Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

91–100 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#91
post #89
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

If you can't use your phone number for password recovery or SMS to your phone number as the 2FA, what do you use instead?

Presumably a security key. A Yubikey or something like it.

Re: Basic Security Precautions for Non-Profits and Journalists

#92
post #54

Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.

One thing to think about is the cost of exploits. [1]

It could be the case that iPhone users are more high value targets. IMHO It's more likely iPhone exploits are just harder to come by. (not impossible, just tougher)

[1] https://arstechnica.com/security/2016/09/1-5-million-bounty-...

Re: Basic Security Precautions for Non-Profits and Journalists

#93
post #9

Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…

Border patrol cannot force you to divulge a PIN or password. They can force you to apply your fingerprint. Look elsewhere in this thread for "why not use an Android device." Don't carry your work devices across the US border because they may be taken, can be taken out of your view, and may be duplicated (and yeah, you should have FDE on your computers etc., but don't take the chance).

The US border patrol cannot force you to give up your password.

But other countries (including Canada) can.

http://news.nationalpost.com/news/canada/guilty-plea-ends-ca...

Re: Basic Security Precautions for Non-Profits and Journalists

#96
post #54

Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.

Security professionals tend to care about open source over closed source much less than many other factors.

Things that seem more important^:

- Well known and vetted data structures/algorithms etc

- Vulnerability history

- Large install base

- well regarded, well funded security team vetting the project

- capacity and history of fighting expensive legal battles on behalf of its users.

Its possible that there are android phones that meet these criteria but there are many that do not. The iphone on the other hand does. So rather than having very specific android phone recommendations its generally easier to just say use iPhone. So much so that most of the security professionals I've talked to view it as the most secure, commonly available computing platform period.

^Not a security professional, but I drink with a couple.

Re: Basic Security Precautions for Non-Profits and Journalists

#97
post #48

Earlier quoted context omitted.

The comment I just wrote says why, succinctly. It helps if you understand the economics of browser exploit development, and then remind yourself that TBB collapses a whole set of valuable targets down to a single release chain.

Does make sense. Any advice on best way to access the Tor network, if not the Tor Browser?

The TOR network is a network: you can access it using any web browser and the TOR client + a local web proxy. Use Chrome and configure it to use the local web proxy, now you're accessing TOR using Chrome.

Re: Basic Security Precautions for Non-Profits and Journalists

#98
post #89
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

If you can't use your phone number for password recovery or SMS to your phone number as the 2FA, what do you use instead?

[deleted]

Re: Basic Security Precautions for Non-Profits and Journalists

#99
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

Yeah. The only reasonably secure option for Android requires you to own a Nexus device within the window Google pushes security updates regularly. Or you flash it yourself to keep it up to date regularly. And even that is kind of dicey unless its just Google apps + Signal + verifiable OSS.

What about a custom ROM (fork) of Android, sans Google apps? Not an option for typical end-users, of course.

Re: Basic Security Precautions for Non-Profits and Journalists

#100
post #72
post #26

Earlier quoted context omitted.

(I don't in any way own this document). I acknowledge that the situation with Bluetooth peripherals is complicated† and accept that there are probably a bunch of vendors that are unsafe to use. It might be reasonable to simply require Apple peripherals --- not because they're the best, but because Apple is more accountable to peripherals security than most other vendors are. On the other hand, what we can't reasonabl…

I completely agree with your ranking/preference and your logic here, but I don't think listing a bunch of models nor even listing your ranking is beyond the comprehension or ability of journalists, lawyers, or activists. I think we differ in how much faith we have in the abilities of those groups of people. In my experience, people, especially people with budgets like most mainstream journalists and lawyers, want a l…

> I don't think listing a bunch of models nor even listing your ranking is beyond the comprehension or ability of journalists, lawyers, or activists.

IME this greatly overestimates how hard this is for typical end users.

Imagine if you were asked to understand and implement a technical legal function. Maybe you could do it, but it would not be trivial, you'd have to figure out what the heck it meant and what was going on, and then try to implement it. You would need to hope you received good advice, because you have no way of discerning good from bad, and that the instructions were accurate, clear and complete.

At HN we are inside a bubble where these thing are trivial. As another analogy, appendectomies may be trivial for surgeons but incredibly difficult for me.

Post reply on HN