Live data from Hacker News

The protester's guide to smartphone security

privacyguides.org

181–190 of 246 posts

Re: The protester's guide to smartphone security

#181
post #3

If you're attending a large-scale protest, it's likely that the cell-towers (or stingrays) won't be able to handle everyone who is connected anyways, so worth planning to use apps that can chat over P2P WiFi or Bluetooth together with the rest of your friends. This also allows you to continue using Airplane Mode the entire time, while being able to communicate with people nearby. Alternatively, investing in walkie-ta…

Burner phones aren't safe. Security through obscurity worked with the 1990s cell network but not with today's vast logging/geolocation tagging.

Can you still buy phones with sim cards that don't require ID to get working? Not in Europe, UAE or Australia.

Re: The protester's guide to smartphone security

#182

> However, in this situation it may make more sense to disable biometric authentication. In Face ID, there's a setting that requires direct eye contact in order to open your phone. Highly recommend enabling this when feeling insecure about someone forcing you to open your phone (if it's not already on by default) because it means somebody forcing you to open your phone with Face ID can be easily defeated by simply cl…

While this is good info, it should also be known that in the USA, a judge (maybe and police officer?) can legally command you to unlock your phone via biometrics, but they cannot legally command you to unlock via password or passphrase. “Legally command” = command you to do something with the force of law, and legally punish you if you resist

IANAL, but I think the distinction is that "give us the password that unlocks this" is forcing you to testify against yourself, producing something from your own memory and forcing you to admit ownership/control of the object. (Which might not even be yours.)

In contrast, "the device opened in response to the same fingerprint/face that the suspect has" is a form of world-evidence which doesn't infringe on your mind, much like "the key found in your pocket unlocked the safe."

Re: The protester's guide to smartphone security

#183

Earlier quoted context omitted.

[flagged]

Thankfully this attitude didn't set in during the civil rights movements of the 60s! Or we might still have had separate white and black bathrooms. If we keep following such advice we may again have special water fountains and schools for those other people.

[flagged]

Re: The protester's guide to smartphone security

#184

Earlier quoted context omitted.

Burner phones aren't safe. Security through obscurity worked with the 1990s cell network but not with today's vast logging/geolocation tagging.

Can you still buy phones with sim cards that don't require ID to get working? Not in Europe, UAE or Australia.

> Not in Europe

In Estonia, you could buy a prepaid SIM card in a convenience shop a few years ago, without any sort of ID verification. Not sure if that’s still an option but I think it’s not a priority there. You can then use it all over the EU.

And of course, buying a phone without a contract doesn’t require ID either.

Re: The protester's guide to smartphone security

#185
post #43

Earlier quoted context omitted.

> Briar runs P2P over Tor so they can't collect data, even if they should want to. That makes the common, dangerous, naive assumption that the implementation is secure. Correct, complete, secure implementations are very hard. (It also assumes the design is secure, which is impossible to tell based on that limited information. P2P is not any more secure than over the Internet: In fact, it's easier to identify (there a…

It...depends. If you're not technical, signal is hands down the best solution. If you have a group that's going to something and you are willing to take some extra steps, something like matrix/briar/simplex/whatever setup with a self hosted instance provides you with the knowledge that all the infrastructure is under your control and that the feds just aren't going to have the time to sit down and figure out how this…

What are the bases of your claims about what government authorities do and don't do, what their capabilities and resources are, etc.?

> the feds just aren't going to have the time to sit down and figure out how this shit works.

They have resources many orders of magnitude larger than you. The NSA has tens of billions of dollars per year and five or six figures of personnel. It's you who don't have time.

Re: The protester's guide to smartphone security

#186

Earlier quoted context omitted.

Burner phones aren't safe. Security through obscurity worked with the 1990s cell network but not with today's vast logging/geolocation tagging.

Can you still buy phones with sim cards that don't require ID to get working? Not in Europe, UAE or Australia.

The countries I am familiar with in Europe (NL to name one) you can buy sim cards without any ID. Additionally there's at least 1 provider I know of that's giving them away for free while for the majority you pay 1-5 EUR but get some data after activation. There's no limit on how many you can purchase at once either.

Re: The protester's guide to smartphone security

#187
post #5
post #4

> If you lose your phone, you may be able to locate or wipe your phone remotely depending on the model... > Please be aware of the legal consequences of these actions. Wiping your device or revoking online account access could lead to obstruction of justice or destruction of evidence charges in some jurisdictions. This can be really serious. It is far better to never have/collect/obtain data in the first place.

It got me curious; lets say I go to a protest, lose my phone and wipe it remotely. I couldn't possibly know who exactly got it (since I lost it) so if I remote wipe it while in police custody, could they really get you for "obstruction of justice" for example? Wouldn't that require intent?

If you lost it and no police took it from you, wiping is the normal action.

Re: The protester's guide to smartphone security

#188
post #178
post #3

If you're attending a large-scale protest, it's likely that the cell-towers (or stingrays) won't be able to handle everyone who is connected anyways, so worth planning to use apps that can chat over P2P WiFi or Bluetooth together with the rest of your friends. This also allows you to continue using Airplane Mode the entire time, while being able to communicate with people nearby. Alternatively, investing in walkie-ta…

Absolutely best idea is to make an encrypted PDA & play forensic scientist by recording everything. 1. Get a Google Pixel 9, 9 Pro, or 9 Pro XL smartphone (Cellebrite-proofn at time of writing). 2. Verify images & GOS. 3. Disable biometrics & wireless connections. 4. Memorize with Anki or your own head a new, NIST-compliant passphrase with ≥ 8+ words. 3. Get a cover for the smartphone. 4. Buy EMI tape and electricall…

How is it more secure than not having a phone?

Re: The protester's guide to smartphone security

#189

Earlier quoted context omitted.

Once the phone is on, they can tie it to a person with geolocation. Either directly if you do it at home, or indirectly when traveling in a vehicle associated with you.

The rule is that you don’t use your burner phone at home, you use it when you are at the protest.

If you have two phones both turned on and they both move around similarly, they can be associated later.

Re: The protester's guide to smartphone security

#190

Earlier quoted context omitted.

The rule is that you don’t use your burner phone at home, you use it when you are at the protest.

If you have two phones both turned on and they both move around similarly, they can be associated later.

They also tell you to keep one off until you get to the place. Never have both phones on at the same time.

This is all well documented

https://www.offgridweb.com/preparation/burner-phone-basics-h...

Post reply on HN