Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

61–70 of 220 posts

Re: Infosec 101 for Activists

#63
post #35

Earlier quoted context omitted.

[flagged]

Blocking a highway is not an act of violence, it is a form of peaceful protest. Like a diner sit-in. You are free to correct your post to explain all the acts of violence you saw which justify the term "riot".

A physical action (like occupying infrastructure) that limits other people’s freedom to move, or brings harm to them or their property, is a violent act to most people. The only people that would claim otherwise are those who want to downplay illegal acts that align with their own politics.

Here’s a definition for ‘violence’, so you’re clear on how blocking highways is violence:

> violence: an unjust or unwarranted exertion of force or power, as against rights or laws

Here’s a definition for riot, so you’re clear on how a violent takeover of public infrastructure constitutes a riot:

> riot: “public violence, tumult, or disorder“

Re: Infosec 101 for Activists

#64
This page says it was last updated a few weeks ago, but the recommendation against iCloud backups seems to have glaring errors and omissions.

> Keys to unlock the phone’s full-disk encryption are also stored in the iCloud backup. This arrangement allows law enforcement to request the backup data from Apple and use the key to unlock the entire phone. It also offers a convenience, where if the user forgets their unlock code, Apple can still recover the device.

This is not true. Even if it were, the advice to activists should in all cases be to enable Advanced Data Protection so that almost everything (except iCloud mail, contacts and calendar) are end-to-end encrypted (including iCloud phone backups). Apple cannot access the data or help in any kind of recovery when Advanced Data Protection is enabled. It is up to the user to set up recovery contacts and recovery key (and keep this safe).

Re: Infosec 101 for Activists

#67
One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not being easily (==cheaply) targeted by exploits, it's not.

Re: Infosec 101 for Activists

#68
post #36

Earlier quoted context omitted.

I'm not at all a fan of the tactic of blocking highways as a protest move, I think that's not the same thing as a riot -- it's civil disobedience. The link that I shared explicitly pointed out that the riot was started by a white supremacist. It's documented and a fact. So were dealing with 1+N cases here. > Near me, I would say all of them that were riots were that way on purpose. Look, it worked. It has framed BLM…

I feel that the label of “civil disobedience” is misused as a tactic to justify illegal acts. Infrastructure is not there to serve as anyone’s political platform, and it is built with taxpayers’ money for other purposes. If the gathering does not have a permit, it is illegal, and therefore a disturbance of the peace - in other words, a riot.

> If the gathering does not have a permit, it is illegal

This is not true, unless it is in a public forum limited in “time, place, and manner”. The first amendment grants freedom of assembly. You do not need a permit to meet up with (dozens of) your friends any more than you need a permit to write in a journal.

Re: Infosec 101 for Activists

#69

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so...

Sources: https://therecord.media/protonmail-forced-to-collect-an-acti... https://x.com/andyyen/status/1884907496705339544

Re: Infosec 101 for Activists

#70

Earlier quoted context omitted.

That's funny because if I was running SIGINT at the NSA I would do all of the above, and also compromise Tor

As if compromising Tor in the long-term is that simple.

Remember when every major player involved with The silk road got raided and the CIA ended up controlling 2/3 of every Bitcoin in circulation?
Post reply on HN