TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Secure Computing for Journalists

179 pointsby _piusabout 8 years ago

10 comments

tptacekabout 8 years ago
A few weeks ago a bunch of us on Slack tried to put together a brief for journalists on why they should prefer iPhones. It&#x27;s still a work in progress, as you&#x27;ll see, but here&#x27;s a draft:<p><a href="https:&#x2F;&#x2F;gist.github.com&#x2F;anonymous&#x2F;9f789aabd7e8681dec0cf5781aecf664" rel="nofollow">https:&#x2F;&#x2F;gist.github.com&#x2F;anonymous&#x2F;9f789aabd7e8681dec0cf5781a...</a>
评论 #13801229 未加载
评论 #13800873 未加载
评论 #13798615 未加载
评论 #13800014 未加载
评论 #13799670 未加载
评论 #13804632 未加载
评论 #13798583 未加载
dguidoabout 8 years ago
I have a security review for a news room coming up, and I plan on sharing this blog post with them. Thanks for writing it Matt! I&#x27;m definitely behind all of the points you made.<p>If anything, I worry that non-technical users will <i>still</i> not understand that desktop programs can do anything you can do with your computer even after reading your post. I&#x27;m not sure the description is &quot;in your face&quot; enough to translate for the intended audience. In their minds, &quot;reading files&quot; may be better expressed as &quot;copy of every email I&#x27;ve ever sent&quot; or &quot;operate my webcam and grab nudes of me.&quot;
评论 #13798379 未加载
评论 #13798742 未加载
r3blabout 8 years ago
I&#x27;ve been trying to secure investigative journalists for about a year and a half, and this article kind of covers two of the points that I make on all of the security trainings. They usually go like this:<p>* Do not have work-related emails on your Android (unless it&#x27;s Google-made). iOS (9+) is okay. * Do not open random attachments on a Windows machine. (We always do our best to convince them to switch to a Ubuntu station with an AppArmor profile for LibreOffice set.)<p>This is a good start. I think this article would be even better if it included some phishing tips (like HTTPS doesn&#x27;t automatically mean &quot;secure&quot;, and if you&#x27;re suddenly logged out of Google for no apparent reason, don&#x27;t just log into the webpage displayed to you, but instead, open Google by typing the address bar manually and log in there).<p>Interesting side-note: Asshats spend days crafting phishing emails specifically targeted to our journalists, and they <i>never</i> get Google&#x27;s postal address right in the footer.
评论 #13799823 未加载
Cieplakabout 8 years ago
This advice makes sense given the threat model. However, it might not make sense for someone in Edward Snowden&#x27;s role. If I were a military agency with a big budget, I would backdoor the shit out of every phone, enforce cultures of secrecy inside companies like google, apple, facebook, intel, qualcomm, at&amp;t, and off any executive that interfered with the mission. Then I would pay experts to spend their lives on internet forums asserting that devices with two cameras, two microphones, wifi that can function as radar, an unremovable battery, a closed-source operating system and root access only available to a major US corporation via ssh, are the most secure computing platforms in the universe. That&#x27;s just me though, if I had a lot of money and lust for world domination, neither of which I possess :)<p>Edit: removed sentence &quot;Most mobile devices have baseband chips with DMA&quot;
评论 #13798348 未加载
评论 #13800722 未加载
remxabout 8 years ago
But if a journalist is going to use a secure desktop Operating System, he&#x2F;she&#x2F;they should investigate the current trio of recommendations which are as follows, and have different threat models baked into each:<p>Subgraph. Currently in Alpha version, so be careful using this. Still has to be vetted by the wider infosec community, but worth downloading and playing around with.<p>TailsOS. Very useful for journalists, but since it heavily relies on Tor it can be tricky dealing with mixed-anonymity workflows where sometimes you just need a Windows environment (preferably an airgapped Windows sandbox you can use to code &#x2F; play around with files using Windows freeware).<p>Qubes. Heavily reliant on compartmentalization, and this can sometimes prove too cumbersome if you typically do one type of activity on the web like chat &#x2F; email &#x2F; hang out on slack. Typically for when you need to insulate different activities from each other and to avoid contaminating different contextual environments &#x2F; tasks.
评论 #13799076 未加载
tyomaabout 8 years ago
This is a great article but only really covers half the issue. The other half is why journalists should use secure messaging applications, and not email.<p>Sometimes the most succesful attacks are phishing attacks that no device will protect against. As an example, it is rumored that John Podesta used an iPad.
评论 #13798502 未加载
patcheudorabout 8 years ago
Use iOS with a privacy proxy they said...<p><a href="http:&#x2F;&#x2F;www.falseconnect.com&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.falseconnect.com&#x2F;</a><p>The first point being, software flaws and particularly those in low level networking libraries can expose secrets and the key I suppose as covered in the article is to ensure your OS is always up to date. The second point, and Dan covers it elsewhere in this thread, be very cautious about insecure hosted VPNs &amp; you should really never trust proxies which some VPN providers are offering.
评论 #13798372 未加载
bubblethinkabout 8 years ago
I wonder how helpful these sort of posts are for actual journalists or whistle blowers. It&#x27;s one thing to tell a casual user to get an iphone as a reasonably secure choice compared to Android&#x27;s fragmented mess, but for someone whose job and&#x2F;or life is on the line, you need a more thorough coverage. You may even need like a mini course of sorts that covers basics of CS and infosec. Short of that, such cavalier advice can be misleading.
评论 #13799946 未加载
claudiojulioabout 8 years ago
IOS more secure than android? Joke ready. IOS is closed source. You can not tell whether Apple, the CIA, or the NSA are spying on you.
评论 #13798286 未加载
评论 #13798247 未加载
评论 #13798248 未加载
claudiojulioabout 8 years ago
To be safe see this site. It has everything you need. Https:&#x2F;&#x2F;www.privacytools.io&#x2F;
评论 #13798283 未加载
评论 #13798719 未加载
评论 #13798275 未加载