Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

41–50 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#41
post #37
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Why is Wire less secure than Signal?

The right way to think about secure messaging software is this:

You want to be using a messenger based on Signal Protocol, no matter what. Nobody has thought more carefully about cryptographic messaging protocols than Trevor Perrin and Moxie.

It's good to have two secure messengers, one that favors usability and has a large user base, and one that can function as a laboratory for strictly secure UX.

The very secure messenger you should have should be Signal; as Trevor and Moxie and their team devise new cryptographic protections for things like contact lists and file transfers, you'll get them through Signal.

The more usable messenger should be WhatsApp or Wire. I don't have strong opinions about which; mostly, I'm just saying there's no other Signal-based messenger I trust at all.

Whatever you do, don't use Telegram.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#42
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> Get an iPhone and use it in preference to your computer.

Color me surprised, but wasn't Apple involved with PRISM. Gives me reason enough to believe they maybe in on similar programs given there have been no drastic changes to their policy and whatnot

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#43
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

notes/questions:

4. a citation why chrome would be "safer" than firefox (or edge) would be appreciated. in terms of privacy, i wouldn't trust chrome as much as i'd trust firefox.

7 and 10: as others have noted, where is the security risk in storing the encrypted vault in the cloud? actually, choosing user-friendly solutions has a security benefit in itself because it doesn't make you switch to less secure alternatives ("i'll just use my standard password for this one thing) out of laziness

9. should mention PGP, although that's certianly not convenient and might not work for less tech-savvy people.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#44
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> but they are the correct answers Citation needed.

[deleted]

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#45
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> but they are the correct answers Citation needed.

https://news.ycombinator.com/user?id=tptacek

OP used to own/manage a world-class security consulting firm in Chicago, and now runs the entire security team for several decent-sized startups. His expertise is the citation.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#46
post #43
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

notes/questions: 4. a citation why chrome would be "safer" than firefox (or edge) would be appreciated. in terms of privacy, i wouldn't trust chrome as much as i'd trust firefox. 7 and 10: as others have noted, where is the security risk in storing the encrypted vault in the cloud? actually, choosing user-friendly solutions has a security benefit in itself because it doesn't make you switch to less secure alternative…

I think it's reasonable to trust Firefox's privacy more than Chrome's. But there are very few people in the industry who trust it's security more than Chrome's. Chrome has a more secure architecture and one of the best security teams assembled for any consumer product.

The iOS and Chrome recommendations are the things I'm saying that I believe to be somewhat unpopular here. But in the software security community, they've been commonly accepted for several years now.

I try not to recommend PGP anymore, not because it's unsafe but because it's difficult to use and discouraging for unsophisticated users.

Having said that: I actively warn against trying to use PGP for secure email. Email has inferior security even with PGP layered on top of it. Signal was designed for long-term asynchronous conversations; if you can use PGP, you can use Signal. Use Signal instead.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#47

Earlier quoted context omitted.

> but they are the correct answers Citation needed.

https://news.ycombinator.com/user?id=tptacek OP used to own/manage a world-class security consulting firm in Chicago, and now runs the entire security team for several decent-sized startups. His expertise is the citation.

The way I would put it is that we run the entire security teams for several decent-sized startups. :)

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#48
post #42
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> Get an iPhone and use it in preference to your computer. Color me surprised, but wasn't Apple involved with PRISM. Gives me reason enough to believe they maybe in on similar programs given there have been no drastic changes to their policy and whatnot

Aside from Apple appearing on a PRISM slide deck, I don't think there is any evidence to support your claim.

I suspect they weren't complicit in being involved in PRISM, but maybe that's just me hoping.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#49
post #33
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> Get an iPhone and use it in preference to your computer. When connecting to a computer or charging, never ever tap on "trust this computer". If I understand it right "trusting this computer" involves some irrevocable certificate exchange, in effect granting the computer elevated permissions. Can someone correct me? What precisely "trusting" on iphone means except from the ability to decrypt backups? Also: Don't use…

This is true. It is most commonly used to decrypt backups and allows developer to install personally signed apps on the device for development.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#50
post #24

Beware of the guy that has too much free time, too many contacts and want to scale up the protest to more violent methods. He is probably an FBI informant. It was common during the previous administration, I don't expect it to have finished. I'm too pessimistic about the security situation since a long time ago. Just email your Gmail/Hotmail/Facebook/Tweeter password to the NSA/CIA/FBI chief, so you don't get a false…

Very much the first two sentences, here: if anyone starts saying that they know where they can get instructions to make a bomb, they are probably an agent trying to provoke you. Kick them out. What they won't do, and you should: learn your rights. Get a friendly lawyer to advise you and agree to represent you, should anybody get arrested.

If anyone says they know where they can get instructions to make a bomb you should kick them out regardless, doesn't matter if they're probably an agent or not.

That actually reminds me of the time when the FBI sent undercover agents to mosques to try and entrap some Muslims by pretending to be jihadists, and the people at the mosque reported the agents to the FBI.

Post reply on HN