Great list, I'm glad the crew in the comment threads put it together. 2 observations: * These lists are often made but are never kept up to date as recommendations change. Will this list be any different? * Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my bro…
Basic Security Precautions for Non-Profits and Journalists
51–60 of 182 posts
Re: Basic Security Precautions for Non-Profits and Journalists
#52I'm a bit confused about the don't backup to Google Drive but use Gmail. are you trusting google or not?
Re: Basic Security Precautions for Non-Profits and Journalists
#53Great list, I'm glad the crew in the comment threads put it together. 2 observations: * These lists are often made but are never kept up to date as recommendations change. Will this list be any different? * Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my bro…
Yes: if you are using email at all, you should use Google's email service. Virtually every concern you'll state about using Google Mail is better articulated as a concern about using email at all (especially because 90% of the people lawyers and activists communicate with also use Google Mail).
If you want, instead, to militate against using email at all, I'll agree and also tell you that I expect this guide will get clearer about that.
Re: Basic Security Precautions for Non-Profits and Journalists
#54Re: Basic Security Precautions for Non-Profits and Journalists
#55Earlier quoted context omitted.
> Use your fingerprint to lock/unlock devices. Fingerprints have a different and weaker legal standard than passwords to protect them > Use an Android phone. It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in. > Take the devices you work on across the US border Any data or passwords you have o…
> You have not been paying attention. Maybe consider accepting the advice of experts? It would be great to have a few of these issues sourced in the comment (and your comments on the Tor Browser expanded with some reasoning) just so everyone is on the same page. I've seen some exploits with Tor Browser but I thought they'd be mostly sorted out. I get that Chrome has some more mature sandboxing code, but I must admit…
Re: Basic Security Precautions for Non-Profits and Journalists
#56Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…
It's not just the US border, any border they can request you open up social media accounts or walk away with your laptop or phone and return it later filled with spyware. Business trips from here to China always involve buying a new phone and wiping/selling it on Craigslist after you return assuming it's been compromised.
Re: Basic Security Precautions for Non-Profits and Journalists
#57I'm a bit confused about the don't backup to Google Drive but use Gmail. are you trusting google or not?
But if you store the content of those messages with a cloud provider--regardless of which company--you have killed a lot of security value. The plaintext will sit there, just waiting for someone to go get it, and you'll never know if they do.
Email does not work that way. Even if it is encrypted in transit, it is always stored in plaintext in servers at either end. So, taking that into account, which email service provider has the best security team to defend that plaintext. This guide argues it is Google.
Re: Basic Security Precautions for Non-Profits and Journalists
#58Great list, I'm glad the crew in the comment threads put it together. 2 observations: * These lists are often made but are never kept up to date as recommendations change. Will this list be any different? * Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my bro…
A weakness in the way these guidelines are worded is that it's not clear enough how much security experts discourage people from using email. Email is the single largest risk most at-risk people have, and not just because only 2 email providers have a team capable of securing their infrastructure or because the protocol is weak, but also because of existing collection capabilities and because of its "archive-by-defau…
Re: Basic Security Precautions for Non-Profits and Journalists
#59Re: Basic Security Precautions for Non-Profits and Journalists
#60Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.
The real glaring issue here is that we don't really have good, safe services or devices available to us, especially if you want to stay plugged in (have access to the internet, social media, and necessary tools). Pretty much everything is owned by a corporation or compromised or both.
I'm not really convinced that much is gained by using one browser or phone over another at the end of the day. If someone really wants your information, and you're connected to the world, they'll figure out how to get it.