Starting this thread because I've seen too many researchers get burned lately. What operational security practices do you actually use day-to-day? Not theory — real, practical stuff.
I'll start: separate machines for separate projects. No crossover. Period. If one environment gets compromised, the blast radius is contained.