Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

61–70 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#62
post #37
post #36

Earlier quoted context omitted.

Search for a presentation from Ruxcon 2016, I don't recall the researchers names but they presented attacks on various keyboards including ones with AES support.

That's a talk about wireless keyboards in general, not Bluetooth. There are attacks on Bluetooth keyboards as well, but they're logistically complicated. See 'dguido's comment for more.

Time to call in the Guardian for an expose on Bluetooth keyboard security.

Re: Basic Security Precautions for Non-Profits and Journalists

#63
post #59

Also, why using fingerprint to unlock devices is not recommended?

US law enforcement is allowed to take fingerprints, which can then be used to unlock the device. Somewhere less friendly may just compel you to put your finger on the device

Re: Basic Security Precautions for Non-Profits and Journalists

#65
post #51
post #46

Great list, I'm glad the crew in the comment threads put it together. 2 observations: * These lists are often made but are never kept up to date as recommendations change. Will this list be any different? * Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my bro…

My guess is it's because Google's security team is top notch and happy to share their threat intel with their users and that's much more relevant to journalists than using a non-US based service or one that avoids content based ad serving.

Except support is nonexistent, so if anything happens to your gmail access you're screwed there's nobody to contact. I would think any non profit who relies on emails for fundraising/networking would want a paid service like FastMail or other paid service with 2FA

Re: Basic Security Precautions for Non-Profits and Journalists

#66

It would probably behoove someone to sell these laptops, iPads, and iPhones to journalists, lawyers, and other folks with these configurations. It's a lot easier to give them a pre-configured locked down device that they can't mess with than it is to ask them to actually buy a Yubikey. It won't work for everyone - Slate's CMS is notorious for only working in Firefox, for example - but if Pro Publica is going to hire…

Wouldn't this provide a great targt for spies and security services? I mean, maybe I'm being stupid here, but if I was in charge of the NSA and knew that people with sensitive information were buying this gear from a certain vendor, said vendor would be right at the top of the target list.

I don't think I'd be able to trust any individual or company selling 'secure devices' for journalists and activists.

Re: Basic Security Precautions for Non-Profits and Journalists

#67

Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…

thegrugq recently had a post about travel kits https://twitter.com/thegrugq/status/829855684636274688 It's not just the US border, any border they can request you open up social media accounts or walk away with your laptop or phone and return it later filled with spyware. Business trips from here to China always involve buying a new phone and wiping/selling it on Craigslist after you return assuming it's been comprom…

Seems like a travel guide could be useful for journalists, I'd imagine most people don't even think about something like a travel kit.

Re: Basic Security Precautions for Non-Profits and Journalists

#68

Would be helpful to provide alternative to some of the Don'ts. How does one transfer information if they can't transfer anything across the border? Where should one store sensitive information? An encrypted drive you're not supposed to transfer across the border? I'm not really sure what a person is supposed to do with either of those two recommendations, especially if we're saying that person is not tech-savvy. I th…

I also have my doubts about 1Password – although I am still a 1Password users, at least of the old approach (pay once, cloud sync but no web-accessible storage with 1Password). I guess I will have to look for an alternative sooner or later! :(

Re: Basic Security Precautions for Non-Profits and Journalists

#69
> If you are going to use email, use Gmail, with a physical security key on your laptop and Google Authenticator on your phone.

I understand Google runs a tight ship security-wise, but what about the unintentional information leakage that occurs because they read all your mail to serve you ads?

Re: Basic Security Precautions for Non-Profits and Journalists

#70

Would be helpful to provide alternative to some of the Don'ts. How does one transfer information if they can't transfer anything across the border? Where should one store sensitive information? An encrypted drive you're not supposed to transfer across the border? I'm not really sure what a person is supposed to do with either of those two recommendations, especially if we're saying that person is not tech-savvy. I th…

1. To transfer information across the border, create an encrypted volume, store it on a cloud provider, and download it when you return. Unfortunately, it's more complicated to do this than it should be, so people hoping to do it need individualized instruction. Also, particularly for refugees, there are legal implications to doing this. Ultimately, the simplest recommendation is: don't bring information across the border at all. Go without.

2. Because Chrome is significantly more secure than Firefox. See: rest of thread.

3. Because no email provider is truly safe, and Google's mail service is better defended than virtually any other mail provider. Things like Protonmail are security gimmicks. If you're concerned enough about messaging safety to use some idiosyncratic email provider, you're concerned enough to stop using email for secrets altogether: use Signal, WhatsApp, or Wire.

4. Because a Chromebook is safer for a typical user than Linux, and also because there's a (remote) chance that people might actually use a Chromebook. The security challenges of 2017 are not an opportunity to finally achieve Linux On The Desktop.

5. The list's most contentious recommendation is a rebuke to Google.

6. Standalone 1Password isn't a cloud-based password manager. People should avoid cloud-based password managers.

Post reply on HN