Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

211–220 of 220 posts

Re: Infosec 101 for Activists

#211
As someone who has decades of tech experience and have been the target of various Government agencies for many years... I have a few things to add:

Most devices have some kind of GPS or positioning system. Phones in particular still communicate certain information to cell towers and E911 even if there is no SIM installed. Wrapping your phone in aluminum foil does not block all the signals as many have been lead to believe. It is not certain, especially with 5G what faraday bags can work. Your best bet is a phone where you can remove the battery. Even this could leave residual power in the device.

One of the most non technical aspects of Government surveillance, especially in the United States, is that their ability to request data depends on each specific provider. Usually, law enforcement has long standing relationships with all these companies and the higher up you go in the U.S. Govt, you get more of this. After all, there are a million ways the Govt can keep a device off the market if they do not comply with whatever the Government wants. Maybe most importantly, parallel construction is often used here. For example, law enforcement will only follow the rules and get a warrant if they intend to present a case in court. Often, they just want information and if they want to use it they will find a way to parallel construct its source. Do not rely on your constitutional protections or anything else. In many cases it is simply not a factor for them.

Everything about your phone comes back to the sim card. It is extremely difficult to get a working SIM without some form of ID. Most SIM cards are traceable this way, especially if you purchase them in the U.S. Most services require a form of authentication as well, often a phone number which requires the SIM belong to someone, or an email address, which very often requires a phone number to create. Used burner phones are your best bet.

Any cloud service connection your phone initiates is able to be intercepted and the Govt can deploy a form of a man in the middle decryption attack with the help of your cell provider. This is not used as often but unless everything you have uses certificate pinning, and often this isn't the case, it is very easy to man in the middle your end to end traffic and decrypt it.

Applications also leak like crazy to various APIs and other things they use. Connections can be downgraded to HTTP and all other forms of tricks to monitor you are used.

For example, if you are using an end to end encrypted messaging app, and you have the content of those messages going to the apple or google notification system, you do not have end to end encrypted messaging. This is why Signal disables the content in the notification by default.

There are other attack surfaces here as well. Keyboard autocomplete is one as it uses remote services. If LE knows you are using something like Signal, and they can see you created a new contact on your phone to message them, they already know who you are talking to you, and if your phone keyboard is using autocomplete or grammar correct, they could potentially get what both sides are writing to each other without actually breaking the encryption.

There are other methods as well. iPhones have the ability to use a form of Remote Desktop that can be accessed over the cell connection. So as you are using the app, your screen can be monitored, thus defeating any encryption security you think you have.

If Law enforcement knows you have cloud accounts, say with iCloud or Google Docs, and you are working on something in there, you can be sure that it is possible for your work to be viewed as you are working on it. This has a ton of implications for people just doing normal non activist work as well. Maybe you're working on your own legal case and they can literally just watch you build a legal defense and then plan accordingly. It really is endless what they can do.

If the Govt is interested in you, most cities are full surveillance cities now. You can have no phone, no RFID anything, change your routes, change your appearance and you will still be found. There are rare exceptions to this but for the most part assume you cannot move around a city without being constantly monitored. Even if you only have a pair of bluetooth headphones, there are all kinds of devices collecting broadcast data, and these can be correlated with device lists uploaded when you pair a device.

This is just a short list of things I've experienced personally... There is so much more. Any large formal resistance basically cannot happen without the Govt knowing about it.

EDIT: Sorry for the wall of text

Re: Infosec 101 for Activists

#212
post #210

All of their advice is pretty moot because they are saying you should have your phone with you and that alone is going to hit cell towers and put you at the location of the action.

Not so if you EMI tape the GOS phone case, disable USB-C except for charging, use second profile to encrypt your actual data so you can attest before decrypting, and keep it turned off and in aeroplane mode when not in use. See my comments.

Your phone going “dark” during an action is in itself a signal that you are involved in the action. Especially when it deviates from your phones normal activity patterns.

It would make more sense to leave your phone on and at home. However, you can’t use any of the tools the articles lists if you have no phone.

Re: Infosec 101 for Activists

#213

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

While I agree they should be "neutral" that is a hilarious and desperate attempt of a hit-piece while ignoring the valid criticism.

I guess that is to be expected by msm, good promo for proton imo.

Re: Infosec 101 for Activists

#214
post #69

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks th…

Service has to follow the law more breaking news at 11....they even before this have always advocated to use a VPN or Tor if your threat model is law enforcement.

Re: Infosec 101 for Activists

#215

Earlier quoted context omitted.

> by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?

> how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system That's a good question. https://en.wikipedia.org/wiki/Apple–FBI_encryption_dispute As a result of this, Apple released a series of tools such as iCloud Advanced Security where they don't even have the keys (but causes user support issues, users can now "lose everything" with no recourse, which is why t…

There exist different laws for different services. There VPN for example is exempt from the court order that got the IP while using there mail service.

https://protonvpn.com/blog/threat-model/

Re: Infosec 101 for Activists

#216
post #142

Hesitant to recommend proton since they can't stay out of politics, I don't think mullvad has any similar slipups: https://theintercept.com/2025/01/28/proton-mail-andy-yen-tru...

Proton has complied with legal orders and implemented JS to target a user. Mullvad is nice.

Nice FUD. They don't need to "implement JS" to get simple connection logs.

Re: Infosec 101 for Activists

#217
post #40

Earlier quoted context omitted.

A more constructive response is to explain why it won't work.

A more constructive response is to explain why it won't work, rather than telling me to explain why it won't work. My first post in this thread has a link that explains why VPN services aren't trustworthy. But the thing I took more issue with is that Tor is omitted entirely. Tor is at least as safe as a VPN. Trying to attack Tor users by registering exit nodes (a Sybil attack) is way more expensive than convincing us…

Or you know just use both because even the most shady VPN is more trustworthy than any ISP. There of course is always the option to just use a trustworthy vpn that even implements traffic analysis protection like mullvad

Re: Infosec 101 for Activists

#218

Rule 0: DO NOT BRING YOUR PHONE TO PROTESTS. I cannot stress this enough. We survived protests without them in the past. There will be plenty of professionals filming anything going on. Coordination needs to be zero tech.

This is the right answer. Bring a map and an action camera, maybe a burner dumbphone.

Re: Infosec 101 for Activists

#219
post #210

Earlier quoted context omitted.

Not so if you EMI tape the GOS phone case, disable USB-C except for charging, use second profile to encrypt your actual data so you can attest before decrypting, and keep it turned off and in aeroplane mode when not in use. See my comments.

Your phone going “dark” during an action is in itself a signal that you are involved in the action. Especially when it deviates from your phones normal activity patterns. It would make more sense to leave your phone on and at home. However, you can’t use any of the tools the articles lists if you have no phone.

That's why you keep it offline at all times! And for calls use something dumb & leave that at home.

Re: Infosec 101 for Activists

#220

Earlier quoted context omitted.

> Why? Because if I was running SIGINT at the NSA and collaborating with the FBI to arrest activists, the very first thing I would do is start up a bunch of VPN providers that bill themselves as "private" and then log everything aggressively. The second thing I would do is have useful idiots (i.e., influencers) spread vague anecdotes about Tor users being "de-anonymized" when VPN users are never "anonymized" to begin…

>Because if I was running SIGINT at the NSA and collaborating with the FBI to arrest activists, the very first thing I would do is start up a bunch of VPN providers that bill themselves as "private" and then log everything aggressively. Sure. But with a limited budget (of both the financial sort and the effort sort), this just isn't feasible. Who the hell wants to manage not one but twenty seemingly private industry…

> with a limited budget (of both the financial sort and the effort sort)

> When you've got every fiber tapped around the world, it becomes trivial

These phrases are in conflict.

If their budget is limited, we shouldn't expect them to be able to trivially tap the whole world.

If tapping the whole world is trivial, they probably have the resources to spin up some VPN front companies. Or more likely, suborn existing VPNs.

Post reply on HN