Infosec 101 for Activists
infosecforactivists.org
infosecforactivists.org
Sources: https://therecord.media/protonmail-forced-to-collect-an-acti... https://x.com/andyyen/status/1884907496705339544
Not wishing to be negative, but how (or more specifically for how long) can any provider refuse to cooperate with law enforcement/the legal system?
See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.
You know that Telegram is giving plenty much of information in these days?
They even changed the privacy policy.
https://techstartups.com/2024/09/06/telegram-silently-update...
https://edition.cnn.com/2024/09/23/tech/telegram-ceo-durov-a...
A strawman mod to protonmail could be to mandate the use of a VPN
So when law enforcement and/or a three-letter agency rocks up with the legal paperwork (whether it be a National Security Letter or a local equivalent) and demands that "the system" be changed to start collecting the information they require, how should managers and engineers respond?
At least, that was my experience.
Apple gets lots of shit for a multitude of reasons, but their stance of "We built it to be securely encrypted from everyone but the owner; if you want to change that then fuck you, make me" is something everyone involved with should be proud of
Realistically, we can't all be one of the richest companies in the modern era. Not every corporation has both morals, and pockets deep enough to pick a fight with not just a government, but the government of the country they're headquartered in. Frankly, shutting down like Lavabit is one of the better realistic scenarios if you're making promises of guaranteed privacy
I think this is easier: there isn't a single corporation on the earth with morals. Morality and profit-chasing are not generally coherent principles. Nobody doing any good on this earth has a need for an LLC.
Sure, except if there's a nondisclosure provision...
"A national security letter is an administrative subpoena issued by the United States government to gather information for national security purposes. NSLs do not require prior approval from a judge. NSLs typically contain a nondisclosure requirement forbidding the recipient of an NSL from disclosing the FBI had requested the information."
That's a good question.
https://en.wikipedia.org/wiki/Apple–FBI_encryption_dispute
As a result of this, Apple released a series of tools such as iCloud Advanced Security where they don't even have the keys (but causes user support issues, users can now "lose everything" with no recourse, which is why this isn't on by default; most users' "threat model" is more risk from deleting themselves accidentally than of nation state disclosure), along with the new feature that a phone not being actively used turns itself, off, and a few more things.
// See also: https://www.wired.com/story/the-time-tim-cook-stood-his-grou... or https://archive.is/fvAqN
when they got that court order that wanted them to retain logs, they , challenged it immediately- and the rulingcame down - and they won.
They can no longer be compelled to cooperate in cases of crimes in other countries that match crimes in Swiss laws, as happened here- and this happened because they fought back -it just took time for the ruling to come down.
https://www.msn.com/en-us/money/other/protonmail-wins-privac...
https://protonmail.com/blog/court-strengthens-email-privacy/
So they are in a good position on that aspect -most countries aren't as solid legally.
Not that it matters though, since I assume all of us here know how encryption works.
I guess that is to be expected by msm, good promo for proton imo.
Activist or Protester? by EFF's Surveillance Self Defense https://ssd.eff.org/playlist/activist-or-protester
The Protester's Guide to Smartphone Security by Privacy Guides https://www.privacyguides.org/articles/2025/01/23/activists-...
for everything else read material from anarchists. ex: https://opsec.riotmedicine.net/downloads#mobile-phone-securi...
Step 2: Realize that none of these measures are adequate for that threat model, in the current environment. (For pretty much any threat model.)
Step 3: Realize that some of these measures draw attention to yourself, however.
How is removing biometric auth going to draw attention to yourself? Also, would love to know why this isn't an adequate measure for security.
people just need to calm down with the "gotcha" comments
Just take the fucking L and move on. Christ.
This makes a good case for using them all the rest of the time. If you’re in a relatively safe position you can help to normalize privacy to provide cover for those who need it now, and perhaps for yourself should you need it in the future.
See also: https://qubes-os.org (my daily driver OS).
Articles of the formula "Want to be an activist or journalist, resisting powerful tyrants? Just install these apps, to be safe!" can be misleading.
https://www.notrace.how/ / http://i4pd4zpyhrojnyx5l3d2siauy4almteocqow4bp2lqxyocrfy6pry...
How about this: if you feel strongly about commercial ad surveillance vs. susceptibility to drive-by RCE exploits loaded off web pages, look to see if the "infosec for activist" guides you're reading at least offer their readership the choice of risks. Does this one? (Rhetorical, obvs.)
Exploits, on other hand, can leak your full environment, including a photo from the cam.
Is Firefox more susceptible to RCE exploits?
All I have seen as a casual user is this from GrapheneOS: https://grapheneos.org/usage#web-browsing
It asserts that Chromium has much better sandboxing and site isolation than Firefox.
> This is not smart. It's entirely reasonable that Chrome may be better on top of its exploit game; but this absolutely pales in comparison to the threat of universal surveillance that Google hits us with frequently.
So the smart thing is to use Chromium, then?
The activists that are legitimately, specifically targeted should probably be past the "101" series of infosec and not be using either without significant other considerations and protections.
Of course, none of them do, because the premise of that question is alien to them. It requires understanding that Firefox and Chrome have different runtime security postures, and to talk about that you have to be willing to push through a fogbank of people ideologically opposed to the idea that Chrome could be, at a technical level, better.
This comment sounds like you think guides should be more nuanced regarding the specific threat model that is trying to be mitigated.
I agree with the second one.
As a security person, I have borne witness to many, many "which browser is really more secure?" or "has Firefox caught up to Chrome?" arguments. I have seen "you should use Chrome (or Chromium) no matter what" as responses; I have seen "it's complicated" as responses. I have never seen "you should use Firefox no matter what".
But that's probably for some other time, I imagine we can leave it at agreeing "this guide is not great". I doubt it is good for my career to butt heads with the tptacek on a security topic.
I just think it's an interesting way to think about these things. There are a couple recommendations these kinds of guides recurringly make that are "tells" that the people writing it aren't, let's say, super engaged with the communities of expertise the recommendations are meant to be drawn from.
I learned last cycle not to waste too much energy red-penciling security guides; there will be more of them following this one. But I am interested in general rules of thumb for how to read any of them.
For what it's worth, I comment here worrying that 'saurik and 'comex and 'pbsd are at any moment about to hand me my ass. Wherever I am in the heirarchy, it's not close to the top.
On this topic, I wonder if Chrome’s safe browsing notably improves the user’s security?
It sends user’s private data to Google for scanning. The trade off has to worth it.
Because if I was running SIGINT at the NSA and collaborating with the FBI to arrest activists, the very first thing I would do is start up a bunch of VPN providers that bill themselves as "private" and then log everything aggressively.
The second thing I would do is have useful idiots (i.e., influencers) spread vague anecdotes about Tor users being "de-anonymized" when VPN users are never "anonymized" to begin with. I would make sure these anecdotes never clarify whether it's "Tor users accessing Hidden Services and getting popped by a Firefox exploit" or "network attack that enables traffic correlation" so everyone fills in the blanks and assumes Tor is dangerous, when it isn't, thereby pushing activists to my VPN services.
After all. There is no real enforcement mechanism if a "private" VPN lies.
https://www.theregister.com/2011/09/26/hidemyass_lulzsec_con...
An unfortunate factor at play in these matters (and that I note in the article) is that the intelligence services are known to run the occasional shell company [0]. It seems likely that some privacy-oriented providers are actually intelligence fronts - because if you were running an intelligence collection agency an obvious thing to try would be a privacy-focused email company or something.
If it isn't built on a trustless model it isn't trustworthy.
My first post in this thread has a link that explains why VPN services aren't trustworthy.
But the thing I took more issue with is that Tor is omitted entirely. Tor is at least as safe as a VPN.
Trying to attack Tor users by registering exit nodes (a Sybil attack) is way more expensive than convincing users to simply not use Tor.
The fact that more effort is spent attacking Firefox (i.e., the Tor Browser) than the network is a data point worth considering when deciding your threat model.
https://www.malwarebytes.com/blog/news/2024/10/tor-browser-a...
Meanwhile, if you want to do traffic correlation against a VPN service that you don't already own, just pwn the datacenter that the VPN company is hosted in and watch packets coming in/out of the VPN.
If you want to try to reframe the conversation to be about defending Tor, you can have that conversation without me. I'm not here to defend Tor, I'm here to advise against using VPN services especially if you have a threat model where Tor is more appropriate.
Recommending ProtonVPN over Tor to motherfucking activists is an act of malfeasance that makes me distrust anything coming from this webpage.
https://krebsonsecurity.com/2014/09/dread-pirate-sunk-by-lea...
Sure. But with a limited budget (of both the financial sort and the effort sort), this just isn't feasible. Who the hell wants to manage not one but twenty seemingly private industry vpn companies? Can they even reach break even status so that it's not a drain on the budget? How long for that? Worse, it entangles their revenue with that of the NSA, making the NSA more vulnerable to the sort of leaks they don't like to have, exposing them to foreign intelligence services and even journalists.
>spread vague anecdotes about Tor users being "de-anonymized" when V
Ulbricht found out the hard way. When you've got every fiber tapped around the world, it becomes trivial to deanonymize Tor users. Granted that it's nearly impossible to climb to the top of the US government's shit list like he did, but if you do manage the feat, they'll know who you are within days.
They didn't find Ulbricht by hacking the Tor network to deanonymize users.
Once he was identified, they trolled through his internet history to find something that if they were luckier than any investigators ever they might have found without cheating. Then claimed they actually did that. It was all horseshit. None of this is controversial. Didn't even have to hack Tor, traffic analysis sufficed.
> When you've got every fiber tapped around the world, it becomes trivial
These phrases are in conflict.
If their budget is limited, we shouldn't expect them to be able to trivially tap the whole world.
If tapping the whole world is trivial, they probably have the resources to spin up some VPN front companies. Or more likely, suborn existing VPNs.
Not to mention even turning a phone off does not guarantee it goes silent. Apple's Find My network works even for turned off devices. Now of course you can turn that feature off, but once the capability to track a turned off device is there, we have to assume that a nation state actor has exploits/backdoors that allow agencies to bypass basic software switches.
You have to assume everything you do on a mobile phone will end up in law enforcement/intelligence agency databases if you're put on a watch list.
[1] https://googleprojectzero.blogspot.com/2023/03/multiple-inte...
edit: my knowledge is clearly out of date.
I can't speak to when Android started doing this, but I know the common chipsets (Qualcomm, Exynos, Mediatek) also do this.
The majority of activists are not worth the effort or expense. And for the ones that are worth - those guides make no difference since they don't harden as much. If you want real security - then the least you must do is have two devices. One used for hotspot only.
are these sophisticated adversaries in the room with us right now?
Most people are completely missing the point in this thread.
The idea that you'll be arrested by some super secret state actors and not Jim Bob the police dude is absurd.
> Keys to unlock the phone’s full-disk encryption are also stored in the iCloud backup. This arrangement allows law enforcement to request the backup data from Apple and use the key to unlock the entire phone. It also offers a convenience, where if the user forgets their unlock code, Apple can still recover the device.
This is not true. Even if it were, the advice to activists should in all cases be to enable Advanced Data Protection so that almost everything (except iCloud mail, contacts and calendar) are end-to-end encrypted (including iCloud phone backups). Apple cannot access the data or help in any kind of recovery when Advanced Data Protection is enabled. It is up to the user to set up recovery contacts and recovery key (and keep this safe).
I get that the backups can potentially be compromised, and of course having the backup means having most of what would be on the phone, but I would love to know more about how having a copy of a backup can compromise the physical device via iCloud.
I cannot stress this enough. We survived protests without them in the past. There will be plenty of professionals filming anything going on.
Coordination needs to be zero tech.
Keep up the good fight!
Generally speaking, with people like comrade elon having so much say into everything, people rushing to pump out new features daily, most often not putting too much effort into security, I've been making a hard push to cut myself off cloud services and self-host everything I can myself.
Can the full might of the fbi and nsa own you of they want? Likely.
The threat model here is local PD, and the goal is to make their job of incriminating you in any way, harder. Meaning making it harder to get into your phone. Harder to passively intercept data like sms and phone calls. Harder to get days by asking the big companies like google.
Any ways to check the current updated official images against what is installed on the phone or notebook via a oneliner or an app?
Like in a couple of minutes like a virus scan.
Burning the hardware is one thing but having confirmation would be nice.
It would make more sense to leave your phone on and at home. However, you can’t use any of the tools the articles lists if you have no phone.
I wish I were making that up. You now have to repeatedly state it.
The USSC has been off the rails for at least ten years.
If you are arrested, then yes you do have to assert your right to remain silent.
https://www.justia.com/criminal/procedure/miranda-rights/rig...
Invoke the right and stay silent.
Do not answer the obvious bullshit questions, those are used as bait, once you start answering any questions, you lose your 5th amendment protection.
And then they send you the bill for shoe polish.
And every time one is uncovered, it is always the case that they've done it before, many times. That "vast majority" may not kick the shit out of you, but they seem willing to tolerate it when others do.
It's even worse at protests, when police officers have been told to expect violence. When you go to a protest, you assume that you are taking physical risks.
https://slate.com/news-and-politics/2017/10/suspect-asks-for...
But in all seriousness: Do not be afraid to sound like a fool making short, unambiguous, and repeated requests for a lawyer if you have to.
This is not my reading. For those who want to read the actual details: https://supreme.justia.com/cases/federal/us/560/370/
Here are some nuggets from the case:
"At no point during the interrogation did Thompkins say that he wanted to remain silent, that he did not want to talk with the police, or that he wanted an attorney."
"Thompkins did not say that he wanted to remain silent or that he did not want to talk with the police. Had he made either of these simple, unambiguous statements, he would have invoked his “ ‘right to cut off questioning.’ ” Mosley, supra, at 103 (quoting Miranda, supra, at 474). Here he did neither, so he did not invoke his right to remain silent."
Omitting pertinent information is the tool of debate not of discourse.
the context to me still says that remaining silent does not invoke the right to silence.
unless tou break your silence to aay that you intend to be silent, yiu will be prosecuted for your silence
I cannot seem to find any supporting text in the SCOTUS text that merely being silent waives rights. Quite the contrary, my quote indicates it that as soon as the I would assert my rights, even in the middle of the interrogation, the interrogation would have to halt. (Additionally, the interrogated Thompkins did speak and answer, it was just terce.)
>I wish I were making that up. You now have to repeatedly state it.
Again, I can find no evidence in the SCOTUS opinion that once I assert my right, I have to repeatedly re-assert it.
From your note:
> unless tou break your silence to aay that you intend to be silent, yiu will be prosecuted for your silence
I find nothing of sort in this case. I can remain truly silent, and my silence cannot be used as evidence of guilt. Of course I can still be prosecuted with other evidence. Griffin v. California (1965) , Doyle v. Ohio (1976), and Salinas v. Texas (2013) just to name a few.
If I missed these, please point me to it so I can correct myself.
No. Based on the opinion linked in one of the other comments, there are these possibilities:
- explicitly say you are invoking your right to remain silent -- the have to stop asking you questions
- say nothing -- you're fine, your right to remain silent means they can't use this against you
- answer questions (without being coerced) -- if they read you your rights properly and confirmed you understood, this waives your right to not do what you just did; if they messed up, then you can get your answers thrown out
I'm currently a Firefox user at home and work, but thinking about going back to Safari in the near future...
You don't have to build it yourself, but other people do and deterministic builds can provide collective assurance the code is what it claims to be.
Sure, your messages are encrypted, but they (whoever they are) have the private keys (both sender and receiver) because the smart phones you are using are compromised by them.
It's really simple.
So next time you read a news story about criminals who were using some supposedly secure app to commit crimes, but got caught anyway... keep this in mind.
It's really simple.
This is a really, really ignorant imperative. First of all, the criminalization of poverty and structural injustice, generally, make technically criminal activity inevitable in some communities, but I recognize that what you actually mean is "don't commit criminal acts of protest" which is still ludicrously ignorant—and cruel!
Civil disobedience, by definition, involves the deliberate violation of a law. It is, nevertheless, our duty to perform when laws or systems perpetuate severe injustices, democratic failures, or lack legitimacy.
As John F. Kennedy famously put it, "Those who make [legal] revolution impossible will make [criminal] revolution inevitable."
This is economics.
You can also believe that there is an industry-wide conspiracy in which everything is backdoored. But that's a philosophical/political claim, not a technical one.
Which type of claim are you making?
Which secure enclaves? If you can read a message on your screen and your OS obeys somebody else, not you, then they can also do it.
Yes, any use of the network is a risk. You take a risk just showing up. This is about mitigating risk, not eliminating it. You have to decide if it's a risk worth taking.
I’ve read the EFF’s guide and it seemed reasonable for a layman. What caveats or disclaimers would you include that they haven’t already? What more do you feel could be done to make people with these needs safer while helping them pursue their goals?
Regarding Proton specifically:
- Proton has been lying about them not logging their users IP and other information in the past. It got caught red-handed in 2021 when they transmitted the data of a user to a french intelligence agency called DGSI. Source(s): https://therecord.media/protonmail-forced-to-collect-an-acti...
- Now they say: "Privacy by default", what they mean by it that by default they do not log the user's information but if an agency asks them to log then they "are required by law" to log the user's data. But the user has no way to know if he is still in the "privacy mode" or has switched to the "surveillance mode".
- It is actually possible that they log everything and use the "by default" wording as a "plausible denial". By saying that your account had been flagged earlier by law enforcement or an intelligence agency.
- All Proton mail traffic goes through Cloudflare. Let that sink in. Yes, they says that the traffic is encrypted using https and that Cloudflare can't see it's content, which might be true. But even if it is true Cloudflare gets to see a ton of interesting meta data, such as the end user's IP, the exact time and the length of what the user is being sending or receiving. Source: So even if you are in Switzerland and you use ProtonMail which is in Switzerland too, your connection still gets tunneled through an American company. Source: https://x.com/andyyen/status/1884907496705339544
I see https://infosecforactivists.org/#acknowledgments and https://github.com/InfosecForActivistsTeam/infosec-activists... but I don't see their experience following their own advice.
The document by itself looks unpolished. Tor, for example, should be at least referenced once, even if they recommend against it.
http://i4pd4zpyhrojnyx5l3d2siauy4almteocqow4bp2lqxyocrfy6pry...
The Grugq has complementary advice which arguably is more important, regarding foundational principles, personas and so on:
https://www.youtube.com/watch?v=L3j1AhS0iKI
https://www.youtube.com/watch?v=3w7E4Hhtubw (there's a bit of presentation and ceremony before they get into the relevant parts)
Immediately closed tab, this post is useless.
WhatsApp has E2EE for all messages too, I don't understand why people think of Signal as a bullet-proof instant messaging solution for privacy, especially when
1. Requires Phone Number in order to use (I'm sure fanboys have explanations for that)
2. It is centralized
3. Uses APNs or GCM for push notifications
Most devices have some kind of GPS or positioning system. Phones in particular still communicate certain information to cell towers and E911 even if there is no SIM installed. Wrapping your phone in aluminum foil does not block all the signals as many have been lead to believe. It is not certain, especially with 5G what faraday bags can work. Your best bet is a phone where you can remove the battery. Even this could leave residual power in the device.
One of the most non technical aspects of Government surveillance, especially in the United States, is that their ability to request data depends on each specific provider. Usually, law enforcement has long standing relationships with all these companies and the higher up you go in the U.S. Govt, you get more of this. After all, there are a million ways the Govt can keep a device off the market if they do not comply with whatever the Government wants. Maybe most importantly, parallel construction is often used here. For example, law enforcement will only follow the rules and get a warrant if they intend to present a case in court. Often, they just want information and if they want to use it they will find a way to parallel construct its source. Do not rely on your constitutional protections or anything else. In many cases it is simply not a factor for them.
Everything about your phone comes back to the sim card. It is extremely difficult to get a working SIM without some form of ID. Most SIM cards are traceable this way, especially if you purchase them in the U.S. Most services require a form of authentication as well, often a phone number which requires the SIM belong to someone, or an email address, which very often requires a phone number to create. Used burner phones are your best bet.
Any cloud service connection your phone initiates is able to be intercepted and the Govt can deploy a form of a man in the middle decryption attack with the help of your cell provider. This is not used as often but unless everything you have uses certificate pinning, and often this isn't the case, it is very easy to man in the middle your end to end traffic and decrypt it.
Applications also leak like crazy to various APIs and other things they use. Connections can be downgraded to HTTP and all other forms of tricks to monitor you are used.
For example, if you are using an end to end encrypted messaging app, and you have the content of those messages going to the apple or google notification system, you do not have end to end encrypted messaging. This is why Signal disables the content in the notification by default.
There are other attack surfaces here as well. Keyboard autocomplete is one as it uses remote services. If LE knows you are using something like Signal, and they can see you created a new contact on your phone to message them, they already know who you are talking to you, and if your phone keyboard is using autocomplete or grammar correct, they could potentially get what both sides are writing to each other without actually breaking the encryption.
There are other methods as well. iPhones have the ability to use a form of Remote Desktop that can be accessed over the cell connection. So as you are using the app, your screen can be monitored, thus defeating any encryption security you think you have.
If Law enforcement knows you have cloud accounts, say with iCloud or Google Docs, and you are working on something in there, you can be sure that it is possible for your work to be viewed as you are working on it. This has a ton of implications for people just doing normal non activist work as well. Maybe you're working on your own legal case and they can literally just watch you build a legal defense and then plan accordingly. It really is endless what they can do.
If the Govt is interested in you, most cities are full surveillance cities now. You can have no phone, no RFID anything, change your routes, change your appearance and you will still be found. There are rare exceptions to this but for the most part assume you cannot move around a city without being constantly monitored. Even if you only have a pair of bluetooth headphones, there are all kinds of devices collecting broadcast data, and these can be correlated with device lists uploaded when you pair a device.
This is just a short list of things I've experienced personally... There is so much more. Any large formal resistance basically cannot happen without the Govt knowing about it.
EDIT: Sorry for the wall of text
Case in point: how BLM protests were turned into riots by antagonistic forces: https://abcnews.go.com/US/man-helped-ignite-george-floyd-rio...
That to organise effective action on the ground, smart protesters were distracting the anti violence bleeding hearts while discussing and implementing more effective actions.
In particular it was stated that part of those particular riots were a distraction to (successfully iirc) lure the cops away from the police station.
Please share a link then.
> That to organise effective action on the ground, smart protesters were distracting the anti violence bleeding hearts while discussing and implementing more effective actions.
There's a lot to be unpacked there, but I'm not sure about what you think is "effective action" and why peaceful demonstrators are a bad thing.
Here's a study that backs up my initial statement: https://acleddata.com/2020/09/03/demonstrations-political-vi...
>Here's a study that backs up my initial statement
They wanted the cop, or at worst the building to burn. Peaceful protests were never going to achieve either. They managed 1/2.
https://paper.wf/downas/partisan-accounts-of-the-george-floy...
Why delegitimizing those who don't abide by the rules of “peaceful protest” amounts to defense of the status quo:
https://north-shore.info/2024/10/04/not-liking-someone-doesn...