Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

201–210 of 220 posts

Re: Infosec 101 for Activists

#201
post #143

Earlier quoted context omitted.

Yep, Cellebrite is popular among LE and my phone (a new Pixel) is able is be extracted. Even if I install a privacy OS such as GrapheneOS, I don't think it would help. The Librem phone looks nice, but it costs a lot and the camera/specs are bad.

Exactly. Just don't commit crimes and don't use a phone/computer to commit crimes thinking you will get away with it. It doesn't work, they know who you are and what you did. It's really simple.

[dead]

Re: Infosec 101 for Activists

#202

Good article, although it stresses the need to have trusted friends to protest with but doesn’t explain how to find, make, keep these friends. To be fair, I’ve been trying to figure that part put for like 10 years but it would be cool to have advice in that area as well. Keep up the good fight!

I think the recommendation is to go to events relevant to your interests, actively contribute, and speak to people.

Re: Infosec 101 for Activists

#203
post #143

Earlier quoted context omitted.

Yep, Cellebrite is popular among LE and my phone (a new Pixel) is able is be extracted. Even if I install a privacy OS such as GrapheneOS, I don't think it would help. The Librem phone looks nice, but it costs a lot and the camera/specs are bad.

Exactly. Just don't commit crimes and don't use a phone/computer to commit crimes thinking you will get away with it. It doesn't work, they know who you are and what you did. It's really simple.

> Just don't commit crimes.

This is a really, really ignorant imperative. First of all, the criminalization of poverty and structural injustice, generally, make technically criminal activity inevitable in some communities, but I recognize that what you actually mean is "don't commit criminal acts of protest" which is still ludicrously ignorant—and cruel!

Civil disobedience, by definition, involves the deliberate violation of a law. It is, nevertheless, our duty to perform when laws or systems perpetuate severe injustices, democratic failures, or lack legitimacy.

As John F. Kennedy famously put it, "Those who make [legal] revolution impossible will make [criminal] revolution inevitable."

This is economics.

Re: Infosec 101 for Activists

#204
post #75

Earlier quoted context omitted.

This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?

>> One of the first things you can do with any of these kinds of lists is to see if they recommend Firefox over Chrome. It's an excellent shibboleth, because Firefox codes (rhetorically) profoundly more activist- and privacy- friendly than Chrome does, but Chrome has much more sophisticated and better tested runtime protections. Firefox seems like it would be the better recommendation, but if what you care about is n…

I still doubt it? It's a marathon, not a sprint; I still trust Firefox more.

Re: Infosec 101 for Activists

#205
post #19

This is ridiculous, just don't use a network of any kind or you'll be tracked by someone somewhere. Simple as that. Misleading people into thinking they can use these tools and be safe is dangerous. I suppose the only way to be safe is to assume you're being tracked somehow and use burners or throw aways that don't matter.

While you’re not wrong, there’s a trade off between communication needs and security guarantees. Activism and protesting requires organization, which is effectively hampered by the inability to quickly and efficiently disseminate information. I’ve read the EFF’s guide and it seemed reasonable for a layman. What caveats or disclaimers would you include that they haven’t already? What more do you feel could be done to…

Staying off the radar is the best advice I think - how to do that is the question. The thing that creeps me out is that even at the operating system level we have no idea what happens... look at Recall. I mean wow.

Re: Infosec 101 for Activists

#206

Earlier quoted context omitted.

>Because if I was running SIGINT at the NSA and collaborating with the FBI to arrest activists, the very first thing I would do is start up a bunch of VPN providers that bill themselves as "private" and then log everything aggressively. Sure. But with a limited budget (of both the financial sort and the effort sort), this just isn't feasible. Who the hell wants to manage not one but twenty seemingly private industry…

> Ulbricht found out the hard way. When you've got every fiber tapped around the world, it becomes trivial to deanonymize Tor users. They didn't find Ulbricht by hacking the Tor network to deanonymize users.

They did, and then they used something called parallel construction (legal term) to not give away the warrantless search that entails. Wanted to avoid fruit of the poison tree, or public backlash, or maybe even both.

Once he was identified, they trolled through his internet history to find something that if they were luckier than any investigators ever they might have found without cheating. Then claimed they actually did that. It was all horseshit. None of this is controversial. Didn't even have to hack Tor, traffic analysis sufficed.

Re: Infosec 101 for Activists

#207
post #97

Step 1: Determine your threat model. Step 2: Realize that none of these measures are adequate for that threat model, in the current environment. (For pretty much any threat model.) Step 3: Realize that some of these measures draw attention to yourself, however.

Please stop with the security nihilism: https://news.ycombinator.com/item?id=27897975 See also: https://qubes-os.org (my daily driver OS).

I think people should know what they're getting into.

Articles of the formula "Want to be an activist or journalist, resisting powerful tyrants? Just install these apps, to be safe!" can be misleading.

Re: Infosec 101 for Activists

#208
post #130

Earlier quoted context omitted.

The only people who died were some of the jan 6 protestors. Check your priors.

You're right, I went back and read and it looks like the officer who died had their stroke ruled as their cause of death, not the blunt force injuries they received, though it was ruled contributing to his cause of death. Upon further reading it looks like they only intended to murder a bunch of people and were prevented from doing so while invading the capitol buildings holding nooses, a completely blameless activit…

If murdering people was on the agenda, believe me they would have come with guns instead of using uncertain means. Your priors still doing ok?

Re: Infosec 101 for Activists

#210

All of their advice is pretty moot because they are saying you should have your phone with you and that alone is going to hit cell towers and put you at the location of the action.

Not so if you EMI tape the GOS phone case, disable USB-C except for charging, use second profile to encrypt your actual data so you can attest before decrypting, and keep it turned off and in aeroplane mode when not in use. See my comments.
Post reply on HN