Live data from Hacker News

How to encrypt your entire life in less than an hour

medium.freecodecamp.com

1–10 of 70 posts

Re: How to encrypt your entire life in less than an hour

#2
[Copied from my comment on a duplicate post -- there seems to be random tracking junk at the end of the URL that prevents these from being detected as duplicates!]

I appreciate how practical these tips are and I hope people will follow them.

I have two quarrels with this:

> Andy Grove was a Hungarian refugee who escaped communism [... and] encourages us to be paranoid.

I'm pretty sure that Grove was referring to business strategy, not communications security.

> Congratulations — you can now use the internet with peace of mind that it’s virtually impossible for you to be tracked.

Something I've seen over and over again is that Tor users tend to have a poor understanding of what Tor protects and doesn't protect. The original Tor paper said that Tor (or any technology of its kind) can't protect you against someone who can see both sides of the connection -- including just their timing. Sometimes, some adversaries can see both sides of a person's connection. As The Grugq and others have documented, Tor users like Eldo Kim and Jeremy Hammond were caught by law enforcement because someone was monitoring the home and university networks from which they connected to Tor and saw that they used Tor at exactly the same time or times as the suspects did. (In Hammond's case, recurrently, confirming law enforcement's hypothesis about his identity; in Kim's case, only once, but apparently he was the only person at the university who used Tor at that specific time.)

As law enforcement has actually identified Tor users in these cases, I think people need to understand that Tor is not magic and it protects certain things and not other things. In fact, I helped to make a chart about this a few years ago:

https://www.eff.org/pages/tor-and-https

This chart was meant to show why using HTTPS is important when you use Tor, but it also points to other possible attacks (including an end-to-end timing correlation attack, represented in the chart by NSA observing the connection at two different places on the network) because many people in the picture know something about what the user is doing.

I've been a fan of Tor for many years, but I think we have to do a lot better at communicating about its limitations.

Re: How to encrypt your entire life in less than an hour

#3
post #2

[Copied from my comment on a duplicate post -- there seems to be random tracking junk at the end of the URL that prevents these from being detected as duplicates!] I appreciate how practical these tips are and I hope people will follow them. I have two quarrels with this: > Andy Grove was a Hungarian refugee who escaped communism [... and] encourages us to be paranoid. I'm pretty sure that Grove was referring to busi…

Re: Tor. It's very effective but users must read the documentation not just plug and play.

Re: How to encrypt your entire life in less than an hour

#4
Isn't 2FA considered dangerous now? We've seen how susceptible it can be to social engineering.

On a related note, I noticed that my Windows Phone displays text message notifications even when it's locked... So adding a PIN doesn't prevent an attacker from doing 2FA if they have access to my phone.

Re: How to encrypt your entire life in less than an hour

#5
post #4

Isn't 2FA considered dangerous now? We've seen how susceptible it can be to social engineering. On a related note, I noticed that my Windows Phone displays text message notifications even when it's locked... So adding a PIN doesn't prevent an attacker from doing 2FA if they have access to my phone.

There were also cases of attackers tampering with the phone system to intercept 2FA tokens. Much better is authenticator-app-based or hard-token-based 2FA.

Re: How to encrypt your entire life in less than an hour

#7
post #3
post #2

[Copied from my comment on a duplicate post -- there seems to be random tracking junk at the end of the URL that prevents these from being detected as duplicates!] I appreciate how practical these tips are and I hope people will follow them. I have two quarrels with this: > Andy Grove was a Hungarian refugee who escaped communism [... and] encourages us to be paranoid. I'm pretty sure that Grove was referring to busi…

Re: Tor. It's very effective but users must read the documentation not just plug and play.

What do you think most users get wrong when they do it "plug and play". What steps does reading the documentation have you do that makes it safer?

Re: How to encrypt your entire life in less than an hour

#8
post #4

Isn't 2FA considered dangerous now? We've seen how susceptible it can be to social engineering. On a related note, I noticed that my Windows Phone displays text message notifications even when it's locked... So adding a PIN doesn't prevent an attacker from doing 2FA if they have access to my phone.

SMS 2FA isn't safe at least, and even NIST is deprecating it. The rest depends on dumb implementations, like Paypal allowing 2FA bypass with a change of the login link, or Google allowing 2FA bypass of all of its other methods by forcing you to use a phone number as "backup", which is to 2FA what secret questions were to passwords (their Achilles's heel).

Re: How to encrypt your entire life in less than an hour

#9
post #6

I tried using Signal but the problem is no one else wants to. So yeah I'd love e2e encryption but it requires both parties to use it, which is a problem.

For iOS, iMessage is usually sufficient for most people, so I can see why they don't bother with other stuff.
Post reply on HN