← index

about

opsec.log is a working notebook, not a manual. It collects defensive operational-security thinking as it forms: threat models that survive contact with reality, compartmentalization that holds under pressure, metadata hygiene, and the quiet failures that undo all three.

The bias here is defensive and practical. Most entries start as a question — what does this actually protect against, and from whom? — and end somewhere less tidy than they began. Posts get revised when they turn out to be wrong. That is the point of keeping a log rather than publishing conclusions.

Everything here is educational. It is not legal advice, and it is not a substitute for a threat assessment tailored to your situation. Adopt nothing on faith; verify against your own model, your own adversary, your own tolerance for failure.

Nothing on this site tracks you. No analytics, no third-party scripts, no cookies, no fonts fetched from someone else’s CDN. Pages are static files served under a strict content-security policy and a no-referrer policy. The only request your browser makes is for this page.

The author writes as “operator” — pseudonymous, deliberately. Practicing what the notes describe is part of writing them.

feed: /feed.xml · no comments, no newsletter, no mailing list.