Live data from Hacker News

Ask HN: Online Security Tips for Newbie Freedom Activists?

news.ycombinator.com

31–40 of 140 posts

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#31

the eff guide is really solid for most people [0] but i think its a little laymen for most people. Especially when you get into the activism side of things. Here are the rules i follow. Rule #1. No phones. If this can't be avoided. burner phones without linked accounts. they cost $30-50, plus some for minutes/sms/basic data. This is good for using maps and visiting forums etc. Burner phones should be able to remove b…

What if someone needs to call or message you at home? I have thought about taking some of these more "paranoid" measures as a precaution against an unpredictable political future. But doing this would cut me off from nearly every friend and family member. How do you meet an average person and keep in contact with them (I.e. start a friendship or relationship) when doing something like this sounds insane?

You should compartmentalize different relationships you have. You wouldn't contact a friend or family member from your burner phone. Inversely, you shouldn't give a member of your activist group your home phone number.

You can maintain both types of relationships, as long as you use the appropriate tools for each one, and maintain strong separation.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#33
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> Get an iPhone and use it in preference to your computer.

When connecting to a computer or charging, never ever tap on "trust this computer". If I understand it right "trusting this computer" involves some irrevocable certificate exchange, in effect granting the computer elevated permissions.

Can someone correct me? What precisely "trusting" on iphone means except from the ability to decrypt backups?

Also:

Don't use icloud or any other cloud sync.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#34
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

First, thank you. Second, how much security does this provide and against what? For example, Moxie said once that Signal was designed to be usable and prevent mass surveillance, but not necessarily to prevent targeted attacks (my paraphrasing);[0] civil rights activists can expect targeted attacks. Finally, the public needs real security professionals to do the work and provide a reliable, authoritative, updated guid…

There are several gradations more security we could specify if we relaxed the constraint that ordinary non-technical activists be able to reliably do things.

The level of protection you're getting here is from targeted non-state attackers, ambient opportunistic state-level actors, and non-specialist law enforcement. Some of this stuff would have helped Ross Ulbricht (I mean that non-normatively), for instance.

Google "you're gonna get Mossaded" for fuller picture of what we can expect for current state of the art against targeted state-level attackers.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#35
post #17

Earlier quoted context omitted.

I have some quibbles with this (the first, practical, checkbox guide post; not so much the longer, abstract policy one). * At-risk users should disable SMS 2FA, and favor code-generating applications instead. It takes some effort to disable SMS, but that effort is worthwhile, because SMS is quite insecure. * The guide correctly notes that attachment are dangerous, but isn't very pragmatic about how to handle that dan…

> FDE handles almost exclusively a single threat: the physical threat of your unattended computer. For most FDE solutions, doesn't the computer have to be off or possibly in hibernation (suspend to disk)? Does sleep mode (effectively suspend to memory?) activate the FDE? IME, most people's computers are almost always on or asleep. EDIT: File-level encryption seems better: All files are encrypted except when open. But…

A decent middle ground is encrypted disk images. You're getting inferior encryption (it'll be sector-level wide-block unauthenticated encryption), but at least you'll have to unlock and lock things as you use them.

There used to be an OS X tool called Vault that managed these with a simple, pretty UI. Unfortunately, it was discontinued. We may put something like it together, but we suck at UI.

Stuff like this, by the way, is why I get so aggravated by UI/UX/Frontend developers who build new encrypted messengers --- the world doesn't need more encrypted messengers, but badly needs more UI/UX help with existing tools (I'd be happy to build the backend for such a thing and sign the IP over to an effective front-end developer).

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#36
post #27
post #23

Earlier quoted context omitted.

Yes. Email in general is an opsec nightmare, no matter what rules you come up with or what tools you use to protect it. It's the worst case scenario, a system that goes out of its way to make sure everyone has copies of everything. Above all else: do not create mailing lists for at-risk projects .

We may be talking at cross purposes, but for clarity's sake: I was not recommending email. I was only recommending that noobs be told to think of any written communication in terms of "like it is being published to the front page of your local paper, where your husband, mother in law, and any personal enemy might see it" and, in this case, where any officials might see it as well. The list in question was mostly full…

I'm enthusiastically agreeing with you.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#37
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Why is Wire less secure than Signal?

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#38
I'm an active German antifascist. Here's something I do:

0) Get a lawyer. If you're arrested and you don't know a lawyer, you're screwed. And learn your rights: what do you have to tell the cops, and what you can refuse to tell them. Always carry a valid ID card with you.

1) When publishing pictures, especially on Twitter: place stickers over people's faces, or better: pixelate using ObscuraCam. The best thing is of course to not take pictures or video at all.

2) Get a "burner dumbphone", best are used, old Nokias and a burner sim-card when going to demonstrations. Do not activate or use the phone at your home or at meeting points.

3) If you insist on carrying a smartphone, get a recent Android phone with support for FDE and an exchangeable battery. Enable FDE, also on your SD card, and in case you're about to get arrested, take out the battery or drop the phone to the ground so that the battery falls out and the cops cannot use imaging devices. Use a strong passphrase. iOS devices may be secure, too, but they have the disadvantage that you can't pull out their battery or switch them off in a hurry. If you care about your device, get an IP68-proof/rugged device - cops don't care if they damage your property when pushing you around, and it's easy to e.g. fall on your phone when you're pushed to the ground. Android: disable USB debugging, or if possible with your model, the entire USB stack. On a rooted Android phone, you can do so via an adb shell command.

4) When browsing around the web researching political stuff, use TOR. Do not download unneccessary stuff onto your computer.

5) Securely encrypt your computers and all external media devices (USB sticks). OS X can use Filevault, Windows can use Bitlocker. USB sticks are best protected by VeraCrypt (as it is a cross-platform solution). If you have a NAS that doesn't support encryption, ditch it and buy one that does.

5) If you receive sensitive information, delete it as soon as in any way possible. Insist on communicating via GPG-secured emails, and password-protect your key. Written information should be shredded to as tiny pieces as possible - don't burn the paper, ash flakes or incompletely burned paper can be restored (as evidenced after 9/11).

6) Enable 2FA, preferrably via a token generator app on your phone, on any service that supports it. Store the backup keys (you will need them e.g. if your phone gets damaged!) somewhere safe that is NOT your home (e.g. at your parents' house). Do not label the sheets with a cleartext name of the service/account associated with them. SMS 2FA is the "last measure" as you'll be vulnerable to government attacks, but better SMS 2FA than simple password protection.

7) Handle sensitive information on a strict need-to-know basis. And for heaven's sake, don't talk about planned actions in public. Or brag about things you/your friends did or plan to do - while bars etc. usually aren't crowded with agents, someone may decide to rat you out to the cops.

8) Before going to any demonstration, write down the name and phone number of your attorney with waterproof ink on your arm. That way you don't have to rely on the cops finding your attorney or delaying calling him by taking their sweet time to do the search.

9) Inform close relatives/roommates that you're away, especially if you have pets, children etc. that need to be taken care of. Have enough cash on your bank account (or have a relative) to pay rent if you end up arrested.

10) don't ditch fares, or if you have a car, always take care that it's up to code, legally registered, and taxes/insurance are paid. Nothing sucks more than getting arrested for petty stuff, and pulling people over for broken lights is a common excuse of cops to search the vehicle. Do not carry huge amounts of cash in your vehicle (google for "asset forfeiture", it's really gross what cops can legally do).

11) don't ever go drunk, intoxicated or not well-rested to any political event. Do not take drugs of any kind with you, except medicine that you need (and for these, best take the original prescription or a copy with you, so the cops can't bother you with drug charges). Preferrably use plastic glasses (glass lenses can cause grave eye injury when damaged), contact lenses and cosmetics of any kind tend to aggregate nasty stuff like pepper spray.

12) Always take sufficient supplies of water, food and a small pack of glucose tablets (in Germany, we know them as Dextro Energy) with you. If you can, take a couple small adhesive bandages with you, and go to a First Responder education (this is useful anyway, even if you're not "actionist" - you can save lives!)

13) Connect with other political groups both in your area and state/nationwide: ACLU, antifa groups, civil rights movements. Political parties (liberals, greens) may also be of interest to you, depending on your focus.

14) Beware of snitches or agents provocateurs that try to incite you to violence. When you want to go the "actionist" route, be aware of the potential consequences if you get caught and don't do anything you're not comfortable with.

15) Do NOT go on political demonstrations with firearms, knives or other weaponry. In most jurisdictions it's illegal, and even if it's legal to assemble with arms, it's not sane to do so. When you see armed protestors, or a demonstration turns violent, GTFO as fast as you can.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#39
post #29
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

Thanks for this, awesome. Questions: > 4. Switch to Google Chrome. Can one configure Chrome to not be a data-sucking kraken? > 7. Disable cloud-based keychain backups. That backup is encrypted, I'd hope? So, is the problem that getting hold of a cloud-backup facilitates off-line attacks on the encryption key? I remember Filippo (FiloSottile here) publishing his encrypted private PGP key [1] (back when he was still po…

Regarding Chrome, here's a good place to start:

https://noncombatant.org/2014/03/11/privacy-and-security-set...

There are also people who use Chromium, or particular configurations of Chromium, instead of Chrome. That's fine. But don't use forks of Chromium, no matter who maintains them, even if it looks like a sizable effort. You don't want your browser to be any number of days behind the Chromium patch cycle.

I use the browser integration for 1Password on OS X (I might not if I was on Windows). I'm generally not that worried about localhost privilege escalation. I am very worried about how well I can reason about cloud-based storage of any sort, and how it will interact with things like my browser.

KISS: keep your secrets out of cloud systems and your backups offline.

If you're very sophisticated, I like Tarsnap for online backups. But you have to be very sophisticated to use it.

Re: Ask HN: Online Security Tips for Newbie Freedom Activists?

#40
post #15

These answers are unlikely to make much of HN happy, but they are the correct answers. 1. Get an iPhone and use it in preference to your computer. 2. Enable "code-generating" or "authenticator app" 2FA on all your accounts, particularly email (this is called "TOTP"). 3. Disable SMS 2FA on any account wherever you're using real 2FA. 4. Switch to Google Chrome, which is significantly more resilient against vulnerabilit…

> but they are the correct answers

Citation needed.

Post reply on HN