Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

81–90 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#81
post #43
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

notes/questions: 4. a citation why chrome would be "safer" than firefox (or edge) would be appreciated. in terms of privacy, i wouldn't trust chrome as much as i'd trust firefox. 7 and 10: as others have noted, where is the security risk in storing the encrypted vault in the cloud? actually, choosing user-friendly solutions has a security benefit in itself because it doesn't make you switch to less secure alternative…

The FBI has repeatedly found and exploited Firefox vulnerabilities. Chrome does all the dangerous bug-prone stuff (parsing) in a separate process that is sandboxed, so vulnerabilities are harder to exploit.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#82
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

This might be naive, but would you recommend being on iOS Beta to get security patches earlier? Also do you prefer Touch ID or password/passcode unlocking?

Personally, I would avoid Touch ID. In my opinion, a good security feature should work even when you are asleep or unconscious.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#83
post #8

I like these guides by AP journalist Jonathan Stray: https://source.opennews.org/en-US/learning/security-journali... https://source.opennews.org/en-US/learning/security-journali... In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector: 1. Enable two-factor auth on all accounts, especially their email. 2. Care about proper access contr…

If you are worried about phishing (you should be) don't use SMS or code-based two-factor. They can and are being phished. Use U2F (yubikeys). They are phishing proof.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#84
post #46
post #43

Earlier quoted context omitted.

notes/questions: 4. a citation why chrome would be "safer" than firefox (or edge) would be appreciated. in terms of privacy, i wouldn't trust chrome as much as i'd trust firefox. 7 and 10: as others have noted, where is the security risk in storing the encrypted vault in the cloud? actually, choosing user-friendly solutions has a security benefit in itself because it doesn't make you switch to less secure alternative…

I think it's reasonable to trust Firefox's privacy more than Chrome's. But there are very few people in the industry who trust it's security more than Chrome's. Chrome has a more secure architecture and one of the best security teams assembled for any consumer product. The iOS and Chrome recommendations are the things I'm saying that I believe to be somewhat unpopular here. But in the software security community, the…

Yeah, its a mixed bag when choosing between Firefox and Chrome - especially if both security and privacy are desired. Personally, I trust and like Mozilla more than Google, but Chrome has better security from what I have observed.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#85
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

If you had to use a cloud-based storage system, what would you use to replace Dropbox? Spider Oak?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#86
post #82

Earlier quoted context omitted.

This might be naive, but would you recommend being on iOS Beta to get security patches earlier? Also do you prefer Touch ID or password/passcode unlocking?

Personally, I would avoid Touch ID. In my opinion, a good security feature should work even when you are asleep or unconscious.

[deleted]

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#88
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Hey you would probably be interested in a app that we make called Umbrella. Built by activists, for activists, Umbrella makes it easier to learn about and manage digital and physical security. It has short lessons and checklists on everything from sending a secure email to security at protests. It's free, open source and available on Android.

You can learn more about it at https://www.secfirst.org or download it from Google Play:

https://play.google.com/store/apps/details?id=org.secfirst.u...

You can also reuse our Creative Commons content and check out our code at https://www.github.com/securityfirst

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#89
post #63

Earlier quoted context omitted.

Aside from Apple appearing on a PRISM slide deck, I don't think there is any evidence to support your claim. I suspect they weren't complicit in being involved in PRISM, but maybe that's just me hoping.

> Aside from Apple appearing on a PRISM slide deck That's far from a random mistake..

No doubt they may have been pwned, either by infiltration or other means. There's no evidence of them (ala Yahoo) complying with the NSA

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#90
post #68

Thank you very much to all for the detailed comments. I appreciate you keeping advice simple enough for someone like me, who decades ago counted as a "power user" of PCs, but who has no particular technical training or computer-related work experience. I will have to digest some of this advice for women (they are mostly women in the local group) who are barely comfortable using Facebook. And I'll pass on other tips t…

Since you have a lot of women, I will suggest that you explicitly instruct them to be careful about talking about other people in their lives in identifiable terms. Men tend to invest their identity in their work. Women tend to invest their identity in their relationships. Telling anecdotes about "My sister/boss/mother/daughter/son/husband" is potentially putting those people at risk. Encourage them to use vaguer ter…

Maybe some of the onlookers don't know that you have long identified yourself as a woman here. As I recall, we (you and I) eventually figured out that we first "met" on an online community before Hacker News was founded.
Post reply on HN