Live data from Hacker News

Basic Security Precautions for Non-Profits and Journalists

techsolidarity.org

171–180 of 182 posts

Re: Basic Security Precautions for Non-Profits and Journalists

#171

Earlier quoted context omitted.

PGP isn't user friendly, but from the Snowden leaks we learned it is one of the few encryption standards the NSA hasn't been able to break. TLS and most configs of VPN protocols were shown to be easily compromised. PGP was basically shown to be a show stopper. 1. http://m.spiegel.de/international/germany/a-1010361.html

Agreed. It has many problems but it's still one of the only games in town.

> TLS and most configs of VPN protocols were shown to be easily compromised.

This is a major claim to be making, and it is false. It is not helpful to spread misinformation like this.

Re: Basic Security Precautions for Non-Profits and Journalists

#172

Earlier quoted context omitted.

Agreed. It has many problems but it's still one of the only games in town.

> TLS and most configs of VPN protocols were shown to be easily compromised. This is a major claim to be making, and it is false. It is not helpful to spread misinformation like this.

Easily was, perhaps, not the correct adverb, but the linked article above as well as this one below go into it more. It does not appear to be false.

http://www.theverge.com/2014/12/28/7458159/encryption-standa...

Bruce Schneier has said while large government actors may be able to exploit it, it's still recommended: https://www.theguardian.com/world/2013/sep/05/nsa-how-to-rem...

Re: Basic Security Precautions for Non-Profits and Journalists

#173

Earlier quoted context omitted.

> TLS and most configs of VPN protocols were shown to be easily compromised. This is a major claim to be making, and it is false. It is not helpful to spread misinformation like this.

Easily was, perhaps, not the correct adverb, but the linked article above as well as this one below go into it more. It does not appear to be false. http://www.theverge.com/2014/12/28/7458159/encryption-standa... Bruce Schneier has said while large government actors may be able to exploit it, it's still recommended: https://www.theguardian.com/world/2013/sep/05/nsa-how-to-rem...

Perhaps older versions of SSL, but there is no evidence that anyone has compromised TLS.

There is evidence that encrypted traffic was stored and research was done on the metadata of these connections but that is no surprise. That may be what they were referring to.

Re: Basic Security Precautions for Non-Profits and Journalists

#174

Earlier quoted context omitted.

Easily was, perhaps, not the correct adverb, but the linked article above as well as this one below go into it more. It does not appear to be false. http://www.theverge.com/2014/12/28/7458159/encryption-standa... Bruce Schneier has said while large government actors may be able to exploit it, it's still recommended: https://www.theguardian.com/world/2013/sep/05/nsa-how-to-rem...

Perhaps older versions of SSL, but there is no evidence that anyone has compromised TLS. There is evidence that encrypted traffic was stored and research was done on the metadata of these connections but that is no surprise. That may be what they were referring to.

Also, threat models are important here...not everyone includes needs to include the five eyes as your threat model.

Re: Basic Security Precautions for Non-Profits and Journalists

#175
post #139

Earlier quoted context omitted.

For one, without Google Play Services you have no Play Store. Unless you're going to prevent users from installing apps entirely, there isn't really another safe way to obtain apps. Additionally Verify Apps, SafetyNet, Safe Browsing, etc. are all part of Google Play Services. You _really_ want Verify Apps.

F-Droid, Raccoon, MicroG?

F-Droid and Racoon are ways to obtain apps. MicroG is an alternative to Google Play Services. How do these solve the other issues the commenter mentioned? Does MicroG include "Verify Apps, SafetyNet, Safe Browsing, etc."?

Re: Basic Security Precautions for Non-Profits and Journalists

#176
Great initiative.

>1. Don't send any sensitive information by email.

>2. Don't store sensitive information in cloud services like Evernote or Dropbox.

Both of these are good advice.

However, what I don't see is "how to share information securely". The intended audience surely needs a way to exchange information, e.g. documents but what are the recommendations on how they should do this?

>Carry a “USB data blocker” (either the whole cable or an adapter that plugs into your cable like this) to charge at airport or hotel chargers.

I would suggest that SyncStop[1][2] is recommended instead of the current device on the basis that SyncStop is created and sold by a security company that specialises in hardware security. It is also recommended by Mikko[3] from fsecure.

[1] http://syncstop.com/

[2] https://www.amazon.com/Syncstop-Syncstop/dp/B00ZQAY23U

[3] https://twitter.com/mikko/status/792980858340769792

Re: Basic Security Precautions for Non-Profits and Journalists

#177

Earlier quoted context omitted.

Perhaps older versions of SSL, but there is no evidence that anyone has compromised TLS. There is evidence that encrypted traffic was stored and research was done on the metadata of these connections but that is no surprise. That may be what they were referring to.

Also, threat models are important here...not everyone includes needs to include the five eyes as your threat model.

Of course. I am just using it as a yardstick for security strength.

Re: Basic Security Precautions for Non-Profits and Journalists

#178
post #97

Earlier quoted context omitted.

The TOR network is a network: you can access it using any web browser and the TOR client + a local web proxy. Use Chrome and configure it to use the local web proxy, now you're accessing TOR using Chrome.

@munin can you clarify is "TOR client" the same as "TOR Browser" downloaded here[1] or is it something different? Do you have any links you can share to best practices for setting up this secure TOR client instead of using the insecure TBB as explained above? [1] https://www.torproject.org/download/download-easy.html.en

The Tor client is the software which runs the 'onion routing' part. This provides a local network port which is your wormhole into the network; this is called a SOCKS proxy.

The TBB has the Tor client and a browser (a slightly tweaked Firefox) configured to connect via the Tor SOCKS proxy rather than via the standard network.

I was disappointed last time I booted up TBB to see they had security by default set to 'Low', which enabled lots of unnecessary stuff, like javascript on for every site by default. Too many content parsers trying to do stuff with untrusted data. Its pretty poor.

Re: Basic Security Precautions for Non-Profits and Journalists

#179
post #114
post #39

Earlier quoted context omitted.

> I have not heard of any major security incident recently with Firefox. https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-a... https://blog.mozilla.org/security/2015/08/06/firefox-exploit...

What can I subscribe to, to hear about news like that in a more systematic fashion? I mean, monitoring all CVEs might be a little to much for somebody who isn't full time security professional, but there surely must be some reasonable compromise between that and position like "this browser is secure because tptacek said so". I don't mean anything against tptacek personally, but without any substantial grounding this…

lwn.net

Re: Basic Security Precautions for Non-Profits and Journalists

#180
post #27
post #13

"Use a bluetooth keyboard for easier typing..." Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in.

> Not a good advice for any public place (airports, cafes, etc). Very easy to listen to BT and intercept passwords as user types them in. It's worth the risk to get people to use a iPhone or iPad more routinely. Also, the risk of this is exceedingly low because an attacker needs to actively interfere with the pairing process and be physically present for collection. This attack doesn't scale like "It's Windows, go pu…

I don't know about LE but SDR is pretty cheap these days. How many people won't re-pair if its not working?

Things I'll never make quite time to play with: http://www.nsaplayset.org/tinyalamo

Post reply on HN