I need serious anonymity online - is this setup secure

rafumem

Newbie
Joined
Apr 15, 2021
Messages
28
Reaction score
2
I need to be completely secure from my government as I do illegal political activities that could put me in jail for decades in my corrupt developing country.

For my activities I will be using Tails OS. I will use : User VPN Tor Internet. I trust my VPN provider so for now I will use my private wifi because COVID lockdown here. My question is how secure is this setup - is there an extra reason to use public wifi other than not trusting VPN? Am I protected from IP or DNS leaks on Tor? Can they track my activities?

I will be using a burner phone bought with cash and install a foreign number sim card to it - this is because I have to - this number will be in a position that it will be obviously used for illegal activity. I will need to check it for SMS messages. I'm aware that they can track its location but how spesific can that be? If I open it in my house can they directly link it to my apartment? In that case I will be using it on public places with caps and masks. Is that secure?

Thank you for your help. The activities I do are indeed illegal but they are not immoral - They are illegal because I live under a oppressive regime run by radicals.
 
Never trust a VPN from a private company. They sell it to you as "privacy", however, if necessary, they will hand over all your data to a intelligence / security service.

TOR is good, but you need the highest level of security in the configuration (no scripts etc.).

Here's my recommendation:

Version 1:
Your own private VPN installed on a private VPS server (only you have access to your logs / they are not recorded). + TOR

Version 2:
Private VPN installed on a VPS + Remote Desktop access to a private Linux installed on a different private VPS + TOR

Verion 3:
Cheap foreign SIM + Version 2.


With the second version you have an additional virtual machine with different Mac address etc.
 
By running tails, which as far as I'm aware already has relay of TOR prior to you connecting to anything, then adding VPN and again tor over it your internet speed will be just unbelievably slow.
Besides that from the perspective of OPSEC, it seems VPN over tor is not really advantageous...
Moreover a lot of ISPs see that you connect to TOR and it gets red flags that's why it is not a cool idea especially in oppressed countries to connect directly to TOR first (and again that's what you do by using TAILS) Unless your VPN is before tails. Somewhere on the router.
VPNs no matter how much you trust them under certain pressure will give away your information. Especially if you live in Five Eyes alliance countries.
If you live somewhere in Russia most likely VPN won't give you away (but don't take my word for it is more my opinion than actually a fact).
However if you are willing to take a risk running this rig from home here's what I'd suggest you run.
VPN on your router with rules to shutdown connection if VPN connection interrupts and tails on the top.
OR
Ununtu run VPN on ubuntu + Whonix virtual machine (it also routes traffic through TOR)
 
Never trust a VPN from a private company. They sell it to you as "privacy", however, if necessary, they will hand over all your data to a intelligence / security service.

TOR is good, but you need the highest level of security in the configuration (no scripts etc.).

Here's my recommendation:

Version 1:
Your own private VPN installed on a private VPS server (only you have access to your logs / they are not recorded). + TOR

Version 2:
Private VPN installed on a VPS + Remote Desktop access to a private Linux installed on a different private VPS + TOR

Verion 3:
Cheap foreign SIM + Version 2.


With the second version you have an additional virtual machine with different Mac address etc.
Do not do any of the suggested above except for internet from SIM. First of all, logs are still kept on VPS unless you fiddle to turn them off or auto delete. But most importantly connection logs are kept on the main Box where all the VPS are hosted. + ISP has these logs.(connection logs are the logs that show where exactly you connected). Yes your ISP won't see it. But VPS provider and their ISP can. So you double your risk than running your rig from a reputable VPN provider.
 
By running tails, which as far as I'm aware already has relay of TOR prior to you connecting to anything, then adding VPN and again tor over it your internet speed will be just unbelievably slow.
Besides that from the perspective of OPSEC, it seems VPN over tor is not really advantageous...
Moreover a lot of ISPs see that you connect to TOR and it gets red flags that's why it is not a cool idea especially in oppressed countries to connect directly to TOR first (and again that's what you do by using TAILS) Unless your VPN is before tails. Somewhere on the router.
VPNs no matter how much you trust them under certain pressure will give away your information. Especially if you live in Five Eyes alliance countries.
If you live somewhere in Russia most likely VPN won't give you away (but don't take my word for it is more my opinion than actually a fact).
However if you are willing to take a risk running this rig from home here's what I'd suggest you run.
VPN on your router with rules to shutdown connection if VPN connection interrupts and tails on the top.
OR
Ununtu run VPN on ubuntu + Whonix virtual machine (it also routes traffic through TOR)
Thank you. I will try to use your advice. What is your opinion on the phone stuff in the 3rd paragraph?
 
Tails is enough. VPN is a weak link.
PLEASE! Don't give advice about a topic you do not have a clear picture about. Especially on topic like that. VPN is never a weak link... Even a bad VPN is not a weak link... When you have tor over it... SMH

Thank you. I will try to use your advice. What is your opinion on the phone stuff in the 3rd paragraph?

If you connect to Phones internet (which of course is not linked to you) it is slightly safer if you have VPN and tor over it. Otherwise it is kinda same as using your own internet because by means of triangulation government still can figure out where you are sitting. But it all boils down to VPN provider (which again is a much better option than dedicated VPS) who has the power to give away connection logs. Which they have to have a really strong reason to. And to find out VPNs IP government first have to go through 3 relays of tor circuit and ask each provider who connected at this time to this service. By then most of the time all your usage logs if any are deleted most of the time... Only connection logs which are really hard to get from the reputable VPN provider if it not for really serious reasons.
But yeah with a SIM's 4g internet which is not linked to your name it is slightly better.
 
Last edited:
PLEASE! Don't give advice about a topic you do not have a clear picture about. Especially on topic like that. VPN is never a weak link... Even a bad VPN is not a weak link... When you have tor over it... SMH



If you connect to Phones internet (which of course is not linked to you) it is slightly safer if you have VPN and tor over it. Otherwise it is kinda same as using your own internet because by means of triangulation government still can figure out where you are sitting. But it all boils down to VPN provider (which again is a much better option than dedicated VPS) who has the power to give away connection logs. Which they have to have a really strong reason to. And to find out VPNs IP government first have to go through 3 relays of tor circuit and ask each provider who connected at this time to this service. By then most of the time all your usage logs if any are deleted most of the time... Only connection logs which are really hard to get from the reputable VPN provider if it not for really serious reasons.
But yeah with a SIM's 4g internet which is not linked to your name it is slightly better.
I will be using a burner phone bought with cash and install a foreign number sim card to it - this is because I have to - this number will be in a position that it will be obviously used for illegal activity. I will need to check it for SMS messages. I'm aware that they can track its location but how spesific can that be? If I open it in my house can they directly link it to my apartment? In that case I will be using it on public places with caps and masks. Is that secure?

I was talking about this - my phone usage will be unrelated to my pc usage.

Also I'd like to correct something I wrote - I won't use vpn to tor I will be using vpn over tor so I guess User → TOR→ VPN→ Internet

So I believe VPN provider won't know who I am if I pay anonymously.
 
Never trust a VPN from a private company. They sell it to you as "privacy", however, if necessary, they will hand over all your data to a intelligence / security service.

TOR is good, but you need the highest level of security in the configuration (no scripts etc.).

Here's my recommendation:

Version 1:
Your own private VPN installed on a private VPS server (only you have access to your logs / they are not recorded). + TOR

Version 2:
Private VPN installed on a VPS + Remote Desktop access to a private Linux installed on a different private VPS + TOR

Verion 3:
Cheap foreign SIM + Version 2.


With the second version you have an additional virtual machine with different Mac address etc.
I wrote that wrong I will be using User → TOR→ VPN→ Internet. So the VPN service won't know who I am I pay anonymously.
 
I will be using a burner phone bought with cash and install a foreign number sim card to it - this is because I have to - this number will be in a position that it will be obviously used for illegal activity. I will need to check it for SMS messages. I'm aware that they can track its location but how spesific can that be? If I open it in my house can they directly link it to my apartment? In that case I will be using it on public places with caps and masks. Is that secure?

I was talking about this - my phone usage will be unrelated to my pc usage.

Also I'd like to correct something I wrote - I won't use vpn to tor I will be using vpn over tor so I guess User → TOR→ VPN→ Internet

So I believe VPN provider won't know who I am if I pay anonymously.
I'll send you a PM in the messages. I don't really want to spam a forum with my replies :)
 
I wont point my fingers at anyone but some guys in this topic can just mislead you. Everyone here wants to be an expert even if given person dont know shit about given topic. Take every word with grain of salt.
Ast this question on many different forums including (but not limited to) stackexchange, stackoverflow, reddit, lowendtalk.

Rule no 1:
Dont do any "own" setup unles you know what are you doing and you are expert in given field. VPS with own vpn is terrible idea.

Read this article very carefully:
https://www.vpnmentor.com/blog/turkish-investigation-proves-expressvpn-does-not-keep-user-logs/
will need to check it for SMS messages. I'm aware that they can track its location but how spesific can that be? If I open it in my house can they directly link it to my apartment?
In worse case scenario - yes.
If you are going to use phone for tasks that can put you in jail do this:

You buy faraday's cage (read about it on internet) and you store your phone there.
You can open faraday's cage only when you are in public place (not in your car for example).
You use phone, check sms etc and you put phone back in faraday's cage.
If you do open faraday's cagein your appartment, friends appartment etc - they can track you and you are lost.

Btw phone use IMEI to log to celluar network, be prepared that your IMEI will be locked and probably you will have to switch phones quite often just because phones/simcards will be locked.
Prepare solution how you want to destroy phone (wipe all data etc).
Ceramic furnace could reach temperature so high that phone would just meltdown.

Btw - there are services like smspva where you can rent number for small monthly payment. Rent number, pay with crypto/whatever etc so you dont have real phone.
 
I wont point my fingers at anyone but some guys in this topic can just mislead you. Everyone here wants to be an expert even if given person dont know shit about given topic. Take every word with grain of salt.
Ast this question on many different forums including (but not limited to) stackexchange, stackoverflow, reddit, lowendtalk.

Rule no 1:
Dont do any "own" setup unles you know what are you doing and you are expert in given field. VPS with own vpn is terrible idea.

Read this article very carefully:
https://www.vpnmentor.com/blog/turkish-investigation-proves-expressvpn-does-not-keep-user-logs/

In worse case scenario - yes.
If you are going to use phone for tasks that can put you in jail do this:

You buy faraday's cage (read about it on internet) and you store your phone there.
You can open faraday's cage only when you are in public place (not in your car for example).
You use phone, check sms etc and you put phone back in faraday's cage.
If you do open faraday's cagein your appartment, friends appartment etc - they can track you and you are lost.

Btw phone use IMEI to log to celluar network, be prepared that your IMEI will be locked and probably you will have to switch phones quite often just because phones/simcards will be locked.
Prepare solution how you want to destroy phone (wipe all data etc).
Ceramic furnace could reach temperature so high that phone would just meltdown.

Btw - there are services like smspva where you can rent number for small monthly payment. Rent number, pay with crypto/whatever etc so you dont have real phone.
I agree. A separate phone just for SMS/Phone activity is not a good idea. + the advice about the usage of VPS is just absurd I facepalmed so hard when I saw his advice.
Only issue which is issue is that OP wants to run all of it from home which if he's not in five eyed alliance should be fine with this rig. But still could be vulnerable. That's why if he absolutely have to run it from home rather than public place then at least it has to be 4G internet which is not linked to his name.
 
the advice about the usage of VPS is just absurd I facepalmed so hard when I saw his advice.
What about fewer points of trust? With a paid VPN service, you pass all of your traffic through a third-party service operator and their cloud or network provider. When you set up your own server, you cut out the middleman — your data is private between you and whoever provides your server.

Let’s say you’re using some overseas VPN provider to hide your traffic from your own government, for whatever reason. Do you really know what security that VPN provider has? Do you know all the laws for the country in which they operate? Do you know their relationship with your government, e.g., EU, US, China, Australia?

There have been many situations where we find out later that some famous VPN provider has been infiltrated by one or more governments for months or years, with access to logs.

It’s going to be infinitely harder for a foreign government to come after some random IP address on Digital Ocean, for example, than just going to a known VPN provider. And if the box is already destroyed when they do come to Digital Ocean or whatever VPS provider you’re using, there’s not too much they’ll be able to do.
 
What about fewer points of trust? With a paid VPN service, you pass all of your traffic through a third-party service operator and their cloud or network provider. When you set up your own server, you cut out the middleman — your data is private between you and whoever provides your server.

Let’s say you’re using some overseas VPN provider to hide your traffic from your own government, for whatever reason. Do you really know what security that VPN provider has? Do you know all the laws for the country in which they operate? Do you know their relationship with your government, e.g., EU, US, China, Australia?

There have been many situations where we find out later that some famous VPN provider has been infiltrated by one or more governments for months or years, with access to logs.

It’s going to be infinitely harder for a foreign government to come after some random IP address on Digital Ocean, for example, than just going to a known VPN provider. And if the box is already destroyed when they do come to Digital Ocean or whatever VPS provider you’re using, there’s not too much they’ll be able to do.
Stop embarrassing yourself. The more you say more you show you have no clue what you are talking about. Yes, most VPN providers rent boxes but they are rented on the basis that they take all the legal obligation to full legal responsibility. So the owner of the box is not liable for whatever happens on the box he just forwards all the legal documents. And they are dealing with some offshore company from Panama or Seychelles. Unless it is a bad owner of the box (like it was the case with Russian boxes that is why NordVPN dumped their servers, and it is not fault of the server providers but simply a country... Because in Russia they don't care about law). And by box I don't mean a shizzy VPS. I mean the whole server box. Every time you connect to VPN you get IP from the pool/subnet of IPs which is random every time and usage is wiped right after the session. While on VPS you actually have to restart it. And in most cases they have Static IP anyway. But it is not even a problem. Problem is that even with dynamic IPs like AWS. The main box tracks all the connection logs of their VPS' on the main server.
while on the VPN whole network is set up by professional network administrators who specialize in OPSEC and who fix all the possible vulnerabilities much faster than an amateur would.
VPN providers who make claims that they don't keep logs make throughout research and don't rent servers from where a NOOB would (as example Digital Ocean).
Digital Ocean would give connection logs without even reading a legal notice. They would look at the legal doc. Who they want info for? There you go...
And IPs are never random... They are purchased and owned by the company. it is all traceable by timestamp and IP. So if I have legal authority I can issue a request to Digital Ocean of who connected to google.com @ 12.35:44 PST. They make a search through their main box and say. It was "AlexanderTheGreat"
 
Last edited:
Stop embarrassing yourself.

While I only mentioned DigitalOcean as an "example" in my last post, they still have good privacy/log rules:
https:// www.digitalocean.com/legal/law-enforcement-guidelines/

Quotes from DO's forum regarding VPN:
"We do not log customer traffic, we do log the volume of that traffic and know which IPs are assigned to Droplets, we do not “filter” traffic but we do have automated alerts in place to check for abuse based on a variety of factors (PPS, Bandwidth, etc.). If one of this alerts is tripped, we may then start filtering out / black holing traffic to protect the infrastructure from harm."

And of course, there are thousands of different VPS providers - including those in offshore areas.

How do you verify a "bad owner" ? How can you fully trust an online company? Even based in Seychelles and claiming having a network of best server admins?
If you’re that much of a threat, they’ll come for you physically and the VPN won’t matter that much.
 
While I only mentioned DigitalOcean as an "example" in my last post, they still have good privacy/log rules:
https:// www.digitalocean.com/legal/law-enforcement-guidelines/

Quotes from DO's forum regarding VPN:
"We do not log customer traffic, we do log the volume of that traffic and know which IPs are assigned to Droplets, we do not “filter” traffic but we do have automated alerts in place to check for abuse based on a variety of factors (PPS, Bandwidth, etc.). If one of this alerts is tripped, we may then start filtering out / black holing traffic to protect the infrastructure from harm."

And of course, there are thousands of different VPS providers - including those in offshore areas.

How do you verify a "bad owner" ? How can you fully trust an online company? Even based in Seychelles and claiming having a network of best server admins?
If you’re that much of a threat, they’ll come for you physically and the VPN won’t matter that much.

It doesn't make any sense to use VPS instead of a VPN if you are trying to hide your identity, some vpn providers proved in court that they do not keep any logs, so couldn't help in the investigation, I see no reason to use a VPS in this case.

I'd recommend (VM + VPN + TOR) to the OP
 
While I only mentioned DigitalOcean as an "example" in my last post, they still have good privacy/log rules:
https:// www.digitalocean.com/legal/law-enforcement-guidelines/

Quotes from DO's forum regarding VPN:
"We do not log customer traffic, we do log the volume of that traffic and know which IPs are assigned to Droplets, we do not “filter” traffic but we do have automated alerts in place to check for abuse based on a variety of factors (PPS, Bandwidth, etc.). If one of this alerts is tripped, we may then start filtering out / black holing traffic to protect the infrastructure from harm."

And of course, there are thousands of different VPS providers - including those in offshore areas.

How do you verify a "bad owner" ? How can you fully trust an online company? Even based in Seychelles and claiming having a network of best server admins?
If you’re that much of a threat, they’ll come for you physically and the VPN won’t matter that much.
Exactly how would you know right? I tell you how. People get burnt - VPN takes a hit and fixes it. Like in the case with Russia. Their servers have been dumped. Same way as servers. When a reputable no-log VPN provider rents the server he makes their legal due diligence and contacts server admins and informs them of their operation standards. Take DMCA for an instance. Doesn't matter how new the movie is VPN takes care of these notices. VPS or any provider of the server (Digital Oceal especially) will either forward this notice to you or your ISP and you get that notice. The legal obligation directly transferred to you. And they shut down your service. Reputable VPN steps in on your behalf and protects your privacy kind of like a lawyer. And both see the same info.
And guess what? most of good VPN provider's server's are in offshore zones. And it is up to you if you want to use Five Eyed alliance servers from VPN which could despite legal obligations to VPN provider give out your info.
You are giving as bad of advice as you would give to a person who wants to separate his entity by opening LLC and you would tell him.. Are you crazy?! do everything as self-employed!!! Because you have 3rd party involved (LLC)
Exactly how would you know right? I tell you how. People get burnt - VPN takes a hit and fixes it. Like in the case with Russia. Their servers have been dumped. Same way as servers. When a reputable no-log VPN provider rents the server he makes their legal due diligence and contacts server admins and informs them of their operation standards. Take DMCA for an instance. Doesn't matter how new the movie is VPN takes care of these notices. VPS or any provider of the server (Digital Oceal especially) will either forward this notice to you or your ISP and you get that notice. The legal obligation directly transferred to you. And they shut down your service. Reputable VPN steps in on your behalf and protects your privacy kind of like a lawyer. And both see the same info.
And guess what? most of good VPN provider's server's are in offshore zones. And it is up to you if you want to use Five Eyed alliance servers from VPN which could despite legal obligations to VPN provider give out your info.
This guy just tries so hard to prove something which is simply really bad practice and brings zero points. VPN providers are professionals in their field. And yes there are some bad ones. And yes if you do some hard-core illegal stuff it doesn't matter what you use you get found. But in the case of VPS you get found SOOOO MUCH easier... Because you are basically acting as if you're a VPN provider yourself. Taking all legal responsibility of using server. Without any thorough research... Without any legal backup... Just waving your ISPs IP address as a surrender flag... Because VPS provider would give out your connection timestamp without any pressure!
 
Last edited:
I wont point my fingers at anyone but some guys in this topic can just mislead you. Everyone here wants to be an expert even if given person dont know shit about given topic. Take every word with grain of salt.
Ast this question on many different forums including (but not limited to) stackexchange, stackoverflow, reddit, lowendtalk.

Rule no 1:
Dont do any "own" setup unles you know what are you doing and you are expert in given field. VPS with own vpn is terrible idea.

Read this article very carefully:
https://www.vpnmentor.com/blog/turkish-investigation-proves-expressvpn-does-not-keep-user-logs/

In worse case scenario - yes.
If you are going to use phone for tasks that can put you in jail do this:

You buy faraday's cage (read about it on internet) and you store your phone there.
You can open faraday's cage only when you are in public place (not in your car for example).
You use phone, check sms etc and you put phone back in faraday's cage.
If you do open faraday's cagein your appartment, friends appartment etc - they can track you and you are lost.

Btw phone use IMEI to log to celluar network, be prepared that your IMEI will be locked and probably you will have to switch phones quite often just because phones/simcards will be locked.
Prepare solution how you want to destroy phone (wipe all data etc).
Ceramic furnace could reach temperature so high that phone would just meltdown.

Btw - there are services like smspva where you can rent number for small monthly payment. Rent number, pay with crypto/whatever etc so you dont have real phone.
First of all thank you. Actually I live in Turkey and ExpressVPN is one of the 2-3 VPN services that I am considering - beside TorGuard - as I am aware of the event in the article. And that also means I am not in a Five Eyes Alliance country so I believe it is relatively safe. About the faraday cage - wouldn't removing the SIM Card do the trick? I will just plug it when I receive SMS and I will know when. The phone will be off otherwise. I will be changing sim cards on a monthly basis not as a caution - it is part of the procedure. I can renew the phone on a monthly basis too as a precaution though I did not understand IMEI/simcard locks you mentioned. I will use old nokia buttonned phones as burners - do they have such things? Can't you just take out the sim and plug a new one? If not I can renew the phone alright.

I am not gonna do a own setup - I am not an expert and I do trust few VPN service providers. I will pay anonymously and will use USER - TOR - VPN - INTERNET setup so I guess the government can access my traffic? Some guy mentioned they can tap VPN servers to start keeping logs covertly even if the VPN Service doesn't log but that's a bit extreme and I am not a INTERPOL level terrorist so that's a bit extreme it seems. What do you think about possible vulnerabilities I may have in the setup I mentioned?
 
Back
Top