Earlier quoted context omitted.
I agree it's overly broad statement without justification, but it's not entirely unfounded either. iOS's extreme walled garden does protect you from many things that Android doesn't. As another commenter mentioned, security permissions are a mess, malware is a real thing, and the power and versatility of Android leaves you very vulnerable if you're in a high risk profession who must keep secrets safe.
Very few of the items in here have justifications listed, because that's not productive for the intended audience. They don't want to know "why" any more than most patients want to know "why" their doctor prescribes one antibiotic versus another.
Basic Security Precautions for Non-Profits and Journalists
101–110 of 182 posts
Re: Basic Security Precautions for Non-Profits and Journalists
#102Great list, I'm glad the crew in the comment threads put it together. 2 observations: * These lists are often made but are never kept up to date as recommendations change. Will this list be any different? * Use Gmail? We can't pick some other web based, 2FA capable non-US hosted service that doesn't specifically use machines to scan your content for ad serves? This recommendation was the only one that furrowed my bro…
Given Google's standing policy of requiring a search warrant for access to user confidential data, as detailed in their Transparency Report[0], my reading is that law enforcement needs to go to the same legal effort to access your data-at-rest stored with Google as they would if it were stored offline in your own house. (And results in the same level of notification to you, modulo NSLs, which are a practical worry fo…
Google can change or ignore its policy at any time, without telling you. Depending on your level of risk, you might not want your security to depend on someone else's goodwill, especially someone for who has very many, much larger concerns than you.
Will Google forgo massive government contracts to protect you? Risk expensive lawsuits? What if you are politically unpopular; will Google risk its reputation for you?
Re: Basic Security Precautions for Non-Profits and Journalists
#103Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…
If you can't use your phone number for password recovery or SMS to your phone number as the 2FA, what do you use instead?
* U2F token (primary method)
* TOTP via phone app (backup)
* Backup keys printed or on encrypted USB, in a safe.
* SMS disabled explicitly.
TOTP fallback doesn't reduce security meaningfully, because U2F principally protects against phishing. But SMS fallback is devastating to security.
Re: Basic Security Precautions for Non-Profits and Journalists
#104Earlier quoted context omitted.
My guess is it's because Google's security team is top notch and happy to share their threat intel with their users and that's much more relevant to journalists than using a non-US based service or one that avoids content based ad serving.
Except support is nonexistent, so if anything happens to your gmail access you're screwed there's nobody to contact. I would think any non profit who relies on emails for fundraising/networking would want a paid service like FastMail or other paid service with 2FA
Re: Basic Security Precautions for Non-Profits and Journalists
#105Earlier quoted context omitted.
Border patrol cannot force you to divulge a PIN or password. They can force you to apply your fingerprint. Look elsewhere in this thread for "why not use an Android device." Don't carry your work devices across the US border because they may be taken, can be taken out of your view, and may be duplicated (and yeah, you should have FDE on your computers etc., but don't take the chance).
The US border patrol cannot force you to give up your password. But other countries (including Canada) can. http://news.nationalpost.com/news/canada/guilty-plea-ends-ca...
Re: Basic Security Precautions for Non-Profits and Journalists
#106"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.
Specifically around BT keyboards they say this on one of their slides:
* Sniffing is possible but kind of “unstable”
* All pre-requirements for a successful PIN cracking can only be sniffed during pairing
* Complex documentation
So overall, not awful, but not fabulous either. Luckily most BT keyboards are severely limited in range (~ 30 feet max).
This is all from 2010, but is the latest source(s) I can find.
[0] http://www.remote-exploit.org/articles/keykeriki_v2_0__8211_...
Re: Basic Security Precautions for Non-Profits and Journalists
#107> Use Chrome as your browser This one breaks my heart a little. I mean, I get it, I understand why it's there. But it still breaks my heart.
Agreed. Luckily Sandboxing, which is pretty much the big feature that sells Chrome for Security will get to FF, it will just take a bit longer. Plus with FF going crazy for Rust, I think FF has a bright future security wise.
Re: Basic Security Precautions for Non-Profits and Journalists
#108Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.
Security professionals tend to care about open source over closed source much less than many other factors. Things that seem more important^: - Well known and vetted data structures/algorithms etc - Vulnerability history - Large install base - well regarded, well funded security team vetting the project - capacity and history of fighting expensive legal battles on behalf of its users. Its possible that there are andr…
Correct?
Re: Basic Security Precautions for Non-Profits and Journalists
#109Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…
Second, whoever made this list should include names that endorse it. They must be names of people trusted by various communities: IT security community, journalists (e.g., NY Times), activists (e.g., EFF), etc. Otherwise, it's just another list of very many on the Internet; who knows how reliable it is?
> It's been jarring to realize how many compromises are required to make things workable for groups of non-experts to use.
Third, I am very familiar with this problem, and that assumes you can persuade them that there's sufficient risk to justify the effort. The only solution is for someone to create secure, foolproof, user-friendly and appealing software that is effortless to install and maintain. I know it's easy for me to say "someone", but I don't have the expertise and this project absolutely requires expertise; it can't be yet another hack claiming to be secure.
Fourth, that will create another problem: If that software becomes widely used it will become a very appealing target for extremely well-resourced attackers. I'm not sure of the solution to this problem; can software really be secured effectively against those attackers? Really, we need more than one secure option; or, what if most communication software was fundamentally secure? One step at a time.
Re: Basic Security Precautions for Non-Profits and Journalists
#110Earlier quoted context omitted.
Except support is nonexistent, so if anything happens to your gmail access you're screwed there's nobody to contact. I would think any non profit who relies on emails for fundraising/networking would want a paid service like FastMail or other paid service with 2FA
Only in the alternate timeline where customer support and nerd optics are more important than platform security, which nobody other than Google does better.