Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

31–40 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#31
It would probably behoove someone to sell these laptops, iPads, and iPhones to journalists, lawyers, and other folks with these configurations. It's a lot easier to give them a pre-configured locked down device that they can't mess with than it is to ask them to actually buy a Yubikey.

It won't work for everyone - Slate's CMS is notorious for only working in Firefox, for example - but if Pro Publica is going to hire 30 journalists, then be their vendor.

Re: Basic Security Precautions for Non-Profits and Journalists

#32
post #25

Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…

> Use your fingerprint to lock/unlock devices. Fingerprints have a different and weaker legal standard than passwords to protect them > Use an Android phone. It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in. > Take the devices you work on across the US border Any data or passwords you have o…

Adding: the Tor Browser might be the least safe browser to use of all available browsers that can be installed on modern computers. It is a perfect storm of "inferior security design" and "maximized adversarial value per exploit dollar spent".

Don't use Tor Browser.

Re: Basic Security Precautions for Non-Profits and Journalists

#33
post #26
post #23

Earlier quoted context omitted.

I'd second adding recommendations for specific models. There are a lot of BT keyboards on the market of varying quality.

(I don't in any way own this document). I acknowledge that the situation with Bluetooth peripherals is complicated† and accept that there are probably a bunch of vendors that are unsafe to use. It might be reasonable to simply require Apple peripherals --- not because they're the best, but because Apple is more accountable to peripherals security than most other vendors are. On the other hand, what we can't reasonabl…

A sneaky way to suggest them would be to mention some that are comfortable to type on.

Re: Basic Security Precautions for Non-Profits and Journalists

#34
post #30
post #15

Earlier quoted context omitted.

The guide doesn't say not to install an ad blocker, but I dispute that claim nonetheless. Ad blockers are fine, and probably add marginally to security, but I don't think they a necessity --- if you're using Chrome/Chromium. If I was using Firefox or IE, I would agree with you. But step one here is not to be using un-hardened browsers.

I generally make an exception for HTTPS Everywhere and Google Password Alert when I wrote things like this, but I agree that maybe it's worth it to cut them and simplify the guide. https://chrome.google.com/webstore/detail/password-alert/noo... https://chrome.google.com/webstore/detail/https-everywhere/g...

HTTPS Everywhere would be a win (I'd have to think about whether it's enough of one to earn its place on the list, but if you added it, you could also suggest an ad-blocker --- another issue there though is suggesting ad blockers to journalists gets to a tricky place).

GPA is great, but the premise behind this guide is that if you're relying on passwords for Google you're already boned. It's a security win even with TOTP enabled, but I don't think it's enough to earn a spot.

These guidelines are being distributed to activists and journalists along with free U2F keys, for whatever that's worth.

Re: Basic Security Precautions for Non-Profits and Journalists

#35

It would probably behoove someone to sell these laptops, iPads, and iPhones to journalists, lawyers, and other folks with these configurations. It's a lot easier to give them a pre-configured locked down device that they can't mess with than it is to ask them to actually buy a Yubikey. It won't work for everyone - Slate's CMS is notorious for only working in Firefox, for example - but if Pro Publica is going to hire…

That's a smart idea. But these instructions are also being given to immigration lawyers and to Muslim rights activists, both of whom have very limited budgets, so vendor isn't a great place to start.

Re: Basic Security Precautions for Non-Profits and Journalists

#36
post #13

"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.

Is there a documented attack on say, Apple's Magic Keyboard? (if it is true that some (relatively modern) bluetooth keyboards are sniffable and some aren't, I'm sure you can convince them to amend the article with specific models that are believed to be better)

Search for a presentation from Ruxcon 2016, I don't recall the researchers names but they presented attacks on various keyboards including ones with AES support.

Re: Basic Security Precautions for Non-Profits and Journalists

#37
post #36

Earlier quoted context omitted.

Is there a documented attack on say, Apple's Magic Keyboard? (if it is true that some (relatively modern) bluetooth keyboards are sniffable and some aren't, I'm sure you can convince them to amend the article with specific models that are believed to be better)

Search for a presentation from Ruxcon 2016, I don't recall the researchers names but they presented attacks on various keyboards including ones with AES support.

That's a talk about wireless keyboards in general, not Bluetooth. There are attacks on Bluetooth keyboards as well, but they're logistically complicated. See 'dguido's comment for more.

Re: Basic Security Precautions for Non-Profits and Journalists

#38
post #25

Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…

> Use your fingerprint to lock/unlock devices. Fingerprints have a different and weaker legal standard than passwords to protect them > Use an Android phone. It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in. > Take the devices you work on across the US border Any data or passwords you have o…

> You have not been paying attention. Maybe consider accepting the advice of experts?

It would be great to have a few of these issues sourced in the comment (and your comments on the Tor Browser expanded with some reasoning) just so everyone is on the same page. I've seen some exploits with Tor Browser but I thought they'd be mostly sorted out.

I get that Chrome has some more mature sandboxing code, but I must admit I'm not a fan of how it handles a lot of things including download behaviour (http://security.stackexchange.com/q/145808 and https://scarybeastsecurity.blogspot.co.uk/2016/11/0day-poc-r...), Firefox at least does a better job here.

I agree with the advice for border passage, only thing that makes this difficult is the state of upload speeds.

Re: Basic Security Precautions for Non-Profits and Journalists

#39

Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…

> I have not heard of any major security incident recently with Firefox.

https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-a...

https://blog.mozilla.org/security/2015/08/06/firefox-exploit...

Re: Basic Security Precautions for Non-Profits and Journalists

#40
Would be helpful to provide alternative to some of the Don'ts.

How does one transfer information if they can't transfer anything across the border?

Where should one store sensitive information? An encrypted drive you're not supposed to transfer across the border?

I'm not really sure what a person is supposed to do with either of those two recommendations, especially if we're saying that person is not tech-savvy. I think these will just be ignored because they don't seem very viable and require a lot of background knowledge and planning.

Also, why is Chrome preferred to Firefox? I generally assume Chrome is listened to by Google across the board, and it still lacks something like NoScript. Chrome doesn't seem to do block XSS well, either.

Similarly, why Gmail as opposed to, I don't know, something like Protonmail or the like? Safety behind big company, reliability, viability?

Why Chromebook and not just a normal Linux?

The inherent trust in Google in this list confuses me.

And 1password over KeyPass. It seems every cloud-based password manager has been hacked in a round robin fashion, but I guess this solves the other cloud based problem.

Post reply on HN