Sam Bent's avatar
Sam Bent
contact@sambent.com
npub1y7rv...d0r3
Agorist. Counter-economist. Privacy maximalist. Student of OPSEC. Anti-authoritarian. Free speech absolutist. Logician. Ex-Darknet Vendor. Youtuber.
Sam Bent's avatar
SamBent 6 days ago
#OPSEC365 196/365 Health insurance claims reveal your medical history to multiple parties. Every claim goes to the insurer, gets reported to industry databases like MIB, and may be shared with employers for self-insured plans. Procedures, diagnoses, and medications become part of your permanent health record beyond your doctor's office. The MIB shares claim history across insurers. One claim can affect your rates with carriers you've never used. #OPSEC365
Sam Bent's avatar
SamBent 1 week ago
#OPSEC365 195/365 Password managers often include emergency access features. Bitwarden, 1Password, and LastPass let you designate emergency contacts who can request access to your vault after a waiting period. If you've enabled this, someone else can potentially reach all your credentials. If you turned it on and forgot, a designated contact may be one request and one waiting period away from everything. #OPSEC365
Sam Bent's avatar
SamBent 1 week ago
#OPSEC365 194/365 Smart doorbells record conversations from people walking past. Ring and Nest cameras with audio capture snippets of conversation from neighbors, delivery workers, and passersby. That private conversation you had on the sidewalk might be recorded in someone else's cloud storage without your knowledge or consent. A Ring camera covers the street, the neighbor's driveway, and anyone who walks past, not just the front door. #OPSEC365
Sam Bent's avatar
SamBent 1 week ago
This has existed for over 10 years. None of this is about protection or any cause that has to do with protecting you. Notice how both still exist? It was never about either of those things, just like ID confiscation (aka 'age verification) isn't about age. There is a reason signaltrace, axon and flock appeared as they did. image
Sam Bent's avatar
SamBent 1 week ago
#OPSEC365 193/365 Cross-cut shredding is not enough for high-sensitivity documents. After the 1979 seizure of the US embassy in Tehran, Iranian student militants painstakingly reassembled strip-shredded classified documents by hand and published them in dozens of volumes. Modern reconstruction software does the same job for cross-cut shreds in minutes. For anything that matters, burn it or use a micro-cut shredder rated P-5 or higher. #OPSEC365
Sam Bent's avatar
SamBent 1 week ago
#OPSEC365 192/365 Video call recordings capture everything in frame and earshot. Zoom and Teams meetings get recorded, often by default in corporate settings. Your facial expressions, background, voice, and any visible documents are preserved. Meetings you thought were ephemeral may sit in cloud storage accessible to IT and management. Side conversations and visible documents end up in storage you don't control. #OPSEC365
Sam Bent's avatar
SamBent 1 week ago
Stack XMR while normies argue about which surveillance coin will pump next. image
Sam Bent's avatar
SamBent 1 week ago
#OPSEC365 191/365 Your employer tracks who clicks on phishing simulations. Corporate security teams send fake phishing emails to test employees. If you click the link, that failure is logged. Repeat offenders get flagged for additional training or worse. Your click rate on simulated attacks becomes part of your employment record. Treat every suspicious email at work as potentially a test of your security awareness. #OPSEC365
Sam Bent's avatar
SamBent 1 week ago
#OPSEC365 190/365 Downloading your social media archive reveals more than you posted. Facebook, Twitter, and Instagram archive downloads include messages, login locations, advertiser categories you're sorted into, facial recognition templates, and data you never knew was collected. The archive is more revealing than your public profile. Download your data archive from each platform and see what they've collected about you. #OPSEC365
Sam Bent's avatar
SamBent 1 week ago
#OPSEC365 189/365 Your Bluetooth device name is a persistent surveillance identifier. In a noted ISS exercise, Jenkins scanned Bluetooth signals on a train and noted five device names. An hour later at an art gallery, one name reappeared. A monitoring operator was on the train.
Sam Bent's avatar
SamBent 2 weeks ago
#OPSEC365 188/365 ATM cameras record your face alongside your transaction. Banks use cameras at ATMs for security, capturing high-quality footage of anyone making a withdrawal or deposit. This footage includes timestamps that correlate exactly with your transaction records. The combination creates a verified record of your presence at that location. ATM cameras produce timestamped facial imagery that correlates exactly with your transaction record. #OPSEC365
Sam Bent's avatar
SamBent 2 weeks ago
#OPSEC365 187/365 Venmo's default settings make your friends list and transactions visible to anyone. Even with private payments, your list of Venmo contacts is publicly searchable unless you change settings. This social graph reveals your relationships, roommates, partners, and anyone else you regularly exchange money with. Check your Venmo privacy settings and make your friends list private. #OPSEC365
Sam Bent's avatar
SamBent 2 weeks ago
#OPSEC365 186/365 Your network is visible even when your profile is locked. Maltego runs a transform on your name and maps every connected entity: your employer, your family, your co-authors, the forums you both post in. Gephi visualizes graph and marks you as a central node. The people around you are not private. The map of who you know is data, and that data sits in tools anyone can run. #OPSEC365
↑