Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

111–120 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#111
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

This is a crazy list. 1. IPhone is closed source and any kind of rootkit can be installed by Apple/NSA secret court system. I suggest not using a smartphone if you are serious about security. 2. Good but difficult to anonymize 3. Good 4. Google Chrome is a botnet effectively and users lose their expectation of privacy there. Should switch to Firefox and use Chromium (Not Chrome) as a backup. Ideally Tor browser thoug…

    IPhone is closed source and any kind of rootkit can be installed by 
    Apple/NSA secret court system. I suggest not using a smartphone if you are 
    serious about security.
I absolutely disagree. While you are correct that in theory an iPhone can have rootkits and other backdoors installed on it by the NSA, in practice, I've found that the average user's computer can be compromised far more easily than their smartphone. Remember, we're not dealing with security professionals. We're not even dealing with people who can use PGP to secure their e-mail. We're dealing with rank newbies. In such a situation, it's far better for them to take incremental steps today to secure themselves (e.g. by using Signal to communicate, rather than e-mail) than it is for them to spend a year learning about encryption and having PGP key signing parties before they can set up a secure infrastructure.

Comments like these are why I have a deep frustration with the "security community". It's letting the perfect be the enemy of the good.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#112
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Thank you so much for this list, it's more concise and useful than any corporate security lecture I've ever received! Some questions: > 10. Install a password management application that doesn't store your secrets in the cloud. Great recommendation, but how do you handle syncing passwords between your computer and phone? > 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email…

    Great recommendation, but how do you handle syncing passwords between your 
    computer and phone?
I use KeePass to encrypt my passwords and store the password vault in Dropbox. It's not a perfect system, in that an adversary can gain access to my password vault and try to brute-force my master password. But it's "safe enough", if you make sure to use a strong passphrase as the master password for the vault.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#113

Earlier quoted context omitted.

This is a crazy list. 1. IPhone is closed source and any kind of rootkit can be installed by Apple/NSA secret court system. I suggest not using a smartphone if you are serious about security. 2. Good but difficult to anonymize 3. Good 4. Google Chrome is a botnet effectively and users lose their expectation of privacy there. Should switch to Firefox and use Chromium (Not Chrome) as a backup. Ideally Tor browser thoug…

IPhone is closed source and any kind of rootkit can be installed by Apple/NSA secret court system. I suggest not using a smartphone if you are serious about security. I absolutely disagree. While you are correct that in theory an iPhone can have rootkits and other backdoors installed on it by the NSA, in practice, I've found that the average user's computer can be compromised far more easily than their smartphone. Re…

It's a silly argument anyway, as in the famous xkcd comic, technology probably isn't the weakest link. And if a state really wants to snoop on you in particular, they will.

Meanwhile, as mentioned elsewhere, Android is vulnerable to several key-extraction techniques and the speed of security updates depends on which model you have.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#114

Earlier quoted context omitted.

Thank you so much for this list, it's more concise and useful than any corporate security lecture I've ever received! Some questions: > 10. Install a password management application that doesn't store your secrets in the cloud. Great recommendation, but how do you handle syncing passwords between your computer and phone? > 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email…

Great recommendation, but how do you handle syncing passwords between your computer and phone? I use KeePass to encrypt my passwords and store the password vault in Dropbox. It's not a perfect system, in that an adversary can gain access to my password vault and try to brute-force my master password. But it's "safe enough", if you make sure to use a strong passphrase as the master password for the vault.

I do this too but it conflicts with tptacek's injunction above to "not use Dropbox."

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#115
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

What is a better solution for remote file sharing, since email and Dropbox are out?

Tresorit

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#117
post #83
post #8

I like these guides by AP journalist Jonathan Stray: https://source.opennews.org/en-US/learning/security-journali... https://source.opennews.org/en-US/learning/security-journali... In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector: 1. Enable two-factor auth on all accounts, especially their email. 2. Care about proper access contr…

If you are worried about phishing (you should be) don't use SMS or code-based two-factor. They can and are being phished. Use U2F (yubikeys). They are phishing proof.

FWIW, I recently got a YubiKey Fido - their U2F-only version, and a disappointingly small number of sites I care about have implemented U2F... It's also website-in-Chrome only right now - which is a little limiting, no help protecting your mobile devices. (Not that any of the other usb 2FA devices are gonna work too well on iOS either...)

I'm not sure how up-to-date this page is, but there's a stark difference between ticks in the OTP column and the U2F column...

(Apart from that, it seems to be a well made bit of kit - but I think I'm gonna spend the extra and order a Yubikey 4 or Nano...)

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#118

Thank you very much to all for the detailed comments. I appreciate you keeping advice simple enough for someone like me, who decades ago counted as a "power user" of PCs, but who has no particular technical training or computer-related work experience. I will have to digest some of this advice for women (they are mostly women in the local group) who are barely comfortable using Facebook. And I'll pass on other tips t…

Consider this:

https://www.amazon.com/Smart-Girls-Guide-Privacy-Rest-ebook/...

I've given a bunch of friends (women and men) that.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#119

Earlier quoted context omitted.

Thank you so much for this list, it's more concise and useful than any corporate security lecture I've ever received! Some questions: > 10. Install a password management application that doesn't store your secrets in the cloud. Great recommendation, but how do you handle syncing passwords between your computer and phone? > 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email…

Great recommendation, but how do you handle syncing passwords between your computer and phone? I use KeePass to encrypt my passwords and store the password vault in Dropbox. It's not a perfect system, in that an adversary can gain access to my password vault and try to brute-force my master password. But it's "safe enough", if you make sure to use a strong passphrase as the master password for the vault.

How is brute-forcing a concern?

Your password might be a guessed in a dictionary attack if you have a weak password. Or if at some future date a KeePass specific vulnerability is discovered, someone might be able to use that.

But someone trying to brute-force your password isn't a problem anyone needs to worry about.

To my mind, the real downside to using dropbox to store encrypted stuff is that the existence of the encrypted stuff is not a secret. And recently it seems the spooks look upon encryption with ever increasing suspicion.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#120
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Regarding point 4: what is your opinion on Edge and its exploit mitigation strategies, in comparison to Chrome?
Post reply on HN