Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

131–140 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#131

Earlier quoted context omitted.

This is a crazy list. 1. IPhone is closed source and any kind of rootkit can be installed by Apple/NSA secret court system. I suggest not using a smartphone if you are serious about security. 2. Good but difficult to anonymize 3. Good 4. Google Chrome is a botnet effectively and users lose their expectation of privacy there. Should switch to Firefox and use Chromium (Not Chrome) as a backup. Ideally Tor browser thoug…

IPhone is closed source and any kind of rootkit can be installed by Apple/NSA secret court system. I suggest not using a smartphone if you are serious about security. I absolutely disagree. While you are correct that in theory an iPhone can have rootkits and other backdoors installed on it by the NSA, in practice, I've found that the average user's computer can be compromised far more easily than their smartphone. Re…

> It's letting the perfect be the enemy of the good.

We are talking activists facing state-sponsored attackers, where "good" security is not enough.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#132
post #63

Earlier quoted context omitted.

> Aside from Apple appearing on a PRISM slide deck That's far from a random mistake..

No doubt they may have been pwned, either by infiltration or other means. There's no evidence of them (ala Yahoo) complying with the NSA

I remember one of the slides implied that Microsoft did comply without much resistance.

I'll see if I can dig it up.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#134
post #18
post #7

I would absolutely start by running a threat modeling exercise, as that will help you focus on the important things and tune out unnecessary FUD (e.g. do you really need to PGP-encrypt everything and run TAILS if you're not being targeted by the NSA?). Once you have an understanding of what you need to protect and who your main adversaries are, choosing the right tools should become more straightforward. My favorite…

Ross Ulbricht was crushed by a mountain of evidence generated by the FBI simply by snatching his laptop from him when he was arrested and not allowing FDE to kick in. Had he compartmentalized and separately encrypted his files, much of that evidence might not have been available to the court. That might have been the difference between a few years in prison and the rest of his natural life. So, the idea that people s…

MLK's inner circle of most trusted associates included a photographer who was an FBI informant.

It may limit your choices for civil disobedience that breaks laws, but the only reasonable assumption is that if a state actor wants access to your information, they will get it. I suggest reading "This is an Uprising" which has a fantastic history of activism.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#135
post #33

Earlier quoted context omitted.

> Get an iPhone and use it in preference to your computer. When connecting to a computer or charging, never ever tap on "trust this computer". If I understand it right "trusting this computer" involves some irrevocable certificate exchange, in effect granting the computer elevated permissions. Can someone correct me? What precisely "trusting" on iphone means except from the ability to decrypt backups? Also: Don't use…

It's revocable: https://support.apple.com/en-us/HT202778 It's anyway not a great idea to plug anything into strange USB ports.

USB condoms - http://www.portablepowersupplies.co.uk/portapow-fast-charge-...

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#136
post #68

Earlier quoted context omitted.

Since you have a lot of women, I will suggest that you explicitly instruct them to be careful about talking about other people in their lives in identifiable terms. Men tend to invest their identity in their work. Women tend to invest their identity in their relationships. Telling anecdotes about "My sister/boss/mother/daughter/son/husband" is potentially putting those people at risk. Encourage them to use vaguer ter…

Maybe some of the onlookers don't know that you have long identified yourself as a woman here. As I recall, we (you and I) eventually figured out that we first "met" on an online community before Hacker News was founded.

As promised: http://micheleincalifornia.blogspot.com/2017/01/infosec-1-in...

You are free to use it, or not, to help your group get oriented.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#137

Earlier quoted context omitted.

I do this too but it conflicts with tptacek's injunction above to "not use Dropbox."

I'm not sure why tptacek specifically warns against using Dropbox. My guess (and I emphasize that this is just a guess) is that you can't rely on Dropbox (or Google Drive or Microsoft OneDrive) to keep your data out of the hands of a state-level adversary. However, encrypting your data before putting it into Dropbox should address that concern. Is there something I'm missing? Is it that cloud folders like Dropbox mak…

Why paint a target on your back?

If you have a device that's relatively well hardened against attack, why subvert those protections by giving a copy of your secrets to a third party who isn't (and can't be, from a legal standpoint) as well protected?

Why give a copy of your secrets to an adversary that's 10 to 20 years ahead of the rest of the world, crypto-analytically speaking?

In short, make them work for it.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#138
post #55
post #34

Earlier quoted context omitted.

There are several gradations more security we could specify if we relaxed the constraint that ordinary non-technical activists be able to reliably do things. The level of protection you're getting here is from targeted non-state attackers, ambient opportunistic state-level actors, and non-specialist law enforcement. Some of this stuff would have helped Ross Ulbricht (I mean that non-normatively), for instance. Google…

Googling that phrase leads to one of your tweets which has a no longer valid link(redirects to the microsoft research homepage). Edit: I presume this is the intended article: https://www.usenix.org/system/files/1401_08-12_mickens.pdf

Yes, that's the one.
Post reply on HN