Live data from Hacker News

The Personal Security Checklist

github.com

11–20 of 116 posts

Re: The Personal Security Checklist

#12
This doesn’t talk about real world adversaries, only hypothetical countermeasures. It would be more useful to know how I’m likely to be attacked, not how to protect against every threat the author could possibly think of.

For example, I want to know where the villains actually go when they want to dox someone. Then I can dox myself and do something about it. I have no idea where to start and wouldn’t want to pay money to criminals to get it.

Re: The Personal Security Checklist

#13

This doesn’t talk about real world adversaries, only hypothetical countermeasures. It would be more useful to know how I’m likely to be attacked, not how to protect against every threat the author could possibly think of. For example, I want to know where the villains actually go when they want to dox someone. Then I can dox myself and do something about it. I have no idea where to start and wouldn’t want to pay mone…

This. Browser based password saving is only a threat of device theft is a concern. The GitHub repo clearly doesn’t understand threat models or convencience-to-risk ratios.

Re: The Personal Security Checklist

#14
Tip #1 should be: determine your threat model.

Who are you, and why should hackers care about hacking you? Who is doing the hacking? Is it a 3-letter organization or other nation-state adversary? Is it a corporate actor trying to commit corporate espionage? Someone trying to steal your identity?

I am less valuable to hack than Vitalik Buterin, who in turn is less valuable to hack than President Biden.

Re: The Personal Security Checklist

#15

This doesn’t talk about real world adversaries, only hypothetical countermeasures. It would be more useful to know how I’m likely to be attacked, not how to protect against every threat the author could possibly think of. For example, I want to know where the villains actually go when they want to dox someone. Then I can dox myself and do something about it. I have no idea where to start and wouldn’t want to pay mone…

The real villains will have access via gov agencies to make emergency data requests to tech companies.

Maltego can also be used to pivot on any info you already have to collect more. I'd say the best you can reasonably do is to use this to find your trails and remove them or worst case obfuscate it with noise.

Re: The Personal Security Checklist

#16

This doesn’t talk about real world adversaries, only hypothetical countermeasures. It would be more useful to know how I’m likely to be attacked, not how to protect against every threat the author could possibly think of. For example, I want to know where the villains actually go when they want to dox someone. Then I can dox myself and do something about it. I have no idea where to start and wouldn’t want to pay mone…

This is a great instinct and I recommend everyone do this.

There’s a ton of resources on this, unfortunately subject to this predictable effect where spam proliferation easily overwhelms your ability to discover useful resources in reasonable time period.

Michael Bazzell has a book on OSINT (and a blog/podcast) which I can recommend for an initial dive. Good starting point for action would be his data broker checklist.

Re: The Personal Security Checklist

#19
post #9

I would love a list like this which is geared towards more advanced users (and software developers who deal with a lot of sensitive data) and describes threat models more comprehensively.

For software developers working for a corporate: Use your corp laptop and phone only for corp work. Don't do any personal stuff on it, including browsing the general web.

Just this alone reduces the risks significantly.

Re: The Personal Security Checklist

#20
post #4

The flaw with this list is that it treats all risks as equally likely and does not distinguish between various threat landscapes. Few people are high value enough to merit the effort required to capture a face from CCTV, generate a mask from the image, get physical access to their device, and use the mask to unlock. So for almost everyone, faceid is fine.

More common associated risk: Police detain you and point your phone at your face to unlock it (or unlock your access to some other resource). That is not a very high-tech or high-effort attack and could be relevant if you're concerned about the police. Someone might say that this concern is useless because the police can also coerce you to unlock your phone via a different method, but that depends on the law and cult…

If you press and hold both the lock button + the volume up button long enough to open the power-off screen, it will disable faceID (on iPhone) until you enter your passcode again.

Handy to know and easy enough to do discreetly in a pinch.

Post reply on HN