要求长期保存可关联调查者、虚构身份和案件活动的敏感记录
原文依据:5 处运行手册要求记录每个身份标识符、创建日期、用途以及每次会话,并在身份停用后继续保留已暴露的号码或地址。虽然主指南建议使用加密存储,但这些集中记录仍会形成能够关联人员、案件、设备和行动时间的高价值资料。
如果案件目录、保险库、备份或共享报告被未授权人员取得,记录可能暴露调查目标、调查节奏、使用过的账户及组织归属,并帮助他人交叉关联原本隔离的身份。长期保留会延长泄露窗口。
手册明确要求集中保存虚构身份的标识符、创建日期、使用位置、每次会话及案件操作,并在停用后继续保留号码或地址记录。主文要求案件加密存储、按保留规则删除收集数据,这属于缓解措施;但标识符记录本身仍被保留。若存储被泄露或访问控制过宽,它可暴露案件、时间线和调查基础设施,并间接关联操作者。用户可要求作者明确加密、最小权限、审计、保留期限,以及停用后只保留不可逆指纹而非完整号码或地址。
Every identifier gets recorded in the persona's file with its creation date andwhere it was used. An untracked persona is one you cannot safely retire.查看另外 4 个位置
- Let it acquire a few incidental connections organically. Do not solicit them.- Keep a log of every session, so the persona's own pattern-of-life stays consistent when a different analyst uses it.Retire personas that were challenged, that touched a case that went adversarial,or that were used across cases by mistake. Retirement means: stop using it,record the retirement date and reason, keep the identifier record so a futureanalyst does not reuse a burned number or address, and delete the persona'scollected data under the case's retention rules in `write-the-intel-brief`.One case, one environment. A dedicated VM per case is the clean answer; adedicated browser profile is the minimum. Containerised tab isolation separatescookies but not fingerprint — a convenience, not a boundary. Across setups: nopersonal accounts ever signed in; snapshot clean and roll back between cases;keep notes and downloads in the case's encrypted store; never open a target'sdocument or PDF in an environment that can reach your real identity. pretext you have no authorization to make, or elicit information from people.- Log what the persona did, when, and what it saw, and archive the pages via `read-deleted-pages` — the persona's access may not survive to be re-checked.