• boonhet@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      16
      ·
      5 days ago

      How’s opsec going to help against a rat anyway? If an insider gives out information, you’re toast anyway, unless you have some kind of a cell network going on like some terrorist organizations and that’s, uh, a bit too much for organizing an union

      • Doc_Crankenstein@slrpnk.net
        link
        fedilink
        English
        arrow-up
        9
        ·
        5 days ago

        OpSec includes vetting people and structuring your organization in a way that frustrates a rat’s ability to gain access to sensitive information.

        Having a structured internal network for the union isn’t “a bit much”, it’s a basic necessity to proper organization.

        • boonhet@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          9
          arrow-down
          2
          ·
          5 days ago

          And yet - if the people organizing are completely anonymous and you can’t even know for sure they’re your coworkers, would you trust them?

          • Doc_Crankenstein@slrpnk.net
            link
            fedilink
            English
            arrow-up
            6
            ·
            4 days ago

            If you’re allowing anonymous people into your private server you have failed in your OpSec.

            The solution to this is to not allow anonymous people into a private server used for organizing. You vet them first before giving access. Basic OpSec 101.

      • TropicalDingdong@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        4 days ago

        Like saying how is a fire extinguisher going to help a house fire.

        Point is, good opsec prevents it from becoming a house fire.

    • Katana314@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      5 days ago

      I don’t see how it’s some advanced technical process. It all comes down to the quandary of who to trust. If you don’t trust enough people, you don’t grow the movement. In this case, all it took was one figure to whom they overextended how much trust he was worth.

      • Doc_Crankenstein@slrpnk.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 days ago

        And that means there was a failure of OpSec in that it allowed someone untrustworthy access to sensitive information.

        A key part of OpSec is figuring out who to trust and how much of it they are extended.