Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

91–100 of 220 posts

Re: Infosec 101 for Activists

#91
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

Does the same apply for Chromium or does Chrome specifically have better runtime protection than Chromium? Why not mention Chromium?

Re: Infosec 101 for Activists

#92
post #89

Earlier quoted context omitted.

> The aim should be to engineer the system so that you don't (and can't) have access to the information So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?

In a perfect world? The same way Apple did in ~2015. Argue that code is equivalent to speech, compelling them to write code to change the way the system works is compelling speech, and making that demand is unconstitutional. Apple gets lots of shit for a multitude of reasons, but their stance of "We built it to be securely encrypted from everyone but the owner; if you want to change that then fuck you, make me" is so…

> Not every corporation has both morals

I think this is easier: there isn't a single corporation on the earth with morals. Morality and profit-chasing are not generally coherent principles. Nobody doing any good on this earth has a need for an LLC.

Re: Infosec 101 for Activists

#93
Yeah, don't use Proton, they're several types of shady. If you can figure out running Matrix, that's better. Email isn't built for security, don't treat it as if it was. Use PGP on the body if you want, but the metadata will still be very talkative.

The Grugq has complementary advice which arguably is more important, regarding foundational principles, personas and so on:

https://www.youtube.com/watch?v=L3j1AhS0iKI

https://www.youtube.com/watch?v=3w7E4Hhtubw (there's a bit of presentation and ceremony before they get into the relevant parts)

Re: Infosec 101 for Activists

#94
post #77

Earlier quoted context omitted.

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

The ones that don't end up shut down, in legal trouble or in jail. See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.

> Telegram

You know that Telegram is giving plenty much of information in these days?

They even changed the privacy policy.

https://techstartups.com/2024/09/06/telegram-silently-update...

Re: Infosec 101 for Activists

#95
post #91
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

Does the same apply for Chromium or does Chrome specifically have better runtime protection than Chromium? Why not mention Chromium?

You lose auto-update, right? The only concern I have off the top of my head.

Re: Infosec 101 for Activists

#96
I personally don't believe basic measures like turning off location services as suggested by the article will make a difference against a sophisticated adversary like a state actor. We know that modern phones are full of proprietary firmware with swiss cheese tier security which allow for 0 day remote code execution exploits [1]. The operating systems, although better, also have been targeted by RCE exploits [2].

Not to mention even turning a phone off does not guarantee it goes silent. Apple's Find My network works even for turned off devices. Now of course you can turn that feature off, but once the capability to track a turned off device is there, we have to assume that a nation state actor has exploits/backdoors that allow agencies to bypass basic software switches.

You have to assume everything you do on a mobile phone will end up in law enforcement/intelligence agency databases if you're put on a watch list.

[1] https://googleprojectzero.blogspot.com/2023/03/multiple-inte...

[2] https://en.m.wikipedia.org/wiki/Pegasus_(spyware)

Re: Infosec 101 for Activists

#97
Step 1: Determine your threat model.

Step 2: Realize that none of these measures are adequate for that threat model, in the current environment. (For pretty much any threat model.)

Step 3: Realize that some of these measures draw attention to yourself, however.

Re: Infosec 101 for Activists

#98
post #89

Earlier quoted context omitted.

In a perfect world? The same way Apple did in ~2015. Argue that code is equivalent to speech, compelling them to write code to change the way the system works is compelling speech, and making that demand is unconstitutional. Apple gets lots of shit for a multitude of reasons, but their stance of "We built it to be securely encrypted from everyone but the owner; if you want to change that then fuck you, make me" is so…

> Not every corporation has both morals I think this is easier: there isn't a single corporation on the earth with morals. Morality and profit-chasing are not generally coherent principles. Nobody doing any good on this earth has a need for an LLC.

Calling them "morals" was meant flippantly, though I suspect should have used quotation marks to call that out a bit more. "Multiple ad campaigns and a marketing posture based around privacy" is probably better.

Re: Infosec 101 for Activists

#99

I personally don't believe basic measures like turning off location services as suggested by the article will make a difference against a sophisticated adversary like a state actor. We know that modern phones are full of proprietary firmware with swiss cheese tier security which allow for 0 day remote code execution exploits [1]. The operating systems, although better, also have been targeted by RCE exploits [2]. Not…

Agreed, when they can own the baseband, you're kinda screwed.

edit: my knowledge is clearly out of date.

Re: Infosec 101 for Activists

#100
post #94
post #77

Earlier quoted context omitted.

The ones that don't end up shut down, in legal trouble or in jail. See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.

> Telegram You know that Telegram is giving plenty much of information in these days? They even changed the privacy policy. https://techstartups.com/2024/09/06/telegram-silently-update...

Seems like they didn't give enough.

https://edition.cnn.com/2024/09/23/tech/telegram-ceo-durov-a...

Post reply on HN