These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…
notes/questions: 4. a citation why chrome would be "safer" than firefox (or edge) would be appreciated. in terms of privacy, i wouldn't trust chrome as much as i'd trust firefox. 7 and 10: as others have noted, where is the security risk in storing the encrypted vault in the cloud? actually, choosing user-friendly solutions has a security benefit in itself because it doesn't make you switch to less secure alternative…
Ask HN: Online Security Tips for Newbie Freedom Activists?
81–90 of 140 posts
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#82These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…
This might be naive, but would you recommend being on iOS Beta to get security patches earlier? Also do you prefer Touch ID or password/passcode unlocking?
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#83I like these guides by AP journalist Jonathan Stray: https://source.opennews.org/en-US/learning/security-journali... https://source.opennews.org/en-US/learning/security-journali... In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector: 1. Enable two-factor auth on all accounts, especially their email. 2. Care about proper access contr…
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#84Earlier quoted context omitted.
notes/questions: 4. a citation why chrome would be "safer" than firefox (or edge) would be appreciated. in terms of privacy, i wouldn't trust chrome as much as i'd trust firefox. 7 and 10: as others have noted, where is the security risk in storing the encrypted vault in the cloud? actually, choosing user-friendly solutions has a security benefit in itself because it doesn't make you switch to less secure alternative…
I think it's reasonable to trust Firefox's privacy more than Chrome's. But there are very few people in the industry who trust it's security more than Chrome's. Chrome has a more secure architecture and one of the best security teams assembled for any consumer product. The iOS and Chrome recommendations are the things I'm saying that I believe to be somewhat unpopular here. But in the software security community, the…
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#85These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#86Earlier quoted context omitted.
This might be naive, but would you recommend being on iOS Beta to get security patches earlier? Also do you prefer Touch ID or password/passcode unlocking?
Personally, I would avoid Touch ID. In my opinion, a good security feature should work even when you are asleep or unconscious.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#87Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#88These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…
You can learn more about it at https://www.secfirst.org or download it from Google Play:
https://play.google.com/store/apps/details?id=org.secfirst.u...
You can also reuse our Creative Commons content and check out our code at https://www.github.com/securityfirst
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#89Earlier quoted context omitted.
Aside from Apple appearing on a PRISM slide deck, I don't think there is any evidence to support your claim. I suspect they weren't complicit in being involved in PRISM, but maybe that's just me hoping.
> Aside from Apple appearing on a PRISM slide deck That's far from a random mistake..
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#90Thank you very much to all for the detailed comments. I appreciate you keeping advice simple enough for someone like me, who decades ago counted as a "power user" of PCs, but who has no particular technical training or computer-related work experience. I will have to digest some of this advice for women (they are mostly women in the local group) who are barely comfortable using Facebook. And I'll pass on other tips t…
Since you have a lot of women, I will suggest that you explicitly instruct them to be careful about talking about other people in their lives in identifiable terms. Men tend to invest their identity in their work. Women tend to invest their identity in their relationships. Telling anecdotes about "My sister/boss/mother/daughter/son/husband" is potentially putting those people at risk. Encourage them to use vaguer ter…