This guide is meant for DNM clients who do any of the following:
- Use Tor/Windows (without using any other safety measures).
- Save their passwords/PGP in a notepad on their Windows environment.
- Have little understanding of tech/OpSec and subsequent nomenclature.
- Don't know how to get/use XMR. Directly deposit their Fiat bought XMR from a CEX to a DNM market directly.
- Use unsafe passwords.
- Don't even know how to use PGP and send their private data without encryption to a vendor.
I want to find a balance between a bad OpSec based on ignorance & false hope, and allowing people be educated to increase their OpSec in a reasonably simple & safe matter, without having an information overload.
I find that a hard balance to maintain, and I appreciate your recommendations.
This guide is in active development. I look into every comment left by the community and /u/headjanitor to improve this guide to higher standards. Let me know if there's other improvements to be made. And feel free to share this guide as your own.
The intent of this guide is to become the reference guide for DW users and DNM buyers.
Table of Contents
1. Introduction to Tails & requirements
2. Hardware & Software Setup
3. Network Configuration
4. Financial Obfuscation
5. Final Considerations
1. Introduction to Tails
Hiya,
This little guide is aimed at people already using Tor on their Windows or Mac laptops. Using Tails is the minimum requirement for your OpSec (Operational Security) when accessing the DNM as a buyer. It comes with simple instructions and provides an easy, mostly idiot-proof way of accessing the DNM on a convenient and secret USB.
And yes, you're probably an idiot, and that's okay. Idiots can live long and happy lives; my cousin is an idiot, and he was able to follow this guide and stay safe because of it. I probably was an idiot more than once.
Ordering from a DNM without protection is like fucking a 5-dollar prostitute without a condom. It's an easy risk to take, or to avoid. For most, it should be an easy choice.
And for anyone out there, feel free to steal this guide and publish it as your own. I'll keep the guide up to date with changes in the DNM buyer landscape.
Let's start.
Requirements:
- USB with 16GB memory, USB version 3.0 minimum. (Buy two and make a backup. Trust me, it's a good idea to do it now.)
- (Anonymous) Internet connection (on an anonymous device)
- A laptop/computer with a USB slot (A disposable laptop bought with cash if your threat model requires it. Most people don't need a dedicated Dark Web laptop. Tails OS is amnesic, and its activity in RAM is quickly overwritten during the shutdown procedure.)
- Save this text somewhere for reference while you're using Tails.
- Optional: Get a trusted VPN if you live in a country where using Tor is seen as suspicious or worse. Use a device with an internet connection to put on the VPN and let the laptop with Tails OS go through the phone.
- Optional 2: Get an additional USB for a backup. It's very easily done by using the 'Tails Cloner'.
Note: Tails/Tor is not illegal, which doesn't mean it's not considered suspiscious by secret agencies of many nations. I have to stand by my suggestions, that in certain circumstances, u should download Tor in a rarely visited public library or internet cafe through an anonymous device. As more, not less, internet surveillance is becoming the norm, and everyone being profiled by increasingly techonlogically power hungry entities, I am concerned about network observers.
Privacy tools like Tails can be scrutinized in contexts where anonymity is seen as a threat to national security or law enforcement efforts. As according to leaked documents from 2014: ''The NSA has targeted Tails users, labeling it as "a comsec mechanism advocated by extremists on extremist forums"''. Law enforcement agencies do scrutinize people more who look into ''privacy online''. It should be considered to stop a profile being build about a person.
2. Hardware & Software Setup
**Important Note on VPN:**
A VPN is usually not recommended due to it being a third party that can see you're connecting through Tor, which increases the attack surface. However, a highly trusted and proven VPN can hide your traffic from your ISP and subsequent government. Tor bridges can be used to obscure Tor connectivity, but Obfs4 can be uncovered through DPI (deep packet inspections), and unlisted Tor bridges are at risk of retroactive detection when made public later.
Reminding note: Tails/Tor is legal in most countries in the world. Yet, unfortunately, data is being harvested on your profile by your ISP, and government organisations have been known for a long time to make lists of 'privacy orientated individuals'.
**Downloading Tails OS:**
- If required for your threat model of an oppressive/dangerous government, find a public space to download Tails OS via Tor. Use public computers paid in cash to download Tails OS. If you've already been using Tor on your Windows computer, don't worry about it; just download Tails OS normally.
- Downloading Tails OS via Tor might take a few hours. If your internet speed doesn't allow for a fast download and a fast download is required, travel to a city where you never go and download Tor at a café, library, hotel lobby, etc. Stay away from cameras and wear some kind of disguising clothing to hide your features if necessary.
Download Tails OS (via Tor or your normal browser), follow their instructions step by step: https://tails.net/install/index.en.html
Now, let's start Tails. We'll start by making an administrator password and creating/configuring the persistent storage: https://tails.net/doc/persistent_storage/create/index.en.html
Make sure to use a strong password that's difficult to crack. Write it down somewhere until you can remember it fully. Then burn the paper when you fully remember.
After the persistent storage is set up, you'll make your own PGP pair. There's a long guide at the end of this short guide. Refer to the long guide if you have questions about PGP.
**Password keeping, PGP & Encryption**
- First, make a KeepassXC file; it's the password keeper. Use a password that you can remember well, yet would be difficult to crack. You can use the same password as the administrator password that you used for your Tails login. Then click 'add a new entry' and let KeepassXC create a password for the upcoming PGP pair creation.
- First, if you've already connected to the internet with Tails, disable that connection. Generating a PGP pair should be done without an internet connection.
- Second, when making the PGP key, make sure the PGP name is the same as your public username on that market (this is useful for the vendor but is optional). Don't fill in the email; just use a username. Protect the to-be-generated PGP key with a passphrase. Fill in the password you have created with KeepassXC, as written in the previous step. Next, select the 'ECDSA/EdDSA' option. Uncheck 'valid until' and check 'authentication'.
- **NEVER** share your private key. **ONLY** share your public key.
- To export your public key, find your PGP username in 'certificates', right-click, click export, save the .asc file, open it with a 'text editor/pad', and share the **public PGP** with the person/website.
- Use the guide if I didn't explain it well enough: ⚠️PGP Guide⚠️
**NEVER** use the auto-encrypt function on the market. Remember when Incognito Market secretly kept all the address data with their fake auto-encrypt and then tried to blackmail vendors/buyers to delete personal data. And then it turned out LE (law enforcement) had infiltrated the market for months, and everyone got compromised. This isn't the first or last time that LE infiltrated a market and let it run for months to gather data. Assume all markets are compromised; it's an assumption that will keep you safe.
**Notes:**
- In KeepassXC, save a manual database backup after every change you make to your KeepassXC data due to the risk of database corruption.
- Make sure not to use the same PGP pair across different platforms unless, like a vendor, you want the possibility of being recognized.
- And this should go without saying: Don't use a username that you frequently use already. Make it random.
3. Network Configuration
Now, you're finally ready to make a Tor connection. Either connect your VPN device, a public Wi-Fi, or, if you're just a small buyer, use your home Wi-Fi.
When in 'Tor connection', click 'Hide my connection'. If that doesn't work, click 'make connection to Tor'. But make sure to check the 'use bridge' and then select a 'default obfs4 bridge'.
That's it. You probably think, "Why should I do this when I can just use Tor?" Here's why:
- You've made it this far to the DNM, but you're just human, and you will fuck up in ways you don't even understand until it's too late.
- Tails OS has a Tor-only connection, encrypted persistent storage, a password keeper (KeepassXC), and has a PGP tool installed. These are all the tools you need to be on the DNM, and it will separate and organize your normal life from your Dark Web life.
Now, let's bookmark these websites in the Tor browser so you won't get phished:
- tforum: http://g66ol3eb5ujdckzqqfmjsbpdjufmjd5nsgdipvxmsh7rckzlhywlzlqd.onion/
- Darknet link directory for markets, etc.: https://daunt.link/
When you start using Tor, and you'll have to do this every new start of Tor, go to settings (top right corner of the three little horizontal lines). Click Privacy & Security, find the security level, and select the safest. This will disable JavaScript, which is an OpSec risk. You'll also have to type: 'about:config' in the browser search bar, search for 'JavaScript.enabled', and set it to false. It might break certain websites; if that happens, lower the setting from safest to safer.
Make sure to keep the safest setting on when browsing markets or tforum.
4. Financial Obfuscation
Now, let's get some XMR to make your purchases on the DNM:
- First, download Feather wallet: http://featherdvtpi7ckdbkb2yxjfwx3oyvr3xjz3oo4rszylfzjdg6pbm3id.onion/
- Start up Feather, make a new wallet, and store the password/seed in KeepassXC before you do anything with the wallet. Double-check the password/seed if all is correct.
- Option 1: Buy XMR directly from a P2P/decentralized exchange such as OpenMonero, BISQ, Haveno, etc. Send your XMR to your Feather wallet (don't send XMR directly to a market).
- Option 2: Buy any crypto (such as Litecoin) from any common fiat-crypto exchanger and send it to a crypto-crypto exchange to convert your crypto into XMR that you receive in your Feather wallet on Tails OS.
Note: Preferably let the XMR sit in your Feather wallet for a couple of hours/days before sending it to the market to minimize timed association attacks.
Find a crypto-crypto exchanger here: http://kycnotmezdiftahfmc34pqbpicxlnx3jbf5p7jypge7gdvduu7i6qjqd.onion/ I can recommend OpenMonero, Trocador, BISQ, Haveno, and many others.
Go to a DNM found on official tforum market pages, such as /d/Superlist /d/DarkNetMarkets or https://daunt.link/, and buy whatever you desire. There's also the new and growing /d/vendorsuperlist/; subscribe to them to support the tforum community!
5. Final Considerations
**ALWAYS** encrypt your own messages; do **NOT** rely on auto-encrypt. **NEVER** send **ANY** personal data without PGP encryption. It's a danger to yourself, but also to the vendor—and I personally will always ban you if you send me your address without encryption.
No compromises on OpSec are acceptable.
Use the second optional USB to make a backup of all your data.
The next OpSec step would be the Qubes/Whonix route.
TailsOS is a tool that should be mandatory for anyone visiting the DW frequently. I am unfamiliar of cases where people got busted due to Tails. But then again, it's not like that information would be freely shared by LE - They usually don't show their cards, they just play them in secret - And we're left guessing and putting the pieces of logic together through snippets of information and deduction, and so do they.
Qubes/Whonx route is only a necessity when the knowledge of your OpSec makes you become aware it's a reasonable necessity to invest your time in to safeguard you from specific threats.
I think Tails suffices for most purposes here, and we should aim te educate each other - We all started here as ignorant apes. And it's usually a journey made by one's self, to venture into the DW. Some guidance would good in this dark place.
You're gonna have gonna have to reference this guide the first couple times when you're using Tails, as you're getting used to everything, but will become an easy habit in no time.
Love,
KS
Good beginner guide for OpSec (/d/DNMBible) : http://biblemeowimkh3utujmhm6oh2oeb3ubjw2lpgeq3lahrfr2l6ev6zgyd.onion/content/bible/pgp/index.html
ps Bonus: detailed guide on OpSec: https://anonymousplanet.org/guide.html#appendix-b3-threat-modeling-resources
pps /d/Tails and /d/OpSec
ppps a comment stolen from /u/DaVenom (mod of /d/OpSec)
Everything you do, publicly, privately, legally or questionable will leave some type of trace.
Proper OpSec will minimize the trace back to your person and your associates.
Your OpSec needs to cover public profile and be in conjunction with your darknet live.
The list below is just an illustration of some aspects to be considered. These aspects should be a part of your threat model.
- Monetary traces - crypto and fiat transactions
- Banking interactions - Information shared with banks or financial institutes
- Traveling traces - Flights, car rents, hotels, border controls, etc.
- Government interactions - Tax declarations, health care, education, etc.
- Biometric traces - DNA, fingerprints,
- Environmental traces - Fibers, dust, mud, etc.
- Contamination traces - Spray DNA, gun oil, gun powder residues, explosive residues, etc.
- Online traces - MAC addresses, VPN connections, Tor connections, social media logins, etc.
- Online behavior - Downloads, Internet searches, Youtube watching, news reading, etc.
- Mobile phone localization - Cell tower triangulation, Google/Apple positioning, etc.
- Surveillance camera captures - Roads, sidewalks, garages, parking's, home, offices, shops, malls, etc.
- Technological patterns - Similarities between technologies used at crimes and downloaded technologies
- Skill levels used - Sophistication and knowledge levels required for specific crimes can be traced back to your education level
- Life style - Spending at home, cars, vacations, night life, etc.
- Social behavior deviations - How friends, neighbors, coworkers, etc. interpretative you as a person
- Social leakage - Talking and writings that indicate a darker side
- Daytime job interpretations - Needs to fit the spending
- And more...
Important to not mix public profile with darknet, here is a few examples:
- Don't buy flight tickets with cash, is not normal, will be flagged.
- Don't pay taxes with cash! Use the legal money for this.
- Don't download darknet tools from clearnet unprotected.
- Withdraw legal cash frequently and save the receipts in your wallet. Make sure you have enough with receipts to cover whatever you have in cash. Refresh the receipts every 3-6 months.
- Don't use any personal social media accounts for darknet
- And most importantly, never talk, not with wife, not with best buddy, absolutely nobody more than associates and keep that need to know basis.
Trust no one. Not even yourself, because you might not even know how stupid you really are.
Please understand, most likely you know too little to just make decisions right now, they might have unforeseen consequences.
Mistakes have already been made by others, you don't need to make the same mistakes.
The path was made through personal sacrifices of time, money, and blood.
Follow the knowledge already laid down before you.
Stay Safe, Stay Anonymous!