Identity Discipline
Protecting Yourself in Hostile Environments
Identity discipline is the practice of separating who you are from what you do. It protects your personal identity, your network, and your sources from surveillance, retaliation, and exposure. Drawn from the published methods of Reporters Sans Frontières, the EFF, and the Freedom of the Press Foundation, and adapted for activists, journalists, and civil society workers operating under scrutiny.
Identity discipline is a structured practice developed by journalists, human rights workers, and resistance movements operating under hostile surveillance. It separates your personal identity from your activist or professional role, and it exists to control what information adversaries can access, correlate, and use against you or your network.
Reporters Sans Frontières frames this as a fundamental protection for anyone working in an information-sensitive role. The same principles that protect a journalist’s sources protect an activist’s network. Exposure of either can result in arrest, harassment, loss of employment, or physical harm, both for the individual and for everyone connected to them.
Identity discipline operates on three layers: digital identity (what you do online and what traces you leave), physical identity (what you present in the world and what can be observed), and social identity (what your network knows and what they might disclose). All three require active management. Weakness in any one layer can compromise the other two.
Identity discipline is a legitimate and widely practiced professional standard for journalists, lawyers, NGO workers, opposition politicians, and anyone whose work puts them in conflict with powerful interests. Your threat environment determines how rigorously to apply it.
Effective identity discipline begins with threat modelling, the process of identifying who might target you, what they are capable of, and what they are trying to find. Your identity discipline measures should be proportionate to your threat environment. Over-preparation wastes resources; under-preparation creates exposure.
Civil society activity in a stable democracy with a free press. Adversary is opportunistic, not targeted. Basic digital hygiene, strong passwords, and careful social media use are sufficient. No dedicated surveillance capacity directed at you.
Organising in a context where authorities monitor activist networks, or working on issues that attract corporate or government attention. Separate identities for activist and personal activity. Encrypted communications standard. Legal observer presence at actions.
Journalist, opposition figure, or activist in a context with documented state surveillance of civil society. Full separation of digital identities. Hardened device security. Source protection protocols. Physical identity discipline at all actions. RSF and EFF full-protocol guidance applies.
Operating in or communicating with contacts in an authoritarian or conflict context. Assume all communications are monitored. Air-gap sensitive material. Use only vetted secure channels. Consult Access Now Digital Security Helpline and RSF emergency protocols directly. This page alone is not sufficient for this threat level.
A threat model adapted from the EFF’s Surveillance Self-Defense guide starts every security assessment with four questions: Who wants to harm me or my sources? What do they want to find? What do they have access to? What are the consequences of exposure? The answers determine the proportionate response.
The most common identity discipline failure is the conflation of personal and activist digital identities. A single email account, phone number, or social media profile that bridges both worlds creates a correlation point that adversaries can exploit. Separation compartmentalises your exposure: a compromise in one identity stays contained instead of spreading to the other.
Separate email accounts: One account for personal life and a distinct account for activist or professional work, ideally on a privacy-focused provider such as Proton Mail or Tuta. Never cross-reference them. Do not forward between them.
Email aliasing: Aliasing services such as SimpleLogin or addy.io generate a unique address for every signup, so one leaked or sold address never links your accounts together. SimpleLogin integrates directly with Proton Mail.
Pseudonymous accounts: Where your role requires public presence, use a consistent pseudonym rather than your legal name. A pseudonym maintained over time builds credibility without exposing your personal identity.
Account creation hygiene: Do not create activist accounts from your personal device or home IP address. Use a VPN or Tor for account creation. Do not use your personal phone number for verification; use a separate SIM or a VoIP service.
Password discipline: Unique strong passwords for every account. A password manager (Bitwarden, KeePassXC) is the only practical solution. Never reuse passwords. Enable 2FA on all accounts using hardware keys (YubiKey) or authenticator apps. Never rely on SMS codes for high-risk accounts.
Audit existing accounts: Review everything you have posted publicly. Details that seem innocuous in isolation, such as your workplace, neighbourhood, daily routine, or family members, can be combined to identify and locate you. Use the OSINT section of this page to see what is already findable.
No cross-posting between identities: Never share content from your activist accounts on personal accounts or vice versa. Engagement patterns such as likes, follows, and shares are metadata that correlates identities even when names differ.
Location data: Disable location tagging on all posts. Review app location permissions. Photographs contain EXIF metadata, including GPS coordinates. Strip metadata before posting images from sensitive locations. ExifTool handles this offline; most phones can remove location data from the share menu.
For moderate to high threat environments, RSF recommends maintaining separate devices for personal and activist use. A dedicated low-cost Android device running GrapheneOS or a hardened configuration for activist communications provides meaningful separation. At minimum, do not conduct sensitive communications on a device that also contains your personal contacts, banking apps, or location history.
Border crossings deserve their own plan. Many jurisdictions claim expanded device search powers at ports of entry, and refusal can mean denied entry or device seizure. Travel with a clean device where possible, power devices off fully before the crossing, and disable biometric unlock in advance.
At any point of arrest or detention, your device may be seized. Assume law enforcement has the technical capability to extract data from unlocked or poorly secured devices. Enable full-disk encryption and use a strong alphanumeric passcode. Biometric unlocks can be compelled; in most jurisdictions passcodes cannot. Know your device’s data protection settings before attending any action.
Digital identity discipline is only half the picture. Physical presence at protests, meetings, and actions creates observable identity data: facial recognition, gait analysis, licence plate readers, and informant identification all operate in the physical domain. Physical identity discipline addresses what can be seen, recorded, and correlated in the real world. The wider protest skill set is covered in Street Level Tactics; this section covers the identity layer.
Face covering: Where legal in your jurisdiction, wearing a face covering at demonstrations protects against facial recognition systems and photographic identification. Check the law in your area; some jurisdictions prohibit face coverings at protests, and non-compliance creates its own legal exposure. Know the Law covers how to research your jurisdiction.
Distinctive clothing: Avoid wearing distinctive items such as branded clothing, unusual accessories, or anything that makes you easily identifiable across multiple events. Adversaries correlate attendance across demonstrations using clothing identification.
Carry only what you need: Do not carry unnecessary identification, loyalty cards, or items linked to your personal identity. Carry only what you are legally required to carry and what you would be comfortable having examined.
Travel to and from actions: Avoid travelling to actions directly from your home. Public transport, cycling, or walking from a neutral location reduces the correlation between your home address and your activist presence. Avoid using personal vehicles; licence plates are logged.
IMSI catchers (stingrays): Law enforcement in many jurisdictions deploys IMSI catchers at demonstrations: devices that mimic cell towers and log all phones in an area. Your phone’s presence at an action is logged even if you make no calls. A separate prepaid SIM, or leaving your primary phone at home, prevents this correlation.
Airplane mode is not sufficient: Some location logging occurs independently of cellular connectivity. If you require your phone to be non-trackable, power it off completely, or leave it at home and use a separate dedicated device for the action.
Bluetooth and WiFi: Both broadcast identifiable signals when enabled. Disable both before arriving at any action.
Communications security is the practice of ensuring that only the intended recipients can read what you send. Unencrypted communications sent over standard channels are accessible to network operators, law enforcement with legal authority, and in some contexts hostile state actors. The Freedom of the Press Foundation’s guides treat encrypted communication as the baseline for anyone in an information-sensitive role. For the full vetted tool stack, tiered by risk level, see the Digital Security & Privacy toolkit.
End-to-end encrypted messaging and calls. Open source, audited. Enable disappearing messages and keep sensitive traffic off SMS entirely. Recommended by RSF, EFF, and FPF as the primary secure messaging tool.
signal.org →End-to-end encrypted email between users on the same platform. For email to non-encrypted recipients, use PGP encryption. Standard email providers (Gmail, Outlook) hand over data under legal compulsion.
proton.me →Routes traffic through multiple encrypted relays, masking your IP address and browsing activity. Slower than standard browsing but provides strong anonymity. Use for sensitive research and account creation. Do not log into personal accounts while using Tor.
torproject.org →Masks your IP address from websites and network operators. The VPN provider can still see your traffic, so choose a provider with a verified no-logs policy in a jurisdiction outside your adversary’s legal reach.
mullvad.net →Open-source, audited disk encryption. Use for sensitive document storage on local devices. Create encrypted containers for activist materials, keeping them separate from personal files.
veracrypt.io →Secure file sharing over Tor. OnionShare for peer-to-peer transfer; SecureDrop for journalist source submissions. Both minimise the metadata trail available to third parties.
onionshare.org →The Electronic Frontier Foundation’s Surveillance Self-Defense guide explicitly advises against adopting all tools simultaneously. Start with Signal for messaging and a password manager for accounts. These two changes address the majority of exposure for most threat levels. Add layers as your threat assessment requires; complexity introduces its own operational risk if tools are used incorrectly.
Open Source Intelligence (OSINT) is the collection and analysis of publicly available information. State actors, hostile organisations, and individuals use OSINT techniques to identify, locate, and build profiles on activists and journalists. Understanding what is findable about you is the first step in reducing your exposure surface.
Before taking any protective action, understand your current exposure. The following process is adapted from standard OSINT methodology and requires no specialist tools:
Google yourself comprehensively: Search your full name, your name plus location, your name plus employer, your email addresses, and your phone number. Note everything that appears. Repeat with Bing and DuckDuckGo; results differ between search engines.
Review all social media profiles: Including inactive accounts. Old accounts often contain more identifying information than current ones. Check privacy settings on every platform. Assume anything set to “friends of friends” is effectively public.
Check data broker sites: People-finder and data broker sites (Spokeo, Whitepages, Intelius equivalents in your country) aggregate personal data from public records. Most allow opt-out removal requests. Submit them. This is standard practice for journalists in any threat environment. Subscription services such as DeleteMe or Optery automate the removal cycle.
Check image search: Reverse image search your profile photographs. If the same photo appears across multiple platforms, it creates a correlation bridge between your personal and activist identities. Use different photographs for different identities, or no photograph at all for activist accounts. Face search engines such as PimEyes and FaceCheck show what a facial recognition query returns for your photographs; run one as part of the audit.
Review public records: Voter registration, property records, and company registrations are often publicly searchable and contain home addresses. Understand what is in the public record in your jurisdiction and whether opt-out or redaction mechanisms exist.
Your identity can be exposed through your network even when your own accounts are clean. A colleague who tags you in a photograph, a contact who lists you publicly, or a group membership that is publicly visible can all create exposure. Brief your network on identity discipline. You are only as protected as your weakest link.
Conduct a personal OSINT audit. Note everything findable. Begin removal requests on data broker sites.
Install a password manager. Change all account passwords to unique strong passwords.
Enable 2FA on all critical accounts. Use an authenticator app or hardware key instead of SMS.
Install Signal. Move sensitive communications off standard SMS and email.
Enable full-disk encryption on all devices. Set a strong alphanumeric passcode.
Confirm your activist and personal digital identities are fully separated. No shared accounts, no cross-posting, no shared photographs.
Strip EXIF metadata from any photographs before posting, especially location data. Use ExifTool or your phone’s share-menu option.
Brief your network. Confirm they understand not to tag, identify, or publicly link you without consent.
At any physical action: disable Bluetooth and WiFi. Carry only what is legally required. Travel from a neutral location.
Repeat your OSINT audit every 6 months. Data brokers re-aggregate removed data over time.
Review app permissions quarterly, particularly location, microphone, and contacts access.
Re-assess your threat level when your circumstances change: a new role, a new campaign, a new jurisdiction.
The following organisations publish the most authoritative publicly available guidance on identity discipline, digital security, and source protection. All materials are free to access.
The primary international reference for journalist digital security. Runs the Digital Security Lab and publishes threat-modelled guides for reporters in hostile environments.
rsf.org →The Electronic Frontier Foundation’s comprehensive threat-based security guide. Covers tools, threat modelling, and specific scenarios.
ssd.eff.org →Publishes security training guides and maintains SecureDrop. Specific guidance for journalists and their sources.
freedom.press →Free direct digital security assistance for civil society, journalists, and activists under threat. Available in multiple languages.
accessnow.org →Digital protection for human rights defenders at risk. Publishes a comprehensive workbook on protection planning.
frontlinedefenders.org →Digital safety resources specifically for journalists. Includes country-specific threat assessments and emergency support.
cpj.org →If you believe you are currently under active surveillance or facing immediate digital threat, contact the Access Now Digital Security Helpline directly at accessnow.org/help. They provide free, confidential, expert assistance to civil society and journalists in real time. This page is an educational reference. In an active threat situation, go straight to direct expert support.
Exposure happens even with good discipline. A doxxing post, a compromised account, or an informant can put your name, address, or affiliations in hostile hands. What you do in the first 48 hours determines most of the damage. Work the steps below in order, and involve the organisations listed above early rather than late.
Document everything first: Take full-page screenshots of the exposing posts with URLs, usernames, and timestamps before they are edited or deleted. You need the record for takedown requests, platform reports, and legal action. Do not engage the poster; engagement raises the post’s visibility and confirms the target is watching.
Lock down your accounts from a clean device: Change passwords, revoke active sessions, and confirm 2FA is active on your email first, then everything else. Check recovery addresses and phone numbers for tampering; attackers plant their own.
File takedown requests: Every major platform has a doxxing policy; report the posts under it. Google’s “Results about you” tool requests removal of personal data from search results. Re-submit data broker opt-outs; exposure often traces back to a broker profile.
Brief your network: The people connected to you are the next targets. Tell them what was exposed, what to watch for, and to tighten their own settings before contact attempts begin.
Assess physical risk: If your home address is exposed, vary your routines, consider staying elsewhere for a period, and keep trusted contacts informed of your movements. Where appropriate to your context, involve legal counsel.
Escalate: The Access Now Digital Security Helpline handles active civil society cases. Journalists should also contact CPJ. Human rights defenders should contact Front Line Defenders. All three are listed in the section above.
Full removal is rare. Exposed data spreads to mirrors and archives faster than takedowns process. The realistic goals are slowing distribution, raising the cost of reposting, and cutting the data trail that led to the exposure. Measure success by reduced spread.
