Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

101–110 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#101
post #12
post #5

Earlier quoted context omitted.

I agree it's overly broad statement without justification, but it's not entirely unfounded either. iOS's extreme walled garden does protect you from many things that Android doesn't. As another commenter mentioned, security permissions are a mess, malware is a real thing, and the power and versatility of Android leaves you very vulnerable if you're in a high risk profession who must keep secrets safe.

Very few of the items in here have justifications listed, because that's not productive for the intended audience. They don't want to know "why" any more than most patients want to know "why" their doctor prescribes one antibiotic versus another.

I agree with you completely, I chose the wording I did to not further anger the Android faithful.

Re: Basic Security Precautions for Non-Profits and Journalists

#102
post #79
post #46

Great list, I'm glad the crew in the comment threads put it together. 2 observations: * These lists are often made but are never kept up to date as recommendations change. Will this list be any different? * Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my bro…

Given Google's standing policy of requiring a search warrant for access to user confidential data, as detailed in their Transparency Report[0], my reading is that law enforcement needs to go to the same legal effort to access your data-at-rest stored with Google as they would if it were stored offline in your own house. (And results in the same level of notification to you, modulo NSLs, which are a practical worry fo…

> Google's standing policy

Google can change or ignore its policy at any time, without telling you. Depending on your level of risk, you might not want your security to depend on someone else's goodwill, especially someone for who has very many, much larger concerns than you.

Will Google forgo massive government contracts to protect you? Risk expensive lawsuits? What if you are politically unpopular; will Google risk its reputation for you?

Re: Basic Security Precautions for Non-Profits and Journalists

#103
post #89
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

If you can't use your phone number for password recovery or SMS to your phone number as the 2FA, what do you use instead?

The best-practices 2FA stack is:

* U2F token (primary method)

* TOTP via phone app (backup)

* Backup keys printed or on encrypted USB, in a safe.

* SMS disabled explicitly.

TOTP fallback doesn't reduce security meaningfully, because U2F principally protects against phishing. But SMS fallback is devastating to security.

Re: Basic Security Precautions for Non-Profits and Journalists

#104
post #51

Earlier quoted context omitted.

My guess is it's because Google's security team is top notch and happy to share their threat intel with their users and that's much more relevant to journalists than using a non-US based service or one that avoids content based ad serving.

Except support is nonexistent, so if anything happens to your gmail access you're screwed there's nobody to contact. I would think any non profit who relies on emails for fundraising/networking would want a paid service like FastMail or other paid service with 2FA

Only in the alternate timeline where customer support and nerd optics are more important than platform security, which nobody other than Google does better.

Re: Basic Security Precautions for Non-Profits and Journalists

#105
post #93
post #9

Earlier quoted context omitted.

Border patrol cannot force you to divulge a PIN or password. They can force you to apply your fingerprint. Look elsewhere in this thread for "why not use an Android device." Don't carry your work devices across the US border because they may be taken, can be taken out of your view, and may be duplicated (and yeah, you should have FDE on your computers etc., but don't take the chance).

The US border patrol cannot force you to give up your password. But other countries (including Canada) can. http://news.nationalpost.com/news/canada/guilty-plea-ends-ca...

They might not be able to force that on US citizens, who have an absolute right both to habeas and to enter the country. They can force it on nonresident aliens.

Re: Basic Security Precautions for Non-Profits and Journalists

#106
post #13

"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.

Here[0] is a link to a talk about wireless keyboard sniffing, including BT keyboards and their hardware/software solution for sniffing.

Specifically around BT keyboards they say this on one of their slides:

* Sniffing is possible but kind of “unstable”

* All pre-requirements for a successful PIN cracking can only be sniffed during pairing

* Complex documentation

So overall, not awful, but not fabulous either. Luckily most BT keyboards are severely limited in range (~ 30 feet max).

This is all from 2010, but is the latest source(s) I can find.

[0] http://www.remote-exploit.org/articles/keykeriki_v2_0__8211_...

Re: Basic Security Precautions for Non-Profits and Journalists

#107
post #88

> Use Chrome as your browser This one breaks my heart a little. I mean, I get it, I understand why it's there. But it still breaks my heart.

Agreed. Luckily Sandboxing, which is pretty much the big feature that sells Chrome for Security will get to FF, it will just take a bit longer. Plus with FF going crazy for Rust, I think FF has a bright future security wise.

An all-Rust browser would make a big difference. Sandboxing is good, but won't close the gap with Chromium, which just invests too much money into software security to lose much ground to other browsers.

Re: Basic Security Precautions for Non-Profits and Journalists

#108
post #54

Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.

Security professionals tend to care about open source over closed source much less than many other factors. Things that seem more important^: - Well known and vetted data structures/algorithms etc - Vulnerability history - Large install base - well regarded, well funded security team vetting the project - capacity and history of fighting expensive legal battles on behalf of its users. Its possible that there are andr…

I see. I think there might be some distinction in regards of what different people view as "secure". Say, your phone produced by my company may be completely transparent to me and completely impenetrable to, say, tptacek. As I understand, in that narrative it is considered secure as you (the user) are supposed to trust me (the manufacturer). That's why iPhone is considered secure in comparison to Android, which is similarly backdoored, but in addition more penetrable to tptacek (the 3rd party).

Correct?

Re: Basic Security Precautions for Non-Profits and Journalists

#109
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

First, thank you so much for putting together this list (you say "we", so I assume you are part of it); a great first step. What was your role? Do you endorse this list now and going forward?

Second, whoever made this list should include names that endorse it. They must be names of people trusted by various communities: IT security community, journalists (e.g., NY Times), activists (e.g., EFF), etc. Otherwise, it's just another list of very many on the Internet; who knows how reliable it is?

> It's been jarring to realize how many compromises are required to make things workable for groups of non-experts to use.

Third, I am very familiar with this problem, and that assumes you can persuade them that there's sufficient risk to justify the effort. The only solution is for someone to create secure, foolproof, user-friendly and appealing software that is effortless to install and maintain. I know it's easy for me to say "someone", but I don't have the expertise and this project absolutely requires expertise; it can't be yet another hack claiming to be secure.

Fourth, that will create another problem: If that software becomes widely used it will become a very appealing target for extremely well-resourced attackers. I'm not sure of the solution to this problem; can software really be secured effectively against those attackers? Really, we need more than one secure option; or, what if most communication software was fundamentally secure? One step at a time.

Re: Basic Security Precautions for Non-Profits and Journalists

#110

Earlier quoted context omitted.

Except support is nonexistent, so if anything happens to your gmail access you're screwed there's nobody to contact. I would think any non profit who relies on emails for fundraising/networking would want a paid service like FastMail or other paid service with 2FA

Only in the alternate timeline where customer support and nerd optics are more important than platform security, which nobody other than Google does better.

Until you get locked out of your account of course, for a number of reasons such as heavy use that triggers an arbitrary lockout and there's nobody to contact. Somebody might also wish to purposely DoS your account with incorrect logins for a number of reasons too, like hiding a money transfer notification or just to screw with you.
Post reply on HN