Secure Computing for Journalists
blog.cryptographyengineering.com
blog.cryptographyengineering.com
https://gist.github.com/anonymous/9f789aabd7e8681dec0cf5781a...
Please don't respond with the strawman you keep using of Iphone vs. Android. I am not arguing that Android is more secure. I am saying that taking either to meet an at risk source is bad. Your advice on this forum will contribute to journalists feeling comfortable doing this.
Things you probably don't know (whether based on account age or admissions within this thread):
* tptacek has been an exceedingly active member of this forum for many, many years
* tptacek has been giving us all free security advice for as long as I can recall
* tptacek has founded at least two successful companies primarily dealing with security
* tptacek has, in the past, given much advice that I've considered questionable at the time, but which has proven to be right to me after I've learned enough to realize my errors
And because that all sounds very much like an appeal to authority, I apologize again, but here's the thing -- the comments he made that you object to, and consider to be trolling? They're spot on. I'm not saying that you should believe him because he has a history of making believable claims. What I am saying is that you should believe him because he's far more versed on the subject at hand than you are, and that's by your own admissions within this thread.
It's worth taking a step back here and asking yourself how well you actually know the things you think you know in regards to this thread. I am honestly not savvy enough on mobile security anywhere near capably enough to suggest that he's right and that you're wrong, so please don't assume that's what I'm doing here -- but many of the people you're arguing with in this thread are people who have the requisite bona fides to make their claims with confidence, and while you are boldly asserting the opposite, you acknowledge that this is not your field of expertise, and that you haven't bothered to learn reverse engineering.
Again, if this seems harsh, please know that it isn't intended to. Language is clumsy, and I'm not its best handler on the best of days, but while you might be 100% correct in every one of the claims you've made, the consensus seems to be otherwise, and you haven't done a good job of convincing me that you should be believed over someone who literally pays their bills through the dispensation of their subject matter expertise on this type of material.
Because of the fantastic community, it's obvious that HN is a great place to teach and to learn. Knowing which to do, and when isn't always so obvious. Most of us have made that mistake in the time. Consider whether or not you may be making it now, or figure out how to better support your claims so as to teach more effectively, but cat-pawing at each other throughout the entire thread isn't doing anyone any favors.
Reverse engineering isn't zero sum. The benefit you get from reverse-engineering a closed platform doesn't vanish when someone else reverse-engineers the platform, just like your ability to read open source code isn't damaged by NSA's ability to read it faster.
As I said, I don't know who's right and who's wrong, but the argument seemed to involve a lot of effort for being so unproductive.
I am very familiar with the OPs posts. I do not want this to become personal. If you re-read this thread (and others in this discussion you might notice that.)
Typical advice applies, too. Keep batteries out. Drive away from normal location to somewhere with plenty of people in cell radius but off camera. Batteries in, make call. Prearranged times or periods.
2) The other choice is a device made by a Chinese or Korean company with a semi-open operating system made by a US company.
3) Either device will have a totally closed baseband chip.
4) Deploying and maintaining secure Linux environment on a Laptop is a full time job that requires expertise journalists don't have.
5) Open versus closed source is a red herring. Everyone is using pre-compiled binaries.
All iPhones are made in China by a Chinese company.
From my somewhat-naive perspective, it seems like the alternative is an Android phone made in China by a Chinese company, which seems not obviously superior.
With a very salutary trend toward reproducible builds, which will help prove a connection between the source and binaries. (Though it's taking years to get there.)
> 1) Apple has shown substantial backbone in fighting against the US government when pressed to exploit a phone.
And the phone was exploited anyway. The only thing that was established is that Apple must not be forced to help.
> 2) The other choice is a device made by a Chinese or Korean company with a semi-open operating system made by a US company.
That makes both alike.
> 3) Either device will have a totally closed baseband chip.
This is the one the iPhone got right. On the iPhones, it is insulated by a closed interface.
> 4) Deploying and maintaining secure Linux environment on a Laptop is a full time job that requires expertise journalists don't have.
Ditto for Android, iOS, Windows, OS/2, AIX, GNU/Hurd... And anything else you may think about.
> 5) Open versus closed source is a red herring. Everyone is using pre-compiled binaries.
Open source is a necessary condition for securing against any targeted attack. It's just far from sufficient. Also, pre-compiled binaries can help you.
Anyway, both platforms are pretty much closed.
http://www.latimes.com/business/la-fi-tn-apple-fbi-call-2016...
To avoid confusion for any readers, you should clarify what this means: Apple has an automated process for serving data in response to any approved FISA court orders from the FBI.
And to make this clear: U.S. companies must comply with valid court orders. Being a "PRISM member" is not optional.
This is increasingly important as it's now really obvious that the different agencies have different politics and may end up investigating each other to see who's been compromised to the Russians.
(also, you have to pick something: telling a journalist not to use a phone is a total non-starter)
Not saying it's happening here. Just reminding you they do this.
The FBI does also have a significant counter-intelligence function where the endgame is often "foreign diplomat declared persona non grata".
You nust have missed the whole Snowden leaks where they were all lying to Congress, courts, and so on. Far as the FBI, here's what they say: "That pertains to highly classified matters of national security. Im afraid I can't discuss that here." (Keep repeating.)
They've also been lying about their counterterrorism cases. That one expose showed they're paying undercovers $100,000 or so to convince harmless people to try something. Even financing, equiping, and training them. They sell it in court as them stopping what was already going on. Despite one informant recording them, nobody leading the FBI is fired or doing time. Deception is business as usual.
So, in courts, FBI said that targets using encryption by U.S. companies was impossible to do anything about. They needed expanded powers under things such as All Writs Act to get at the information in such devices. In secret, they were backdooring U.S. companies' products with NSA. They and the DEA were getting actionable information from those programs that they had to hide from courts under a process called parallel construction. They had to create a second trail of evidence that made it look like they found the person another way. Then, get the conviction through that second trail of evidence. The FBI was also willing to dismiss cases any time its claims were tested in court presumably because the claims were lies and methods unconstitutional.
So, the Snowden leaks, the San Bernardino case, and activity around things such as Stingrays shows the FBI will lie to courts to achieve political or legal ends. They'll even sacrifice their own court cases to protect their illegal methods. So, your claim that they won't lie in court or that court has some power over their corrupt activities is false. They consistently mislead everyone they can about both encryption and backdoors. They even exit courts when caught without any criminal penalties whatsoever. James Comey is in fact still free and directing the FBI despite caught in tons of lies from Congress to courts to media.
FBI will lie about these topics in court. They've done it consistently for over a decade now and nobody there has been imprisoned for it. QED.
The clueful people who argue in favor of Android start not by saying "you can't trust anything that isn't open source" (that would be especially silly if you're arguing for Google's Android phones, which are the only trustworthy phones), but by acknowledging the consensus that iOS is more secure and then challenging it.
On this thread alone, you've:
* Suggested that reverse engineering is a kind of arms race between the NSA and the "good guys", which it is not.
* Suggested that Tor is inextricable from Tor Browser.
* Complained about the suggestion that you might learn how reverse engineering works, because you're just a software developer.
I'm sorry, but comments the one upthread I'm replying to are indistinguishable from trolling to me. I know that's a bit of an aggro thing to say. But: do you honestly believe that the people who write advice like Matt Green in the story we're commenting on, or in the brief we're commenting on here, don't understand what open source is?
EDIT > "I'm sorry, but comments the one upthread I'm replying to are indistinguishable from trolling to me. I know that's a bit of an aggro thing to say."
If that not a personal attack I don't know what it is.
Oh and would you have time to address any of my questions? (In terms other than ios vs. android?)
Let's be honest, if your adversary is the US government, I suspect that there is no electronic equipment you can use.
Most journalists, however, are more in fear of their lives or communications when outside the US. For that, an iPhone is provably a much better choice.
I've upvoted you because of the first sentence but the second one leaves me a bit puzzled. There are plenty of places where the threat level against journalists is equivalent to the US and quite a few where it is actually less.
In fact, the current 'head-of-state' of the United States is on the record for saying the press is the enemy of his administration.
While your point is well taken, I haven't seen any US administration execute a journalist for quite a while.
Russia and China don't have quite so much restraint. And most of the petty dictatorships and theocracies make Russia and China look perfectly reasonable.
The fact that the US is not a bastion of moral rectitude does not automatically grant moral equivalence to bad or worse actors.
I am perfectly capable of condemning the actions of the US government and working to make it better even while acknowledging that it is better than most and worse than some.
"But he does it, too!" is not a valid argument for justification. But neither is it a valid reason to refrain from reasoned comparison.
Where can I get some citations for this?
https://www.silentcircle.com/products-and-solutions/devices/
Pretty much the only thing Silent Circle has going for it is a commitment to open source. All else being equal, open source is better than closed source. But all else is nowhere close to equal in this case.
I recommend against Silent Circle's phone.
Worst case, this will make people with sensitive information and without technical expertise more secure. Best case, it will compel Google and Android device manufacturers to step up.
Would be great to see some good guides that take into account the challenges that others outside of the states will face. Perhaps these guides may not have that audience in mind though. Maybe if these guides had a link to a good guide for securing your Android device the best you can, it would serve help those who are financially restrained.
My limited understanding of the Android ecosystem is also that the fragmentation makes it very difficult to have a comprehensive guide for Android, since what is applicable on device A may not be applicable for device B, whereas with iOS, "turn on these settings" is applicable across the entire ecosystem.
I think it's just the difficulty of having a comprehensive and simple reference document for Android, regardless of cost. The same regional difficulties even for specific device recommendations makes such a comparable document difficult, as not all phones are easily purchasable in all regions.
So it's definitely something that needs attention, but the low-cost-secure doc may be more difficult than it seems at first blush.
* As mentioned by codelitt, a guide for securing Android phones and recommended Android devices, especially at lower price points.
* Thoughts on Windows vs Linux vs MacOS from a security perspective.
* For people who are only comfortable using Windows, recommendations to lock down devices.
* (Already existing) Don't use commercial VPNs. Use Algo https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-th...
* Explain the Tor browser situation and why it's a bad idea to use the Tor browser bundle.
* Recommendations for anonymity from an opsec POV.
* Recommendations on how to cross borders with minimal privacy intrusions. There's lots of bs advice floating around.
If there are existing posts about any of the above, please link them in a comment below.
Well this is news to me. Can you explain why it is bad?
EDIT Rate lime :( so replying here. any ideas on where one can get started with a literature review on this? There is so much misinformation and big egos in this field so it would be nice to know from an expert where to start.
If anything, I worry that non-technical users will still not understand that desktop programs can do anything you can do with your computer even after reading your post. I'm not sure the description is "in your face" enough to translate for the intended audience. In their minds, "reading files" may be better expressed as "copy of every email I've ever sent" or "operate my webcam and grab nudes of me."
Isn't there something more professional and accurate available? I fear there is not.
I also recommend you show them the Teen Vogue article.
* Do not have work-related emails on your Android (unless it's Google-made). iOS (9+) is okay. * Do not open random attachments on a Windows machine. (We always do our best to convince them to switch to a Ubuntu station with an AppArmor profile for LibreOffice set.)
This is a good start. I think this article would be even better if it included some phishing tips (like HTTPS doesn't automatically mean "secure", and if you're suddenly logged out of Google for no apparent reason, don't just log into the webpage displayed to you, but instead, open Google by typing the address bar manually and log in there).
Interesting side-note: Asshats spend days crafting phishing emails specifically targeted to our journalists, and they never get Google's postal address right in the footer.
VServer or similar could also work well but might be harder to configure correctly.
Also modern versions of Office already run in a sandbox on Windows (AppContainer?) so how much are you really gaining?
* It doesn't have all that macro bundling stuff in normal documents that's the source of the whole macrovirus issue.
* It doesn't have any OLE-object-can-run-embedded-EXE-files-on-click-feature.
I'd say that's a huge win.
Edit: removed sentence "Most mobile devices have baseband chips with DMA"
Doesn't that depend on the manufacturer, or does Google somehow make that a requirement?
Linking to some sources would help, please.
{edit: And it would use a slush-fund}
Subgraph. Currently in Alpha version, so be careful using this. Still has to be vetted by the wider infosec community, but worth downloading and playing around with.
TailsOS. Very useful for journalists, but since it heavily relies on Tor it can be tricky dealing with mixed-anonymity workflows where sometimes you just need a Windows environment (preferably an airgapped Windows sandbox you can use to code / play around with files using Windows freeware).
Qubes. Heavily reliant on compartmentalization, and this can sometimes prove too cumbersome if you typically do one type of activity on the web like chat / email / hang out on slack. Typically for when you need to insulate different activities from each other and to avoid contaminating different contextual environments / tasks.
But none of these are reasonable suggestions for journalists and activists. We're not talking about people who are running conspiracies and can organize their working lives around opsec. You can barely get these people to the point where they aren't blindly clicking on attachments (and the attachments they open need to open in office software that is compatible with their existing workflows). They're simply not going to use Linux on their desktops.
This is why security people like phones so much: they run secure operating systems that laypeople have accepted and can work with.
There is the caveat that it's hard to get things done in a timely manner on phones, or even tablets/phablets. If I need to crank out a lengthy blogpost, then I need a full desktop environment where I can do cross referencing, wikipedia lookups, file selection, photo editing, and all the other things that a desktop affords. I have tried writing a blogpost on an iPad and it took up my whole day when it should have taken 2-3 hours.
I know people who have developed super-fast methods for working on iOS but they are such a rare creature, and I'm not so sure their workflow is even teachable enough to be widely adopted by journalists or professional bloggers. From my experience they're relying on all sorts of hacks to get a blogpost out the door like using some perfectly curated mix of apps, and being able to pass files to and fro different apps with ease. Hardly the stuff of laypeople.
Sometimes the most succesful attacks are phishing attacks that no device will protect against. As an example, it is rumored that John Podesta used an iPad.
The first point being, software flaws and particularly those in low level networking libraries can expose secrets and the key I suppose as covered in the article is to ensure your OS is always up to date. The second point, and Dan covers it elsewhere in this thread, be very cautious about insecure hosted VPNs & you should really never trust proxies which some VPN providers are offering.
iOS patches are:
1) available, directly from the vendor
2) come with new features
3) required for certain apps
4) nag you
etc
The key advantage Apple has is vertical integration. Google has to coordinate with third party vendors to ensure that an OS patch reaches Android users. Apple can just flip a switch.
Is that still true for the Google reference models? The Pixel, Nexus and other references devices tend to get updates in a much timelier fashion than, say, the Galaxies, Experias, and Notes of the world, and because the reference models aren't laden with proprietary bloatware, they tend to work more reliably after upgrading as well.
IOS is a completely closed box whereas AOSP is completely open. You can argue for or against security by obscurity v/s security in open software, but at the very least it needs a mention in any fair comparison.
This gets addressed by people working in security on every single HN thread, including this one. Assessments of the security of iOS are not dependent on its 'openness'. There is also nobody seriously arguing 'security by obscurity' vs 'open software'. That's not what 'security by obscurity' means nor does the security of iOS depend on 'obscurity'. None of this needs a mention in a 'fair comparison' because it's simply wrong.
And besides, open source doesn't mean anyone has reviewed the code. Reviewing a program for security takes work, regardless of whether it is open or closed.
and not to mention the nasty Heartbleed that's still affecting us.
Open source only means the code at some "point" may have been vetted and secured but it will not remain secure forever.
At this point, there is no secure anything, as long as it is man-made, it can be broken by another man.
Apple has incentives to protect your data and it has enough money to not have to rely on sharing the data unlike Google and other Android companies. But this is not to say Apple isn't evil. They all are by default as in the nature of for-profit business they're in.
There are cases where using the Tor Browser makes sense, but it's a terrible blanket recommendation. If you're not actively trying to hide your identity, using it will make you less secure than you would otherwise be.
Is it? Please provide references.
> and you mark yourself out as an interesting target/
Yeah that seems likely.
> Using Chrome over Tor is strictly better from a privacy viewpoint than using Chrome on its own.
Is it? If Chrome leaks any local information this is not true. NB I do not know if Chrome does so but please refer to https://blog.torproject.org/blog/bittorrent-over-tor-isnt-go... for an example of what I am getting at.
> If privacy is your absolute priority, the Tor Browser reduces the number of cases of information leakage but still requires you to have the discipline to avoid any other methods of leaking your identity.
Yes. But Tor Browser is released specifically to help you manage this. Information leakage through the web browser is amazingly easy - and it doesn't take logging onto a website to be finger printed (Chrome over Tor is probably a fairly unique fingerprint on its own). Why not find out for your self how unique at https://panopticlick.eff.org/
> If you understand all the issues around that then you probably also understand enough to ignore Tptacek and use it anyway.
No comment.
> But if you don't, using the Tor Browser leaves you in a worse position than you'd otherwise be in - you're less secure and you're probably leaking PII anyway.
Doubt it but again citations needed.
> There are cases where using the Tor Browser makes sense,
agreed.
> but it's a terrible blanket recommendation. Citation needed.
> using it will make you less secure than you would otherwise be. Citation needed.
Sandboxing alone justifies this.
> If Chrome leaks any local information this is not true.
Leaking information over Tor is no worse than leaking it over non-Tor, and in general cases Chrome isn't directly sending information that allows a single site to identify you.
> Chrome over Tor is probably a fairly unique fingerprint on its own
What's your threat model? That's a serious question.
> Leaking information over Tor is no worse than leaking it over non-Tor, and in general cases Chrome isn't directly sending information that allows a single site to identify you.
More like: Leaking local information over Tor is equivalent to not using Tor, and in general cases the user has no control over what data Chrome is sending.
The OS is in no position to sandbox multiple tabs running in the same browser good grief
> More like: Leaking local information over Tor is equivalent to not using Tor
This isn't even slightly true
> in general cases the user has no control over what data Chrome is sending.
Nor do they have any control over what data the Tor Browser is sending. At some point you have to trust that your software is doing what it's supposed to do.
If privacy is an absolute priority for you, then yes, run Tor Browser. But be aware that in return for privacy you're giving up security. For most people that tradeoff will result in less privacy in the long run. If someone isn't in a position to make an informed choice, a blanket "Use Tor" recommendation may do much more harm than good.
Who said anything about tabs?
>> More like: Leaking local information over Tor is equivalent to not using Tor
> This isn't even slightly true
There is no middle ground. There are two states here. Anonymous and not anonymous. Once one is not anonymous they are not anonymous. If one leaks one's local IP one is not anonymous. If one leaks one's voice data one is not anonymous.
> At some point you have to trust that your software is doing what it's supposed to do.
I agree. The thing is that Tor Browser is supposed to be limiting data leakage whilst Chrome is supposed to be sending data to Google.
If all your tabs run in the same process, any vulnerability triggered by malicious content in one tab has access to all the content in any other tab. Sandboxing the brower process makes it more difficult for that to result in taking over your entire system, but in this case merely taking over the browser is sufficient.
So no, OS-level sandboxing isn't sufficient. And if you don't understand that, you should not be making assertions about security.
1) Chrome over Tor? I've read that they don't integrate well (but I know very little about it).
2) Chrome to a (secure) VPN? How does a typical end user find a secure VPN?
3) ?
A good point. Though in fairness, that's why I included Chrome over a VPN as an option.
> The information stored on their computer is far more sensitive than the list of sites they visit.
Not that it invalidates your points, but I wonder how true this one statement is. First, remember that in addition to metadata Tor hides content (which may be redundant in the case of HTTPS-secured websites, but that's not a bad thing). Also, a journalists' metadata could tell you a lot about the who, what, when, where, why and how they are researching, and expose sources.
What is more valuable, knowing who a journalist is talking to and when, or knowing what was said? IM very HO, I think the former.
Above all the many problems it has, it recommends using insecure hosted VPNs and advocates an app-centric approach to restoring your privacy (e.g., Install this app and you'll be safe!). This is no better than believing you can eat unhealthy food and fix it with weight loss pills.
If you're looking for a better solution to a communications security problem, you're welcome to check out Algo, a self-hosted VPN that I support:
https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-th...
I was under the impression that PrivateInternetAccess was well regarded, but this link [1] which is in the blog post linked above was an eye opener.
The reputation of this page emphasizes (epitomizes?) a need the public has: An authoritative, accurate, comprehensive, usable security guide for non-technical end-users.
* Authoritative: There are too many pages, apps, and too much advice like the parent. Most end users - even most IT professionals, IMHO - have no good way to differentiate between good advice and bad. The solution is for one source of advice to become authoritative; i.e., it needs to be endorsed by people respected in the IT security industry and by names the public recognizes (e.g., the NY Times, ACLU, NRA, etc.). Its authority must stand out from the rest, and in a way the general public recognizes (endorsements on HN don't work), or it becomes just another voice among many.
* Accurate: Written by true IT security professionals who do real homework for it. Not IT pros or devs who read about security and have some sense of it. Not even by cryptographers who don't know the implementation side.
* Comprehensive: A one-stop shop. Otherwise, it loses authority and usefulness.
* Usable: Something non-technical end users can grasp and implement, as easily as possible. The harder it is, the fewer people will use it and the more people will misuse it (i.e., misunderstand it and make mistakes). 'Easily' also means affordably; telling everyone to buy iPhones may not be realistic.
Personally I wouldn't mind a guide for technical users, but that is a very secondary concern.