How much does a Firefox 0-day cost these days on the grey market compared to a Chrome 0-day with sandbox escape?
Infosec 101 for Activists
101–110 of 220 posts
Re: Infosec 101 for Activists
#102I personally don't believe basic measures like turning off location services as suggested by the article will make a difference against a sophisticated adversary like a state actor. We know that modern phones are full of proprietary firmware with swiss cheese tier security which allow for 0 day remote code execution exploits [1]. The operating systems, although better, also have been targeted by RCE exploits [2]. Not…
Agreed, when they can own the baseband, you're kinda screwed. edit: my knowledge is clearly out of date.
I can't speak to when Android started doing this, but I know the common chipsets (Qualcomm, Exynos, Mediatek) also do this.
Re: Infosec 101 for Activists
#103Earlier quoted context omitted.
Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks. A strawman mod to protonmail could be to mandate the use of a VPN
> The aim should be to engineer the system so that you don't (and can't) have access to the information So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?
Re: Infosec 101 for Activists
#104Earlier quoted context omitted.
There are multiple documented cases where emergency vehicles are blocked by "blocking a highway" as a "peaceful protest" that resulted in deaths. e.g., London (2022) - Mark Heap and Lisa Webber.
That's what makes it effective. That's the point. A protest that doesn't affect anyone is just performative. Protests aren't to spread the word. It's to jam up the gears, aka, sabotage, to make leaders act. "You're just making us late to work, it's not causing us to join your side!" Jamming up commerce and the functions of a city is how you get people to act. Not by filling out a permit to have a block party in a par…
Re: Infosec 101 for Activists
#105Earlier quoted context omitted.
This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?
See, this is what I'm talking about. If you're trying to protect activists from threats, protect them from threats. Making a political statement about commercial surveillance isn't doing that. A lot of these guides are LARPs. How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're re…
Re: Infosec 101 for Activists
#106https://www.notrace.how/ / http://i4pd4zpyhrojnyx5l3d2siauy4almteocqow4bp2lqxyocrfy6pry...
Re: Infosec 101 for Activists
#107Remember when the FBI and NSA were trying to outlaw encryption? Like a couple years ago? How the turn tables!
I’m not sure I understand why the tables are turned now.
Re: Infosec 101 for Activists
#108For someone in the know: what's the credibility of the authors on this topic? I see https://infosecforactivists.org/#acknowledgments and https://github.com/InfosecForActivistsTeam/infosec-activists... but I don't see their experience following their own advice. The document by itself looks unpolished. Tor, for example, should be at least referenced once, even if they recommend against it.
http://i4pd4zpyhrojnyx5l3d2siauy4almteocqow4bp2lqxyocrfy6pry...
Re: Infosec 101 for Activists
#109Earlier quoted context omitted.
> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?
Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks. A strawman mod to protonmail could be to mandate the use of a VPN
Re: Infosec 101 for Activists
#110One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…