Basic Security Precautions for Non-Profits and Journalists
techsolidarity.org
Basic Security Precautions for Non-Profits and Journalists
1–10 of 182 posts
Re: Basic Security Precautions for Non-Profits and Journalists
#2(Especially without saying to use only FOSS OS)
Re: Basic Security Precautions for Non-Profits and Journalists
#3chromebook?...tails...whonix....librem 15.... qubesos... lets get real here...
Re: Basic Security Precautions for Non-Profits and Journalists
#4So, no Android phones is not very pragmatic... Any justifications? (Especially without saying to use only FOSS OS)
As it happens, I use an Android phone as a daily driver. But I'm not a journalist and I'm not handling data that isn't sensitive to anyone but myself. I'm willing to take that risk (edit: and I'm able to, to a level I'm comfortable with, mitigate those risks, which a non-technical person probably can't evaluate safely, to say nothing of implement). But I'm not a journalist whose sources may depend on me.
Re: Basic Security Precautions for Non-Profits and Journalists
#5So, no Android phones is not very pragmatic... Any justifications? (Especially without saying to use only FOSS OS)
Re: Basic Security Precautions for Non-Profits and Journalists
#6So, no Android phones is not very pragmatic... Any justifications? (Especially without saying to use only FOSS OS)
I agree it's overly broad statement without justification, but it's not entirely unfounded either. iOS's extreme walled garden does protect you from many things that Android doesn't. As another commenter mentioned, security permissions are a mess, malware is a real thing, and the power and versatility of Android leaves you very vulnerable if you're in a high risk profession who must keep secrets safe.
Re: Basic Security Precautions for Non-Profits and Journalists
#7dont use android?? copperheados?? hello? sure sounds bias to me. and no u wouldnt use gmail, u would use something non fourteen eyes. like protonmail or ur own pgp enigmal with riseup. u wouldnt even use social media. this is ridicules. whatsapp? really? after all the extreme crap they got caught with? how about u advise signal, silence, or xmpp options out there. chromebook?...tails...whonix....librem 15.... qubesos…
As far as "ur own pgp enigmal with riseup" goes: how are you going to get people to email you? Are you, a journalist, going to manage SPF/DKIM and make sure you're doing it right? How are you going to manage antispam? Gmail is not perfect--but unless the totality of your threat model includes getting black-bagged because an NSL found encrypted emails in your inbox, it is probably the best option. (Protonmail is fine too, but increases friction--and increased friction increases the likelihood that you're not going to use it, falling back to easier tools.)
WhatsApp: either that or Signal are fine (and, indeed, run the same protocol!). XMPP relies largely on federation, which relies on federated servers not being compromised, so no, that's out. (I haven't looked at Silence, can't speak to it.)
Chromebooks are a decent option for some use cases, unless (as more and more journalists tend to do) you need something that can easily and effectively edit audio and video. Tails/Whonix/especially-Qubes are not because people need their stuff to actually work and to not spend more of their time fighting their computer than doing their jobs; to that end, a properly patched OS X is a pretty reasonable call.
"Getting real here" means finding a workable place on the do-your-job/security curve, and most of what you're saying is not. For example, of course you would "use social media", because that's a large part of the job of a journalist in 2017. Your recommendations, while (I assume) in good faith, indicate a willingness to invest more time in fighting your stuff than doing your job. Nobody else cares. Recommend what's easy and what gets 95% of the way there (and not, as with something like CopperheadOS, actually detracts).
Re: Basic Security Precautions for Non-Profits and Journalists
#8Don't :
> Use your fingerprint to lock/unlock devices.
> Use an Android phone.
> Take the devices you work on across the US border.
Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the persons devices always be in visibility or do the CBP officers handle them in separate rooms?
Assuming I have to carry my laptop and phone across the border, what precautions can I take to minimize the potential privacy violations? After crossing the border, do I just reinstall my OS of choice (Ubuntu) from scratch and reset all passwords?
Regarding the browser recommendation, why is Firefox not recommended? It's used in the Tor browser and I have not heard of any major security incident recently with Firefox.
Re: Basic Security Precautions for Non-Profits and Journalists
#9Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…
Look elsewhere in this thread for "why not use an Android device."
Don't carry your work devices across the US border because they may be taken, can be taken out of your view, and may be duplicated (and yeah, you should have FDE on your computers etc., but don't take the chance).
Re: Basic Security Precautions for Non-Profits and Journalists
#10These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine, but not workable for the audience these instructions are intended for.
We're simultaneously working with the airport lawyer groups (there's a huge one at ORD). It's been jarring to realize how many compromises are required to make things workable for groups of non-experts to use. Just getting software installed is a major hassle, so anything you install or customize needs to be really worth the effort.