By comparison, the Tech Solidarity checklist is the result of a survey of a bunch of different security people and is both generally more sophisticated and sound than this checklist and also manages to be a little shorter (in word count):
By comparison, the Tech Solidarity checklist is the result of a survey of a bunch of different security people and is both generally more sophisticated and sound than this checklist and also manages to be a little shorter (in word count):
> Do as much of your work as possible on an iPhone or iPad rather than on a laptop. Use a bluetooth keyboard for easier typing.
Is that serious? I mean sure, iPhones and iPads are generally less prone to viruses and such, but I feel like it is generally safe to use computers, and if you do other things on this list you won't end up with an infected computer. In addition, if you are doing most your work on these, it is almost guaranteed that all the information is going to be sent to iCloud / another apps 'cloud'.
* Google Mail is, for most people, the safest email service, with the most mature and comprehensive 2FA, direct connectivity to GDocs to make viewing attachments safer, and a gigantic security team. Note too: this guide also suggests avoiding email as much as possible.
* If you work with sensitive documents (this checklist was originally devised for journalists and the airport lawyers), all the cloud drive services (not just Google Drive) are a bad idea.
* Chrome is the safest browser with the most mature and reliable anti-exploitation hardening and the most responsive security team.
* iOS devices are, for most people, far more secure than computers, which aren't locked down at all and for which any kind of local code execution is almost invariably game-over all the way through the kernel, and at least game over for all of the user's data. Most computer users are never more than an errant couple of clicks away from losing their whole machine to an attacker, which is not the case for someone reading their mail on an iPad.
> Google Mail is, for most people, the safest email service, with the most mature and comprehensive 2FA, direct connectivity to GDocs to make viewing attachments safer
> If you work with sensitive documents (this checklist was originally devised for journalists and the airport lawyers), all the cloud drive services (not just Google Drive) are a bad idea.
So is Google Drive a good idea or a bad idea? Maybe for normal people Gmail is good, but in the next point you say this list is for journalists and airport lawyers, wouldn't you advice them to use something more secure like fastmail/proton mail, or if you are serious, your own mail server or something? Why does this list not talk about TOR / PGP, the most fundamental tools for security for journalists?
> Chrome is the safest browser with the most mature and reliable anti-exploitation hardening and the most responsive security team.
I don't think this is true at all. What is wrong with Chromium or Firefox open source alternatives? Why doesn't it mention things like no-script and ublock origin?
> iOS devices are, for most people, far more secure than computers, which aren't locked down at all and for which any kind of local code execution is almost invariably game-over all the way through the kernel, and at least game over for all of the user's data. Most computer users are never more than an errant couple of clicks away from losing their whole machine to an attacker, which is not the case for someone reading their mail on an iPad.
My fundamental problem with this is that if you are going to be doing things on an iPad you are almost certainly going to be using cloud services. Weather it is Google Docs or Pages or Word or anything, it is very difficult to keep things 'local' to your hard drive on a iPad, where on a computer with dropbox it is much more clear that files in there are going to leave your computer.
For most people, including technically inclined people, running your own mail server will almost certainly lose you significant amounts of security.
If you deal with sensitive documents like legal artifacts in immigration cases, you want to have control over which of your documents wind up in the cloud and which you retain custody over. So while viewing attachments in the cloud is very good practice (viewing them locally is a good way to get owned), running a service that generally slurps your local drive (or big chunks of it) into the cloud is not a good idea.
If you want to run a Chromium build rather than Chrome, that's fine.
I provided the reasoning for preferring iOS devices to general purpose computers already. The additional concern you just added doesn't come close to offsetting.
I'll add, though this isn't in the Tech Solidarity checklist, that if the goal is commercially reasonable security and not security in the public interest, Chromebooks are another good option for end-user computing.
> If you deal with sensitive documents like legal artifacts in immigration cases, you want to have control over which of your documents wind up in the cloud and which you retain custody over.
This is incredibly easy with Dropbox or Google Drive. Everyone I know who uses these services has an intuitive knowledge for 'stuff in this folder goes in the cloud', and if they wanted to keep sensitive data off it they would know exactly how.
I am on an iPad, so no mature options for encrypting it myself with pgp or something really exist. I shouldn't upload it to a cloud service (although chances are that it already is, because pretty much every iOS app uses a cloud of some sort). I shouldn't email it. I can't plug in a physical usb device because iOS doesn't have File reading access to. I guess I convince everyone to use Signal? That is pretty impractical for 'normal' people to convert everyone over to their own messaging app.
Also, on your phone, what browser do you use? Chrome? Well, not really because it is all webkit under the hood, so you are going to be using Safari no matter what.
Regarding sharing of sensitive documents: if you have to do it over the Internet, use a secure messenger to do it. Email attachments are probably the second most dangerous attack vector facing end-users (after phishing). That's why we tell people to use Google Mail; attachments open in their browser viewer and are rendered Google-serverside.
You don't need to convince everyone to use Signal; it's adequate to use WhatsApp, which, again, is already one of the most popular messaging applications in the world (this is one of the reasons getting Signal Protocol baked into WhatsApp was such a monumental achievement).
In the particular case you mentioned they aren't picking on Drive, they're saying that if there are copies of your messages that's less secure in the sense that now somebody could get those copies, not the originals you have. Doesn't matter how, write an NSL, break into a server, trick a customer services agent - the problem is you allowed copies to exist, so it's not that Drive is specifically bad but that you shouldn't use anything at all.
For the iOS reliance, I personally wouldn't do this but I can see the sense of the advice. Full blown personal computers are not easy to secure against unsolicited garbage, why take the risk?
That Tech Solidarity checklist does say who it's for, which is a start, but it doesn't tell them what it's aiming to achieve for them if they follow the advice.
For example, maybe WhatsApp makes the list because it uses the Signal protocol design and they assessed that this was especially resistant to attacks on the confidentiality of individual messages. Or, perhaps they felt WhatsApp would protect a journalist's sources especially well due to the large volume of other WhatsApp users acting as cover for any analysis. Maybe they felt the method users follow to confirm that there's no MITM was better (easier to use, better documented) in WhatsApp than competitors, or maybe they felt its owners were more likely to tell the FBI to fuck off if they turn up with a warrant.
> Use a bluetooth keyboard for easier typing.
Creator here - thanks for bringing this up. I was concerned about the message here as well. I'm not getting paid for that ad. I had a couple companies offer sponsorship of this list, but I decided to not pursue. In the end, 1Password simply offered this discount to visitors. For me this felt like the best thing I could do from a user experience point of view (switching to a password manager is hard for most people, and giving the extra nudge to do something really important for their online security might just do the trick) and from an ethical point of view (I'm not getting paid, and will continue adding competing password managers to the list).