Digital Security
for ActivistsSeguridad Digital
para Activistasv.2026.03
A Practical Security Guide for Activists & CollectivesGuía práctica de seguridad para activistas y colectivos
& ToolsSecciones
y herramientas
ToolsHerramientas
interactivas
OpenGratis y
abierto
IntroductionIntroducción
👁Understanding Modern SurveillanceComprendiendo la vigilancia moderna
Every tap, every app
Sends logs upstream
Microsoft · Telegram
- Location history & daily routine
- Political & religious interests inferred from browsing
- Income, health queries, relationships
- Home & work address, family members
- Buyers: far-right groups, stalkers, private investigators, employers, insurers
- Full message history (if not E2E encrypted)
- Contacts & call records: who you organized with
- Location timeline: everywhere you've been
- Search history, documents, photos, deleted files
- Also direct: Pegasus spyware, IMSI catchers, CCTV + AI, tower dumps
- Stalkerware (mSpy, FlexiSPY) installed by abusive partners: reads messages in real time
- Data breaches expose credentials to criminal markets
- OSINT tools let anyone map your network from public posts
- Social engineering: impersonation requires no hacking, just a browser
States have sophisticated tools to surveil, intercept, and extract data from your devices.Los Estados tienen herramientas sofisticadas para vigilar, interceptar y extraer datos de tus dispositivos.
None are invincible. But you need to know what exists to decide how to protect yourself.Ninguna es invencible. Pero necesitas saber qué existe para decidir cómo protegerte.
What the police can do with your phone:Lo que la policía puede hacer con tu teléfono:
• Extract ALL data from an unlocked phone in minutes
• Crack weak Android PINs with specialized equipment
• Locate your phone with meter-level precision via the mobile network
• Intercept calls, SMS, and browsing metadata via your carrier
• Install spyware that accesses camera, microphone, and messages
• Obtain your data from Google, Apple, Meta, and Telegram with a court order• Extraer TODOS los datos de un teléfono desbloqueado en minutos
• Descifrar PINs débiles de Android con equipo especializado
• Localizar tu teléfono con precisión de metros vía la red móvil
• Interceptar llamadas, SMS y metadatos de navegación vía tu operador
• Instalar spyware que accede a cámara, micrófono y mensajes
• Obtener tus datos de Google, Apple, Meta y Telegram con orden judicial
Physical device extractionExtracción física de dispositivos
The most common way activists lose data is not through sophisticated hacking. It is through physical access: a seized phone, a confiscated laptop, a border search. Understanding what is possible without your cooperation changes how you prepare.La forma más común en que los activistas pierden datos no es mediante hackeo sofisticado. Es a través del acceso físico: un teléfono incautado, un portátil confiscado, un registro fronterizo. Entender qué es posible sin tu cooperación cambia cómo te preparas.
Cellebrite UFED
Israeli system used by police worldwide.Sistema israelí usado por policías en todo el mundo.
Works on: Most Android phones and older iPhones. Newer versions (Cellebrite Premium) can brute-force weak Android PINs.
Limitations: With an updated iPhone 8+, full encryption active, and a 6-digit PIN, the Secure Enclave's wait times make brute-force decryption impractical (years or decades). A phone that is powered off is significantly harder to attack than one that is on and locked.Cellebrite fabrica dispositivos que se conectan a tu teléfono por USB y pueden extraer: mensajes (incluyendo los "eliminados"), fotos, videos, contactos, historial de ubicación, datos de apps, historial de navegación, y datos eliminados que aún no han sido sobrescritos en el disco.
Funciona en: La mayoría de teléfonos Android y iPhones antiguos. Versiones más nuevas (Cellebrite Premium) pueden descifrar PINs débiles de Android por fuerza bruta.
Limitaciones: Con un iPhone 8+ actualizado, encriptación completa activa, y un PIN de 6 dígitos, los tiempos de espera del Secure Enclave hacen que el descifrado por fuerza bruta sea impráctico (años o décadas). Un teléfono apagado es significativamente más difícil de atacar que uno encendido y bloqueado.
GrayKey / Magnet (formerly Grayshift)
Designed specifically for iPhones.Diseñado específicamente para iPhones.
Limitations: iPhones with Secure Enclave (iPhone 8+) impose escalating wait times between attempts: 1 minute after 5 attempts, 5 minutes, 15 minutes, 1 hour... With a 6-digit PIN (1 million combinations), total time can be months to years. As of iOS 17 (2023), Apple has blocked many of GrayKey's former attack vectors - verify protection for your specific iOS version.
Why this matters: 6-digit PIN minimum, keep updates current, and power off your phone if you think it may be seized.GrayKey es un dispositivo que se conecta al iPhone y puede intentar combinaciones de PIN en iPhones bloqueados. Vendido principalmente a agencias de EE.UU. pero cada vez más disponible para policías europeas.
Limitaciones: iPhones con Secure Enclave (iPhone 8+) imponen tiempos de espera cada vez mayores entre intentos: 1 minuto después de 5 intentos, 5 minutos, 15 minutos, 1 hora... Con un PIN de 6 dígitos (1 millón de combinaciones), el tiempo total puede ser de meses a años. Con actualizaciones recientes de iOS, Apple ha bloqueado muchos de los vectores de ataque anteriores de GrayKey.
Por qué importa: PIN de 6 dígitos mínimo, mantén las actualizaciones al día, y apaga tu teléfono si crees que puede ser confiscado.
Network surveillance & spywareVigilancia de red y spyware
Network-level surveillance does not require physical access to your device. It happens upstream, invisibly, through the infrastructure your data travels through. Spyware goes further still, turning your own device into the surveillance instrument.La vigilancia a nivel de red no requiere acceso físico a tu dispositivo. Ocurre río arriba, de forma invisible, a través de la infraestructura por la que viajan tus datos. El spyware va aún más lejos, convirtiendo tu propio dispositivo en el instrumento de vigilancia.
IMSI Catchers (?)
Fake antennas that impersonate cell towers.Antenas falsas que se hacen pasar por torres celulares.
Capabilities: Identify all phones present at a demonstration. Intercept unencrypted calls and SMS. Track a specific phone's movements. Some versions can inject fake SMS messages.
Documented in: Demonstrations in Germany, France, UK, US, and many more countries. They're relatively cheap (from €50,000 for basic models) and increasingly available to local police.
Protection: Airplane mode eliminates the cellular threat (IMSI catchers can't see you). However, airplane mode does NOT disable GPS · disable Location Services separately if you don't want apps logging your position. Signal over WiFi works without connecting to the mobile network.Tu teléfono se conecta automáticamente a la torre con mejor señal. Un IMSI catcher finge ser esa torre y captura el IMSI (identificador de SIM), IMEI (identificador del teléfono) y ubicación de todos los teléfonos en un radio de cientos de metros.
Capacidades: Identificar todos los teléfonos presentes en una manifestación. Interceptar llamadas y SMS sin cifrar. Rastrear los movimientos de un teléfono específico. Algunas versiones pueden inyectar mensajes SMS falsos.
Documentado en: Manifestaciones en Alemania, Francia, Reino Unido, EE.UU. y muchos más países. Son relativamente baratos (desde €50,000 para modelos básicos) y cada vez más disponibles para policías locales.
Protección: El modo avión elimina la amenaza celular (los IMSI catchers no pueden verte). Sin embargo, el modo avión NO desactiva el GPS · desactiva los Servicios de Ubicación por separado si no quieres que las apps registren tu posición. Signal por WiFi funciona sin conectar a la red móvil.
Pegasus (NSO Group)
Israeli spyware that infects phones without user interaction.Spyware israelí que infecta teléfonos sin interacción del usuario.
Capabilities once installed: Total access to messages (including Signal and WhatsApp), camera, microphone, GPS location, email, photos, contacts, browsing history, saved passwords, and any data on the phone.
Documented cases:
, Spain (Catalangate): At least 65 people linked to the Catalan independence movement were spied on with Pegasus, including the Parliament president and MEPs. Documented by Citizen Lab in 2022.
, Mexico: Journalists investigating corruption and families of the 43 Ayotzinapa students.
, Saudi Arabia: Used against journalist Jamal Khashoggi before his assassination.
, Morocco: Against journalists and activists from the Rif.
, Poland, Hungary, El Salvador, India and dozens more.
Protection: Immediate OS updates (Apple and Google patch vulnerabilities when discovered). GrapheneOS has a reduced attack surface. But against a state-sponsored zero-click attack with resources, there is no total protection: this is for very high-profile activists.Pegasus es spyware vendido por la compañía israelí NSO Group exclusivamente a gobiernos. Puede infectar iPhones y Android remotamente sin que el usuario haga nada (ataque "zero-click").
Capacidades una vez instalado: Acceso total a mensajes (incluyendo Signal y WhatsApp), cámara, micrófono, ubicación GPS, email, fotos, contactos, historial de navegación, contraseñas guardadas y cualquier dato en el teléfono.
Casos documentados:
, España (Catalangate): Al menos 65 personas vinculadas al movimiento independentista catalán fueron espiadas con Pegasus, incluyendo al presidente del Parlament y eurodiputados. Documentado por Citizen Lab en 2022.
, México: Periodistas investigando corrupción y familias de los 43 estudiantes de Ayotzinapa.
, Arabia Saudita: Usado contra el periodista Jamal Khashoggi antes de su asesinato.
, Marruecos: Contra periodistas y activistas del Rif.
, Polonia, Hungría, El Salvador, India y docenas más.
Protección: Actualizaciones inmediatas del sistema operativo (Apple y Google parchean vulnerabilidades cuando se descubren). GrapheneOS tiene una superficie de ataque reducida. Pero contra un ataque zero-click patrocinado por el Estado con recursos, no hay protección total: esto es para activistas de muy alto perfil.
Metadata retentionRetención de metadatos
Your carrier stores who you talk to, when, and from where.Tu operador almacena con quién hablas, cuándo y desde dónde.
Example: If you call a human rights lawyer, then three activists, and then you're near a demonstration, the metadata tells a story without needing to hear any conversation.
Accessible by: Court order in most EU countries. In some countries, intelligence agencies can access it without a court order for "national security."
Protection: Use Signal for everything (Signal calls and messages don't generate metadata at the carrier). Airplane mode during actions (remember: airplane mode disables cellular but NOT GPS · disable Location Services separately).En la UE, los operadores de telecom retienen datos de tráfico: a quién llamas, cuándo, durante cuánto tiempo, desde qué torre celular (ubicación) y a qué números envías mensajes. No el contenido de conversaciones, pero los metadatos revelan con alta precisión tus patrones de vida, relaciones sociales y movimientos.
Ejemplo: Si llamas a un abogado de derechos humanos, luego a tres activistas, y luego estás cerca de una manifestación, los metadatos cuentan una historia sin necesidad de escuchar ninguna conversación.
Accesible por: Orden judicial en la mayoría de países de la UE. En algunos países, las agencias de inteligencia pueden acceder sin orden judicial por "seguridad nacional".
Protección: Usa Signal para todo (las llamadas y mensajes de Signal no generan metadatos en el operador). Modo avión durante acciones (recuerda: modo avión desactiva celular pero NO el GPS · desactiva Servicios de Ubicación por separado).
Tower dumpsVolcados de torre
List of ALL phones connected to a cell tower at a specific time.Lista de TODOS los teléfonos conectados a una torre celular en un momento específico.
What they get: IMEI and IMSI of every phone. If your phone appears on the list, they know you were there. If you appear on lists from multiple demonstrations, you establish a pattern.
Cross-referencing: By comparing phones that appear in multiple tower dumps from different actions, police identify regular participants. Your IMEI is constant even if you change SIM cards.
Protection: Airplane mode 30 minutes before and 500 meters from the event. Your phone in airplane mode doesn't connect to the tower and doesn't appear in the tower dump.La policía solicita un "volcado de torre" del operador: todos los teléfonos conectados a una torre específica durante un período de tiempo. Si hubo una manifestación frente al ayuntamiento el sábado a las 5 PM, solicitan datos de la torre más cercana entre las 4 PM y las 7 PM.
Lo que obtienen: IMEI e IMSI de cada teléfono. Si tu teléfono aparece en la lista, saben que estuviste allí. Si apareces en listas de múltiples manifestaciones, estableces un patrón.
Referencias cruzadas: Al comparar teléfonos que aparecen en múltiples volcados de torre de diferentes acciones, la policía identifica participantes regulares. Tu IMEI es constante incluso si cambias tarjetas SIM.
Protección: Modo avión 30 minutos antes y 500 metros del evento. Tu teléfono en modo avión no se conecta a la torre y no aparece en el volcado de torre.
Court orders to tech companiesÓrdenes judiciales a empresas tech
Google, Apple, Meta, Telegram hand over data when the law requires it.Google, Apple, Meta, Telegram entregan datos cuando la ley lo requiere.
From Google: Your entire search history, locations (Google Maps timeline), Gmail emails, Google Photos, Android data, YouTube history, Google Drive documents.
From Apple: iCloud backups (which include iMessage messages, photos, app data), purchases, "Find My" location data.
From Meta (Facebook/Instagram/WhatsApp): Messages, communication metadata, contact lists, location data, shared photos. WhatsApp: while messages are E2E (end-to-end) encrypted in transit, chat backups stored on Google Drive or iCloud are not E2E encrypted by default: users must manually enable encrypted backups in WhatsApp Settings > Chats > Chat Backup > End-to-end Encrypted Backup. Most users have not enabled this.
From Telegram: Messages (unencrypted by default), contacts, metadata, access IPs. Since Pavel Durov's arrest in France (August 2024), Telegram has updated its privacy policy and now shares user data, including IP addresses and phone numbers, with authorities in response to valid legal requests in more jurisdictions.
Protection: Don't use services that store sensitive data. Signal doesn't retain messages on servers. CryptPad with passwords. ProtonMail encrypted. Minimize your big tech footprint.Con una orden judicial (y a veces con una simple citación administrativa), las fuerzas del orden pueden obtener:
De Google: Todo tu historial de búsqueda, ubicaciones (línea de tiempo de Google Maps), emails de Gmail, Google Photos, datos de Android, historial de YouTube, documentos de Google Drive.
De Apple: Backups de iCloud (que incluyen mensajes de iMessage, fotos, datos de apps), compras, datos de ubicación de "Buscar".
De Meta (Facebook/Instagram/WhatsApp): Mensajes, metadatos de comunicación, listas de contactos, datos de ubicación, fotos compartidas. WhatsApp: aunque los mensajes están cifrados E2E en tránsito, las copias de seguridad en Google Drive o iCloud no están cifradas E2E por defecto: los usuarios deben activar manualmente las copias cifradas en Ajustes > Chats > Copia de seguridad de chats > Copia de seguridad cifrada de extremo a extremo. La mayoría de usuarios no lo ha activado.
De Telegram: Mensajes (sin cifrar por defecto), contactos, metadatos, IPs de acceso. Desde el arresto de Pavel Durov en Francia (agosto 2024), Telegram ha actualizado su política de privacidad y ahora comparte datos de usuarios, incluyendo direcciones IP y números de teléfono, con autoridades en respuesta a solicitudes legales válidas en más jurisdicciones.
Protección: No uses servicios que almacenen datos sensibles. Signal no retiene mensajes en servidores. CryptPad con contraseñas. ProtonMail cifrado. Minimiza tu huella en big tech.
Social media surveillance (OSINT, Open Source Intelligence)Vigilancia en redes sociales (OSINT, Inteligencia de Fuentes Abiertas)
Automated tools that monitor public profiles.Herramientas automatizadas que monitorean perfiles públicos.
• Monitor public profiles in real time during protests
• Cross-reference photos posted on social media with facial recognition databases
• Map contact networks by analyzing who follows whom, who likes what posts
• Identify organizers and regular participants
• Geolocate photos by metadata or visual elements (buildings, signs)
Known tools: Palantir, Babel Street, Media Sonar, and many more, sold directly to law enforcement.
Protection: Completely separate personal and activist identities. Private profiles. Don't post real-time location. Blur faces. Don't tag.La policía usa herramientas OSINT (Open Source Intelligence) para:
• Monitorear perfiles públicos en tiempo real durante protestas
• Cruzar fotos publicadas en redes sociales con bases de datos de reconocimiento facial
• Mapear redes de contactos analizando quién sigue a quién, quién le da like a qué publicaciones
• Identificar organizadores y participantes regulares
• Geolocalizar fotos por metadatos o elementos visuales (edificios, señales)
Herramientas conocidas: Palantir, Babel Street, Media Sonar y muchas más, vendidas directamente a fuerzas del orden.
Protección: Separa completamente identidades personales y activistas. Perfiles privados. No publiques ubicación en tiempo real. Difumina caras. No etiquetes.
Every threat has a countermeasureCada amenaza tiene una contramedida
Nothing in this section should leave you feeling helpless. Every surveillance capability described above has a specific, tested response. The goal is not to achieve perfect security but to raise the cost of targeting you high enough that it stops being worth the effort.Nada en esta sección debería dejarte sintiéndote impotente. Cada capacidad de vigilancia descrita arriba tiene una respuesta específica y probada. El objetivo no es lograr una seguridad perfecta sino elevar el coste de atacarte lo suficiente como para que deje de merecer el esfuerzo.
What we want to prevent → What you'll learnLo que queremos prevenir → Lo que aprenderás
Data extraction from your phone → Strong PIN + full encryption + power off when seized
Being tracked at actions → Airplane mode 30 min before + 500m away
Messages being read → Signal with disappearing messages + never Telegram
Documents being accessed → CryptPad with passwords + disk encryption
Being identified via mobile network → No calls or SMS + Signal username
Your contact network being mapped → Don't save activist contacts in your phone
Your accounts being breached → 2FA with app + strong passwords + encrypted managerExtracción de datos de tu teléfono → PIN fuerte + cifrado completo + apagar al confiscar
Ser rastreado en acciones → Modo avión 30 min antes + 500m de distancia
Mensajes leídos → Signal con mensajes que desaparecen + nunca Telegram
Acceso a documentos → CryptPad con contraseñas + cifrado de disco
Identificación vía red móvil → Sin llamadas ni SMS + nombre de usuario Signal
Mapeo de tu red de contactos → No guardes contactos activistas en tu teléfono
Cuentas comprometidas → 2FA con app + contraseñas fuertes + gestor cifrado
How Your Habits Put Others at RiskCómo tus hábitos ponen a otros en riesgo
You can secure your own devices perfectly and still get your comrades arrested. Every contact you save, every group you join, every photo you take at an action. That is not just your data. It belongs to everyone in it. This section is about collective responsibility.Puedes asegurar tus propios dispositivos perfectamente y aun así hacer que detengan a tus compañerxs. Cada contacto que guardas, cada grupo al que te unes, cada foto que tomas en una acción. No son solo tus datos. Pertenecen a todxs los que aparecen en ellos. Esta sección trata de la responsabilidad colectiva.
It's about the people you talk toSe trata de la gente con la que hablas
The ones who talk to you. The ones who appear in your footage. It's about our mutual responsibility.Los que hablan contigo. Los que aparecen en tus grabaciones. Se trata de nuestra responsabilidad mutua.
Who this guide is forPara quién es esta guía
Activists in direct actions and protest camps, operating in jurisdictions where police do not typically use torture. Written for mid-2025 onwards. This guide covers the most common scenarios but cannot cover every situation: context always matters.Activistas en acciones directas y campamentos de protesta, en jurisdicciones donde la policía típicamente no tortura. Escrito para mediados de 2025 en adelante. Esta guía cubre los escenarios más comunes pero no puede cubrir todas las situaciones.
🎯Build Your Threat ModelConstruye tu modelo de amenazas
Not everyone faces the same threats. Select your adversaries, what you need to protect, and what's at stake. The tool builds your personalized threat model with a capability matrix and prioritized action plan.No todos enfrentan las mismas amenazas. Selecciona tus adversarios, lo que necesitas proteger y lo que está en juego. La herramienta construye tu modelo de amenazas personalizado con una matriz de capacidades y un plan de acción priorizado.
📋 Phase 01 · Key Takeaways📋 Fase 01 · Puntos clave
Device & Physical SecuritySeguridad de dispositivos y física
🔑The 6-Digit PINPIN de 6 dígitos
Your phone's lock screen is the first and most important line of defense. Everything else in this guide is useless if someone can unlock your device. Start here.La pantalla de bloqueo de tu teléfono es la primera y más importante línea de defensa. Todo lo demás en esta guía es inútil si alguien puede desbloquear tu dispositivo. Empieza aquí.
Unique and not guessableÚnico y no adivinable
Never enter it in front of police or their cameras.Nunca lo introduzcas delante de la policía o sus cámaras.
iPhone 8+
6-digit PIN is adequate. Exponential wait times after failed attempts + Secure Enclave hardware encryption.PIN de 6 dígitos es adecuado. Tiempos de espera exponenciales tras intentos fallidos + cifrado hardware Secure Enclave.
Android
A PIN helps but is ineffective against specialized equipment (Cellebrite, GrayKey). A long passphrase is ideal but impractical for frequent unlocking. GrapheneOS improves this significantly.Un PIN ayuda pero es ineficaz contra equipo especializado (Cellebrite, GrayKey). Una frase larga es ideal pero impráctica para desbloqueos frecuentes. GrapheneOS mejora esto significativamente.
⏱Quick Lock & Emergency Power-OffBloqueo rápido y apagado de emergencia
Auto-lock: 15-30 secondsBloqueo automático: 15-30 segundos
If your phone is seized, every second counts.Si te incautan el teléfono, cada segundo cuenta.
iPhone: Settings > Display & Brightness > Auto-Lock > 30 seconds
Android: Settings > Display > Screen timeout > 15 seconds
It's short enough for the phone to lock itself before reaching a police vehicle. A locked phone with full encryption is much harder to access than an unlocked one. Cómo configurar:
iPhone: Ajustes > Pantalla y brillo > Bloqueo automático > 30 segundos
Android: Ajustes > Pantalla > Tiempo de espera de pantalla > 15 segundos
Es tiempo suficiente para que el teléfono se bloquee solo antes de llegar a un vehículo policial. Un teléfono bloqueado con cifrado completo es mucho más difícil de acceder que uno desbloqueado.
Practice powering off quickly under stressPractica apagar rápido bajo estrés
Long press or swipe gesture.Pulsación larga o gesto de deslizar.
Android: Hold power button › Power off. On some models, holding 10 seconds forces a shutdown.
Practice this until it's muscle memory - you may need to do it while being restrained. iPhone: Mantén botón lateral + subir volumen > desliza para apagar. También: pulsa el botón lateral 5 veces para activar modo SOS y desactivar Face ID.
Android: Mantén el botón de encendido > Apagar. En algunos modelos, mantener 10 segundos fuerza un apagado.
Practica en situaciones estresantes para poder hacerlo si te están deteniendo pero aún tienes acceso a tu teléfono.
Record with phone lockedGrabar con el teléfono bloqueado
If seized, other functions aren't available.Si lo incautan, otras funciones no están disponibles.
Android: Double press power button (enable in Settings > System > Gestures > Quick camera access).
When recording authorities in medium-to-high risk situations, use this method. If your device is quickly seized, they don't have access to your data. iPhone: Desde la pantalla de bloqueo, desliza a la izquierda para abrir la cámara. La cámara funciona pero no puedes acceder a fotos anteriores ni otras apps.
Android: Pulsa dos veces el botón de encendido (actívalo en Ajustes > Sistema > Gestos > Acceso rápido a cámara).
Al grabar a autoridades en situaciones de riesgo medio-alto, usa este método. Si tu dispositivo es incautado rápidamente, no tienen acceso a tus datos.
🔄Update EverythingActualiza todo
💽Full Encryption, Not PartialCifrado completo, no parcial
Without full encryptionSin cifrado completo
Anyone with physical access extracts everything. Intermediate skill. Low cost. Also gains permanent control of the device.Cualquiera con acceso físico extrae todo. Habilidad intermedia. Bajo coste. También obtiene control permanente del dispositivo.
Partial encryption = false securityCifrado parcial = falsa seguridad
Data gets copied to unencrypted areas during use.Los datos se copian a áreas no cifradas durante el uso.
How to verify & enable encryption (mobile)Cómo verificar y activar el cifrado (móvil)
Most modern phones encrypt storage by default, but default settings are not always active and the details matter. A phone that appears encrypted can still be readable if the PIN is weak or biometrics are enabled at the wrong moment. Walk through this now, before you need it.La mayoría de los teléfonos modernos cifran el almacenamiento por defecto, pero la configuración predeterminada no siempre está activa y los detalles importan. Un teléfono que parece cifrado puede seguir siendo legible si el PIN es débil o si la biometría está activada en el momento equivocado. Revisa esto ahora, antes de necesitarlo.
iPhone
If you have a PIN, it's already encrypted automatically.Si tienes un PIN, ya está cifrado automáticamente.
Settings > Face ID & Passcode (or Touch ID & Passcode) > scroll to the bottom.
It should say: "Data protection is enabled".
If this message doesn't appear, something is wrong and you should consult your tech team.
iPhone encryption is based on the Secure Enclave, a dedicated chip that stores the key and limits unlock attempts with escalating wait times (1 min, 5 min, 15 min, 1 hour after failed attempts).Verificar:
Ajustes > Face ID y código (o Touch ID y código) > desplázate hasta abajo.
Debería decir: "La protección de datos está activada".
Si este mensaje no aparece, algo está mal y deberías consultar a tu equipo técnico.
El cifrado de iPhone se basa en el Secure Enclave, un chip dedicado que almacena la clave y limita los intentos de desbloqueo con tiempos de espera escalados (1 min, 5 min, 15 min, 1 hora tras intentos fallidos).
Android
Encryption is only as strong as your PIN. Non-Pixel Android is forensically weak.El cifrado es tan fuerte como tu PIN. Android no-Pixel es forense débil.
Settings > Security > Encryption & credentials
It should say "Encrypted".
⚠️ Critical nuance: Standard Android encryption (file-based encryption since Android 10+) is only as strong as your PIN. There is no hardware-enforced brute-force throttling on most Android devices. Cellebrite UFED can attempt thousands of PINs per second on stock Samsung, Xiaomi, and other brands, cracking a 6-digit PIN in hours.
Pixel phones with Titan M2: Google Pixel 6+ includes the Titan M2 security chip, which enforces hardware-backed wait times between PIN attempts (similar to Apple's Secure Enclave). After failed attempts, wait times escalate exponentially: 30s, then 1min, 5min, 15min, 1hr. This makes a 6-digit PIN forensically viable · it would take months to years to brute-force, even with Cellebrite.
Bottom line: On non-Pixel Android, use a long passphrase (8+ random words) or switch to GrapheneOS on a Pixel. On stock Samsung/Xiaomi/etc., a 6-digit PIN provides only hours of protection against professional tools.
📍Your Phone Is a TrackerTu teléfono es un rastreador
IMEI
identifies your phoneidentifica tu teléfono
IMSI
identifies your SIMidentifica tu SIM
LOCATIONUBICACIÓN
10-50m in cities10-50m en ciudades
✅ Solution: Airplane mode✅ Solución: Modo avión
30 minutes before and 500 meters from the event.30 minutos antes y 500 metros del evento.
iPhone: swipe from top-right corner > airplane icon
Android: swipe down from top > Airplane mode
⚠️ IMPORTANT: Airplane mode does NOT disable GPS. Your phone's GPS receiver continues to work in airplane mode. Apps with location permissions that have already cached data can still log your position. To fully prevent location tracking: disable Location Services / GPS separately (Settings > Privacy > Location Services OFF on iPhone; Settings > Location > OFF on Android), or power off the phone entirely.
⚠️ GPS PERSISTENCE WARNING: Background apps (maps, weather, fitness trackers, social media) can log GPS data locally while offline and silently transmit it to servers the moment you reconnect. This means even with airplane mode, your location history during an action may be uploaded the instant you turn cellular back on. Google Timeline, Apple Significant Locations, and fitness apps like Strava are the worst offenders.
📋 Post-Action Location Scrub Checklist:
✅ Before reconnecting: go to Settings > Privacy > Location Services > System Services > Significant Locations > Clear History (iPhone) or Google Maps > Timeline > Delete this day (Android)
✅ Delete all location caches: Google Maps Timeline, Apple Maps history, fitness apps (Strava, Health)
✅ Revoke location permissions from all non-essential apps before reconnecting
✅ On Android: Settings > Location > App permissions · set everything to "Only while using" or "Deny"
✅ Consider staying on airplane mode until you've completed the scrub
✅ Best option: power off entirely 30 min before arrival, power on again only after leaving the area and scrubbing
WiFi can stay on with airplane mode if there's a trusted network. This allows Signal over WiFi without revealing IMEI or IMSI to the mobile network.
Always avoid: Conventional calls and SMS. The carrier keeps metadata logs: who calls whom, when, from which tower. Use Signal for all communications.
🗺️ Safe offline navigation (Google Maps alternative)🗺️ Navegación offline segura (alternativa a Google Maps)
Google Maps tracks your location even when offline. Use these privacy-respecting alternatives instead.Google Maps rastrea tu ubicación incluso offline. Usa estas alternativas que respetan la privacidad.
Safe alternatives:
, OsmAnd (recommended). Available on F-Droid (Android) and App Store (iOS). Uses OpenStreetMap data. Download maps for your region in advance. Navigation works fully offline with no data sent anywhere. Free and open source. No account required. No telemetry.
Install → download regional map → navigate in airplane mode
, Organic Maps. Also based on OpenStreetMap. Lighter and faster than OsmAnd. Fully offline navigation. No ads, no tracking, no data collection. Available on F-Droid, Google Play, and App Store. Open source.
Install → download map → use in airplane mode
Pre-action setup:
1. Install OsmAnd or Organic Maps days before the action (not the day of)
2. Download the offline map for your area over WiFi at home
3. Test the route before the action to confirm the maps are complete
4. On action day: airplane mode ON + Location Services OFF, navigate using only the pre-downloaded map
5. Neither app sends any data to any server. Your route stays on your device only
⚠️ Never use Google Maps or Apple Maps for navigation to or from an action. Both log your precise route, timestamps, and speed, and this data is subpoena-accessible.
🤖GrapheneOS (Hardened Android)GrapheneOS (Android reforzado)
Android without Google, hardened for security. Only works on Google Pixel.Android sin Google, reforzado para seguridad. Solo funciona en Google Pixel.
How to install GrapheneOSCómo instalar GrapheneOS
🍎Apple Lockdown ModeModo aislamiento de Apple
For high-risk iPhone users who may be targeted by state-sponsored spyware. iOS 16+ only. Dramatically narrows the attack surface Pegasus and similar tools exploit.Para usuarios de iPhone de alto riesgo que pueden ser objetivo de spyware estatal. Solo iOS 16+. Reduce drásticamente la superficie de ataque que explotan Pegasus y herramientas similares.
Who should enable it?¿Quién debería activarlo?
📱 Burner Phone Guide📱 Guía de teléfonos desechables
A burner phone is only anonymous if you set it up correctly. Most people leave traces that link it directly back to them.Un teléfono desechable solo es anónimo si lo configuras correctamente. La mayoría deja rastros que lo vinculan directamente con ellos.
📱 Burner Phone Lifecycle: From Purchase to Disposal📱 Ciclo de vida del desechable: de la compra a la eliminación
A burner phone is only as anonymous as its weakest link. Follow this complete lifecycle to maintain operational security from acquisition through destruction.Un teléfono desechable es tan anónimo como su eslabón más débil. Sigue este ciclo completo para mantener la seguridad operativa desde la adquisición hasta la destrucción.
- Purchase phone and SIM from different stores, on different days
- Pay exclusively with cash · no cards, no mobile payments
- Wear nondescript clothing, no loyalty cards, leave personal phone at home
- Travel to purchase location via public transit or bicycle (no license plates)
- Choose common models: Samsung A-series, Nokia, Motorola · nothing distinctive
- Buy prepaid SIM that doesn't require ID (check local laws · EU requires ID in most countries since 2022)
- Consider purchasing abroad where ID requirements are laxer
- Activate at least 2km from home, work, or any location tied to you
- Use a busy commercial area with public WiFi you've never used before
- NEVER connect to your home WiFi · this immediately burns the burner
- Skip all account setup (Google, Samsung, etc.) · decline everything
- Disable location services, WiFi scanning, Bluetooth scanning
- Install only essential apps via APK sideload (Signal from signal.org/android/apk)
- Set a strong PIN (not biometrics · plausible deniability)
- Register Signal with the burner number, use a pseudonymous username
- NEVER carry burner and personal phone simultaneously (co-location analysis)
- Leave personal phone at home (or at a friend's) when using burner
- Power off burner when not in active use · remove battery if possible
- Top up credit with cash only at stores you don't frequent
- Store burner and SIM separately in secure location (not at home)
- Never contact any number from your personal phone's contacts
- Use only for intended purpose · no "just checking email"
- Delete all messages and call logs after each use session
- Keep notes about burner (number, PIN) in encrypted password manager only
- Factory reset the phone multiple times (this doesn't guarantee data destruction but helps)
- Remove and destroy the SIM card: cut into pieces, burn, dispose in separate locations
- Physically destroy the phone: hammer the circuit board, particularly memory chips
- Dispose of components in multiple locations far from your area
- Water destruction: submerge components in salt water for 24+ hours before disposal
- Never dispose in your home trash or recycling
- Consider incineration for highest security (requires proper facilities)
- Dispose at least 48 hours before or after any significant event
The #1 mistake: co-location analysisEl error nº1: análisis de co-localización
Carrying your real phone and burner phone together, even once, can permanently link them.Llevar tu teléfono real y el desechable juntos, aunque sea una vez, puede vincularlos permanentemente.
• Just 3-5 co-located events (same tower, same 15-minute window) is enough for high confidence
• Police don't even need a warrant for this analysis in most jurisdictions · carrier metadata is often available with a simple legal order
• The analysis is retroactive · carriers store location metadata for 12-24 months, so the damage is done the moment you make the mistake
• It's also automated: law enforcement tools like PenLink and i2 Analyst's Notebook can run co-location queries across millions of records in seconds
The rule: NEVER carry both phones simultaneously. Leave your personal phone at home (or better: at a friend's house) when using the burner. When the burner is stored, remove the battery and SIM. Never power both on in the same location.
💻Full Disk EncryptionCifrado completo del disco
A strong password on your laptop means nothing if the drive isn't encrypted. Someone with physical access and a USB drive can bypass your login screen in minutes and read every file. Full disk encryption closes that door entirely.Una contraseña fuerte en tu portátil no significa nada si el disco no está cifrado. Alguien con acceso físico y una memoria USB puede saltarse tu pantalla de inicio de sesión en minutos y leer todos los archivos. El cifrado completo del disco cierra esa puerta por completo.
Windows, BitLocker
Only available on Windows Pro, Education, and Enterprise.Solo disponible en Windows Pro, Education y Enterprise.
Control Panel > System and Security > BitLocker Drive Encryption
Or search "BitLocker" in the Start menu.
Enable: Click "Turn on BitLocker" next to the C: drive. Choose to save the recovery key to a file (not to Microsoft account). Store that key in your password manager.
Windows Home: Doesn't include BitLocker. Alternative: VeraCrypt (veracrypt.fr). More technical: download, install, choose "Encrypt the system partition/drive," follow the wizard. Takes several hours.
How to check your version: Windows key + I > System > About > "Windows edition."Comprobar si está activo:
Panel de control > Sistema y seguridad > Cifrado de unidad BitLocker
O busca "BitLocker" en el menú Inicio.
Activar: Haz clic en "Activar BitLocker" junto a la unidad C:. Elige guardar la clave de recuperación en un archivo (no en la cuenta de Microsoft). Guarda esa clave en tu gestor de contraseñas.
Windows Home: No incluye BitLocker. Alternativa: VeraCrypt (veracrypt.fr). Más técnico: descarga, instala, elige "Cifrar la partición/unidad del sistema", sigue el asistente. Tarda varias horas.
Cómo comprobar tu versión: Tecla Windows + I > Sistema > Acerca de > "Edición de Windows".
macOS, FileVault
Simple to enable. Encrypts the entire disk.Simple de activar. Cifra el disco completo.
System Preferences > Security & Privacy > FileVault tab > lock icon at bottom left > Turn On FileVault.
On macOS Ventura or later: System Settings > Privacy & Security > FileVault > Turn On.
Important: When enabling, it will give you a recovery key. Store it in your password manager (KeePass or ProtonPass), NOT in iCloud. The first time takes a few hours to encrypt the disk but you can keep using the computer.Activar:
Preferencias del Sistema > Seguridad y privacidad > pestaña FileVault > icono de candado abajo a la izquierda > Activar FileVault.
En macOS Ventura o posterior: Ajustes del Sistema > Privacidad y seguridad > FileVault > Activar.
Importante: Al activarlo, te dará una clave de recuperación. Guárdala en tu gestor de contraseñas (KeePass o ProtonPass), NO en iCloud. La primera vez tarda unas horas en cifrar el disco pero puedes seguir usando el ordenador.
Linux, LUKS
Configured during installation.Se configura durante la instalación.
In Ubuntu: During installation, check "Encrypt the new Ubuntu installation for security." It will ask for a password at boot.
Check if you already have LUKS: Open terminal and run
sudo lsblk -f. If you see "crypto_LUKS" on any partition, you already have encryption.Si ya instalaste sin cifrado: Desafortunadamente, la forma más fiable es hacer una copia de seguridad de tus datos y reinstalar, eligiendo cifrado completo del disco durante la instalación. La mayoría de distribuciones (Ubuntu, Fedora, Debian) ofrecen esto como opción en el instalador.En Ubuntu: Durante la instalación, marca "Cifrar la nueva instalación de Ubuntu por seguridad". Te pedirá una contraseña al arrancar.
Comprobar si ya tienes LUKS: Abre terminal y ejecuta
sudo lsblk -f. Si ves "crypto_LUKS" en alguna partición, ya tienes cifrado.
💾Tails OS (Amnesic Operating System)Tails OS (sistema operativo amnésico)
Operating system on a USB. All traffic through Tor. Leaves no trace on the computer.Sistema operativo en un USB. Todo el tráfico a través de Tor. No deja rastro en el ordenador.
What it doesQué hace
Boots from USB, everything goes through Tor, doesn't touch the computer's hard drive.Arranca desde USB, todo va a través de Tor, no toca el disco duro del ordenador.
Includes pre-installed tools: Tor Browser, LibreOffice, Thunderbird email client, KeePassXC for passwords.Cuando arrancas Tails, el sistema operativo se carga completamente en RAM desde el USB. Nada se escribe en el disco duro del ordenador. Todo el tráfico de red pasa por la red Tor automáticamente. Cuando apagas, la RAM se borra. Es como si nunca hubieras usado ese ordenador.
Incluye herramientas preinstaladas: Tor Browser, LibreOffice, cliente de correo Thunderbird, KeePassXC para contraseñas.
What it's forPara qué sirve
Sensitive research, confidential documents, high-risk communications.Investigación sensible, documentos confidenciales, comunicaciones de alto riesgo.
• Research sensitive information without leaving traces in your history
• Draft documents you don't want on your hard drive
• Access CryptPad or email from a clean environment
• Communicate in situations requiring maximum anonymity
• Access blocked or censored resources in your country
Not for daily use. It's for specific high-risk tasks or if your laptop might be seized.Casos de uso concretos:
• Investigar información sensible sin dejar rastros en tu historial
• Redactar documentos que no quieres en tu disco duro
• Acceder a CryptPad o email desde un entorno limpio
• Comunicarte en situaciones que requieren máximo anonimato
• Acceder a recursos bloqueados o censurados en tu país
No es para uso diario. Es para tareas específicas de alto riesgo o si tu portátil puede ser incautado.
Encrypted persistencePersistencia cifrada
Encrypted volume on the same USB to save documents between sessions.Volumen cifrado en el mismo USB para guardar documentos entre sesiones.
Set up: When booting Tails, go to Applications > Tails > Configure persistent volume. Choose what data persists. The volume is encrypted with your password.
If you need to destroy everything, simply physically destroy the USB.Tails permite crear un espacio de "almacenamiento persistente" cifrado en el USB. Esto sobrevive entre sesiones: puedes guardar documentos, claves GPG, marcadores de Tor Browser y configuración de red.
Configuración: Al arrancar Tails, ve a Aplicaciones > Tails > Configurar volumen persistente. Elige qué datos persisten. El volumen está cifrado con tu contraseña.
Si necesitas destruir todo, simplemente destruye físicamente el USB.
How to install TailsCómo instalar Tails
🔒Physical Device ProtectionProtección física de dispositivos
Encryption protects data at rest, but physical access to your devices opens other attack vectors. Anti-tamper measures and secure disposal complete your hardware security.El cifrado protege datos en reposo, pero el acceso físico a tus dispositivos abre otros vectores de ataque. Las medidas anti-manipulación y la eliminación segura completan tu seguridad de hardware.
Evil Maid attacks & anti-tamperAtaques Evil Maid y anti-manipulación
Someone with brief physical access to your device can compromise it.Alguien con breve acceso físico a tu dispositivo puede comprometerlo.
• Hardware keyloggers: Tiny devices inserted between keyboard and USB port that record every keystroke
• Boot-level malware: Modifying the boot partition to capture your disk encryption password
• Firmware attacks: Flashing modified firmware to a USB controller or network card
Countermeasures:
• Glitter nail polish: Apply unique glitter nail polish over laptop screws. Photograph it. The random pattern is impossible to replicate, any tampering is visible. (Technique recommended by EFF)
• Tamper-evident tape: Special stickers that show "VOID" if removed, placed over ports and seams
• Secure Boot: Enable Secure Boot in BIOS to prevent unauthorized boot modifications
• USB port blockers: Physical blockers that prevent unauthorized USB devices from being inserted
• Never leave devices unattended at protests, meetings, or social centers
• Power off devices when leaving them (not just sleep/hibernate)Un ataque "Evil Maid" (doncella malvada) ocurre cuando alguien obtiene acceso físico breve a tu dispositivo desatendido (habitación de hotel, oficina compartida, centro social) e instala un implante de hardware o software:
• Keyloggers de hardware: Dispositivos diminutos insertados entre el teclado y el puerto USB que registran cada pulsación
• Malware a nivel de arranque: Modificar la partición de arranque para capturar tu contraseña de cifrado de disco
• Ataques de firmware: Flashear firmware modificado a un controlador USB o tarjeta de red
Contramedidas:
• Esmalte de uñas con purpurina: Aplica esmalte de uñas con purpurina único sobre los tornillos del portátil. Fotografíalo. El patrón aleatorio es imposible de replicar, cualquier manipulación es visible. (Técnica recomendada por la EFF)
• Cinta anti-manipulación: Pegatinas especiales que muestran "VOID" si se retiran, colocadas sobre puertos y juntas
• Secure Boot: Activa Secure Boot en BIOS para prevenir modificaciones de arranque no autorizadas
• Bloqueadores de puertos USB: Bloqueadores físicos que impiden insertar dispositivos USB no autorizados
• Nunca dejes dispositivos desatendidos en protestas, reuniones o centros sociales
• Apaga los dispositivos cuando los dejes (no solo suspender/hibernar)
🗑️ Secure device disposal🗑️ Eliminación segura de dispositivos
Factory reset ≠ secure erase. When you sell, donate, or discard a device, data can often be recovered with freely available tools.Restablecimiento de fábrica ≠ borrado seguro. Cuando vendes, donas o descartas un dispositivo, los datos a menudo pueden recuperarse con herramientas disponibles gratuitamente.
📱 Phones📱 Teléfonos
How to properly wipe a phone before disposal.Cómo borrar correctamente un teléfono antes de desecharlo.
• Sign out of iCloud (Settings → Your Name → Sign Out)
• Go to Settings → General → Transfer or Reset → Erase All Content and Settings
• iPhone uses hardware encryption, so "Erase" actually destroys the encryption key, making data unrecoverable. This is secure.
Android (with encryption enabled):
• Verify encryption is on: Settings → Security → Encryption
• Remove Google account: Settings → Accounts → Google → Remove
• Factory reset: Settings → System → Reset → Erase all data
• If encrypted, factory reset destroys the key. If NOT encrypted, data may be recoverable.
Extra paranoid: After factory reset, fill the phone's storage with dummy data (record a long video until storage is full), then factory reset again. This overwrites the flash memory cells.
Physical destruction: For truly sensitive devices: remove the SIM, drill through the circuit board, and dispose of parts in separate locations. SIM cards should be cut with scissors through the chip.iPhone:
• Cierra sesión en iCloud (Ajustes → Tu nombre → Cerrar sesión)
• Ve a Ajustes → General → Transferir o restablecer → Borrar contenido y ajustes
• iPhone usa cifrado de hardware, así que "Borrar" realmente destruye la clave de cifrado, haciendo los datos irrecuperables. Esto es seguro.
Android (con cifrado activado):
• Verifica que el cifrado esté activado: Ajustes → Seguridad → Cifrado
• Elimina la cuenta de Google: Ajustes → Cuentas → Google → Eliminar
• Restablecimiento de fábrica: Ajustes → Sistema → Restablecer → Borrar todos los datos
• Si está cifrado, el restablecimiento de fábrica destruye la clave. Si NO está cifrado, los datos pueden ser recuperables.
Extra paranoico: Después del restablecimiento de fábrica, llena el almacenamiento del teléfono con datos basura (graba un video largo hasta que el almacenamiento esté lleno), luego restablece de fábrica otra vez. Esto sobrescribe las celdas de memoria flash.
Destrucción física: Para dispositivos verdaderamente sensibles: retira la SIM, taladra la placa de circuito, y desecha las partes en ubicaciones separadas. Las tarjetas SIM deben cortarse con tijeras a través del chip.
💻 Computers💻 Ordenadores
Factory reset is not enough for HDDs. SSDs are more complex.El restablecimiento de fábrica no es suficiente para HDDs. Los SSDs son más complejos.
• Use DBAN (Darik's Boot and Nuke): Boot from USB, select "DoD Short" wipe method (3 passes). Takes several hours but is thorough.
• Linux/macOS:
shred -vzu -n 3 filename securely overwrites a single file (3 passes + zero-fill + delete). For entire drives: shred -v /dev/sdX: do NOT use on SSDs (see below).• Windows: Eraser (eraser.heidi.ie) or SDelete (
sdelete -p 3 -z C: from Sysinternals) for DoD-grade HDD wipes.• Alternative: Encrypt the entire drive with VeraCrypt using a random password you immediately forget, then format.
• Physical destruction: Open the drive, scratch the platters with a screwdriver, drill holes through them.
SSDs (solid state drives):
• SSDs have wear leveling, meaning some data blocks are preserved even after "overwriting." Standard wipe tools may miss data.
• Use the manufacturer's Secure Erase tool (Samsung Magician, Crucial Storage Executive, etc.)
• Or: Enable full disk encryption (BitLocker/FileVault/LUKS), use the drive normally, then destroy the encryption header/key
• For maximum security: physical destruction. SSDs are small, a hammer and drill will do.
USB drives: Same as SSDs, encrypt first, then format, or physically destroy.HDDs (discos duros mecánicos):
• Usa DBAN (Darik's Boot and Nuke): Arranca desde USB, selecciona el método de borrado "DoD Short" (3 pasadas). Tarda varias horas pero es exhaustivo.
• Linux/macOS:
shred -vzu -n 3 archivo sobrescribe de forma segura un archivo individual (3 pasadas + ceros + eliminación). Para discos completos: shred -v /dev/sdX: NO usar en SSDs (ver abajo).• Windows: Eraser (eraser.heidi.ie) o SDelete (
sdelete -p 3 -z C: de Sysinternals) para borrados HDD al nivel DoD.• Alternativa: Cifra todo el disco con VeraCrypt usando una contraseña aleatoria que olvidas inmediatamente, luego formatea.
• Destrucción física: Abre el disco, rasca los platos con un destornillador, taladra agujeros a través de ellos.
SSDs (discos de estado sólido):
• Los SSDs tienen nivelación de desgaste, lo que significa que algunos bloques de datos se preservan incluso después de "sobrescribir". Las herramientas de borrado estándar pueden no borrar datos.
• Usa la herramienta Secure Erase del fabricante (Samsung Magician, Crucial Storage Executive, etc.)
• O: Activa cifrado completo del disco (BitLocker/FileVault/LUKS), usa el disco normalmente, luego destruye la cabecera/clave de cifrado
• Para máxima seguridad: destrucción física. Los SSDs son pequeños, un martillo y un taladro servirán.
Unidades USB: Igual que los SSDs, cifra primero, luego formatea, o destruye físicamente.
📡Faraday Bags & RF ShieldingBolsas de Faraday y blindaje RF
A Faraday bag blocks all radio signals (cellular, WiFi, Bluetooth, GPS, NFC) from reaching your device. Unlike airplane mode, which is software-controlled and can leak, a Faraday bag is a physical barrier that cannot be bypassed remotely.Una bolsa de Faraday bloquea todas las señales de radio (celular, WiFi, Bluetooth, GPS, NFC) para que no lleguen a tu dispositivo. A diferencia del modo avión, que está controlado por software y puede filtrar, una bolsa de Faraday es una barrera física que no puede ser eludida remotamente.
Why airplane mode is NOT enoughPor qué el modo avión NO es suficiente
Software controls can be overridden. Physical shielding cannot.Los controles de software pueden ser anulados. El blindaje físico no.
• Does NOT disable the GPS receiver (apps can still log position)
• Can be remotely toggled off by sophisticated malware (Pegasus-class)
• Some devices still emit brief signals during "airplane mode" transitions
• Baseband processor (radio chip) operates independently from the main OS and may not fully comply
A Faraday bag solves all of these by physically blocking electromagnetic signals. No software exploit can overcome physics.Problemas del modo avión:
• NO desactiva el receptor GPS (las apps aún pueden registrar tu posición)
• Puede ser desactivado remotamente por malware sofisticado (clase Pegasus)
• Algunos dispositivos aún emiten señales breves durante las transiciones del "modo avión"
• El procesador baseband (chip de radio) opera independientemente del OS principal y puede no cumplir completamente
Una bolsa de Faraday resuelve todo esto bloqueando físicamente las señales electromagnéticas. Ningún exploit de software puede superar la física.
Commercial Faraday bagsBolsas de Faraday comerciales
Purpose-built bags rated for specific frequency ranges.Bolsas diseñadas específicamente para rangos de frecuencia específicos.
• Silent Pocket: Lab-tested, blocks all signals. ~$40-60 for phone-sized bags
• Mission Darkness: Military-grade shielding. Used by forensics teams (which tells you they work)
• GoDark Bags: Budget-friendly option with decent shielding
How to verify your bag works:
1. Put your phone inside the bag, seal it properly
2. Call your phone from another device · it should go straight to voicemail
3. Try sending a text · it should fail
4. Check WiFi/Bluetooth · your phone should disappear from nearby devices
5. Test periodically · bags degrade with wear and tear, especially at seamsProductos recomendados:
• Silent Pocket: Probada en laboratorio, bloquea todas las señales. ~$40-60 para bolsas tamaño teléfono
• Mission Darkness: Blindaje de grado militar. Usado por equipos forenses (lo que te dice que funcionan)
• GoDark Bags: Opción económica con blindaje decente
Cómo verificar que tu bolsa funciona:
1. Pon tu teléfono dentro de la bolsa, séllala correctamente
2. Llama a tu teléfono desde otro dispositivo · debería ir directamente al buzón de voz
3. Intenta enviar un mensaje de texto · debería fallar
4. Comprueba WiFi/Bluetooth · tu teléfono debería desaparecer de los dispositivos cercanos
5. Prueba periódicamente · las bolsas se degradan con el uso, especialmente en las costuras
🆘 Emergency DIY: 3-layer aluminum foil method🆘 DIY de emergencia: método de 3 capas de papel de aluminio
When you don't have a Faraday bag but need RF shielding NOW.Cuando no tienes una bolsa de Faraday pero necesitas blindaje RF AHORA.
Materials: Standard kitchen aluminum foil (heavy-duty preferred)
Method:
1. Tear off a sheet of aluminum foil approximately 3× the size of your phone
2. Place your phone in the center
3. Wrap tightly, folding edges over · ensure NO gaps or holes
4. Repeat with a second layer, offsetting the seams from the first layer
5. Repeat with a third layer, again offsetting seams
6. Press firmly to eliminate air pockets and ensure good contact between layers
Why 3 layers: A single layer of kitchen foil (~15μm thick) attenuates signals by ~20-30dB. Three layers provide ~60-85dB of attenuation, which is sufficient to block cellular and GPS signals. Each layer should be oriented differently to cover seam gaps from the previous layer.
Limitations:
• Not reusable (foil tears, loses seal quality)
• Hard to achieve consistent seal around edges
• Cannot verify effectiveness without a second phone to test with
• Not effective if there are ANY holes or gaps · signals find the smallest opening
Test immediately: Call the wrapped phone. If it rings, rewrap with better seam coverage.Este es un método de emergencia, no una solución permanente. Las bolsas comerciales son más fiables y duraderas.
Materiales: Papel de aluminio de cocina estándar (preferiblemente grueso)
Método:
1. Arranca una hoja de papel de aluminio aproximadamente 3× el tamaño de tu teléfono
2. Coloca tu teléfono en el centro
3. Envuelve firmemente, doblando los bordes · asegura que NO haya huecos ni agujeros
4. Repite con una segunda capa, desplazando las costuras de la primera capa
5. Repite con una tercera capa, de nuevo desplazando costuras
6. Presiona firmemente para eliminar bolsas de aire y asegurar buen contacto entre capas
Por qué 3 capas: Una sola capa de papel de aluminio de cocina (~15μm de grosor) atenúa las señales en ~20-30dB. Tres capas proporcionan ~60-85dB de atenuación, suficiente para bloquear señales celulares y GPS. Cada capa debe orientarse diferente para cubrir los huecos de costura de la capa anterior.
Limitaciones:
• No reutilizable (el papel se rompe, pierde calidad de sellado)
• Difícil conseguir un sellado consistente alrededor de los bordes
• No se puede verificar la efectividad sin un segundo teléfono para probar
• No es efectivo si hay CUALQUIER agujero o hueco · las señales encuentran la apertura más pequeña
Prueba inmediatamente: Llama al teléfono envuelto. Si suena, vuelve a envolver con mejor cobertura de costuras.
🖨️Secure Printing & Machine Identification CodesImpresión segura y códigos de identificación de máquina
Every color laser printer secretly encodes its serial number into every page it prints, invisible to the naked eye, visible to forensic analysis. If you're printing leaflets, zines, or any document linked to an action, you need to know this.Todas las impresoras láser de color codifican en secreto su número de serie en cada página que imprimen, invisible al ojo humano, visible para el análisis forense. Si estás imprimiendo folletos, fanzines o cualquier documento vinculado a una acción, necesitas saber esto.
If you make physical materials (flyers, fanzines, posters, stickers), your printer is leaving invisible fingerprints on every page. Understanding this risk is critical for anyone producing anonymous printed materials.Si produces materiales físicos (folletos, fanzines, carteles, pegatinas), tu impresora está dejando huellas invisibles en cada página. Entender este riesgo es crítico para cualquiera que produzca materiales impresos anónimos.
⚠️ What are Machine Identification Codes (Yellow Dots)?⚠️ ¿Qué son los Códigos de Identificación de Máquina (Puntos Amarillos)?
Most color laser printers secretly encode invisible tracking information on every page you print. This is not a conspiracy theory. It is a documented, industry-wide practice.La mayoría de impresoras láser a color codifican secretamente información de rastreo invisible en cada página que imprimes. Esto no es una teoría conspirativa. Es una práctica documentada en toda la industria.
How yellow dots work (MIC, Machine Identification Code)Cómo funcionan los puntos amarillos (MIC, Código de Identificación de Máquina)
Tiny yellow dots invisible to the naked eye encode your printer's serial number and the exact time of printing on every page.Diminutos puntos amarillos invisibles a simple vista codifican el número de serie de tu impresora y la hora exacta de impresión en cada página.
• Printer serial number: uniquely identifies the specific printer that produced the page
• Date and time of printing: exact timestamp down to the minute
This system was developed in cooperation with intelligence agencies (primarily the US Secret Service) to trace counterfeit currency. However, it is applied to ALL printed documents, not just currency, including your flyers, fanzines, open letters, and leaflets.
How the dots are structured: The pattern is typically a 15×8 grid of yellow dots repeated across the page. Each column encodes a different piece of data (serial number digits, date, time, etc.) using binary encoding. The dots are approximately 0.1mm in diameter and spaced about 1mm apart, invisible under normal lighting.
The Reality Winner case (2017): NSA contractor Reality Winner printed and leaked classified documents to The Intercept. The FBI identified her partly through the MIC dots on the printed pages, which encoded the exact printer serial number and timestamp. Cross-referencing with printer access logs at her workplace pinpointed her as the source. She was sentenced to more than five years in prison.
How to see the dots yourself:
1. Print a page with large areas of white space from a color laser printer
2. Examine the white areas under a blue LED light or UV light (a cheap UV flashlight works)
3. You'll see a faint, repeating pattern of yellow dots
4. Alternatively, scan the page at high resolution (1200+ DPI, Dots Per Inch) and boost the blue channel in image software. The yellow dots will become visible
Which printers are affected: The EFF maintains a research database. As a general rule: virtually all color laser printers from major brands embed these dots. The system is so widespread that it's safer to assume your color printer tracks you unless you have specifically verified otherwise.Desde mediados de los 2000, la mayoría de los principales fabricantes de impresoras láser a color (incluyendo HP, Xerox, Canon, Brother, Epson y Lexmark) han incrustado un patrón de puntos amarillos microscópicos en cada página impresa. Estos puntos están dispuestos en una cuadrícula repetitiva a lo largo de toda la página y codifican:
• Número de serie de la impresora: identifica de forma única la impresora específica que produjo la página
• Fecha y hora de impresión: marca de tiempo exacta hasta el minuto
Este sistema fue desarrollado en cooperación con agencias de inteligencia (principalmente el Servicio Secreto de EE.UU.) para rastrear moneda falsificada. Sin embargo, se aplica a TODOS los documentos impresos, no solo a moneda, incluyendo tus folletos, fanzines, cartas abiertas y octavillas.
Cómo están estructurados los puntos: El patrón es típicamente una cuadrícula de 15×8 puntos amarillos repetida a lo largo de la página. Cada columna codifica un dato diferente (dígitos del número de serie, fecha, hora, etc.) usando codificación binaria. Los puntos tienen aproximadamente 0,1mm de diámetro y están espaciados unos 1mm, invisibles bajo iluminación normal.
El caso de Reality Winner (2017): La contratista de la NSA Reality Winner imprimió y filtró documentos clasificados a The Intercept. El FBI la identificó en parte a través de los puntos MIC en las páginas impresas, que codificaban el número de serie exacto de la impresora y la marca de tiempo. Cruzando con los registros de acceso a impresoras en su lugar de trabajo la identificaron como la fuente. Fue sentenciada a más de cinco años de prisión.
Cómo ver los puntos tú mismo:
1. Imprime una página con grandes áreas de espacio en blanco desde una impresora láser a color
2. Examina las áreas blancas bajo una luz LED azul o luz UV (una linterna UV barata funciona)
3. Verás un patrón tenue y repetitivo de puntos amarillos
4. Alternativamente, escanea la página a alta resolución (1200+ DPI, puntos por pulgada) y aumenta el canal azul en un software de imagen. Los puntos amarillos se volverán visibles
Qué impresoras están afectadas: La EFF mantiene una base de datos de investigación. Como regla general: virtualmente todas las impresoras láser a color de marcas principales incrustan estos puntos. El sistema está tan extendido que es más seguro asumir que tu impresora a color te rastrea a menos que lo hayas verificado específicamente.
Countermeasures for anonymous printingContramedidas para impresión anónima
How to print without being traced back to your printer.Cómo imprimir sin que te rastreen hasta tu impresora.
Option 2: Use a public printer. Library printers, copy shops, university print stations. Pay cash. Don't use your library card or university login.
Option 3: Inkjet printers. Most consumer inkjet printers do NOT embed MIC dots (this is primarily a laser printer issue). But verify your specific model.
Option 4: DEDA toolkit. The TU Dresden developed DEDA (Tracking Dots Extraction, Decoding and Anonymisation), a Python tool that can analyze and anonymize MIC dots. Available on GitHub: github.com/dfd-tud/deda
Option 5: Risograph printing. Risograph machines use a completely different printing technology (stencil duplication) and do NOT embed tracking dots. Many activist spaces and art studios have them. Ideal for zines and flyers.
For your fanzines specifically: B&W laser printer from the EFF list, or Risograph for color. Pay cash for toner/ink. Don't order supplies online with your personal account.Opción 1: Impresoras láser en blanco y negro. La mayoría de impresoras láser B&N NO incrustan puntos de rastreo. Esta es la solución más simple. Consulta la lista de la EFF: eff.org/pages/list-printers-which-do-or-do-not-display-tracking-dots
Opción 2: Usa una impresora pública. Impresoras de biblioteca, copisterías, estaciones de impresión universitarias. Paga en efectivo. No uses tu carnet de biblioteca o login universitario.
Opción 3: Impresoras de inyección de tinta. La mayoría de impresoras de inyección de tinta de consumo NO incrustan puntos MIC (esto es principalmente un problema de impresoras láser). Pero verifica tu modelo específico.
Opción 4: Toolkit DEDA. La TU Dresden desarrolló DEDA (Tracking Dots Extraction, Decoding and Anonymisation), una herramienta Python que puede analizar y anonimizar puntos MIC. Disponible en GitHub: github.com/dfd-tud/deda
Opción 5: Impresión Risograph. Las máquinas Risograph usan una tecnología de impresión completamente diferente (duplicación por plantilla) y NO incrustan puntos de rastreo. Muchos espacios activistas y estudios de arte los tienen. Ideal para fanzines y folletos.
Para tus fanzines específicamente: Impresora láser B&N de la lista de la EFF, o Risograph para color. Paga en efectivo por el tóner/tinta. No pidas suministros online con tu cuenta personal.
📋 Phase 02 · Key Takeaways📋 Fase 02 · Puntos clave
Digital Identity & CommunicationsIdentidad digital y comunicaciones
🎭Device Identity SeparationSeparación de identidad de dispositivos
Keep your activist and personal digital lives completely separated, even on the same device. These tools create isolated environments that don't leak data between each other.Mantén tu vida digital activista y personal completamente separadas, incluso en el mismo dispositivo. Estas herramientas crean entornos aislados que no filtran datos entre sí.
Android User ProfilesPerfiles de usuario de Android
Built-in feature: separate, encrypted spaces on the same phone.Función integrada: espacios separados y cifrados en el mismo teléfono.
Setup: Settings → System → Multiple users → Add user
• Create a "Personal" profile for daily life and an "Activism" profile with only Signal, CryptPad, and Tor Browser
• Each profile has separate encryption keys, data from one profile is inaccessible from the other
• When police ask you to unlock, you unlock the personal profile. The activism profile and its data remain hidden
• On GrapheneOS, each profile has its own PIN and independent encryption
Limitations: Advanced forensic tools may detect the existence of multiple profiles. This protects against quick inspections, not deep forensic analysis. Some Android phones from Samsung/Xiaomi may not fully support this.Android soporta múltiples perfiles de usuario, cada uno con sus propias apps, datos y cifrado. En Android stock y especialmente en GrapheneOS:
Configuración: Ajustes → Sistema → Múltiples usuarios → Añadir usuario
• Crea un perfil "Personal" para la vida diaria y un perfil "Activismo" solo con Signal, CryptPad y Tor Browser
• Cada perfil tiene claves de cifrado separadas, los datos de un perfil son inaccesibles desde el otro
• Cuando la policía te pida desbloquear, desbloqueas el perfil personal. El perfil de activismo y sus datos permanecen ocultos
• En GrapheneOS, cada perfil tiene su propio PIN y cifrado independiente
Limitaciones: Herramientas forenses avanzadas pueden detectar la existencia de múltiples perfiles. Esto protege contra inspecciones rápidas, no contra análisis forense profundo. Algunos teléfonos Android de Samsung/Xiaomi pueden no soportar esto completamente.
Shelter app (Android)App Shelter (Android)
Uses Android's Work Profile to isolate apps within a single user account.Usa el Perfil de Trabajo de Android para aislar apps dentro de una sola cuenta de usuario.
Use cases:
• Install apps you don't fully trust (social media, banking) in the work profile, keeping them isolated from sensitive activist tools
• "Freeze" work profile apps when not in use, they can't run in the background or access sensors
• Separate Google Play Services into the work profile (on GrapheneOS)
Install: Available on F-Droid. Open source. Does not require root.
Limitations: Work profile is visible in settings (it's not hidden like user profiles). Best used for app isolation rather than as a hidden container.Qué hace Shelter: Crea un "Perfil de Trabajo" aislado en tu teléfono. Las apps instaladas en el perfil de trabajo no pueden acceder a datos de apps personales y viceversa.
Casos de uso:
• Instala apps en las que no confías plenamente (redes sociales, banca) en el perfil de trabajo, manteniéndolas aisladas de herramientas activistas sensibles
• "Congela" apps del perfil de trabajo cuando no las uses, no pueden ejecutarse en segundo plano ni acceder a sensores
• Separa Google Play Services en el perfil de trabajo (en GrapheneOS)
Instalación: Disponible en F-Droid. Código abierto. No requiere root.
Limitaciones: El perfil de trabajo es visible en ajustes (no está oculto como los perfiles de usuario). Mejor usado para aislamiento de apps que como contenedor oculto.
Firefox Multi-Account ContainersFirefox Multi-Account Containers
Isolate your browsing identities within a single browser.Aísla tus identidades de navegación dentro de un solo navegador.
• Log into Facebook in a "Personal" container and activist Twitter in an "Activism" container, Facebook cannot see your Twitter activity, and trackers can't link the two
• Create containers for: Personal, Activism, Shopping, Banking
• Each container has its own cookies, localStorage, and cache
• Tabs are color-coded so you always know which identity you're browsing as
Setup:
1. Install "Firefox Multi-Account Containers" add-on (official Mozilla add-on)
2. Create containers for each identity
3. Assign websites to containers (Facebook always opens in "Personal," activist platforms in "Activism")
4. Combine with uBlock Origin and Privacy Badger for maximum isolation
For maximum separation: Use containers + a VPN that supports per-app routing (Mullvad) so different containers route through different servers.Firefox Containers mantiene cookies, sesiones y datos de navegación completamente separados por contenedor. Esto significa:
• Inicia sesión en Facebook en un contenedor "Personal" y en Twitter activista en un contenedor "Activismo", Facebook no puede ver tu actividad de Twitter, y los rastreadores no pueden vincular los dos
• Crea contenedores para: Personal, Activismo, Compras, Banca
• Cada contenedor tiene sus propias cookies, localStorage y caché
• Las pestañas están codificadas por colores para que siempre sepas con qué identidad estás navegando
Configuración:
1. Instala el add-on "Firefox Multi-Account Containers" (add-on oficial de Mozilla)
2. Crea contenedores para cada identidad
3. Asigna sitios web a contenedores (Facebook siempre abre en "Personal", plataformas activistas en "Activismo")
4. Combina con uBlock Origin y Privacy Badger para máximo aislamiento
Para máxima separación: Usa contenedores + una VPN que soporte enrutamiento por app (Mullvad) para que diferentes contenedores se enruten a través de diferentes servidores.
🔑Password ManagementGestión de contraseñas
Reusing passwords is how most activist accounts get compromised: not through sophisticated hacking, but because one leaked database gives access to everything. A password manager eliminates that entire attack surface in an afternoon.Reutilizar contraseñas es como se comprometen la mayoría de las cuentas activistas, no mediante hackeo sofisticado, sino porque una base de datos filtrada da acceso a todo. Un gestor de contraseñas elimina toda esa superficie de ataque en una tarde.
One strong master password to rule them allUna contraseña maestra fuerte para dominarlas a todas
Your password manager's password must be the strongest you have.La contraseña de tu gestor de contraseñas debe ser la más fuerte que tengas.
Don't use personal information (names, dates). Don't reuse passwords. For each service, let the manager generate a long random password.
Practical rule: You only need to memorize 3 passwords: the password manager's, the disk encryption's, and your phone PIN. The manager generates and remembers everything else.Método recomendado: Frase de paso de 5-6 palabras aleatorias. Ejemplo: "caballo batería grapa mesa correcto".
No uses información personal (nombres, fechas). No reutilices contraseñas. Para cada servicio, deja que el gestor genere una contraseña larga y aleatoria.
Regla práctica: Solo necesitas memorizar 3 contraseñas: la del gestor de contraseñas, la del cifrado del disco, y tu PIN del teléfono. El gestor genera y recuerda todo lo demás.
🎣Phishing ProtectionProtección contra phishing
Phishing attacks are the most common way to compromise activists. They don't need technical vulnerabilities: just for you to click a link and enter your password.Los ataques de phishing son la forma más común de comprometer a activistas. No necesitan vulnerabilidades técnicas: solo que hagas clic en un enlace e introduzcas tu contraseña.
How to recognize a phishing attackCómo reconocer un ataque de phishing
Artificial urgency, unexpected links, suspicious senders.Urgencia artificial, enlaces inesperados, remitentes sospechosos.
• Artificial urgency: "Your account will be blocked in 24 hours," "Action required immediately"
• Unexpected links: An email or message you weren't expecting with a link to "verify" something
• Subtle URL errors: proton-mail.com instead of protonmail.com, slgnal.org instead of signal.org
• Credential requests: No legitimate service will ask for your password via email or message
• Unsolicited attachments: PDFs, Word documents, especially with macrosSeñales de alerta:
• Urgencia artificial: "Tu cuenta será bloqueada en 24 horas," "Acción requerida inmediatamente"
• Enlaces inesperados: Un email o mensaje que no esperabas con un enlace para "verificar" algo
• Errores sutiles en URLs: proton-mail.com en lugar de protonmail.com, slgnal.org en lugar de signal.org
• Solicitudes de credenciales: Ningún servicio legítimo pedirá tu contraseña por email o mensaje
• Adjuntos no solicitados: PDFs, documentos Word, especialmente con macros
What to do if you receive something suspiciousQué hacer si recibes algo sospechoso
🔐Two-Factor Authentication (2FA)Autenticación de dos factores (2FA)
If someone obtains your password (through phishing, data breach, or brute force), two-factor authentication prevents them from accessing your account without a second factor.Si alguien obtiene tu contraseña (a través de phishing, filtración de datos, o fuerza bruta), la autenticación de dos factores les impide acceder a tu cuenta sin un segundo factor.
❌ SMS-based 2FA❌ 2FA basado en SMS
SMS is interceptable. "SIM swapping" attacks allow an attacker to receive your SMS by convincing your carrier to transfer your number to another SIM. Don't use SMS as a second factor.Los SMS son interceptables. Los ataques de "SIM swapping" permiten a un atacante recibir tus SMS convenciendo a tu operador de transferir tu número a otra SIM. No uses SMS como segundo factor.
✅ Aegis (Android)✅ Aegis (Android)
Open source authenticator app.App autenticadora de código abierto.
How it works: When you enable 2FA on a service (Signal, ProtonMail, CryptPad...), it shows you a QR code. You scan it with Aegis. From then on, Aegis generates a 6-digit code that changes every 30 seconds.
Important: Aegis allows you to export an encrypted backup of your codes. Do it and store it in your password manager or on a USB drive. If you lose the phone without a backup, you lose access to your accounts.Instalación: Busca "Aegis Authenticator" en Play Store o F-Droid.
Cómo funciona: Cuando activas 2FA en un servicio (Signal, ProtonMail, CryptPad...), te muestra un código QR. Lo escaneas con Aegis. A partir de entonces, Aegis genera un código de 6 dígitos que cambia cada 30 segundos.
Importante: Aegis permite exportar una copia de seguridad cifrada de tus códigos. Hazlo y guárdala en tu gestor de contraseñas o en una unidad USB. Si pierdes el teléfono sin copia de seguridad, pierdes acceso a tus cuentas.
✅ 2FAS Auth (iOS)✅ 2FAS Auth (iOS)
Open source authenticator app for iPhone. Replaces the previously recommended Raivo.App autenticadora de código abierto para iPhone. Reemplaza al anteriormente recomendado Raivo.
Works like Aegis: scan the QR when enabling 2FA, the app generates codes every 30 seconds. Also allows exporting backups.
Why not Raivo? Raivo OTP was acquired by a company called Mobime in 2023, which subsequently pushed an update that wiped many users' stored codes. The app's trustworthiness has been severely compromised. If you currently use Raivo, migrate to 2FAS immediately.
Alternative: If you already use KeePassXC on desktop, it can also generate TOTP codes. So you have everything in one place.Instalación: Busca "2FAS" en la App Store.
Funciona como Aegis: escanea el QR al activar 2FA, la app genera códigos cada 30 segundos. También permite exportar copias de seguridad.
¿Por qué no Raivo? Raivo OTP fue adquirido por una empresa llamada Mobime en 2023, que posteriormente publicó una actualización que borró los códigos almacenados de muchos usuarios. La confiabilidad de la app ha sido severamente comprometida. Si actualmente usas Raivo, migra a 2FAS inmediatamente.
Alternativa: Si ya usas KeePassXC en escritorio, también puede generar códigos TOTP. Así tienes todo en un solo lugar.
🔑 Hardware security keys (gold standard)🔑 Llaves de seguridad de hardware (estándar de oro)
Physical keys like YubiKey or Nitrokey, the most phishing-resistant 2FA method available.Llaves físicas como YubiKey o Nitrokey, el método 2FA más resistente al phishing disponible.
Recommended models:
• YubiKey 5 NFC (~€50-60), works with USB-A/C and NFC on phones
• Nitrokey FIDO2 (~€30), open source hardware, made in Germany
Who should use them: Anyone in a leadership or high-risk organizing role. If your email or Signal is compromised, the entire network can be exposed.
Important: Always register at least TWO keys per account. If you lose one, the backup key is your lifeline. Store the backup in a separate, secure location.A diferencia de las apps autenticadoras, las llaves de hardware son a prueba de phishing: verifican el dominio del sitio web criptográficamente, así que incluso si te engañan para visitar un sitio falso, la llave no autenticará.
Modelos recomendados:
• YubiKey 5 NFC (~€50-60), funciona con USB-A/C y NFC en teléfonos
• Nitrokey FIDO2 (~€30), hardware de código abierto, hecho en Alemania
Quién debería usarlas: Cualquiera en un rol de liderazgo o de organización de alto riesgo. Si tu email o Signal es comprometido, toda la red puede quedar expuesta.
Importante: Siempre registra al menos DOS llaves por cuenta. Si pierdes una, la llave de respaldo es tu salvación. Guarda el respaldo en una ubicación separada y segura.
Where to enable 2FA (in order of priority)Dónde activar 2FA (por orden de prioridad)
📡WiFi & Network SecurityWiFi y Seguridad de Red
The network layer is surveillance infrastructure. Every café, airport, hotel, and protest zone is a potential interception point. Connecting to public WiFi without protection means the operator sees every site you visit, your device's hardware ID, and when you connected. This module covers what leaks, how to stop it, and how to harden your own network.La capa de red es infraestructura de vigilancia. Cada café, aeropuerto, hotel y zona de protesta es un punto de interceptación potencial. Conectarte al WiFi público sin protección significa que el operador ve cada sitio que visitas, el ID de hardware de tu dispositivo y cuándo te conectaste. Este módulo cubre qué se filtra, cómo detenerlo y cómo reforzar tu propia red.
⚠ What Public WiFi Actually Exposes⚠ Qué Expone Realmente el WiFi Público
Most people assume HTTPS makes public WiFi safe. It does not. Multiple surveillance channels operate simultaneously: the network operator captures all of them without needing to break encryption. La mayoría asume que HTTPS hace seguro el WiFi público. No es así. Múltiples canales de vigilancia operan simultáneamente: el operador de red los captura todos sin necesidad de romper el cifrado.
Three Threat ClassesTres Clases de Amenaza
🛡 Network Options by Risk Level🛡 Opciones de Red por Nivel de Riesgo
Choose your connection method based on what you're doing and who might be watching. Not all situations demand the same level of protection.Elige tu método de conexión según lo que estás haciendo y quién podría estar vigilando. No todas las situaciones exigen el mismo nivel de protección.
🔧 Hardening Your Device & Network🔧 Hardening de tu Dispositivo y Red
Four concrete actions, ordered by impact. Each one independently reduces your exposure.Cuatro acciones concretas, ordenadas por impacto. Cada una reduce independientemente tu exposición.
Prevents passive location tracking via probe requests. A global toggle is not enough: each saved network stores its own setting.Previene el rastreo pasivo de ubicaciones vía solicitudes de sonda. Un interruptor global no basta: cada red guardada almacena su propia configuración.
Even on HTTPS sites, DNS queries are unencrypted by default. The router sees "signal.org" every time you load it, before any encryption applies. DoH wraps those queries in an HTTPS tunnel so the network only sees noise.Incluso en sitios HTTPS, las consultas DNS están sin cifrar por defecto. El router ve "signal.org" cada vez que lo cargas, antes de que se aplique ningún cifrado. DoH envuelve esas consultas en un túnel HTTPS para que la red solo vea ruido.
dns.quad9.netdns.quad9.netSwiss foundation, no logs, EFF-recommendedFundación suiza, sin registros, recomendado por EFFadblock.dns.mullvad.netZero-log, ad blocking, same org as Mullvad VPNCero registros, bloqueo de ads, misma org que Mullvad VPNnextdns.ioConfigurable, free tier, disable logs in settingsConfigurable, capa gratuita, desactiva registros en ajustesEvery network you save becomes part of a broadcast list your device transmits constantly. Attackers use this list to create evil twin hotspots matching exactly the SSIDs your device trusts. Delete any network you do not use daily.Cada red que guardas pasa a formar parte de una lista de transmisión que tu dispositivo emite constantemente. Los atacantes usan esta lista para crear hotspots evil twin que coinciden exactamente con los SSIDs en los que tu dispositivo confía. Elimina cualquier red que no uses a diario.
Your own router is far safer than public WiFi, but ships with insecure defaults. Three areas to address: encryption, attack surface, and network segmentation to isolate activist devices from smart speakers and IoT sensors.Tu propio router es mucho más seguro que el WiFi público, pero viene con valores por defecto inseguros. Tres áreas a tratar: cifrado, superficie de ataque y segmentación de red para aislar dispositivos de activistas de altavoces inteligentes y sensores IoT.
Use WPA3 if your router supports it. Minimum WPA2-AES. Never WEP (completely broken) or WPA-TKIP (vulnerable). Use a strong unique password, 20+ characters.Usa WPA3 si tu router lo admite. Mínimo WPA2-AES. Nunca WEP (completamente roto) o WPA-TKIP (vulnerable). Usa una contraseña fuerte y única, 20+ caracteres.
Disable UPnP, WPS, and remote management in your router admin panel. Change the default admin username and password immediately. The admin password must be different from the WiFi password.Desactiva UPnP, WPS y gestión remota en el panel de administración del router. Cambia el usuario y contraseña de administración por defecto inmediatamente. La contraseña de administración debe ser diferente a la contraseña WiFi.
Put IoT devices and personal phones on a guest network, separate from activist devices. A compromised smart TV or speaker on the same network can be used to access your laptop or phone.Pon dispositivos IoT y teléfonos personales en una red de invitados, separada de los dispositivos de activistas. Un televisor inteligente o altavoz comprometido en la misma red puede usarse para acceder a tu portátil o teléfono.
🛡️VPN: When It Helps, When It Doesn'tVPN: cuándo ayuda y cuándo no
VPNs are the most misunderstood security tool. They don't make you anonymous. They don't protect your messages. But they do have real, specific uses. Here's the honest guide.Las VPNs son la herramienta de seguridad más malentendida. No te hacen anónimo. No protegen tus mensajes. Pero tienen usos reales y específicos. Aquí está la guía honesta.
When a VPN actually helpsCuándo una VPN realmente ayuda
Specific scenarios where a VPN adds real protection.Escenarios específicos donde una VPN añade protección real.
✅ Public WiFi: Prevents the café, airport, or hotel from seeing your traffic (and prevents man-in-the-middle attacks on unsecured networks)
✅ Hiding your IP from websites: The site sees the VPN server's IP, not yours. Useful for browsing that shouldn't be linked to your location.
✅ Bypassing censorship: Access blocked websites, circumvent national firewalls (Turkey, Russia, China).
✅ Preventing ISP surveillance: Your internet provider sees you connecting to a VPN, but not what you're doing inside it.
✅ Accessing geoblocked resources: Reach content restricted to other countries.
✅ Preventing network-level tower dump correlation: Makes it harder to link your browsing activity to your physical location via ISP records.La VPN es útil cuando:
✅ WiFi público: Impide que la cafetería, aeropuerto u hotel vean tu tráfico (y previene ataques man-in-the-middle en redes no seguras)
✅ Ocultar tu IP de sitios web: El sitio ve la IP del servidor VPN, no la tuya. Útil para navegación que no debería vincularse a tu ubicación.
✅ Evadir censura: Acceder a sitios web bloqueados, eludir firewalls nacionales (Turquía, Rusia, China).
✅ Prevenir vigilancia del ISP: Tu proveedor de internet ve que te conectas a una VPN, pero no lo que haces dentro de ella.
✅ Acceder a recursos geo-bloqueados: Alcanzar contenido restringido a otros países.
✅ Prevenir correlación de tower dump a nivel de red: Dificulta vincular tu actividad de navegación con tu ubicación física mediante registros del ISP.
When a VPN gives false securityCuándo una VPN da falsa seguridad
What a VPN does NOT do.Lo que una VPN NO hace.
❌ Make you anonymous: You're still logged into your accounts. Google/Facebook still know who you are. Your browser fingerprint is still unique.
❌ Encrypt your messages: Signal is already E2E encrypted. A VPN adds nothing to Signal, ProtonMail, or any E2E encrypted service.
❌ Protect against malware/spyware: Pegasus, keyloggers, browser exploits all work through the VPN tunnel.
❌ Hide your identity from your VPN provider: The VPN company sees all your traffic instead of your ISP. You're just shifting trust.
❌ Protect against correlation attacks: A state-level adversary can match traffic entering and exiting the VPN if they control both endpoints.
❌ Replace Tor: For genuine anonymity, only Tor provides sufficient protection. A VPN is not a substitute.La VPN NO:
❌ Te hace anónimo: Sigues conectado a tus cuentas. Google/Facebook siguen sabiendo quién eres. Tu huella digital del navegador sigue siendo única.
❌ Cifra tus mensajes: Signal ya está cifrado E2E. Una VPN no añade nada a Signal, ProtonMail, o cualquier servicio con cifrado E2E.
❌ Protege contra malware/spyware: Pegasus, keyloggers, exploits de navegador todos funcionan a través del túnel VPN.
❌ Oculta tu identidad de tu proveedor VPN: La compañía VPN ve todo tu tráfico en lugar de tu ISP. Solo estás cambiando la confianza de lugar.
❌ Protege contra ataques de correlación: Un adversario a nivel estatal puede emparejar tráfico entrando y saliendo de la VPN si controla ambos puntos.
❌ Sustituye a Tor: Para anonimato genuino, solo Tor proporciona protección suficiente. Una VPN no es un sustituto.
Which VPNs to trust (and which to avoid)En qué VPNs confiar (y cuáles evitar)
Most VPNs are worse than no VPN.La mayoría de las VPNs son peores que no tener VPN.
• Mullvad: €5/month. No email required to sign up. Accept cash payment by mail. No logs (audited). Open source. Based in Sweden. Generate anonymous account number, no personal data needed at all. In 2023, Swedish police raided Mullvad's offices and seized hardware - no user data was recovered, validating the no-logs architecture. Top recommendation.
• IVPN: Similar philosophy to Mullvad. No email required. Cash/Monero accepted. Audited no-logs. Based in Gibraltar.
• ProtonVPN: Free tier available (limited). Swiss jurisdiction. Trustworthy company (Proton ecosystem). Requires email to sign up (use ProtonMail).
AVOID:
• Free VPNs: If you're not paying, you're the product. Hola VPN sold user bandwidth. Betternet contained malware. SuperVPN leaked 360M records in 2023.
• NordVPN, ExpressVPN, Surfshark: Heavy marketing, opaque ownership structures (Kape Technologies owns ExpressVPN and CyberGhost, former adware company). Not necessarily malicious, but trust is hard to verify.
• Any VPN based in 14 Eyes countries (US, UK, Canada, Australia, NZ + extended) without proven no-logs policy, legally compellable to share data.Opciones de confianza:
• Mullvad: €5/mes. No requiere email para registrarse. Acepta pago en efectivo por correo. Sin logs (auditado). Código abierto. Con sede en Suecia. Genera número de cuenta anónimo, no se necesitan datos personales. En 2023, la policía sueca registró las oficinas de Mullvad y confiscó hardware - no se recuperó ningún dato de usuario, validando la arquitectura sin registros. Máxima recomendación.
• IVPN: Filosofía similar a Mullvad. No requiere email. Acepta efectivo/Monero. Sin logs auditado. Con sede en Gibraltar.
• ProtonVPN: Nivel gratuito disponible (limitado). Jurisdicción suiza. Compañía de confianza (ecosistema Proton). Requiere email para registrarse (usa ProtonMail).
EVITAR:
• VPNs gratuitas: Si no estás pagando, tú eres el producto. Hola VPN vendió ancho de banda de usuarios. Betternet contenía malware. SuperVPN filtró 360M de registros en 2023.
• NordVPN, ExpressVPN, Surfshark: Marketing agresivo, estructuras de propiedad opacas (Kape Technologies es dueña de ExpressVPN y CyberGhost, antigua empresa de adware). No necesariamente maliciosas, pero la confianza es difícil de verificar.
• Cualquier VPN basada en países de los 14 Ojos (EE.UU., Reino Unido, Canadá, Australia, NZ + extendidos) sin política verificada de no-logs, legalmente obligables a compartir datos.
💬Secure Messaging: Signal, Matrix & AlternativesMensajería segura: Signal, Matrix y alternativas
Most people think they're communicating securely because they have "nothing to hide." That's the wrong framing. The question is what you're handing to anyone who gets a court order, seizes a phone, or runs a foreign intelligence operation. The difference between platforms is the difference between protected and exposed.La mayoría de la gente cree que se comunica de forma segura porque no tiene "nada que ocultar." Ese es el enfoque equivocado. La pregunta es qué le estás entregando a quien consiga una orden judicial, incaute un teléfono o dirija una operación de inteligencia extranjera. La diferencia entre plataformas es la diferencia entre protegido y expuesto.
Messaging comparison at a glanceComparación de mensajería de un vistazo
Not all messaging apps offer the same protection. The differences between them are not about features or interface preferences. They are about what a prosecutor can legally obtain, what a seized phone reveals, and what a platform will hand over without telling you.No todas las aplicaciones de mensajería ofrecen la misma protección. Las diferencias entre ellas no son sobre características o preferencias de interfaz. Se trata de lo que un fiscal puede obtener legalmente, lo que revela un teléfono incautado y lo que una plataforma entregará sin avisarte.
| FeatureCaracterística | Signal | Telegram | |
|---|---|---|---|
| E2E encryption by defaultCifrado E2E por defecto | ✓ Always✓ Siempre | ✓ Messages✓ Mensajes | ✗ Only "secret chats"✗ Solo "chats secretos" |
| Group E2E encryptionCifrado E2E en grupos | ✓ Yes✓ Sí | ✓ Yes✓ Sí | ✗ No✗ No |
| Open source (client + server)Código abierto (cliente + servidor) | ✓ Both✓ Ambos | ✗ No✗ No | ~ Client only~ Solo cliente |
| No phone number needed to addSin necesidad de número de teléfono | ✓ Usernames✓ Nombres de usuario | ✗ Number required✗ Número requerido | ✓ Usernames✓ Nombres de usuario |
| Disappearing messagesMensajes que desaparecen | ✓ Default option✓ Opción por defecto | ✓ Yes✓ Sí | ~ Secret chats only~ Solo chats secretos |
| Metadata stored on serverMetadatos almacenados en servidor | ✓ Minimal✓ Mínimos | ~ Some metadata~ Algunos metadatos | ✗ Extensive✗ Extensos |
| Data handed to authoritiesDatos entregados a autoridades | ✓ Almost none✓ Casi ninguno | ~ Metadata yes~ Metadatos sí | ✗ Yes, actively cooperates✗ Sí, coopera activamente |
| Trusted crypto protocolProtocolo criptográfico confiable | ✓ Signal Protocol✓ Protocolo Signal | ✓ Signal Protocol✓ Protocolo Signal | ✗ MTProto (unverified)✗ MTProto (no verificado) |
Why Signal?¿Por qué Signal?
Signal is not just the most private messaging app. It is the only major messenger whose architecture makes it technically impossible to comply with a broad surveillance order. The reasons are worth understanding, not just accepting on faith.Signal no es solo la aplicación de mensajería más privada. Es el único mensajero importante cuya arquitectura hace técnicamente imposible cumplir con una orden de vigilancia amplia. Las razones merecen entenderse, no solo aceptarse por fe.
🔒 Signal is the gold standard for activist communication🔒 Signal es el estándar de oro para la comunicación activista
Before diving into setup, here's why every digital-security guide recommends Signal above all other messengers.Antes de entrar en la configuración, aquí está por qué cada guía de seguridad digital recomienda Signal por encima de todos los demás mensajeros.
🔓 Open source🔓 Código abierto
Signal's code (both the client apps and the server) is publicly auditable on GitHub. Anyone can inspect it for backdoors or weaknesses. No other major messenger offers this level of transparency.El código de Signal (tanto las apps cliente como el servidor) es públicamente auditable en GitHub. Cualquiera puede inspeccionarlo en busca de puertas traseras o debilidades. Ningún otro mensajero importante ofrece este nivel de transparencia.
🛡️ End-to-end encryption by default🛡️ Cifrado de extremo a extremo por defecto
Every message, call, and file is encrypted with the Signal Protocol before it leaves your device. Not even Signal's own servers can read your content. Unlike WhatsApp (owned by Meta) or Telegram (no E2E by default - groups are never encrypted, and 1-to-1 Secret Chats are opt-in, not the default), Signal was designed for privacy from day one.Cada mensaje, llamada y archivo se cifra con el Protocolo Signal antes de salir de tu dispositivo. Ni siquiera los propios servidores de Signal pueden leer tu contenido. A diferencia de WhatsApp (propiedad de Meta) o Telegram (sin E2E por defecto - los grupos nunca están cifrados, y los Chats Secretos 1-a-1 son opcionales, no el modo por defecto), Signal fue diseñado para la privacidad desde el primer día.
📉 Metadata minimization📉 Minimización de metadatos
Signal stores almost no information about you. When served with a court order, Signal can only hand over your account creation date and last connection date. Nothing else. No contacts, no groups, no message history. This has been publicly proven in multiple subpoena responses.Signal almacena casi ninguna información sobre ti. Cuando se les presenta una orden judicial, Signal solo puede entregar la fecha de creación de tu cuenta y la fecha de última conexión. Nada más. Sin contactos, sin grupos, sin historial de mensajes. Esto ha sido probado públicamente en múltiples respuestas a citaciones.
👤 No phone number exposure👤 Sin exposición del número de teléfono
Signal now supports usernames, so you can communicate with other activists without ever sharing your phone number. This is critical for keeping your real identity separate from your activist identity.Signal ahora soporta nombres de usuario, para que puedas comunicarte con otros activistas sin compartir nunca tu número de teléfono. Esto es crítico para mantener tu identidad real separada de tu identidad activista.
Signal Setup GuideGuía de configuración de Signal
Installing Signal is not enough. The default settings leave several critical protections turned off. This guide walks through every setting that matters for activist use, in the order you should configure them.Instalar Signal no es suficiente. La configuración predeterminada deja varias protecciones críticas desactivadas. Esta guía repasa cada ajuste que importa para uso activista, en el orden en que debes configurarlos.
Update to the latest versionActualiza a la última versión
App Store › Signal › Update
Hide your phone numberOculta tu número de teléfono
Settings › Privacy › Phone Number › Nobody
Create a usernameCrea un nombre de usuario
Settings › Your Profile › Username · Memorize it so you can share it without pulling out your phone.Memorízalo para poder compartirlo sin sacar tu teléfono.
Enable registration lockActiva el bloqueo de registro
Settings › Account › Registration Lock · Prevents someone from registering your number on another device without your PIN.Impide que alguien registre tu número en otro dispositivo sin tu PIN.
Set disappearing messages defaultConfigura mensajes que desaparecen por defecto
Settings › Privacy › Default timer for new chats · 1 week normal, 4 hours or less during actions.1 semana normal, 4 horas o menos durante acciones.
Mute notification contentSilencia el contenido de notificaciones
Settings › Notifications › Show › "No name or message" · Push notifications are stored on Apple/Google servers.Las notificaciones push se almacenan en servidores de Apple/Google.
⚠️ Cloud backups can expose your Signal messages⚠️ Las copias de seguridad en la nube pueden exponer tus mensajes de Signal
iCloud and Google backups may create a plaintext copy of your Signal database. This is one of the most common ways Signal's encryption is bypassed.Las copias de seguridad de iCloud y Google pueden crear una copia en texto plano de tu base de datos de Signal. Esta es una de las formas más comunes de eludir el cifrado de Signal.
iPhone: If iCloud Backup is enabled WITHOUT Advanced Data Protection (ADP), Apple holds the encryption keys to your backup. Signal messages included in this backup are accessible to Apple and law enforcement.
Fix: Either disable iCloud Backup entirely, or enable Advanced Data Protection (Settings → Apple ID → iCloud → Advanced Data Protection). Verify this now · most people never check.
Android: Google Drive backups can include app data. While Signal's own backup system is encrypted, the device-level Google backup may capture Signal data in a less protected form.
Fix: Disable Google backup for Signal specifically (Settings → Google → Backup → disable Signal), or disable cloud backup entirely.
Signal's built-in backup (Android only) uses a 30-digit passphrase and is safely encrypted. Use this instead of cloud backups if you need to transfer data.
Action item: Check your backup settings RIGHT NOW. Go to your phone's Settings and verify that Signal data is NOT being sent to iCloud or Google Drive.El riesgo: Si tu teléfono hace copia de seguridad en iCloud (iPhone) o Google Drive (Android), una copia de tu base de datos de mensajes de Signal puede incluirse en la copia. Esta copia de seguridad se almacena en servidores de Apple/Google y puede ser accedida con una orden judicial, efectivamente eludiendo el cifrado de extremo a extremo de Signal. En la práctica, esto significa que tus mensajes "cifrados" de Signal pueden estar ahora mismo sin protección en servidores de Apple o Google.
iPhone: Si la Copia de Seguridad de iCloud está activada SIN Protección de Datos Avanzada (ADP), Apple tiene las claves de cifrado de tu copia de seguridad. Los mensajes de Signal incluidos en esta copia son accesibles para Apple y las fuerzas del orden.
Solución: O desactiva la Copia de Seguridad de iCloud completamente, o activa la Protección de Datos Avanzada (Ajustes → ID de Apple → iCloud → Protección de Datos Avanzada). Verifica esto ahora · la mayoría nunca lo comprueba.
Android: Las copias de seguridad de Google Drive pueden incluir datos de apps. Aunque el propio sistema de copia de seguridad de Signal está cifrado, la copia de seguridad de Google a nivel de dispositivo puede capturar datos de Signal en una forma menos protegida.
Solución: Desactiva la copia de seguridad de Google para Signal específicamente (Ajustes → Google → Copia de seguridad → desactivar Signal), o desactiva la copia de seguridad en la nube completamente.
La copia de seguridad integrada de Signal (solo Android) usa una frase de paso de 30 dígitos y está cifrada de forma segura. Usa esto en lugar de copias de seguridad en la nube si necesitas transferir datos.
Acción requerida: Comprueba tus ajustes de copia de seguridad AHORA MISMO. Ve a los Ajustes de tu teléfono y verifica que los datos de Signal NO se están enviando a iCloud o Google Drive.
Contact & Group SecuritySeguridad de contactos y grupos
Your personal Signal setup is only as strong as the practices of everyone you communicate with. A single person in a group with poor habits can expose the entire network. These practices are non-negotiable for any group doing sensitive work.Tu configuración personal de Signal es tan fuerte como las prácticas de todos con quienes te comunicas. Una sola persona en un grupo con malos hábitos puede exponer toda la red. Estas prácticas no son negociables para ningún grupo que realice trabajo sensible.
Signal Group RulesReglas para grupos de Signal
A Signal group is only secure if everyone in it follows the same discipline. These rules exist because the weakest link determines the security of the whole chain. Read them with your group and agree on them explicitly before using any shared channel for sensitive coordination.Un grupo de Signal solo es seguro si todos sus miembros siguen la misma disciplina. Estas reglas existen porque el eslabón más débil determina la seguridad de toda la cadena. Léelas con tu grupo y acuérdalas explícitamente antes de usar cualquier canal compartido para coordinación sensible.
Disappearing messages FROM creationMensajes que desaparecen DESDE la creación
4-7 days normal. 2 hours or less during actions. Set when creating the group, not after. Messages sent before enabling the feature don't disappear retroactively.4-7 días normal. 2 horas o menos durante acciones. Configúralo al crear el grupo, no después. Los mensajes enviados antes de activar la función no desaparecen retroactivamente.
Always 2-3 adminsSiempre 2-3 admins
A single admin is dangerous: if their phone is seized, they can't be removed. Assign two more admins immediately when creating the group.Un solo admin es peligroso: si su teléfono es confiscado, no pueden ser eliminados. Asigna dos admins más inmediatamente al crear el grupo.
Permissions: "Only admins"Permisos: "Solo admins"
Edit group > Permissions > both first options set to "Only admins." Group links: "Admin approval" always enabled. This prevents anyone from adding people without approval.Editar grupo > Permisos > las dos primeras opciones en "Solo admins". Enlaces de grupo: "Aprobación de admin" siempre activado. Esto impide que nadie añada gente sin aprobación.
Secure EmailEmail seguro
Email is structurally one of the least private communication tools. It was designed for open relay, not confidentiality. Encrypting email is possible but fragile, and most people you contact will not do it. The honest recommendation for activists is to understand what email can and cannot protect, then use it accordingly.El correo electrónico es estructuralmente una de las herramientas de comunicación menos privadas. Fue diseñado para transmisión abierta, no para confidencialidad. Cifrar el correo es posible pero frágil, y la mayoría de las personas con las que contactas no lo harán. La recomendación honesta para activistas es entender qué puede y no puede proteger el correo, y usarlo en consecuencia.
❌ Gmail, Outlook, Yahoo❌ Gmail, Outlook, Yahoo
They store all content on their servers. Accessible via court order to Google/Microsoft/Yahoo. Metadata (who writes to whom, when, from what IP) is always visible to the provider.Almacenan todo el contenido en sus servidores. Accesible mediante orden judicial a Google/Microsoft/Yahoo. Los metadatos (quién escribe a quién, cuándo, desde qué IP) siempre son visibles para el proveedor.
✅ ProtonMail✅ ProtonMail
End-to-end encryption between Proton users.Cifrado de extremo a extremo entre usuarios de Proton.
Emails between ProtonMail users are end-to-end encrypted. Emails to external users (Gmail, etc.) are stored encrypted on Proton's servers but the content travels unencrypted over the internet.
Limitation: ProtonMail complies with Swiss court orders and can provide metadata (access IP, recipients). For maximum protection, access via Tor.Crear cuenta: proton.me > Crear cuenta gratuita
Los emails entre usuarios de ProtonMail están cifrados de extremo a extremo. Los emails a usuarios externos (Gmail, etc.) se almacenan cifrados en los servidores de Proton pero el contenido viaja sin cifrar por internet.
Limitación: ProtonMail cumple con órdenes judiciales suizas y puede proporcionar metadatos (IP de acceso, destinatarios). Para máxima protección, accede vía Tor.
✅ Tuta (formerly Tutanota)✅ Tuta (anteriormente Tutanota)
End-to-end encryption. Based in Germany.Cifrado de extremo a extremo. Con sede en Alemania.
Similar to ProtonMail: E2E encryption between Tuta users. Simpler interface. Free plan includes 1 GB of storage.
For activist email: Use ProtonMail or Tuta exclusively. Never your personal email for anything movement-related. Don't link the activist email to your real identity.Crear cuenta: tuta.com > Registrarse
Similar a ProtonMail: cifrado E2E entre usuarios de Tuta. Interfaz más simple. El plan gratuito incluye 1 GB de almacenamiento.
Para email activista: Usa ProtonMail o Tuta exclusivamente. Nunca tu email personal para nada relacionado con el movimiento. No vincules el email activista con tu identidad real.
Secure Video CallsVideollamadas seguras
Video calls are among the highest-risk communications for activists. They capture audio, video, metadata, and often screen content simultaneously. Zoom, Google Meet, and Teams are workplace tools built for corporate compliance, not activist privacy. The alternatives here are built differently.Las videollamadas son una de las comunicaciones de mayor riesgo para los activistas. Capturan simultáneamente audio, vídeo, metadatos y frecuentemente el contenido de la pantalla. Zoom, Google Meet y Teams son herramientas de trabajo empresarial diseñadas para el cumplimiento corporativo, no para la privacidad activista. Las alternativas aquí están construidas de otra manera.
❌ Zoom, Google Meet, Microsoft Teams❌ Zoom, Google Meet, Microsoft Teams
They store meeting metadata (participants, duration, IPs). Can comply with court orders. Zoom has had multiple documented security issues.Almacenan metadatos de reuniones (participantes, duración, IPs). Pueden cumplir con órdenes judiciales. Zoom ha tenido múltiples problemas de seguridad documentados.
✅ Jitsi Meet✅ Jitsi Meet
No registration, no installation, open source.Sin registro, sin instalación, código abierto.
1. Go to meet.jit.si in the browser
2. Type a room name (long and random, not "activist-meeting")
3. Share the link via Signal
4. Enable room password (lock icon at bottom left)
More secure instances (don't keep logs):
• meet.systemli.org (German tech collective)
• jitsi.autistici.org (Italian collective)
For large groups (10+ people), Jitsi supports more participants than Signal.Cómo usar:
1. Ve a meet.jit.si en el navegador
2. Escribe un nombre de sala (largo y aleatorio, no "reunion-activista")
3. Comparte el enlace vía Signal
4. Activa contraseña de sala (icono de candado abajo a la izquierda)
Instancias más seguras (no guardan logs):
• meet.systemli.org (colectivo tech alemán)
• jitsi.autistici.org (colectivo italiano)
Para grupos grandes (10+ personas), Jitsi soporta más participantes que Signal.
✅ Signal video calls✅ Videollamadas de Signal
For groups up to 75 people. End-to-end encryption guaranteed. No metadata accessible to third parties. The most secure option.Para grupos de hasta 75 personas. Cifrado de extremo a extremo garantizado. Sin metadatos accesibles para terceros. La opción más segura.
📡Communication Without InternetComunicación sin internet
Governments cut mobile data at protests (Iran 2019/2022, Myanmar 2021, India Kashmir). Spain jammed signals during Catalonia 2017. You need a plan for when the internet goes dark.Los gobiernos cortan los datos móviles en protestas (Irán 2019/2022, Myanmar 2021, India Cachemira). España bloqueó señales durante Cataluña 2017. Necesitas un plan para cuando el internet se apague.
Mesh networking: BriarRed mesh: Briar
Encrypted messaging that works without internet via Bluetooth and WiFi Direct.Mensajería cifrada que funciona sin internet vía Bluetooth y WiFi Direct.
• Peer-to-peer encrypted messaging, no servers, no internet needed
• Works via Bluetooth (range ~10m), WiFi Direct (~100m), or Tor when internet is available
• Messages hop between devices to reach recipients (mesh network)
• Android only (no iOS due to Apple Bluetooth restrictions)
• Must add contacts in person first (exchange keys face-to-face)
Best use: Pre-add all team members before an action. If internet is cut, Briar continues working via Bluetooth chain between nearby devices.
Limitations: Short Bluetooth range, Android only, requires pre-established contacts. Battery-intensive. Not suitable for real-time coordination of large groups.Cómo funciona Briar:
• Mensajería cifrada peer-to-peer, sin servidores, sin internet necesario
• Funciona vía Bluetooth (rango ~10m), WiFi Direct (~100m), o Tor cuando hay internet disponible
• Los mensajes saltan entre dispositivos para alcanzar destinatarios (red mesh)
• Solo Android (no iOS debido a restricciones de Bluetooth de Apple)
• Debes añadir contactos en persona primero (intercambiar claves cara a cara)
Mejor uso: Pre-añade a todos los miembros del equipo antes de una acción. Si se corta internet, Briar sigue funcionando vía cadena Bluetooth entre dispositivos cercanos.
Limitaciones: Rango Bluetooth corto, solo Android, requiere contactos pre-establecidos. Consume mucha batería. No apto para coordinación en tiempo real de grupos grandes.
Meshtastic & LoRa radiosMeshtastic y radios LoRa
Long-range communication (kilometers) without cellular infrastructure.Comunicación de largo alcance (kilómetros) sin infraestructura celular.
• Open-source firmware for cheap LoRa radio hardware (~€25-40 per device)
• Range: 1-10km+ depending on terrain and antenna (up to 50km with line of sight)
• Text messaging, GPS sharing, encrypted channels
• Works as a mesh: each device relays messages, extending range
• No SIM card, no phone number, no registration
• Pairs with phone via Bluetooth for UI, but radio works independently
Hardware options: Heltec V3 (~€25), LilyGO T-Beam (~€35), RAK WisBlock
Operational considerations: LoRa transmissions can be direction-found with SDR (Software Defined Radio) equipment. Use encrypted channels. Messages are short (text only). Not suitable for voice or images. Legal in EU ISM (Industrial, Scientific, Medical) bands (868 MHz) but check local regulations for power limits.Meshtastic:
• Firmware de código abierto para hardware de radio LoRa barato (~€25-40 por dispositivo)
• Alcance: 1-10km+ dependiendo del terreno y antena (hasta 50km con línea de visión)
• Mensajería de texto, compartir GPS, canales cifrados
• Funciona como mesh: cada dispositivo retransmite mensajes, extendiendo el alcance
• Sin tarjeta SIM, sin número de teléfono, sin registro
• Se empareja con teléfono vía Bluetooth para UI, pero la radio funciona independientemente
Opciones de hardware: Heltec V3 (~€25), LilyGO T-Beam (~€35), RAK WisBlock
Consideraciones operacionales: Las transmisiones LoRa pueden ser localizadas con equipos SDR (Radio Definida por Software). Usa canales cifrados. Los mensajes son cortos (solo texto). No apto para voz o imágenes. Legal en bandas ISM de la UE (868 MHz) pero verifica regulaciones locales para límites de potencia.
Analog backup: walkie-talkies & dead dropsRespaldo analógico: walkie-talkies y dead drops
Low-tech methods that have worked for decades.Métodos low-tech que han funcionado durante décadas.
• License-free in Europe (PMR446 band)
• Range: 1-5km urban, up to 10km open terrain
• NO encryption on consumer models, assume anyone can listen
• Use pre-agreed code words for sensitive information
• Change channels frequently during actions
• Models: Motorola TLKR T82, Baofeng BF-88E (check local legality of Baofeng)
Physical dead drops:
• Pre-agreed locations to leave physical messages or USB drives
• Use encrypted USB drives (VeraCrypt containers)
• Never go to the same dead drop location twice in a row
• Leave a signal (chalk mark, arranged objects) to indicate a drop is waiting
• Old-school but effective when digital is compromised
Emergency signal system: Pre-agree non-digital signals: specific social media posts that mean "I'm safe" or "I'm compromised" (a specific emoji, a phrase). This is your warrant canary on a personal level.Walkie-talkies PMR446 (Radio Móvil Privada):
• Sin licencia en Europa (banda PMR446)
• Alcance: 1-5km urbano, hasta 10km terreno abierto
• SIN cifrado en modelos de consumo, asume que cualquiera puede escuchar
• Usa palabras clave pre-acordadas para información sensible
• Cambia de canales frecuentemente durante acciones
• Modelos: Motorola TLKR T82, Baofeng BF-88E (verifica legalidad local de Baofeng)
Dead drops físicos:
• Ubicaciones pre-acordadas para dejar mensajes físicos o unidades USB
• Usa unidades USB cifradas (contenedores VeraCrypt)
• Nunca vayas a la misma ubicación de dead drop dos veces seguidas
• Deja una señal (marca de tiza, objetos arreglados) para indicar que hay un drop esperando
• Anticuado pero efectivo cuando lo digital está comprometido
Sistema de señales de emergencia: Pre-acuerda señales no digitales: publicaciones específicas en redes sociales que signifiquen "Estoy a salvo" o "Estoy comprometido" (un emoji específico, una frase). Este es tu warrant canary a nivel personal.
🎯Doxxing: Prevention & ResponseDoxxing: prevención y respuesta
Doxxing, the public release of your personal information, can endanger your safety, your family, and your livelihood. Prevention is 10x easier than response.El doxxing, la publicación pública de tu información personal, puede poner en peligro tu seguridad, tu familia y tu sustento. La prevención es 10 veces más fácil que la respuesta.
Audit your digital footprint (defensive OSINT)
Search for yourself the way an adversary would.
1. Google yourself: Full name, name + city, name + organization, phone number, email, username. Use incognito mode. Check Images tab too.
2. Search your email: Paste your email into
haveibeenpwned.com, see which breaches exposed your data.3. Search your username: Use
whatsmyname.app or Sherlock tool, finds every platform where your username exists.4. Reverse image search: Upload your profile photo to Google Images, TinEye, Yandex, see where your face appears.
5. Check data brokers: Search yourself on Spokeo, BeenVerified, Whitepages, Pipl (EU: check local equivalents). Request removal.
6. Archived content: Check web.archive.org for cached versions of old profiles, blogs, forum posts you forgot about.
Do this quarterly. Set a recurring reminder. New data surfaces constantly.
Separate your identities
Your activist identity and civil identity should never connect.
• Email: Separate ProtonMail/Tuta for activism. Never use it for anything personal. Never use it to sign up for commercial services.
• Phone: If possible, separate number for activist work (prepaid, cash-purchased).
• Username: Unique username per platform. Never reuse between activist and personal accounts. Use a password manager to track them.
• Photos: Different profile photos on activist vs personal accounts. AI can cross-reference faces across platforms.
• Writing style: Surprisingly effective for identification. Stylometry analysis can link anonymous writing to known authors. Vary sentence length, vocabulary, punctuation in anonymous work.
• Browser: Separate browser or profile for each identity. Firefox containers or Brave profiles work well.
• Payment: Never use personal payment methods for activist purchases. Cash or crypto for sensitive materials.
If you get doxxed: emergency response
Act fast. The first 24 hours are critical.
1. Document everything: Screenshot the doxx, the source, the distribution channels. This is evidence.
2. Alert your network: Trusted comrades, family, employer (if relevant). They may be contacted or targeted too.
3. Lock accounts: Change passwords on all accounts. Enable 2FA everywhere. Make all social media private.
4. Contact platforms: Report for doxxing/harassment on every platform where your info appears. Most have expedited review for doxxing.
First 24 hours:
5. Google removal request: Submit personal info removal at google.com/webmasters/tools/removals
6. Data broker removal: Submit opt-out requests to every broker showing your data.
7. Legal options: In the EU, GDPR gives you the right to request deletion. In Spain, the AEPD can act quickly. File a police report (in some jurisdictions doxxing is criminal).
8. Physical safety: If your address was leaked: vary your routine, inform neighbors, consider staying elsewhere temporarily. Contact local anti-fascist networks for support if the doxx comes from far-right sources.
Services that help: DeleteMe (paid, US-focused), Deseat.me (EU), JustDeleteMe (directory of account deletion links).
💰Financial Security for ActivistsSeguridad financiera para activistas
Money trails are the easiest way to map a network. Every transaction connects people, places, and activities. Financial surveillance is often more dangerous than digital surveillance.Los rastros de dinero son la forma más fácil de mapear una red. Cada transacción conecta personas, lugares y actividades. La vigilancia financiera es a menudo más peligrosa que la vigilancia digital.
Payment platforms as surveillance tools
Bizum, PayPal, Venmo, they see everything.
• Bizum (Spain): Linked to your bank account and national ID (DNI). Every transaction is traceable. Police access with court order. Bizum is the worst possible option for activist-related payments.
• PayPal: Full transaction history, IP logs, linked bank accounts. PayPal has frozen accounts of activist organizations (documented cases with BDS-related groups, Palestinian NGOs).
• Venmo: Public transaction feed by default (!). Even when set to private, metadata is retained. Venmo transaction data has been used in criminal investigations.
• Revolut/N26: Fintech banks share data with Europol upon request. Lower barrier than traditional banks in some cases.
• Apple Pay/Google Pay: Transaction metadata visible to Apple/Google in addition to the bank.
Key insight: Payment networks don't just show what you bought, they show WHO you're connected to. Police use transaction analysis to map entire networks from a single account.
Anonymous funding for collectives
How to fund activist work without leaving financial traces.
• Physical cash collection at meetings, no digital trace
• Cash-purchased prepaid cards (Visa/Mastercard gift cards) for online purchases
• Cash deposits at ATMs to collective accounts (varies by bank/country, check limits that trigger reporting)
Cryptocurrency (with caveats):
• Monero (XMR): Privacy-focused, untraceable by design. The best option for anonymous donations. Buy with cash at crypto ATMs.
• Bitcoin: NOT anonymous - pseudonymous. Every transaction is permanently public on the blockchain. Chain analysis tools (Chainalysis, Elliptic) can de-anonymize most addresses. CoinJoin and Lightning Network add privacy but require significant technical care. Only use with extensive precautions.
• Accept donations via BTCPay Server (self-hosted), no intermediary sees the transactions
Structuring collective finances:
• Designate one person as treasurer with a separate account for collective funds
• Rotate who makes purchases to distribute the risk
• Keep minimal records of who donated (need-to-know basis)
• In the EU, be aware of anti-money-laundering thresholds: cash transactions over €10,000 trigger automatic reporting. Multiple smaller transactions can trigger "structuring" suspicion.
Crowdfunding safely
When you need to raise money publicly.
• GoFundMe: Requires real identity to withdraw. Has frozen Palestinian solidarity fundraisers. Shares data with law enforcement.
• Patreon: Real identity required for payouts. Has deplatformed creators under political pressure.
• Ko-fi: Lower profile, but still requires identity for withdrawal via PayPal/Stripe.
Safer alternatives:
• Open Collective: Transparent finances through a fiscal host. Legal entity handles the money. Good for legitimate organizations.
• Liberapay: Open-source, Europe-based, supports anonymous donations (but recipient still identified).
• Direct crypto donations: Publish a Monero address. Donors remain anonymous. You remain pseudonymous until withdrawal.
• Mutual aid models: In-person cash collection, community fridges/supplies rather than money transfers, skill/time exchanges instead of financial transactions.
🏳️🌈Queer-Specific Digital ThreatsAmenazas digitales específicas LGBTQ+
Queer activists face unique digital threats: forced outing, dating app surveillance, targeted harassment, and legal risks in hostile jurisdictions. Digital security is literal safety.Les activistas queer enfrentan amenazas digitales únicas: outing forzado, vigilancia de apps de citas, acoso dirigido, y riesgos legales en jurisdicciones hostiles. La seguridad digital es seguridad literal.
📋 Phase 03 · Key Takeaways📋 Fase 03 · Puntos clave
Data Handling & Forensics DefenseManejo de datos y defensa forense
📸Secure Documentation & EvidenceDocumentación segura y evidencia
Documenting police violence and human rights abuses is essential. But doing it wrong can endanger you, your sources, and the people in your footage.Documentar la violencia policial y los abusos de derechos humanos es esencial. Pero hacerlo mal puede ponerte en peligro a ti, a tus fuentes, y a las personas en tu material.
Metadata scrubbing workflow
Clean every file before sharing, uploading, or publishing.
1. Shoot with the camera app (not social media apps)
2. Transfer to secure device or encrypted folder
3. Strip metadata:
• ExifTool:
exiftool -all= -overwrite_original *.jpg• mat2:
mat2 --inplace file.mp4 (works on video too)• ObscuraCam (Guardian Project, Android): records with face auto-blur
4. Blur faces: Signal's built-in blur, GIMP, or ffmpeg batch processing
5. Remove audio if it contains identifiable voices
6. Share via Signal or SecureDrop, never via email attachments or cloud links
For video:
•
ffmpeg -i input.mp4 -map_metadata -1 -c copy output.mp4 (strips metadata without re-encoding)• For audio removal:
ffmpeg -i input.mp4 -an -map_metadata -1 output.mp4• For face blur: use YouTube Studio's built-in blur tool (processes locally before upload)
Chain of custody for legal evidence
If your footage might be used in court, preservation matters.
• Never edit the original. Work only on copies. Store the untouched original in an encrypted container.
• Hash the original: Generate SHA-256 hash immediately:
sha256sum video.mp4. Store the hash separately. This proves the file wasn't altered.• Document the context: Write down: date, time, location, what you witnessed, your vantage point. Do this immediately while memory is fresh.
• Timestamp proof: Email the hash to yourself (creates a third-party timestamp), or use OpenTimestamps (blockchain anchoring).
• Storage: Multiple encrypted backups in different physical locations. Don't rely on a single device.
• Transfer to lawyers/NGOs: Use SecureDrop, OnionShare, or hand-deliver on an encrypted USB. Never use WeTransfer, Google Drive, or Dropbox for evidence.
Organizations that accept evidence: WITNESS.org, Bellingcat, Syrian Archive model. In Europe: ECCHR (Berlin), Forensic Architecture.
Tools for documentalists
Purpose-built tools for safe documentation.
• ProofMode (Guardian Project): adds cryptographic signatures and metadata for verification while protecting identity
• ObscuraCam (Android): auto-detects and blurs faces during recording
• Tella (Android/iOS): encrypted camera app designed for human rights documentation. Files encrypted on device, can auto-upload to secure server.
Secure transfer:
• SecureDrop: Used by major news organizations. Tor-based, anonymous submission.
• OnionShare: Peer-to-peer file sharing over Tor. No server, no accounts, no traces.
• Dangerzone: (EFF-recommended) Converts potentially dangerous documents to safe PDFs.
Archival:
• Hunchly: Captures and preserves web evidence with hashes for legal proceedings.
• ArchiveBox: Self-hosted web archiving. Save social media posts before they're deleted.
exiftool -all= -overwrite_original *.jpg (desktop) or the Scrambled Exif app (mobile).Elimina metadatos EXIF. Cada foto incrusta GPS, modelo del dispositivo, fecha y número de serie. Usa exiftool -all= -overwrite_original *.jpg (escritorio) o la app Scrambled Exif (móvil).
2
Blur every face, tattoo, and distinctive clothing. Facial recognition runs on social media at scale within minutes of upload. Use Signal's built-in blur (tap photo, edit, blur), ObscuraCam for batch video, or ffmpeg for command-line processing. Background details (signs, buildings, vehicles) can also identify location; blur or crop those too.Difumina cada cara, tatuaje y ropa distintiva. El reconocimiento facial procesa redes sociales a escala en minutos. Usa el desenfoque integrado de Signal (toca foto, editar, desenfoque), ObscuraCam para vídeo en lote, o ffmpeg para procesamiento por línea de comandos. Los detalles del fondo (carteles, edificios, vehículos) también pueden identificar la ubicación; difumínalos o recórtalos también.
3
Share only via Signal. WhatsApp re-uploads to Meta's servers. Email attachments are logged. Social media apps re-inject new metadata. Signal-to-Signal is the only safe transfer.Comparte solo por Signal. WhatsApp sube a los servidores de Meta. Los adjuntos de correo se registran. Las apps de redes sociales re-inyectan nuevos metadatos. Signal a Signal es la única transferencia segura.
4
Keep the original locked. Never share unprocessed originals. Store originals in an encrypted folder (VeraCrypt/Cryptomator). If the footage has legal value, hash it immediately: sha256sum file.jpgGuarda el original bajo llave. Nunca compartas originales sin procesar. Guarda los originales en una carpeta cifrada (VeraCrypt/Cryptomator). Si el material tiene valor legal, genera su hash inmediatamente: sha256sum file.jpg
⚠ One unblurred face shared to Twitter is enough for police facial recognition to identify the person within hours. This is not hypothetical; it has happened.⚠ Una cara sin difuminar publicada en Twitter es suficiente para que el reconocimiento facial policial identifique a la persona en horas. Esto no es hipotético; ha ocurrido.
📄Secure Documents: CryptPad vs RiseUpDocumentos seguros: CryptPad vs RiseUp
Google Docs is a surveillance tool. Every document you edit is stored in plaintext on Google's servers, readable with a subpoena and accessible to any insider. Activist planning, legal strategy, and contact lists have no business being there. Here's what to use instead.Google Docs es una herramienta de vigilancia. Cada documento que editas se almacena en texto plano en los servidores de Google, legible con una citación y accesible a cualquier persona interna. La planificación activista, la estrategia legal y las listas de contactos no tienen nada que hacer ahí. Aquí está lo que usar en cambio.
❌ RiseUp Pad❌ RiseUp Pad
The server can reconstruct the text from traffic logs. The police don't need your device.El servidor puede reconstruir el texto de los logs de tráfico. La policía no necesita tu dispositivo.
✅ CryptPad✅ CryptPad
End-to-end encryption. The server cannot read your documents if you use them correctly.Cifrado de extremo a extremo. El servidor no puede leer tus documentos si los usas correctamente.
How to use CryptPad securelyCómo usar CryptPad de forma segura
🌐Secure BrowsingNavegación segura
Sensitive info → Tor BrowserInfo sensible → Tor Browser
On a COMPUTER. On phone it doesn't offer the same guarantees.En un ORDENADOR. En móvil no ofrece las mismas garantías.
Tor routes your traffic through three random encrypted servers. Neither your ISP, the sites you visit, nor intermediate nodes can simultaneously see who you are and what you visit.
Rules when using Tor:
• Don't log into personal accounts (Gmail, social media)
• Don't download torrents over Tor
• Don't maximize the browser window (window size can identify you)
• Don't install additional extensions
• On phone, Tor Browser exists but the OS can leak data through other channels. Use Tor on a computer or with Tails.Descargar: torproject.org > Download Tor Browser
Tor enruta tu tráfico a través de tres servidores cifrados aleatorios. Ni tu ISP, los sitios que visitas, ni los nodos intermedios pueden ver simultáneamente quién eres y qué visitas.
Reglas al usar Tor:
• No inicies sesión en cuentas personales (Gmail, redes sociales)
• No descargues torrents por Tor
• No maximices la ventana del navegador (el tamaño de ventana puede identificarte)
• No instales extensiones adicionales
• En móvil, Tor Browser existe pero el SO puede filtrar datos por otros canales. Usa Tor en un ordenador o con Tails.
Everyday use → DuckDuckGoUso diario → DuckDuckGo
Default browser on your phone.Navegador por defecto en tu móvil.
Set as default:
iPhone: Settings > DuckDuckGo > Default Browser App
Android: Settings > Apps > Default apps > Browser app
DuckDuckGo blocks trackers, deletes cookies when closing tabs, and doesn't store search history on their servers. Never open links in Chrome.
Brave as a second option: blocks ads and trackers by default. More features than DuckDuckGo but a more complex business model.Instalar: Busca "DuckDuckGo" en tu tienda de apps.
Establecer como predeterminado:
iPhone: Ajustes > DuckDuckGo > App de navegador predeterminada
Android: Ajustes > Apps > Apps predeterminadas > App de navegador
DuckDuckGo bloquea rastreadores, elimina cookies al cerrar pestañas, y no almacena historial de búsqueda en sus servidores. Nunca abras enlaces en Chrome.
Brave como segunda opción: bloquea anuncios y rastreadores por defecto. Más funciones que DuckDuckGo pero un modelo de negocio más complejo.
🧹Metadata HygieneHigiene de metadatos
Files: remove metadataArchivos: elimina metadatos
Location, date, camera model, OS username...Ubicación, fecha, modelo de cámara, nombre de usuario del SO...
Easiest way:
1. Take photos directly in Signal (Signal doesn't save location metadata)
2. Or send photos to yourself via Signal: open the "Note to Self" conversation, send the photo, download it. Signal automatically removes metadata.
Web tool: metadata.systemli.org, upload your file and download it clean.
On computer: On Linux, install
mat2 (apt install mat2) and run mat2 filename.jpg.GrapheneOS: The camera doesn't save metadata. No extra steps needed.Los archivos (fotos, PDFs, documentos Word) contienen metadatos: coordenadas GPS, fecha y hora exactas, modelo de cámara, nombre de usuario del ordenador que lo creó, a veces historial de edición.
Forma más fácil:
1. Toma fotos directamente en Signal (Signal no guarda metadatos de ubicación)
2. O envíate fotos a ti mismo por Signal: abre la conversación "Nota para mí", envía la foto, descárgala. Signal elimina automáticamente los metadatos.
Herramienta web: metadata.systemli.org, sube tu archivo y descárgalo limpio.
En ordenador: En Linux, instala
mat2 (apt install mat2) y ejecuta mat2 nombrearchivo.jpg.GrapheneOS: La cámara no guarda metadatos. No se necesitan pasos extra.
Links: clean trackingEnlaces: limpia el rastreo
Platforms add parameters that identify you.Las plataformas añaden parámetros que te identifican.
?utm_source=, ?fbclid=, ?si= that identify who shared the link.Solution: linkcleaner.app, Paste the link, copy the clean link.
Also: Don't share Google Maps links that include your starting coordinates. Copy only the destination coordinates.Cuando copias un enlace de Facebook, Instagram, Twitter, Google, o cualquier plataforma, normalmente añaden parámetros como
?utm_source=, ?fbclid=, ?si= que identifican quién compartió el enlace.Solución: linkcleaner.app, Pega el enlace, copia el enlace limpio.
También: No compartas enlaces de Google Maps que incluyan tus coordenadas de inicio. Copia solo las coordenadas de destino.
📝Secure Information StorageAlmacenamiento seguro de información
Where you store sensitive notes, passwords, and documents matters as much as how you communicate. The wrong app is a direct pipeline to potential adversaries.Dónde almacenas notas, contraseñas y documentos sensibles importa tanto como cómo te comunicas. La app equivocada es un pipeline directo hacia adversarios potenciales.
KeePass: recommended password manager
Open source, works offline, you control the file.
Android: KeePassDX (on F-Droid or Play Store)
iPhone: Strongbox or KeePassium
KeePass stores everything in an encrypted file (.kdbx) that you control. It doesn't depend on any server. You can sync the file via CryptPad, Signal "Note to Self," or a USB drive.
ProtonPass is an easier-to-use alternative (browser extension + app), with automatic syncing. But it depends on Proton's servers.
Rule: move directly, not "temporarily"
Never put sensitive data in insecure apps first "to move later." Move information directly from Signal to the manager. Use Signal's 4-week timer so you don't forget to delete temporary notes.
🔏Document SanitizationSanitización de documentos
Redacting sensitive information from documents is harder than it looks. Common methods leave data fully recoverable.Redactar información sensible de documentos es más difícil de lo que parece. Los métodos comunes dejan los datos completamente recuperables.
🚫 Why the "black highlighter" in PDFs doesn't work
PDF redaction tools often just draw a black rectangle OVER the text · the text is still there underneath.
• Simply selecting all text (Ctrl+A) and pasting into a text editor
• Opening the PDF in a text editor and reading raw strings
• Using tools like
pdftotext or strings file.pdf• Removing the annotation layer programmatically
Real-world failures:
• In 2011, the US TSA accidentally published SSNs under black bars in a PDF
• Court documents have repeatedly leaked redacted information
• Government agencies have exposed classified information this way
Same problem applies to: Microsoft Word (black highlighting), Google Docs (dark backgrounds), image editors that use layers (Photoshop, GIMP if you save with layers).
✅ Safe redaction methods
Methods that actually destroy the underlying data.
1. Print the document on paper
2. Use a thick black marker to cross out sensitive information (press hard, multiple passes)
3. Hold the paper up to a light to verify nothing is visible through the ink
4. Scan the document back to PDF
5. Run the scanned PDF through
mat2 to remove scan metadataThis works because the scanner only captures what is visible · the underlying text is physically destroyed by the marker ink.
Method 2: Dangerzone (digital, EFF-recommended)
• Download from dangerzone.rocks (available for Windows, macOS, Linux)
• Opens documents inside a disposable sandbox (container)
• Converts the document to raw pixel data, then reconstructs a clean PDF
• All hidden text, macros, metadata, tracking pixels, and embedded code are destroyed
• Also protects you from malicious documents (macros, exploits)
Method 3: Proper PDF redaction tools
• LibreOffice Draw: Open PDF → delete the text objects (not cover them) → export as new PDF
• PDF-Redact-Tools (by Micah Lee/The Intercept): Command-line tool that actually removes text from the PDF structure
• Adobe Acrobat Pro: Has a real "Redaction" tool (NOT the highlighter) that removes underlying data. But it's proprietary software.
📦Sandboxing: Opening Suspicious Files SafelySandboxing: abrir archivos sospechosos con seguridad
When you receive a document, USB drive, or file from an unknown or semi-trusted source, opening it directly on your main system is a risk. A compromised file can install malware, exfiltrate data, or take control of your device.Cuando recibes un documento, unidad USB, o archivo de una fuente desconocida o semi-confiable, abrirlo directamente en tu sistema principal es un riesgo. Un archivo comprometido puede instalar malware, exfiltrar datos, o tomar control de tu dispositivo.
Virtual Machines (VirtualBox)
Open suspicious files inside a disposable virtual computer.
Quick setup:
1. Install VirtualBox (virtualbox.org, free, open-source)
2. Download a Linux ISO (Ubuntu or Fedora)
3. Create a new VM, install Linux, take a snapshot of the clean state
4. Open suspicious files inside the VM
5. When done, revert to the clean snapshot · any malware is destroyed
Key rules:
• Disable shared folders between VM and host
• Disable clipboard sharing (malware can escape via clipboard)
• Don't give the VM network access unless necessary
• Use snapshots: always revert to clean state after opening untrusted files
• The VM should have NO access to your real files
Qubes OS: security through compartmentalizationQubes OS: seguridad mediante compartimentación
The most secure approach: every task runs in a separate VM.El enfoque más seguro: cada tarea se ejecuta en una VM separada.
• Personal qube: Your personal browsing, email
• Work qube: Separate browser sessions, documents
• Untrusted qube: For opening suspicious files · completely isolated
• Vault qube: No network access, stores passwords and keys
• Disposable qubes: Single-use VMs that are destroyed after closing
Even if malware compromises one qube, it cannot access others. Used by Edward Snowden, recommended by Freedom of the Press Foundation.
Limitations: Requires dedicated hardware (doesn't run well inside another OS), steep learning curve, and high RAM usage (16GB minimum). For advanced users and high-risk activists.Qubes OS (qubes-os.org) lleva el sandboxing al extremo: tu sistema operativo entero se divide en compartimentos (llamados "qubes"), cada uno ejecutándose en su propia VM:
• Qube personal: Tu navegación personal, email
• Qube de trabajo: Sesiones de navegador separadas, documentos
• Qube no confiable: Para abrir archivos sospechosos · completamente aislado
• Qube bóveda: Sin acceso a red, almacena contraseñas y claves
• Qubes desechables: VMs de un solo uso que se destruyen al cerrar
Incluso si el malware compromete un qube, no puede acceder a otros. Usado por Edward Snowden, recomendado por Freedom of the Press Foundation.
Limitaciones: Requiere hardware dedicado (no funciona bien dentro de otro SO), curva de aprendizaje pronunciada, y alto uso de RAM (16GB mínimo). Para usuarios avanzados y activistas de alto riesgo.
Quick alternative: DangerzoneAlternativa rápida: Dangerzone
Don't need a full VM? Dangerzone sandboxes documents automatically.¿No necesitas una VM completa? Dangerzone aísla documentos automáticamente.
When to use what:
• Dangerzone: For documents (PDF, DOC, XLS, images) · quick, easy, no setup
• VirtualBox: For anything else (executables, USB drives, complex file types)
• Qubes OS: If your threat model requires permanent compartmentalizationDangerzone (dangerzone.rocks) abre documentos (PDF, Office, imágenes) dentro de un contenedor temporal, los convierte a píxeles seguros, y produce un PDF limpio. Es como una VM desechable específicamente para documentos.
Cuándo usar qué:
• Dangerzone: Para documentos (PDF, DOC, XLS, imágenes) · rápido, fácil, sin configuración
• VirtualBox: Para cualquier otra cosa (ejecutables, unidades USB, tipos de archivo complejos)
• Qubes OS: Si tu modelo de amenazas requiere compartimentación permanente
🧠AI OPSEC: What They Use Against You & How to RespondIA y OPSEC: Lo que usan contra ti y cómo responder
We Do Not Recommend Using AI ToolsNo recomendamos usar herramientas de IA
We strongly urge you to avoid using AI tools entirely. The use of AI carries serious ethical implications and a significant negative environmental impact on our planet. Large AI models consume enormous quantities of energy and water, accelerate carbon emissions, and are built on labour practices and data extraction that harm communities worldwide. These costs are not abstract; they are paid by the most vulnerable people and ecosystems on Earth. Instamos encarecidamente a evitar el uso de herramientas de IA por completo. El uso de IA conlleva graves implicaciones éticas y un impacto ambiental negativo significativo en nuestro planeta. Los grandes modelos de IA consumen enormes cantidades de energía y agua, aceleran las emisiones de carbono y se construyen sobre prácticas laborales y extracción de datos que dañan a comunidades de todo el mundo.
From an activist security standpoint, AI is also one of the most dangerous tools you can use carelessly. Every query you type is a permanent, subpoena-accessible log. Please do not use AI assistants for any sensitive, operational, or movement-related work. Desde un punto de vista de seguridad activista, la IA también es una de las herramientas más peligrosas que puedes usar descuidadamente. Cada consulta que escribes es un registro permanente y accesible mediante orden judicial. Por favor, no uses asistentes de IA para ningún trabajo sensible, operacional o relacionado con el movimiento.
If you choose to proceed despite this warning, the operational security information you need is documented below. Understanding the risks is essential whether or not you decide to use these tools. Si decides continuar a pesar de esta advertencia, la información de seguridad operacional que necesitas está documentada a continuación.
AI has fundamentally changed the threat landscape. It has made surveillance cheaper, phishing more convincing, and evidence fabrication trivially easy. But it has also created new exposure for activists who use AI carelessly. This section covers both directions: how AI is weaponized against you, and how your own AI use creates surveillance trails.La IA ha cambiado fundamentalmente el panorama de amenazas. Ha hecho la vigilancia más barata, el phishing más convincente y la fabricación de evidencias trivialmente fácil. Esta sección cubre ambas direcciones: cómo se usa la IA contra ti, y cómo tu propio uso de IA crea rastros de vigilancia.
Deepfakes & Voice CloningDeepfakes y clonación de voz
As little as 30–60 seconds of audio can clone your voice convincingly. Fabricated video can place you at scenes, discredit you, or split your movement.Con tan solo 30–60 segundos de audio se puede clonar tu voz de forma convincente. El vídeo fabricado puede colocarte en escenas o desacreditarte.
AI-Powered PhishingPhishing potenciado con IA
Hyper-personalized attacks built from your social media. Perfect grammar. Timed for when you're most distracted.Ataques hiperpersonalizados construidos con tus redes. Gramática perfecta. Cronometrados para cuando estás más distraído.
Chatbot Surveillance TrailsRastros de vigilancia en chatbots
Every prompt you type is stored, linked to your account, and fully subpoena-accessible. ChatGPT is a wiretapped phone.Cada prompt que escribes se almacena, vincula a tu cuenta y es accesible mediante orden judicial.
Predictive Policing & OSINTPredicción policial y OSINT
AI aggregates public data at scale to build profiles, predict actions, and identify networks. Already deployed in US and EU cities.La IA agrega datos públicos a escala para crear perfiles, predecir acciones e identificar redes.
🗡️ Part 1: How AI Is Weaponized Against You🗡️ Parte 1: Cómo se usa la IA contra ti
These are offensive AI attacks: technology used by adversaries to impersonate, discredit, or manipulate activists and their communities.Estos son ataques ofensivos de IA: tecnología usada por adversarios para suplantar, desacreditar o manipular a activistas y sus comunidades.
🎤 Voice cloning attacks🎤 Ataques de clonación de voz
30–60 seconds of audio is enough to clone your voice convincingly - and tools improve rapidly. Clips as short as 3 seconds exist but produce lower-quality results. This is not theoretical: it is operational.30–60 segundos de audio son suficientes para clonar tu voz de forma convincente - y las herramientas mejoran rápidamente. Existen clips de tan solo 3 segundos pero producen resultados de menor calidad. Esto no es teórico: es operacional.
Fake voice messages: Signal voice notes impersonating a comrade to extract information or trigger bad decisions.
Phone impersonation: Calling your lawyer, family, or collective pretending to be you.
Evidence fabrication: Creating fake audio of statements you never made.
Defenses:
• Establish a voice code phrase: a word spoken in every sensitive call that proves authenticity
• Be skeptical of urgent voice messages requesting actions, money, or sensitive info
• Always verify through a separate channel (if a voice note on Signal, call back directly)
• Minimize public audio: podcasts, interviews, and social videos are training data Las herramientas modernas pueden replicar una voz a partir de un clip de podcast, video o nota de voz. Esto permite: mensajes de voz falsos, suplantación telefónica y fabricación de evidencias.
Defensas: Establece una frase de código de voz, verifica siempre a través de un canal separado, minimiza el audio público.
🎬 Deepfake video & image fabrication🎬 Fabricación de vídeo e imágenes deepfake
Fabricated video can discredit activists, fabricate evidence, or be used for harassment. Detection is getting harder each year.El vídeo fabricado puede desacreditar a activistas, fabricar evidencias o usarse para acoso.
• Discrediting: Fabricated video of you at a compromising location or making inflammatory statements
• Harassment: Non-consensual intimate imagery (especially targeting women and LGBTQ+ activists)
• False evidence: Placing you at a scene or fabricating incriminating footage
• Movement splitting: Fake video of leaders making statements to fragment coalitions
Detection indicators:
Inconsistent lighting on face vs background · Unnatural eye movements or blinking · Artifacts around hairline and ears · Audio-lip sync slightly off · Malformed hands and fingers
Defenses: Use C2PA/Content Credentials metadata to prove authenticity of your own media. Document your actual whereabouts. Report deepfakes immediately. Indicadores de detección: iluminación inconsistente, movimientos oculares antinaturales, artefactos en el contorno del cabello. Defensa: usa metadatos C2PA para probar la autenticidad de tus propios medios.
🎣 AI-powered phishing & social engineering🎣 Phishing e ingeniería social potenciados con IA
AI makes phishing hyper-personalized, grammatically perfect, and precisely timed for moments of stress.La IA hace el phishing hiperpersonalizado, gramaticalmente perfecto y cronometrado para momentos de estrés.
• Personalization at scale: Scrapes your social media and writes a message referencing your real activities, friends, and interests
• No more typos: Perfect grammar eliminates the main red flag activists learned to spot
• Multi-modal attacks: AI voice call followed by a "verification" email, each reinforcing the other
• Timed for stress: Sent during actions, after arrests, or other moments when you're least careful
Defenses:
• Verify all unusual requests through a separate, pre-established channel
• Use hardware security keys (YubiKey/Nitrokey): they verify the actual domain, AI phishing can't bypass this
• Establish group verification protocols for requests involving money, access, or sensitive info
• Urgency is the trigger. Pause. Verify. La IA personaliza ataques de phishing a escala, con gramática perfecta y cronometrados para momentos de estrés. Defensa: verifica a través de canal separado, usa llaves de seguridad hardware, pausa ante la urgencia.
📊 Predictive policing & AI-powered OSINT📊 Predicción policial y OSINT potenciado por IA
AI systems aggregate open-source data at scale to build profiles, predict actions, and map activist networks automatically.Los sistemas de IA agregan datos de fuentes abiertas a escala para crear perfiles y mapear redes de activistas.
• Cross-reference social media, public records, and photos to build profiles automatically
• Analyze patterns in protest activity, movement data, and online behavior to predict future actions
• Map second and third-degree social connections from metadata alone
• Flag individuals from watchlists across multiple camera networks in real time
Deployed systems: Palantir (US, UK, EU cities), PredPol, ShotSpotter. Already operational in multiple US and EU jurisdictions for monitoring activist groups.
Defenses: Minimize your public digital footprint. Scrub metadata from all shared content. Separate activist identity from personal identity online. Sistemas como Palantir agregan datos de redes sociales, registros públicos y fotos para crear perfiles automáticamente. Ya están operativos en múltiples ciudades de EE.UU. y la UE.
📡 Part 2: When You Use AI, You Create Surveillance Trails📡 Parte 2: Cuando usas IA, creas rastros de vigilancia
This is the less obvious threat: not AI used against you, but AI used by you. ChatGPT, Claude, Gemini, and similar tools are productivity apps with a surveillance architecture underneath. Every question you type is logged, linked to your account, associated with your IP, and fully accessible to law enforcement under legal process.Esta es la amenaza menos obvia: no la IA usada contra ti, sino la IA usada por ti. ChatGPT, Claude, Gemini y similares son apps de productividad con una arquitectura de vigilancia debajo. Todo lo que escribes queda registrado.
Chat logs are subpoena-accessibleLos registros de chat son accesibles judicialmente
OpenAI, Google, and Meta can and do comply with court orders. Never discuss operations, names, or plans with any cloud AI tool.OpenAI, Google y Meta cumplen con órdenes judiciales. Nunca discutas operaciones, nombres o planes con ninguna herramienta de IA en la nube.
Image generation leaves trailsLa generación de imágenes deja rastros
AI-generated images often contain invisible C2PA watermarks and metadata linking them back to the specific account that created them.Las imágenes generadas por IA a menudo contienen marcas de agua C2PA invisibles que las vinculan a la cuenta que las creó.
Account linkageVinculación de cuentas
Most AI platforms require real email addresses. Your queries can be linked to your identity, location, device, and browsing patterns.La mayoría de plataformas de IA requieren correos reales. Tus consultas pueden vincularse a tu identidad, ubicación y dispositivo.
Training data exposureExposición de datos de entrenamiento
Some platforms use your conversations for model training. Sensitive details you share could theoretically resurface in model outputs to other users.Algunas plataformas usan tus conversaciones para entrenar modelos. Los detalles sensibles que compartes podrían resurgir en respuestas a otros usuarios.
🛡️ Part 3: Your Defense Strategy🛡️ Parte 3: Tu estrategia de defensa
Three tiers, in order of preference. Always start at tier 1 and only descend when genuinely unavoidable.Tres niveles, en orden de preferencia. Comienza siempre en el nivel 1 y desciende solo cuando sea genuinamente inevitable.
🥇 Tier 1 (Best): Avoid AI entirely: use offline & open-source alternatives🥇 Nivel 1 (Mejor): Evitar la IA por completo: usar alternativas offline y de código abierto
Every common AI use-case has a privacy-respecting, zero-surveillance alternative. This is always the first choice.Cada caso de uso habitual de IA tiene una alternativa que respeta la privacidad. Esta es siempre la primera opción.
• LibreTranslate: self-hostable, no data sent externally. Run locally:
pip install libretranslate• Argos Translate: fully offline, open-source
• DeepL (no account, private window): don't paste sensitive content
Writing / editing / summarizing:Escritura / edición / resumen:
• A human collaborator you trust
• LanguageTool: offline grammar checker
• Hemingway App: browser-based, no server-side storage
Research / search:Investigación / búsqueda:
• SearXNG: self-hosted anonymous meta-search
• Brave Search or DuckDuckGo over Tor Browser
Image editing:Edición de imágenes:
• GIMP: powerful open-source editor, fully offline
• Inkscape: vector graphics, offline
• Stable Diffusion (local) via AUTOMATIC1111 or ComfyUI: no data leaves your device
Code assistance:Asistencia de código:
• Ollama + CodeLlama: self-hosted, runs entirely on your machine
• Stack Overflow, official documentation, community forums
🥈 Tier 2 (Acceptable): Run AI locally on your own device🥈 Nivel 2 (Aceptable): Ejecutar IA localmente en tu propio dispositivo
Local AI eliminates the surveillance risk entirely. Your queries never leave your device. No accounts. No logs. No legal exposure.La IA local elimina el riesgo de vigilancia por completo. Tus consultas nunca salen de tu dispositivo. Sin cuentas. Sin registros.
curl -fsSL https://ollama.com/install.sh | shollama run llama3Recommended local models:Modelos locales recomendados:
• LLaMA 3 (Meta, open weights): strong general assistant
• Mistral 7B: fast, lightweight, excellent for most tasks
• Phi-3 Mini: runs on 4GB RAM, very efficient
Hardware requirements:Requisitos de hardware:
• Minimum: 8GB RAM for 7B models (CPU-only, slow but functional)
• Recommended: 16GB RAM + GPU for good speeds
• LM Studio (lmstudio.ai): graphical interface, no terminal needed
🥉 Tier 3 (Last resort): Cloud AI with strict isolation protocol🥉 Nivel 3 (Último recurso): IA en la nube con protocolo de aislamiento estricto
Only if Tier 1 and 2 are genuinely not possible. Apply every step of this protocol without exception.Solo si los niveles 1 y 2 no son genuinamente posibles. Aplica cada paso de este protocolo sin excepción.
• Open Tor Browser: never your regular browser
• Create a throwaway account with ProtonMail or Tuta: no link to your identity
• Use a public WiFi network not associated with home/work/routine locations
• Enable Mullvad VPN before connecting
During:Durante:
• Disable chat history upon account creation (OpenAI: Settings → Data Controls → toggle off)
• Never type real names, locations, dates, group names, or operational details
• Replace all real details with generic placeholders: "a person", "a city", "an organization"
• Never upload documents, photos, or files containing metadata
• Limit each session to one narrow task: don't let context accumulate
After:Después:
• Delete the conversation immediately from the platform's history
• Clear all browser data and cookies
• Do not reuse the same throwaway account across different tasks
🔬Spyware Detection: Pegasus & State-Level ThreatsDetección de spyware: Pegasus y amenazas de nivel estatal
Pegasus doesn't announce itself. It arrives through a zero-click exploit: no link to tap, no file to open. From that moment your microphone, camera, and every message are streamed to a foreign server. This section is for activists who may already be targets.Pegasus no se anuncia. Llega a través de un exploit zero-click: sin enlace que tocar, sin archivo que abrir. Y desde ese momento tu micrófono, cámara y cada mensaje se transmiten a un servidor extranjero. Esta sección es para activistas que ya pueden ser objetivos.
As discussed in Module 1, Pegasus (NSO Group) is state-level spyware capable of infecting phones without any user interaction (zero-click exploits). Once installed, it gives the attacker total access: camera, microphone, messages, location, passwords, everything. Its use has been documented in Spain (CatalanGate, 65+ targets), Mexico (journalists and human rights lawyers), India, Hungary, and dozens of other countries. If your threat model includes state-level adversaries, knowing how to check for infection is critical.Como se discutió en el Módulo 1, Pegasus (NSO Group) es spyware de nivel estatal capaz de infectar teléfonos sin ninguna interacción del usuario (exploits zero-click). Una vez instalado, da al atacante acceso total: cámara, micrófono, mensajes, ubicación, contraseñas, todo. Su uso ha sido documentado en España (CatalanGate, 65+ objetivos), México (periodistas y abogados de derechos humanos), India, Hungría, y docenas de otros países. Si tu modelo de amenazas incluye adversarios de nivel estatal, saber cómo comprobar si hay infección es crítico.
📱 iOS (iPhone / iPad)📱 iOS (iPhone / iPad)
The best-supported platform for spyware forensics. Most Pegasus research has focused on iOS.La plataforma mejor soportada para forense de spyware. La mayoría de la investigación de Pegasus se ha centrado en iOS.
Created by Amnesty International's Security Lab. The gold standard for forensic analysis. MVT scans a full iTunes backup (or filesystem dump) against known Indicators of Compromise (IOCs) maintained by Amnesty Tech and Citizen Lab. iOS analysis is the most thorough because iOS keeps detailed system logs that spyware struggles to erase completely.
How to use it:
1. On a separate, trusted computer:
pip install mvt2. Create a full encrypted iTunes backup of the iPhone (encryption unlocks more data for analysis)
3. Download the latest IOCs:
git clone https://github.com/AmnestyTech/investigations4. Run:
mvt-ios check-backup --iocs indicators.stix2 /path/to/backup5. Review output. Flagged indicators appear with timestamps and matched IOC names
Detects: Pegasus, Predator (Cytrox/Intellexa), QuaDream's Reign, and any spyware with published IOCs.
Limitations: Command-line only. Requires Python. Only finds known IOC patterns. A new zero-day with no published trace will not be detected.
GitHub: mvt-project/mvt Amnesty IOCs
2. iMazing Spyware Analyzer (GUI, non-technical users)
A commercial Mac/Windows application that wraps MVT's analysis engine in a graphical interface. Connect your iPhone via USB, click scan, get a readable report. No command line required.
• Scans for Pegasus, Predator, and other known spyware families
• The spyware detection feature is completely free, no license purchase needed
• Same IOC-based detection as MVT, same fundamental limitation (known traces only)
iMazing Spyware Analyzer
3. Shutdown.log analysis (Kaspersky method)
Kaspersky's Global Research and Analysis Team (GReAT) discovered that iOS logs reboot events in a file called
shutdown.log, and that certain Pegasus processes leave traces there. Since Pegasus does not survive a reboot, regularly restarting your iPhone and then analyzing this log can reveal past infections. MVT can parse this log automatically. This is a lightweight, complementary check, not a full forensic scan.4. Apple Lockdown Mode (prevention, not detection)
Not a scanner, but a critical hardening measure. Lockdown Mode (iOS 16+) disables many attack surfaces that Pegasus exploits: message preview parsing, JIT JavaScript compilation, most shared albums, and unknown USB connections. If you face state-level threats, enable it: Settings → Privacy & Security → Lockdown Mode. Some features will be restricted, but the reduction in attack surface is substantial.
🤖 Android🤖 Android
Fewer forensic traces than iOS, but several tools cover different threat levels.Menos rastros forenses que iOS, pero varias herramientas cubren diferentes niveles de amenaza.
MVT also supports Android, though analysis is more limited than iOS because Android retains fewer system logs. MVT can analyze an ADB backup or scan installed APK packages for known malicious indicators.
How to use it:
1. Enable USB debugging on the Android device
2. On a trusted computer:
pip install mvt3. Run:
mvt-android check-adb --iocs indicators.stix24. MVT scans SMS messages for malicious links, installed APKs for known spyware packages, and the limited system logs available
Limitations: Android's sandboxing model means spyware traces are harder to find. ADB backups capture less data than iOS iTunes backups. Full filesystem analysis requires root access, which most users don't have.
GitHub: mvt-project/mvt
2. Hypatia (real-time scanner, open-source)
A free, open-source malware scanner developed by the DivestOS project. Available on F-Droid (not Google Play). Provides real-time and on-demand signature-based scanning.
• Good for detecting common Android malware, trojans, adware, and stalkerware (commercial spying apps installed by abusive partners or employers)
• Real-time scanning of new files and downloads
• No telemetry, no ads, no tracking. Fully open-source
• Limitation: Signature-based detection is not effective against state-level spyware like Pegasus, which uses zero-day exploits and sophisticated evasion. Hypatia is excellent for everyday threats but insufficient for nation-state actors
Hypatia on F-Droid
3. Google Play Protect (built-in, basic)
Enabled by default on all Google-certified Android devices. Scans installed apps and new downloads against Google's malware database. Better than nothing, but relies on Google's cloud scanning, offers no protection against state-level threats, and does not exist on de-Googled ROMs like GrapheneOS or CalyxOS. Consider it a baseline, not a defense.
4. GrapheneOS hardening (prevention)
Not a scanner, but the most effective Android defense. GrapheneOS removes Google services, hardens the kernel, enforces strict app sandboxing, and provides per-app network/sensor toggles. It significantly reduces the attack surface available to spyware. Pixel phones only.
🍎 macOS
Objective-See's free tools are the gold standard for macOS threat detection.
Scans all known persistence locations on macOS: launch daemons, agents, kernel extensions, login items, browser extensions, and more. Lists everything that is set to run automatically, letting you identify anything suspicious. Think of it as an audit of what has installed itself permanently on your system.
• Free, open-source
• One-time scan (not real-time)
KnockKnock
2. BlockBlock (Objective-See)
Real-time persistence monitor. Alerts you the moment any process tries to install itself persistently (launch daemons, login items, etc.). If spyware tries to survive a reboot by registering a persistence mechanism, BlockBlock will catch it and alert you.
• Free, open-source, runs as a daemon
BlockBlock
3. LuLu (Objective-See)
A free, open-source macOS firewall that alerts you when any process attempts an outbound network connection for the first time. Spyware must exfiltrate data. LuLu makes that visible. You can block unknown or suspicious connections on the spot.
LuLu Firewall
4. OverSight (Objective-See)
Monitors your Mac's microphone and camera. Alerts you whenever a process activates either one, even if the hardware LED is suppressed (some exploits can bypass the LED). Essential for detecting spyware that silently records audio or video.
OverSight
5. ClamAV (open-source antivirus)
An open-source, signature-based antivirus engine. Good for scanning files and email attachments for known malware. Install via Homebrew:
brew install clamav. Run a scan: clamscan -r /path/to/scan. Update signatures first: freshclam. Not effective against state-level threats but useful as a general-purpose scanner.Recommended stack: Run KnockKnock for a one-time audit, then keep BlockBlock + LuLu + OverSight running permanently. This combination covers persistence, network exfiltration, and sensor access: the three things all spyware must do.
🪟 Windows
Combine built-in tools with open-source scanners for layered detection.
Included with Windows 10/11. Provides real-time protection, cloud-based analysis, and periodic scans. Significantly improved in recent years and catches most common malware. However, it is a Microsoft product with telemetry, and is insufficient against state-level threats. Keep it enabled as a baseline, but don't rely on it alone.
2. Autoruns (Sysinternals / Microsoft)
The Windows equivalent of KnockKnock. Shows every program configured to start automatically: registry keys, startup folders, services, drivers, scheduled tasks, browser extensions, and dozens of other persistence locations. Highlights entries that are unsigned or from unusual locations. Essential for spotting malware persistence.
• Free, from Microsoft's Sysinternals suite
• Run as administrator for full visibility
• Compare against a known-clean baseline if possible
Autoruns (Sysinternals)
3. Process Explorer (Sysinternals)
An advanced task manager that shows every running process, its parent, loaded DLLs, network connections, and VirusTotal integration (right-click → Check VirusTotal). Lets you investigate suspicious processes in real time. Useful for spotting injected or hidden processes that standard Task Manager won't show.
Process Explorer
4. ClamAV (open-source antivirus)
Same open-source scanner available on other platforms. Install the Windows version from clamav.net. Useful as a second-opinion scanner that doesn't conflict with Defender. Signature-based, so limited against advanced threats.
5. Malwarebytes (free scan)
The free version provides on-demand malware scanning (no real-time protection). Effective at catching adware, PUPs (potentially unwanted programs), and stalkerware that Defender sometimes misses. Good as a periodic second-opinion scanner. The free tier is sufficient. No need to buy premium for basic detection.
6. Hardentools (Security Without Borders)
A simple tool that disables Windows features commonly exploited by malware: Office macros, PowerShell scripting, Windows Script Host, AutoRun, and more. One-click hardening, one-click undo. Not a scanner, but reduces your attack surface significantly.
Hardentools
Recommended stack: Keep Defender running. Install Autoruns and Process Explorer for investigation. Run periodic Malwarebytes scans. Apply Hardentools. For state-level threats, consider switching to a hardened Linux distribution instead.
🐧 Linux
Powerful command-line tools for rootkit detection, integrity checking, and security auditing.
A classic tool that scans for known rootkits: malware that hides deep in the system to maintain persistent, invisible access. It checks system binaries, kernel modules, network interfaces, and log files for signs of tampering.
• Install:
sudo apt install chkrootkit (Debian/Ubuntu)• Run:
sudo chkrootkit• Limitation: Signature-based. Only detects known rootkits. Run regularly, not just once.
2. rkhunter (Rootkit Hunter)
Similar purpose to chkrootkit but uses different detection methods. Checks for rootkits, backdoors, and local exploits. Also verifies system binary integrity (checks SHA-256 hashes against known-good values), detects suspicious files in common locations, and checks for hidden processes and ports.
• Install:
sudo apt install rkhunter• Update signatures:
sudo rkhunter --update• Run:
sudo rkhunter --check• Best practice: Run both chkrootkit and rkhunter. They complement each other.
3. ClamAV (open-source antivirus)
The same cross-platform scanner. On Linux, install via your package manager:
sudo apt install clamav. Update: sudo freshclam. Scan: clamscan -r --bell -i /path. Useful for scanning downloaded files, email attachments, and shared directories. Not a rootkit detector. Use alongside chkrootkit/rkhunter.4. Lynis (security auditing)
A comprehensive system auditing tool that checks hundreds of security configurations: file permissions, kernel settings, firewall rules, authentication policies, installed software, and more. It doesn't scan for specific malware. Instead, it identifies weaknesses that could be exploited.
• Install:
sudo apt install lynis• Run:
sudo lynis audit system• Produces a detailed report with a hardening score and specific recommendations
Lynis
5. YARA rules (advanced, custom scanning)
YARA is a pattern-matching tool used by security researchers to identify and classify malware. You write (or download) rules that describe malware characteristics, then scan files or memory. Amnesty and Citizen Lab publish YARA rules alongside their IOCs. This is a power tool for advanced users, not a one-click solution, but the most flexible option for custom threat hunting.
• Install:
sudo apt install yara• Run:
yara -r rules.yar /path/to/scanYARA
Recommended stack: Run
chkrootkit + rkhunter weekly. Run lynis audit system monthly and address critical findings. Keep ClamAV updated for file scanning. For high-risk environments, consider Tails OS (amnesic, leaves no trace) or Qubes OS (compartmentalized).
• Access Now Digital Security Helpline: [email protected] (24/7, multilingual)
• Amnesty International Security Lab: Through Amnesty's regional offices
• Citizen Lab: citizenlab.ca (University of Toronto, research on targeted surveillance)
• EFF (Electronic Frontier Foundation): For US-based activists
Switch to a known-clean device for all communications. Assume all accounts, passwords, and messages on the compromised device have been accessed.
💾Secure Backup StrategyEstrategia de backup seguro
Backups are essential but they're also a security risk. An unencrypted backup is a complete copy of everything you're trying to protect.Las copias de seguridad son esenciales pero también son un riesgo de seguridad. Una copia de seguridad sin cifrar es una copia completa de todo lo que intentas proteger.
The 3-2-1 backup ruleLa regla de backup 3-2-1
Three copies, two media types, one offsite.Tres copias, dos tipos de medio, una fuera del sitio.
2 media types: Internal drive + external drive/USB (protects against hardware failure)
1 offsite: One backup in a different physical location (protects against fire, raid, theft)
For activists, adapt this to:
• Working copy on your encrypted device
• Backup 1: Encrypted USB drive stored at a trusted comrade's house
• Backup 2: Encrypted cloud storage (CryptPad, Proton Drive, or a Nextcloud instance you control)
Frequency: Back up critical documents weekly. Encryption keys and recovery codes: immediately upon creation.3 copias: Tu copia de trabajo + 2 backups
2 tipos de medio: Disco interno + disco externo/USB (protege contra fallo de hardware)
1 fuera del sitio: Un backup en una ubicación física diferente (protege contra incendio, redada, robo)
Para activistas, adapta esto a:
• Copia de trabajo en tu dispositivo cifrado
• Backup 1: Unidad USB cifrada guardada en casa de un compañero de confianza
• Backup 2: Almacenamiento en nube cifrado (CryptPad, Proton Drive, o una instancia de Nextcloud que controles)
Frecuencia: Haz backup de documentos críticos semanalmente. Claves de cifrado y códigos de recuperación: inmediatamente al crearlos.
⚠️ iCloud & Google Drive: encryption risks⚠️ iCloud y Google Drive: riesgos de cifrado
Your cloud backups may be your biggest vulnerability.Tus copias de seguridad en la nube pueden ser tu mayor vulnerabilidad.
• Apple holds the encryption keys. With a court order, Apple can and will hand over: iMessage history, photos, app data, device backups, contacts, calendars, notes, and more.
• This bypasses Signal's encryption: if Signal messages are included in iCloud backup, they're accessible.
• Fix: Enable Advanced Data Protection (ADP): Settings → Apple ID → iCloud → Advanced Data Protection. This E2E encrypts most iCloud data so even Apple can't access it.
Google Drive backups (Android):
• WhatsApp backups to Google Drive are not E2E encrypted by default. Enable encrypted backup in WhatsApp settings.
• Google Photos: all photos accessible to Google and law enforcement with a court order.
• Android device backups: include app data, WiFi passwords, settings, all accessible to Google.
Secure alternatives:
• CryptPad: E2E encrypted, no access by server operators
• Proton Drive: E2E encrypted, Swiss jurisdiction
• Nextcloud (self-hosted): You control the server entirely
• VeraCrypt containers: Create an encrypted container, store it anywhere (even Google Drive), without the password, the contents are unreadableCopias de seguridad de iCloud (sin Protección de Datos Avanzada):
• Apple tiene las claves de cifrado. Con una orden judicial, Apple puede y entregará: historial de iMessage, fotos, datos de apps, copias del dispositivo, contactos, calendarios, notas, y más.
• Esto elude el cifrado de Signal: si los mensajes de Signal están incluidos en la copia de iCloud, son accesibles.
• Solución: Activa la Protección de Datos Avanzada (ADP): Ajustes → ID de Apple → iCloud → Protección de Datos Avanzada. Esto cifra E2E la mayoría de los datos de iCloud para que ni Apple pueda acceder.
Copias de seguridad de Google Drive (Android):
• Las copias de WhatsApp a Google Drive no están cifradas E2E por defecto. Activa copia de seguridad cifrada en ajustes de WhatsApp.
• Google Fotos: todas las fotos accesibles para Google y fuerzas del orden con orden judicial.
• Copias de dispositivos Android: incluyen datos de apps, contraseñas WiFi, ajustes, todo accesible para Google.
Alternativas seguras:
• CryptPad: Cifrado E2E, sin acceso por operadores del servidor
• Proton Drive: Cifrado E2E, jurisdicción suiza
• Nextcloud (auto-hospedado): Controlas el servidor completamente
• Contenedores VeraCrypt: Crea un contenedor cifrado, guárdalo donde sea (incluso Google Drive), sin la contraseña, el contenido es ilegible
Backup encryption checklistLista de verificación de cifrado de backups
☐ iCloud ADP enabled (iPhone users)
☐ WhatsApp encrypted backup enabled (if using WhatsApp)
☐ Android backup set to encrypted
☐ External drives encrypted with VeraCrypt or LUKS
☐ Recovery codes for 2FA stored in password manager AND on paper in a safe location
☐ Password manager database backed up to encrypted USB☐ ADP de iCloud activado (usuarios de iPhone)
☐ Copia de seguridad cifrada de WhatsApp activada (si usas WhatsApp)
☐ Backup de Android configurado como cifrado
☐ Discos externos cifrados con VeraCrypt o LUKS
☐ Códigos de recuperación de 2FA guardados en gestor de contraseñas Y en papel en ubicación segura
☐ Base de datos del gestor de contraseñas con backup en USB cifrado
😷Countering Facial RecognitionCómo contrarrestar el reconocimiento facial
Physical and digital countermeasures to defeat facial recognition systems at actions and protests.Contramedidas físicas y digitales para derrotar los sistemas de reconocimiento facial en acciones y protestas.
Digital countermeasures
Reducing your facial footprint online.
• Remove or limit photos showing your face on social media
• Use avatars/illustrations instead of real photos on activist accounts
• Ask comrades not to post unblurred photos of you
• Use PimEyes (ironically) to search yourself and see what's out there
• Request removal from Clearview AI (clearview.ai/privacy/requests), they're legally required to comply in the EU, though enforcement varies
At actions:
• Blur all faces before sharing any photos (ObscuraCam or Signal's blur tool)
• Strip metadata from all images (mat2 or metadata.systemli.org)
• Never upload unblurred protest photos to any platform, even "private" groups
📋 Phase 04 · Key Takeaways📋 Fase 04 · Puntos clave
Field Operations & TravelOperaciones de campo y viaje
📋Prepare: Days & Hours BeforePreparar: días y horas antes
Everything in this section happens before you walk out the door. If you skip preparation, no amount of in-field discipline will save you.Todo en esta sección ocurre antes de salir por la puerta. Si te saltas la preparación, ninguna disciplina en el terreno te salvará.
📱 Device lockdown
Airplane mode protocol
Enable airplane mode 30 minutes before reaching the action area, or 500 meters before, whichever comes first. This prevents your phone from connecting to cell towers that log your location.
Camera geolocation OFF
Settings → Privacy → Location Services → Camera → Never. Do this now, not the morning of. Every photo with GPS coordinates is a timestamp placing you at the scene.
Practice remote wipe BEFORE you need it
Remote wipe is useless if you've never done it before.
Android: android.com/find → select device → Erase Device. Requires Google account access.
Key order: wipe FIRST, then deactivate SIM. If you deactivate the SIM first, the phone can't receive the wipe command.
SIM deactivation: Log into your carrier's website (Movistar, Vodafone, Orange…) → customer area → SIM management → deactivate. Practice accessing it without needing SMS verification (you won't have your phone anymore). Know if you can do it online or need to visit a store, and how many days a replacement takes.
⚖️ Know your rights (condensed)
Lawyer's number: memorized AND on paper
Before any action, have the phone number of a lawyer (or the collective's legal team) memorized or written on paper. If your phone is seized and the number was only there, you can't contact anyone. Some collectives print cards with the legal team's number to distribute before actions.
You are NOT obligated to provide your PIN
In most European jurisdictions, the right against self-incrimination protects you.
Core phrase to memorize
"I want to speak to my lawyer."
This is the only sentence you need. Don't confirm which apps you use, who you talk to, or which groups you're in. Exercising your right to remain silent is not suspicious.
🕵️ Operational security
Digital security means nothing if your physical security is compromised. These practices bridge the gap between your devices and the real world.La seguridad digital no significa nada si tu seguridad física está comprometida. Estas prácticas cierran la brecha entre tus dispositivos y el mundo real.
Tail detection
How to know if you're being followed, and what to do about it.
Key techniques:
, The double-back: Walk past your destination, turn a corner, stop to "check your phone," then reverse. Anyone following must either pass you (revealing themselves) or stop awkwardly.
, The dead-end: Walk into a dead-end street or enter a shop with a single exit. Anyone who follows you in has revealed themselves.
, The transit switch: Get on public transport, ride a few stops, get off at the last second. Repeat on a different line.
, The window check: Use shop windows as mirrors. Pause naturally and observe reflections.
, Time checks: Note the same face, jacket, or bag appearing in different locations. Once is coincidence. Twice is a pattern. Three times is surveillance.
If you confirm a tail:
• Do NOT go to your destination or meeting point
• Head to a busy, public area (shopping center, transit hub)
• Alert your group via Signal
• Do not confront the follower
• Cancel or relocate the meeting
Secure meeting locations
Choosing locations that minimize surveillance risk.
• Parks and open outdoor spaces (hard to bug, easy to spot surveillance)
• Busy cafés with background noise (defeats directional microphones)
• Locations with multiple exits
• Places you can reach without passing through choke points with CCTV
Bad meeting locations:
• Your home or a comrade's home (establishes patterns)
• The same place twice in a row
• Near government buildings or police stations (higher CCTV density)
• Quiet restaurants where conversations carry
Meeting protocol:
• Arrive separately, leave separately
• Vary meeting times and locations
• Phones on airplane mode or left at home
• Agree on a fallback location in case of compromise
• One person acts as lookout outside
Counter-surveillance walks
A routine to clean yourself before arriving at a sensitive meeting.
How to do it:
• Plan 30-60 minutes of extra travel time
• Use a mix of walking and public transit
• Include at least 3 direction changes and 2 stops
• Visit a shop, buy something, leave from a different exit if possible
• Use escalators (allows natural backward glances)
• Cross a bridge (limited following options, good visibility)
• End by entering a building with multiple exits, leave from a different one
Key rule: Everything must look natural. You're not in a movie. You're someone running errands on the way to coffee.
📢 Identity separation & device hygiene
🔌 USB data blockers
When charging your phone at public stations (airports, cafés, events), use a USB data blocker ("USB condom"). These small devices allow power through but block the data pins, preventing "juice jacking" attacks that can install malware or extract data. Available for a few euros online.
👥 Team roles: assign before the action
Every action needs four pre-assigned roles. Don't improvise this during a crisis. Decide who does what today.Cada acción necesita cuatro roles preasignados. No improvises esto durante una crisis. Decide quién hace qué hoy.
Legal Contact
Calls the lawyer immediately. Confirms detention location. Informs family if appropriate. This person is pre-assigned, not improvised.
Device Handler
Has credentials for remote wipe. Initiates wipe on arrested comrade's device. Then deactivates SIM via carrier website. Pre-authorized for this.
Digital Cleanup
Rotates shared passwords. Removes arrested person from sensitive Signal groups. Archives or locks shared CryptPad docs. Alerts other members.
Comms Lead
Sends pre-written alert message to the group. Coordinates public response if needed. Manages information flow, only verified facts, no speculation on Signal.
Preparation checklist (do this BEFORE any action)
📱 Burner Phones & 🖨️ Secure Printing
Complete guides for burner phone lifecycle (acquisition → activation → operation → disposal) and anonymous printing (Machine Identification Codes, countermeasures) have been moved to Module 2.1: Mobile Devices and Module 2.6: Printers & Printing respectively. Read them as part of your hardware security preparation before any action.
📹Operate: You're in the FieldOperar: estás en el terreno
The action is live. Your priorities are personal safety, documentation, and protecting everyone around you. This section is short on purpose. During an action, you don't read paragraphs.La acción está en marcha. Tus prioridades son seguridad personal, documentación y proteger a quienes te rodean. Esta sección es breve a propósito. Durante una acción no lees párrafos.
📸 Documentation protocol
Filming rules
☐ Check framing: don't film identifiable comrades
☐ Point camera at police, not at protesters' faces
☐ If possible, record with screen locked
☐ No live-streaming to public social media (gives police real-time intelligence)
After capturing
☐ Pass EVERYTHING through Signal before moving it anywhere else
☐ Don't upload anything to social media without reviewing
☐ Blur faces before sharing
☐ Check for tattoos, clothing, and license plates
Blur faces in Signal
Signal has a built-in blur tool with automatic face detection.
1. Open Signal and select send image
2. Select the photo you want to send
3. Before sending, tap the edit icon (pencil or similar)
4. Select the blur tool (circle icon)
5. Signal will automatically detect faces and blur them
6. You can also manually swipe over areas to blur
Alternative: ObscuraCam (from Guardian Project, guardianproject.info) for more advanced photo editing: blurring, metadata removal, selective pixelation.
Copwatch & secure live-streaming
Document police conduct while protecting yourself and others.
• In most EU countries and the US, you have the right to film police in public spaces
• Live-streaming creates an immediate backup that can't be deleted if your phone is seized
• Point camera at police, not at protesters' faces
Secure live-streaming options:
• Signal video call to a trusted person offsite who records
• ACLU Mobile Justice app (US): auto-uploads to ACLU servers when recording stops
, Tella app (guardianproject): encrypted recording with auto-upload to a secure server
Important: Disable facial features in frame when possible. If you must film protesters, blur faces before any upload. Never live-stream to public social media during an action, it gives police real-time intelligence.
📡 Communication discipline
Signal only, no exceptions
All field communications go through Signal with disappearing messages enabled. No phone calls, no SMS, no WhatsApp, no Telegram. If someone isn't on Signal, they don't get real-time updates.
No real-time social media
Every post, story, or tweet during an action is free intelligence for anyone watching. No check-ins, no live tweets, no stories. Post after, never during.
🚨 Quick reference: if things go wrong
Memorize these four rules. They are your entire playbook if you're detained.Memoriza estas cuatro reglas. Son todo tu manual si te detienen.
1. PHONE OFF
Power off immediately. A phone in BFU state is nearly impenetrable.
2. SAY NOTHING
"I want to speak to my lawyer." Repeat to every question. Nothing else.
3. NEVER UNLOCK
Don't unlock your phone "to prove you have nothing." They record everything.
4. CONFIRM NOTHING
Don't confirm apps, contacts, or group memberships. Silence protects everyone.
🚨Respond: When Things Go WrongResponder: cuando las cosas salen mal
Someone got detained. A device was seized. A raid is happening. This section is the crisis playbook: what to do in the first minutes and hours.Alguien fue detenido. Un dispositivo fue incautado. Hay una redada. Esta sección es el manual de crisis: qué hacer en los primeros minutos y horas.
⚡ What's happening right now?¿Qué está pasando ahora mismo?
Select your situation to get step-by-step guidance.Selecciona tu situación para recibir orientación paso a paso.
👥 Group response: activate pre-assigned rolesRespuesta grupal: activar roles preasignados
You assigned these roles in 6.1 Prepare. Now execute them.Asignaste estos roles en 6.1 Preparar. Ahora ejecútalos.
Immediate actions (first 30 minutes)Acciones inmediatas (primeros 30 minutos)
Within the first hourDurante la primera hora
🧹Recover: After the ActionRecuperar: después de la acción
You're home. Everyone is safe. But your security work isn't done. The next 24 hours are when most mistakes happen.Estás en casa. Todxs están a salvo. Pero tu trabajo de seguridad no ha terminado. Las próximas 24 horas son cuando ocurren la mayoría de errores.
🧹 Post-action data cleaning protocol
Execute in orderEjecutar en orden
Location wiping checklist
Your phone tracks more locations than you think.
• Google Maps Timeline (if enabled)
• Apple Significant Locations (Settings → Privacy → Location Services → System Services)
• Photo metadata (EXIF GPS coordinates)
• WiFi connection logs (your phone remembers every network it connected to)
• App-specific location data (social media, weather, maps)
• Fitness trackers and health apps
After every action:
☐ Delete Google Maps Timeline for the relevant period
☐ Clear Apple Significant Locations
☐ Remove unknown/event WiFi networks from saved networks
☐ Check fitness/health apps for location data
☐ Review photo gallery for geotagged images
🧠 Emotional OPSEC: the post-action adrenaline trap
Your brain chemistry actively works against your security in the hours after an action. Understanding this is critical.
Why post-action is the most dangerous time
Your brain is chemically compromised and working against your security.
• Adrenaline rush: Creates feelings of invincibility and reduces risk assessment
• Dopamine spike: Creates reward-seeking behavior · posting for likes/validation
• Emotional bonding: Strong urge to share the experience with your community
• Reduced executive function: Fatigue + adrenaline crash impairs decision-making
Common mistakes during this window:
• Posting photos/videos to social media before scrubbing metadata and blurring faces
• Sending messages with identifying details on unsecured channels
• Taking group photos with unmasked faces while still in distinctive clothing
• Live-tweeting celebrations that confirm your participation
• Calling/texting personal contacts from your burner phone
• Going directly home instead of using counter-surveillance routes
• Keeping incriminating items (flyers, clothing, devices) instead of proper disposal
Real consequences: Multiple activists have been identified and arrested from photos they or comrades posted in the immediate aftermath of actions, while the emotional high was still active.
⏱️ Mandatory Cooling Off Period
Implement these time-based restrictions on all post-action communication:
Execute cleanup protocol only
Disappearing msgs, no photos
Metadata scrubbed, faces blurred
After full security review
How to implement cooling off in your group
Build the pause into your action protocol.
• All participants agree to the cooling off timeline before the action
• Designate one person as "media coordinator" who handles all external comms
• Set a specific time (24+ hours later) for the first approved post
• Create a shared folder (CryptPad) where raw footage goes for review
Accountability buddies:
• Pair up with someone who will check on you during the danger window
• Grant them permission to call you out if you start posting
• Have a code phrase: "Remember the cooling protocol"
Technical barriers:
• Log out of social media before the action (don't just close the app)
• Leave your personal phone at home entirely
• If you must bring a phone, use airplane mode until you've completed the full cleanup
• Use app blockers or screen time limits for social apps
Redirect the energy:
• Write in a private, encrypted journal (Signal Note to Self with disappearing messages)
• Physical activity helps process the adrenaline
• Call a trusted friend (not about the action, just to talk)
• Rest · your brain needs time to return to baseline decision-making
✈️Border & Travel SecuritySeguridad en fronteras y viajes
Crossing borders is one of the highest-risk moments for activists. Border agents in many countries have broad powers to search devices without a warrant. Prepare before you travel: not at the airport.Cruzar fronteras es uno de los momentos de mayor riesgo para activistas. Los agentes fronterizos en muchos países tienen amplios poderes para registrar dispositivos sin orden judicial.
✈️ Before You Travel: Clean ProfileAntes de viajar: perfil limpio
Creating a clean travel profile
Your daily-use device should never cross a hostile border.
• Use a separate phone/laptop with only essential apps
• Fresh install, no activist data, no Signal groups
• Log into "travel-only" accounts (see below)
• Your real device stays at home, powered off
Option 2: Clean your main device
• Back up everything to encrypted storage before travel
• Factory reset the device
• Set up clean accounts for the trip
• Restore from backup after crossing the border
Option 3: Cloud-based profile (most convenient)
• Before border: log out of all accounts, delete sensitive apps
• Cross border with a "clean" phone
• After border: reinstall apps and log back in
• Risk: browsing history and app installation logs may persist
"Travel-only" accounts
Separate email and social media accounts that contain nothing sensitive.
, Email: A clean ProtonMail or Gmail with only travel confirmations
, Social media: A clean Instagram/Twitter with generic posts (food, travel, landscapes)
, Cloud: A clean Google Drive or iCloud with nothing sensitive
Purpose: If a border agent demands you unlock your phone and show your accounts, they see a normal person traveling, not an activist. Having NO social media can itself look suspicious.
Keep these accounts active: Post occasionally, have some contacts, look lived-in. A brand-new empty account is suspicious.
✅ Border Crossing ChecklistChecklist para cruce de fronteras
Complete every item before any international trip.Completa todos los puntos antes de cualquier viaje internacional.
PRE-TRAVEL SECURITY CHECKLIST
⚖️ Know Your Rights at BordersConoce tus derechos en fronteras
Your rights vary dramatically by country. Border zones have reduced legal protections compared to domestic law.Tus derechos varían dramáticamente por país. Las zonas fronterizas tienen protecciones legales reducidas.
🇪🇺 European Union (Schengen)
Generally stronger protections, but varies by member state.
• GDPR applies: data collected must be proportional and lawful
• You cannot be forced to provide passwords in most EU countries (right against self-incrimination)
• However: refusal can lead to extended detention or denied entry for non-EU citizens
, Spain: Ley de Seguridad Ciudadana allows device inspection with judicial authorization
, France: Border police can inspect devices for up to 4 hours under certain conditions
, Germany: BPolG allows device searches at border with reasonable suspicion
Advice: Know the specific laws for your destination. Power off devices before approaching the border. Don't lie, refuse politely or comply with a clean device.
🇬🇧 United Kingdom
Some of the broadest border search powers in the democratic world.
• You CAN be compelled to provide device passwords. Refusal is a criminal offense (up to 3 months imprisonment)
• Officers can detain you for up to 6 hours
• They can copy data from your devices
• This applies at airports, ports, and the Eurostar
Advice: UK borders require a clean device strategy. Do not carry sensitive data across UK borders. Use cloud restoration after entry.
🇺🇸 United States ⚠️ ELEVATED RISK 2025
The "border search exception" allows warrantless device searches - and powers expanded significantly in 2025.
• A 2021 ruling requires "reasonable suspicion" for advanced/forensic searches, but basic searches (scrolling through your phone) have no such requirement
• You can refuse to provide your password, but CBP can seize your device for up to 5 days (and sometimes longer)
• Non-citizens can be denied entry for refusing
• US citizens cannot be denied entry but can face significant delays and device seizure
⚠️ 2025 update: Executive Order 14147 and subsequent DHS directives expanded CBP's digital search authorities and removed prior internal guidelines that provided some protections. Activists - including those from allied countries - have reported device searches and detentions at US borders when entering for protests, conferences, or solidarity work. Treat every US border crossing as high-risk.
Advice: Use the cloud backup/restore strategy. Never cross a US border with a device containing activist data, Signal groups, or contact lists. A clean travel device is not optional for high-risk activists entering the US. Know the EFF Border Search Guidance before departure: eff.org/border-search.
📋 Phase 05 · Key Takeaways📋 Fase 05 · Puntos clave
Collective Security & Incident ResponseSeguridad colectiva y respuesta a incidentes
🕵️Why This Matters: Documented Infiltration & Digital RepressionPor qué importa: infiltración documentada y represión digital
These aren't conspiracy theories. State and corporate infiltration of activist groups is documented, systematic, and ongoing. Understanding the real history of repression is the foundation of any coherent threat model: and the reason the protocols in this module exist.Estas no son teorías conspirativas. La infiltración estatal y corporativa en grupos activistas está documentada, es sistemática y continúa. Entender la historia real de la represión es la base de cualquier modelo de amenazas coherente.
🕵️ Why this matters: documented infiltration cases🕵️ Por qué importa: casos documentados de infiltración
These aren't conspiracy theories. State and corporate infiltration of activist groups is documented, systematic, and ongoing. Knowing the history helps calibrate your threat model correctly: neither dismissing it nor becoming paralyzed by paranoia.Estas no son teorías conspirativas. La infiltración estatal y corporativa en grupos activistas está documentada, es sistemática y continúa. Conocer la historia ayuda a calibrar correctamente tu modelo de amenazas.
🇺🇸 COINTELPRO (FBI, 1956–1971) and its heirs🇺🇸 COINTELPRO (FBI, 1956–1971) y sus sucesores
The FBI's illegal counterintelligence program disrupted civil rights, socialist, and Indigenous rights organizations through informants, forged letters, and blackmail.El programa ilegal de contrainteligencia del FBI desarticuló organizaciones de derechos civiles, socialistas e indígenas mediante informantes, cartas falsificadas y chantaje.
• Informants: Long-term plants inside organizations, sometimes rising to leadership positions. Fred Hampton's murder was enabled by informant William O'Neal, who was his own bodyguard.
• Poison pen letters: Anonymous letters to members accusing leaders of crimes, affairs, or financial theft: designed to cause internal collapse.
• False flag operations: Sending threatening letters appearing to come from rival groups to incite violence between organizations (e.g., Black Panthers vs. US Organization).
• Psychological harassment: Surveillance, anonymous late-night calls, telling employers of members' activities.
Modern successors: The FBI's Domestic Investigations and Operations Guide (DIOG) still permits infiltration of political groups. The 2020 George Floyd protests saw extensive domestic intelligence gathering across all 50 states. Environmental and animal rights groups have been classified as domestic terrorism since the 2000s under the "Green Scare." Tácticas documentadas clave (desclasificadas):
• Informantes: Plantas a largo plazo dentro de organizaciones, a veces ascendiendo a posiciones de liderazgo.
• Cartas envenenadas: Cartas anónimas acusando a líderes de crímenes o robo financiero: diseñadas para causar colapso interno.
• Operaciones de falsa bandera: Enviar cartas amenazantes aparentando venir de grupos rivales para incitar violencia entre organizaciones.
Sucesores modernos: La Guía de Investigaciones y Operaciones Domésticas del FBI (DIOG) aún permite la infiltración de grupos políticos. Las protestas de 2020 vieron recopilación extensiva de inteligencia doméstica en los 50 estados.
🌿 The Green Scare & corporate surveillance🌿 El Green Scare y la vigilancia corporativa
Environmental and animal rights activists have faced FBI Joint Terrorism Task Forces, corporate intelligence firms, and SLAPP lawsuits since the 1990s.Los activistas medioambientales y de derechos animales se han enfrentado a Fuerzas de Tareas Conjuntas del FBI, firmas de inteligencia corporativa y demandas SLAPP desde los años 90.
• Judi Bari (1990): Earth First! organizer whose car was bombed; FBI attempted to frame her as the bomber while suppressing evidence pointing to the timber industry.
• SHAC 7 (2004): Animal rights activists sentenced to 3–6 years under the Animal Enterprise Terrorism Act for running a protest website: a chilling precedent for online activism.
• Standing Rock (2016): Energy Transfer Partners hired TigerSwan, a private mercenary firm, to conduct counterinsurgency-style surveillance including drone surveillance, social media monitoring, and informants.
• Confidential America (ongoing): Corporations routinely hire intelligence firms to infiltrate union drives, pipeline protests, and climate campaigns. Wylie, Palantir, and similar firms provide this as a service.
The lesson: Your adversary may not be a government agency. Corporate security firms operate with fewer legal constraints, more resources for specific targets, and zero transparency requirements. Casos documentados:
• Standing Rock (2016): Energy Transfer Partners contrató a TigerSwan, una firma mercenaria privada, para realizar vigilancia al estilo contrainsurgencia incluyendo drones, monitoreo de redes sociales e informantes.
• SHAC 7 (2004): Activistas de derechos animales sentenciados a 3–6 años bajo la Ley de Terrorismo de Empresas Animales por gestionar un sitio web de protesta.
La lección: Tu adversario puede no ser una agencia gubernamental. Las firmas de seguridad corporativa operan con menos restricciones legales y más recursos para objetivos específicos.
🇬🇧 UK Undercover Policing Inquiry: what we learned🇬🇧 Investigación policial encubierta del Reino Unido: lo que aprendimos
The UK's ongoing Undercover Policing Inquiry (UCPI) has confirmed systematic long-term infiltration of activist groups across 40+ years.La investigación policial encubierta del Reino Unido ha confirmado infiltración sistemática a largo plazo de grupos activistas durante 40+ años.
• Officers adopted cover identities and lived undercover for 4–10 years inside activist groups
• Sexual relationships with activists were documented as a standard (if unofficial) intelligence-gathering technique used by multiple officers
• Officers infiltrated environmental groups, anti-apartheid campaigns, Socialist Workers Party, and many other organizations
• Information gathered was shared with corporations (including blacklisting workers in the construction industry)
• Similar programs ran in Germany (Verfassungsschutz), Netherlands, and Spain
Security implications:
A long-term undercover officer will pass all normal vetting checks because their back-story is real and verifiable. No security process is 100% effective against a state intelligence agency with years to invest. What compartmentalization does: limits the damage when infiltration happens. If a cell is penetrated, only that cell's information is exposed. This is why cell structure matters even for groups that believe they're clean. Lo que confirmó la investigación:
• Los agentes adoptaron identidades de cobertura y vivieron encubiertos durante 4–10 años dentro de grupos activistas
• Las relaciones sexuales con activistas fueron documentadas como técnica estándar de recopilación de inteligencia
• Los agentes se infiltraron en grupos medioambientales, campañas anti-apartheid y muchas otras organizaciones
• La información recopilada fue compartida con corporaciones
Implicaciones de seguridad:
Un agente encubierto a largo plazo pasará todas las verificaciones normales. Lo que hace la compartimentalización: limita el daño cuando ocurre la infiltración.
🌐 Digital repression: what modern surveillance looks like🌐 Represión digital: cómo es la vigilancia moderna
State surveillance of activists has moved decisively into the digital domain. Understanding the current toolkit helps you choose countermeasures that actually match the threat.La vigilancia estatal de activistas se ha trasladado decisivamente al dominio digital. Entender el conjunto de herramientas actual ayuda a elegir contramedidas que realmente coincidan con la amenaza.
• IMSI catchers (Stingrays): Used routinely at US protests since at least 2011. Capture phone identifiers of everyone present at a protest: no warrant required in many jurisdictions.
• Social media monitoring: Geofeedia and similar firms sell real-time social media location tracking to law enforcement. Facebook/Instagram/Twitter have all complied with mass data requests during protests.
• Geofence warrants: Google receives warrants requiring them to hand over the identities of all devices present at a specific location during a specific time window. No individual is targeted: everyone at the protest is.
• Facial recognition: Clearview AI's database (scraping social media) is used by 3,000+ law enforcement agencies. Your face at a protest can be matched to your personal social media within hours.
• License plate readers: Fixed and mobile LPR networks create movement histories. Your car's presence near an activist meeting is logged.
• Fusion centers: The US has 80 state/federal fusion centers that aggregate data from multiple surveillance systems and share with federal agencies.
What this means operationally:
Passive presence data (being in a location) is systematically collected. Active communications (Signal) provide the strongest protection. Physical separation of personal and activist identities must start before any public-facing activity: you cannot undo association after the fact. Capacidades actuales documentadas:
• Captadores IMSI (Stingrays): Capturan identificadores de teléfonos de todos los presentes en una protesta: sin orden judicial requerida en muchas jurisdicciones.
• Monitoreo de redes sociales: Geofeedia y firmas similares venden rastreo de ubicación en tiempo real en redes sociales a fuerzas del orden.
• Órdenes de geovalla: Google recibe órdenes que requieren entregar identidades de todos los dispositivos presentes en una ubicación específica durante una ventana de tiempo.
• Reconocimiento facial: La base de datos de Clearview AI es usada por 3,000+ agencias de aplicación de la ley. Tu rostro en una protesta puede ser identificado en horas.
🔗 Cell structure: designing for infiltration resilience🔗 Estructura de células: diseñar para resistir la infiltración
The two diagrams below show the same scenario: one person is arrested. In a flat structure, that person knows everyone - the whole network collapses. In a cell structure, they know only their cell. One cell goes down. The rest keep operating. Los dos diagramas muestran el mismo escenario: una persona es arrestada. En una estructura plana, esa persona conoce a todos - toda la red colapsa. En una estructura celular, solo conoce su célula. Una célula cae. El resto sigue operando.
✕ Red = compromised · ● Green = isolated and safe ✕ Rojo = comprometido · ● Verde = aislado y seguro
How to structure your collective so a single point of failure doesn't collapse everythingCómo estructurar tu colectivo para que un único punto de fallo no lo colapse todo
Cell structure is not just for clandestine organizations. Any group where infiltration, arrest, or device compromise is a realistic risk benefits from compartmentalization.La estructura celular no es solo para organizaciones clandestinas. Cualquier grupo donde la infiltración, el arresto o el compromiso de dispositivos sea un riesgo realista se beneficia de la compartimentalización.
• Each cell is a small group (3–7 people) working on a specific area: logistics, communications, legal support, direct action
• Cells communicate through a single liaison point: cells don't have direct contact with each other
• No cell knows the composition of other cells
• Decisions that require coordination happen through liaisons, not full-group meetings where possible
Practical implementation for most collectives:
You don't need to go full clandestine. Start with information compartmentalization:
• Working groups have their own Signal groups: not a single big group where everything is discussed
• Operational plans are shared with participants only: not the whole org, not support members, not former members
• The logistics of specific actions are not discussed in general channels: only in a time-limited, action-specific group
• Core leadership is a small, vetted set: not everyone who shows up to meetings
The blast radius calculation:
When designing your structure, ask: "If person X is arrested/compromised/turned, what do they know?" If any single person knows everything: leadership composition, all operational plans, all member identities, all accounts and access: your blast radius is 100%. Good compartmentalization brings this to 15–20%: the content of their own cell's work only. Principios básicos de estructura celular:
• Cada célula es un grupo pequeño (3–7 personas) trabajando en un área específica: logística, comunicaciones, apoyo legal, acción directa
• Las células se comunican a través de un único punto de enlace: las células no tienen contacto directo entre sí
• Ninguna célula conoce la composición de otras células
Implementación práctica para la mayoría de los colectivos:
• Los grupos de trabajo tienen sus propios grupos de Signal
• Los planes operativos se comparten solo con los participantes
• La logística de acciones específicas no se discute en canales generales
El cálculo del radio de daño:
Si cualquier persona sabe todo: composición del liderazgo, todos los planes operativos, todas las identidades de miembros: tu radio de daño es del 100%. Una buena compartimentalización lo reduce al 15–20%.
🗺Collective Security Protocol MapMapa de protocolos de seguridad colectiva
Security protocols aren't a binary on/off. They exist on a spectrum matching your actual threat level. The wrong tier in either direction: too loose or too paranoid: will get people hurt or burn out your collective. Find your tier, implement it completely, then reassess after each action.Los protocolos de seguridad no son un interruptor binario. Existen en un espectro que coincide con tu nivel de amenaza real. El nivel equivocado en cualquier dirección: demasiado laxo o demasiado paranoico: perjudicará a las personas o agotará tu colectivo. Encuentra tu nivel, impleméntalo completamente y reevalúa después de cada acción.
🔄Onboarding, Operations & OffboardingIncorporación, operaciones y baja
The most common security failures in activist collectives happen at membership transitions. A new member who doesn't know the protocols, or a departing one whose access wasn't revoked, can expose the entire network. This section covers all three phases completely.Los fallos de seguridad más comunes en colectivos activistas ocurren en las transiciones de membresía. Un nuevo miembro que no conoce los protocolos, o uno que se va cuyo acceso no se revocó, puede exponer toda la red. Esta sección cubre las tres fases completamente.
Step 1: VettingPaso 1: Vetting
🔍 Who vouches for them, and how do you verify?🔍 ¿Quién avala a esta persona y cómo lo verificas?
The vouching system is your first line of defense against infiltration. It must have teeth.El sistema de aval es tu primera línea de defensa contra la infiltración. Debe tener peso real.
• At least one existing core member vouches for them in person
• Vouching member has known them for 6+ months outside activist contexts
• New member has attended at least 2 open public events before being considered for internal access
• Core team reviews the vouch: majority approval required
Red flags that should pause or end onboarding:
• Pushes for access before trust period
• Asks operational questions before they're contextually relevant
• Overperforms: too eager, too helpful, too agreeable
• Can't explain personal political history in ways that are consistent over multiple conversations
• Has existing relationships with known informants
• Comes in through a single connection, unknown to everyone else
Important: Infiltration is real. FBI, police intelligence, and private firms (like Pinkerton successors) have historically infiltrated environmental, labor, and social justice groups. Documented cases: COINTELPRO, Green Scare, Standing Rock surveillance. Paranoia is counterproductive. Rigorous processes are not. Requisitos mínimos antes de incorporar:
• Al menos un miembro central existente avala a esta persona en persona
• El miembro que avala la conoce desde hace 6+ meses fuera de contextos activistas
• El nuevo miembro ha asistido al menos a 2 eventos públicos abiertos antes de considerarse para acceso interno
• El equipo central revisa el aval: se requiere aprobación por mayoría
Señales de alerta que deben pausar o terminar la incorporación:
• Presiona para obtener acceso antes del período de confianza
• Hace preguntas operativas antes de que sean contextualmente relevantes
• Rinde demasiado bien: demasiado entusiasta, servicial, de acuerdo con todo
• No puede explicar su historial político personal de forma consistente en múltiples conversaciones
• Tiene relaciones existentes con informantes conocidos
• Llega a través de una única conexión, desconocida para todos los demás
Step 2: Device SetupPaso 2: Configuración de dispositivos
📱 New member device configuration checklist📱 Checklist de configuración de dispositivos para nuevo miembro
Don't assume they know any of this. Walk through it with them on their actual device.No asumas que saben nada de esto. Repásalo con ellos en su dispositivo real.
Step 3: Security BriefingPaso 3: Briefing de seguridad
📋 What every new member must understand before getting any internal access📋 Lo que todo nuevo miembro debe entender antes de recibir acceso interno
This is a conversation, not a document to sign. Ask questions, check understanding.Esta es una conversación, no un documento para firmar. Haz preguntas, verifica la comprensión.
1. The threat model: Who specifically is surveilling your organization? What have they done historically? What data are they after? Make it concrete, not abstract.
2. The communication stack: Signal for everything internal. No WhatsApp. No Telegram (metadata). No unencrypted email for anything sensitive. Explain why.
3. Compartmentalization: They will only know what they need for their role. This protects them as much as it protects others. If they're ever interrogated or compromised, less information means less damage.
4. Operational security basics: No photos/videos in sensitive spaces. No posting about upcoming actions. No sharing member info with people outside the org. Location tracking hygiene.
5. The offboarding commitment: When (not if) they leave, they commit to: returning org devices, accepting credential rotation, not discussing internal operations, and not taking org documents. This should feel normal, not paranoid.
6. Emergency protocols: The arrest protocol. The device wipe procedure. The legal contact. Make sure they have these memorized or saved in the right place. Cubre estos puntos explícitamente:
1. El modelo de amenazas: ¿Quién específicamente vigila tu organización? ¿Qué han hecho históricamente?
2. La pila de comunicaciones: Signal para todo lo interno. Sin WhatsApp. Sin correo no cifrado para nada sensible.
3. Compartimentalización: Solo sabrán lo necesario para su rol. Esto los protege tanto como protege a los demás.
4. Fundamentos de seguridad operacional: Sin fotos/vídeos en espacios sensibles. Sin publicar sobre acciones próximas.
5. El compromiso de baja: Cuando (no si) se vayan, se comprometen a: devolver dispositivos, aceptar rotación de credenciales, no discutir operaciones internas.
6. Protocolos de emergencia: El protocolo de arresto. El procedimiento de borrado. El contacto legal.
Step 4: Tiered Access GrantPaso 4: Concesión de acceso por niveles
🔓 Access tiers: what they get, and when🔓 Niveles de acceso: qué obtienen y cuándo
Minimum viable access at each stage. Don't over-provision out of trust or convenience.Acceso mínimo viable en cada etapa. No sobredimensiones por confianza o conveniencia.
| Stage | Access level | What they get | When |
|---|---|---|---|
| Week 1–2 | Observer | Public Signal group, reading rights only. No operational channels. | Day 1 |
| Month 1 | Participant | Working group Signal, task-specific access. No strategy channels. | After briefing + device setup |
| Month 2–3 | Active member | Full working channels. Shared credential access for their role. Attendance at planning meetings. | After demonstrated reliability |
| 6+ months | Core | All channels. Admin access. Infrastructure keys. Vault admin rights. | Explicit core team vote |
Principle of least privilege: Every access grant should be the minimum needed for someone to do their work. If you can't explain why they specifically need it, they don't get it yet.
| Etapa | Nivel | Qué obtienen | Cuándo |
|---|---|---|---|
| Semana 1–2 | Observador | Grupo Signal público, solo lectura. | Día 1 |
| Mes 1 | Participante | Signal del grupo de trabajo, acceso específico de tarea. | Después del briefing |
| Mes 2–3 | Miembro activo | Todos los canales de trabajo. Acceso de credenciales para su rol. | Después de fiabilidad demostrada |
| 6+ meses | Core | Todos los canales. Acceso admin. Claves de infraestructura. | Votación explícita del equipo central |
Meeting Security ProtocolsProtocolos de seguridad en reuniones
🤝 In-person meeting rules🤝 Reglas para reuniones presenciales
In-person has risks too. Know how to run a secure meeting.Lo presencial también tiene riesgos. Sabe cómo gestionar una reunión segura.
• Rotate locations. Don't use the same space repeatedly, especially for planning meetings
• For Tier 3+: sweep the room for devices. Phones in a box/bag outside the meeting room, or in Faraday bags
• Don't announce locations on unencrypted channels or to non-attendees
• Confirm attendees on Signal only: no email, no calendar invites
During the meeting:
• No phones in the room for sensitive discussions (Tier 2+)
• Designate a note-taker: notes are encrypted and deleted after use
• Use code language or abbreviations for sensitive operations: agree on them beforehand
• Challenge unknowns: if someone brings a guest without prior notice, the meeting pauses
After the meeting:
• Notes are destroyed or moved to encrypted storage within 24 hours
• Any decisions are communicated via Signal only
• Debrief protocol: if you felt surveillance, report it to the security role immediately Antes de la reunión:
• Rota las ubicaciones. No uses el mismo espacio repetidamente
• Para Nivel 3+: revisa la sala en busca de dispositivos. Teléfonos en una caja fuera de la sala
• No anuncies ubicaciones en canales no cifrados
• Confirma asistentes solo por Signal
Durante la reunión:
• Sin teléfonos en la sala para discusiones sensibles (Nivel 2+)
• Designa un tomador de notas: las notas se cifran y eliminan después del uso
• Desafía a los desconocidos: si alguien trae a un invitado sin aviso previo, la reunión se pausa
Después de la reunión:
• Las notas se destruyen o se mueven a almacenamiento cifrado en 24 horas
💬 Digital communications hygiene (ongoing)💬 Higiene de comunicaciones digitales (continua)
The rules that must be practiced every day, not just before actions.Las reglas que deben practicarse cada día, no solo antes de las acciones.
• Disappearing messages enabled on all group chats (1 week for regular comms, 1 day for operational)
• Note to Self as secure notepad: not WhatsApp, not Telegram
• No screenshots of Signal conversations. Announce this norm explicitly
• Use Signal's "Note to Self" group instead of personal notes for anything sensitive
• Remove departing members from Signal groups within 24 hours of their departure
Email rules:
• No sensitive information in email ever: not even encrypted email for Tier 3+
• Email is for public coordination only: events, public communications, press contacts
• Use ProtonMail for all org email, not Gmail/Outlook/Yahoo
• All org email addresses use pseudonyms unlinked to personal identity
File sharing:
• Use Signal's file transfer for sensitive documents
• For collaborative editing: OnlyOffice on self-hosted Nextcloud (or CryptPad as cloud alternative)
• Never Google Drive, Dropbox, or iCloud for sensitive documents
• Documents that contain member names, operational plans, or meeting notes are encrypted-at-rest
Social media:
• No posting about upcoming actions, even vague references
• No tagging members without explicit permission
• Public-facing accounts are managed by a designated communications role
• Separate personal social media from org work completely Disciplina de Signal:
• Mensajes que desaparecen habilitados en todos los chats grupales (1 semana para comunicaciones regulares, 1 día para operacionales)
• Sin capturas de pantalla de conversaciones de Signal. Anuncia esta norma explícitamente
• Elimina a los miembros que se van de los grupos de Signal en 24 horas
Reglas de correo electrónico:
• Sin información sensible en correo electrónico nunca
• El correo es solo para coordinación pública
• Usa ProtonMail para todo el correo org, no Gmail/Outlook
Compartición de archivos:
• Usa la transferencia de archivos de Signal para documentos sensibles
• Para edición colaborativa: CryptPad o Nextcloud autoalojado
• Nunca Google Drive o Dropbox para documentos sensibles
Quarterly Security AuditAuditoría de seguridad trimestral
🔁 Quarterly collective hygiene checklist🔁 Checklist de higiene colectiva trimestral
Run this every 3 months, or after any significant event (arrest, raid, suspicious behavior, member departure).Realiza esto cada 3 meses, o después de cualquier evento significativo (arresto, redada, comportamiento sospechoso, baja de miembro).
☐ Lista cada persona con acceso a cada sistema
☐ Confirma que cada persona todavía necesita ese acceso
☐ Revoca todo lo que no esté claramente justificado
Rotación de credenciales:
☐ Rota contraseñas compartidas
☐ Genera nuevas semillas TOTP para cuentas compartidas
☐ Verifica credenciales filtradas en haveibeenpwned.com
Verificación de dispositivos:
☐ Actualizaciones de SO aplicadas en todos los dispositivos
☐ Verifica apps no reconocidas o perfiles MDM
Shared Infrastructure: Credentials & AssetsInfraestructura compartida: Credenciales y activos
🔑 Collective password management & the asset matrix🔑 Gestión de contraseñas colectivas y la matriz de activos
Every collective needs a centralized credential vault. Individuals holding org passwords in their personal password manager is a critical failure mode.Todo colectivo necesita una bóveda de credenciales centralizada. Los individuos que tienen contraseñas de la org en su gestor personal es un modo de fallo crítico.
1. Vaultwarden (self-hosted Bitwarden): Best option. €4/month VPS. Full sharing features, TOTP, audit logs. You control the data entirely.
2. KeePassXC + Syncthing: Offline database synced via Syncthing. No cloud at all. Works great for Tier 3+ groups.
3. Bitwarden Organizations: Hosted option. Easier to manage but Bitwarden sees encrypted metadata. €3/user/month.
Mandatory rules:
• Every shared credential has a named primary holder and a backup holder
• No single person holds primary on more than 3 critical assets
• Backup holder actively verifies their access quarterly
• When any holder leaves, execute offboarding AND reassign their assets same day
• Master vault password: 6+ word passphrase, known only to Core tier
Asset matrix: maintain this and keep it current:
| Asset | Primary | Backup | Rotation trigger |
|---|---|---|---|
| Domain registrar | Core A | Core B | Annual / on departure |
| Hosting / VPS | Core A | Core B | Annual / on departure |
| Vaultwarden admin | Core B | Core A | On departure |
| Bank account | Core C | Core A | Quarterly |
| Social media | Comms lead | Core B | On departure |
| Signal registration phones | Core B | Core C | Per action cycle |
1. Vaultwarden autoalojado: Mejor opción. €4/mes VPS. Control total de los datos.
2. KeePassXC + Syncthing: Base de datos offline sincronizada vía Syncthing. Sin nube. Ideal para Nivel 3+.
3. Bitwarden Organizations: Opción hospedada. Más fácil pero Bitwarden ve metadatos cifrados.
Reglas obligatorias:
• Cada credencial compartida tiene un titular principal nombrado y un titular de respaldo
• Ninguna persona tiene titularidad principal en más de 3 activos críticos
• El titular de respaldo verifica activamente su acceso trimestralmente
Immediate Actions (within 24 hours)Acciones inmediatas (en 24 horas)
🚨 Zero-delay offboarding checklist🚨 Checklist de baja sin demora
This list is executed the same day. No exceptions for "we'll do it next week."Esta lista se ejecuta el mismo día. Sin excepciones para "lo haremos la próxima semana."
Planned Departure (with notice)Salida planificada (con aviso)
📤 Full offboarding process for graceful exits📤 Proceso completo de baja para salidas planificadas
When someone gives notice, you have time to do this properly.Cuando alguien avisa, tienes tiempo para hacerlo bien.
• Document any institutional knowledge they hold that isn't elsewhere
• Reassign their responsibilities to existing members: don't let this float
• Update the asset matrix: reassign any assets they hold as primary
• Identify and document any processes only they understood
Device handling:
• Any org-owned devices returned. Do NOT trust a returned device until it's been wiped and reinstalled
• Factory reset returned devices before giving them to another member
• Personal devices with org software: they should uninstall Signal org groups and delete org-related data
• You cannot verify this. Accept the risk, rotate credentials, and compartmentalize
Debrief (before last day):
• What security concerns do they have? Did they observe anything suspicious?
• What would they do differently? (Genuinely valuable for improving protocols)
• Remind them of their ongoing confidentiality obligation: not as a threat, as a mutual protection
• Ask directly: do they have any org documents, plans, or member data they need to delete?
Post-departure compartmentalization:
• Don't discuss active operations with them after departure
• Don't tell them about new actions, new members, or security changes
• Their knowledge of your protocols should be assumed as known to potential adversaries after 6–12 months if there's any concern
• If there's any reason to suspect bad faith: immediately assume all known protocols are compromised. Rotate everything. Transferencia de conocimiento (semana 1 después del aviso):
• Documenta cualquier conocimiento institucional que posean que no esté en otro lugar
• Reasigna sus responsabilidades a miembros existentes
• Actualiza la matriz de activos: reasigna los activos que tengan como titular principal
Manejo de dispositivos:
• Devolver cualquier dispositivo propiedad de la org. No confíes en un dispositivo devuelto hasta que haya sido borrado
• Restablecimiento de fábrica de dispositivos devueltos antes de dárselos a otro miembro
Debriefing (antes del último día):
• ¿Qué preocupaciones de seguridad tienen? ¿Observaron algo sospechoso?
• Recuérdales su obligación de confidencialidad continua
• Pregunta directamente: ¿tienen documentos org, planes o datos de miembros que necesiten eliminar?
Compartimentalización post-salida:
• No discutas operaciones activas con ellos después de la salida
• Su conocimiento de tus protocolos debe asumirse como conocido por posibles adversarios después de 6–12 meses
⚡ Emergency offboarding: hostile or abrupt departures⚡ Baja de emergencia: salidas hostiles o abruptas
Someone is removed for cause, leaves angry, is arrested, or has their device compromised. Different playbook.Alguien es expulsado, se va enojado, es arrestado o tiene su dispositivo comprometido. Diferente manual.
1. Immediate blackout: Remove from all channels before any confrontation or notification. Announce to core team first.
2. Assume worst case: Operate as if everything they knew is now known to your adversary. What's the damage radius?
3. Rotate everything connected to their access: see the immediate actions checklist above, do it within the hour
4. Change operational patterns: meeting locations, communication schedules, any plans they had visibility into
5. Brief remaining members: what happened (appropriately), what's changed, what to watch for
6. Document the incident in encrypted storage: date, access levels they had, what was rotated, by whom
Special case: arrest:
When a member is arrested, assume their phone is being analyzed by law enforcement. Rotate everything they had access to. Pause any planned actions they knew about. Contact your legal support immediately. Trata esto como un incidente de seguridad completo:
1. Apagón inmediato: Eliminar de todos los canales antes de cualquier confrontación o notificación.
2. Asumir el peor caso: Opera como si todo lo que sabían ahora lo sabe tu adversario.
3. Rotar todo lo conectado a su acceso: dentro de la hora
4. Cambiar patrones operacionales: ubicaciones de reuniones, horarios de comunicación
5. Informar a los miembros restantes: qué pasó, qué cambió, qué vigilar
6. Documentar el incidente en almacenamiento cifrado
Caso especial: arresto:
Cuando un miembro es arrestado, asume que su teléfono está siendo analizado por fuerzas del orden. Rota todo a lo que tenían acceso.
🔍Vetting & Trust VerificationVerificación de confianza
The vouching system is your primary defense against infiltration. Without formal vetting, an infiltrator only needs to make one friend in your collective. With it, they need to fool multiple trusted members over an extended period: dramatically raising the cost of infiltration.El sistema de avales es tu principal defensa contra la infiltración. Sin verificación formal, un infiltrado solo necesita hacerse amigo de una persona en tu colectivo. Con él, necesita engañar a múltiples miembros de confianza durante un período prolongado.
6+ mo. historyAvalador A
6+ meses
min. access firstNuevo miembro
acceso mínimo
6+ mo. historyAvalador B
6+ meses
• "I have known this person ≥6 months outside this context" • "I can describe specific shared experiences" • "I accept personal accountability if they become a security problem" • "Conozco a esta persona ≥6 meses fuera de este contexto" • "Puedo describir experiencias compartidas específicas" • "Acepto responsabilidad personal si generan un problema de seguridad"
🚩 Red Flags: Agent Provocateur Patterns🚩 Señales de alerta: Patrones de agente provocador
Infiltrators follow patterns, not just personas. Click each flag to read more. Remember: these can also indicate inexperience: the response (slow down, apply process) is the same regardless.Los infiltrados siguen patrones, no solo personas. Haz clic en cada señal para leer más. Recuerda: también pueden indicar inexperiencia: la respuesta (ralentiza, aplica el proceso) es la misma.
No vetting system is perfect. What vetting does is raise the cost of infiltration and create accountability chains. The goal is not a lie-detector: it's making infiltration expensive enough that low-value targets are deprioritized.Ningún sistema de verificación es perfecto. Lo que hace la verificación es elevar el costo de la infiltración y crear cadenas de responsabilidad. El objetivo no es un detector de mentiras: es hacer que la infiltración sea lo suficientemente cara.
🗝️The Bus Factor & Key CustodyEl factor autobús y custodia de claves
The "Bus Factor" asks: how many members could be suddenly unavailable before the organization can no longer function? If the answer is one: if one person holds the passwords to your servers, domain, and vault: you have a single point of failure that is also your adversary's highest-value target.El "factor autobús" pregunta: ¿cuántos miembros pueden quedar repentinamente no disponibles antes de que la organización no pueda funcionar? Si la respuesta es uno: si una persona tiene las contraseñas de tus servidores, dominio y bóveda: tienes un punto único de fallo.
⚠️ Why single-custodian models fail⚠️ Por qué fallan los modelos de custodia única
That one person is simultaneously: your most critical dependency and your adversary's best target.Esa persona es simultáneamente: tu dependencia más crítica y el mejor objetivo de tu adversario.
What adversaries can do: Target that specific person for physical device seizure · Apply legal pressure to extract credentials · Use their arrest to cripple your entire infrastructure in one move Qué falla cuando no están: Los dominios caducan (la web desaparece) · Las credenciales del servidor son inaccesibles · La bóveda de contraseñas bloqueada · Los backups cifrados no se pueden abrir
Qué pueden hacer los adversarios: Atacar a esa persona específica para incautar dispositivos · Aplicar presión legal para extraer credenciales · Usar su arresto para paralizar toda tu infraestructura
Imagine a high-security vault that requires 3 keyholders to turn their keys simultaneously to open. No single person can open it alone. Two people together still cannot open it. But any 3 of the 5 keyholders can. This is Shamir's Secret Sharing (SSS) applied to your passwords.Imagina una bóveda de alta seguridad que requiere que 3 portadores de llave giren sus llaves simultáneamente para abrirla. Ninguna persona puede abrirla sola. Dos personas juntas tampoco pueden abrirla. Pero cualquier 3 de los 5 portadores pueden. Esto es Shamir's Secret Sharing (SSS) aplicado a tus contraseñas.
Your master password is split by a computer into 5 random-looking pieces. Each piece alone is mathematically useless: it reveals nothing. Only when 3 or more pieces are combined does the math reconstruct the original password. This means: no single member can be pressured, arrested, or compromised into handing over your vault. Your adversary would need to simultaneously compromise at least 3 separate people.Tu contraseña maestra es dividida por un ordenador en 5 piezas de apariencia aleatoria. Cada pieza sola es matemáticamente inútil: no revela nada. Solo cuando se combinan 3 o más piezas reconstruye la matemática la contraseña original. Esto significa: ningún miembro individual puede ser presionado, arrestado o comprometido para entregar tu bóveda.
PasswordContraseña
Maestra
🔐 Tools & practical setup🔐 Herramientas y configuración práctica
How to actually implement SSS for your collective: from command-line tools to paper-based options.Cómo implementar SSS para tu colectivo: desde herramientas de línea de comandos hasta opciones en papel.
• ssss (command-line, Linux/Mac):
apt install ssss: simplest implementation• Paper-based SSS: for groups without technical infrastructure: print shares, distribute physically to geographically separated custodians
• Hashicorp Vault: enterprise-grade, overkill for most groups but appropriate for larger organizations
What to split:
1. Domain registrar master password
2. Primary server root credentials
3. KeePassXC vault master password (or the key file)
4. Signal group admin account credentials
5. Shared email account password
Where to store shares: Different geographic locations. Not all in the same city. Each custodian stores their share physically offline (printed, in a sealed envelope in a safe place). Herramientas:
• ssss (línea de comandos, Linux/Mac):
apt install ssss• SSS en papel: imprime partes, distribúyelas físicamente a custodios geográficamente separados
Qué dividir:
1. Contraseña maestra del registrador de dominio
2. Credenciales root del servidor principal
3. Contraseña maestra del bóveda KeePassXC
4. Credenciales de la cuenta admin de Signal
5. Contraseña de la cuenta de correo compartida
🚨 The Break-Glass Protocol: step by step🚨 El protocolo de emergencia: paso a paso
A documented emergency procedure for when a keyholder is suddenly unavailable. Write this down before you need it.Un procedimiento de emergencia documentado para cuando un custodio queda repentinamente no disponible. Escríbelo antes de necesitarlo.
⚠️ Storage rule:⚠️ Regla de almacenamiento: This document must NOT be stored in any system it provides access to. Print it. Encrypt a copy with a separate SSS key held by a different set of members.Este documento NO debe almacenarse en ningún sistema al que proporciona acceso. Imprímelo. Cifra una copia con una clave SSS separada.
🎯Tabletop Exercises / Fire DrillsEjercicios de mesa y simulacros
A fire drill is a practice run of your security protocols: done in a safe, low-stakes setting before you need them for real. Just like a building fire drill teaches people which exit to use before the fire happens, a security tabletop exercise teaches your collective who calls the lawyer, who rotates the credentials, and who makes decisions: before someone's phone actually gets seized at 2am.Un simulacro es un ensayo de tus protocolos de seguridad en un entorno seguro antes de necesitarlos de verdad. Igual que un simulacro de incendio enseña a la gente qué salida usar antes del incendio, un ejercicio de mesa enseña a tu colectivo quién llama al abogado, quién rota las credenciales y quién toma decisiones: antes de que alguien realmente tenga su teléfono confiscado.
Security protocols you have only read but never practiced will fail in a crisis. Run one exercise per quarter. Each takes 60 to 90 minutes. You do not need to be technical: you just need to sit together and walk through "what would we actually do?"Los protocolos de seguridad que solo has leído pero nunca practicado fallarán en una crisis. Haz un ejercicio por trimestre. Cada uno toma 60 a 90 minutos. No necesitas ser técnico: solo necesitas sentarte y recorrer "¿qué haríamos realmente?"
🎭 How to run one (90 min format)🎭 Cómo hacer uno (formato 90 min)
Step-by-step facilitation guide for a tabletop exercise.Guía de facilitación paso a paso para un ejercicio de mesa.
1. Present the scenario: read it out loud. Do not skip details. (2 min)
2. Walk through it step by step: the facilitator asks "OK, what happens first? Who does it? How do they contact the group if Signal is down?" (30-45 min)
3. Compare what you said to the written protocol: where did you diverge? Where was there no written protocol at all? (15 min)
4. Document the gaps: one named person owns each gap. They update the protocol within one week. (10 min)
What good exercises always reveal:
• Steps that exist on paper but nobody actually knows how to do
• Dependencies on one person who might be the arrested member
• Communication tools that assume the compromised service is still working
• Decisions that require group vote when there is no time for one Antes de empezar: Designa un facilitador que no sea el líder del grupo. Todos tienen acceso a los documentos de protocolo escritos.
1. Presenta el escenario: léelo en voz alta. (2 min)
2. Recórrelo paso a paso: el facilitador pregunta "¿qué pasa primero? ¿Quién lo hace? ¿Cómo contacta al grupo si Signal está comprometido?" (30-45 min)
3. Compara con el protocolo escrito: ¿dónde divergiste? (15 min)
4. Documenta las lagunas: una persona responsable por cada laguna, actualiza en una semana. (10 min)
A trusted member texts from a borrowed phone: "They took my phone at the protest. It was unlocked. Signal with all group chats was open. The shared vault file may have been on it too."Un miembro escribe desde un teléfono prestado: "Me cogieron el teléfono. Estaba desbloqueado. Signal con todos los chats estaba abierto."
- Who receives this alert and how? If Signal is compromised, what's your out-of-band channel?¿Quién recibe esta alerta y cómo? Si Signal está comprometido, ¿cuál es tu canal fuera de banda?
- First 15 minutes: what exactly happens and who does it?Primeros 15 minutos: ¿qué ocurre exactamente y quién lo hace?
- Which credentials need rotation and in what order?¿Qué credenciales necesitan rotación y en qué orden?
- Who has authority to initiate rotation without a group vote?¿Quién tiene autoridad para iniciar la rotación sin votación del grupo?
- How do you confirm the incident is real, not social engineering?¿Cómo confirmas que el incidente es real y no ingeniería social?
- No out-of-band alert channel existsNo existe canal de alerta fuera de banda
- Credential rotation bottlenecked on one person (Bus Factor)La rotación de credenciales depende de una sola persona (Factor Autobús)
- No plan for reforming Signal group if compromisedSin plan para reformar el grupo de Signal si está comprometido
Email from your cloud provider: "We have received a legal data request for your account. We will comply in 72 hours unless challenged in court."Email de tu proveedor de nube: "Hemos recibido una solicitud legal de datos. Cumpliremos en 72 horas a menos que se impugne judicialmente."
- Do you have a lawyer contact? If not, who do you call in the next 30 minutes?¿Tienes contacto de abogado? Si no, ¿a quién llamas en los próximos 30 minutos?
- What's actually in that drive: and is it all sensitive?¿Qué hay realmente en esa nube: y es todo sensible?
- Can you challenge the scope before the 72-hour window closes?¿Puedes impugnar el alcance antes de que cierre la ventana de 72 horas?
- Do you have an offline backup? Can you migrate critical data in time?¿Tienes copia de seguridad offline? ¿Puedes migrar datos críticos a tiempo?
- Does your warrant canary need updating?¿Necesita actualización tu canario de orden?
- No pre-established lawyer relationshipSin relación preestablecida con un abogado
- No offline backup of critical documentsSin copia de seguridad offline de documentos críticos
- Warrant canary not maintained (or never set up)Canario de orden no mantenido (o nunca configurado)
After a heated conflict, a member announces they're leaving. Raised voices, accusations, and a threat to "expose" the organization. The departure is hostile and immediate.Tras un conflicto acalorado, un miembro anuncia que se va. Voces elevadas, acusaciones, y una amenaza de "exponer" la organización.
- Immediate access revocation sequence: who handles Signal / email / server / social, in what order?Secuencia de revocación de acceso inmediata: ¿quién maneja Signal / correo / servidor / social, en qué orden?
- What does this person know that's a security risk? (Real identities, plans, infrastructure)¿Qué sabe esta persona que es un riesgo de seguridad? (Identidades reales, planes, infraestructura)
- Do you change the meeting location? The Signal invite link?¿Cambiais la ubicación de las reuniones? ¿El enlace de invitación de Signal?
- What elevated security posture do you adopt, for how long, and who decides de-escalation?¿Qué postura de seguridad elevada adoptáis, y quién decide la desescalada?
- No pre-agreed hostile departure protocol: people argue about what to do in the momentSin protocolo de salida hostil acordado previamente
- Revocation feels like punishment: wasn't framed as security in advance, so it gets personalLa revocación parece un castigo: no se enmarcó como seguridad de antemano
- No tiered de-escalation plan after the immediate crisisSin plan de desescalada escalonado tras la crisis
The best time to discover gaps is during a 90-minute meeting with coffee. The worst time is 2am when someone's phone has just been seized.El mejor momento para descubrir lagunas es durante una reunión de 90 minutos. El peor momento es a las 2am cuando el teléfono de alguien acaba de ser incautado.
⚖️Security Culture vs. ParanoiaCultura de seguridad vs. paranoia
Security culture protects the organization. Paranoia destroys it. State agencies know this: the most sophisticated operations don't arrest activists; they destabilize them from within using a well-documented playbook of psychological manipulation.La cultura de seguridad protege a la organización. La paranoia la destruye. Las agencias estatales lo saben: las operaciones más sofisticadas no arrestan activistas; los desestabilizan desde dentro.
🕵️ COINTELPRO Tactics: Know What You're Up Against🕵️ Tácticas COINTELPRO: Conoce a qué te enfrentas
These are documented, historically-verified methods used by intelligence agencies to destroy activist organizations from within. Recognizing them is not paranoia: it is history.Estos son métodos documentados e históricamente verificados usados por agencias de inteligencia para destruir organizaciones activistas desde dentro. Reconocerlos no es paranoia: es historia.
Security decisions must be based on specific, articulable behavior: not discomfort, not personality clashes, not rumors. The security committee handles security. The group handles everything else. Keep these separate.Las decisiones de seguridad deben basarse en comportamientos específicos y articulables: no en incomodidad, choques de personalidad o rumores. El comité de seguridad maneja la seguridad. El grupo maneja todo lo demás.
💰Collective Financial OPSECOPSEC financiero colectivo
Infrastructure costs leave financial trails. Domains, servers, VPNs, and SIM cards bought with traceable payment methods link your digital infrastructure to real identities. The goal is plausible separation between your collective's infrastructure and any individual's financial identity.Los costos de infraestructura dejan rastros financieros. Dominios, servidores, VPNs y tarjetas SIM comprados con métodos de pago rastreables vinculan tu infraestructura digital con identidades reales. El objetivo es una separación plausible.
🔄 Rotating treasurer model🔄 Modelo de tesorero rotativo
A simple operational practice that prevents any single member from being the bottleneck for all financial traces.Una práctica operacional simple que evita que un solo miembro sea el cuello de botella para todos los rastros financieros.
🔵 Monero (XMR): high-threat model🔵 Monero (XMR): modelo de amenaza alta
For groups facing serious financial surveillance, Monero provides cryptographic privacy that cash-equivalent prepaid cards cannot.Para grupos que enfrentan vigilancia financiera seria, Monero proporciona privacidad criptográfica que las tarjetas prepago equivalentes al efectivo no pueden.
Acquiring XMR without a KYC link:
• Peer-to-peer cash trades (LocalMonero shut down in 2023; use Bisq or in-person community exchanges)
• Bitcoin ATM → XMR via atomic swap (Serai DEX / Farcaster)
• CPU mining (very slow, but zero financial trace)
Services that accept XMR: Mullvad, iVPN, 1984.is, Njalla, Cockbox
⚠️ Critical warning: Converting XMR back to fiat at any KYC exchange re-links your funds to your identity at the exit point. The anonymity chain is only as strong as its weakest link. Por qué Monero y no Bitcoin: Bitcoin es pseudónimo: todas las transacciones son públicas. Monero usa firmas de anillo, direcciones sigilosas y transacciones confidenciales: el remitente, el receptor y el monto son todos indistinguibles.
Adquirir XMR sin un vínculo KYC:
• Intercambios peer-to-peer en efectivo (LocalMonero cerró en 2023; usa Bisq o intercambios en persona)
• ATM de Bitcoin → XMR mediante intercambio atómico
• Minería con CPU (muy lenta, pero sin rastro financiero)
Servicios que aceptan XMR: Mullvad, iVPN, 1984.is, Njalla
⚠️ Advertencia crítica: Convertir XMR de nuevo a fiat en cualquier exchange con KYC vincula tus fondos a tu identidad en el punto de salida.
The goal is proportionate separation: your infrastructure costs should not be directly traceable to any member's legal identity. Prepaid cards loaded with cash are sufficient for most groups. Monero is for high-threat situations where even that is not enough.El objetivo es separación proporcional: los costos de infraestructura no deben ser directamente rastreables a la identidad legal de ningún miembro. Las tarjetas prepago son suficientes para la mayoría de los grupos. Monero es para situaciones de amenaza alta.
📋 Phase 06 · Key Takeaways📋 Fase 06 · Puntos clave
Legal DefenseDefensa Legal
🛡️Know Your RightsConoce tus derechos
Most people make their worst legal decisions in the first 30 seconds of a police encounter: not because they don't know their rights, but because they haven't practiced saying the words under pressure. These three phrases are your entire legal toolkit.La mayoría de las personas toman sus peores decisiones legales en los primeros 30 segundos de un encuentro policial: no porque no conozcan sus derechos, sino porque no han practicado decir las palabras bajo presión.
📋 Legal observer protocols & documentation📋 Protocolos de observador legal y documentación
Knowing your rights is necessary but not sufficient: documentation creates accountability.Conocer tus derechos es necesario pero no suficiente: la documentación crea responsabilidad.
• Officer badge numbers and names if visible
• Time, location, what was said
• Witnesses' contact information
• Injuries or property taken
Legal observer presence: Organizations like the National Lawyers Guild (US) and Bindmans Activists Legal Support (UK) train and deploy legal observers to protests. They wear distinctive clothing, document arrests, and provide rapid legal support. Know how to contact them before your action. Siempre documenta los encuentros:
• Números de placa y nombres de los agentes si son visibles
• Hora, ubicación, qué se dijo
• Información de contacto de testigos
• Lesiones o propiedad confiscada
Presencia de observadores legales: Organizaciones como National Lawyers Guild (EE.UU.) y Bindmans (UK) despliegan observadores legales en protestas. Sabe cómo contactarlos antes de tu acción.
👁️Legal ObserversObservadores Legales
Legal observers are trained volunteers who attend protests and direct actions to document police conduct, record arrests, and provide critical information to lawyers. They are not your lawyer: but they may save your case.Los observadores legales son voluntarios entrenados que asisten a protestas y acciones directas para documentar la conducta policial, registrar arrestos y proporcionar información crítica a los abogados.
📋 What legal observers do📋 Qué hacen los observadores legales
Their role, what they record, and what they can and can't do for you.Su rol, qué registran y qué pueden y no pueden hacer por ti.
• Names and badge numbers of officers involved in arrests
• Arrest times, locations, and circumstances
• Charges read at the time of arrest
• Any use of force or crowd control weapons
• Names and contact info of witnesses
They do not:
• Interfere with police actions
• Provide legal advice at the scene
• Act as your personal bodyguard or representative
After an action, they pass documentation to:
• Defense lawyers for arrested activists
• Organizations like the NLG (US), GreenLegal (UK), or equivalent in your country Documentan:
• Nombres y números de placa de agentes involucrados en arrestos
• Horas, lugares y circunstancias de arrestos
• Cargos leídos en el momento del arresto
• Cualquier uso de fuerza o armas de control de multitudes
No hacen:
• Interferir con acciones policiales
• Proporcionar asesoría legal en el lugar
Después de la acción, pasan documentación a:
• Abogados de defensa para activistas arrestados
• Organizaciones como NLG (EE.UU.) o equivalentes en tu país
🎓 How to become a legal observer🎓 Cómo convertirse en observador legal
Training requirements and organizations to contact.Requisitos de formación y organizaciones a contactar.
• Legal observer role and limitations
• Documentation techniques and what to record
• How to interact with police without interfering
• Chain of custody for your notes
Key organizations:
• US: National Lawyers Guild (NLG): nlg.org. Green-hat observers at almost every major US protest
• UK: Green & Black Cross: greenandblackcross.org
• Germany: Rote Hilfe: rote-hilfe.de
• France: Observateurs légaux / La Quadrature du Net
• Spain: Contact your local social movement legal network or Xnet La mayoría de programas requieren una formación corta (tipicamente 2–4 horas) que cubre:
• Rol y limitaciones del observador legal
• Técnicas de documentación
• Cómo interactuar con la policía sin interferir
Organizaciones clave:
• EE.UU.: National Lawyers Guild (NLG): nlg.org
• Reino Unido: Green & Black Cross: greenandblackcross.org
• Alemania: Rote Hilfe: rote-hilfe.de
• España: Contacta tu red legal de movimientos sociales o Xnet
⚖️Know Your Rights by CountryConoce tus derechos por país
Legal protections vary dramatically between countries. Tap a country to see the key differences that affect activist security.Las protecciones legales varían dramáticamente entre países. Toca un país para ver las diferencias clave que afectan la seguridad activista.
📜When They Subpoena Your DataCuando citan tus datos judicialmente
Governments don't need to crack your encryption if they can order Google, Meta, or your email provider to hand over everything. Understanding how this works is critical to choosing the right tools.Los gobiernos no necesitan romper tu cifrado si pueden ordenar a Google, Meta, o tu proveedor de email que les entreguen todo. Entender cómo funciona esto es crítico para elegir las herramientas adecuadas.
What tech companies hand over (and what they can't)
The difference between "we have it" and "we can't access it" is your security margin.
• Hands over: Email content (full text), Drive files, search history, YouTube watch history, location timeline, Chrome bookmarks/history (if synced), device info, IP logs, ad profile
• Can't access: Nothing. If it's on Google's servers, Google can read it and hand it over.
• Notification: Google generally notifies users of legal requests unless a gag order prohibits it. Check Google Transparency Report.
Meta (Facebook, Instagram, WhatsApp):
• Hands over: Profile data, friend lists, messages (FB/IG, not E2E by default), photos, IP logs, login times, ad interactions, group memberships
• WhatsApp: Metadata (who you talk to, when, how often), group membership, profile photo. Message content is E2E encrypted BUT if you use iCloud/Google Drive backup, the backup is accessible.
• Can't access: E2E encrypted WhatsApp message content (if no cloud backup)
Apple:
• Hands over: iCloud data (photos, backups, mail, notes, contacts), purchase history, device info
• iMessage: E2E encrypted, but iCloud backups include iMessage history in readable form (unless Advanced Data Protection is enabled)
• Can't access: Device content on a locked phone (with exceptions for old iOS versions). iMessage content with ADP enabled.
Signal:
• Hands over: Account creation date and last connection date. That's it. Published in Signal's transparency report with actual subpoena responses.
• Can't access: Messages, contacts, groups, profile, anything else. They don't have it.
ProtonMail:
• Hands over: Account metadata, IP address (if logging is enabled by Swiss court order). Email content of incoming unencrypted emails.
• Can't access: Content of Proton-to-Proton encrypted emails. But be aware: Proton has complied with Swiss court orders to log IP addresses of specific users.
How to set up transparency alerts
Know when a company receives a request about your account.
• Google: If Google receives a legal request, they typically notify you via email (unless gagged). Keep your recovery email updated and check it regularly. Enable Google Account security alerts.
• Apple: Enable Advanced Data Protection (Settings → Apple ID → iCloud → ADP). This E2E encrypts almost all iCloud data, making it inaccessible even to Apple.
• Meta: No reliable notification system. Assume they comply silently. Minimize data on their platforms.
Warrant canary:
A warrant canary is a public statement that says "we have NOT received a secret government order." If the statement disappears, it implies they received one (since they can be legally prohibited from disclosing it, but not compelled to lie).
• Check your service providers' transparency pages for canary statements
• For collectives: publish your own warrant canary on your website. Update it regularly on a predictable schedule. If you miss an update, your community knows something may be wrong.
Practical advice:
• Don't use cloud backups for sensitive data (disable iCloud backup, Google backup for activist device)
• Host your own services where possible (Nextcloud, Vaultwarden, Matrix/Element)
• Use services in jurisdictions with strong privacy protections (Swiss: Proton, Tresorit. Icelandic: Flokinet)
What to do if you're served
If you or your organization receives a subpoena for digital data.
1. Don't panic. Don't destroy evidence. Destroying evidence after receiving a legal preservation order is a crime (spoliation). Do not delete anything after being served.
2. Contact a lawyer immediately. Before responding, before talking to anyone, before touching any devices. Digital rights organizations that offer free legal support:
• EFF (US): eff.org
• Access Now (international): accessnow.org/help, 24/7 digital security helpline
• EDRi (EU): edri.org, network of digital rights organizations across Europe
• Xnet (Spain): xnet-x.net, digital rights and anti-corruption
• Chaos Computer Club (Germany): ccc.de, legal and technical support
• La Quadrature du Net (France): laquadrature.net
3. Evaluate scope: What data is being requested? Is the request overly broad? A lawyer can challenge overbroad requests.
4. Notify your collective: They need to know and may need to adjust their security posture.
5. Document everything: Keep copies of the subpoena and all communications about it.
🐦Warrant Canaries & Transparency ReportsCanarios de orden e informes de transparencia
A warrant canary is a regularly published statement that a service provider has NOT received certain types of secret government demands. When government agencies serve national security letters or gag orders, they can prohibit the provider from disclosing the request: but they cannot compel the provider to actively lie. Removing the canary statement implies the canary has "died": that a secret order has been received.Un canario de orden es una declaración publicada regularmente de que un proveedor de servicios NO ha recibido ciertos tipos de demandas gubernamentales secretas. Las agencias gubernamentales pueden prohibir al proveedor revelar la solicitud: pero no pueden obligarlo a mentir activamente.
💀 If a canary dies: what to do💀 Si un canario muere: qué hacer
A missing or unupdated canary implies a secret order may have been received. Here's the response protocol.Un canario faltante o no actualizado implica que se puede haber recibido una orden secreta. Aquí está el protocolo de respuesta.
Monitor via Warrant Canary Watch (warrantcanary.com) which aggregates status for major providers. Also bookmark canary URLs directly and check monthly.Monitorea via Warrant Canary Watch (warrantcanary.com). También marca las URLs de canario directamente y verifica mensualmente.
🏗️ Running Your Own Warrant Canary🏗️ Gestionar tu propio canario de orden
Collectives that host their own services can: and should: publish and maintain their own warrant canary.Los colectivos que alojan sus propios servicios pueden: y deben: publicar y mantener su propio canario de orden.
A canary is most credible when it makes specific, verifiable, time-stamped claims. Include:
1. The date of publication (and commit to updating on a fixed schedule: monthly or quarterly)
2. Explicit statements of what has NOT been received: "We have not received any National Security Letters, FISA court orders, subpoenas for user data, or gag orders."
3. A cryptographic signature by a known key (PGP-signed canary is much more credible than plain text)
4. A description of what infrastructure/services the canary covers
How to host it:
• Publish on your website as a standalone page (/canary.txt is a conventional path)
• Commit to updating it on a public schedule: a missed update is the warning signal
• PGP-sign each update: this proves the statement was made by your collective and not forged
• The signing key should have a known, established fingerprint: publish the fingerprint alongside the canary
Limitations to communicate to your users:
• Canaries are most effective for NSLs and similar secret orders in specific jurisdictions
• They provide no protection against non-disclosure agreements that cover the canary itself (some jurisdictions have unclear law on this)
• They are not a guarantee: they are a best-effort transparency mechanism Lo que debe declarar el canario de tu colectivo:
Incluye:
1. La fecha de publicación (y comprometete a actualizar en un horario fijo: mensual o trimestral)
2. Declaraciones explícitas de lo que NO se ha recibido
3. Una firma criptográfica por una clave conocida (el canario firmado con PGP es mucho más creíble)
4. Una descripción de qué infraestructura/servicios cubre el canario
Cómo alojarlo:
• Publica en tu web como página independiente (/canary.txt es una ruta convencional)
• Comprometete a actualizarlo en un horario público: una actualización perdida es la señal de advertencia
• Firma con PGP cada actualización
🏢Platform Compliance with Law EnforcementCumplimiento de plataformas con fuerzas del orden
Every platform has a legal team that responds to government requests. What they can hand over is determined by what they technically have. Understanding both helps you choose the right tool before you need to.Cada plataforma tiene un equipo legal que responde a solicitudes gubernamentales. Lo que pueden entregar lo determina lo que técnicamente tienen. Entender ambos te ayuda a elegir la herramienta correcta.
Who you messaged, when, how often, and from where can be used to map your network even when message content is protected by encryption. Platforms that store metadata comply with metadata requests even when they cannot access content.Con quién mensajeaste, cuándo, con qué frecuencia y desde dónde puede usarse para mapear tu red incluso cuando el contenido está cifrado.
⚠️Criminal Exposure for ActivistsExposición penal para activistas
Activist activities: even legal ones: can expose you to criminal liability through broad or misapplied laws. Knowing the legal landscape is not paranoia: it's operational security.Las actividades activistas: incluso las legales: pueden exponerte a responsabilidad penal a través de leyes amplias o mal aplicadas. Conocer el panorama legal no es paranoia: es seguridad operacional.
⚖️ Charges commonly used against activists⚖️ Cargos usados frecuentemente contra activistas
Understanding which laws get weaponized: and how.Entender qué leyes se utilizan como armas: y cómo.
Incitement / Sedition: Used against speech and organizing, particularly around protests. The bar for incitement varies dramatically by country. In the US, it requires imminent lawless action. In the UK and EU, definitions are broader. Social media posts can constitute incitement.
Computer Fraud and Abuse Act (CFAA) / Computer Misuse Act (UK): Extremely broad computer crime laws frequently used against activists, journalists, and security researchers. In the US, the CFAA has been used to prosecute basic web scraping and account sharing. Know that accessing systems "without authorization": even systems you have partial access to: can trigger these laws.
Obstruction of Justice: Can apply to deleting communications, refusing to answer questions, or even coordinating your story with fellow activists before talking to police. Do not discuss the facts of an incident with anyone except your lawyer.
Terrorism enhancement charges: In the US, EU, and UK, "eco-terrorism" and "domestic terrorism" labels have been applied to property destruction and civil disobedience. These labels dramatically increase sentencing and can trigger additional surveillance authorities. Conspiración: Uno de los cargos más peligrosos para activistas. Solo requiere un acuerdo entre dos o más personas para cometer una infracción: la infracción no necesita ocurrir.
Incitación / Sedición: Usada contra el discurso y la organización. El umbral varía dramáticamente por país. Las publicaciones en redes sociales pueden constituir incitación.
Leyes de delitos informáticos (CFAA / Computer Misuse Act): Leyes extremadamente amplias usadas con frecuencia contra activistas, periodistas e investigadores de seguridad.
Obstrucción a la justicia: Puede aplicarse a eliminar comunicaciones, negarse a responder preguntas, o coordinar tu historia con otros activistas antes de hablar con la policía.
Cargos de terrorismo: Las etiquetas de "eco-terrorismo" y "terrorismo doméstico" se han aplicado a la destrucción de propiedad y la desobediencia civil.
🔒 Digital evidence and how it's used🔒 Evidencia digital y cómo se usa
What prosecutors extract from devices and accounts: and what minimizes your exposure.Lo que los fiscales extraen de dispositivos y cuentas: y qué minimiza tu exposición.
• Signal/WhatsApp group messages (if device is seized and unlocked)
• Location data from carrier records or Google Timeline
• Social media posts, DMs, and deleted posts (via subpoena to platforms)
• Email metadata and content (via subpoena to providers)
• Photos and videos with EXIF data (GPS coordinates, timestamp, device ID)
• Venmo/PayPal/Cashapp transaction records showing coordination
How to minimize exposure:
• Use Signal with disappearing messages enabled (set to 1 week or less for sensitive discussions)
• Disable location history in Google / Apple
• Strip EXIF from all photos before sending
• Use cash or privacy-respecting payment methods for collective funds
• Maintain discipline around what is committed to writing at all: the best evidence minimization is not generating it Evidencia digital más usada en juicios contra activistas:
• Mensajes de grupos Signal/WhatsApp (si el dispositivo es incautado y desbloqueado)
• Datos de ubicación de registros de operador o Google Timeline
• Publicaciones en redes sociales y DMs (vía citación a plataformas)
• Fotos y videos con datos EXIF (coordenadas GPS, marca de tiempo, ID de dispositivo)
• Registros de transacciones de Bizum/PayPal mostrando coordinación
Cómo minimizar la exposición:
• Usa Signal con mensajes temporales habilitados
• Desactiva el historial de ubicación en Google/Apple
• Elimina EXIF de todas las fotos antes de enviar
• Usa efectivo para fondos colectivos
• Mantén disciplina sobre qué se pone por escrito
In conspiracy prosecutions, the communications of every member of your group can become evidence against every other member. A single person's sloppy OPSEC can implicate the entire collective. Security culture is not just personal protection: it is protection for everyone you organize with. En juicios por conspiración, las comunicaciones de cada miembro de tu grupo pueden convertirse en evidencia contra todos los demás. Un OPSEC descuidado de una persona puede implicar a todo el colectivo. La cultura de seguridad no es solo protección personal: es protección para todos con quienes te organizas.
📚Legal Resources & How to Find SupportRecursos legales y cómo encontrar apoyo
You need to identify legal support resources before you need them. A lawyer's number you don't have at 2am in a holding cell is worthless. These organizations provide free or low-cost legal support to activists and civil society.Necesitas identificar recursos de apoyo legal antes de necesitarlos. El número de un abogado que no tienes a las 2am en una celda no sirve de nada.
📋 How to find a movement lawyer before you need one📋 Cómo encontrar un abogado de movimientos antes de necesitarlo
A lawyer you've already contacted is worth ten times one you're cold-calling from a holding cell.Un abogado con quien ya has contactado vale diez veces más que uno al que llamas en frío desde una celda.
Step 2: Have a brief consultation before you need them. Understand their fee structure (many movement lawyers work pro bono or sliding scale for civil disobedience cases). Confirm they understand the kind of cases you might face.
Step 3: Write down their number on paper and memorize it, or ensure your collective's emergency contact list includes it. Your phone may not be available after an arrest.
Step 4: Brief your collective. Everyone should know the number and know to say only: "I am exercising my right to remain silent. I want a lawyer." Nothing else. Paso 1: Contacta tu equivalente nacional o regional de NLG / Rote Hilfe / Green & Black Cross.
Paso 2: Ten una breve consulta antes de necesitarlos. Entiende su estructura de honorarios.
Paso 3: Escribe su número en papel y memorízalo.
Paso 4: Informa a tu colectivo. Todos deben saber decir solo: "Ejerzo mi derecho a guardar silencio. Quiero un abogado."
Consider printing a physical card with: (1) your lawyer's number, (2) your collective's legal hotline, (3) the three sentences you say to police. Keep it in your physical wallet: not just your phone. Print one for every member of your collective before any high-risk action. Considera imprimir una tarjeta física con: (1) el número de tu abogado, (2) la línea legal de tu colectivo, (3) las tres frases que dices a la policía. Guárdala en tu cartera física: no solo en tu teléfono.
📋 Phase 07 · Key Takeaways📋 Fase 07 · Puntos clave
Audit, Self-Certification & Next StepsAuditoría, auto-certificación y próximos pasos
🔧Tool DirectoryDirectorio de herramientas
Filter by category to find the right secure tool for your needs. Click any card to visit the official site.Filtra por categoría para encontrar la herramienta segura adecuada. Haz clic en cualquier tarjeta para visitar el sitio oficial.
🧹Complete Digital CleanupLimpieza digital completa
Follow these 6 phases to systematically reduce your digital footprint. Track your progress · each checked task makes you harder to surveil.Sigue estas 6 fases para reducir sistemáticamente tu huella digital. Rastrea tu progreso · cada tarea marcada te hace más difícil de vigilar.
🧹 Digital Cleanup Wizard
6 phases · 36 tasks · ~2 hours
Progress:Progreso: 0/20 completedcompletados
PHASE 3.9: SOCIAL MEDIA & FEDIVERSEFASE 3.9: REDES SOCIALES Y FEDIVERSO
📲Social Media SecuritySeguridad de redes sociales
Social media is the primary OSINT source for law enforcement. Every post, like, and connection is potential evidence. Corporate platforms are surveillance infrastructure by design - but there's an alternative. Read the harm reduction guide for corporate platforms below, then read about the Fediverse.Las redes sociales son la fuente principal de OSINT para las fuerzas del orden. Las plataformas corporativas son infraestructura de vigilancia por diseño - pero existe una alternativa.
🏢 If you stay on corporate platforms: harm reduction🏢 Si te quedas en plataformas corporativas: reducción de daños
You may have reasons to stay on Instagram, X, or TikTok: visibility, community, existing reach. These settings won't make them safe, but they'll reduce the damage. Treat them as broadcast tools only, never as organizing tools.Puede que tengas razones para quedarte en Instagram, X o TikTok: visibilidad, comunidad, alcance existente. Estas configuraciones no las harán seguras, pero reducirán el daño. Tratalas solo como herramientas de difusión, nunca de organización.
How platforms share data with police
Transparency reports reveal the scale of government requests.
• Meta (Instagram/Facebook): IP logs, DMs (not E2E by default on IG), login timestamps, location history from check-ins, tagged photos, friend lists. Meta complied with 88% of US government requests in 2024.
• X/Twitter: Account info, IP addresses, DMs (not encrypted), tweet history including deleted tweets (retained 30 days). Known for geofence compliance.
• TikTok: Device identifiers, IP, watch history, draft videos (stored on servers even if never posted), clipboard data (caught scraping in 2020).
• Google (YouTube): Search history, watch history, location timeline, Gmail content, Drive files. Google received 150,000+ government requests in 2023 alone.
Without a court order (emergency disclosure): All major platforms have "emergency request" processes where police can access data without a warrant by claiming imminent danger. This is routinely abused, the fake emergency request (SWATting adjacent) problem is well-documented.
Key insight: Even E2E encrypted platforms store metadata: who you talk to, when, how often, from where. Metadata alone is enough to map an entire network.
Instagram hardening
Most activists live on Instagram. Configure it properly.
• Settings → Privacy → Private account → ON
• Settings → Privacy → Activity Status → OFF
• Settings → Privacy → Story → hide story from specific people, disable sharing to messages
• Settings → Security → Two-factor → Authenticator app (NOT SMS)
• Settings → Privacy → Tags → manually approve all tags
• Settings → Account → Personal info → remove phone number if possible (use email only)
• Settings → Privacy → Guides → OFF
• Disable location in every post, always
Behavioral: Never post in real-time at actions. Post 24-48h later minimum. Never show faces at actions (even in stories). Don't use polls or questions that reveal organizer knowledge. Disable "seen" in DMs via airplane mode trick (open DM in airplane mode, read, close app, disable airplane mode). Never organize in IG DMs, Meta has full access.
Photo metadata (EXIF, Exchangeable Image File) dangers
Every photo contains invisible data that can identify you.
• GPS coordinates (latitude, longitude, altitude)
• Device model, serial number, unique camera ID
• Date, time (to the second), timezone
• Software used to edit
• Thumbnail of original (even if you cropped something out)
Platforms that strip EXIF: Instagram, Twitter/X, Facebook (strip on upload, but they retain a copy internally)
Platforms that DON'T strip EXIF: Signal (does strip), Telegram (strips in compressed mode, NOT in "file" mode), email attachments, cloud links (Google Drive, Dropbox)
Tools to strip manually:
• ExifTool (command line):
exiftool -all= photo.jpg• Scrambled Exif (Android app): strips before sharing
• Metapho (iOS): view and remove EXIF
• mat2 (Linux): strips metadata from multiple file types
Geotagging and location leaks
You reveal your location even without GPS coordinates in the photo.
• WiFi network names visible in screenshots
• Street signs, building numbers, distinctive architecture in background
• Shadows reveal time of day + direction (used in OSINT investigations)
• Reflections in windows, sunglasses, eyes (yes, really, academic research has extracted room layouts from eye reflections)
• Transit vehicles, bus numbers, tram routes = pinpoint location
• Weather conditions cross-referenced with meteorological data
Rules for posting: Photograph against plain backgrounds when possible. Blur or crop any identifying environmental details. Use Signal's built-in face blur tool. Never post photos while still at a sensitive location. Be aware that multiple photos from different angles can be triangulated.
🌐 The Fediverse: the internet that isn't watching you🌐 El Fediverso: la internet que no te vigila
The Fediverse isn't a single platform - it's a network of thousands of independent servers that all speak the same language (ActivityPub). A Mastodon user can follow a Pixelfed user, comment on a PeerTube video, and interact with a Pleroma account - all from their own server. No single company owns any of it.El Fediverso no es una sola plataforma - es una red de miles de servidores independientes que hablan el mismo idioma (ActivityPub). Un usuario de Mastodon puede seguir a uno de Pixelfed, comentar un vídeo de PeerTube e interactuar con una cuenta de Pleroma - todo desde su propio servidor.
📖 Fediverse platform directory: what replaces what📖 Directorio de plataformas del Fediverso: qué reemplaza a qué
Every major social media type has a Fediverse equivalent. Here's the map.Cada tipo de red social tiene un equivalente en el Fediverso. Aquí está el mapa.
The largest and most mature Fediverse platform. Text-first microblogging (500 chars default, some instances allow more). Chronological feed: no algorithm. Strong instance-level content warnings culture. Used widely by journalists, activists, academics, and developers who left Twitter.La plataforma del Fediverso más grande y madura. Microblogging orientado al texto (500 caracteres por defecto). Feed cronológico: sin algoritmo. Muy usado por periodistas, activistas, académicos y desarrolladores que dejaron Twitter.
Photo and short video sharing, built for privacy by design. No algorithmic feed. No tracking pixels. No "suggested posts" feeding you content to keep you engaged. Built by a single developer (dansup) committed to privacy. Federated: your Pixelfed posts appear in Mastodon timelines.Compartición de fotos y vídeo corto, construido para la privacidad por diseño. Sin feed algorítmico. Sin píxeles de seguimiento. Sin "publicaciones sugeridas". Las publicaciones de Pixelfed aparecen en los timelines de Mastodon.
Federated video hosting. Instances can share videos peer-to-peer (BitTorrent-style), reducing bandwidth costs. No ads. No demonetization. No takedowns by YouTube's opaque content ID system. Used by independent media, documentary filmmakers, and activist channels that have been repeatedly removed from YouTube. You can run your own instance and maintain full control.Alojamiento de vídeo federado. Las instancias pueden compartir vídeos peer-to-peer, reduciendo costes de ancho de banda. Sin anuncios. Sin desmonetización. Sin eliminaciones opacas. Usado por medios independientes y canales activistas eliminados repetidamente de YouTube. Puedes gestionar tu propia instancia.
Link aggregation and community discussion boards. After Reddit's 2023 API changes killed third-party clients and sparked massive protests, a wave of users moved to Lemmy. "Communities" (like subreddits) are federated: a community on one instance can be subscribed to from any other. Lemmy is the most prominent, Kbin/Mbin is a lighter alternative.Agregación de enlaces y tablones de comunidad. Tras los cambios de API de Reddit en 2023, una ola de usuarios se mudó a Lemmy. Las "comunidades" (como subreddits) están federadas. Lemmy es el más prominente, Kbin/Mbin es una alternativa más ligera.
Long-form writing platforms that federate into Mastodon. A post on WriteFreely (write.as) gets a Mastodon-compatible profile: anyone on Mastodon can follow your blog and get posts in their feed. Ghost also supports ActivityPub. Minimal, distraction-free writing, no platform dependency for your audience.Plataformas de escritura larga que se federan en Mastodon. Una publicación en WriteFreely obtiene un perfil compatible con Mastodon: cualquier persona en Mastodon puede seguir tu blog. Ghost también soporta ActivityPub. Escritura minimalista sin dependencia de plataforma.
Federated audio hosting for music, podcasts, and recordings. Particularly useful for bands, radio projects, and activist podcast collectives. No label gatekeeping. Federated: your Funkwhale library can be followed from Mastodon.Alojamiento de audio federado para música, podcasts y grabaciones. Especialmente útil para bandas, proyectos de radio y colectivos de podcasts activistas. Sin control de discográficas. Tu biblioteca Funkwhale puede seguirse desde Mastodon.
⚙️ How federation actually works: and why it matters for your security⚙️ Cómo funciona la federación en realidad: y por qué importa para tu seguridad
Understanding the model helps you choose the right instance and understand the real threat surface.Entender el modelo te ayuda a elegir la instancia correcta y comprender la superficie de amenaza real.
Federation works exactly like email. You have a Gmail account, your comrade has a Proton account - you can still email each other. In the Fediverse: you're on mastodon.social, they're on kolektiva.social, you can still follow and interact with each other. The protocol (ActivityPub) handles the communication between instances.
What your instance admin can see:
• Your IP address on login (same as any website)
• Your posts, including deleted posts (for a short time before deletion propagates)
• Your followers/following list
• Direct messages sent within the same instance (DMs between different instances are effectively plaintext: they're not end-to-end encrypted, treat them like email)
What your instance admin cannot see:
• The content of your Signal messages
• What you do on other instances
• Your real identity, if you registered pseudonymously (use a Mullvad or ProtonMail address to register, access via VPN)
Federation means data spreads:
When you post publicly, your post gets copied to the servers of anyone who follows you. If you're on a tiny private instance and your followers are on mastodon.social, your public posts exist on mastodon.social's servers. Deleted posts propagate deletion requests, but not all servers process them immediately. Private/followers-only posts are shared only with the servers of people in that audience.
The threat model difference:
On Twitter/X, one subpoena to one company gives police everything. On the Fediverse, posts are distributed across potentially hundreds of servers in different jurisdictions, operated by different people under different legal frameworks. Surveillance requires either: a subpoena to your specific instance, or requesting data from every instance that federated your posts: a logistically harder operation with much weaker legal standing. La analogía del correo electrónico:
La federación funciona exactamente como el correo. Tienes una cuenta de Gmail, tu compañero tiene una de Proton - aún podéis enviáros emails. En el Fediverso: tú estás en mastodon.social, ellos en kolektiva.social, aún podéis seguiros e interactuar. El protocolo (ActivityPub) gestiona la comunicación entre instancias.
Lo que tu administrador de instancia puede ver:
• Tu dirección IP al iniciar sesión
• Tus publicaciones, incluidas las eliminadas (durante un corto período)
• Tu lista de seguidores/seguidos
• Mensajes directos en la misma instancia (los DMs entre diferentes instancias no están cifrados de extremo a extremo)
Lo que tu administrador de instancia NO puede ver:
• Tus mensajes de Signal
• Lo que haces en otras instancias
• Tu identidad real, si te registraste con seudónimo
La federación significa que los datos se dispersan:
Cuando publicas públicamente, tu publicación se copia a los servidores de quienes te siguen. Las publicaciones eliminadas propagan solicitudes de eliminación, pero no todos los servidores las procesan inmediatamente.
La diferencia en el modelo de amenazas:
En Twitter/X, una citación a una empresa da a la policía todo. En el Fediverso, las publicaciones están distribuidas en potencialmente cientos de servidores en diferentes jurisdicciones. La vigilancia requiere subpoenas a múltiples instancias bajo distintos marcos legales: una operación logísticamente mucho más difícil.
🏠 How to pick the right instance: and when to run your own🏠 Cómo elegir la instancia correcta: y cuándo gestionar la tuya propia
Your instance is your home. The admin has access to your data. Choose accordingly.Tu instancia es tu hogar. El administrador tiene acceso a tus datos. Elige en consecuencia.
• Jurisdiction: Where is the server legally based? EU instances fall under GDPR: stronger protections than US-based servers. Check the "About" page.
• Admin identity: Is the admin identifiable? Do they have a history of fighting legal requests? Small collectives running their own instances > anonymous unknown admins.
• Privacy policy: Does the instance have one? Does it explicitly address law enforcement requests?
• Size: Tiny instances have higher admin accountability. Very large instances (mastodon.social, 1M+ users) have more legal risk surface.
• Defederation policy: Does the instance block fascist/harassers? Can you see their blocklist? Good moderation matters.
• Uptime and maintenance: How long has it been running? Is it maintained by someone who will still be around in a year?
Good resources for finding instances:
• instances.social: searchable directory with rules, admin info, stats
• joinmastodon.org/servers: curated list of stable, moderated instances
• fedidb.org: technical stats on instances
When to run your own instance:
Running your own Mastodon/Pixelfed/PeerTube instance gives you maximum control: you are the admin, you set the rules, you handle (or resist) any legal requests. It's not technically difficult: Mastodon can be deployed on a €5/month VPS. Trade-offs:
• Pro: Complete control, no admin above you, customize rules and storage
• Pro: Your collective's data stays on your servers, not a third party's
• Con: You become a legal point of contact for any requests about your users
• Con: You're responsible for maintenance, updates, and backups
For small collectives: consider running a private invite-only instance for internal use alongside public presence on a larger instance. Qué comprobar antes de unirte a una instancia:
• Jurisdicción: ¿Dónde está legalmente basado el servidor? Las instancias de la UE están bajo el RGPD. Comprueba la página "Acerca de".
• Identidad del administrador: ¿Es identificable? ¿Tienen historial de resistir solicitudes legales?
• Política de privacidad: ¿Aborda explícitamente las solicitudes de las fuerzas del orden?
• Tamaño: Las instancias pequeñas tienen mayor responsabilidad del admin. Las muy grandes tienen mayor superficie de riesgo legal.
• Política de defederación: ¿Bloquea la instancia a fascistas/acosadores?
Cuándo gestionar tu propia instancia:
Para colectivos pequeños: considera ejecutar una instancia privada solo por invitación para uso interno junto a presencia pública en una instancia más grande.
🛡️ Using the Fediverse with maximum privacy🛡️ Usar el Fediverso con máxima privacidad
The Fediverse is not anonymous by default. Here's how to harden it for activist use.El Fediverso no es anónimo por defecto. Cómo reforzarlo para uso activista.
• Register with a ProtonMail or Tuta alias, never your personal email
• Username: don't reuse any existing handle from other platforms
• Access via VPN (Mullvad) or Tor browser to mask your IP from the instance admin
• Use the Tor Browser with a .onion Mastodon instance for maximum anonymity:
mastodon.socialand several others run Tor hidden servicesContent visibility settings (Mastodon):
• Public: on your profile and federated to all instances. Indexed by search engines if the instance allows it.
• Unlisted: visible to anyone who finds it, but not in local/federated timelines. Use this for most posts.
• Followers only: only your followers see it. NOT encrypted. Still viewable by your instance admin and the admins of your followers' instances.
• Direct message: only the tagged person. Still not encrypted. Use Signal for anything sensitive.
Apps for mobile:
• Tusky (Android, FOSS): open source, supports instance-level blocks
• Moshidon (Android): Tusky fork with extra privacy features
• Ivory (iOS): polished, from Tapbots
• Metatext (iOS, FOSS): open source
• Fedilab (Android): multi-account support, supports multiple Fediverse platforms
Cross-posting if you maintain corporate accounts:
Tools like Moa Party or Buffer can cross-post from Mastodon to Twitter/X and Instagram. This lets you maintain corporate presence while building Fediverse audience. However: if you cross-post, assume both audiences apply to your opsec: behave as if police follow both. Configuración de cuenta:
• Regístrate con un alias de ProtonMail o Tuta, nunca tu email personal
• Nombre de usuario: no reutilices ningún handle existente de otras plataformas
• Accede mediante VPN (Mullvad) o navegador Tor para ocultar tu IP al administrador de la instancia
Configuración de visibilidad de contenido (Mastodon):
• Público: en tu perfil y federado a todas las instancias. Indexado por motores de búsqueda.
• No listado: visible para quien lo encuentre, pero no en timelines. Úsalo para la mayoría de publicaciones.
• Solo seguidores: NO cifrado. Sigue siendo visible para el admin de tu instancia y los admins de las instancias de tus seguidores.
• Mensaje directo: solo la persona etiquetada. Tampoco cifrado. Usa Signal para cualquier cosa sensible.
Apps para móvil:
• Tusky (Android, FOSS): código abierto
• Fedilab (Android): soporte multi-cuenta, múltiples plataformas del Fediverso
• Ivory (iOS): pulido, de Tapbots
📢 Censorship resistance and content preservation on the Fediverse📢 Resistencia a la censura y preservación de contenido en el Fediverso
Palestinian content, protest footage, climate science: all suppressed or removed by corporate platforms. How the Fediverse handles this differently.Contenido palestino, material de protestas, ciencia climática: todo suprimido o eliminado por plataformas corporativas. Cómo el Fediverso lo gestiona de forma diferente.
• Meta's systematic suppression of Palestinian content during the 2021 and 2023/2024 Gaza offensives: documented by Human Rights Watch, 7amleh (Arab Center for the Advancement of Social Media), and Al-Haq. Instagram hid stories in real-time, reduced reach of solidarity posts, and in some cases removed accounts.
• Twitter/X's suppression of protest footage during the 2019 Hong Kong protests, Iran uprising (2022), and others. Content labeled "sensitive" algorithmically suppresses reach without explicit removal.
• YouTube's removal of anti-war content under pressure from state actors. RT's deplatforming was government-coordinated: whether you agree with it or not, it demonstrated the mechanism is available.
• GoFundMe and PayPal freezing accounts of Palestinian solidarity organizations.
How the Fediverse resists this:
• No algorithmic suppression. If someone follows you, they see your posts in chronological order. There is no "shadow-banning" at the protocol level.
• Instance-level choices. Kolektiva.social, run by anarchist activists, explicitly protects content corporate platforms suppress. They set their own moderation rules.
• Distributed copies. Public posts are federated: they exist on many servers. Removing them requires coordinated action across all instances that federated the content. This has happened (some instances chose to block content) but it's not a unilateral corporate decision.
• No advertiser pressure. Corporate platforms censor partly because advertisers don't want their ads near controversial content. The Fediverse has no ad model and therefore no advertiser pressure.
Content preservation tools:
• Archive important posts with archive.org before they can be removed from corporate platforms
• Mirror videos to PeerTube in addition to YouTube
• Use
yt-dlpto download and archive video documentation before it disappears• For sensitive documentation: consider eyeWitness to Atrocities: stores cryptographically verified evidence for legal use Incidentes documentados de censura corporativa:
• Supresión sistemática de Meta del contenido palestino durante las ofensivas de Gaza en 2021 y 2023/2024: documentada por Human Rights Watch, 7amleh y Al-Haq. Instagram ocultó historias en tiempo real y redujo el alcance de publicaciones de solidaridad.
• Supresión por Twitter/X de material de protestas durante las manifestaciones de Hong Kong en 2019 y el levantamiento iraní en 2022.
• Congelación por GoFundMe y PayPal de cuentas de organizaciones de solidaridad palestina.
Cómo resiste el Fediverso:
• Sin supresión algorítmica. Si alguien te sigue, ve tus publicaciones en orden cronológico. No hay "shadow-banning" a nivel de protocolo.
• Elecciones a nivel de instancia. Kolektiva.social, gestionada por activistas anarquistas, protege explícitamente el contenido que suprimen las plataformas corporativas.
• Copias distribuidas. Las publicaciones públicas están federadas: existen en muchos servidores. Eliminarlas requiere acción coordinada en todas las instancias.
• Sin presión de anunciantes. El Fediverso no tiene modelo publicitario y por tanto ninguna presión de anunciantes.