Earlier quoted context omitted.
The problem: "Nothing to hide" depends on the context. Maybe you don't have anything to hide under the current laws, but what about laws in 20 years from now? Maybe times change and suddenly, you've got a lot to hide.
I'm having trouble finding it but the perfect example of this is a census that collected religious affiliation (for innocent statistics) that some brave citizens went to great lengths to destroy when they came under Nazi occupation in order to try and protect Jewish residents.
Going dark: online privacy and anonymity for normal people
111–120 of 125 posts
Re: Going dark: online privacy and anonymity for normal people
#112Earlier quoted context omitted.
I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…
I wonder if there's any demand for a pre-built whitelist for NoScript that includes stuff like Amazon, Google, Apple, banks, and most other popular sites. The admin would err on the side of allowing scripts to run, while the default-block rule would still block unknown and ad/tracker domains. It would obviously be less secure than an intelligent user making all their own decisions, but it would make the barrier to us…
Re: Going dark: online privacy and anonymity for normal people
#113Earlier quoted context omitted.
I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…
Until my aging mother can use NoScript and still understand why many websites just don't seem to work, it isn't covering the majority use cases.
Re: Going dark: online privacy and anonymity for normal people
#114Great article. The only real omission I noticed is the lack of mention of advanced browser fingerprinting techniques that can be used against browsers, even if caches are emptied, 'porn modes' activated, VPNs opnened. As demonstrated here by the EFF's Panopticlick initiative. https://panopticlick.eff.org/ One of the most important points about the anonymity provied by the Tor project to remember is that the Tor Brows…
What do you mean with "VPNs opnened"? The article is wrong about Tor being an alternative option to a VPN. If anonymity is your concern, you should use TOR to connect to a VPN (paid with Bitcoins).
Operational security and Tor is such an interesting and frankly, quite scary subject. I've mainly used and instructed people on Tor for read-only uses of the web.
For my own needs, masking the origin of an actively participating persona is out of scope. I generally warn people about doing anything that requires sign-on/nicknames etc without very careful research.
I recognize that my lack of a need for serious anonymity for basic political activism etc is a huge privilege. So I try to give back by running a bunch of Tor middle relay myself.
For serious anonymity, I'd really be strict about using a forensically clean Tails USB boot environment, on varying public Wi-FI hotspots with a dedicated laptop that never has touched my regular network. The laptop must not ever be powered on near my house. Lots of systems, like Cisco Meraki business Wi-Fi APs take note of all nearby Wi-Fi and Bluetooth devices for 'location analytics'.
Javascript and stuff must be disabled of course. Carrying any cell phone, burner or otherwise is out of the question.
The reasons are many, but for starters, you don't want to be identifiable as the only person at your location making Tor connections, if you're doing something important.
Here are some good points on the subject. https://www.youtube.com/watch?v=eQ2OZKitRwc
My approach for promoting Tor to regular people around me is through describing it as a way to do random googling on subjects people don't necessarily want linked back to them, through analytics and ad companies.
I'm personally pretty convinced that insurance companies around the globe are looking pretty seriously at how far they could push their use of intelligence from data brokers. For purposes like identifying people with potential inherited diseases, recreational drug use habits, mental health problems etc.
So, I think Tor is important for all of us.
Re: Going dark: online privacy and anonymity for normal people
#115Earlier quoted context omitted.
I just bought an entire TLD for signups/spam and made it a catchall. One positive is I know when companies are breached often before they announce it as my pagerduty@domain.com told me a little while ago. http://www.theregister.co.uk/2015/07/31/incident_managers_pa...
This is a great idea! What's it like viewing email? Which client do you use? Is it easy to see which email address the email was sent to?
Re: Going dark: online privacy and anonymity for normal people
#116Skimmed the article, saw that he reccomended using Googlemail. Looked at the title of the post again. Looked at Googlemail reccomendation. Laughed and made a mental note not to trust "Troy Hunt".
Re: Going dark: online privacy and anonymity for normal people
#117Earlier quoted context omitted.
If you primarily use honeywords, then you can filter out anything going to craigds@host.tld as spam. The hard part would be transitioning people you want to communicate with to craigds+{family,friends,correspondence}@host.tld. Optionally, retain craigds@host.tld for personal and professional communication/correspondence, and move everything else to craigds1+{something}@host.tld (or a different host).
I just bought an entire TLD for signups/spam and made it a catchall. One positive is I know when companies are breached often before they announce it as my pagerduty@domain.com told me a little while ago. http://www.theregister.co.uk/2015/07/31/incident_managers_pa...
It's also nice to be able to kill specific email addresses once a breach has been disclosed and the spam becomes plentiful.
Re: Going dark: online privacy and anonymity for normal people
#118Earlier quoted context omitted.
What do you mean with "VPNs opnened"? The article is wrong about Tor being an alternative option to a VPN. If anonymity is your concern, you should use TOR to connect to a VPN (paid with Bitcoins).
"VPNs opened" was poor wording. Clarifications provided by the guys below seem to match what I remember from listening to talks on Tor by the project's developers. Operational security and Tor is such an interesting and frankly, quite scary subject. I've mainly used and instructed people on Tor for read-only uses of the web. For my own needs, masking the origin of an actively participating persona is out of scope. I…
Re: Going dark: online privacy and anonymity for normal people
#119Earlier quoted context omitted.
The problem: "Nothing to hide" depends on the context. Maybe you don't have anything to hide under the current laws, but what about laws in 20 years from now? Maybe times change and suddenly, you've got a lot to hide.
I'm having trouble finding it but the perfect example of this is a census that collected religious affiliation (for innocent statistics) that some brave citizens went to great lengths to destroy when they came under Nazi occupation in order to try and protect Jewish residents.
http://jacquesmattheij.com/if-you-have-nothing-to-hide
It's cropped up on HN before.
Re: Going dark: online privacy and anonymity for normal people
#120Earlier quoted context omitted.
With the phrase "nothing to _hide_" you are starting from a bias: that if you have something that is not public knowledge then it must be wrong or evil and must therefore be hidden.
This is an excellent observation. Perhaps the phrase should be "If you have nothing private you have nothing to fear".
And that better sentence busts open the assumption :)