How to encrypt your entire life in less than an hour
medium.freecodecamp.com
medium.freecodecamp.com
1) idea that security is something you check off and be done with is dangerously wrong. Security must be continuous, must be updated, reviewed, etc.
2) idea that you can "encrypt" [secure] your entire life is ludacris and leads to many dangerous security misconceptions. You don't even have control of your entire life, let alone ability to secure it. Most the data on you is owned by others and not even available to you to secure. The world is not private or secure. Everyone needs to know and think about this when they are tweeting, sexting, talking shit about future president and then being surprised when SS comes to investigate.
3) idea that security is either on/off, a binary, that you can be secure or not. Is False and leads to extremely poor security choices, over/under securing. Nothing is secure. There is not such thing as SECURE. Things lie on a gradient of security from easy to break to impractically difficult. Things on the impractical to break technically end are still broken due to social engineering, externalities (power consumption of cpu), poor practices surrounding item, etc. Security is making the effort required to get an item greater than the value of getting the item.
I'm sure you means ludicrous and not https://en.wikipedia.org/wiki/Ludacris
I appreciate how practical these tips are and I hope people will follow them.
I have two quarrels with this:
> Andy Grove was a Hungarian refugee who escaped communism [... and] encourages us to be paranoid.
I'm pretty sure that Grove was referring to business strategy, not communications security.
> Congratulations — you can now use the internet with peace of mind that it’s virtually impossible for you to be tracked.
Something I've seen over and over again is that Tor users tend to have a poor understanding of what Tor protects and doesn't protect. The original Tor paper said that Tor (or any technology of its kind) can't protect you against someone who can see both sides of the connection -- including just their timing. Sometimes, some adversaries can see both sides of a person's connection. As The Grugq and others have documented, Tor users like Eldo Kim and Jeremy Hammond were caught by law enforcement because someone was monitoring the home and university networks from which they connected to Tor and saw that they used Tor at exactly the same time or times as the suspects did. (In Hammond's case, recurrently, confirming law enforcement's hypothesis about his identity; in Kim's case, only once, but apparently he was the only person at the university who used Tor at that specific time.)
As law enforcement has actually identified Tor users in these cases, I think people need to understand that Tor is not magic and it protects certain things and not other things. In fact, I helped to make a chart about this a few years ago:
https://www.eff.org/pages/tor-and-https
This chart was meant to show why using HTTPS is important when you use Tor, but it also points to other possible attacks (including an end-to-end timing correlation attack, represented in the chart by NSA observing the connection at two different places on the network) because many people in the picture know something about what the user is doing.
I've been a fan of Tor for many years, but I think we have to do a lot better at communicating about its limitations.
You're describing a very different use case than what I use Signal for (discussing things that could be harmful for clients if it got out, not things where I'd want repudiation).
I think my use case is relatively well solved, but I'd be super curious to see how algorithms could be changed to solve yours.
Too bad meta-data and social graphs will screw you over anyways. Unless you don't use the device for interacting with people you know, in which case, what's the point?
Categorize your levels of paranoia appropriately.
If you do all these things, your resistance to even NSA-level incriminating evidence goes WAY down, and your vulnerability to local LEO and hackers goes to near-zero.
This is, at best, a brick wall, through which an adversary would have to bulldoze.
Bluntly, if you want to tangle with the pros playing like an amateur and not calculating the risks, you're going to be demoralized in your jail cell or worse.
Understand, in depth, opsec before playing with the pros. Understand, understand, understand. Don't just grab random blog posts and mindless implement them. Understand specific details of what you're giving up and the tradeoffs.
Activists have been doing amateur hour opsec for forty years and most of have been cracked like a crab constantly. Pay attention to history, folks!
If everybody did all the things in this blogpost, we would be better of.
There's no such thing as privacy when using proprietary software.
If the goal is to secure your privacy, there no need to argue beyond that.
Sure it might be secure now but we have no clue if / when the app is infiltrated or even worse, could be spoofed and have a bad app pushed to our phones.
(Don't hang me. Just off the cuff idea, I have no clue if it is completely possible to do such a thing but it seems within the realm of possibilities)
EDIT: On second thought, don't you have to sign apps with a private key? I assume that raises the bar a bit, as long as the devs can keep those keys private which seems reasonable enough for such an app.
However, when the author suggests using FileVault, it shows that he doesn't consider the implications of installing a proprietary software, or using a proprietary OS.
[1]: https://en.wikipedia.org/wiki/Time-based_One-time_Password_A...
* Trusted friends (like in Facebook)
* Renew your password in the office (like in my university)
* User-side SSL certificate
* Oh, end then Telegram introduced PIN+TFA
Truth is, though, you wont be participating with most people online if you have very strong INFOSEC and OPSEC. The baseline is just way too low with insecurity and surveillance everywhere.
http://security.stackexchange.com/questions/32367/what-is-th...
Don't use this email for anything else.
(Shops are regularly hacked with leak of email addresses and possibly compromising passwords.)
I use separate addresses for banks, brokerage, etc. Because the email address associated with each isn't used elsewhere, I can almost always identify the culprit when it starts getting spammed, so I can cease business with and blacklist anyone who does it[1].
Because of that, any phishing attempts that go to the wrong address, even well done, tricky ones, are so obvious a machine can trash them with certainty.
Yet another reason is that if someone is going to try to guess/steal your password, if they don't know the email address used for that account, that's something else that can slow them down/trip them up.
[1] That is how Wells Fargo lost my business, well before they made a surprisingly strong go at proving Lenin right about capitalists.
If you use the same email, once that one is compromised, than all accounts related to it could be in jeopardy.
By having a separate account just for financial purposes, which isn't used for regular emails with anyone, it just decreases the chances of it being leaked.
Me too! Though I'm curious as to what you mean by multi-device? I use it on multiple devices just fine, though I have to sync them by hand.
https://jmcphers.github.io/security/2016/05/08/passwords.htm...
FastMail is a decent paid service. Or ProtonMail, Hushmail who market on privacy and security.
They pay a large expert security team to work hard on security all the time (including both mitigating attacks on Google's own infrastructure, and detecting sophisticated phishing attacks against Gmail users).
They pay a large expert legal team to work hard on legal issues all the time.
They're so popular that metadata analysis actually starts to get difficult a lot of the time.
They attract a lot of attention from governments. Governments have put resources into figuring out how to request data from Gmail. Gmail fights many of these requests vigorously, and ends up complying with many of them.
On a related note, I noticed that my Windows Phone displays text message notifications even when it's locked... So adding a PIN doesn't prevent an attacker from doing 2FA if they have access to my phone.
However a secret question like "who did you have a crush on back in 5th grade" is limited to maybe 10 people the world who know and I'm comfortable with that (of course this changes with the over-publicising of our lives on social media).
But I'm digressing and agree TOTOP 2FA is great for the masses. Just be sure to have the backup codes stored in a safe space.
Who quite possibly can be established from either your Facebook or your friends' Facebook (eg you have your friends list set private but a friend who posts on your wall doesn't).
Taking the "I had a crush on 'snail-fridge-running-spectrum'" line reduces the number who know the answer to on average less than 1(!).
SMS 2FA is weak, but either better than no second factor or worse depending on your situation. Use a TOTP app like FreeOTP or Google Authenticator for good 2FA.
> I noticed that my Windows Phone displays text message notifications even when it's locked
On Android you can disable that, even per app. Maybe Windows can do that too.
2FA with, say, a hardware token or even a phone app is generally pretty good.