Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

21–30 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#21
post #20
post #17

Earlier quoted context omitted.

I have some quibbles with this (the first, practical, checkbox guide post; not so much the longer, abstract policy one). * At-risk users should disable SMS 2FA, and favor code-generating applications instead. It takes some effort to disable SMS, but that effort is worthwhile, because SMS is quite insecure. * The guide correctly notes that attachment are dangerous, but isn't very pragmatic about how to handle that dan…

I think the risk of your unattended computer being compromised is quite low for the average journalist, but don't activists in the field face increased danger of having their laptops/property seized during an arrest? It could be an activist participating in a march who happens to bring their laptop bag with them. Yes, ideally, people would have a policy not to engage in a protest while carrying laptops, but I could s…

The unattended compromise scenario is that your laptop is grabbed out of your house or car in a breakin, or left in your backpack in a bar or a cab, which happens all the time even to savvy people. Full disk encryption contains that catastrophe so that all you lose is your data and not your privacy.

It doesn't really protect you in any other scenario. In particular: if you can use your computer without a password, it is not at that moment protected by FDE.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#22
Years ago on an email list, we were advised to not say anything on list that we wouldn't want posted to the front page of the local newspaper. I still find this to be a good rule of thumb.

Humans are incredibly, horribly bad about writing stuff online like it is confidential, just between you and me -- even when it is a public forum that anyone can read, like Hacker News. Thinking of it in terms of published to the front page of the local paper can help people keep some of their worst, stupidest impulses down to a dull roar.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#23
post #22

Years ago on an email list, we were advised to not say anything on list that we wouldn't want posted to the front page of the local newspaper. I still find this to be a good rule of thumb. Humans are incredibly, horribly bad about writing stuff online like it is confidential, just between you and me -- even when it is a public forum that anyone can read, like Hacker News. Thinking of it in terms of published to the f…

Yes. Email in general is an opsec nightmare, no matter what rules you come up with or what tools you use to protect it. It's the worst case scenario, a system that goes out of its way to make sure everyone has copies of everything.

Above all else: do not create mailing lists for at-risk projects.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#24

Beware of the guy that has too much free time, too many contacts and want to scale up the protest to more violent methods. He is probably an FBI informant. It was common during the previous administration, I don't expect it to have finished. I'm too pessimistic about the security situation since a long time ago. Just email your Gmail/Hotmail/Facebook/Tweeter password to the NSA/CIA/FBI chief, so you don't get a false…

Very much the first two sentences, here: if anyone starts saying that they know where they can get instructions to make a bomb, they are probably an agent trying to provoke you. Kick them out.

What they won't do, and you should: learn your rights. Get a friendly lawyer to advise you and agree to represent you, should anybody get arrested.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#25

If you are seriously concerned about your security and safety, I would avoid electronic communication completely.

That concedes an enormous amount of ground to your opposition, who then has the privilege of using efficient communication while you don't. It's worth building up a gradient of security so that people who are simply exercising their rights can do so effectively without electronic harassment.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#26
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

First, thank you.

Second, how much security does this provide and against what? For example, Moxie said once that Signal was designed to be usable and prevent mass surveillance, but not necessarily to prevent targeted attacks (my paraphrasing);[0] civil rights activists can expect targeted attacks.

Finally, the public needs real security professionals to do the work and provide a reliable, authoritative, updated guide - including pointing out where in the technology/solution stack we need better solutions. There are many guides out there, some cited below; like all the other unreliable information on the Internet, some are obviously flawed, some are flawed in ways that few will notice. There is no alternative to real security expertise. Also, it will need names on it that people know and trust. Crowdfund it; I will happily contribute.

[0] https://news.ycombinator.com/item?id=10665789

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#27
post #23
post #22

Years ago on an email list, we were advised to not say anything on list that we wouldn't want posted to the front page of the local newspaper. I still find this to be a good rule of thumb. Humans are incredibly, horribly bad about writing stuff online like it is confidential, just between you and me -- even when it is a public forum that anyone can read, like Hacker News. Thinking of it in terms of published to the f…

Yes. Email in general is an opsec nightmare, no matter what rules you come up with or what tools you use to protect it. It's the worst case scenario, a system that goes out of its way to make sure everyone has copies of everything. Above all else: do not create mailing lists for at-risk projects .

We may be talking at cross purposes, but for clarity's sake: I was not recommending email. I was only recommending that noobs be told to think of any written communication in terms of "like it is being published to the front page of your local paper, where your husband, mother in law, and any personal enemy might see it" and, in this case, where any officials might see it as well.

The list in question was mostly full time mothers. I was a full time mother, but also a military wife. I was more familiar with general information security practices than most of them. So this is the most noobie friendly line I know that seems helpful in trying to get inexperienced people to think before they speak/type.

I also got annual InfoSec training while working for an insurance company for more than five years. Getting human beings to take InfoSec seriously is incredibly challenging. If you can't get that to happen, no amount of good tech will save you.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#28
post #17
post #8

I like these guides by AP journalist Jonathan Stray: https://source.opennews.org/en-US/learning/security-journali... https://source.opennews.org/en-US/learning/security-journali... In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector: 1. Enable two-factor auth on all accounts, especially their email. 2. Care about proper access contr…

I have some quibbles with this (the first, practical, checkbox guide post; not so much the longer, abstract policy one). * At-risk users should disable SMS 2FA, and favor code-generating applications instead. It takes some effort to disable SMS, but that effort is worthwhile, because SMS is quite insecure. * The guide correctly notes that attachment are dangerous, but isn't very pragmatic about how to handle that dan…

> FDE handles almost exclusively a single threat: the physical threat of your unattended computer.

For most FDE solutions, doesn't the computer have to be off or possibly in hibernation (suspend to disk)? Does sleep mode (effectively suspend to memory?) activate the FDE? IME, most people's computers are almost always on or asleep.

EDIT: File-level encryption seems better: All files are encrypted except when open. But I don't know if there are any solutions that implement it securely and useably.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#29
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Thanks for this, awesome. Questions:

> 4. Switch to Google Chrome.

Can one configure Chrome to not be a data-sucking kraken?

> 7. Disable cloud-based keychain backups.

That backup is encrypted, I'd hope? So, is the problem that getting hold of a cloud-backup facilitates off-line attacks on the encryption key?

I remember Filippo (FiloSottile here) publishing his encrypted private PGP key [1] (back when he was still positive on PGP). If that's safe, how is this problematic?

> 10. Install a password management application that doesn't store your secrets in the cloud.

Same question as 7. My understanding was that most password manager vulnerabilities have been related to browser integration, so that is the first thing I'd switch off.

[1] https://blog.filippo.io/on-keybase-dot-io-and-encrypted-priv...

Post reply on HN