Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

121–130 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#121

Earlier quoted context omitted.

IPhone is closed source and any kind of rootkit can be installed by Apple/NSA secret court system. I suggest not using a smartphone if you are serious about security. I absolutely disagree. While you are correct that in theory an iPhone can have rootkits and other backdoors installed on it by the NSA, in practice, I've found that the average user's computer can be compromised far more easily than their smartphone. Re…

It's a silly argument anyway, as in the famous xkcd comic, technology probably isn't the weakest link. And if a state really wants to snoop on you in particular, they will. Meanwhile, as mentioned elsewhere, Android is vulnerable to several key-extraction techniques and the speed of security updates depends on which model you have.

Literally every other phone on the planet is vulnerable. Even some garbage flip-phone you got at Wal-Mart thinking it's not smart and therefore secure is likely a joke for anyone to crack into. That software hasn't changed in years. It's full of unpatched holes.

This is why Snowden wanted people to put their phones in the freezer to avoid eavesdropping: https://thelede.blogs.nytimes.com/2013/06/25/why-snowdens-vi...

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#122
post #33

Earlier quoted context omitted.

> Get an iPhone and use it in preference to your computer. When connecting to a computer or charging, never ever tap on "trust this computer". If I understand it right "trusting this computer" involves some irrevocable certificate exchange, in effect granting the computer elevated permissions. Can someone correct me? What precisely "trusting" on iphone means except from the ability to decrypt backups? Also: Don't use…

It's revocable: https://support.apple.com/en-us/HT202778 It's anyway not a great idea to plug anything into strange USB ports.

> It's anyway not a great idea to plug anything into strange USB ports.

Solid advice, gentlemen. Goes for all your USB-cabels.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#123
post #35

Earlier quoted context omitted.

> FDE handles almost exclusively a single threat: the physical threat of your unattended computer. For most FDE solutions, doesn't the computer have to be off or possibly in hibernation (suspend to disk)? Does sleep mode (effectively suspend to memory?) activate the FDE? IME, most people's computers are almost always on or asleep. EDIT: File-level encryption seems better: All files are encrypted except when open. But…

A decent middle ground is encrypted disk images. You're getting inferior encryption (it'll be sector-level wide-block unauthenticated encryption), but at least you'll have to unlock and lock things as you use them. There used to be an OS X tool called Vault that managed these with a simple, pretty UI. Unfortunately, it was discontinued. We may put something like it together, but we suck at UI. Stuff like this, by the…

> I'd be happy to build the backend for such a thing and sign the IP over to an effective front-end developer.

If you're serious, we should talk. Email in profile.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#124
post #33

Earlier quoted context omitted.

> Get an iPhone and use it in preference to your computer. When connecting to a computer or charging, never ever tap on "trust this computer". If I understand it right "trusting this computer" involves some irrevocable certificate exchange, in effect granting the computer elevated permissions. Can someone correct me? What precisely "trusting" on iphone means except from the ability to decrypt backups? Also: Don't use…

It's revocable: https://support.apple.com/en-us/HT202778 It's anyway not a great idea to plug anything into strange USB ports.

http://syncstop.com/

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#125

Earlier quoted context omitted.

Great recommendation, but how do you handle syncing passwords between your computer and phone? I use KeePass to encrypt my passwords and store the password vault in Dropbox. It's not a perfect system, in that an adversary can gain access to my password vault and try to brute-force my master password. But it's "safe enough", if you make sure to use a strong passphrase as the master password for the vault.

I do this too but it conflicts with tptacek's injunction above to "not use Dropbox."

I'm not sure why tptacek specifically warns against using Dropbox. My guess (and I emphasize that this is just a guess) is that you can't rely on Dropbox (or Google Drive or Microsoft OneDrive) to keep your data out of the hands of a state-level adversary. However, encrypting your data before putting it into Dropbox should address that concern. Is there something I'm missing? Is it that cloud folders like Dropbox make it too easy to accidentally share information in cleartext?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#126
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> Don't use Dropbox.

Can you elaborate a bit? You mean "don't use any file sharing program" like SpiderOak and the like, or specifically Dropbox?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#128
post #27
post #23

Earlier quoted context omitted.

Yes. Email in general is an opsec nightmare, no matter what rules you come up with or what tools you use to protect it. It's the worst case scenario, a system that goes out of its way to make sure everyone has copies of everything. Above all else: do not create mailing lists for at-risk projects .

We may be talking at cross purposes, but for clarity's sake: I was not recommending email. I was only recommending that noobs be told to think of any written communication in terms of "like it is being published to the front page of your local paper, where your husband, mother in law, and any personal enemy might see it" and, in this case, where any officials might see it as well. The list in question was mostly full…

> Getting human beings to take InfoSec seriously is incredibly challenging. If you can't get that to happen, no amount of good tech will save you.

I personally know one case when an assistant for a medical study forwarded a email list of participants to everyone when it was specifically complied that it was confidential. You would think that the person was fired because of this but no they literally couldn't find another employee that would take the job for such a low pay, so he kept his job and security didn't improve...

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#129

Earlier quoted context omitted.

> but they are the correct answers Citation needed.

https://news.ycombinator.com/user?id=tptacek OP used to own/manage a world-class security consulting firm in Chicago, and now runs the entire security team for several decent-sized startups. His expertise is the citation.

This is Argument from authority.

We should instead ask for evidence that IOS provides better security than any other alternative for activists.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#130

Earlier quoted context omitted.

https://news.ycombinator.com/user?id=tptacek OP used to own/manage a world-class security consulting firm in Chicago, and now runs the entire security team for several decent-sized startups. His expertise is the citation.

This is Argument from authority. We should instead ask for evidence that IOS provides better security than any other alternative for activists.

I'm satisfied with an expert's opinion without a citation list. That's the benefit of being an expert; your reputation vouches for your knowledge.
Post reply on HN