Earlier quoted context omitted.
Very few of the items in here have justifications listed, because that's not productive for the intended audience. They don't want to know "why" any more than most patients want to know "why" their doctor prescribes one antibiotic versus another.
Even if your intended audience doesn't care about the why, you must necessarily provide justification so that another audience, which would want to make sure that you're not selling snake oil, could verify your why. Knowledge sharing only really works when there's a vetting process on some level.
Basic Security Precautions for Non-Profits and Journalists
71–80 of 182 posts
Re: Basic Security Precautions for Non-Profits and Journalists
#72Earlier quoted context omitted.
I'd second adding recommendations for specific models. There are a lot of BT keyboards on the market of varying quality.
(I don't in any way own this document). I acknowledge that the situation with Bluetooth peripherals is complicated† and accept that there are probably a bunch of vendors that are unsafe to use. It might be reasonable to simply require Apple peripherals --- not because they're the best, but because Apple is more accountable to peripherals security than most other vendors are. On the other hand, what we can't reasonabl…
In my experience, people, especially people with budgets like most mainstream journalists and lawyers, want a list of specific things, best of all SKUs, they can buy that will give them the most security.
Re: Basic Security Precautions for Non-Profits and Journalists
#73Earlier quoted context omitted.
Why exactly?
The comment I just wrote says why, succinctly. It helps if you understand the economics of browser exploit development, and then remind yourself that TBB collapses a whole set of valuable targets down to a single release chain.
Re: Basic Security Precautions for Non-Profits and Journalists
#74Earlier quoted context omitted.
(I don't in any way own this document). I acknowledge that the situation with Bluetooth peripherals is complicated† and accept that there are probably a bunch of vendors that are unsafe to use. It might be reasonable to simply require Apple peripherals --- not because they're the best, but because Apple is more accountable to peripherals security than most other vendors are. On the other hand, what we can't reasonabl…
I completely agree with your ranking/preference and your logic here, but I don't think listing a bunch of models nor even listing your ranking is beyond the comprehension or ability of journalists, lawyers, or activists. I think we differ in how much faith we have in the abilities of those groups of people. In my experience, people, especially people with budgets like most mainstream journalists and lawyers, want a l…
Re: Basic Security Precautions for Non-Profits and Journalists
#75Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…
Re: Basic Security Precautions for Non-Profits and Journalists
#76Earlier quoted context omitted.
Even if your intended audience doesn't care about the why, you must necessarily provide justification so that another audience, which would want to make sure that you're not selling snake oil, could verify your why. Knowledge sharing only really works when there's a vetting process on some level.
No, that's not how it works. The guide itself doesn't need to be bulletproofed against zany accusations that the authors are selling snake oil; there are other ways to accomplish that without crudding the recommendations themselves up with verbiage to placate angry nerds.
I didn't say the authors are selling snake oil. But if a person doesn't know much about a subject, they may not be able to tell, and they should be suspicious. They might want to see a review or criticism of it. They might want to verify that it's well intentioned, especially on a sensitive subject such as this. There's nothing zany about that, it's common sense.
If I find some information source that presents itself as an arbiter of truth, but has no justification for its points, I cannot in good faith recommend it to anyone.
The only angry one here seems to be you, with many unnecessarily rude responses that do not at all inspire confidence.
Re: Basic Security Precautions for Non-Profits and Journalists
#77Also, why using fingerprint to unlock devices is not recommended?
US law enforcement is allowed to take fingerprints, which can then be used to unlock the device. Somewhere less friendly may just compel you to put your finger on the device
Re: Basic Security Precautions for Non-Profits and Journalists
#78I'm a bit confused about the don't backup to Google Drive but use Gmail. are you trusting google or not?
Re: Basic Security Precautions for Non-Profits and Journalists
#79Great list, I'm glad the crew in the comment threads put it together. 2 observations: * These lists are often made but are never kept up to date as recommendations change. Will this list be any different? * Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my bro…
[0]: https://www.google.com/transparencyreport/userdatarequests/l...
Re: Basic Security Precautions for Non-Profits and Journalists
#80Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.
Android is so bad that iPhone is probably better, despite all those issues. The real glaring issue here is that we don't really have good, safe services or devices available to us, especially if you want to stay plugged in (have access to the internet, social media, and necessary tools). Pretty much everything is owned by a corporation or compromised or both. I'm not really convinced that much is gained by using one…
Maybe there is a better security guide for a bit more technical people? With why's and how's, explaining what are the real issues and causes of some practice being bad, and what are the possible solutions to it. Why is Android bad? Is it solved by stripping out google services? How do you do it properly? Is it solved by replacing an Android phone with iPhone? Etc. Without any of "jumping into the snake-pit is so bad, that jumping straight into the fire is probably better". Probably better, huh.