Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

71–80 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#71
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Thank you so much for this list, it's more concise and useful than any corporate security lecture I've ever received! Some questions:

> 10. Install a password management application that doesn't store your secrets in the cloud.

Great recommendation, but how do you handle syncing passwords between your computer and phone?

> 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP").

Do you recommend using the TOTP feature of 1Password, or would you consider storing your password / TOTP together a loss of the "2nd Factor"?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#72
post #9

It's already too late, if you have an active Facebook group where you're discussing this stuff then you're already all tagged and profiled.

But..but..we set the group's privacy to "Secret"!

Go back to reddit

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#73
post #11
post #9

It's already too late, if you have an active Facebook group where you're discussing this stuff then you're already all tagged and profiled.

And there's no reason to suppose that YCombinator and HackerNews is not compromised and that there is no profiling going on by some entity.

It doesn't even need to be compromised. A lot of the HN data is available through the HN API. Plenty of data there without requiring any additional access to the HN hardware.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#74
post #64
post #18

Earlier quoted context omitted.

Ross Ulbricht was crushed by a mountain of evidence generated by the FBI simply by snatching his laptop from him when he was arrested and not allowing FDE to kick in. Had he compartmentalized and separately encrypted his files, much of that evidence might not have been available to the court. That might have been the difference between a few years in prison and the rest of his natural life. So, the idea that people s…

could you please provide links? googling this phrase is unhelpfully returning this precise thread and not much else that appears useful.

Probably this gem: https://www.usenix.org/system/files/1401_08-12_mickens.pdf

> In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US"

> Threat: Organized criminals breaking into your email account and sending spam using your identity

Solution:

Strong passwords + common sense (don’t click on unsolicited herbal Viagra ads that result in keyloggers and sorrow)

> Threat: The Mossad doing Mossad things with your email account

Solution

* Magical amulets?

* Fake your own death, move into a submarine?

* YOU’RE STILL GONNA BE MOSSAD’ED UPON

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#75
post #27
post #23

Earlier quoted context omitted.

Yes. Email in general is an opsec nightmare, no matter what rules you come up with or what tools you use to protect it. It's the worst case scenario, a system that goes out of its way to make sure everyone has copies of everything. Above all else: do not create mailing lists for at-risk projects .

We may be talking at cross purposes, but for clarity's sake: I was not recommending email. I was only recommending that noobs be told to think of any written communication in terms of "like it is being published to the front page of your local paper, where your husband, mother in law, and any personal enemy might see it" and, in this case, where any officials might see it as well. The list in question was mostly full…

Indeed. The fundamental truth about communication is that you want at least one person to be able to read it. That person might be undercover, or get turned (just now thousands of (new) people can be threatened with deportation, for example).

Doesn't mean one shouldn't organise, just be aware that all communication have risks.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#76
post #42
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> Get an iPhone and use it in preference to your computer. Color me surprised, but wasn't Apple involved with PRISM. Gives me reason enough to believe they maybe in on similar programs given there have been no drastic changes to their policy and whatnot

The problem is that PRISM has conflated two separate things, and it is unclear how much of that conflation occurred at the NSA and how much outside.

Apple was (and is) compliant in the "release customer details with a court order" thing, which it seems is part of the PRISM data.

However, there was a second part, where the NSA got bulk access to communications without a court order. It is unclear which companies were complicit in this part. We know Google wasn't (because the NSA slide decks show how they had to intercept Google's inter and intra-data center links which were unencrypted at the time - and Google undertook a crash program to fix that).

Apple's statements are pretty clear: they say they only release information with a court order. That means they weren't complicit in bulk collection - but they may have been hacked at the time like Google was.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#77
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

any recommendation encryption for linux?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#78
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Thank you so much for this list, it's more concise and useful than any corporate security lecture I've ever received! Some questions: > 10. Install a password management application that doesn't store your secrets in the cloud. Great recommendation, but how do you handle syncing passwords between your computer and phone? > 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email…

1Password has a WiFi sync option that syncs your passwords between your computer and phone when they're both connected to the same WiFi network. I've been doing it Mac --> Android for quite some time and never had any issues.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#79

I'm an active German antifascist. Here's something I do: 0) Get a lawyer. If you're arrested and you don't know a lawyer, you're screwed. And learn your rights: what do you have to tell the cops, and what you can refuse to tell them. Always carry a valid ID card with you. 1) When publishing pictures, especially on Twitter: place stickers over people's faces, or better: pixelate using ObscuraCam. The best thing is of…

Thanks especially for items 8 through 15, which some people forget. Part of what I hope happens where I live is that 13 happens in a big way, and the overall inclusive movement becomes broader and broader as different specialized local groups network with one another and with a variety of national groups.

You're welcome. I wish you all the best!

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#80
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

This might be naive, but would you recommend being on iOS Beta to get security patches earlier? Also do you prefer Touch ID or password/passcode unlocking?
Post reply on HN