Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Infosec 101 for Activists.

⁨17⁩ ⁨likes⁩

Submitted ⁨⁨8⁩ ⁨months⁩ ago⁩ by ⁨Cat@ponder.cat⁩ to ⁨technology@lemmy.zip⁩

https://infosecforactivists.org/

source

Comments

Sort:hotnewtop
  • huginn@feddit.it ⁨8⁩ ⁨months⁩ ago

    suggesting proton mail and proton VPN

    Lmao bad plan. Mullvad for the vpn. Idek for proton mail replacements but they’re 100% boot licking, proactively reporting “illegal” mail to the cops.

    source
    • fangleone2526@lemmy.world ⁨8⁩ ⁨months⁩ ago

      Activists should not be using email for activism at all. I agree on mullvad for the VPN. This video does a good job explaining the issues with email for people who need privacy from groups like governments : youtu.be/iH626CXyNtE

      I also question recommending signal over one of the decentralized alternatives like matrix or simplex, though really that’s probably fine.

      source
  • socsa@piefed.social ⁨8⁩ ⁨months⁩ ago

    The part about Google location tracking is out of date. They specifically moved that functionality on device because of all the warrants they were getting, and it never really had anything to do with Google maps. Either way, if you are using a cell phone there's a dozen other ways to track you.

    The biggest point they miss in terms of encrypted messaging is only secure in transit. If there is a compromised device in your chat group then it might as well not matter, so opsec always comes first. An anonymous user agent is therefore arguably just as important as encrypted transport. Signal is a tough sell because it requires a phone number. I would argue that email+PGP is a better option but requires a lot more technical overhead.

    Finally, don't discount the value of patterns of life. If you are doing something you don't want people to know about, make sure your phone is where it usually is that time of day. I think a lot of internet pop security types get this wrong by focusing so much on privacy for shit nobody cares about. Having a normal looking digital fingerprint is a powerful tool if you know how to leverage it properly.

    source