Earlier quoted context omitted.
Framing the question a bit differently could help: The aim should be to engineer the system so that you don't (and can't) have access to the information, so you minimize vulnerability to legal attacks. A strawman mod to protonmail could be to mandate the use of a VPN
> The aim should be to engineer the system so that you don't (and can't) have access to the information So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?
Infosec 101 for Activists
151–160 of 220 posts
Re: Infosec 101 for Activists
#152Earlier quoted context omitted.
Yep, Cellebrite is popular among LE and my phone (a new Pixel) is able is be extracted. Even if I install a privacy OS such as GrapheneOS, I don't think it would help. The Librem phone looks nice, but it costs a lot and the camera/specs are bad.
Exactly. Just don't commit crimes and don't use a phone/computer to commit crimes thinking you will get away with it. It doesn't work, they know who you are and what you did. It's really simple.
Re: Infosec 101 for Activists
#153Can the full might of the fbi and nsa own you of they want? Likely.
The threat model here is local PD, and the goal is to make their job of incriminating you in any way, harder. Meaning making it harder to get into your phone. Harder to passively intercept data like sms and phone calls. Harder to get days by asking the big companies like google.
Re: Infosec 101 for Activists
#154One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…
[flagged]
To me, a blanket pardon appears very problematic because I firmly believe that the underlying action (violent protest directly aimed at government representatives) was and is still a crime (I think that a group of protestors similarly storming the capitol or white house now would --and should-- not be pardoned either).
The whole thing is even more problematic because it basically directly rewards for loyalty to a person over the country/democratic ideals.
Personally, I have no doubt that a lot of them were honest, well-meaning protestors that caused little harm-- but definitely not all of them.
Commutations done for individual cases would have been much less problematic in my view.
Re: Infosec 101 for Activists
#155Earlier quoted context omitted.
As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks th…
> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?
That's a good question.
https://en.wikipedia.org/wiki/Apple–FBI_encryption_dispute
As a result of this, Apple released a series of tools such as iCloud Advanced Security where they don't even have the keys (but causes user support issues, users can now "lose everything" with no recourse, which is why this isn't on by default; most users' "threat model" is more risk from deleting themselves accidentally than of nation state disclosure), along with the new feature that a phone not being actively used turns itself, off, and a few more things.
// See also: https://www.wired.com/story/the-time-tim-cook-stood-his-grou... or https://archive.is/fvAqN
Re: Infosec 101 for Activists
#156Earlier quoted context omitted.
wut? How is removing biometric auth going to draw attention to yourself? Also, would love to know why this isn't an adequate measure for security.
"realize some" was the comment. you're now assuming that biometric auth is part of that "some". assuming can get you into trouble. if biometric auth does not bring attention to yourself, that does not negate the validity of the comment. people just need to calm down with the "gotcha" comments
Just take the fucking L and move on. Christ.
Re: Infosec 101 for Activists
#157Earlier quoted context omitted.
Blocking a highway is not an act of violence, it is a form of peaceful protest. Like a diner sit-in. You are free to correct your post to explain all the acts of violence you saw which justify the term "riot".
A physical action (like occupying infrastructure) that limits other people’s freedom to move, or brings harm to them or their property, is a violent act to most people. The only people that would claim otherwise are those who want to downplay illegal acts that align with their own politics. Here’s a definition for ‘violence’, so you’re clear on how blocking highways is violence: > violence: an unjust or unwarranted e…
To be clear you're suggesting standing in the street constitutes:
> a violent takeover of public infrastructure
I suppose sitting in a diner which people didn't want you sitting in would also constitute, "A violent takeover of a private establishment".
Re: Infosec 101 for Activists
#158Earlier quoted context omitted.
"realize some" was the comment. you're now assuming that biometric auth is part of that "some". assuming can get you into trouble. if biometric auth does not bring attention to yourself, that does not negate the validity of the comment. people just need to calm down with the "gotcha" comments
> : Realize that none of these measures are adequate for that threat model, Just take the fucking L and move on. Christ.
Re: Infosec 101 for Activists
#159Step 1: Determine your threat model. Step 2: Realize that none of these measures are adequate for that threat model, in the current environment. (For pretty much any threat model.) Step 3: Realize that some of these measures draw attention to yourself, however.
This makes a good case for using them all the rest of the time. If you’re in a relatively safe position you can help to normalize privacy to provide cover for those who need it now, and perhaps for yourself should you need it in the future.
Re: Infosec 101 for Activists
#160Earlier quoted context omitted.
[flagged]
Do you think the blanket-pardon for J6 was ethically justifiable? To me, a blanket pardon appears very problematic because I firmly believe that the underlying action (violent protest directly aimed at government representatives) was and is still a crime (I think that a group of protestors similarly storming the capitol or white house now would --and should-- not be pardoned either). The whole thing is even more prob…