Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

131–140 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#131
post #118

Earlier quoted context omitted.

What about a custom ROM (fork) of Android, sans Google apps? Not an option for typical end-users, of course.

Disabling Verified Boot and not having Google Play Services would dramatically reduce the security posture of an Android device. Disclaimer: I work at Google.

> not having Google Play Services would dramatically reduce the security posture of an Android device.

I understand Verified Boot, but how would removing Google Play Services damage security? It would seem to reduce the attack surface.

Re: Basic Security Precautions for Non-Profits and Journalists

#132
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

First, thank you so much for putting together this list (you say "we", so I assume you are part of it); a great first step. What was your role? Do you endorse this list now and going forward? Second, whoever made this list should include names that endorse it. They must be names of people trusted by various communities: IT security community, journalists (e.g., NY Times), activists (e.g., EFF), etc. Otherwise, it's j…

> whoever made this list should include names that endorse it.

Clarifying to my own comment: I trust that it is authoritative, but people who don't read HN need to trust it.

Also, my whole comment is very much IMH - non-authoritative, - O.

Re: Basic Security Precautions for Non-Profits and Journalists

#133
post #32
post #25

Earlier quoted context omitted.

> Use your fingerprint to lock/unlock devices. Fingerprints have a different and weaker legal standard than passwords to protect them > Use an Android phone. It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in. > Take the devices you work on across the US border Any data or passwords you have o…

Adding: the Tor Browser might be the least safe browser to use of all available browsers that can be installed on modern computers. It is a perfect storm of "inferior security design" and "maximized adversarial value per exploit dollar spent". Don't use Tor Browser.

And what about TAILS? It has a separated/modified Tor Browser. If I frequent a certain site and LE knows that I know I can be exploited, but what if I'm an activist who puts the TAILS USB in his notebook, boot from it, then publish an article on medium.com with a freshly created account. Will LE be able to exploit me?

Re: Basic Security Precautions for Non-Profits and Journalists

#134
post #34
post #30

Earlier quoted context omitted.

I generally make an exception for HTTPS Everywhere and Google Password Alert when I wrote things like this, but I agree that maybe it's worth it to cut them and simplify the guide. https://chrome.google.com/webstore/detail/password-alert/noo... https://chrome.google.com/webstore/detail/https-everywhere/g...

HTTPS Everywhere would be a win (I'd have to think about whether it's enough of one to earn its place on the list, but if you added it, you could also suggest an ad-blocker --- another issue there though is suggesting ad blockers to journalists gets to a tricky place). GPA is great, but the premise behind this guide is that if you're relying on passwords for Google you're already boned. It's a security win even with…

> HTTPS Everywhere would be a win

IME, it breaks too many sites to give to all end-users; if the default configuration omitted sites listed as 'Partial'; maybe it would be passable. Maybe have a subcategory for intermediate users and put it there. Novice-level users (for lack of a better term) have no idea why the website is not working, and thus don't even know to consider disabling HTTPS Everywhere.

Also, it makes the user easier to identify.

Re: Basic Security Precautions for Non-Profits and Journalists

#135
post #66

It would probably behoove someone to sell these laptops, iPads, and iPhones to journalists, lawyers, and other folks with these configurations. It's a lot easier to give them a pre-configured locked down device that they can't mess with than it is to ask them to actually buy a Yubikey. It won't work for everyone - Slate's CMS is notorious for only working in Firefox, for example - but if Pro Publica is going to hire…

Wouldn't this provide a great targt for spies and security services? I mean, maybe I'm being stupid here, but if I was in charge of the NSA and knew that people with sensitive information were buying this gear from a certain vendor, said vendor would be right at the top of the target list. I don't think I'd be able to trust any individual or company selling 'secure devices' for journalists and activists.

[deleted]

Re: Basic Security Precautions for Non-Profits and Journalists

#138

Questions and suggestions: 1. For "Do as much of your work as possible on an iPhone or iPad." -- as opposed to what? Android and Windows? Would listing device options be a possibility? 2. Possibly: add a set of suggestions for transporting device(s) across borders or acquiring them. I suspect mail or package delivery might be an option -- or if it's not, then clarifying the risks would be of interest. 3. Operating sy…

1. As opposed to a laptop.

2. Any concrete advice about crossing borders is hard to give right now. The goal in this document is just to alert people that it is not OK to travel with your work device.

3. For the audience here (think someone providing legal aid at an airport) this is too technical.

4,5,6 Great idea, thank you!

7. It's funny but the XKCD really seems to be the best thing to link.

Re: Basic Security Precautions for Non-Profits and Journalists

#139
post #118

Earlier quoted context omitted.

Disabling Verified Boot and not having Google Play Services would dramatically reduce the security posture of an Android device. Disclaimer: I work at Google.

> not having Google Play Services would dramatically reduce the security posture of an Android device. I understand Verified Boot, but how would removing Google Play Services damage security? It would seem to reduce the attack surface.

For one, without Google Play Services you have no Play Store. Unless you're going to prevent users from installing apps entirely, there isn't really another safe way to obtain apps. Additionally Verify Apps, SafetyNet, Safe Browsing, etc. are all part of Google Play Services. You _really_ want Verify Apps.
Post reply on HN