It won't work for everyone - Slate's CMS is notorious for only working in Firefox, for example - but if Pro Publica is going to hire 30 journalists, then be their vendor.
Basic Security Precautions for Non-Profits and Journalists
31–40 of 182 posts
Re: Basic Security Precautions for Non-Profits and Journalists
#32Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…
> Use your fingerprint to lock/unlock devices. Fingerprints have a different and weaker legal standard than passwords to protect them > Use an Android phone. It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in. > Take the devices you work on across the US border Any data or passwords you have o…
Don't use Tor Browser.
Re: Basic Security Precautions for Non-Profits and Journalists
#33Earlier quoted context omitted.
I'd second adding recommendations for specific models. There are a lot of BT keyboards on the market of varying quality.
(I don't in any way own this document). I acknowledge that the situation with Bluetooth peripherals is complicated† and accept that there are probably a bunch of vendors that are unsafe to use. It might be reasonable to simply require Apple peripherals --- not because they're the best, but because Apple is more accountable to peripherals security than most other vendors are. On the other hand, what we can't reasonabl…
Re: Basic Security Precautions for Non-Profits and Journalists
#34Earlier quoted context omitted.
The guide doesn't say not to install an ad blocker, but I dispute that claim nonetheless. Ad blockers are fine, and probably add marginally to security, but I don't think they a necessity --- if you're using Chrome/Chromium. If I was using Firefox or IE, I would agree with you. But step one here is not to be using un-hardened browsers.
I generally make an exception for HTTPS Everywhere and Google Password Alert when I wrote things like this, but I agree that maybe it's worth it to cut them and simplify the guide. https://chrome.google.com/webstore/detail/password-alert/noo... https://chrome.google.com/webstore/detail/https-everywhere/g...
GPA is great, but the premise behind this guide is that if you're relying on passwords for Google you're already boned. It's a security win even with TOTP enabled, but I don't think it's enough to earn a spot.
These guidelines are being distributed to activists and journalists along with free U2F keys, for whatever that's worth.
Re: Basic Security Precautions for Non-Profits and Journalists
#35It would probably behoove someone to sell these laptops, iPads, and iPhones to journalists, lawyers, and other folks with these configurations. It's a lot easier to give them a pre-configured locked down device that they can't mess with than it is to ask them to actually buy a Yubikey. It won't work for everyone - Slate's CMS is notorious for only working in Firefox, for example - but if Pro Publica is going to hire…
Re: Basic Security Precautions for Non-Profits and Journalists
#36"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.
Is there a documented attack on say, Apple's Magic Keyboard? (if it is true that some (relatively modern) bluetooth keyboards are sniffable and some aren't, I'm sure you can convince them to amend the article with specific models that are believed to be better)
Re: Basic Security Precautions for Non-Profits and Journalists
#37Earlier quoted context omitted.
Is there a documented attack on say, Apple's Magic Keyboard? (if it is true that some (relatively modern) bluetooth keyboards are sniffable and some aren't, I'm sure you can convince them to amend the article with specific models that are believed to be better)
Search for a presentation from Ruxcon 2016, I don't recall the researchers names but they presented attacks on various keyboards including ones with AES support.
Re: Basic Security Precautions for Non-Profits and Journalists
#38Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…
> Use your fingerprint to lock/unlock devices. Fingerprints have a different and weaker legal standard than passwords to protect them > Use an Android phone. It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in. > Take the devices you work on across the US border Any data or passwords you have o…
It would be great to have a few of these issues sourced in the comment (and your comments on the Tor Browser expanded with some reasoning) just so everyone is on the same page. I've seen some exploits with Tor Browser but I thought they'd be mostly sorted out.
I get that Chrome has some more mature sandboxing code, but I must admit I'm not a fan of how it handles a lot of things including download behaviour (http://security.stackexchange.com/q/145808 and https://scarybeastsecurity.blogspot.co.uk/2016/11/0day-poc-r...), Firefox at least does a better job here.
I agree with the advice for border passage, only thing that makes this difficult is the state of upload speeds.
Re: Basic Security Precautions for Non-Profits and Journalists
#39Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…
https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-a...
https://blog.mozilla.org/security/2015/08/06/firefox-exploit...
Re: Basic Security Precautions for Non-Profits and Journalists
#40How does one transfer information if they can't transfer anything across the border?
Where should one store sensitive information? An encrypted drive you're not supposed to transfer across the border?
I'm not really sure what a person is supposed to do with either of those two recommendations, especially if we're saying that person is not tech-savvy. I think these will just be ignored because they don't seem very viable and require a lot of background knowledge and planning.
Also, why is Chrome preferred to Firefox? I generally assume Chrome is listened to by Google across the board, and it still lacks something like NoScript. Chrome doesn't seem to do block XSS well, either.
Similarly, why Gmail as opposed to, I don't know, something like Protonmail or the like? Safety behind big company, reliability, viability?
Why Chromebook and not just a normal Linux?
The inherent trust in Google in this list confuses me.
And 1password over KeyPass. It seems every cloud-based password manager has been hacked in a round robin fashion, but I guess this solves the other cloud based problem.