Hey everyone,
I’m working on a journalism project that requires a very high level of digital privacy, and I’m trying to figure out the most effective way to secure my hardware setup. My specific threat model is this: I’m dealing with sensitive work that could attract surveillance, so I need to assume my digital footprint is being monitored. However, I’m reasonably confident that no one will ever get their hands on my physical laptop (no physical raids, no seizure of the device).
Here’s where I’m stuck. I know the general advice is to buy a laptop with cash or Monero (XMR) to break the financial link to my identity. But I’m wondering: Is that actually necessary if I’m going to run a hardened setup anyway?
My plan is to:
- Use Whonix as the primary OS (or maybe Tails, but Whonix feels more permanent for my workflow).
- Route everything through multiple VPNs in a chain.
- Enable MAC randomization on all network interfaces.
- Never log into any personal accounts or reveal any real-world details.
If I’m already doing all that, does it really matter if I bought the laptop with a credit card or a bank transfer? Could the manufacturer’s firmware, the IMEI/Serial number, or just the act of purchasing the device itself compromise my anonymity later on?
I’m worried I might be over-engineering this, or conversely, underestimating a single point of failure. If the laptop itself isn’t physically seized, can I rely purely on the software stack to keep me anonymous, or is the “cash/XMR” part non-negotiable?
Also, any thoughts on the multiple VPN approach? I’ve heard that stacking them can sometimes introduce more leaks if not configured perfectly, but I’m not sure if that’s a real risk compared to just using Tor through Whonix.
Thanks in advance!