Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

171–180 of 220 posts

Re: Infosec 101 for Activists

#171

Earlier quoted context omitted.

It's complicated to explain, but in the republican(/conservative/trump supporter) mind "activists" are (in support of) "far-left marxist communist liberal extremists" like Biden, Obama or Harris, so the FBI/CIA/NSA under the Biden administration were protecting them and calls for making encryption illegal only targeted "the republican" so activists supported ending encryption because it benefited them in their unjust…

It’s not complex to explain. The establishment was all Democrats and they tried to ban encryption. Now the establishment is Republican and the same elites who tried to take away encryption are now using it.

Many such cases.

Re: Infosec 101 for Activists

#172

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

Proton is still very much worth recommending, you can ignore the noise. The article you linked was debunked in this article which provides overwhelming evidence pointing to the org being liberal: https://www.reddit.com/r/Anarchism/comments/1id5v21/does_pro...

Not that it matters though, since I assume all of us here know how encryption works.

Re: Infosec 101 for Activists

#173
> Intrusion Protection

Any ways to check the current updated official images against what is installed on the phone or notebook via a oneliner or an app?

Like in a couple of minutes like a virus scan.

Burning the hardware is one thing but having confirmation would be nice.

Re: Infosec 101 for Activists

#174
post #8

Earlier quoted context omitted.

Why? I've personally seen more news articles about Tor users getting de-anonymized than I have VPN users. Purely anecdotal, I know, but the point being Tor is obviously not foolproof, so I am curious why recommending one over the other is apparently enough for you to call the entire article into question.

> Why? Because if I was running SIGINT at the NSA and collaborating with the FBI to arrest activists, the very first thing I would do is start up a bunch of VPN providers that bill themselves as "private" and then log everything aggressively. The second thing I would do is have useful idiots (i.e., influencers) spread vague anecdotes about Tor users being "de-anonymized" when VPN users are never "anonymized" to begin…

>Because if I was running SIGINT at the NSA and collaborating with the FBI to arrest activists, the very first thing I would do is start up a bunch of VPN providers that bill themselves as "private" and then log everything aggressively.

Sure. But with a limited budget (of both the financial sort and the effort sort), this just isn't feasible. Who the hell wants to manage not one but twenty seemingly private industry vpn companies? Can they even reach break even status so that it's not a drain on the budget? How long for that? Worse, it entangles their revenue with that of the NSA, making the NSA more vulnerable to the sort of leaks they don't like to have, exposing them to foreign intelligence services and even journalists.

>spread vague anecdotes about Tor users being "de-anonymized" when V

Ulbricht found out the hard way. When you've got every fiber tapped around the world, it becomes trivial to deanonymize Tor users. Granted that it's nearly impossible to climb to the top of the US government's shit list like he did, but if you do manage the feat, they'll know who you are within days.

Re: Infosec 101 for Activists

#175

Earlier quoted context omitted.

A more constructive response is to explain why it won't work, rather than telling me to explain why it won't work. My first post in this thread has a link that explains why VPN services aren't trustworthy. But the thing I took more issue with is that Tor is omitted entirely. Tor is at least as safe as a VPN. Trying to attack Tor users by registering exit nodes (a Sybil attack) is way more expensive than convincing us…

There is one reason- VPN traffic, vs tor traffic monitoring. Tor traffic stands out and that has been used to nab people famously, like that bomb hoax incident. Which suggests cloaking tor with a solid VPN is the way to go. Yes, bridges may be an option as well, but I don't know that their ease of use is where it should be for everyone wanting to be hidden

IIRC they used NetFlow data to find the only Tor user. So as long as your VPN doesn't use a different exit than entry IP it's as easy to find you as the Tor user.

Re: Infosec 101 for Activists

#176
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

The majority of activists aren't going to be targeted by a 0-day. Most probably won't even be purposefully, directly targeted. They're more likely to have their data given/sold to the government as part of a larger batch (geo-fence, etc.). I would not recommend a Google product with that considered. The activists that are legitimately, specifically targeted should probably be past the "101" series of infosec and not…

My new line when people rebut this is just to ask: did the guide we're talking about lay this out, so that people could make up their own mind about whether their organization was likely to be targeted by federal law enforcement agencies, which license zero-day vulnerabilities and delivery platforms from 4-5 different providers, or instead by commercial telemetry?

Of course, none of them do, because the premise of that question is alien to them. It requires understanding that Firefox and Chrome have different runtime security postures, and to talk about that you have to be willing to push through a fogbank of people ideologically opposed to the idea that Chrome could be, at a technical level, better.

Re: Infosec 101 for Activists

#177

Earlier quoted context omitted.

The majority of activists aren't going to be targeted by a 0-day. Most probably won't even be purposefully, directly targeted. They're more likely to have their data given/sold to the government as part of a larger batch (geo-fence, etc.). I would not recommend a Google product with that considered. The activists that are legitimately, specifically targeted should probably be past the "101" series of infosec and not…

My new line when people rebut this is just to ask: did the guide we're talking about lay this out, so that people could make up their own mind about whether their organization was likely to be targeted by federal law enforcement agencies, which license zero-day vulnerabilities and delivery platforms from 4-5 different providers, or instead by commercial telemetry? Of course, none of them do, because the premise of th…

Your original comment sounded like (how I read it, at least) you think Chrome should be the default recommend in this (and similar) guides. Full stop, end of story.

This comment sounds like you think guides should be more nuanced regarding the specific threat model that is trying to be mitigated.

I agree with the second one.

Re: Infosec 101 for Activists

#179

Earlier quoted context omitted.

My new line when people rebut this is just to ask: did the guide we're talking about lay this out, so that people could make up their own mind about whether their organization was likely to be targeted by federal law enforcement agencies, which license zero-day vulnerabilities and delivery platforms from 4-5 different providers, or instead by commercial telemetry? Of course, none of them do, because the premise of th…

Your original comment sounded like (how I read it, at least) you think Chrome should be the default recommend in this (and similar) guides. Full stop, end of story. This comment sounds like you think guides should be more nuanced regarding the specific threat model that is trying to be mitigated. I agree with the second one.

No, I think people should use Chrome. But my actual docket of security advice wasn't the point; my point was: if they got this wrong (and by suggesting that Firefox is a categorically better choice than Chrome, they have), what else did they get wrong?

As a security person, I have borne witness to many, many "which browser is really more secure?" or "has Firefox caught up to Chrome?" arguments. I have seen "you should use Chrome (or Chromium) no matter what" as responses; I have seen "it's complicated" as responses. I have never seen "you should use Firefox no matter what".

Re: Infosec 101 for Activists

#180
post #122

How much does a Firefox 0-day cost these days on the grey market compared to a Chrome 0-day with sandbox escape?

Disproportionally more if you divide it on the user base to get the cost of targeting 1 user when you want them all (and most of evildoers want that exactly).

No, that's not at all how the market for high-end zero-day vulnerabilities work. It's interesting to see people just make random stuff up from first principles. Actual market participants have talked through this stuff; you can just find out empirically.
Post reply on HN