PS, if you're ever on the US West Coast or in Singapore, drop me a DM. I'll buy you a drink someplace.
PS, if you're ever on the US West Coast or in Singapore, drop me a DM. I'll buy you a drink someplace.
-It's tricky for a non-technical user to setup
-It disrupts their regular workflow
-People get frustrated with speeds of Tor etc
-People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner.
-People get annoyed as it doesn't solve their problems and exposure on mobile
-You have to restart to run it
-They can't run their regular programs on it - MS Office, Outlook, Adobe, etc.
-It's Linux based, so a big mental jump for most people coming from Windows (or most people not at the command line on OS X)
-It's hard to access files on other drives
-Documentation and TAILS is only available in certain languages
-It often has driver problems - e.g Macbook Pro 2015 WIFI issues
-In developing states, computer literacy is low, so anything other than the norm (Windows) is confusing
-In developing states, hardware tends to be slow (often counterfeit) so running TAILS in RAM is slow
-People lose the USB sticks they put TAILS on (also many counterfeits, so they often fail or have a false size)
-TAILS often requires training, which not everyone has access to
-Skills fade for digital security training with journalists/activists is often quite high, especially if they don't need it that often.
-the list goes on............
Don't get me wrong, I think it's great (as is Qubes, Subgraph etc) but we need to be realistic about it's limitations for the majority of people. Especially if we want to be sensible and try to tailor advice, training and tools to their realistic threat models.
P.S Definitely, I'm on the West Coast probably once a year. Ditto you if your ever in Dublin (Ireland, not that fake one in California :) or London!
If you're going to be actively targeted by exploits like this, then you shouldn't give a damn about some of these tradeoffs. If you have journalists/activists willing to go to information war with a nation-state, they shouldn't be surprised when their adversaries have the resources to pwn them. If David wants to fight goliath, they will need to take this into account. The guys with guns and power want their heads.
If the activists/journalists/whatever don't want to take the necessary precautions to use computers to talk to people in a way in which they are protected from capable adversaries, then I'm not sure what it is that they are expecting.
Also, I was recommending these users simply defending in depth by using Tails as a sandbox for a leaky browser, to require a chain of expensive exploits (browser 0day + VM escape 0day). Training someone to install VirtualBox or VMWare and run an ISO from it doesn't really disrupt too much workflow and defends in depth against the browser issues, then again I am likely wrongfully assuming VT-x/VT-d and a lot of RAM on the activists' computers.
I get what your saying but humans are humans, journalists are busy and security is a pain for most people (until they need it).
The threat model really depends and so is too wide for me to make any sweeping statements. Clearly a US journalist working on drone strikes is a different threat model to an democracy activist in Sudan.
...until they see they need it.
Sad, as most people may not even know that they need to go to these kind of depths. For them, TBB seems more than enough.
The problem with this mentality is, often its not themselves they're protecting but others. If Alice and Bob are communicating, and only Alice is the one under threat: Alice may be willing to go to great lengths to make her side secure, but you really need to be making it as easy as possible for Bob, who has less of a direct incentive to overcome the inconveniences.
I feel the urge to mention https://chatsecure.org/ as a notable middle of the way alternative.
Ideally Tails would move in the direction of Signal Private Messenger, Anonymity tools need to be as user friendly as possible, otherwise the user has to develop specialized skills and expectations to deal with them, which creates user rejection & user apathy.
Or, we could swap i2p in there, it'd likely be more consistent than TBB, but user friendliness was worse last I checked.
In an attempt to take back a little control over my personal data, I've switched from android devices back to ios. I notice that orbot/orfox aren't available for ios and it doesn't appear umbrella is either.
Is there something I am missing about apple's platform that makes android the better choice for security? Or why aren't people building ios apps for security?
-Umbrella on iOS is coming in 2nd quarter of next year! Whoohoo (We get asked about this all the time).
-The main reason that we and a number of other open-source projects built on Android first is that because is by far the dominant smartphone platform. Especially in developing areas with significant human rights problems like China, Russia, parts of Africa and Asia. Mainly because the cost of Android phones is low.
-On the security specific question. I think the Android vs iOS debate has evolved. A few years ago it was felt that the open-source(ish) and customisation aspects of the Android platform meant that it was the more obvious choice for a secure phone.
I think that what we have seen recently, with tens of millions of Android phones not getting updates etc - has probably challenged that[1]. Especially when iOS now has encryption as standard and other security features. Of course there are Android options like Copperhead/F-Droid/Guardian Project which are examples of how you can retake control to a certain extent, but I think for the average person's threat model iOS is probably pulling ahead on the security side of things.
[1] https://threatpost.com/android-security-report-29-percent-of...
It's hard to recommend alternative distributions of android to most people. I feel like it's similar to linux 15 years ago, it CAN be more secure, but it can also be incredibly insecure if setup improperly. And if you are just going to go install playstore and google apps, was anything really accomplished?
100% agreed! It's like using new, super secret, awesome encryption (telegram/zcash) vs something more established that's been reviewed, tested, and has support.
What exactly? A non-technical user can plug a flashdrive on an usb port. Other than that, it's basically read instructions and doing exactly what the instructions are telling, which should be what "regular" operating systems already make you do. But obviously that is the perspective of a power user. In the quality of someone trying to teach people how to use tails I also perceive the barrier imposed. I am convinced that the best path to lower this barrier is to constantly question "what exactly", until we find out.
---
> -It disrupts their regular workflow
I am afraid that this is non negotiable, although other people may disagree. I advocate that security and privacy is less about the digital tools I use and more about my habits and perspective. Much energy is wasted trying to make "fool-proof" tools, but that is ignoring the fact that the responsibility shall be on the end user, and not in the developers. There are parts of the tails documentation explaining those things much better worded than my comment.
---
> -People get frustrated with speeds of Tor etc
That is frustrating for much people. Many people don't want to be part of any anarchist agenda, but there is simply no alternative. The tor network probably will continue to be volunteer driven and an instrument of tech resistance, and that's not a hipster thing, the network is suffering real world attacks and almost always being flagged as a bad thing.
---
> -People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner.
Adding to the above comment, it boils down to the same thing. I understand that people don't want to be tricked in political agenda, but this really is about system administrators deliberately blocking tor traffic because they don't want to deal with the tor network, or because they've read somewhere that tor traffic is bad. This basically should be motivating "genuine" tor users to demand that tor network stops being blocked everywhere, but like I said, people shouldn't have to feel obligated to engage in political agenda. Although I personally advocate for the exact opposite elsewhere ;)
---
> -People get annoyed as it doesn't solve their problems and exposure on mobile
That's important. Being android a linux based system, one would think that by now we'd have something like tails for smartphones too. But is not that simple. These devices started to being manufactured in a time that placing backdoors in the hardware or in a lower software level is easier, therefore making harder to secure them, compared to desktops/laptops. That said, there are plenty initiatives and things being developed to bring security and privacy for mobile devices, but I agree that it's not yet "for the masses".
---
> -You have to restart to run it
> -They can't run their regular programs on it - MS Office, Outlook, Adobe, etc.
> -It's Linux based, so a big mental jump for most people coming from Windows (or most people not at the command line on OS X)
I can't think of other answer to that than "that's closed source people's fault, blame microsoft and adobe". I am aware that this answer doesn't solve people's problems.
---
> -It's hard to access files on other drives
I don't fully agree with this one. However, I agree that the default GNOME look and feel doesn't provide an obvious "my computer" sort of thing. That is well done on many ways in linux distros. Previous versions of tails had that solved. GTK devs, where are thou? The tails website has called everyone already, little help here =)
---
> -Documentation and TAILS is only available in certain languages
I am one of the lazy volunteer translators who should dedicate more time translating tails than the other futile things I do with my life. I hope more potential translators feel ashamed as well.
---
> -It often has driver problems - e.g Macbook Pro 2015 WIFI issues
I acknowledge that as a big problem, because people shouldn't have to compile drivers just to use an operational system. But I can't miss this one: "that's apple's fault!".
---
> -In developing states, computer literacy is low, so anything other than the norm (Windows) is confusing
> -In developing states, hardware tends to be slow (often counterfeit) so running TAILS in RAM is slow
> -People lose the USB sticks they put TAILS on (also many counterfeits, so they often fail or have a false size)
Here is the magic point where the "go blame microsoft" arguments have no sense and lose their meaning. This is the kind of reality that I see everyday and that I think should be top priority in tails development. Whose privacy and security issues are we trying to address? I don't mean to be rude, but I believe people with easy access to macbooks, fast internet connection and with means to buy many disposable usb flashdrives won't understand easily, if not at all, what it is having to operate frankenstein machines and to have only one usb flashdrive which is probably used by other people. This is serious shit because apart from the everyday problems, when these people are offered "digital inclusion", it is often something to take away for good their privacy and security, and everyday there are less gaps and possibilities of "hacking" the way out of censorship and surveillance. See internet dot org for the most nefarious example.
---
> -TAILS often requires training, which not everyone has access to
> -Skills fade for digital security training with journalists/activists is often quite high, especially if they don't need it that often.
Again that divides my opinion. I recognize that the tails doc people should always improve it bearing in mind that anyone should be able to operate tails just from reading the docs, and should be the most accessible as possible. In the other hand, security and privacy are not subjects you can solve by means of digital tools alone. There are not, and there shall be not any magical tool that dispenses the concomitant lectures people should listen to while trying to address privacy and security.