Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

161–170 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#161
post #68

Would be helpful to provide alternative to some of the Don'ts. How does one transfer information if they can't transfer anything across the border? Where should one store sensitive information? An encrypted drive you're not supposed to transfer across the border? I'm not really sure what a person is supposed to do with either of those two recommendations, especially if we're saying that person is not tech-savvy. I th…

I also have my doubts about 1Password – although I am still a 1Password users, at least of the old approach (pay once, cloud sync but no web-accessible storage with 1Password). I guess I will have to look for an alternative sooner or later! :(

I use 1Password + Resilio (formerly BTSync) in local sync only mode.

It's kind of a pain in the ass sometimes (I can only sync at home) but the upside is no cloud component and it syncs nicely and automatically between multiple machines.

For mobile devices, I use the Wifi sync mode.

Re: Basic Security Precautions for Non-Profits and Journalists

#162

Earlier quoted context omitted.

How can a standard guide to installing and using PGP through various different methods be a security issue?

Because people should not be using PGP for secure messaging.

On what grounds? on what threat models? on what attacks? what alternatives?

Re: Basic Security Precautions for Non-Profits and Journalists

#163

Earlier quoted context omitted.

How can a standard guide to installing and using PGP through various different methods be a security issue?

Because people should not be using PGP for secure messaging.

PGP isn't user friendly, but from the Snowden leaks we learned it is one of the few encryption standards the NSA hasn't been able to break. TLS and most configs of VPN protocols were shown to be easily compromised. PGP was basically shown to be a show stopper.

1. http://m.spiegel.de/international/germany/a-1010361.html

Re: Basic Security Precautions for Non-Profits and Journalists

#164

Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the devices you work on across the US border. Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the pe…

thegrugq recently had a post about travel kits https://twitter.com/thegrugq/status/829855684636274688 It's not just the US border, any border they can request you open up social media accounts or walk away with your laptop or phone and return it later filled with spyware. Business trips from here to China always involve buying a new phone and wiping/selling it on Craigslist after you return assuming it's been comprom…

> wiping/selling it on Craigslist after you return assuming it's been compromised.

Seems like if you assume a phone is compromised, it would be immoral to sell it to someone else without full disclosure of your concerns.

Re: Basic Security Precautions for Non-Profits and Journalists

#165

Earlier quoted context omitted.

Because people should not be using PGP for secure messaging.

PGP isn't user friendly, but from the Snowden leaks we learned it is one of the few encryption standards the NSA hasn't been able to break. TLS and most configs of VPN protocols were shown to be easily compromised. PGP was basically shown to be a show stopper. 1. http://m.spiegel.de/international/germany/a-1010361.html

Agreed. It has many problems but it's still one of the only games in town.

Re: Basic Security Precautions for Non-Profits and Journalists

#166

Earlier quoted context omitted.

How can a standard guide to installing and using PGP through various different methods be a security issue?

Because people should not be using PGP for secure messaging.

I really think you're vastly exaggerating the difficulty of using PGP properly. With Enigmail and a small sheet of instructions, anyone slightly computer literate should do fine.

And there simply aren't any better alternatives for encrypting emails or files for transmission. I'd love to be wrong about that, but I haven't seen anything.

Re: Basic Security Precautions for Non-Profits and Journalists

#167
post #97

Earlier quoted context omitted.

Does make sense. Any advice on best way to access the Tor network, if not the Tor Browser?

The TOR network is a network: you can access it using any web browser and the TOR client + a local web proxy. Use Chrome and configure it to use the local web proxy, now you're accessing TOR using Chrome.

@munin can you clarify is "TOR client" the same as "TOR Browser" downloaded here[1] or is it something different?

Do you have any links you can share to best practices for setting up this secure TOR client instead of using the insecure TBB as explained above?

[1] https://www.torproject.org/download/download-easy.html.en

Re: Basic Security Precautions for Non-Profits and Journalists

#168
post #139

Earlier quoted context omitted.

> not having Google Play Services would dramatically reduce the security posture of an Android device. I understand Verified Boot, but how would removing Google Play Services damage security? It would seem to reduce the attack surface.

For one, without Google Play Services you have no Play Store. Unless you're going to prevent users from installing apps entirely, there isn't really another safe way to obtain apps. Additionally Verify Apps, SafetyNet, Safe Browsing, etc. are all part of Google Play Services. You _really_ want Verify Apps.

F-Droid, Raccoon, MicroG?

Re: Basic Security Precautions for Non-Profits and Journalists

#169
post #166

Earlier quoted context omitted.

Because people should not be using PGP for secure messaging.

I really think you're vastly exaggerating the difficulty of using PGP properly. With Enigmail and a small sheet of instructions, anyone slightly computer literate should do fine. And there simply aren't any better alternatives for encrypting emails or files for transmission. I'd love to be wrong about that, but I haven't seen anything.

Agree, that's why we have it in. Even things like Mailvelope, can make it easier for a semi-technical user.

Re: Basic Security Precautions for Non-Profits and Journalists

#170
post #114
post #39

Earlier quoted context omitted.

> I have not heard of any major security incident recently with Firefox. https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-a... https://blog.mozilla.org/security/2015/08/06/firefox-exploit...

What can I subscribe to, to hear about news like that in a more systematic fashion? I mean, monitoring all CVEs might be a little to much for somebody who isn't full time security professional, but there surely must be some reasonable compromise between that and position like "this browser is secure because tptacek said so". I don't mean anything against tptacek personally, but without any substantial grounding this…

US-CERT publishes alerts on vulnerabilities affecting common software. Several RSS feeds available. They also have weekly vulnerability summaries for a wide range of software.

https://www.us-cert.gov/ncas

Post reply on HN