Live data from Hacker News

Infosec 101 for Activists

infosecforactivists.org

131–140 of 220 posts

Re: Infosec 101 for Activists

#131
post #118
post #94

Earlier quoted context omitted.

> Telegram You know that Telegram is giving plenty much of information in these days? They even changed the privacy policy. https://techstartups.com/2024/09/06/telegram-silently-update...

Yeah, after they got into trouble with the law

In trouble.. France keeps the CEO hostage and blackmails him with decades of jail for numerous crimes committed over Telegram.

Re: Infosec 101 for Activists

#133

Earlier quoted context omitted.

> The aim should be to engineer the system so that you don't (and can't) have access to the information So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?

https://signal.org/bigbrother/

> https://signal.org/bigbrother/ > "When legally forced to provide information to government or law enforcement agencies, we'll disclose the transcripts of that communication here"

Sure, except if there's a nondisclosure provision...

"A national security letter is an administrative subpoena issued by the United States government to gather information for national security purposes. NSLs do not require prior approval from a judge. NSLs typically contain a nondisclosure requirement forbidding the recipient of an NSL from disclosing the FBI had requested the information."

https://en.wikipedia.org/wiki/National_security_letter

Re: Infosec 101 for Activists

#134
post #79
post #75

Earlier quoted context omitted.

This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently. Shouts to the heroes on the inside, but what did I just hear about an AI removal pledge?

See, this is what I'm talking about. If you're trying to protect activists from threats, protect them from threats. Making a political statement about commercial surveillance isn't doing that. A lot of these guides are LARPs. How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're re…

[deleted]

Re: Infosec 101 for Activists

#135
post #97

Step 1: Determine your threat model. Step 2: Realize that none of these measures are adequate for that threat model, in the current environment. (For pretty much any threat model.) Step 3: Realize that some of these measures draw attention to yourself, however.

wut?

How is removing biometric auth going to draw attention to yourself? Also, would love to know why this isn't an adequate measure for security.

Re: Infosec 101 for Activists

#137
It's hard for me to believe that people actually think they can use Signal or some other 'security app' on a device that is fundamentally compromised already.

Sure, your messages are encrypted, but they (whoever they are) have the private keys (both sender and receiver) because the smart phones you are using are compromised by them.

It's really simple.

So next time you read a news story about criminals who were using some supposedly secure app to commit crimes, but got caught anyway... keep this in mind.

Re: Infosec 101 for Activists

#138

I personally don't believe basic measures like turning off location services as suggested by the article will make a difference against a sophisticated adversary like a state actor. We know that modern phones are full of proprietary firmware with swiss cheese tier security which allow for 0 day remote code execution exploits [1]. The operating systems, although better, also have been targeted by RCE exploits [2]. Not…

> sophisticated adversary

are these sophisticated adversaries in the room with us right now?

Most people are completely missing the point in this thread.

The idea that you'll be arrested by some super secret state actors and not Jim Bob the police dude is absurd.

Re: Infosec 101 for Activists

#139
If I'm going to be involved in something like this I'm sure as hell not bringing my daily driver phone. Get serious. Grab a burner, go in expecting it to get discarded or to fall into unfriendly hands.

Re: Infosec 101 for Activists

#140
post #16

Earlier quoted context omitted.

Also note that repeatedly invoking your right to remain silent is going to be considered "resisting arrest" and you're going to get the shit kicked out of you. And then they send you the bill for shoe polish.

Telling people how violent the police are tends to get applause in some circles online, but spreading misinformation that you can't get away with exercising your rights is pretty straightforwardly pro -police propaganda. The vast majority of police officers in the US will not kick you if you say you don't want to talk to them.

The correct number of police officers beating the shit out of you is zero. Not a tiny minority; zero.

And every time one is uncovered, it is always the case that they've done it before, many times. That "vast majority" may not kick the shit out of you, but they seem willing to tolerate it when others do.

It's even worse at protests, when police officers have been told to expect violence. When you go to a protest, you assume that you are taking physical risks.

Post reply on HN