a kidnapping plan. Gart.io tracks this category of physical threat. If your opsec stops at the keyboard and doesn't account for what a determined group can do with a home address and a van, it isn't finished. Different adversaries, different budgets. Decide who you're declining to be visible to, then work down the list. Opsec that tries to defend against everything defends against nothing — and burns out its operator by March.
The order below is deliberate. We start at the anchor — the identity points that fuse you to your meatspace self — and work outward through device, network, comms, compute, and money. Pull the big wires first.
The name is the anchor
Never use your legal name. Not "rarely." Never, in any context where pseudonymity matters.

Your legal name is the master key: nearly every database on earth is indexed by it. The moment it appears next to a pseudonym anywhere — one forum comment, one shipping label, one donation receipt — the two identities fuse forever, and every future leak carries both.
Pick a nym. Use it consistently within one context. Keep the contexts apart: the handle you shitpost under is not the handle you consult under is not the name your hardware wallet knows. The compromise is almost never dramatic. It's a Tuesday, you're tired, and you sign the wrong email.
Close the social media accounts
All of them. Not "log out." Not "post less." Close them.
An abandoned account is still a data tap. It keeps feeding advertisers your history, keeps working as an account-recovery path for an attacker, and keeps proving to any subpoena that this timeline of your last decade belongs to you. Export your data if you want a copy. Then delete. Don't be surprised when deletion is harder than signup — that asymmetry is the business model.
The hard part isn't technical, it's social. You're not deleting an app; you're deleting a habit loop. This is where nostr earns its keep: your identity and your follows are your keys, and the platform is interchangeable. You can leave and take the people with you — the exit web2 never once offered.
The phone is a radio that hates you
Step one: run GrapheneOS. Hardened Android, no Google, the whole deal.
Step two — the part everyone skips: keep it in airplane mode. On GrapheneOS, airplane mode fully disables the cellular radio. No SIM handshake, no tower triangulation, no "anonymous" cell metadata. This is the step that stops your every movement being tracked 24 hours a day. A powered-on phone with a SIM registers with cell towers constantly — that log is your real-time location history, retained for months or years, available to anyone who subpoenas or buys it. Airplane mode kills the radio. The phone stops being a phone and becomes a small, well-armored computer that reaches the internet over Wi-Fi, ideally through a VPN.

But you still live in a world that demands cellular — for SMS codes, for calls, and for internet on the move. So let's deal with each:
- SMS codes and verifications: crypton.sh — private numbers for receiving codes, paid in bitcoin, no personal details attached. Use it for the services that insist on SMS.
- Actual calls: Cheogram, which does calls over XMPP. Pair it with a number from JMP.chat and your "phone number" is just another data stream over your tunnel.
- Internet on the move: a SIM in your phone is a tracking device you're paying for, so don't reach for one by reflex. Better: live without when you don't need it, use public Wi-Fi, or share a hotspot with people you trust. When you do need your own pipe, the first option is the burner phone described below — a secondary GrapheneOS phone with a no-KYC eSIM acting as a Wi-Fi hotspot. It keeps the SIM out of your daily driver entirely. The travel routers in the section below are the next step up — a GL.iNet Mudi (GL-E750) fits in a pocket and tunnels everything through WireGuard, and for longer trips where bulk is acceptable, the GL.iNet Puli AX (GL-XE3000) is the bigger, faster sibling. Note that a GrapheneOS phone acting as a hotspot can't run a VPN at the same time, so it's a fallback — the travel routers are the plan when the tunnel matters.
And when a service offers something better than SMS — TOTP, hardware keys — take it. SMS 2FA is the screen door of authentication. It exists to be SIM-swapped.
eSIMs and burner phones
Run your burner on GrapheneOS too — same hardened Android, same no-Google baseline. A SIM belongs in a burner, never in your main device. The moment a SIM is active in a phone, that phone is registered with cell towers — logging its location, correlating with any account that phone touches, and feeding the same databases you're trying to leave. A burner keeps the radio fire away from your real identity and your real data.

First option: no-KYC eSIMs — Silent.link (anonymous, paid in bitcoin or Lightning, no name, no registration) or Bitrefill (crypto payments, no account required beyond an email). Activate on a secondary GrapheneOS phone that contains nothing else: no accounts, no apps, no data. Just a dumb cellular lifeline that never touches your main identity. Keep it powered off until you need it.
Second option: no-KYC SIMs purchased with cash in countries that still allow it — increasingly rare, but they exist. Pay cash, don't give a name, accept that the number is disposable.
The burner also solves the emergency-call problem. A phone with no SIM can't dial 999/112/911, and in a real emergency you could just turn off airplane mode on your main phone — but that betrays your location at the worst possible moment. A powered burner with a no-KYC eSIM makes the call without lighting up your daily driver. Two devices, two threat models, no compromises.
Encrypt the pipe — and pay for it right
A VPN doesn't make you anonymous. It moves trust from your ISP (which keeps logs because law) to a provider you chose. So choose one that collects nothing: Mullvad, IVPN, Obscura. The account is a random number. No email, no name. Pay in bitcoin. Your provider should be unable to answer a question about you — because it never asked one.
Then take the tunnel to the router. GL.iNet hardware runs WireGuard out of the box, so everything in the house rides the VPN — including the devices you can't configure, like the TV you should probably unplug anyway. Or terminate the tunnel on a server you control; a small box in the closet does the job fine.
The principle: a VPN client on your laptop covers one device. A VPN on the router covers the network. The device you forgot about is always the one that leaks.

Email is where habits go to leak
Two rules. Both are cheap.
First: never type your handle into an email. Muscle memory is identity-blind. Sooner or later you'll sign a pseudonymous email with your legal name, or a work email with your nym, and merge two worlds in one keystroke. Configure your footer once, per account, in the client. The right identity gets appended by config, not by memory — and config beats memory every time.
Second: use email that doesn't read you. ProtonMail, or self-hosted mail with GPG where you can. Never Gmail, Outlook, Hotmail. "Free" email is paid for by profiling you, and it sits one subpoena away from handing over the archive.
The best option is the one nobody likes: don't use email at all. Every account you don't create is one less archive of you waiting to leak.
Messengers: no phone numbers, no identifiers
For one-to-one and small group chat, SimpleX has no phone numbers and no user identifiers at all — messages pass through queues that hold nothing linking to you. It's the messenger you hand to people who flinch at onboarding forms.
For nostr-native group chat, three protocols are worth your attention — we wrote a full comparison of them that goes deeper than this piece can:
- Marmot — MLS (RFC 9420) ratcheting for small, high-stakes groups. Forward secrecy, post-compromise security, no privileged server. The closest thing nostr has to Signal-grade group crypto. A breaking v2 is in progress.
- Cordn — same MLS family, but runs through a lightweight, self-hostable coordinator per group. Better public-metadata behaviour than relay-native schemes: relays see only generic encrypted traffic, and the coordinator never sees an IP.
- Concord — Discord-style communities at scale, end-to-end encrypted, no company in the middle. Trades ratchets and forward secrecy for channels, roles, kicks, bans, and the full platform feature set. The rational trade for a large public room.
For team chat beyond nostr, Matrix on a homeserver you run yourself, or Den Chat.
Notice the pattern across all of these. Open protocol. Server you can own. Identity you can carry out the door. It's the same test every single time, and most software fails it in the first sentence.
Own the compute
Run a sovereign OS on a box in your closet: Start9 (StartOS), Archipelago, YunoHost. One machine runs your services — sync, git, relays, whatever you use. Not because cloud is expensive, but because your data shouldn't live in a building you don't control, under a policy you've never read and can't change.
This is the "no chicken" principle in hardware form: self-hosted before SaaS, open protocols before walled gardens. It's also literally our day job — we package things like strfry relays and Blossom servers so self-hosting takes an afternoon, not a sysadmin career.

Money: clean coins, cash-like spending, no exchanges
Bitcoin is pseudonymous, not anonymous. Coins carry history, and an entire industry exists to read it.
Cleaning: Wasabi with a third-party coinjoin coordinator. (zkSNACKs shut down their official coordinator in late 2024 — the wallet still works, but you need to find a coordinator or run your own.) Coinjoin rounds break the deterministic link between the coins you received and the coins you'll spend. Then practice UTXO hygiene: label everything, and never merge cleaned coins with known-history coins — merging undoes the work at the speed of one careless spend.
Then tier your holdings by how much they'd hurt to lose.

Generational wealth: multivendor multisig. Don't trust one hardware vendor, one app, or one set of firmware — spread the signing devices across manufacturers so a single supply-chain compromise can't drain you. The setup is more work than a single sig, and it should be; this is the layer where inconvenience is a feature.
Personal savings: a hardware wallet, a strong passphrase, and entropy you generated yourself. Don't use Coldcard or Ledger — both have failed their customers. (Coldcard shipped devices with compromised secure elements and fumbled the disclosure; Ledger's recover feature proved they can exfiltrate seed material, regardless of what the marketing said it would do.) Pick a vendor whose incentives align with yours, generate your own entropy so you're not trusting theirs, and memorize a strong passphrase so the seed alone is useless.
Large spends: Lightning. Phoenix or Zeus for mobile, or self-host a node if you're moving enough volume to justify it. Load the channel from a single Wasabi-cleaned UTXO so the Lightning balance doesn't leak your on-chain history to whoever's watching the mempool.
Small, daily spends: ecash — Cashu or Fedi. You hand over a blinded token, not an on-chain event. The merchant gets paid without learning your chain history.
Honest note, because we don't sell tickets to magic shows: ecash is custodial. Mints hold the sats and issue tokens; Fedi's federations spread the trust across several parties instead of one, but the trust never hits zero. Use ecash as a spending wallet — small balances, fast in and out. Savings live in your own cold storage.
Never exchanges. A KYC exchange is the airport where bitcoin meets your legal name, your passport, and your bank account — all in one photograph, kept forever, subpoenaable, and eventually leaked, because that's what databases do. Every withdrawal you ever made sits in a spreadsheet with your name at the top.
Cash first. Before you route around the bank, ask why you're routing through it at all. For everything local — groceries, fuel, the haircut, the second-hand whatever — cash remains the cleanest payment technology ever deployed. No account, no counterparty, no ledger with your name in it, nothing to subpoena, nothing to leak, nothing to freeze. Every payment is final and every record dies at the till. A card payment quietly files a report about you — who you are, where you stood, what you bought, at the second you bought it — to a consortium of parties you've never heard of and will never audit. Cash files nothing. As a rule: cash where you can, bitcoin where you can't, a bank account only where it is forced on you. The third category exists — salaries, landlords, states that insist — but it's smaller than your habits think, and every purchase you move out of it is a page fewer in someone else's archive of your life.
Fiat rails that touch a bank account are also the on-ramp profile that follows your money around: if the account is compromised, every purchase, transfer, and counterparty is compromised with it. Cash decouples the daily economy from that archive entirely. Think of it as ecash with the counterparty count dropped to zero — no mint to trust, nothing to redeem, too low-tech to subpoena, too dumb to phish.
For the fiat corners of life where cash physically can't go: 2fiat.com, GoblinCard, and — country by country — the MB Way / TWINT / BLIK family: BitWay (Portugal), BitTwint (Switzerland), BitBlik (Poland). Ramps exist that don't require a biography first.
Opsec is a practice, not a purchase
You don't buy privacy. You operate it, like a garden or a server. It decays without attention.
The goal isn't invisibility — that mirage sells products. The goal is to be expensive. Every wire you pull out raises the price of watching you until, for most adversaries, you're simply not worth it. Perfect opsec is a myth. Better opsec is a direction.
Start ugly: pick your biggest leak this week — for most people it's the phone number or the Gmail account — and fix it. Then the next one. And remember that opsec fails at the seams, not in the middle. One lazy signup at 2am undoes a year of discipline.
Boring to track. Expensive to hack. Free to speak.
That's the whole project.
Questions, arguments, or a leak you want help closing? Find us at nostrdev.com — or hi@ft.hn if email is still your thing.
