Hacking / Opsec

compromised PGP keys

Started by LearnOpsec · Jul 26, 2026

#235
Let's imagine a scenario where a vendor's system is compromised,
and it's possible that LE has access to their encryption keys and
messages.

Suppose I sent sensative info in a DM to the vendor. Now, during damage
control, I've deleted my compromised PGP keys from Kleopatra. Is there
still residual data lingering in TAILS' persistent storage that could be
linked to my compromised PGP keys, even after deletion? Should I
consider doing a clean reinstall of TAILS and setting up a new
persistent storage to minimize risk or is this unnecesary?
#236
↳ Replying to @LearnOpsec
see online methods to make recovery
hard of your hardware(SSD/ hard drive), next time encrypt OS at base
level like when installing so even hardware get compromised they won't
we able to find data, is drive is unencrypted it can easy to get data
even with pass(homescreen lock) on both windows / linux
#237
↳ Replying to @LearnOpsec
Your tails persistent storage is
encrypted and protected by password. Unless you think they can gain
access to your tails there is no point deleting anything.
#239
↳ Replying to @LearnOpsec
you're thinking about this wrong.
delete your pgp key on the market or site you're using following any
sensitive content transmissions, and put a new pgp key up. the messages
will not be decryptable using the new pgp key.