Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

71–80 of 220 posts

Re: Infosec 101 for Activists

#72
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

The point isn't that Firefox is less exploitable it's that it has less blatant tracking than alternatives like Chrome. If you're an activist I'd imagine that exploits are a scary thought but the more direct threat is the tracking we (un)knowingly succumb to every day.

Re: Infosec 101 for Activists

#73
post #47

Earlier quoted context omitted.

That does not a riot make. It is still a peaceful protest, whether you like it or not, contingent on the definition of "peaceful" being the absence of violence. You do not have to like the outcome of a protest, but if it is not a violent one, you are expected here to describe it in accurate language. You are not doing that. To illustrate my point: your logic dictates that not pulling over for an emergency vehicle is…

I was responding to your note that it is peaceful, not that is or is not a riot. A gathering where someone dies because of the gathering it is no longer undisturbed by strife, turmoil, calm, and tranquil. It is no longer peaceful. > ... contingent on the definition of "peaceful" being the absence of violence. The breaking of peaceful to me is not absence of violence. It is no longer peaceful because force was used to…

This is not a credible definition. By this standard a traffic jam is a human rights violation.

Re: Infosec 101 for Activists

#74
post #2

More resources on this topic: Activist or Protester? by EFF's Surveillance Self Defense https://ssd.eff.org/playlist/activist-or-protester The Protester's Guide to Smartphone Security by Privacy Guides https://www.privacyguides.org/articles/2025/01/23/activists-...

eff's a good source for most people on most occasions

for everything else read material from anarchists. ex: https://opsec.riotmedicine.net/downloads#mobile-phone-securi...

Re: Infosec 101 for Activists

#75
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?

Re: Infosec 101 for Activists

#76
post #69

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks th…

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so

Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

Re: Infosec 101 for Activists

#77
post #69

Earlier quoted context omitted.

As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks th…

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

The ones that don't end up shut down, in legal trouble or in jail.

See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.

Re: Infosec 101 for Activists

#78
post #69

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks th…

[deleted]

Re: Infosec 101 for Activists

#79
post #75
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?

See, this is what I'm talking about. If you're trying to protect activists from threats, protect them from threats. Making a political statement about commercial surveillance isn't doing that. A lot of these guides are LARPs.

How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're reading at least offer their readership the choice of risks. Does this one? (Rhetorical, obvs.)

Re: Infosec 101 for Activists

#80
post #69

Earlier quoted context omitted.

As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks th…

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks.

A strawman mod to protonmail could be to mandate the use of a VPN

Post reply on HN