Mexican cartels are known to have infiltrated ISPs, where they were able to tie IP addresses to identities. Using encryption is the only way.
EDIT: may I ask why the downvotes? Did I say something offensive or break the HN rules?
Mexican cartels are known to have infiltrated ISPs, where they were able to tie IP addresses to identities. Using encryption is the only way.
EDIT: may I ask why the downvotes? Did I say something offensive or break the HN rules?
I would say that for some of these local journalists, you're correct in suspecting that their technical expertise isn't high...however, it's not easy to report on dangerous local conditions from outside that locality. For one thing, you've introduced another attack vector for a MITM attack -- between the local stringer and the international point-of-contact who then publishes the content.
But the bigger problem is this: the people most passionate about this kind of local reporting, well, they're passionate about it because it is in their town or neighborhood. It's generally not feasible to be a long-time resident (the type who really gives a shit about the terror that's going on in the neighborhood) and then uproot so that you can do reporting safely. For one thing, you're just not as connected to the events once you've left the area.
Some newspapers (correct me if I'm wrong, I think it was NY Times) have even started running an .onion website where people can leave so called "dead drops".
Are a terrible idea. You need to trust the operator that they won't screw you by keeping logs. Since these are centralized they are always at the whims of cartels and the like. Just stop and think for a second if you won't give everything you have to them if they took your children hostage as an extreme example.
The only way to deal with a situation like the one in Mexico is to get the whole community to use something like Tor. The cartels already are so they can't kill all such connections, and if everyone uses it all the time then you can't target anyone for using it. The reporters are protected by the crowd they hide in.
This is the same reason why tor isn't blocked in the first world. It gives all the alphabet soup agencies proper anonymity that doesn't raise red flags when used in other countries which might not be friendly.
Opsec is not a simple matter, as the death of this woman shows and people like the grugq try to explain.
You need serious technical nous to get it right.
And even if that's not the case, using Tor and not linking your online vigilante identity to your real identity (e.g. by having your whistleblower twitter account linked to your personal phone) is a very basic precaution.
I REALLY don't want to sound insensitive, but if people are going to use technology to fight people who wield the power of physical violence, they DO need to learn how to apply it properly.
This flies completely contrary to precautionary measures and utilizing knowledge/education as a barrier to attack. The sooner society gets away from the "that's 'victim-blaming'" mentality and embraces education for all, the sooner everyone is better of for it. It's not saying, "yeah, they had this coming, this is their fault" but rather, "let's analyze the situation and provide mitigation for the future"
Then try to use less insensitive language. "It amazes me that people don't take these basic precautions" sounds an awful lot like "Look at this poor misguided savage, killed because she was too stupid to know what an Onion Router is." Maybe try something like "We need to educate whistleblowers about security technology to avoid tragedies like this."
Anyway, tor wouldn't have helped the woman in the article; she was found by them going through her local app.
(Also upvoted you.)
Unless, you know, the "outside country" is one participating in those surveillance schemes, like 5-eyes, and is in bed with your local goverment and not beyond sending a tip or two (or even supporting its own thugs acting on the ground in your country).
More or less like it has been throughtout the 20th century in Latin America.