Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

101–110 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#101
post #43
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

notes/questions: 4. a citation why chrome would be "safer" than firefox (or edge) would be appreciated. in terms of privacy, i wouldn't trust chrome as much as i'd trust firefox. 7 and 10: as others have noted, where is the security risk in storing the encrypted vault in the cloud? actually, choosing user-friendly solutions has a security benefit in itself because it doesn't make you switch to less secure alternative…

Chrome holds up far better in the annual Pwn2Own competitions than any other browser. The Chrome team really goes over the top on security and sandboxing. Firefox is unfortunately a CVE-fest.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#103
post #41

Earlier quoted context omitted.

The right way to think about secure messaging software is this: You want to be using a messenger based on Signal Protocol, no matter what. Nobody has thought more carefully about cryptographic messaging protocols than Trevor Perrin and Moxie. It's good to have two secure messengers, one that favors usability and has a large user base, and one that can function as a laboratory for strictly secure UX. The very secure m…

Reasons/links as to why no Telegram? Honestly curious.

https://medium.com/@thegrugq/operational-telegram-cbbaadb901...

https://moxie.org/blog/telegram-crypto-challenge/

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#104
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

I don't disagree with the list. But I do think that few political organizations are going to have the will and discipline to enforce it upon their members particularly in the US. For a political organization with the will and discipline to enforce such practices, effort would might be better invested in creating a cell structure that isolates access to information in terms of the social graph.

Or to put it another way, an organization that relies on technical means to maintain secrets is still subject to infiltration. Wikileaks shows how readily organizations with dedicated and expert security staff and meaningful budgets are compromised by lack of or weak compartmentalization. A Snowden knockoff just walks out the door with a thumb drive of documents and hands it over to people who aren't supposed to have access bypassing NSA level security. And that's in an environment where people are rigorously vetted, not one looking for volunteers to the cause.

If I have an issue with the answer, it's that it conceives of an adversary who is 'just like us'. But plant a bug. Tape a cell phone to a car. Hire a honeypot. All will bypass an iPhone and disk-encryption and the local police can do any of them legally with a little effort and just about anyone with a will and a few hundred dollars can do them illegally with even less effort. And in the political realm there are lots of people with lots of will and more than a few hundred dollars at risk.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#105
post #41

Earlier quoted context omitted.

The right way to think about secure messaging software is this: You want to be using a messenger based on Signal Protocol, no matter what. Nobody has thought more carefully about cryptographic messaging protocols than Trevor Perrin and Moxie. It's good to have two secure messengers, one that favors usability and has a large user base, and one that can function as a laboratory for strictly secure UX. The very secure m…

Reasons/links as to why no Telegram? Honestly curious.

Quick response and I'm no expert: their encryption technology isn't open source and from what I recall hasn't been verified by third parties. They claim that is sufficient but no one has been able to confirm that. "Security through obscurity" if you will.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#107
post #39

Earlier quoted context omitted.

Regarding Chrome, here's a good place to start: https://noncombatant.org/2014/03/11/privacy-and-security-set... There are also people who use Chromium, or particular configurations of Chromium, instead of Chrome. That's fine. But don't use forks of Chromium , no matter who maintains them, even if it looks like a sizable effort. You don't want your browser to be any number of days behind the Chromium patch cycle. I us…

> I am very worried about how well I can reason about cloud-based storage of any sort, and how it will interact with things like my browser. In that case, why 1password over keepassx?

1Password doesn't store secrets in the cloud, as far as I know. You have to manually back up the database and some users choose to store that encrypted db in the cloud.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#108
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

This is a crazy list.

1. IPhone is closed source and any kind of rootkit can be installed by Apple/NSA secret court system. I suggest not using a smartphone if you are serious about security.

2. Good but difficult to anonymize

3. Good

4. Google Chrome is a botnet effectively and users lose their expectation of privacy there. Should switch to Firefox and use Chromium (Not Chrome) as a backup. Ideally Tor browser though.

5. Why? It's great for sharing encrypted files. Certainly if you trust Apple, why not trust Dropbox?

8. Signal transmits metadata that Google/Apple and by extension NSA/FBI/CIA/DEA know about now. Use something else that protects your anonymity and is secure. Something like cryptocat/Pidgin OTR is better.

9. You can use email to send encrypted information.

10. Unnecessary. Good strong password is good enough and you don't have a centralized password storage app. Another benefit is avoiding all the frustration that comes with using it when you are on someone else's computer.

11. Commercial AVs are better than Microsoft's native solution as repeatedly shown on independent tests. If you are tech literate, you're probably fine with the native solution or no solution at all.

12. Good idea. Best not to have a smartphone at all.

13. That's crazy. Just know your email app. Attachments should be read only and if your software is updated, it's very very unlikely you'll be compromised. If the email isn't signed and you are worried, use an alternative app to open common document formats. PDF.js for PDF, Libre Office for documents.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#109
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

What is a better solution for remote file sharing, since email and Dropbox are out?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#110
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

How does Linux compare with either MacOS, Windows, or just using an iPhone? Any particular distros that are more secure than others, or software to include / not to include? I assume Android is a bad idea because of the ease of picking up spyware and the privileges that such software can have once downloaded? What's the best way to secure your web browsing & search history? Being an ex-Googler, I can think of a coupl…

"Android is vulnerable to several key-extraction techniques." [0] Another likely reason is the appalling update situation on non-Nexus/non-Pixel devices.

[0] https://arstechnica.com/security/2016/07/androids-full-disk-...

Post reply on HN