Court filings from the battle between GTA 6 studio Rockstar and fired workers have revealed how Rockstar accessed a Discord server set up by union organisers.
How’s opsec going to help against a rat anyway? If an insider gives out information, you’re toast anyway, unless you have some kind of a cell network going on like some terrorist organizations and that’s, uh, a bit too much for organizing an union
If you’re allowing anonymous people into your private server you have failed in your OpSec.
The solution to this is to not allow anonymous people into a private server used for organizing. You vet them first before giving access. Basic OpSec 101.
SimpleX makes you anonymous and messages can’t be attributed to you. HR would probably believe screenshots still. If people identify themselves on the chat, and they don’t have to.
Seeing more governments salivating over chat control and banning VPNs, some even actively implementing these, I really dont’t think we’re seeing OPSEC being taught in schools or colleges.
They used to tell us to be careful around the Internet, don’t use real names or give addresses or phone numbers or share any of our personal information online, to be cautios, to beware… now it’s all about “You dont’t have to worry if you don’t have anything to hide” and giving away all of your data voluntarily or being denied service until you do (or at least getting worse or more expensive service) and age verification.
I don’t see how it’s some advanced technical process. It all comes down to the quandary of who to trust. If you don’t trust enough people, you don’t grow the movement. In this case, all it took was one figure to whom they overextended how much trust he was worth.
I was taught in Elementary/Kindergarten.
I had the privilege of being taught information security, programming, and OPSEC in a private school that no longer exists.
See you at school board meetings.
Really need to start teaching opsec in highschool and college.
How’s opsec going to help against a rat anyway? If an insider gives out information, you’re toast anyway, unless you have some kind of a cell network going on like some terrorist organizations and that’s, uh, a bit too much for organizing an union
OpSec includes vetting people and structuring your organization in a way that frustrates a rat’s ability to gain access to sensitive information.
Having a structured internal network for the union isn’t “a bit much”, it’s a basic necessity to proper organization.
And yet - if the people organizing are completely anonymous and you can’t even know for sure they’re your coworkers, would you trust them?
If you’re allowing anonymous people into your private server you have failed in your OpSec.
The solution to this is to not allow anonymous people into a private server used for organizing. You vet them first before giving access. Basic OpSec 101.
It works for the CIA. And they even wrote a declassified on exactly what we are talking about.
Like saying how is a fire extinguisher going to help a house fire.
Point is, good opsec prevents it from becoming a house fire.
Study OPSEC. It has an entire segment on dealing with spies (rats), internally, and outside.
SimpleX makes you anonymous and messages can’t be attributed to you. HR would probably believe screenshots still. If people identify themselves on the chat, and they don’t have to.
Seeing more governments salivating over chat control and banning VPNs, some even actively implementing these, I really dont’t think we’re seeing OPSEC being taught in schools or colleges.
They used to tell us to be careful around the Internet, don’t use real names or give addresses or phone numbers or share any of our personal information online, to be cautios, to beware… now it’s all about “You dont’t have to worry if you don’t have anything to hide” and giving away all of your data voluntarily or being denied service until you do (or at least getting worse or more expensive service) and age verification.
I don’t see how it’s some advanced technical process. It all comes down to the quandary of who to trust. If you don’t trust enough people, you don’t grow the movement. In this case, all it took was one figure to whom they overextended how much trust he was worth.
And that means there was a failure of OpSec in that it allowed someone untrustworthy access to sensitive information.
A key part of OpSec is figuring out who to trust and how much of it they are extended.
I was taught in Elementary/Kindergarten.
I had the privilege of being taught information security, programming, and OPSEC in a private school that no longer exists.
See you at school board meetings.