6 ms·
A Guide to Not Getting Hacked
- edraferi 9y agoThis is a pretty thorough introduction to personal digital security. It starts by emphasizing Threat Modeling, which lay users often forget. Most of the recommendations are standard (password manager, two factor authentication, basic OPSEC, ad blocking plugins) but it also has a fairly detailed discussion about the TOR browser. The recommendation to use a VPN may be controversial, but it includes a discussion of the relevant threat model, which helps.
- ryanlol 9y agoThis is overwhelmingly terrible advice. It even tells you to install a mobile antivirus!
- paulryanrogers 9y agoWhy else is it terrible?
- ryanlol 9y agoIt also recommends running an antivirus on desktop, using a VPN, using tor browser, pidgin and goes as far as discussing android as a viable option. The “lock up your SIM” part is simply ridiculous too, this has never ever stopped anyone. This article is terrible because it has clearly been written by non-experts who should not be writing any security guides.
- deleted 9y ago[deleted]
- Redoubts 9y agoI’m out of the loop, what’s wrong with pidgin?
- ryanlol 9y agolibpurple suffers from very poor code quality, leading to tons of exploitable vulnerabilities. Just as you would expect when writing C parsers for lots of complicated protocols.
- the_common_man 9y ago> libpurple suffers from very poor code quality, leading to tons of exploitable vulnerabilities. Just as you would expect when writing C parsers for lots of complicated protocols. Is this your personal feeling or do you have something to back this up? A quick look at the source code suggests it's basically like any other glib based program.
- ryanlol 9y agoThis is a commonly known fact, not just my personal feeling.
- daxorid 9y agoThese are just public ones: https://www.cvedetails.com/vulnerability-list/vendor_id-6938/product_id-11666/Pidgin-Pidgin.html https://www.cvedetails.com/vulnerability-list/vendor_id-6938... Filter by CVSS > 6, note the number of execs. Enjoy.
- jlgaddis 9y agoYour comments (this one, and others downthread) get downvoted to hell yet tptacek's comment [0] -- which says basically the same thing -- is at the top. WTF? [0]: https://news.ycombinator.com/item?id=15735789 https://news.ycombinator.com/item?id=15735789
- drdaeman 9y agoInteresting. I'm not an security expert, but believe locking SIM card with a PIN code is a reasonably good idea to ensure in case of a stolen smartphone (non-targeted) it would be more likely thrown out as useless rather than used for any nefarious purposes. Or I'm wrong?
- ryanlol 9y agoSIM card PINs are not discussed in the article. Instead they recommend asking your telcos support rep to attach a note to your account to prevent sim swapping, which doesn't work.
- suyash 9y agoMost of the advice seems to be very sound to me other than the mobile anti virus. I've used Lookout several times on Android, and it does nothing to prevent malicious software, I know from personal experience when I Android got Malware and lookout scan reported everything is fine.
- qrbLPHiKpiux 9y agoBut nobody really wants to understand anything. They want a turn key solution. An intro to threat modeling is good. But it’s lost on deaf ears. The weakest link in compsec will always be the person using the device.
- eropple 9y agoI have been programming computers for twenty-two years right now, using them for twenty-five, and I don't understand much of anything. I probably understand more than, what, 95% of the population? More? And I still do things that I am sure are stupid and clueless. Whether people "want to" or not is not relevant or meaningful. People have stuff to do. Wringing one's hands about "oh, but they don't want to understand" is the toxic kind of elitism.
- ajb 9y ago"It is a profoundly erroneous truism, repeated by all copy-books and by eminent people when they are making speeches, that we should cultivate the habit of thinking of what we are doing. The precise opposite is the case. Civilization advances by extending the number of important operations which we can perform without thinking about them. Operations of thought are like cavalry charges in a battle — they are strictly limited in number, they require fresh horses, and must only be made at decisive moments." - Alfred North Whitehead
- ploggingdev 9y ago> Do use antivirus I think the standard advice from the security community is to not use any antivirus at all and maybe only Windows Defender if you're on windows. The advice to use Tor browser is also terrible. The Tor browser is based on an older version of Firefox ( currently version 52 vs 57 for upstream Firefox ) and so might contain known bugs. On a side note what does the security community think about Qubes OS [0]? The approach of security by isolation is interesting. [0] https://www.qubes-os.org/ https://www.qubes-os.org/
- robin_reala 9y agoTor Browser is based on ESR releases of Firefox which have security fixes backported.
- chippy 9y agoFirefox 52 is a special Extended Support Release version and will continue to get security patches.
- tptacek 9y agoESR releases get a subset of security patches. Don't use Tor Browser.
- fffimem 9y agoNot true. It’s based on the long-term-support version of firefox, called ESR. The ESR branch typically eschews new features for stability but certainly receives any security bug fixes alongside evergreen firefox.
- kuschku 9y ago> The advice to use Tor browser is also terrible. Mozilla uses tracking scripts in Firefox, which in some versions (such as Firefox Beta, Developer Edition, and Nightly) can not even be disabled (If you go to about:config, you’ll notice that toolkit.telemetry.enabled is "locked:true"). So Mozilla themselves suggests that if you do not trust Google Analytics to hold up their agreements with Mozilla, you should instead use another browser (e.g. Tor Browser).
- stoolpigeon 9y agoI don't understand why their first point for mobile was "Get an iPhone" but they didn't do something similar for desktop. Why didn't they say "Run OpenBSD"?
- ryanlol 9y agoOne is good advice, the other is not. HN: The only place where you need to explain the difference between iOS and OpenBSD.
- foodstances 9y agoBecause an iPhone is easy to use for the vast majority of people and OpenBSD is not.
- folknor 9y agoI've installed Xfce/Gnome/Mate on new computers for senior family members and they don't even notice half the time. They just think it's a new version of Windows or Mac. In age ranges from 40-72+. The "vast majority" you speak of probably mostly use a web browser and a mail client, so their interactions with the actual OS are minimal. Sometimes I get calls about digital cameras (or phones nowadays), so then I either go there and set it up, or have them open external access in some manner (usually Teamviewer, because it's easier for them). But this is rare, and of course I don't mind talking to them and helping them anyway. And it would also happen when they used Windows.
- unicornporn 9y agoProbably fine until they try to install Spotify, or some other life critical piece of software.
- SomeStupidPoint 9y agoEveryone should appropriately consider the source (and their security concerns), but this also exists: https://github.com/iadgov https://github.com/iadgov It provides some advice and references a number of other government sources once you dig into it.
- xcopy 9y agoLike
- JepZ 9y ago> Mac users can install Adium, PC (and Linux) users will have to install Pidgin and the OTR plugin. No word about OMEMO[1] or Conversations[2]. I think running your own XMPP Server with end-to-end encryption should be pretty safe (if needs to be safer run it within a VPN). After that the unsafest part is probably to device you use your app with (closed source firmwares nobody has ever seen). https://xmpp.org/extensions/xep-0384.html https://xmpp.org/extensions/xep-0384.html https://conversations.im https://conversations.im
- davidscolgan 9y agoI've lately only been using Linux on my laptop and desktop, but my grandparents recently asked me about advice on a new computer. Is the current best practice to avoid all antivirus software and assume Windows 10 is secure with whatever is built in? Grandpa thinks Avast makes his computer secure and is using their custom browser for his banking. Is my great distrust in all antivirus systems as worse than the viruses they theoretically find still valid?
- theossuary 9y agoI think so. Antivirus systems are a huge attack surface. Maybe have windless defender installed; make sure Windows automated patching is on; use the latest version of Chrome or Firefox with an ad blocker installed, and don't give them access to the admin account. And if you're paranoid like me get a managed switch and setup Snort to monitor your network. That'll protect you more than an antivirus will.
- davidscolgan 9y agoMakes sense. For some adblocking on steroids, put all of this in your hosts file: http://someonewhocares.org/hosts/ http://someonewhocares.org/hosts/ 12,000 domains of ads and tracking blocked at the OS level!
- folknor 9y agoI've used https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts for years now, and any close- and extended-family laptop or computer I touch gets it either silently or with some explanation if they ask me what I'm doing. Noone has ever complained. My only gripe is that I haven't written a cron-type update script for my extended family members who use Windows. Which means I only update it for them periodically. It's still better than not doing it. It aggregates someonewhocares.org and many other sources into a combined hosts file, to the point where it actually slows down DNS lookups noticably on most computers. I even use it on my phones, and all other devices where I can access the filesystem. Almost all devices in the world support a hosts file, becase most of the network stacks in use today spring from the same code. EDIT: It has 40-55 thousand host entries, depending on which version you use. In my scripts I just curl https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts https://raw.githubusercontent.com/StevenBlack/hosts/master/h...
- beamatronic 9y agoFor the parents and grandparents: Do as much as you can with just a Chromebook Use 2 factor authentication Don't go anywhere near Windows
- trumpisyourdad 9y agololvice
- gggvvh 9y agoBan China, Russia and India IP space. Problem solved. Edit: what’s with the downvotes? Burned much? Hey, try looking at your failed ssh login attempts before and after doing this. You’re welcome.
- suyash 9y ago"Camera access" - let's discuss this in more detail. So I am not convinced that I need to put that ugly piece of sticker onto my laptop camera. Is this really a big problem on Mac or no. Is there another alternative than putting some ugly sticker on a beautiful laptop?
- teamhappy 9y agoIf you don't use it you can disconnect it from the motherboard. ifixit.com can help you find the connector.
- kfriede 9y agoI printed a blank strip of "White on Black" label tape and stuck it over on my MBP. I only see it when I'm in a super bright environment, such as in sunlight. Otherwise I forget its there.
- jlgaddis 9y agoIf you don't want an "ugly sticker" on your laptop, you can get some nice laptop camera stickers [0] from the EFF. I have them on all of my laptops. [0]: https://supporters.eff.org/shop/laptop-camera-cover-set https://supporters.eff.org/shop/laptop-camera-cover-set
- suyash 9y agoPretty solid guide, considering sharing this with all your family and friends on Facebook, email etc as an average Joe can learn a lot from this.
- tptacek 9y agoEverything that's in this piece that's true is on the Tech Solidarity guide. What isn't, is false. https://techsolidarity.org/resources/basic_security.htm https://techsolidarity.org/resources/basic_security.htm In particular: * Do NOT install antivirus on your computers. Antivirus software is absurdly dangerous. The closest you'll come to benign AV is Microsoft's, but that's an asymptotic kind of safety. * Do NOT go out of your way to funnel your traffic through a commercial VPN provider. If you need a VPN for your NGO or journalism outlet, let me or someone else trustworthy know, and we'll set up Algo for you. No commercial VPN provider is safe for at-risk users. * Do NOT EVER use Tor Browser. It's the least safe browser you can use: a lagged fork of Firefox for which whole classes of security bugs are potentially WONTFIX'd, and also the only browser that goes out of it's way to collect high-value targets. * Do NOT install Adium or Pidgin to speak to people over OTR. It's difficult to find exploitable bugs in libotr, but it is not difficult to find them in libpurple. Use Signal, WhatsApp, or Wire. * You would have to be out of your fucking mind to install mobile AV.
- ikeboy 9y agoIs tor browser inside whonix good? Would you recommend a different browser inside of whonix instead?
- tptacek 9y agoIf you use your browser for more than one site per execution, having your browser process owned up is devastating. Don't use Tor Browser.
- raarts 9y agoWhat's the better alternative?
- ryanlol 9y agohttps://medium.com/@thegrugq/tor-and-its-discontents-ef5164845908 https://medium.com/@thegrugq/tor-and-its-discontents-ef51648... You really just want to use Chrome/Chromium.
- proee 9y agoRegarding web extensions like Adblock or others, this seems to be quite risky I'm using because the developers of the plug-in could get hacked and silenly release a version that captures your password fields. Are we really ok giving full read/write access to our webpages from companies we know nothing about? I'm considering removal of all web extensions that have read/write access. Thoughts?
- jdietrich 9y agouBlock Origin is GPL licensed. It collects no analytics. The code base is concise and highly legible. The primary maintainer (Raymond Hill) appears to be a principled man. I don't think that it has been independently audited, but I trust it more than most of the software on my computer. https://github.com/gorhill/uBlock https://github.com/gorhill/uBlock
- proee 9y agoRight, but do you trust that his entire system is locked down. Wouldn't this be the ultimate target by a hacker at the highest level. They might even go so far as to physically breach his location if they knew they could gain access to his machine. Installing keyloggers, etc. This might allow them to change the plugin at the last minute if he made an update and pushed it out.
- Santosh83 9y agoYes, but your parent is afraid that an extension's account may be hacked. Now that going forward Mozilla will be doing only minimal manual code review on AMO, this is not an entirely fanciful concern. We talk about reducing the attack surface of every other program out there, but funnily enough, almost no one mentions reducing the attack surface of the single program that's more exposed than almost any other to exploits: the web browser. On the contrary we pile it with addon after addon and even the browser makers have long succumbed to feature creep.
- mar77i 9y ago....With my 32 years and tech affinity I simply can't imagine owning a credit card. The missing security being one thing, but it may also have to do with relatives being perpetually short on money for debt they accumulated themselves.