Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

141–150 of 220 posts

Re: Infosec 101 for Activists

#141
post #97

Step 1: Determine your threat model. Step 2: Realize that none of these measures are adequate for that threat model, in the current environment. (For pretty much any threat model.) Step 3: Realize that some of these measures draw attention to yourself, however.

wut? How is removing biometric auth going to draw attention to yourself? Also, would love to know why this isn't an adequate measure for security.

"realize some" was the comment. you're now assuming that biometric auth is part of that "some". assuming can get you into trouble. if biometric auth does not bring attention to yourself, that does not negate the validity of the comment.

people just need to calm down with the "gotcha" comments

Re: Infosec 101 for Activists

#142

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

Proton has complied with legal orders and implemented JS to target a user. Mullvad is nice.

Re: Infosec 101 for Activists

#143

It's hard for me to believe that people actually think they can use Signal or some other 'security app' on a device that is fundamentally compromised already. Sure, your messages are encrypted, but they (whoever they are) have the private keys (both sender and receiver) because the smart phones you are using are compromised by them. It's really simple. So next time you read a news story about criminals who were using…

Yep, Cellebrite is popular among LE and my phone (a new Pixel) is able is be extracted. Even if I install a privacy OS such as GrapheneOS, I don't think it would help. The Librem phone looks nice, but it costs a lot and the camera/specs are bad.

Re: Infosec 101 for Activists

#144
post #143

It's hard for me to believe that people actually think they can use Signal or some other 'security app' on a device that is fundamentally compromised already. Sure, your messages are encrypted, but they (whoever they are) have the private keys (both sender and receiver) because the smart phones you are using are compromised by them. It's really simple. So next time you read a news story about criminals who were using…

Yep, Cellebrite is popular among LE and my phone (a new Pixel) is able is be extracted. Even if I install a privacy OS such as GrapheneOS, I don't think it would help. The Librem phone looks nice, but it costs a lot and the camera/specs are bad.

Exactly. Just don't commit crimes and don't use a phone/computer to commit crimes thinking you will get away with it. It doesn't work, they know who you are and what you did.

It's really simple.

Re: Infosec 101 for Activists

#145

It's hard for me to believe that people actually think they can use Signal or some other 'security app' on a device that is fundamentally compromised already. Sure, your messages are encrypted, but they (whoever they are) have the private keys (both sender and receiver) because the smart phones you are using are compromised by them. It's really simple. So next time you read a news story about criminals who were using…

If you have evidence of how the secure enclaves on mobile devices are compromised, you should share those details.

You can also believe that there is an industry-wide conspiracy in which everything is backdoored. But that's a philosophical/political claim, not a technical one.

Which type of claim are you making?

Re: Infosec 101 for Activists

#146
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

The majority of activists aren't going to be targeted by a 0-day. Most probably won't even be purposefully, directly targeted. They're more likely to have their data given/sold to the government as part of a larger batch (geo-fence, etc.). I would not recommend a Google product with that considered.

The activists that are legitimately, specifically targeted should probably be past the "101" series of infosec and not be using either without significant other considerations and protections.

Re: Infosec 101 for Activists

#147

Some of the crowd here is already aware of the issues with these recommendations, so let's take things up a level. https://www.notrace.how/ / http://i4pd4zpyhrojnyx5l3d2siauy4almteocqow4bp2lqxyocrfy6pry... https://www.anarsec.guide/

Thanks! This looks like some interesting reading.

Re: Infosec 101 for Activists

#148
> We recommend Signal, which was built from the ground up for personal security.

WhatsApp has E2EE for all messages too, I don't understand why people think of Signal as a bullet-proof instant messaging solution for privacy, especially when

1. Requires Phone Number in order to use (I'm sure fanboys have explanations for that)

2. It is centralized

3. Uses APNs or GCM for push notifications

Re: Infosec 101 for Activists

#149

Serious question: what are the reasons for Firefox over Safari? I'm currently a Firefox user at home and work, but thinking about going back to Safari in the near future...

I use multiple OS's throughout the day. Firefox works on all OS's smoothly. Safari doesn't let you set a custom search engine. Firefox has some great extensions.

Re: Infosec 101 for Activists

#150

> We recommend Signal, which was built from the ground up for personal security. WhatsApp has E2EE for all messages too, I don't understand why people think of Signal as a bullet-proof instant messaging solution for privacy, especially when 1. Requires Phone Number in order to use (I'm sure fanboys have explanations for that) 2. It is centralized 3. Uses APNs or GCM for push notifications

For me, the difference choosing between whatsapp and signal has more to do the who is in, and behind, the respective companies. Liar Zuckerberg lost by fvcking mile.
Post reply on HN