Sam Bent's avatar
Sam Bent
contact@sambent.com
npub1y7rv...d0r3
Agorist. Counter-economist. Privacy maximalist. Student of OPSEC. Anti-authoritarian. Free speech absolutist. Logician. Ex-Darknet Vendor. Youtuber.
Sam Bent's avatar
SamBent 8 hours ago
#OPSEC365 147/365 Every OAuth authorization you've granted is a standing breach. Most are still active. That quiz app from 2018 still holds read access to your friend list and email. Each authorized app runs its own retention schedule, independent of the platform. MITRE ATT&CK T1585 (Establish Accounts): adversaries build cross-platform access. Your apps built the same access the moment you clicked Allow. Audit every platform. Revoke anything unused. #OPSEC365
Sam Bent's avatar
SamBent 22 hours ago
Darknet vendors figured out Bitcoin was a honeypot around 2017, the rest of crypto is still catching up. image
Sam Bent's avatar
SamBent yesterday
Every scene gets captured eventually. The tell is when the tickets get expensive.
Sam Bent's avatar
SamBent yesterday
#OPSEC365 146/365 Gift cards aren't anonymous once you buy them with a card. The purchase creates a transaction linking your identity to that card number. If the gift card is later used somewhere, the chain connects you to that purchase. Even cash-bought cards get registered to real identities when people activate them online. Cash-purchased gift cards lose their anonymity the moment they're activated with an email or phone number. #OPSEC365
Sam Bent's avatar
SamBent 2 days ago
And suddenly I'm glad that I'm not going to defcon this year. I have no issue waiting and watching the talks to avoid shit like this. How it started: "The Electronic Frontier Foundation was formed in 1990 by John Gilmore, John Perry Barlow and Mitch Kapor. The foundation was a response to concerns that law enforcement and policymakers lacked sufficient knowledge about the internet to make decisions or policies that respected people's rights." How it's going: "get your purple beard done, and let's talk about compliance at fedcon". image
Sam Bent's avatar
SamBent 2 days ago
#OPSEC365 145/365 Office building visitor logs create permanent records of who you met with. Sign-in sheets, badge issuance systems, and lobby cameras all document visitors. Security keeps these records indefinitely in some buildings. The person who signed you in has documented that you visited their floor on that date. Building security logs document every visitor, including ones who were never suspected of anything. #OPSEC365
Sam Bent's avatar
SamBent 2 days ago
The government cannot tell you how many federal laws exist. The Justice Department spent two years trying and stopped. You are not following all of them.
Sam Bent's avatar
SamBent 3 days ago
You don't need their permission to store or send your own wealth anymore and that terrifies them. image
Sam Bent's avatar
SamBent 3 days ago
#OPSEC365 144/365 Valet parking gives strangers complete access to your vehicle. Your car contains registration documents with your address, garage door openers, house keys if you leave them on the ring, and anything stored in the console or glove box. The valet has unsupervised access to all of it. Before you valet park, consider what's accessible inside your car and who's about to have the keys. #OPSEC365
Sam Bent's avatar
SamBent 4 days ago
The scary "Monero deanonymized over Tor" story needs an attacker running a chunk of the Tor network itself to ever reach your IP. I break down what the paper actually proves versus what happens to you, on real nodes in an isolated lab. #NewVideo image
Sam Bent's avatar
SamBent 4 days ago
#OPSEC365 143/365 Two-factor authentication backup codes are just passwords you might have written down somewhere. Those recovery codes printed out during setup, stored in a notes app, or saved in a text file give the same access as the password they bypass. Anyone who finds them can access your account without your second factor. Find where you stored your 2FA backup codes and decide if those locations are secure enough. #OPSEC365
Sam Bent's avatar
SamBent 4 days ago
Nobody broke Monero's cryptography. They found a node that talked too much, and the devs fixed it in December 2024.
Sam Bent's avatar
SamBent 5 days ago
Mining Monero on your CPU is the most accessible way to acquire coins without touching a KYC exchange. image
Sam Bent's avatar
SamBent 5 days ago
#OPSEC365 142/365 Photo metadata stripping varies by platform, and you should never assume. Twitter and Facebook strip EXIF from images served on their CDN. Discord strips it from most upload paths as of recent testing. Email attachments preserve everything. Slack, Telegram, and many smaller platforms vary by file type and by whether the image is sent or attached. Test each platform yourself by uploading a photo and downloading it back to see what survives. #OPSEC365
Sam Bent's avatar
SamBent 6 days ago
#OPSEC365 141/365 In 1992, NYNEX alone processed 25,510 subpoenas. Scaled nationally, Ross Anderson estimated roughly half a million Americans have phone records seized each year. Metadata is collected on perhaps 100x as many people as are wiretapped. This is surveillance as routine administrative process. The infrastructure existed before you were a person of interest.