Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

151–160 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#151
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

What I'm missing here is a simple: Don't use a laptop or cellphone to store sensitive information in the first place (regardless of whether of not you take it across the border). That seems to be the simplest precaution of all. Was that an option or was it assumed un-avoidable that people will always have a smart phone or laptop with sensitive info on them? (so it would have to be an iphone according to the article)…

What you're missing here is that the work these people do requires them to use computers and phones, and telling them to stop using them is like telling them to be 1/100th as effective as they would be otherwise.

This isn't "advice for refugees entering the country whose lives depend on getting past CBP".

Re: Basic Security Precautions for Non-Profits and Journalists

#152

Earlier quoted context omitted.

What I'm missing here is a simple: Don't use a laptop or cellphone to store sensitive information in the first place (regardless of whether of not you take it across the border). That seems to be the simplest precaution of all. Was that an option or was it assumed un-avoidable that people will always have a smart phone or laptop with sensitive info on them? (so it would have to be an iphone according to the article)…

What you're missing here is that the work these people do requires them to use computers and phones, and telling them to stop using them is like telling them to be 1/100th as effective as they would be otherwise. This isn't "advice for refugees entering the country whose lives depend on getting past CBP".

Using a laptop or cellphone is not the same as storing sensitive info on them.

Re: Basic Security Precautions for Non-Profits and Journalists

#153
post #10

Before you freak out about these recommendations, please take into account: These instructions are written for unsophisticated users, particularly journalists and activists, and were written with feedback from those users. So, for instance, the steps you might take to arrive at a secure Firefox or Android configuration are probably fine , but not workable for the audience these instructions are intended for. We're si…

What I'm missing here is a simple: Don't use a laptop or cellphone to store sensitive information in the first place (regardless of whether of not you take it across the border). That seems to be the simplest precaution of all. Was that an option or was it assumed un-avoidable that people will always have a smart phone or laptop with sensitive info on them? (so it would have to be an iphone according to the article)…

This is advice for busy, working people to whom you cannot say "rethink your entire workflow" or "don't have a phone".

The goal is to provide practical security advice that people will use, and that does not make things worse.

Re: Basic Security Precautions for Non-Profits and Journalists

#154
post #43

Just a bit of feedback: might be nice to repeat the "Don't" in front of each sentence, even if it's grouped under the heading and therefore repetitive: I found myself being like "wait, it's telling me to backup my messages to google drive? Are they client-side encrypted?"

Yes, I read the article through Readability and it actually stripped out the Do and Don't headers

Thank you both! I'll fix this.

Re: Basic Security Precautions for Non-Profits and Journalists

#155

Hey everyone. Apologies for the blatant plug but seeing as we are talking about security precautions for non-profits and journalists, it's probably relevant... We build a tool specifically to help non-profits and journalists learn about and manage their digital and physical security on the move. It's called Umbrella App. It's free, open source, on Android and contains tons of lessons on privacy related issues like di…

Please get this vetted by real security people. The fact that you mention PGP suggests to me you haven't.

Re: Basic Security Precautions for Non-Profits and Journalists

#156

Earlier quoted context omitted.

What I'm missing here is a simple: Don't use a laptop or cellphone to store sensitive information in the first place (regardless of whether of not you take it across the border). That seems to be the simplest precaution of all. Was that an option or was it assumed un-avoidable that people will always have a smart phone or laptop with sensitive info on them? (so it would have to be an iphone according to the article)…

This is advice for busy, working people to whom you cannot say "rethink your entire workflow" or "don't have a phone". The goal is to provide practical security advice that people will use, and that does not make things worse.

Ok, I got that. So here's a suggestion for a simple but very effective addendum:

- do not store on your laptop / cellphone what you no longer need

- make sure you protect your back-ups as well as you protect your originals

- don't type in credentials while under camera observation

Re: Basic Security Precautions for Non-Profits and Journalists

#157
post #52
post #45

I'm a bit confused about the don't backup to Google Drive but use Gmail. are you trusting google or not?

There's virtually nothing in security that works this way. It's not the NFL. We don't pick teams and root for them. There are things that Google does that are superior to the alternatives, and there are things Apple does that are superior to the alternatives.

I understand and I agree with your point, however to me Gmail and google drive both fall into one bucket, Google's cloud offering. If any thing I would assume Drive is safer since it isnt forced to interact with an old unsecure protocol. They have full control of how it's implemented.

Re: Basic Security Precautions for Non-Profits and Journalists

#158

Hey everyone. Apologies for the blatant plug but seeing as we are talking about security precautions for non-profits and journalists, it's probably relevant... We build a tool specifically to help non-profits and journalists learn about and manage their digital and physical security on the move. It's called Umbrella App. It's free, open source, on Android and contains tons of lessons on privacy related issues like di…

Please get this vetted by real security people. The fact that you mention PGP suggests to me you haven't.

How can a standard guide to installing and using PGP through various different methods be a security issue?

Re: Basic Security Precautions for Non-Profits and Journalists

#159
post #139

Earlier quoted context omitted.

> not having Google Play Services would dramatically reduce the security posture of an Android device. I understand Verified Boot, but how would removing Google Play Services damage security? It would seem to reduce the attack surface.

For one, without Google Play Services you have no Play Store. Unless you're going to prevent users from installing apps entirely, there isn't really another safe way to obtain apps. Additionally Verify Apps, SafetyNet, Safe Browsing, etc. are all part of Google Play Services. You _really_ want Verify Apps.

Excellent points; thanks.

Re: Basic Security Precautions for Non-Profits and Journalists

#160

Earlier quoted context omitted.

Please get this vetted by real security people. The fact that you mention PGP suggests to me you haven't.

How can a standard guide to installing and using PGP through various different methods be a security issue?

Because people should not be using PGP for secure messaging.
Post reply on HN