Skip to content

OPSEC for Activists and Journalists

Journalists, activists, and dissidents face adversaries far more capable than the commercial data brokers most privacy advice targets — police with subpoenas, corporations with lawyers, and sometimes nation-states with interception capability. Good operational security here is not about theoretical perfection; it’s about calibrating defenses to a realistic adversary and being disciplined about the few things that matter.

You can’t defend against everyone equally — decide who you’re actually up against:

AdversaryCan typically seeWill typically do
Corporations / data brokersTracking, purchased data, public recordsProfile, sell, deplatform
Local law enforcementSubpoenas to providers, device seizure, location dataCompel records, search devices
Nation-stateNetwork interception, malware, border controlTargeted compromise, coercion

Your defenses should match the top adversary you realistically face — overbuilding for a nation-state when your risk is a data broker wastes effort and usability; underbuilding the reverse can be dangerous.

The core discipline: keep identities, devices, accounts, networks, and social graphs separated so a breach of one doesn’t unravel the rest.

  • Distinct accounts per role, never sharing recovery addresses or phone numbers.
  • A dedicated device or profile for sensitive work — see Burner Devices Guide and Sock Puppet Accounts.
  • Reach sensitive accounts only over an anonymized path (Tor/VPN), consistently — see Tor Network Guide.
  • Full-disk encryption everywhere (LUKS, FileVault, Android/iOS default) — useless if the device is unlocked when seized, so power down at checkpoints (encryption keys leave RAM when off).
  • Strong passphrases over biometrics in high-risk moments — in many jurisdictions a fingerprint/face can be compelled more easily than a memorized passphrase.
  • Amnesic systemsTails boots from USB, routes everything through Tor, and leaves no trace on the host.
  • Border crossings — assume devices may be searched or copied; travel with minimal data, or clean devices, and restore afterward.
  • Scrub file/photo metadata before publishing — see Metadata Hygiene.
  • Reduce location history, ad IDs, and account exposure; audit what’s public about you.
  • Resist browser fingerprinting for research personas.

For in-person sensitive work: leave phones behind or use a Faraday pouch (a powered phone is a tracker and a microphone), agree on meeting protocols in advance over a secure channel, and learn basic surveillance-awareness. The most secure conversation is one with no electronics in the room.

  • Use Signal (disappearing messages) or a SecureDrop instance for source intake — purpose-built to protect source anonymity even from the news organization’s own infrastructure.
  • Protect source identity in published work too: strip document metadata, paraphrase identifying details, and avoid publishing originals that carry hidden tracking.
  • Treat your notes and contacts as seizable; encrypt and compartmentalize them.