I use QubesOS with detached boot partition on 2 duplicated USB drives with any data that rests on the SSD/HDDs being encrypted with LUKS2. Whonix gateway is proxied through a VPN qube to hide Tor IPs (can't hide communication patterns) without bridges since bridge IPs can be farmed. Sometimes Tor through I2P outproxy or vice-versa or with different anonymizing network overlays. Clients used for browsing are only opened in on-RAM ephemeral qubes with no access to permanent storage. Attack surface is quite minimum since no extra things added like USB mouse and no PV qubes (aside from sys-usb and sys-net) are used for launching HVM qubes with qemu stub domains unless very necessary and every other qube on the system gets shut down first to keep information leakage minimum. A veracrypt volume with hidden storage on a permanent qube for data storage and plausible deniability.
what's your setup like?
>>807865>torture is a reliable way to extract informationxkcd is truly reddit
>>807868like you wouldnt just spill the beans once they pull out a live rat to stick up your ass
>>807869Don't forget the paint thinner.
>>807869Theyre gonna torture and kill you anyway what difference does it make. You might as well spite them
>>807694Mint + Whonix, plus other stuff. CIA aren't targeting me.
t. former QubesOS
>>807868happens all the time to crypto bros. they end up missing afterward.
Theres no way to hide your secrets if the state actually comes after you. Best bet would be not to have anything incriminating in the first place. And do anything shady completely offline in the absence of witnesses.