Earlier quoted context omitted.
The reason I do this is that there are fascinating and unpredictable interactions between behavior and identity that extend out into the indeterminate future. If we assume this information persists forever - and we might as well - it represents infinite liability and risk whereas the mitigations I have proposed cost almost nothing. Or, to put it another way, it's very cheap insurance.
You're saying the word "unpredictable" but with cognitive dissonance, because you are predicting disaster. If it is truly unpredictable, then you may be diminishing something which may actually be beneficial and necessary in the future. This obfuscated data which may or may not be linked to you (or the lack of data entirely, a void which certainly is linked to you) is itself forever persistent and represents its own…
Ask HN: Do you manage your family's digital safety?
101–110 of 132 posts
Re: Ask HN: Do you manage your family's digital safety?
#102Steps to make it "simple" - use password manager - store shared and individual pw DBs on a NAS where family has access - use Syncthing to keep changes aligned between devices - configure all browsers and devices to be integrated with pw manager and demo proper usage - everything important stored on a NAS that is in my physical possesion and which uses redundant storage (RAID) - implement backup of critical NAS data - test backups monthly! (can be restored? are still occurring properly?) - install a Linux distro and configure key-based auth (my key trusted) SSH for family members who are willing to use Linux on the desktop. 2022 is the year for it! ;) - ensure things auto-update - if problem occurs shell access is a few keystrokes away - can manage family's digital situation remotely to some degree this way. very helpful! much better than the ole' "Call up grammy and try to drive her clicks and typing remotely..." routine!
Restorative powers retained? - yes, except for the master password to any private password DBs
Which subjects spurred the most discussions and how did you solve it? - Linux: Some people have no idea what an operating system even is, let alone how a "Linux" differs from an "Apple" (not OSX, it's an Apple!) or a "Windows". This was solved by reminding them what I do professionally and them remembering how much time I spent behind the screen doing the bits n bytes. Basically "I got u fam, don't worry about it." was my solution. - Social Media: This is an unsolved problem. Some insist on having FB, Insta, whatever installed on their cellphone! It's nuts. I'm not cool with it, but we all make our own choices. I try to educate people on this topic, but it's an uphill battle.
Items shared for all family members - none - within household: shared pw database with things like streaming & delivery service logins, etc
Re: Ask HN: Do you manage your family's digital safety?
#103I have a wife and 2 kids under 13. - We have a phone that never leaves home and has no SIM card. We use it for banking apps and 2FA critical services. - So our "street phones" don't have any banking apps installed, nor social media apps, 2FA nor password managers. - We have a paper notebook with secrets and 2FA recovery codes in the bookshelf sitting among many other notebooks and old dusty random stuff. - Our kid's…
Re: Ask HN: Do you manage your family's digital safety?
#104Earlier quoted context omitted.
> Is this a disaster waiting to happen if visa/mc one day flip the switch on name verification? Doesn't even have to be that big of a policy change; if Facebook gets suspicious about you using a fake name or various other scenarios, they'll lock your account until you provide a scan of a passport or state ID.
You are assuming that a person who is cautious about privacy, uses facebook. Unlikely. However, I have been in that alley. I renamed my facebook account yearly, until it got blocked indeed. But then again, there are some great ID .psd templates out there:P solved it immediately.
Re: Ask HN: Do you manage your family's digital safety?
#105I preconfigure all windows machines in my family, and take away their local admin rights. No crapware installs, no disabling of updates or defender. No microsoft accounts. They get firefox browser with adblocker preinstalled. I manage their important passwords (eg fastmail) and trained them to rely on firefox sync for the recoverable accounts. I use MeshCentral for remote administration (amt)… its amazing for the pri…
> No microsoft accounts.
Good look with that from now on.Re: Ask HN: Do you manage your family's digital safety?
#106I have a wife and 2 kids under 13. - We have a phone that never leaves home and has no SIM card. We use it for banking apps and 2FA critical services. - So our "street phones" don't have any banking apps installed, nor social media apps, 2FA nor password managers. - We have a paper notebook with secrets and 2FA recovery codes in the bookshelf sitting among many other notebooks and old dusty random stuff. - Our kid's…
I’m curious what threat model your first two bullets are intended to mitigate.
"Smishing" (aka "SMS phishing"), for a start.
Then it seems to me that a phone that is only used for banking apps and 2FA is less likely to be owned than a phone used for everything under the sun.
Re: Ask HN: Do you manage your family's digital safety?
#107I preconfigure all windows machines in my family, and take away their local admin rights. No crapware installs, no disabling of updates or defender. No microsoft accounts. They get firefox browser with adblocker preinstalled. I manage their important passwords (eg fastmail) and trained them to rely on firefox sync for the recoverable accounts. I use MeshCentral for remote administration (amt)… its amazing for the pri…
> No microsoft accounts. Good look with that from now on.
I'm asking because I do exactly the same: no admin accounts for my family on their own Windows machine (mother in law and wife etc.).
They're also using only local account. Is Microsoft banning local accounts?
Re: Ask HN: Do you manage your family's digital safety?
#108> What steps did you take to make it simple enough for your family to care?
GNU/Linux desktops for all, for me NixOS/Emacs (EXWM), for relatives mostly Gnome SHell (the second capital is NOT a mistake, but they want something like that) and XFce, no wifi, at least I have few MikroTik APs but powerd off, powered on only if I have a guest and he/she can't use wired ethernet. Desktops have "proper" WebVM [1] with user.js/various extensions etc all regularly kept up to date backed up and casually restored around once or twice a year when I upgrade from a major release to another. IoT stuff (domestic p.v. + related tools) offline on a separate network with a homeserver (Home Assistant pip-installed, not the absurd docker image) bridging the WebUI part from the desktop's LAN.
> Did you retain any restorative powers? As in keeping master passwords to certain things and/or emergency accesses like in LastPass?
I have a printed copy, "encrypted" with a simple letter substitution scheme those who need know it, of some passwords, so they can ask for help someone who know GNU/Linux if I have some health issues/I can't really help for some reasons, but it's not much a tested setup just something do and explained a bit without really having ever used it so I can't really know how much it can work, it's a potentially serious issue but so far no one seems interesting in that, I'm healthy etc so...
In iron terms I have enough iron to survive various faults on both desktops and homeserver/mini-small-rack side, in software terms everything is almost reproducible with org-mode documented and tangle-ed NixOS configs and relevant custom ISOs ventoy-deployed locally or deployed via LAN depending on the case. Not everything is fully covered but it's enough.
> Which subjects spurred the most discussions and how did you solve it?
Well... The "family policy" a bit against my will is "you are the techie, we do not care" so there aren't really be discussions, just few explanations/training etc
> Which items do you share amongst all family members?
Phone system (Grandstream UCM PBX + GXP phones simply because when my old Asterisk card die and I see an offer for the PBX I was a bit tired of Asterisk), video surveillance, witch is only outside and physically powered off when someone of us is at home. Aside the small p.v. system witch, sigh, is to be counted in the "digital" things since it's full of FWs and to be effective enough (like piloting the hot water production depending on the sunlight) it demand a home assistant...
Essentially my general policy is:
- restricting as much as possible the attack surface
- restricting connected stuff (witch count in the attack surface) as much as possible, still leaving a bit of comfort
- be reproducible
- have a bit of redundant gears, not for anything, too expensive and demand too much space, but for something yes. For instance a VoIP spare phone + two analogs (with the PBX that have two fxs ports), around a desktop (ssds, mobos, CPUs, ram etc) and a half as spare parts, two 16 ports spare switches against a 48 ports in production one (not all ports used, of course) etc.
[1] monsters mostly called browsers for legacy reasons, like Firefox or Chromium that actually are not much more "browsers" than a JDK...
Re: Ask HN: Do you manage your family's digital safety?
#109Family 1Password for me + spouse, separate 1Password account for my elderly parent–in–law. I maintain paper copies of all keys. I back up (export) 1Password vaults quarterly to an offline backup I maintain. I maintain two small (1Tb) SSDs with digital copies/scans of all important documents, offline. Try to sync monthly. Store inside faraday bags inside fireproof (in theory) safes. We both lie excessively when creati…
How do you find using GSuite (etc) for family accounts? I've been considering it for a bit but I'd love to hear about your experience.
For our purposes it’s been fine, but it’s overkill for the typical family or typical consumer.
One definite downside is that G Suite accounts are not considered to be consumer accounts so you run into various Google services which either don’t work at all or work very differently. For the brief time we used Google Home it could not access either of our G Suite calendars (but somehow the Alexa could). Our Nest footprint exists in a separate world from our G Suite accounts. When we had YoutubeTV we had to use a separate GMail account because (at the time, I don’t know if this is still the case) …because G Suite accounts could not be used for YouTube TV.
Re: Ask HN: Do you manage your family's digital safety?
#110- run my own DNS and tunnel into the home network,
- no TVs,
- no smart devices,
- networked devices in communal spaces only.
I think all the rest like password managers and such are personal choices, but those sorts of behaviors will be encouraged.
There's a line between trying to control the behavior of your family and keeping the environment they're in healthy and safe. I wouldn't want to have a master password or access to all their personal accounts.