Before even messing around, have you tried tails?
Have you tried running linux distros off of usb drives?
If it is not connected to the internet, then yes it is safe.
There would be other attack vectors though like physical possession of an unencrypted machine or an encrypted machine powered on at the time of the raid.
But nothing can "phone home" or do anything with your stuff if it doesn't have an ethernet cable plugged into it or it is not connected to any Wifi.
There would be other attack vectors though like physical possession of an unencrypted machine or an encrypted machine powered on at the time of the raid.
But nothing can "phone home" or do anything with your stuff if it doesn't have an ethernet cable plugged into it or it is not connected to any Wifi.
Not how you described it, no. IP based blocking can easily be bypassed by requesting a new lease. This can even happen without your knowledge if the machine has been powered off for long enough.
If you never connected your host to the internet and just forwarded your wireless card to the vm, that would be safer. Though I don't understand the point of doing this over just running free software on your host.
If you never connected your host to the internet and just forwarded your wireless card to the vm, that would be safer. Though I don't understand the point of doing this over just running free software on your host.
It has a couple identifying markers but one that would be completely unique to your machine is the GUID. All windows machines have them.
Thanks for the replies, I use BitLocker for encrypting that I personally don't trust much, Windows is on the SSD some more sensitive files are on the HD that I can delete for sure, I assign the IP to the Mac of my computer to try to keep the same IP, my idea of blocking was just to try to "disable" the AMD PSP and Windows telemetry, I've used Whonix and Tails I still have Tails on a USB but I'm not using it much
GDID, and if you use the right warez you can remove that shit from your system.
tails and thats it
It's embedded into your motherboard
every OS when you make it without any WI-FI it becomes safe from attack vectors that comes from internet and use Linux like Mint or Debian it is better if you want to run Vm's. Infact Linux have better things for OPSec
Turn on the PIN for BitLocker. It makes it unhackable. Google "Bitlocker TPM+PIN" and change those settings. Note PIN doesn't have to be numbers. It can be a twenty letter and number alphanumeric string with characters. You'll enter it immediately on boot. Successful BitLocker hacks require two things:
1. Private keys backed up to a Microsoft Account.
2. BitLocker installed WITHOUT the PIN protection.
Make sure both of those aren't happening and your harddrive is truly encrypted. Now, as for the software running on the machine when it's being used -- that's another story.
1. Private keys backed up to a Microsoft Account.
2. BitLocker installed WITHOUT the PIN protection.
Make sure both of those aren't happening and your harddrive is truly encrypted. Now, as for the software running on the machine when it's being used -- that's another story.
Members-only continuation
This discussion contains more posts.
Create an account or sign in to continue reading the full conversation. 4 additional posts await inside.