# Guia OpSec da arcano¶noide Canonical URL: https://arcanoeparanoide.com/opsec Language: Portuguese (Brazil) Author: A.R.C. Published: 2026-07-30 Last reviewed: 2026-07-31 HTML edition: https://arcanoeparanoide.com/opsec Sitemap: https://arcanoeparanoide.com/opsec/sitemap.xml ## What this page is An original Portuguese-language field guide to operational security, digital privacy and anonymity. It begins with threat modelling, baseline security, observation, compartmentalization, objective-based workflows and failure containment, then explains the practical uses and limits of Tails, Qubes OS with Whonix, GrapheneOS with Tor Browser, OpenPGP/GnuPG, Monero, VPNs and encrypted messengers. Portuguese summary: Segurança operacional (OpSec) é a prática de reduzir os sinais que permitem relacionar uma atividade, identidade, aparelho, local ou rotina a uma pessoa. O guia organiza ferramentas por contexto e explicita o que cada uma não protege. This is educational material, not a guarantee of anonymity and not individualized legal, financial or security advice. Recommendations depend on the reader's threat model. Cite the canonical HTML edition when referring readers to the guide. ## Sections - Threat model: identify what must be protected, from whom, for how long, the adversary's plausible access and the consequence of failure before selecting tools. - Baseline security: updates, unique credentials, a password manager, MFA, disk encryption, recovery codes and tested backups. - How observation works: financial, telecom, network, platform, physical and file records considered through observers, identifiers, correlations, encryption boundaries, mitigations and residual risk. - Compartmentalization: separate identities across accounts, devices, networks, payments, recovery, files, relationships, language, places and schedules. - Objective-based workflows: publishing without civil attribution, maintaining a persistent pseudonym, receiving a sensitive file and verifying a signature. - Tails: one task and one identity per boot. Its amnesic sessions use Tor, bridges, MAC address randomization, disabled persistence and metadata removal. - Qubes OS with Whonix: reusable pseudonyms separated into qubes. It uses disposable Whonix workstations, offline handling and qrexec boundaries. - GrapheneOS with Tor Browser: a dedicated compatible Pixel, no SIM/eSIM, Wi-Fi only, separate identity and restricted app networking. - OpenPGP with GnuPG: key generation, full fingerprint verification, detached signatures, public-key encryption, revocation and offline backups. - Monero: private digital payments using ring signatures, stealth addresses and RingCT. It is presented as a payment tool, not an investment. - VPNs: geographic circumvention and reduced direct ISP exposure. A VPN changes the trusted intermediary and does not create anonymity by itself. - Messengers: end-to-end encryption protects content but not all account, device, timing, backup or social-graph metadata. Signal, Matrix and Telegram have different security properties. - Files: metadata, visual content, revision history, cloud records and writing style can reveal provenance. Untrusted files belong in a disposable offline environment. - Failures and containment: stop the activity, identify the exposed bridge and observers, revoke only what is affected, notify contacts when necessary, then decide whether the identity can still serve its original objective. ## Supporting dossiers - How tracking records connect across ordinary systems: https://arcanoeparanoide.com/dossies/como-voce-e-rastreado - Pix architecture and privacy boundaries: https://arcanoeparanoide.com/dossies/o-que-o-pix-revela - Mobile subscriber, device, network, app and physical signals: https://arcanoeparanoide.com/dossies/o-que-um-celular-sabe-sobre-voce - Identity resolution across CPF, phone, email, device, IP, payment and social graph: https://arcanoeparanoide.com/dossies/anatomia-de-uma-identidade-digital ## Important boundaries - OpSec reduces linkable signals. It cannot promise complete anonymity. - Security against account takeover and anonymity against correlation are different objectives. Both matter. - Endpoint compromise defeats protections that depend on the endpoint. - Tor does not erase physical surveillance, local records, timing correlation, writing style, traffic volume or account reuse. - OpenPGP protects content and authenticity but not normal email metadata. - Monero protects blockchain transaction details, not exchange, bank, delivery, device or conversation records. - A VPN replaces trust in the ISP with trust in the VPN provider. - End-to-end encryption does not hide every messaging metadata field. ## Primary references - W3C Threat Modeling Guide: https://www.w3.org/TR/threat-modeling-guide/ - CISA Secure Our World: https://www.cisa.gov/secure-our-world - NIST incident response recommendations: https://csrc.nist.gov/pubs/sp/800/61/r3/final - OnionShare receive mode and file warnings: https://docs.onionshare.org/2.6.3/en/features.html - Tails warnings: https://tails.net/doc/about/warnings/index.pt.html - Tails installation: https://tails.net/install/index.pt.html - Qubes OS installation: https://www.qubes-os.org/doc/installation-guide/ - Whonix disposables: https://www.whonix.org/wiki/Qubes/Disposables - GrapheneOS cellular tracking: https://grapheneos.org/faq#cellular-tracking - GrapheneOS Wi-Fi privacy: https://grapheneos.org/features#wifi-privacy - Tor Browser safety: https://support.torproject.org/tor-browser/security/using-tb-safely/ - Tor with VPN: https://support.torproject.org/tor-browser/general/vpn-with-tor/ - GnuPG examples: https://gnupg.org/documentation/manuals/gnupg/GPG-Examples.html - OpenPGP RFC 9580: https://www.rfc-editor.org/rfc/rfc9580.html - Monero FAQ: https://www.getmonero.org/get-started/faq/ - Monero technical specifications: https://docs.getmonero.org/technical-specs/ - Bitcoin whitepaper: https://bitcoin.org/bitcoin.pdf - EU Regulation 2024/1624: https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng - Mullvad no-logging policy: https://mullvad.net/en/help/no-logging-data-policy - Signal specifications: https://signal.org/docs/ - Matrix end-to-end encryption: https://spec.matrix.org/latest/client-server-api/#end-to-end-encryption - Telegram Secret Chats: https://telegram.org/faq#secret-chats