Independent Tor encyclopedia Glossary
Glossary definition

OPSEC

Operational security is the systematic check of which actions could leak sensitive information. That includes metadata, timing patterns, account separation, and the device in use. Good OPSEC starts with a realistic threat model. A single tool such as Tor cannot make up for organizational mistakes.

Threat model first, then the tool

OPSEC does not start with software, but with three questions: What information must be protected, from whom, and what means does that adversary have? The answers look entirely different for a journalist with a confidential source than for someone who wants to reduce ad tracking. Without that framing, typical mistakes follow: elaborate measures against unlikely adversaries, while everyday gaps stay open.

Where anonymity fails in practice

Documented deanonymization cases rarely come from broken cryptography. They come from reused pseudonyms, a one-time login without Tor, metadata in an uploaded file, a recognizable writing style, or an activity pattern that reveals a time zone. Mixing roles belongs here too: as soon as the same identifier appears in two contexts that were meant to stay separate, both are linked.

Tools complement discipline

Tor hides network metadata and keeps the destination invisible to the access network. It does not inspect what a text says, strip EXIF from a photo, or stop a login under a real name. An Exit Node, for example, is only as trustworthy as the protocol running over it allows. Consistent account separation, minimal data sharing, and a clean endpoint therefore remain the foundation.

How technical and editorial processes work together is shown by SecureDrop. An overview of what Tor can and cannot do is in What is Tor?.

Category: Security

Back to the glossary A–Z