Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

181–190 of 220 posts

Re: Infosec 101 for Activists

#181

Earlier quoted context omitted.

It's complicated to explain, but in the republican(/conservative/trump supporter) mind "activists" are (in support of) "far-left marxist communist liberal extremists" like Biden, Obama or Harris, so the FBI/CIA/NSA under the Biden administration were protecting them and calls for making encryption illegal only targeted "the republican" so activists supported ending encryption because it benefited them in their unjust…

It’s not complex to explain. The establishment was all Democrats and they tried to ban encryption. Now the establishment is Republican and the same elites who tried to take away encryption are now using it.

Of course it's easy for you to say, but the rest of us do need some explanation to understand what you believe. I assume you aren't against encryption being widely available despite the elites/activists using it for nefarious purposes though? Like you are just pointing out the far-lefts hypocrisy when they tried to ban it before?

Re: Infosec 101 for Activists

#182

Earlier quoted context omitted.

Your original comment sounded like (how I read it, at least) you think Chrome should be the default recommend in this (and similar) guides. Full stop, end of story. This comment sounds like you think guides should be more nuanced regarding the specific threat model that is trying to be mitigated. I agree with the second one.

No, I think people should use Chrome. But my actual docket of security advice wasn't the point; my point was: if they got this wrong (and by suggesting that Firefox is a categorically better choice than Chrome, they have), what else did they get wrong? As a security person, I have borne witness to many, many "which browser is really more secure?" or "has Firefox caught up to Chrome?" arguments. I have seen "you shoul…

As a security person, I agree that this guide is not great. I agree with pretty much everything you've said. However, I disagree with your original comment that a recommendation in favor of Firefox means writing off a guide entirely.

But that's probably for some other time, I imagine we can leave it at agreeing "this guide is not great". I doubt it is good for my career to butt heads with the tptacek on a security topic.

Re: Infosec 101 for Activists

#183
post #4

National Lawyers Guild Know Your Rights reminder: Shut the f** up! https://www.youtube.com/watch?v=nWEpW6KOZDs https://www.aclu.org/know-your-rights/stopped-by-police

Are there equivalent resources for other countries? I am from Belgium?

Re: Infosec 101 for Activists

#184

I wonder how many of the posts here saying "this is all useless" actually go to protest, or in their heart support those who do. Can the full might of the fbi and nsa own you of they want? Likely. The threat model here is local PD, and the goal is to make their job of incriminating you in any way, harder. Meaning making it harder to get into your phone. Harder to passively intercept data like sms and phone calls. Har…

*harder to get data by asking

Re: Infosec 101 for Activists

#185

Earlier quoted context omitted.

No, I think people should use Chrome. But my actual docket of security advice wasn't the point; my point was: if they got this wrong (and by suggesting that Firefox is a categorically better choice than Chrome, they have), what else did they get wrong? As a security person, I have borne witness to many, many "which browser is really more secure?" or "has Firefox caught up to Chrome?" arguments. I have seen "you shoul…

As a security person, I agree that this guide is not great. I agree with pretty much everything you've said. However, I disagree with your original comment that a recommendation in favor of Firefox means writing off a guide entirely. But that's probably for some other time, I imagine we can leave it at agreeing "this guide is not great". I doubt it is good for my career to butt heads with the tptacek on a security to…

Oof.

I just think it's an interesting way to think about these things. There are a couple recommendations these kinds of guides recurringly make that are "tells" that the people writing it aren't, let's say, super engaged with the communities of expertise the recommendations are meant to be drawn from.

I learned last cycle not to waste too much energy red-penciling security guides; there will be more of them following this one. But I am interested in general rules of thumb for how to read any of them.

For what it's worth, I comment here worrying that 'saurik and 'comex and 'pbsd are at any moment about to hand me my ass. Wherever I am in the heirarchy, it's not close to the top.

Re: Infosec 101 for Activists

#186

Earlier quoted context omitted.

As a security person, I agree that this guide is not great. I agree with pretty much everything you've said. However, I disagree with your original comment that a recommendation in favor of Firefox means writing off a guide entirely. But that's probably for some other time, I imagine we can leave it at agreeing "this guide is not great". I doubt it is good for my career to butt heads with the tptacek on a security to…

Oof. I just think it's an interesting way to think about these things. There are a couple recommendations these kinds of guides recurringly make that are "tells" that the people writing it aren't, let's say, super engaged with the communities of expertise the recommendations are meant to be drawn from. I learned last cycle not to waste too much energy red-penciling security guides; there will be more of them followin…

except about SOC2

Re: Infosec 101 for Activists

#187
post #75
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?

>> One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not being easily (==cheaply) targeted by exploits, it's not.

> This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently.

So the smart thing is to use Chromium, then?

Re: Infosec 101 for Activists

#188
post #79

Earlier quoted context omitted.

See, this is what I'm talking about. If you're trying to protect activists from threats, protect them from threats. Making a political statement about commercial surveillance isn't doing that. A lot of these guides are LARPs. How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're re…

>commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages Is Firefox more susceptible to RCE exploits?

I would like more input on this. Maybe I'll ask Claude.ai later.

All I have seen as a casual user is this from GrapheneOS: https://grapheneos.org/usage#web-browsing

It asserts that Chromium has much better sandboxing and site isolation than Firefox.

Re: Infosec 101 for Activists

#189
Good article, although it stresses the need to have trusted friends to protest with but doesn’t explain how to find, make, keep these friends. To be fair, I’ve been trying to figure that part put for like 10 years but it would be cool to have advice in that area as well.

Keep up the good fight!

Re: Infosec 101 for Activists

#190
post #77

Earlier quoted context omitted.

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

The ones that don't end up shut down, in legal trouble or in jail. See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.

You forgot the mother of all: QWest.
Post reply on HN