Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…
If you can't use your phone number for password recovery or SMS to your phone number as the 2FA, what do you use instead?
Basic Security Precautions for Non-Profits and Journalists
91–100 of 182 posts
Re: Basic Security Precautions for Non-Profits and Journalists
#92Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.
It could be the case that iPhone users are more high value targets. IMHO It's more likely iPhone exploits are just harder to come by. (not impossible, just tougher)
[1] https://arstechnica.com/security/2016/09/1-5-million-bounty-...
Re: Basic Security Precautions for Non-Profits and Journalists
#93Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…
Border patrol cannot force you to divulge a PIN or password. They can force you to apply your fingerprint. Look elsewhere in this thread for "why not use an Android device." Don't carry your work devices across the US border because they may be taken, can be taken out of your view, and may be duplicated (and yeah, you should have FDE on your computers etc., but don't take the chance).
But other countries (including Canada) can.
http://news.nationalpost.com/news/canada/guilty-plea-ends-ca...
Re: Basic Security Precautions for Non-Profits and Journalists
#94In Canada you can be put in prison for 1 year if you don't give up your password at the border.
Re: Basic Security Precautions for Non-Profits and Journalists
#95Re: Basic Security Precautions for Non-Profits and Journalists
#96Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.
Things that seem more important^:
- Well known and vetted data structures/algorithms etc
- Vulnerability history
- Large install base
- well regarded, well funded security team vetting the project
- capacity and history of fighting expensive legal battles on behalf of its users.
Its possible that there are android phones that meet these criteria but there are many that do not. The iphone on the other hand does. So rather than having very specific android phone recommendations its generally easier to just say use iPhone. So much so that most of the security professionals I've talked to view it as the most secure, commonly available computing platform period.
^Not a security professional, but I drink with a couple.
Re: Basic Security Precautions for Non-Profits and Journalists
#97Earlier quoted context omitted.
The comment I just wrote says why, succinctly. It helps if you understand the economics of browser exploit development, and then remind yourself that TBB collapses a whole set of valuable targets down to a single release chain.
Does make sense. Any advice on best way to access the Tor network, if not the Tor Browser?
Re: Basic Security Precautions for Non-Profits and Journalists
#98Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…
If you can't use your phone number for password recovery or SMS to your phone number as the 2FA, what do you use instead?
Re: Basic Security Precautions for Non-Profits and Journalists
#99Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…
Yeah. The only reasonably secure option for Android requires you to own a Nexus device within the window Google pushes security updates regularly. Or you flash it yourself to keep it up to date regularly. And even that is kind of dicey unless its just Google apps + Signal + verifiable OSS.
Re: Basic Security Precautions for Non-Profits and Journalists
#100Earlier quoted context omitted.
(I don't in any way own this document). I acknowledge that the situation with Bluetooth peripherals is complicated† and accept that there are probably a bunch of vendors that are unsafe to use. It might be reasonable to simply require Apple peripherals --- not because they're the best, but because Apple is more accountable to peripherals security than most other vendors are. On the other hand, what we can't reasonabl…
I completely agree with your ranking/preference and your logic here, but I don't think listing a bunch of models nor even listing your ranking is beyond the comprehension or ability of journalists, lawyers, or activists. I think we differ in how much faith we have in the abilities of those groups of people. In my experience, people, especially people with budgets like most mainstream journalists and lawyers, want a l…
IME this greatly overestimates how hard this is for typical end users.
Imagine if you were asked to understand and implement a technical legal function. Maybe you could do it, but it would not be trivial, you'd have to figure out what the heck it meant and what was going on, and then try to implement it. You would need to hope you received good advice, because you have no way of discerning good from bad, and that the instructions were accurate, clear and complete.
At HN we are inside a bubble where these thing are trivial. As another analogy, appendectomies may be trivial for surgeons but incredibly difficult for me.