Use Thinkpad x60 or x200 if you can.
It's stable and clean. The wifi 802.11 card (require closed embedded
firmware), modem card, bluetooth card, infra-red and microphone should be removed.
Speakers should
also be removed (see side-channel attacks bellow). The dockstation input
should be removed (Direct Memory Access). Some blobs still remain, as
in the case of the Embedded Controller (use external keyboard for
mitigation).
Note: It has to be stochastic. Digital white-noise
players won't work.
Kscope (HDD turned into a microphone). The author provides this
solution. I suppose a white noise machine would also work (if it's
close enough to the machine to interfere with the vibrations).
Don't use stickies. They can identify you or at least profile you. Remove serial number stickies too if your hardware have it.
Don't go on public thinking you're such a "hacker", opening
terminals and compiling stuff. People will call security guards. If you
want to use public wifi, be stealth.
Hardware manipulation:
Coldboot attack (DDR2 only), EPROM reflashing, Direct-Memory Access attacks (such as PCILeech
- your system should encrypt your memory anyway), all can be prevented
if you have good physical security practices. For laptops, for example, Pelican has some rugged cases that can be adapted for it and Evva MCS is a very hard lock to pick.
Storage firmware exploits, such as HDD hack and BadUSB. No solution yet, although you can debug and dump your firmware with the specific tools. See Psychson.
Jamming. Although there's a extensive military and academic research on this area, no solution seems to be in production (that we know of). Most of it use notch filtering. If you have more information about it, contact us on endchan.
Hardware Trojan
(manufacturer instruction set manipulation). Although there's some
academic hypothesis about a solution, we can't do nothing about it now.
About package shipping, be aware of Interdiction (shipping interception). We can't do nothing about it. You can pay in cash for a locked PO Box
to prevent seller identification of your location, but we can't prevent
interception. If you buy a open hardware, check if the product match
the schematics provided and always reflash your firmware.
Natural language analysis:
Stylometrics analysis can be mitigated with Anonymouth (caution, it uses Java). A coded language or a constructed language (see Lojban) might help with that.
And finally: have a gun with you. Nothing will help you if they use Rubberhose attack.
Then, transform the range of IP's to CIDR. There's many ways to do it,
just search. The range of CIDR should be used on pf(4) to block all
traffic.
After that, put the securelevel(7) to 2 and configure files the pf rule with chflags so it become immutable.
Note: you have to setup Transparent Proxy on your system. Use sysctl to stop
recording TCP timestamps.
Disable ICMP service, since it can leak host time. Don't run tor as
root. Configure resolv.conf to localhost, so you don't leak DNS (needs
DNSPort). Put Tor on chroot. And compile it yourself.
This configuration will exclude countries that you probably don't
want to route your traffic and ensure exitnodes to better places (such
as Iceland). It may break your connections, though. Use at your own
risk.
Mesh Networks
B.A.T.M.A.N. (Better Approach To Mobile Ad-hoc Networking)
Note: check also ADVcash or similar for bitcoin cards.
Always buy bitcoin using money, and then use a BT Mixer (like this or coinjoin),
through Tor. As always: bitcoin is not anonymous, be
careful. That's why we're suggesting Dashcoin
instead.
Passphrase Manager
If you can't or don't want to buy a Nitrokey, use this command:
$ head -c 10 /dev/random | base64 > passphrase
Use the file generated as your passphrase and further encrypt it using reop
Always remove files securely using the command rm -rfP on OpenBSD or shred on other unix-like systems
When possible, don't use X windowing system. It's a mess. Even Xenocara
(OpenBSD fork of X). When you have no alternative, always init the
session using tmux:
$ tmux
Then type this command inside it:
$ startx & lock -np
Go back to tmux, close the session (using control+b) and exit
the user. This is a good way to prevent someone that has physical
access to the machine from just pressing Ctrl+C on the tty and exit your
X session (gaining complete shell access).
Make sure to do your own router using OpenBSD and a SoC board
Don't use hardware-based cryptography
If you can, don't use wireless connections
Don't use social media and don't expose your personal life on the internet.
Smartphones are a government tool. Don't even try.
TODO
Show how to get Tor transparent proxy working on OpenBSD
See more on traffic shaping and deep packet inspection. See this
Put Wikipedia Snapshots on Searx, so you don't need to request the page everytime. See if plato.stanford.edu has a public snapshot.
Show how to disable all protocols but TCP/IPv4 and Close all ports,
allow only Tor (generally 9050 and 5555). Disable WoL (Wake on LAN) and
INET6 using ifconfig.
Show how to compile Links2 from ports. Disable cookies and iframe support. Add pledge privsep.
Show how to mount the system as read-only and put everything on RAM, through MFS - nosuid, nodev, noexec. [?]
See if it's possible to adapt this or this to OpenBSD
Disclaimer
No disclaimer needed. You know you should use anything listed here at your own risk.