Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

81–90 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#81
post #77

Earlier quoted context omitted.

US law enforcement is allowed to take fingerprints, which can then be used to unlock the device. Somewhere less friendly may just compel you to put your finger on the device

Is it that different from making you enter your password? I don't see any real issue here if it's the only problem.

Your password is, in a weird US Constitutional sense, speech, and your 5th Amendment right not to be forced to self-incriminate protects you. Your fingerprint is not speech, and not protected in the same fashion.

(Once more for the folks in the back: fingerprints are usernames. Passwords are things you can rotate.)

Re: Basic Security Precautions for Non-Profits and Journalists

#82
post #53
post #46

Great list, I'm glad the crew in the comment threads put it together. 2 observations: * These lists are often made but are never kept up to date as recommendations change. Will this list be any different? * Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my bro…

A weakness in the way these guidelines are worded is that it's not clear enough how much security experts discourage people from using email. Email is the single largest risk most at-risk people have, and not just because only 2 email providers have a team capable of securing their infrastructure or because the protocol is weak, but also because of existing collection capabilities and because of its "archive-by-defau…

Why g-mail instead of a more security focused provider like proton-mail? It seems to me like the only downside of proton-mail is that it is less well-known, but I'd compare it to signal vs whatsapp. And you can get journalists to use signal.

Only other thing I can think of is google being more secure by virtue of being bigger.

Re: Basic Security Precautions for Non-Profits and Journalists

#83
post #81
post #77

Earlier quoted context omitted.

Is it that different from making you enter your password? I don't see any real issue here if it's the only problem.

Your password is, in a weird US Constitutional sense, speech, and your 5th Amendment right not to be forced to self-incriminate protects you. Your fingerprint is not speech, and not protected in the same fashion. (Once more for the folks in the back: fingerprints are usernames. Passwords are things you can rotate.)

I see. Thanks. The first one seems relevant only for people in the USA, but inability to change fingerprints is something, I guess.

Re: Basic Security Precautions for Non-Profits and Journalists

#84
post #82
post #53

Earlier quoted context omitted.

A weakness in the way these guidelines are worded is that it's not clear enough how much security experts discourage people from using email. Email is the single largest risk most at-risk people have, and not just because only 2 email providers have a team capable of securing their infrastructure or because the protocol is weak, but also because of existing collection capabilities and because of its "archive-by-defau…

Why g-mail instead of a more security focused provider like proton-mail? It seems to me like the only downside of proton-mail is that it is less well-known, but I'd compare it to signal vs whatsapp. And you can get journalists to use signal. Only other thing I can think of is google being more secure by virtue of being bigger.

It is, in fact, more secure because is bigger. But that's not the only reason. See also: rest of thread.

Re: Basic Security Precautions for Non-Profits and Journalists

#85
post #71

Earlier quoted context omitted.

No, that's not how it works. The guide itself doesn't need to be bulletproofed against zany accusations that the authors are selling snake oil; there are other ways to accomplish that without crudding the recommendations themselves up with verbiage to placate angry nerds.

I didn't say anything about bulletproofed, just explained. Right now, there's no explanation, and I'm asking for some justification, how are you getting "bulletproofing" from that? I didn't say the authors are selling snake oil. But if a person doesn't know much about a subject, they may not be able to tell, and they should be suspicious. They might want to see a review or criticism of it. They might want to verify t…

Again: the audience for these instructions isn't asking for explanations or justifications. If you have a concern with any of these instructions, write a comment detailing it, and someone will respond.

Re: Basic Security Precautions for Non-Profits and Journalists

#86
It's sort of sad and wonderful that the best we can do is an iPad when it comes to secure computing. It's awesome that something you can buy most anywhere for < $500 USD is pretty secure. It's also sad that it's the best we can do, and there is only 1 manufacturer of such a device. We desperately need better privacy and security, both from a legal and a technical point of view.

Re: Basic Security Precautions for Non-Profits and Journalists

#87
post #83
post #81

Earlier quoted context omitted.

Your password is, in a weird US Constitutional sense, speech, and your 5th Amendment right not to be forced to self-incriminate protects you. Your fingerprint is not speech, and not protected in the same fashion. (Once more for the folks in the back: fingerprints are usernames. Passwords are things you can rotate.)

I see. Thanks. The first one seems relevant only for people in the USA, but inability to change fingerprints is something, I guess.

Most other countries probably feel similarly, or they don't have anything like the 5th amendment. In places without something like the 5th amendment, you can choose to lie about your password, do it enough times, the device will reset and erase everything(assuming you set that up). One can not lie about their fingerprints.

Of course in places without something like the 5th, and you lie a few times, your death may find you quite quickly, there is at the very least an option... With a fingerprint, no options. Have a picture of your finger and game over.

Re: Basic Security Precautions for Non-Profits and Journalists

#88

> Use Chrome as your browser This one breaks my heart a little. I mean, I get it, I understand why it's there. But it still breaks my heart.

Agreed. Luckily Sandboxing, which is pretty much the big feature that sells Chrome for Security will get to FF, it will just take a bit longer. Plus with FF going crazy for Rust, I think FF has a bright future security wise.

Re: Basic Security Precautions for Non-Profits and Journalists

#89
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

If you can't use your phone number for password recovery or SMS to your phone number as the 2FA, what do you use instead?

Re: Basic Security Precautions for Non-Profits and Journalists

#90

> If you are going to use email, use Gmail, with a physical security key on your laptop and Google Authenticator on your phone. I understand Google runs a tight ship security-wise, but what about the unintentional information leakage that occurs because they read all your mail to serve you ads?

If you're using email to communicate with humans, you are using Gmail since your counterparty is almost always using Gmail. Gmail and their ad scanning is unavoidable in practice when using email so your only real recourse is to use a different communication protocol.

Gmail is reasonably secure in situations that actually occur frequently. No other providers are. But even Gmail is optimized for adoption and monitization over security, so it's security efforts only go so far, particularly when interacting with other email providers.

Post reply on HN