layout | title |
---|---|
page |
Introduction |
In short: If you are a professional dealing with sensitive information, such as a journalist, doctor, lawyer, counselor, political activist:
-
Use an iPhone in Lockdown Mode.
-
Use Signal for end-to-end encrypted messaging and voice calls.
-
Use a password manager and 2FA, or Apple's Passkeys.
-
Disable JavaScript in your Browser. For further anonymity, use Tor (The Onion Router).
The remainder of this page is obsolete, but left for reference.
This is an introduction to basic information security practices ("InfoSec101") for professionals dealing with sensitive information, such as journalists, doctors, lawyers, counselors, political activists, and so forth. Contents:
-
InfoSec101. How can you keep your information private and secure? An introduction (covering more secure passwords, browsing, chatting, etc.), including a curated, commented list of recommended software.
-
What to do next. A concrete list of some quick and simple steps, for users of computers (OS X, Windows), and smart phones (iOS, Android), and a list of further guides.
-
If you're not yet convinced that one ought to care about Information Security, there is some background, motivation, examples, and quotes.
-
If you wish, you can read more on the technical background.
This short presentation was given to the Foreign Correspondents Club in HK in February 2015. Here is an alternative version, somewhat drier, but more comprehensive.
- 2022-07-06 Obsoleted.*
- 2016-02-19: Added link to Paragonie's Guide to Securing Your Business's Online Presence, also aimed at non-experts.
- 2015-12-25: Added reminder to avoid short passwords and use at least 12 characters; added GCF Internet Safety link
- 2015-11-23: Added short youtube video on Clients, Servers, Protocols from Udacity to the Technical Background page.
- 2015-11-19: Added the (advanced) OS X Security and Privacy Guide.
- 2015-11-15: Ed Snowden, in an interview with The Intercept, recommends:
- use Signal by Open Whisper Systems,
- encrypt your hard disk,
- use a password manager,
- enable Two-Factor-Authentication.
- use Tor,
- use ad block software.
- 2015-10-05: Reporta, security app designed for journalists, might not be as secure as claimed.
- 2015-09-22: More security flaws and fixes for Flash. Really - just uninstall it completely.
- 2015-03-02: Open Whisper Systems released Signal 2.0 for iPhone. This is the recommended solution now for voice and text chat for iOS (Signal) and Android (RedPhone, TextSecure).
These documents are intended as a supplement to an introductory talk on Information Security for (non-IT) professionals.
Thus:
- They're not necessarily elaborate enough to be fully self-contained.
- They're not meant to elucidate every aspect comprehensively and objectively, but to give some opionated advice on "the best" tool to use for users with
- average technical IT background, and
- somewhat above average need for privacy and security of information.
Feedback from Joseph Bonneau, Dr Melanie Bryan, Silkie Carlo, Nan-Hie In, Michael Lee, Pete Membrey, Larry Salibra, Max Veytsman, Leonhard Weese gratefully acknowledged.