Live data from Hacker News

How to encrypt your entire life in less than an hour

medium.freecodecamp.com

51–60 of 70 posts

Re: How to encrypt your entire life in less than an hour

#51
Better off reading JJ Luna's How to Be Invisible plus espionage non-fiction about Cold War fieldcraft. Then just stop using electronics when you really want privacy. Also, if you do crypto, make it look like HTTPS or something normal to be lost in the crowds over WiFi proxies. Signal and Tor screams "Look at me!"

Truth is, though, you wont be participating with most people online if you have very strong INFOSEC and OPSEC. The baseline is just way too low with insecurity and surveillance everywhere.

Re: How to encrypt your entire life in less than an hour

#52
post #38

Signal is atrocious for security. You literally log in with your phone number. Anything you send is directly and irrevocably tied with your physical identity. What good is to me that the messages are encrypted? When the police come knocking, either I'll decrypt them, they'll beat me until I decrypt them, or I'll die in prison for not decrypting them. I do want my messages encrypted, but more than that I really want t…

Walk to a Target with $200 cash and no electronic devices on you. Buy a prepaid android smart-phone and a pre-paid airtime card, and activate them using said device. Too bad meta-data and social graphs will screw you over anyways. Unless you don't use the device for interacting with people you know, in which case, what's the point?

Best find a Target you can walk to without being on camera.

Re: How to encrypt your entire life in less than an hour

#53

Earlier quoted context omitted.

Walk to a Target with $200 cash and no electronic devices on you. Buy a prepaid android smart-phone and a pre-paid airtime card, and activate them using said device. Too bad meta-data and social graphs will screw you over anyways. Unless you don't use the device for interacting with people you know, in which case, what's the point?

Best find a Target you can walk to without being on camera.

Depends on your threat model, really.

Re: How to encrypt your entire life in less than an hour

#54

Earlier quoted context omitted.

I also use Keepass[x]! The issue that I see people facing is that it isn't multi-device (it's an offline password manager). For me, that is the selling point though.

> For me, that is the selling point though. Me too! Though I'm curious as to what you mean by multi-device? I use it on multiple devices just fine, though I have to sync them by hand.

At a guess, that it won't allow two devices to open the same db file (the first writes a lockfile). This does at least prevent corruption...

Re: How to encrypt your entire life in less than an hour

#55

I am not 100% sold on one particular password manager. Any hints/suggestions?

I like Keepass becuase it is not tied to any ongoing subscriptions or providers. You can use the file sync tool of your choice to distribute your file. The downside/feature is not having tight browser/app integration.

Yeah KeePass is great! I currently use KeePass2 on my Trisquel 7 machine. I use that app in conjunction with Deja Dup to back up my password database to S3. There's even an app on the fdroid store called KeePassDroid but I've yet to make it work. I think the version on the store hasn't been recently updated.

Re: How to encrypt your entire life in less than an hour

#56

Earlier quoted context omitted.

> For me, that is the selling point though. Me too! Though I'm curious as to what you mean by multi-device? I use it on multiple devices just fine, though I have to sync them by hand.

At a guess, that it won't allow two devices to open the same db file (the first writes a lockfile). This does at least prevent corruption...

Well it's an offline program, so two devices can't open the same file anyway.

Re: How to encrypt your entire life in less than an hour

#57
post #48

Earlier quoted context omitted.

I really wonder if intelligence services are paid to demoralize user groups when I see posts like this. If you do all these things, your resistance to even NSA-level incriminating evidence goes WAY down, and your vulnerability to local LEO and hackers goes to near-zero. This is, at best, a brick wall, through which an adversary would have to bulldoze.

> I really wonder if intelligence services are paid to demoralize user groups when I see posts like this. Bluntly, if you want to tangle with the pros playing like an amateur and not calculating the risks, you're going to be demoralized in your jail cell or worse. Understand, in depth , opsec before playing with the pros. Understand, understand, understand. Don't just grab random blog posts and mindless implement the…

At its core its about economics. The NSA wants to do mass survailance, and if masses of people adopt even small amounts of improved security it has an effect. People dont have to understand Signal, just use it, just as https.

If everybody did all the things in this blogpost, we would be better of.

Re: How to encrypt your entire life in less than an hour

#58

I am not 100% sold on one particular password manager. Any hints/suggestions?

I've tried many (1pass, ...), and hated them, now finally I am using Dashlane and it's pretty good. Still needs a little bit of work/love, but it mostly just works. I'm paying for the sync version, I don't mind paying for a usable way to have strong passwords all around.

Re: How to encrypt your entire life in less than an hour

#59

Earlier quoted context omitted.

Best find a Target you can walk to without being on camera.

Depends on your threat model, really.

If the threat model includes "the police come knocking" and "die in prison" then it's best to assume the phone can be traced back to the store and approximate time it was sold (potentially even the exact time and cash register), and surveillance videos will be searched.

Re: How to encrypt your entire life in less than an hour

#60

Earlier quoted context omitted.

What do you think most users get wrong when they do it "plug and play". What steps does reading the documentation have you do that makes it safer?

IIRC the docs say not to change the default window size to prevent tracking based on window size.

The tor browser bundle pops up a warning if you try to resize it.
Post reply on HN