Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

101–110 of 220 posts

Re: Infosec 101 for Activists

#101

How much does a Firefox 0-day cost these days on the grey market compared to a Chrome 0-day with sandbox escape?

Not sure how reliable this information is [1], but apparently, 200k vs 500k. Another [2] organization states 350k vs 1.5M (including LPE).

[1] https://opzero.ru/en/prices/

[2] https://www.crowdfense.com/exploit-acquisition-program/

Re: Infosec 101 for Activists

#102
post #99

I personally don't believe basic measures like turning off location services as suggested by the article will make a difference against a sophisticated adversary like a state actor. We know that modern phones are full of proprietary firmware with swiss cheese tier security which allow for 0 day remote code execution exploits [1]. The operating systems, although better, also have been targeted by RCE exploits [2]. Not…

Agreed, when they can own the baseband, you're kinda screwed. edit: my knowledge is clearly out of date.

Since the mid-2010s Apple has put every baseband / WiFi / Bluetooth radio either on USB or PCIe with an IOMMU that restricts access to only the pages required for networking and packet management.

I can't speak to when Android started doing this, but I know the common chipsets (Qualcomm, Exynos, Mediatek) also do this.

Re: Infosec 101 for Activists

#103
post #80

Earlier quoted context omitted.

Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks. A strawman mod to protonmail could be to mandate the use of a VPN

> The aim should be to engineer the system so that you don't (and can't) have access to the information So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?

https://signal.org/bigbrother/

Re: Infosec 101 for Activists

#104

Earlier quoted context omitted.

There are multiple documented cases where emergency vehicles are blocked by "blocking a highway" as a "peaceful protest" that resulted in deaths. e.g., London (2022) - Mark Heap and Lisa Webber.

That's what makes it effective. That's the point. A protest that doesn't affect anyone is just performative. Protests aren't to spread the word. It's to jam up the gears, aka, sabotage, to make leaders act. "You're just making us late to work, it's not causing us to join your side!" Jamming up commerce and the functions of a city is how you get people to act. Not by filling out a permit to have a block party in a par…

Unfortunately our leaders have successfully convinced the masses that it's only acceptable to protest as long as they do it at a scheduled time and place, without disrupting or offending anyone, and without any implicit threats of escalation and violence if the protestors' grievances aren't heard and rectified. That way people can vent to temporarily release frustration but we're powerless to effect any meaningful change, by design.

Re: Infosec 101 for Activists

#105
post #79
post #75

Earlier quoted context omitted.

This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?

See, this is what I'm talking about. If you're trying to protect activists from threats, protect them from threats. Making a political statement about commercial surveillance isn't doing that. A lot of these guides are LARPs. How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're re…

Commercial surveillance enables government surveillance. If an app constantly sends my location to a corporation by default, a government-level adversary can just demand it from that corporation, no need to burn a 0-day on me.

Re: Infosec 101 for Activists

#107
post #27

Remember when the FBI and NSA were trying to outlaw encryption? Like a couple years ago? How the turn tables!

I’m not sure I understand why the tables are turned now.

It's complicated to explain, but in the republican(/conservative/trump supporter) mind "activists" are (in support of) "far-left marxist communist liberal extremists" like Biden, Obama or Harris, so the FBI/CIA/NSA under the Biden administration were protecting them and calls for making encryption illegal only targeted "the republican" so activists supported ending encryption because it benefited them in their unjust war against republicans. So if they now see activists discussing opsec, they view it as liberals being "scared" at the righteous Trump administration coming for them.

Re: Infosec 101 for Activists

#108

For someone in the know: what's the credibility of the authors on this topic? I see https://infosecforactivists.org/#acknowledgments and https://github.com/InfosecForActivistsTeam/infosec-activists... but I don't see their experience following their own advice. The document by itself looks unpolished. Tor, for example, should be at least referenced once, even if they recommend against it.

Can't speak for OP's link, but as a contrast No Trace Project's resources contain lots of advice from people who actually routinely face state repression, with in-depth analysis of specific cases. The scope is international (though focused on the North Atlantic region) rather than english- & u.s.-exclusive. There are plenty of references to Tor+Tails.

https://www.notrace.how/

http://i4pd4zpyhrojnyx5l3d2siauy4almteocqow4bp2lqxyocrfy6pry...

Re: Infosec 101 for Activists

#109
post #80

Earlier quoted context omitted.

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks. A strawman mod to protonmail could be to mandate the use of a VPN

The aim should be to engineer the system so that you had over every piece of information that you have and that it is totally useless to anyone, either through encryption (that you don't have access to) or through not collecting it in the first place.

Re: Infosec 101 for Activists

#110
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

[flagged]
Post reply on HN