Be aware, that on Google's Android every app in the background has access to the clipboard. And Google refuses to fix that. It is fixed in CopperheadOS afaik.
Basic Security Precautions for Non-Profits and Journalists
141–150 of 182 posts
Re: Basic Security Precautions for Non-Profits and Journalists
#142The contrast with Snowdens recommendations is quite stark: https://theintercept.com/2015/11/12/edward-snowden-explains-...
Re: Basic Security Precautions for Non-Profits and Journalists
#143Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…
There's a reason that pwn2own (the hacking competition) has much higher bounties for finding Chrome vulnerabilities than finding Firefox vulnerabilities - http://blog.trendmicro.com/pwn2own-returns-for-2017-to-celeb...
Re: Basic Security Precautions for Non-Profits and Journalists
#144Earlier quoted context omitted.
> I have not heard of any major security incident recently with Firefox. https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-a... https://blog.mozilla.org/security/2015/08/06/firefox-exploit...
What can I subscribe to, to hear about news like that in a more systematic fashion? I mean, monitoring all CVEs might be a little to much for somebody who isn't full time security professional, but there surely must be some reasonable compromise between that and position like "this browser is secure because tptacek said so". I don't mean anything against tptacek personally, but without any substantial grounding this…
Re: Basic Security Precautions for Non-Profits and Journalists
#145Earlier quoted context omitted.
My guess is it's because Google's security team is top notch and happy to share their threat intel with their users and that's much more relevant to journalists than using a non-US based service or one that avoids content based ad serving.
Except support is nonexistent, so if anything happens to your gmail access you're screwed there's nobody to contact. I would think any non profit who relies on emails for fundraising/networking would want a paid service like FastMail or other paid service with 2FA
Re: Basic Security Precautions for Non-Profits and Journalists
#146We build a tool specifically to help non-profits and journalists learn about and manage their digital and physical security on the move. It's called Umbrella App. It's free, open source, on Android and contains tons of lessons on privacy related issues like digital and physical security. Umbrella has everything from how to do basic stuff like communicate with basic tools like Signal to sending a secure email with PGP. However, the unique bit is we also have stuff on the physical side, like how to plan travel, cross borders, set-up a secure physical meeting, deal with detecting surveillance, covering a protest, respond to a kidnapping etc. Basically we have tried to make it a bit of a one-stop-shop for security for regular people, activists, refugees and journalists. We also pull security feeds from places like the UN, Centres for Disease Control etc - which is obviously very important to folks in places like Syria or affected by Zika/Ebola.
There’s tons of really relevant stuff in it, especially for those now mobilising for the first time on some issues. Loads of people are writing guides that solve small parts of the puzzle but we have tried to provide the whole picture in the one place.
Google Play Store: https://play.google.com/store/apps/details?id=org.secfirst.u...
Amazon App Store: https://www.amazon.com/Security-First-Umbrella-made-easy/dp/...
F-Droid Repo: https://secfirst.org/fdroid/repo
Github Repo: https://github.com/securityfirst
Code Audit: https://secfirst.org/blog.html
Hope some folks here find it useful/interesting!
Ends blatant plug
Re: Basic Security Precautions for Non-Profits and Journalists
#147Earlier quoted context omitted.
If you can't use your phone number for password recovery or SMS to your phone number as the 2FA, what do you use instead?
The best-practices 2FA stack is: * U2F token (primary method) * TOTP via phone app (backup) * Backup keys printed or on encrypted USB, in a safe. * SMS disabled explicitly. TOTP fallback doesn't reduce security meaningfully, because U2F principally protects against phishing. But SMS fallback is devastating to security.
Re: Basic Security Precautions for Non-Profits and Journalists
#148Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…
Was that an option or was it assumed un-avoidable that people will always have a smart phone or laptop with sensitive info on them? (so it would have to be an iphone according to the article) whereas that is assuming the choice has already been made that you have to have a smartphone to begin with.
Re: Basic Security Precautions for Non-Profits and Journalists
#149Earlier quoted context omitted.
I generally make an exception for HTTPS Everywhere and Google Password Alert when I wrote things like this, but I agree that maybe it's worth it to cut them and simplify the guide. https://chrome.google.com/webstore/detail/password-alert/noo... https://chrome.google.com/webstore/detail/https-everywhere/g...
HTTPS Everywhere would be a win (I'd have to think about whether it's enough of one to earn its place on the list, but if you added it, you could also suggest an ad-blocker --- another issue there though is suggesting ad blockers to journalists gets to a tricky place). GPA is great, but the premise behind this guide is that if you're relying on passwords for Google you're already boned. It's a security win even with…
Re: Basic Security Precautions for Non-Profits and Journalists
#150Questions and suggestions: 1. For "Do as much of your work as possible on an iPhone or iPad." -- as opposed to what? Android and Windows? Would listing device options be a possibility? 2. Possibly: add a set of suggestions for transporting device(s) across borders or acquiring them. I suspect mail or package delivery might be an option -- or if it's not, then clarifying the risks would be of interest. 3. Operating sy…
1. As opposed to a laptop. 2. Any concrete advice about crossing borders is hard to give right now. The goal in this document is just to alert people that it is not OK to travel with your work device. 3. For the audience here (think someone providing legal aid at an airport) this is too technical. 4,5,6 Great idea, thank you! 7. It's funny but the XKCD really seems to be the best thing to link.
1. Windows laptop, I take it? Or any laptop?
2. Even if specifics are hard to provide, a pointer to best information, a clear statement that "Any concrete advice about crossing borders is hard to give right now" (in fact that exact phrase strikes me as excellent), and perhaps a pointer to a larger document with laws pertaining to specific countries. Ranked, say, by interest and/or travel volume. World Bank has listings: http://data.worldbank.org/indicator/ST.INT.ARVL?year_high_de...
3. Even people providing legal aid may have support teams who could assimilate the information. Out-of-document link here. Think staged information delivery.
7. It's an effective format for communciation. There are several generators (caveat emptor) as well. For MacOS, it would be easy to create a local generator using wordlists (I've done same on Linux). The problem is actually that the system dictionaries are generally too comprehensive and have really obscure words in them. A GUI wrapper around a Very Simple Shell Script would tend to give good outputs.