Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

191–200 of 220 posts

Re: Infosec 101 for Activists

#191

Earlier quoted context omitted.

That's what makes it effective. That's the point. A protest that doesn't affect anyone is just performative. Protests aren't to spread the word. It's to jam up the gears, aka, sabotage, to make leaders act. "You're just making us late to work, it's not causing us to join your side!" Jamming up commerce and the functions of a city is how you get people to act. Not by filling out a permit to have a block party in a par…

Unfortunately our leaders have successfully convinced the masses that it's only acceptable to protest as long as they do it at a scheduled time and place, without disrupting or offending anyone, and without any implicit threats of escalation and violence if the protestors' grievances aren't heard and rectified. That way people can vent to temporarily release frustration but we're powerless to effect any meaningful ch…

Yep and our country doesn't have a history of beheading or tossing leaders out of windows like Europe does which gives us a faux sense of being more civilized, or above it. Violence isn't always the answer, but sometimes it's the only answer.

Re: Infosec 101 for Activists

#192
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

Given that Google has vast resources, someone with no background in security should still be able to infer that Chrome is likely to be more secure.

On this topic, I wonder if Chrome’s safe browsing notably improves the user’s security?

It sends user’s private data to Google for scanning. The trade off has to worth it.

Re: Infosec 101 for Activists

#193

Earlier quoted context omitted.

> Why? Because if I was running SIGINT at the NSA and collaborating with the FBI to arrest activists, the very first thing I would do is start up a bunch of VPN providers that bill themselves as "private" and then log everything aggressively. The second thing I would do is have useful idiots (i.e., influencers) spread vague anecdotes about Tor users being "de-anonymized" when VPN users are never "anonymized" to begin…

>Because if I was running SIGINT at the NSA and collaborating with the FBI to arrest activists, the very first thing I would do is start up a bunch of VPN providers that bill themselves as "private" and then log everything aggressively. Sure. But with a limited budget (of both the financial sort and the effort sort), this just isn't feasible. Who the hell wants to manage not one but twenty seemingly private industry…

> Ulbricht found out the hard way. When you've got every fiber tapped around the world, it becomes trivial to deanonymize Tor users.

They didn't find Ulbricht by hacking the Tor network to deanonymize users.

Re: Infosec 101 for Activists

#194

For someone in the know: what's the credibility of the authors on this topic? I see https://infosecforactivists.org/#acknowledgments and https://github.com/InfosecForActivistsTeam/infosec-activists... but I don't see their experience following their own advice. The document by itself looks unpolished. Tor, for example, should be at least referenced once, even if they recommend against it.

Can't speak for OP's link, but as a contrast No Trace Project's resources contain lots of advice from people who actually routinely face state repression, with in-depth analysis of specific cases. The scope is international (though focused on the North Atlantic region) rather than english- & u.s.-exclusive. There are plenty of references to Tor+Tails. https://www.notrace.how/ http://i4pd4zpyhrojnyx5l3d2siauy4almteocq…

Thanks for the links. It's a bit annoying that OP's link turned out to be a LARP; I hope no one actually relies on those people for their security.

Re: Infosec 101 for Activists

#195
post #192
post #67

One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is not…

Given that Google has vast resources, someone with no background in security should still be able to infer that Chrome is likely to be more secure. On this topic, I wonder if Chrome’s safe browsing notably improves the user’s security? It sends user’s private data to Google for scanning. The trade off has to worth it.

This is another part of what I mean: people on message boards read these things as message board arguments, oblivious to the fact that the whole point of these guides, if they're for real, is to communicate with people who are making absolutely none of these inferences.

Re: Infosec 101 for Activists

#196

Earlier quoted context omitted.

It’s not complex to explain. The establishment was all Democrats and they tried to ban encryption. Now the establishment is Republican and the same elites who tried to take away encryption are now using it.

Of course it's easy for you to say, but the rest of us do need some explanation to understand what you believe. I assume you aren't against encryption being widely available despite the elites/activists using it for nefarious purposes though? Like you are just pointing out the far-lefts hypocrisy when they tried to ban it before?

I am not on either side of the 2 party system. I am pointing out the hilarity of former members of the panopticon now understanding the value of privacy preserving technologies.

Re: Infosec 101 for Activists

#197

Earlier quoted context omitted.

Of course it's easy for you to say, but the rest of us do need some explanation to understand what you believe. I assume you aren't against encryption being widely available despite the elites/activists using it for nefarious purposes though? Like you are just pointing out the far-lefts hypocrisy when they tried to ban it before?

I am not on either side of the 2 party system. I am pointing out the hilarity of former members of the panopticon now understanding the value of privacy preserving technologies.

Ahh I see a liber - but no of course labels don't apply to me - tarian, they tend to believe the same nonsense trumpists believe nowadays so it can be hard to tell sometimes

Re: Infosec 101 for Activists

#198

Earlier quoted context omitted.

I am not on either side of the 2 party system. I am pointing out the hilarity of former members of the panopticon now understanding the value of privacy preserving technologies.

Ahh I see a liber - but no of course labels don't apply to me - tarian, they tend to believe the same nonsense trumpists believe nowadays so it can be hard to tell sometimes

I don’t care if you call me names or say my beliefs are nonsense. I’m most enthused now that so much government funded “nonsense” is being defunded, and all of the federal and NGO employees being fired, so they can be free to actually contribute to society.

Re: Infosec 101 for Activists

#199

Earlier quoted context omitted.

If your threat model is tracking, then worry about carrying around the 24/7 tracking device more than the specific software you run on it.

Isn't it the software which is tracking you? You can switch off the cellular connection whenever you need to not be tracked by the towers ( if you trust your software, or with a hardware switch on some phones).

See, again: this is how message board logic turns these kinds of guides into LARPs. "Turn off your cellular connection whenever you need to not be tracked. Also use ProtonVPN."

Re: Infosec 101 for Activists

#200
post #59

Earlier quoted context omitted.

Interesting. I read an article stating the opposite. That to organise effective action on the ground, smart protesters were distracting the anti violence bleeding hearts while discussing and implementing more effective actions. In particular it was stated that part of those particular riots were a distraction to (successfully iirc) lure the cops away from the police station.

> I read an article stating the opposite. Please share a link then. > That to organise effective action on the ground, smart protesters were distracting the anti violence bleeding hearts while discussing and implementing more effective actions. There's a lot to be unpacked there, but I'm not sure about what you think is "effective action" and why peaceful demonstrators are a bad thing. Here's a study that backs up my…

I will have a best effort look for an old article but I cant guarantee anything.

>Here's a study that backs up my initial statement

They wanted the cop, or at worst the building to burn. Peaceful protests were never going to achieve either. They managed 1/2.

Post reply on HN