Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

11–20 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#11
post #7

dont use android?? copperheados?? hello? sure sounds bias to me. and no u wouldnt use gmail, u would use something non fourteen eyes. like protonmail or ur own pgp enigmal with riseup. u wouldnt even use social media. this is ridicules. whatsapp? really? after all the extreme crap they got caught with? how about u advise signal, silence, or xmpp options out there. chromebook?...tails...whonix....librem 15.... qubesos…

As far as Android goes: who's auditing CopperheadOS? What white hats are looking at it and trying to compromise it so that it can be improved? What's their rep, what's their record, and how do they stack up against iOS's internal and external security tests? As far as "ur own pgp enigmal with riseup" goes: how are you going to get people to email you? Are you, a journalist, going to manage SPF/DKIM and make sure you'…

not well? i advise u do some reasearch as this has been documented.

"Tails/Whonix/especially-Qubes are not because people need their stuff to actually work and to not spend more of their time fighting their computer than doing their jobs; "

lol? what kind of statment is this.. u can easily get work done on these. if your fighting your computer then technology isnt for you. qubes is stupid easy to use, tails in plug in and go. whonix especially with the auto installers now are even more click and go. where are you hearing people say they cant do work with these. thats literally outragious. security is not google i can tell u that for a fact. secuirty is not something u compromise with. as far as email, pgp isnt hard, and even proton mail makes it stupid easy. if its that big of an issue use something like ECS email where u dont need to deal with pgp but u still get security

Re: Basic Security Precautions for Non-Profits and Journalists

#12
post #5
post #2

So, no Android phones is not very pragmatic... Any justifications? (Especially without saying to use only FOSS OS)

I agree it's overly broad statement without justification, but it's not entirely unfounded either. iOS's extreme walled garden does protect you from many things that Android doesn't. As another commenter mentioned, security permissions are a mess, malware is a real thing, and the power and versatility of Android leaves you very vulnerable if you're in a high risk profession who must keep secrets safe.

Very few of the items in here have justifications listed, because that's not productive for the intended audience. They don't want to know "why" any more than most patients want to know "why" their doctor prescribes one antibiotic versus another.

Re: Basic Security Precautions for Non-Profits and Journalists

#15
post #14

> Avoid installing spurious, unknown or unnecessary extensions. This is wrong. You absolutely must use an ad blocker or noscript extension if you intend to browse the web securely.

The guide doesn't say not to install an ad blocker, but I dispute that claim nonetheless. Ad blockers are fine, and probably add marginally to security, but I don't think they a necessity --- if you're using Chrome/Chromium.

If I was using Firefox or IE, I would agree with you. But step one here is not to be using un-hardened browsers.

Re: Basic Security Precautions for Non-Profits and Journalists

#16
post #14

> Avoid installing spurious, unknown or unnecessary extensions. This is wrong. You absolutely must use an ad blocker or noscript extension if you intend to browse the web securely.

Not so much wrong as missing a line to install a script blocker that's neither spurious, unknown nor unnecessary. In general, the warning against extension is good.

Re: Basic Security Precautions for Non-Profits and Journalists

#17
post #14

> Avoid installing spurious, unknown or unnecessary extensions. This is wrong. You absolutely must use an ad blocker or noscript extension if you intend to browse the web securely.

Consider the meanings of "must use", "spurious", "unknown" and "unnecessary".

Re: Basic Security Precautions for Non-Profits and Journalists

#18
While iOS devices are generally more secure, its been proven that Apple has been a part of the various NSA programs (X-Keyscore, PRISM, etc).

Chromebooks are made by Google, who is also a known partner ni these programs.

It all comes down to who you trust, and recommending that Journalists use iOS Devices and Chromebooks made by Apple and Google who are known snoopers is a bad bet if the thing you're trying to avoid is the US Government.

Also, bluetooth keyboards are trivial to listen in on. Not a great recommendation.

This article is short but bogus.

Re: Basic Security Precautions for Non-Profits and Journalists

#19
post #13

"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.

There are keyboards that force AES-128 and don't fall back IIRC microsoft makes some.

A USB keyboard is almost certainly easier to secure though.

Re: Basic Security Precautions for Non-Profits and Journalists

#20
post #18

While iOS devices are generally more secure, its been proven that Apple has been a part of the various NSA programs (X-Keyscore, PRISM, etc). Chromebooks are made by Google, who is also a known partner ni these programs. It all comes down to who you trust, and recommending that Journalists use iOS Devices and Chromebooks made by Apple and Google who are known snoopers is a bad bet if the thing you're trying to avoid…

The people these notes are targeted at are not going to use whatever the vanity "secure" non-Google-infected non-Apple-infected non-Microsoft-infected options you'll have in mind. It's not going to happen. If you want to write a separate set of recommendations for people who spend their lives on Tor, that's fine. These recommendations have to work for people who are barely willing to install software, let along switch to idiosyncratic hardware.
Post reply on HN