It's already too late, if you have an active Facebook group where you're discussing this stuff then you're already all tagged and profiled.
Ask HN: Online Security Tips for Newbie Freedom Activists?
11–20 of 140 posts
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#12It's already too late, if you have an active Facebook group where you're discussing this stuff then you're already all tagged and profiled.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#13the eff guide is really solid for most people [0] but i think its a little laymen for most people. Especially when you get into the activism side of things. Here are the rules i follow. Rule #1. No phones. If this can't be avoided. burner phones without linked accounts. they cost $30-50, plus some for minutes/sms/basic data. This is good for using maps and visiting forums etc. Burner phones should be able to remove b…
I have thought about taking some of these more "paranoid" measures as a precaution against an unpredictable political future. But doing this would cut me off from nearly every friend and family member.
How do you meet an average person and keep in contact with them (I.e. start a friendship or relationship) when doing something like this sounds insane?
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#14Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#151. Get an iPhone and use it in preference to your computer.
2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP").
3. Disable SMS 2FA on any account wherever you're using real 2FA.
4. Switch to Google Chrome, which is significantly more resilient against vulnerabilities than either Safari, Firefox, or IE.
5. Don't use Dropbox.
6. Enable your OS's built-in full-disk encryption (this is FileVault on a Mac, BitLocker on Windows).
7. Disable cloud-based keychain backups (OS X will ask you to opt-in when you configure your phone or laptop the first time; Windows will make you go out of your way to do it).
8. Install Signal and either WhatsApp or Wire on your iPhone. Use Signal when you can, and fall back to the less strict alternative app when you can't.
9. Don't use email to send sensitive information, full stop.
10. Install a password management application that doesn't store your secrets in the cloud. I recommend 1Password. Better though to rely on 2FA than on a password manager.
11. Do not use antivirus software, other than Microsoft's own antivirus software on Windows.
12. Turn off cloud photo backups and location sharing for your camera.
13. Don't accept or click on email attachments, or allow your peers to send email attachments.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#16Personally I don't think these resources go far enough, and some of the methods recommended have obvious exploits, or are too complicated for the less tech literate. Lot's of work to be done in this area for sure
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#17I like these guides by AP journalist Jonathan Stray: https://source.opennews.org/en-US/learning/security-journali... https://source.opennews.org/en-US/learning/security-journali... In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector: 1. Enable two-factor auth on all accounts, especially their email. 2. Care about proper access contr…
* At-risk users should disable SMS 2FA, and favor code-generating applications instead. It takes some effort to disable SMS, but that effort is worthwhile, because SMS is quite insecure.
* The guide correctly notes that attachment are dangerous, but isn't very pragmatic about how to handle that danger. I think the right answer is: establish a rule that you won't be using email attachments to transmit documents. If you can be sure of the provenance of a file, you don't need an error-prone dance to pre-screen it before opening it on your desktop.
* The guide wildly overstates the value of full disk encryption. FDE handles almost exclusively a single threat: the physical threat of your unattended computer. Alter any of those words, and FDE does essentially nothing. You should, of course, enable FDE. You should not have high expectations about what it accomplishes.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#18I would absolutely start by running a threat modeling exercise, as that will help you focus on the important things and tune out unnecessary FUD (e.g. do you really need to PGP-encrypt everything and run TAILS if you're not being targeted by the NSA?). Once you have an understanding of what you need to protect and who your main adversaries are, choosing the right tools should become more straightforward. My favorite…
So, the idea that people should be blasé about encryption is worth questioning. If your threat model includes "law enforcement", then there's not much difference between "ostensibly NSA proof"† and "protected from police".
† Security people have a bit about this, which you can find by searching for "you're gonna get Mossaded".
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#19I'm too pessimistic about the security situation since a long time ago. Just email your Gmail/Hotmail/Facebook/Tweeter password to the NSA/CIA/FBI chief, so you don't get a false sensation of privacy.
Perhaps someone can try to keep some conversation private, like a journalist-whistleblower conversation, but it's too difficult to scale it up to bigger groups.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#20I like these guides by AP journalist Jonathan Stray: https://source.opennews.org/en-US/learning/security-journali... https://source.opennews.org/en-US/learning/security-journali... In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector: 1. Enable two-factor auth on all accounts, especially their email. 2. Care about proper access contr…
I have some quibbles with this (the first, practical, checkbox guide post; not so much the longer, abstract policy one). * At-risk users should disable SMS 2FA, and favor code-generating applications instead. It takes some effort to disable SMS, but that effort is worthwhile, because SMS is quite insecure. * The guide correctly notes that attachment are dangerous, but isn't very pragmatic about how to handle that dan…
I think the option of FDE is important to mention because I'm thinking the average non-techie thinks that having a password on their laptop prevents the (easy) reading of files when the laptop is confiscated.