Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

111–120 of 220 posts

Re: Infosec 101 for Activists

#111
post #79
post #75

Earlier quoted context omitted.

This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?

See, this is what I'm talking about. If you're trying to protect activists from threats, protect them from threats. Making a political statement about commercial surveillance isn't doing that. A lot of these guides are LARPs. How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're re…

>commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages

Is Firefox more susceptible to RCE exploits?

Re: Infosec 101 for Activists

#112
post #3

A bit of a tangent, but modern protests are subject to hijacking from agents provocateur and general shit stirrers -- it's been quite effective in delegitimizing public protests. It would be nice to find ways to counter that. Case in point: how BLM protests were turned into riots by antagonistic forces: https://abcnews.go.com/US/man-helped-ignite-george-floyd-rio...

What actually happened at 2020's protests & riots in the u.s., in the words of those who were there:

https://paper.wf/downas/partisan-accounts-of-the-george-floy...

Why delegitimizing those who don't abide by the rules of “peaceful protest” amounts to defense of the status quo:

https://north-shore.info/2024/10/04/not-liking-someone-doesn...

Re: Infosec 101 for Activists

#113

I personally don't believe basic measures like turning off location services as suggested by the article will make a difference against a sophisticated adversary like a state actor. We know that modern phones are full of proprietary firmware with swiss cheese tier security which allow for 0 day remote code execution exploits [1]. The operating systems, although better, also have been targeted by RCE exploits [2]. Not…

>I personally don't believe basic measures like turning off location services as suggested by the article will make a difference against a sophisticated adversary like a state actor.

The majority of activists are not worth the effort or expense. And for the ones that are worth - those guides make no difference since they don't harden as much. If you want real security - then the least you must do is have two devices. One used for hotspot only.

Re: Infosec 101 for Activists

#115

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

Proton also suffers from a pathology similar to the LavaBit problem. Better off using some other email service that doesn't insist on keeping GPG keys on its servers and using something like Mega instead.

Re: Infosec 101 for Activists

#116
post #79

Earlier quoted context omitted.

See, this is what I'm talking about. If you're trying to protect activists from threats, protect them from threats. Making a political statement about commercial surveillance isn't doing that. A lot of these guides are LARPs. How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're re…

Commercial surveillance enables government surveillance. If an app constantly sends my location to a corporation by default, a government-level adversary can just demand it from that corporation, no need to burn a 0-day on me.

This is a complex thing. Don't give your location to the app. Turn off GPS, use VPN and don't use any apps/sites that linked with your real identity on the same device. Most of the other parameters in the commercial surveillance are too common to ID someone with a good probability.

Exploits, on other hand, can leak your full environment, including a photo from the cam.

Re: Infosec 101 for Activists

#117
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

[flagged]

They literally got a pardons for murdering people. Please check your priors.

Re: Infosec 101 for Activists

#118
post #94
post #77

Earlier quoted context omitted.

The ones that don't end up shut down, in legal trouble or in jail. See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.

> Telegram You know that Telegram is giving plenty much of information in these days? They even changed the privacy policy. https://techstartups.com/2024/09/06/telegram-silently-update...

Yeah, after they got into trouble with the law

Re: Infosec 101 for Activists

#119
post #69

Earlier quoted context omitted.

As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks th…

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

Asking them to is different than a warrant, they are free to refuse without one.
Post reply on HN