Basic Security Precautions for Non-Profits and Journalists
41–50 of 182 posts
Re: Basic Security Precautions for Non-Profits and Journalists
#42Earlier quoted context omitted.
> Use your fingerprint to lock/unlock devices. Fingerprints have a different and weaker legal standard than passwords to protect them > Use an Android phone. It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in. > Take the devices you work on across the US border Any data or passwords you have o…
Adding: the Tor Browser might be the least safe browser to use of all available browsers that can be installed on modern computers. It is a perfect storm of "inferior security design" and "maximized adversarial value per exploit dollar spent". Don't use Tor Browser.
Re: Basic Security Precautions for Non-Profits and Journalists
#43Just a bit of feedback: might be nice to repeat the "Don't" in front of each sentence, even if it's grouped under the heading and therefore repetitive: I found myself being like "wait, it's telling me to backup my messages to google drive? Are they client-side encrypted?"
Re: Basic Security Precautions for Non-Profits and Journalists
#44For example in the Don't section it says "[Don't] Store sensitive information in cloud services like Evernote or Dropbox." Ok, but where is the corresponding entry in the "Do" section, which tells folks how to store sensitive information? Especially in a way that permits more than one person to access and use the information, which is key to how both journalists and activists work?
There might not be a "good" answer. But recognizing that people have to work, there is probably a sense of "better" or "best for now". Maybe that's the format:
Don't | Better
Don't use your fingerprint | Use a long passphrase
to lock/unlock devices | to lock your devices.
EDIT: This guide is very helpful and kudos to the folks to made it. I offer my thoughts solely in the spirit of "maybe this feedback will be helpful." My intention is not to sit on the sidelines throwing rocks at people who are actually doing things.Re: Basic Security Precautions for Non-Profits and Journalists
#45are you trusting google or not?
Re: Basic Security Precautions for Non-Profits and Journalists
#46* These lists are often made but are never kept up to date as recommendations change. Will this list be any different?
* Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my brow.
Re: Basic Security Precautions for Non-Profits and Journalists
#471. For "Do as much of your work as possible on an iPhone or iPad." -- as opposed to what? Android and Windows? Would listing device options be a possibility?
2. Possibly: add a set of suggestions for transporting device(s) across borders or acquiring them. I suspect mail or package delivery might be an option -- or if it's not, then clarifying the risks would be of interest.
3. Operating systems: A list of most to least secure might also be handy. E.g., WinCE, Windows, MacOS, iOS, Linux, TAILS, etc. Some indication of where "good enough" starts to apply.
4. Out-of-scope for document to include a full set of terms and definitions, but a glossary with links to additional reading might be of interest.
5. Providing "why" links might also be useful. E.g., Fingerprints (can be forced to divulge, fewer legal protections than passwords).
6. Formatting: A bulleted list would be slightly easier to read. A numbered list can be specifically referenced (e.g., "'Don't' #4 ...").
7. Define terms. E.g., "Long password" "At least 20 characters, 200 if possible", say. Tips on passphrase generation (e.g., xkcd passphrases, "correct battery horse staple".
Finally: thank you for setting this up.
Re: Basic Security Precautions for Non-Profits and Journalists
#48Earlier quoted context omitted.
Adding: the Tor Browser might be the least safe browser to use of all available browsers that can be installed on modern computers. It is a perfect storm of "inferior security design" and "maximized adversarial value per exploit dollar spent". Don't use Tor Browser.
Why exactly?
Re: Basic Security Precautions for Non-Profits and Journalists
#49Earlier quoted context omitted.
I agree it's overly broad statement without justification, but it's not entirely unfounded either. iOS's extreme walled garden does protect you from many things that Android doesn't. As another commenter mentioned, security permissions are a mess, malware is a real thing, and the power and versatility of Android leaves you very vulnerable if you're in a high risk profession who must keep secrets safe.
Very few of the items in here have justifications listed, because that's not productive for the intended audience. They don't want to know "why" any more than most patients want to know "why" their doctor prescribes one antibiotic versus another.
Re: Basic Security Precautions for Non-Profits and Journalists
#50I pretty much follow most of these guidelines already, however I do use the Firefox browser and I wasn't aware it was so inseucre compared to Chrome. Is there a nice guide on hardening Firefox security or am I out of luck because of the sandbox situation?
Or try Firejail https://firejail.wordpress.com/ (Linux) or possibly Sandboxie on Windows https://www.sandboxie.com/