Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

51–60 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#51
post #39
post #29

Earlier quoted context omitted.

Thanks for this, awesome. Questions: > 4. Switch to Google Chrome. Can one configure Chrome to not be a data-sucking kraken? > 7. Disable cloud-based keychain backups. That backup is encrypted, I'd hope? So, is the problem that getting hold of a cloud-backup facilitates off-line attacks on the encryption key? I remember Filippo (FiloSottile here) publishing his encrypted private PGP key [1] (back when he was still po…

Regarding Chrome, here's a good place to start: https://noncombatant.org/2014/03/11/privacy-and-security-set... There are also people who use Chromium, or particular configurations of Chromium, instead of Chrome. That's fine. But don't use forks of Chromium , no matter who maintains them, even if it looks like a sizable effort. You don't want your browser to be any number of days behind the Chromium patch cycle. I us…

If you're very sophisticated, I like Tarsnap for online backups. But you have to be very sophisticated to use it.

I think you're overstating this a bit. You have to be comfortable at a UNIX command line. Surely that alone doesn't qualify someone as "very sophisticated"?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#52
post #39

Earlier quoted context omitted.

Regarding Chrome, here's a good place to start: https://noncombatant.org/2014/03/11/privacy-and-security-set... There are also people who use Chromium, or particular configurations of Chromium, instead of Chrome. That's fine. But don't use forks of Chromium , no matter who maintains them, even if it looks like a sizable effort. You don't want your browser to be any number of days behind the Chromium patch cycle. I us…

If you're very sophisticated, I like Tarsnap for online backups. But you have to be very sophisticated to use it. I think you're overstating this a bit. You have to be comfortable at a UNIX command line. Surely that alone doesn't qualify someone as "very sophisticated"?

Yes, it very much does.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#53

the eff guide is really solid for most people [0] but i think its a little laymen for most people. Especially when you get into the activism side of things. Here are the rules i follow. Rule #1. No phones. If this can't be avoided. burner phones without linked accounts. they cost $30-50, plus some for minutes/sms/basic data. This is good for using maps and visiting forums etc. Burner phones should be able to remove b…

That's expensive for a burner phone.

I don't know about the USA, but in New Zealand you can get a phone for $10, usually with $10 credit already loaded onto it. So in essence a free phone. It won't be a smart phone, but that's probably good.

Viewing Google maps on your phone, burner or not, is a pretty bad idea from a privacy viewpoint. Good old fashioned static maps is what you want, printed out is even better.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#54
post #47

Earlier quoted context omitted.

https://news.ycombinator.com/user?id=tptacek OP used to own/manage a world-class security consulting firm in Chicago, and now runs the entire security team for several decent-sized startups. His expertise is the citation.

The way I would put it is that we run the entire security teams for several decent-sized startups. :)

Edited! Thanks for correcting me!

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#55
post #34

Earlier quoted context omitted.

First, thank you. Second, how much security does this provide and against what? For example, Moxie said once that Signal was designed to be usable and prevent mass surveillance, but not necessarily to prevent targeted attacks (my paraphrasing);[0] civil rights activists can expect targeted attacks. Finally, the public needs real security professionals to do the work and provide a reliable, authoritative, updated guid…

There are several gradations more security we could specify if we relaxed the constraint that ordinary non-technical activists be able to reliably do things. The level of protection you're getting here is from targeted non-state attackers, ambient opportunistic state-level actors, and non-specialist law enforcement. Some of this stuff would have helped Ross Ulbricht (I mean that non-normatively), for instance. Google…

Googling that phrase leads to one of your tweets which has a no longer valid link(redirects to the microsoft research homepage).

Edit: I presume this is the intended article: https://www.usenix.org/system/files/1401_08-12_mickens.pdf

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#56
post #33
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> Get an iPhone and use it in preference to your computer. When connecting to a computer or charging, never ever tap on "trust this computer". If I understand it right "trusting this computer" involves some irrevocable certificate exchange, in effect granting the computer elevated permissions. Can someone correct me? What precisely "trusting" on iphone means except from the ability to decrypt backups? Also: Don't use…

It's revocable:

https://support.apple.com/en-us/HT202778

It's anyway not a great idea to plug anything into strange USB ports.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#57
post #39
post #29

Earlier quoted context omitted.

Thanks for this, awesome. Questions: > 4. Switch to Google Chrome. Can one configure Chrome to not be a data-sucking kraken? > 7. Disable cloud-based keychain backups. That backup is encrypted, I'd hope? So, is the problem that getting hold of a cloud-backup facilitates off-line attacks on the encryption key? I remember Filippo (FiloSottile here) publishing his encrypted private PGP key [1] (back when he was still po…

Regarding Chrome, here's a good place to start: https://noncombatant.org/2014/03/11/privacy-and-security-set... There are also people who use Chromium, or particular configurations of Chromium, instead of Chrome. That's fine. But don't use forks of Chromium , no matter who maintains them, even if it looks like a sizable effort. You don't want your browser to be any number of days behind the Chromium patch cycle. I us…

>You don't want your browser to be any number of days behind the Chromium patch cycle.

Since Chromium does not upgrade itself, do you happen to have a suggestion on how to be arrange to be notified when a new patch is released?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#58
post #18
post #7

I would absolutely start by running a threat modeling exercise, as that will help you focus on the important things and tune out unnecessary FUD (e.g. do you really need to PGP-encrypt everything and run TAILS if you're not being targeted by the NSA?). Once you have an understanding of what you need to protect and who your main adversaries are, choosing the right tools should become more straightforward. My favorite…

Ross Ulbricht was crushed by a mountain of evidence generated by the FBI simply by snatching his laptop from him when he was arrested and not allowing FDE to kick in. Had he compartmentalized and separately encrypted his files, much of that evidence might not have been available to the court. That might have been the difference between a few years in prison and the rest of his natural life. So, the idea that people s…

You're proving GP's point. If you're running the largest darknet drug market in the world, you should probably have stronger security and assume a group like the NSA, or with the means of the NSA, is targeting you.

Local police aren't going to be able to tap into the power of the NSA. Your local country sheriff isn't going to be able to tap into NSA resources, it's going to be difficult enough for them to tap into the resources of the FBI.

For the average person participating in activism of whatever sort, it's going to be perceived as more effort than it's worth if you suggest that they compartmentalize and separately encrypt all their files, keep several burner phones etc. etc. Simply encrypting their full drive is enough.

There's diminishing returns the further down security rabbit hole you go.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#59
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

You don't mean Chromium?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#60
post #55
post #34

Earlier quoted context omitted.

There are several gradations more security we could specify if we relaxed the constraint that ordinary non-technical activists be able to reliably do things. The level of protection you're getting here is from targeted non-state attackers, ambient opportunistic state-level actors, and non-specialist law enforcement. Some of this stuff would have helped Ross Ulbricht (I mean that non-normatively), for instance. Google…

Googling that phrase leads to one of your tweets which has a no longer valid link(redirects to the microsoft research homepage). Edit: I presume this is the intended article: https://www.usenix.org/system/files/1401_08-12_mickens.pdf

[deleted]
Post reply on HN