Earlier quoted context omitted.
There are several gradations more security we could specify if we relaxed the constraint that ordinary non-technical activists be able to reliably do things. The level of protection you're getting here is from targeted non-state attackers, ambient opportunistic state-level actors, and non-specialist law enforcement. Some of this stuff would have helped Ross Ulbricht (I mean that non-normatively), for instance. Google…
Googling that phrase leads to one of your tweets which has a no longer valid link(redirects to the microsoft research homepage). Edit: I presume this is the intended article: https://www.usenix.org/system/files/1401_08-12_mickens.pdf
Ask HN: Online Security Tips for Newbie Freedom Activists?
61–70 of 140 posts
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#62Earlier quoted context omitted.
Regarding Chrome, here's a good place to start: https://noncombatant.org/2014/03/11/privacy-and-security-set... There are also people who use Chromium, or particular configurations of Chromium, instead of Chrome. That's fine. But don't use forks of Chromium , no matter who maintains them, even if it looks like a sizable effort. You don't want your browser to be any number of days behind the Chromium patch cycle. I us…
If you're very sophisticated, I like Tarsnap for online backups. But you have to be very sophisticated to use it. I think you're overstating this a bit. You have to be comfortable at a UNIX command line. Surely that alone doesn't qualify someone as "very sophisticated"?
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#63Earlier quoted context omitted.
> Get an iPhone and use it in preference to your computer. Color me surprised, but wasn't Apple involved with PRISM. Gives me reason enough to believe they maybe in on similar programs given there have been no drastic changes to their policy and whatnot
Aside from Apple appearing on a PRISM slide deck, I don't think there is any evidence to support your claim. I suspect they weren't complicit in being involved in PRISM, but maybe that's just me hoping.
That's far from a random mistake..
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#64I would absolutely start by running a threat modeling exercise, as that will help you focus on the important things and tune out unnecessary FUD (e.g. do you really need to PGP-encrypt everything and run TAILS if you're not being targeted by the NSA?). Once you have an understanding of what you need to protect and who your main adversaries are, choosing the right tools should become more straightforward. My favorite…
Ross Ulbricht was crushed by a mountain of evidence generated by the FBI simply by snatching his laptop from him when he was arrested and not allowing FDE to kick in. Had he compartmentalized and separately encrypted his files, much of that evidence might not have been available to the court. That might have been the difference between a few years in prison and the rest of his natural life. So, the idea that people s…
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#65I'm an active German antifascist. Here's something I do: 0) Get a lawyer. If you're arrested and you don't know a lawyer, you're screwed. And learn your rights: what do you have to tell the cops, and what you can refuse to tell them. Always carry a valid ID card with you. 1) When publishing pictures, especially on Twitter: place stickers over people's faces, or better: pixelate using ObscuraCam. The best thing is of…
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#66Advice that especially fits our situation is having an appropriate level of security for an intentionally PUBLIC organization whose members will be identifiable by multiple in-person activities in public places over the next few years. We are not afraid to be known as people who support the cause that we support. We are resolutely sticking to peaceful, legal means to reach our goals. Many group members are VERY wary of new group members--plenty of them are wary of me--so we will have to build mutual trust as we build mutual communication and public-facing communication. I like mz's advice to remind members that anything they say in an online group--even in our internal online groups for members only--might show up in mass media or in propaganda spread by opponents, so I try to model careful speaking and writing.
I'll link here to a document about the bad-case scenario of living under an actual dictatorship with a secret police force that kills political opponents. That's something I've actually done (in Taiwan, in the 1980s). The good news is that nonviolent popular movements can even overthrow dictators and establish democratic republics with full protection of civil liberties. That takes mental toughness, but it can be done. I've seen it done. You may be inspired by the document linked here and the other documents (in numerous languages) posted at the same website.
http://www.aeinstein.org/wp-content/uploads/2013/09/FDTD.pdf
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#67Earlier quoted context omitted.
If you're very sophisticated, I like Tarsnap for online backups. But you have to be very sophisticated to use it. I think you're overstating this a bit. You have to be comfortable at a UNIX command line. Surely that alone doesn't qualify someone as "very sophisticated"?
Very sophisticated varies on the demographics of the group, For HN no, for the general population yes.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#68Thank you very much to all for the detailed comments. I appreciate you keeping advice simple enough for someone like me, who decades ago counted as a "power user" of PCs, but who has no particular technical training or computer-related work experience. I will have to digest some of this advice for women (they are mostly women in the local group) who are barely comfortable using Facebook. And I'll pass on other tips t…
Women are incredibly prone to talking about other people in terms that they don't think is problematic and in terms that they think is anonymous enough for the internet, but really is not ("my sister" instead of "sister's name" -- but it is possible to identify your sister). This is a habit they need to break if they value the welfare of these other people.
Edit: Since this is getting down votes, I will add that if you think they won't listen to a man saying this, I will be happy to blog about it and you can give them the link. Perhaps it will be more palatable coming from a woman.
Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#69Re: Ask HN: Online Security Tips for Newbie Freedom Activists?
#70Earlier quoted context omitted.
Thanks for this, awesome. Questions: > 4. Switch to Google Chrome. Can one configure Chrome to not be a data-sucking kraken? > 7. Disable cloud-based keychain backups. That backup is encrypted, I'd hope? So, is the problem that getting hold of a cloud-backup facilitates off-line attacks on the encryption key? I remember Filippo (FiloSottile here) publishing his encrypted private PGP key [1] (back when he was still po…
Regarding Chrome, here's a good place to start: https://noncombatant.org/2014/03/11/privacy-and-security-set... There are also people who use Chromium, or particular configurations of Chromium, instead of Chrome. That's fine. But don't use forks of Chromium , no matter who maintains them, even if it looks like a sizable effort. You don't want your browser to be any number of days behind the Chromium patch cycle. I us…
In that case, why 1password over keepassx?