Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

21–30 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#21
post #13

"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.

Is there a documented attack on say, Apple's Magic Keyboard?

(if it is true that some (relatively modern) bluetooth keyboards are sniffable and some aren't, I'm sure you can convince them to amend the article with specific models that are believed to be better)

Re: Basic Security Precautions for Non-Profits and Journalists

#22

Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…

Chrome has more robust exploit mitigations and its separated architecture is more mature than Firefox's.

Re: Basic Security Precautions for Non-Profits and Journalists

#23
post #13

"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.

Is there a documented attack on say, Apple's Magic Keyboard? (if it is true that some (relatively modern) bluetooth keyboards are sniffable and some aren't, I'm sure you can convince them to amend the article with specific models that are believed to be better)

I'd second adding recommendations for specific models. There are a lot of BT keyboards on the market of varying quality.

Re: Basic Security Precautions for Non-Profits and Journalists

#24
Just a bit of feedback: might be nice to repeat the "Don't" in front of each sentence, even if it's grouped under the heading and therefore repetitive: I found myself being like "wait, it's telling me to backup my messages to google drive? Are they client-side encrypted?"

Re: Basic Security Precautions for Non-Profits and Journalists

#25

Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…

> Use your fingerprint to lock/unlock devices.

Fingerprints have a different and weaker legal standard than passwords to protect them

> Use an Android phone.

It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in.

> Take the devices you work on across the US border

Any data or passwords you have on you is data you could lose, get forced to cough up, etc.

> Assuming I have to carry my laptop and phone across the border, what precautions can I take to minimize the potential privacy violations?

Put an encrypted blob on [name a cloud provider]. Download it once you cross through customs.

> why is Firefox not recommended?

Because Firefox has no sandbox and gets routinely exploited by Law Enforcement

> It's used in the Tor browser

The Tor Browser is an abomination.

> I have not heard of any major security incident recently with Firefox.

You have not been paying attention. Maybe consider accepting the advice of experts?

Re: Basic Security Precautions for Non-Profits and Journalists

#26
post #23

Earlier quoted context omitted.

Is there a documented attack on say, Apple's Magic Keyboard? (if it is true that some (relatively modern) bluetooth keyboards are sniffable and some aren't, I'm sure you can convince them to amend the article with specific models that are believed to be better)

I'd second adding recommendations for specific models. There are a lot of BT keyboards on the market of varying quality.

(I don't in any way own this document).

I acknowledge that the situation with Bluetooth peripherals is complicated† and accept that there are probably a bunch of vendors that are unsafe to use. It might be reasonable to simply require Apple peripherals --- not because they're the best, but because Apple is more accountable to peripherals security than most other vendors are.

On the other hand, what we can't reasonably do is create a Bluetooth Keyboard Product Guide in a simple set of security recommendations. Not only will it not be effective, but it will discourage the audience, who will fall back to their previous insecure configurations.

So I'd ask to what extent we think Bluetooth sniffing attacks on journalists are a spy movie threat. No matter what device they use, simply by using a wireless device as an input, they're exposing those inputs to timing as well. But then, as well, Apple's software update could be targeted too.

The basic idea behind the "use a Bluetooth keyboard recommendation" is, I presume, to convince people who would otherwise use computers to do sensitive work to instead use an iDevice. That's a very sound security principle; those iDevices are far more secure than the median fully-functional computer.

If I had to pick between telling a journalist to use a random Bluetooth keyboard with an iPad, or use a Macbook or Thinkpad, I would have a hard time deciding, but I think I'd ultimately go with the random Bluetooth keyboard --- there are too many different ways the computer can be undetectably (to a typical user) owned up, and only one fairly elaborate scenario where the BT keyboard will screw them.

What I'm learning from working with at-risk normal users is that a lot of security steps we all take for granted are simply not on the table for the people who need security the most.

Way more complicated than the people claiming "Bluetooth keyboards are trivially sniffable" are letting on

Re: Basic Security Precautions for Non-Profits and Journalists

#27
post #13

"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.

> Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.

It's worth the risk to get people to use a iPhone or iPad more routinely. Also, the risk of this is exceedingly low because an attacker needs to actively interfere with the pairing process and be physically present for collection. This attack doesn't scale like "It's Windows, go pull the hard drive and read everything on it." I've never heard of LE using active BT attacks and I keep up on these things.

Re: Basic Security Precautions for Non-Profits and Journalists

#28
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

What about not using public wifi hotspots?

Re: Basic Security Precautions for Non-Profits and Journalists

#29
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

What about not using public wifi hotspots?

I wouldn't, but the instructions here assume the network itself is compromised, so I'm not sure we gain much security by adding another scary-sounding technical requirement.

Re: Basic Security Precautions for Non-Profits and Journalists

#30
post #15
post #14

> Avoid installing spurious, unknown or unnecessary extensions. This is wrong. You absolutely must use an ad blocker or noscript extension if you intend to browse the web securely.

The guide doesn't say not to install an ad blocker, but I dispute that claim nonetheless. Ad blockers are fine, and probably add marginally to security, but I don't think they a necessity --- if you're using Chrome/Chromium. If I was using Firefox or IE, I would agree with you. But step one here is not to be using un-hardened browsers.

I generally make an exception for HTTPS Everywhere and Google Password Alert when I wrote things like this, but I agree that maybe it's worth it to cut them and simplify the guide.

https://chrome.google.com/webstore/detail/password-alert/noo...

https://chrome.google.com/webstore/detail/https-everywhere/g...

Post reply on HN