Earlier quoted context omitted.
It's complicated to explain, but in the republican(/conservative/trump supporter) mind "activists" are (in support of) "far-left marxist communist liberal extremists" like Biden, Obama or Harris, so the FBI/CIA/NSA under the Biden administration were protecting them and calls for making encryption illegal only targeted "the republican" so activists supported ending encryption because it benefited them in their unjust…
It’s not complex to explain. The establishment was all Democrats and they tried to ban encryption. Now the establishment is Republican and the same elites who tried to take away encryption are now using it.
Infosec 101 for Activists
181–190 of 220 posts
Re: Infosec 101 for Activists
#182Earlier quoted context omitted.
Your original comment sounded like (how I read it, at least) you think Chrome should be the default recommend in this (and similar) guides. Full stop, end of story. This comment sounds like you think guides should be more nuanced regarding the specific threat model that is trying to be mitigated. I agree with the second one.
No, I think people should use Chrome. But my actual docket of security advice wasn't the point; my point was: if they got this wrong (and by suggesting that Firefox is a categorically better choice than Chrome, they have), what else did they get wrong? As a security person, I have borne witness to many, many "which browser is really more secure?" or "has Firefox caught up to Chrome?" arguments. I have seen "you shoul…
But that's probably for some other time, I imagine we can leave it at agreeing "this guide is not great". I doubt it is good for my career to butt heads with the tptacek on a security topic.
Re: Infosec 101 for Activists
#183National Lawyers Guild Know Your Rights reminder: Shut the f** up! https://www.youtube.com/watch?v=nWEpW6KOZDs https://www.aclu.org/know-your-rights/stopped-by-police
Re: Infosec 101 for Activists
#184I wonder how many of the posts here saying "this is all useless" actually go to protest, or in their heart support those who do. Can the full might of the fbi and nsa own you of they want? Likely. The threat model here is local PD, and the goal is to make their job of incriminating you in any way, harder. Meaning making it harder to get into your phone. Harder to passively intercept data like sms and phone calls. Har…
Re: Infosec 101 for Activists
#185Earlier quoted context omitted.
No, I think people should use Chrome. But my actual docket of security advice wasn't the point; my point was: if they got this wrong (and by suggesting that Firefox is a categorically better choice than Chrome, they have), what else did they get wrong? As a security person, I have borne witness to many, many "which browser is really more secure?" or "has Firefox caught up to Chrome?" arguments. I have seen "you shoul…
As a security person, I agree that this guide is not great. I agree with pretty much everything you've said. However, I disagree with your original comment that a recommendation in favor of Firefox means writing off a guide entirely. But that's probably for some other time, I imagine we can leave it at agreeing "this guide is not great". I doubt it is good for my career to butt heads with the tptacek on a security to…
I just think it's an interesting way to think about these things. There are a couple recommendations these kinds of guides recurringly make that are "tells" that the people writing it aren't, let's say, super engaged with the communities of expertise the recommendations are meant to be drawn from.
I learned last cycle not to waste too much energy red-penciling security guides; there will be more of them following this one. But I am interested in general rules of thumb for how to read any of them.
For what it's worth, I comment here worrying that 'saurik and 'comex and 'pbsd are at any moment about to hand me my ass. Wherever I am in the heirarchy, it's not close to the top.
Re: Infosec 101 for Activists
#186Earlier quoted context omitted.
As a security person, I agree that this guide is not great. I agree with pretty much everything you've said. However, I disagree with your original comment that a recommendation in favor of Firefox means writing off a guide entirely. But that's probably for some other time, I imagine we can leave it at agreeing "this guide is not great". I doubt it is good for my career to butt heads with the tptacek on a security to…
Oof. I just think it's an interesting way to think about these things. There are a couple recommendations these kinds of guides recurringly make that are "tells" that the people writing it aren't, let's say, super engaged with the communities of expertise the recommendations are meant to be drawn from. I learned last cycle not to waste too much energy red-penciling security guides; there will be more of them followin…
Re: Infosec 101 for Activists
#187One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…
This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?
> This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently.
So the smart thing is to use Chromium, then?
Re: Infosec 101 for Activists
#188Earlier quoted context omitted.
See, this is what I'm talking about. If you're trying to protect activists from threats, protect them from threats. Making a political statement about commercial surveillance isn't doing that. A lot of these guides are LARPs. How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're re…
>commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages Is Firefox more susceptible to RCE exploits?
All I have seen as a casual user is this from GrapheneOS: https://grapheneos.org/usage#web-browsing
It asserts that Chromium has much better sandboxing and site isolation than Firefox.
Re: Infosec 101 for Activists
#189Keep up the good fight!
Re: Infosec 101 for Activists
#190Earlier quoted context omitted.
> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?
The ones that don't end up shut down, in legal trouble or in jail. See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.