OPSEC guide BTS
From Frankfurt to WIRED
Yesterday, WIRED published The WIRED Guide to Digital Opsec for Teens, which I had the privilage of co-authoring with WIRED senior writer Lily Hay Newman. Here’s how it came together.
One Monday in October I took a one-day trip to Frankfurt for a two-hour client meeting. Ten hours of bus, train, airport, and plane. Public transit and airports are always stressful to me, so on the train from Lausanne to Geneva I began a micro-project: OPSEC advice for my almost 15 year-old daughter. As a hacker and as a member of the local association Hygiène Numérique where I’d been running awareness sessions to parents and kids on online risks, I felt more than qualified.
Back home around 11pm, I had a first draft. It had already morphed into a blog post. I wanted it short, almost minimalist, to match people's attention span. Over the next few days I polished the text and wondered who might publish it, since I didn’t have this blog then. But before sending it anywhere I asked a few people who know OPSEC better than I do for a sanity check. They liked it and suggested a handful of key improvements—thank you, Doug Henkin and Rob Graham.
I had worked with Lily before, having been quoted in several of her WIRED pieces. She immediately liked the idea of turning the OPSEC post into a WIRED story, and her editors did too. We just needed to transform my raw notes into something that met WIRED’s editorial standards. Lily drafted a first version from my raw material. Then she, WIRED senior editor Andrew Couts, and I went through a few editing rounds before scheduling the publication, which WIRED kindly agreed to make non-paywalled.
Now here’s my my raw, unedited version, with the original title:
Digital OPSEC for my daughter (and other teenagers)
1 What’s OPSEC and why it matters
OPSEC = operations security. In digital OPSEC:
Operations = the stuff you do online: messages, searches, AI chats, websites, photos, accounts, passwords, etc.
Security = 2 goals:
Secrecy = no one sees stuff they shouldn’t.
Availability = you don’t lose access to your data and accounts.
OPSEC is hard because secrecy and availability conflict: the more secret you make things, the easier you lock yourself out, and the other way around. Good security is balance.
OPSEC is not paranoia. You’re not a cartel boss. For you it’s about:
Not being an easy target.
Building habits that prevent disasters, like
Getting your social media accounts hacked.
Losing all your photos from the last two years.
All your school reading your AI chats.
It’s also about time travel: OPSEC now before it becomes important. The police will grab your Google search history and LLM prompt history covering the period when you hadn’t yet committed to the course of action they are now investigating you for.
2 Famous OPSEC disasters
Even the pros blow it:
2025 “Signalgate”: U.S. officials discussed war plans in a Signal group chat and accidentally added a journalist. They also used a modified, insecure version of Signal.
CIA Director Petraeus (2012) shared a Gmail account with his mistress to “hide” messages in drafts. FBI found it.
Printer dots: an NSA leaker got caught because most color printers secretly add yellow dots that trace the printout.
Lesson: If the CIA and NSA can screw it up, so can you.
3 Disclaimers
Some of this contradicts the “10 Best Security Tips” lists. Good.
I don’t cover everything.
I skip the obvious (don’t give your password to friends, duh).
I explain some tech because knowing how things work saves you from dumb mistakes.
I’ll tell you what to do. Details of the how are up to you.
Remember:
Murphy’s law — anything that can go wrong will go wrong.
Law of unintended consequences — every change has side effects.
4 Why should I listen to you instead of AIs?
AIs will give you generic “best practices,” often outdated. I give you reality: 20 years in infosec, OPSEC in both chill and high-risk situations, lessons from experts and from failures, mine and others’. Also, I designed cryptography that runs on your phone.
5 Essentials
5.1 Say goodbye to your phone
One day your phone will be lost or stolen. It’s just statistics. Could be a stranger, could be a pissed-off friend, could be bad luck.
To minimize the damage, lock it down:
Strong PIN/pattern (not 1234 or your birthday), and
Don’t show it around. Change it occasionally.
To be able to locate the phone, enable Find My (Device).
You shouldn’t lose your life when your phone is gone:
Photos: Sync with Google Photos, iCloud, whatever works.
Chats:
WhatsApp: Enable backups.
Signal: no backups, but history stays on other devices.
Telegram: keeps everything in clear on their servers… (avoid)
Contacts: Sync to Google/Apple. Saves weeks of begging for numbers.
2FA codes: Back them up. Google Authenticator now syncs.
5.2 Passwords and account access
The #1 reason people’s accounts get hacked is that they’ve reused the same password across important accounts.
Think in tiers:
5.2.1 Master account (usually Gmail or Apple ID)
If this is compromised, you’re toast: emails, photos, resets for every other account.
Rules:
Unique, strong password. Memorize it. Keep a paper copy at home.
Enable 2-factor authentication (2FA). Print recovery codes and store them offline.
If supervised by parents, logins already need approval. Fine. Add 2FA anyway as extra defense.
5.2.2 Important accounts (socials, Spotify, school)
If hacked, it hurts but won’t cascade to everything else.
Rules:
Unique passwords. Save in your phone/browser manager, or don’t save them and reset.
2FA where possible.
5.2.3 The rest (random services)
Be lazy here:
Let your device generate random passwords, or
Use a simple pattern you tweak, like
OPsec823??xxwhere xx are the service initials.Honestly, you may even reuse the same password when the account really doesn’t matter.
5.2.4 Basic hygiene
Only download apps from official stores. They run malware checks that sketchy stores don’t.
Stay away from Chinese app ecosystems (WeChat, Tencent).
Don’t keep things you don’t need. Old files, photos, chats are liabilities waiting to leak.
Regularly erase your history (browser, YouTube, AI, etc.)
6 Networking
6.1 What’s encrypted and what’s not
Most apps and websites now encrypt your traffic. The tech behind is called TLS. It prevents WiFi networks, your ISP, and criminals from seeing the data you send and receive: photos, emails, DMs, and so on.
But domain names are not protected. When you access instagram.com your device sends a message that means “what’s the IP address of instagram.com?” and gets one back. This step is called called DNS resolution, and is usually not encrypted. So if you connect to your school’s WiFi, their admin can see the list of apps and websites you use.
Incognito/Private tabs ignore cookies and don’t keep a browser history. These won’t help hide domain names. They make you slightly harder to track and discard all active sessions when the tab is closed.
6.2 VPNs
A VPN app routes your traffic through another server, adding a layer of encryption between your device and that VPN server. DNS requests are also routed through the VPN, hence your local WiFi and ISP won’t see the domain names accessed (but the VPN provider will.)
VPNs also hide your IP address from the websites you access. They’ll only see the VPN server’s address.
A VPN can thus fake your location, which is why people use it for blocked or region-locked content.
My favorite VPN app is Mullvad (5 EUR/month). ProtonVPN is good too (free for one device).
Careful with free VPN apps. Many spy on you worse than any local ISP would. They often retain your data even when they claim they don’t. Some VPNs even route your traffic to China
6.3 Anonymity: Tor
The Tor Browser offers higher anonymity than a VPN: no one will know both your IP address and the site you’re accessing.
Don’t use Tor for socials networks or video streaming. It’s too slow and defeats the point. Use Tor when you want searches or sites to be (almost) impossible to trace back to you. It runs in its own browser, isolated from your other sessions, and doesn’t save history or cookies. Never enter identifying details like your real name or main usernames.
If you log into a service via Tor, never log in directly from your home address. That’s how people get caught.
Tor Browser apps exist for Android, iOS, and desktops.
7 Searching, browsing, ad-blocking
Google tracks what you search and builds a profile on you. Privacy-focused search engines won’t save your history or track you (but you won’t get personalized results.) Try Brave Search, DuckDuckGo, or Startpage. You can set them as your default search engine.
For browsing:
Brave has ad-blocking and privacy features built in.
Chrome, Edge, Firefox are fine too. Just install uBlock Origin (Lite) to kill trackers and ads.
8 Messaging
WhatsApp and Signal guarantee end-to-end encryption: only the recipient’s device can decrypt your message, not the provider. WhatsApp will use your social graph to send contact suggestions on Instagram and Facebook. Unlike WhatsApp, Signal doesn’t show your online status. I prefer Signal.
Rules of thumb for both:
Enable disappearing messages when useful (screenshots still possible).
Add Face ID unlock for your chat apps. It’s nearly transparent and saves you if someone snatches your unlocked phone.
Know their privacy features (one-time images, etc.)
When you see the police obtaining WhatsApp/Signal messages, they haven’t “cracked” the encryption or used a “backdoor.” They got the messages from a device: the defendant’s or that of persons they were talking to.
9 Compartmentation
That’s the hardest part. Failure to compartmentalize is often how criminals get caught.
Think of your online life like rooms in a house. Each room has a separate key. If someone breaks into one room, you don’t want them walking into the others.
9.1 Why it matters
If your school account is compromised, it shouldn’t expose your private Instagram username.
If your anonymous Reddit is discovered, it shouldn’t lead back to your real name.
If your anonymous email is leaked, it shouldn’t give access to your main inbox.
9.2 Identities
You have multiple identities online:
Real you: school email, main Gmail/Apple ID
jane.doe@gmail.com, family stuff.Social you: semi-anonymous handles (
jnd03). Friends know it, classmates can probably guess it.Pseudonymous you: alt accounts with no obvious link to real you (
_aksdi0_0,peter_mayfield01). Should live under a different email address altogether.
9.3 Rules of separation
Usernames: Don’t recycle across worlds. If
JaneD03is your Insta handle, don’t use it or a similar name for your anonymous Reddit.Emails: Use separate ones for pseudonymous accounts. ProtonMail is good. Gmail “dot tricks” (
janedoe@,j.ane.doe@) don’t count as they all point to the same mailbox. But this can be useful in other cases.Passwords: Unique for each identity. Don’t reuse between real and pseudonymous.
Cross-talk: Don’t send emails between your real and pseudonymous accounts. Don’t DM your alt account from your main.
Browser: Connect to your pseudonymous account from Incognito tabs or from a different browser. This way, cookies and sessions can’t betray you.
10 AI chats
Double-check answers. Don’t blindly copypaste.
Delete old chats you don’t need (remember: Archive ≠ Delete).
Don’t mix school prompts with personal stuff in a same chat. Careful when using the same account, as it retains memories across chats.
Again, enable 2FA.
11 Advanced stuff
Check leaks on haveibeenpwned.com. If your email is listed, change password.
Photos: Strip EXIF data (Signal and WhatsApp do it). Otherwise, selfies = GPS tags.
Cloud sync traps: Deleting photos locally (on the device) doesn’t delete in the cloud. Review regularly.
Reverse image search: Know how it works (both to check yourself and others).
Public defaults: Playlists (Spotify), payments (Venmo) often start public. Check settings.
Social media:
Don’t post in real time to hide your current location.
Prune friends every few months.
Screenshot if you need “evidence.” Links vanish.
Self-search: Google your name once in a while to see what’s out there.
12 Contingency
Shit happens. Remember the two laws. We’ve all lost a password, an account, and data. When it happens, learn from it. Understand what went wrong, how it could have been avoided, and adapt your OPSEC.
To reduce the risk of data loss, make offline backups. Google Takeout will let you export your data. Copy the most critical stuff on USB drives or a home NAS if you have one.
Featured image: 七人の侍.