Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

81–90 of 220 posts

Re: Infosec 101 for Activists

#82

Serious question: what are the reasons for Firefox over Safari? I'm currently a Firefox user at home and work, but thinking about going back to Safari in the near future...

Firefox is open source.

You don't have to build it yourself, but other people do and deterministic builds can provide collective assurance the code is what it claims to be.

Re: Infosec 101 for Activists

#83

Earlier quoted context omitted.

As if compromising Tor in the long-term is that simple.

Remember when every major player involved with The silk road got raided and the CIA ended up controlling 2/3 of every Bitcoin in circulation?

You mean the Silk Road which exposed the real IP of the web server due to misconfiguration? Tor can be compromised (run a bunch of exit nodes and do traffic correlation) but Silk Road made pretty basic mistakes.

https://krebsonsecurity.com/2014/09/dread-pirate-sunk-by-lea...

Re: Infosec 101 for Activists

#85
post #80

Earlier quoted context omitted.

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks. A strawman mod to protonmail could be to mandate the use of a VPN

> The aim should be to engineer the system so that you don't (and can't) have access to the information

So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?

Re: Infosec 101 for Activists

#86
post #80

Earlier quoted context omitted.

Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks. A strawman mod to protonmail could be to mandate the use of a VPN

> The aim should be to engineer the system so that you don't (and can't) have access to the information So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?

Generally, in my experience, people want to help "catch the criminal" -- note these are usually the worst of the worst at first. Then you start getting less and less information and starts becoming a process rather than an event/discussion.

At least, that was my experience.

Re: Infosec 101 for Activists

#87

Serious question: what are the reasons for Firefox over Safari? I'm currently a Firefox user at home and work, but thinking about going back to Safari in the near future...

I've had the opportunity to work with the safari team in the past. I can't say a lot due to an NDA, but lets just say there is a good reason to prefer Firefox.

Re: Infosec 101 for Activists

#88
post #69

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks th…

https://xcancel.com/andyyen/status/1884907496705339544

Re: Infosec 101 for Activists

#89
post #80

Earlier quoted context omitted.

Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks. A strawman mod to protonmail could be to mandate the use of a VPN

> The aim should be to engineer the system so that you don't (and can't) have access to the information So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?

In a perfect world? The same way Apple did in ~2015. Argue that code is equivalent to speech, compelling them to write code to change the way the system works is compelling speech, and making that demand is unconstitutional.

Apple gets lots of shit for a multitude of reasons, but their stance of "We built it to be securely encrypted from everyone but the owner; if you want to change that then fuck you, make me" is something everyone involved with should be proud of

Realistically, we can't all be one of the richest companies in the modern era. Not every corporation has both morals, and pockets deep enough to pick a fight with not just a government, but the government of the country they're headquartered in. Frankly, shutting down like Lavabit is one of the better realistic scenarios if you're making promises of guaranteed privacy

Re: Infosec 101 for Activists

#90
I am really struggling to find ways to approve anything if you don't have 100% control over it. Signal seems to be a solid choice generally and I do believe they are doing their absolute best to keep it airtight but this is software and some obscene, tiny little hole may very well exist.

Generally speaking, with people like comrade elon having so much say into everything, people rushing to pump out new features daily, most often not putting too much effort into security, I've been making a hard push to cut myself off cloud services and self-host everything I can myself.

Post reply on HN