Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

11–20 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#11
post #9

It's already too late, if you have an active Facebook group where you're discussing this stuff then you're already all tagged and profiled.

And there's no reason to suppose that YCombinator and HackerNews is not compromised and that there is no profiling going on by some entity.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#13

the eff guide is really solid for most people [0] but i think its a little laymen for most people. Especially when you get into the activism side of things. Here are the rules i follow. Rule #1. No phones. If this can't be avoided. burner phones without linked accounts. they cost $30-50, plus some for minutes/sms/basic data. This is good for using maps and visiting forums etc. Burner phones should be able to remove b…

What if someone needs to call or message you at home?

I have thought about taking some of these more "paranoid" measures as a precaution against an unpredictable political future. But doing this would cut me off from nearly every friend and family member.

How do you meet an average person and keep in contact with them (I.e. start a friendship or relationship) when doing something like this sounds insane?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#15
These answers are unlikely to make much of HN happy, but they are the correct answers.

1. Get an iPhone and use it in preference to your computer.

2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP").

3. Disable SMS 2FA on any account wherever you're using real 2FA.

4. Switch to Google Chrome, which is significantly more resilient against vulnerabilities than either Safari, Firefox, or IE.

5. Don't use Dropbox.

6. Enable your OS's built-in full-disk encryption (this is FileVault on a Mac, BitLocker on Windows).

7. Disable cloud-based keychain backups (OS X will ask you to opt-in when you configure your phone or laptop the first time; Windows will make you go out of your way to do it).

8. Install Signal and either WhatsApp or Wire on your iPhone. Use Signal when you can, and fall back to the less strict alternative app when you can't.

9. Don't use email to send sensitive information, full stop.

10. Install a password management application that doesn't store your secrets in the cloud. I recommend 1Password. Better though to rely on 2FA than on a password manager.

11. Do not use antivirus software, other than Microsoft's own antivirus software on Windows.

12. Turn off cloud photo backups and location sharing for your camera.

13. Don't accept or click on email attachments, or allow your peers to send email attachments.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#16
In addition to the EFF Security Self Defense (https://ssd.eff.org/ ) I've also seen this circulated: https://securityinabox.org/en/

Personally I don't think these resources go far enough, and some of the methods recommended have obvious exploits, or are too complicated for the less tech literate. Lot's of work to be done in this area for sure

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#17
post #8

I like these guides by AP journalist Jonathan Stray: https://source.opennews.org/en-US/learning/security-journali... https://source.opennews.org/en-US/learning/security-journali... In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector: 1. Enable two-factor auth on all accounts, especially their email. 2. Care about proper access contr…

I have some quibbles with this (the first, practical, checkbox guide post; not so much the longer, abstract policy one).

* At-risk users should disable SMS 2FA, and favor code-generating applications instead. It takes some effort to disable SMS, but that effort is worthwhile, because SMS is quite insecure.

* The guide correctly notes that attachment are dangerous, but isn't very pragmatic about how to handle that danger. I think the right answer is: establish a rule that you won't be using email attachments to transmit documents. If you can be sure of the provenance of a file, you don't need an error-prone dance to pre-screen it before opening it on your desktop.

* The guide wildly overstates the value of full disk encryption. FDE handles almost exclusively a single threat: the physical threat of your unattended computer. Alter any of those words, and FDE does essentially nothing. You should, of course, enable FDE. You should not have high expectations about what it accomplishes.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#18
post #7

I would absolutely start by running a threat modeling exercise, as that will help you focus on the important things and tune out unnecessary FUD (e.g. do you really need to PGP-encrypt everything and run TAILS if you're not being targeted by the NSA?). Once you have an understanding of what you need to protect and who your main adversaries are, choosing the right tools should become more straightforward. My favorite…

Ross Ulbricht was crushed by a mountain of evidence generated by the FBI simply by snatching his laptop from him when he was arrested and not allowing FDE to kick in. Had he compartmentalized and separately encrypted his files, much of that evidence might not have been available to the court. That might have been the difference between a few years in prison and the rest of his natural life.

So, the idea that people should be blasé about encryption is worth questioning. If your threat model includes "law enforcement", then there's not much difference between "ostensibly NSA proof"† and "protected from police".

Security people have a bit about this, which you can find by searching for "you're gonna get Mossaded".

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#19
Beware of the guy that has too much free time, too many contacts and want to scale up the protest to more violent methods. He is probably an FBI informant. It was common during the previous administration, I don't expect it to have finished.

I'm too pessimistic about the security situation since a long time ago. Just email your Gmail/Hotmail/Facebook/Tweeter password to the NSA/CIA/FBI chief, so you don't get a false sensation of privacy.

Perhaps someone can try to keep some conversation private, like a journalist-whistleblower conversation, but it's too difficult to scale it up to bigger groups.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#20
post #17
post #8

I like these guides by AP journalist Jonathan Stray: https://source.opennews.org/en-US/learning/security-journali... https://source.opennews.org/en-US/learning/security-journali... In general, I think the two things that activists and journalists need to do that they often don't do, yet is a very common attack vector: 1. Enable two-factor auth on all accounts, especially their email. 2. Care about proper access contr…

I have some quibbles with this (the first, practical, checkbox guide post; not so much the longer, abstract policy one). * At-risk users should disable SMS 2FA, and favor code-generating applications instead. It takes some effort to disable SMS, but that effort is worthwhile, because SMS is quite insecure. * The guide correctly notes that attachment are dangerous, but isn't very pragmatic about how to handle that dan…

I think the risk of your unattended computer being compromised is quite low for the average journalist, but don't activists in the field face increased danger of having their laptops/property seized during an arrest? It could be an activist participating in a march who happens to bring their laptop bag with them. Yes, ideally, people would have a policy not to engage in a protest while carrying laptops, but I could see activists who do the mobile-multimedia thing (shoot, process video/photos in the field) just being used to having their laptops out at all times.

I think the option of FDE is important to mention because I'm thinking the average non-techie thinks that having a password on their laptop prevents the (easy) reading of files when the laptop is confiscated.

Post reply on HN