Thanks for any suggestions you have.
Ask HN: Online Security Tips for Newbie Freedom Activists?
1–10 of 140 posts
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#2Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#3Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#4This may involve drastic steps like not using email.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#5Rule #1. No phones. If this can't be avoided. burner phones without linked accounts. they cost $30-50, plus some for minutes/sms/basic data. This is good for using maps and visiting forums etc. Burner phones should be able to remove batteries. keep them fully powered down anytime you are near home or in your neighborhood. Major companies and governments are incredibly good at connecting profiles based on ancillary meta-data that you don't even think about.
Rule #2. see rule #1. Your phone isn't secure, get used to it.
rule #3. encrypt everything, use tails and TOR.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#6Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#7Once you have an understanding of what you need to protect and who your main adversaries are, choosing the right tools should become more straightforward.
My favorite guide to threat modeling for activists comes from WITNESS: https://blog.witness.org/2016/11/getting-started-digital-sec...
EFF Surveillance Self-Defense (mentioned elsewhere in this thread) also has a guide to threat modeling, as well as a lot of good resources around how to use various tools.
But my advice: don't choose the tools first, or the non-techies won't understand why they have to use them and may become discouraged by the friction and poor usability they encounter.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#8https://source.opennews.org/en-US/learning/security-journali...
https://source.opennews.org/en-US/learning/security-journali...
In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector:
1. Enable two-factor auth on all accounts, especially their email.
2. Care about proper access control.
#2 is something I see violated quite frequently by tech novices, as it is a fairly mundane detail. Such as giving everyone admin level access to the org's Wordpress installation, and someone inevitably gets phished. And then there's the even more common problem of not revoking access when a member leaves.
And of course, phishing seems by far the most common way that groups get hacked. The recent U.S. election is the new canonical example, but I believe it's been the downfall of many other high profile orgs, such as the Associated Press and HBGary.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#9Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#10Privacy is the antithesis of public advocacy.