One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…
Infosec 101 for Activists
91–100 of 220 posts
Re: Infosec 101 for Activists
#92Earlier quoted context omitted.
> The aim should be to engineer the system so that you don't (and can't) have access to the information So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?
In a perfect world? The same way Apple did in ~2015. Argue that code is equivalent to speech, compelling them to write code to change the way the system works is compelling speech, and making that demand is unconstitutional. Apple gets lots of shit for a multitude of reasons, but their stance of "We built it to be securely encrypted from everyone but the owner; if you want to change that then fuck you, make me" is so…
I think this is easier: there isn't a single corporation on the earth with morals. Morality and profit-chasing are not generally coherent principles. Nobody doing any good on this earth has a need for an LLC.
Re: Infosec 101 for Activists
#93The Grugq has complementary advice which arguably is more important, regarding foundational principles, personas and so on:
https://www.youtube.com/watch?v=L3j1AhS0iKI
https://www.youtube.com/watch?v=3w7E4Hhtubw (there's a bit of presentation and ceremony before they get into the relevant parts)
Re: Infosec 101 for Activists
#94Earlier quoted context omitted.
> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?
The ones that don't end up shut down, in legal trouble or in jail. See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.
You know that Telegram is giving plenty much of information in these days?
They even changed the privacy policy.
https://techstartups.com/2024/09/06/telegram-silently-update...
Re: Infosec 101 for Activists
#95One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…
Does the same apply for Chromium or does Chrome specifically have better runtime protection than Chromium? Why not mention Chromium?
Re: Infosec 101 for Activists
#96Not to mention even turning a phone off does not guarantee it goes silent. Apple's Find My network works even for turned off devices. Now of course you can turn that feature off, but once the capability to track a turned off device is there, we have to assume that a nation state actor has exploits/backdoors that allow agencies to bypass basic software switches.
You have to assume everything you do on a mobile phone will end up in law enforcement/intelligence agency databases if you're put on a watch list.
[1] https://googleprojectzero.blogspot.com/2023/03/multiple-inte...
Re: Infosec 101 for Activists
#97Step 2: Realize that none of these measures are adequate for that threat model, in the current environment. (For pretty much any threat model.)
Step 3: Realize that some of these measures draw attention to yourself, however.
Re: Infosec 101 for Activists
#98Earlier quoted context omitted.
In a perfect world? The same way Apple did in ~2015. Argue that code is equivalent to speech, compelling them to write code to change the way the system works is compelling speech, and making that demand is unconstitutional. Apple gets lots of shit for a multitude of reasons, but their stance of "We built it to be securely encrypted from everyone but the owner; if you want to change that then fuck you, make me" is so…
> Not every corporation has both morals I think this is easier: there isn't a single corporation on the earth with morals. Morality and profit-chasing are not generally coherent principles. Nobody doing any good on this earth has a need for an LLC.
Re: Infosec 101 for Activists
#99I personally don't believe basic measures like turning off location services as suggested by the article will make a difference against a sophisticated adversary like a state actor. We know that modern phones are full of proprietary firmware with swiss cheese tier security which allow for 0 day remote code execution exploits [1]. The operating systems, although better, also have been targeted by RCE exploits [2]. Not…
edit: my knowledge is clearly out of date.
Re: Infosec 101 for Activists
#100Earlier quoted context omitted.
The ones that don't end up shut down, in legal trouble or in jail. See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.
> Telegram You know that Telegram is giving plenty much of information in these days? They even changed the privacy policy. https://techstartups.com/2024/09/06/telegram-silently-update...
https://edition.cnn.com/2024/09/23/tech/telegram-ceo-durov-a...