14 ms·
Secure Computing for Journalists
- claudiojulio 10y agoIOS more secure than android? Joke ready. IOS is closed source. You can not tell whether Apple, the CIA, or the NSA are spying on you.
- dguido 10y agoDo you own a disassembler? I do. Also, a decompiler, debugger, and other analysis tools. Closed source does not mean "black box." And besides, open source doesn't mean anyone has reviewed the code. Reviewing a program for security takes work, regardless of whether it is open or closed.
- claudiojulio 10y agoI really do not understand any of this. I am in the 1st period of the Information Systems course. But I know one thing, it's much easier to find a backdoor with the open code than the other way around. Besides that nothing guarantees that with these techniques you do not miss something.
- idlewords 10y agoWhether it's open or closed source, you have to examine the actual binary code to see what's running on the device. And the tools for this are very good. Both Android and iOS have been very heavily vetted.
- mikhailt 10y agoIf you don't understand this, then you're in the wrong business. I hope your school teaches that even vetted security code can be turned against you.
- deleted 10y ago[deleted]
- mikecb 10y agoMany people who find bugs for a living would argue the opposite.
- tedunangst 10y agoOne of my perennial favorite HN comments: you, the professional reverse engineer, could not possibly do what you do. I've never tried to do it, but I know you can't.
- jhlgkhkhil 10y agoMore like I the lowly software developer can read code but I can't reverse engineer - and why should I learn?
- tptacek 10y agoIt's fine not to learn. What's less fine is stridently asserting, as you have all over this thread, that security advice from experts is flawed while at the same time huffing about how little time you have to learn about the details.
- jhlgkhkhil 10y agoI have repeatedly asked you to actually provide some citations for your claims. Please do so.
- detaro 10y agoExplicit backdoors are a tiny part of the risk you are exposed to, so even if the risk of a undiscovered backdoor in a product is higher than in another, it can still be more secure overall. The article we are commenting on explains quite a few points counting in favor of iOS. An adversary doesn't care about backdoors if the thing you use has plain old unplanned vulnerabilities they can exploit instead.
- pag 10y agoGiven enough googly eyes, all bugs are hilarious.
- claudiojulio 10y agoHello! Have you seen the CIA's leaks? It does not matter, because you should already be aware of all the vulnerabilities in IOS.
- deleted 10y ago[deleted]
- mikhailt 10y agoOpen source doesn't mean it's secure either and you have no proof that Google isn't doing the same via its Google Play Services on top of Android nor do you have any proof that none of the Android manufacturers are not modifying the Android code without your knowledge. Recall this security issue: http://www.prnewswire.com/news-releases/kryptowire-discovered-mobile-phone-firmware-that-transmitted-personally-identifiable-information-pii-without-user-consent-or-disclosure-300362844.html http://www.prnewswire.com/news-releases/kryptowire-discovere... and not to mention the nasty Heartbleed that's still affecting us. Open source only means the code at some "point" may have been vetted and secured but it will not remain secure forever. At this point, there is no secure anything, as long as it is man-made, it can be broken by another man. Apple has incentives to protect your data and it has enough money to not have to rely on sharing the data unlike Google and other Android companies. But this is not to say Apple isn't evil. They all are by default as in the nature of for-profit business they're in.
- dguido 10y agoI have a security review for a news room coming up, and I plan on sharing this blog post with them. Thanks for writing it Matt! I'm definitely behind all of the points you made. If anything, I worry that non-technical users will still not understand that desktop programs can do anything you can do with your computer even after reading your post. I'm not sure the description is "in your face" enough to translate for the intended audience. In their minds, "reading files" may be better expressed as "copy of every email I've ever sent" or "operate my webcam and grab nudes of me."
- deleted 10y ago[deleted]
- hackuser 10y ago> I have a security review for a news room coming up, and I plan on sharing this blog post with them Isn't there something more professional and accurate available? I fear there is not.
- dguido 10y agoThere are plenty of alternative sources I could list, but Matt's blog post is 1) accessible 2) correct 3) short. That's a winner in my book!
- idlewords 10y agoThis piece is professional, accurate, and written in a way human beings can read. I also recommend you show them the Teen Vogue article.
- claudiojulio 10y agoTo be safe see this site. It has everything you need. Https://www.privacytools.io/
- tptacek 10y agoThis page is batshit crazy. The very first thing it asks you to do is sign up with a random VPN vendor. Then it recommends Firefox or Tor Browser --- Tor Browser is the single least safe browser of all possible browsers you can install.
- jhlgkhkhil 10y agoWhy is that?
- tptacek 10y agoBecause it's based on and thus only ever asymptotically secure as Firefox, which is not the most secure browser architecture, and because of the economics of browser exploit development, and the fact that Tor Browser Bundle collapses a whole set of valuable targets down to a single release train, we can be sure that pretty much anyone who uses browser exploits as standard operating procedure has a stockpile of TBB exploits.
- jhlgkhkhil 10y agoSo how would you suggest browsing privately then?
- tptacek 10y agoI would start by learning the difference between Tor and Tor Browser.
- jhlgkhkhil 10y agoOK this advice is dangerous. The reason Tor Browser exists is because configuring Tor for safe use is difficult...
- tptacek 10y agoA few weeks ago a bunch of us on Slack tried to put together a brief for journalists on why they should prefer iPhones. It's still a work in progress, as you'll see, but here's a draft: https://gist.github.com/anonymous/9f789aabd7e8681dec0cf5781aecf664 https://gist.github.com/anonymous/9f789aabd7e8681dec0cf5781a...
- hackuser 10y agoThanks; the public needs more of this.
- jhlgkhkhil 10y agoWhy would someone who's threat model includes the US government possibly want to trust a totally closed OS made by a US company?? Do you still not see the US government as a threat to journalists? If not how do you justify this position?
- nickpsecurity 10y agoSmartphones shouldnt be trusted in such a scenario. Many journalists will use them anyway. In that scenario, Apple is probably better since they're not a surveillance company and it's harder to load malware.
- jhlgkhkhil 10y agoBut the OP doesn't go around saying one branch of smart phones are the best of a bad bunch - he goes around saying that they are good. How does he know? Is he better as reverse engineering than everyone as the NSA put together? (And that's not even taking into account all the potential wrench attack targets at a large US company?)
- tedunangst 10y agoWhich phone do you use that's too secure for the NSA to hack?
- Cieplak 10y agoThis advice makes sense given the threat model. However, it might not make sense for someone in Edward Snowden's role. If I were a military agency with a big budget, I would backdoor the shit out of every phone, enforce cultures of secrecy inside companies like google, apple, facebook, intel, qualcomm, at&t, and off any executive that interfered with the mission. Then I would pay experts to spend their lives on internet forums asserting that devices with two cameras, two microphones, wifi that can function as radar, an unremovable battery, a closed-source operating system and root access only available to a major US corporation via ssh, are the most secure computing platforms in the universe. That's just me though, if I had a lot of money and lust for world domination, neither of which I possess :) Edit: removed sentence "Most mobile devices have baseband chips with DMA"
- tptacek 10y agoNo, iPhone basebands do not have direct memory access. This is a myth that will not die. The baseband on an iPhone (and on modern Android phones) is connected via a serial bus, as a peripheral. Both Google's and Apple's security teams consider the baseband an adversarial device. This has been true for many years, just as for many years people have been popping onto message boards to confidently inform us that basebands have direct access to memory.
- Cieplak 10y agoI never used the word iPhone in my comment. Thanks for dropping the knowledge, though.
- hackuser 10y ago> The baseband on ... on modern Android phones ... is connected via a serial bus, as a peripheral Doesn't that depend on the manufacturer, or does Google somehow make that a requirement?
- eeZah7Ux 10y ago> This is a myth that will not die. Linking to some sources would help, please.
- 10y ago
- patcheudor 10y agoUse iOS with a privacy proxy they said... http://www.falseconnect.com/ http://www.falseconnect.com/ The first point being, software flaws and particularly those in low level networking libraries can expose secrets and the key I suppose as covered in the article is to ensure your OS is always up to date. The second point, and Dan covers it elsewhere in this thread, be very cautious about insecure hosted VPNs & you should really never trust proxies which some VPN providers are offering.
- dguido 10y agoYes, definitely always keep your OS up to date! Even in 2017, this is still a major advantage that iPhones have over Android phones. There will be bugs in any device, and iPhones have a better plan for dealing with them than Android phones. There is a vast amount of empirical data that shows patch adoption rates are far faster on iOS. iOS patches are: 1) available, directly from the vendor 2) come with new features 3) required for certain apps 4) nag you etc
- patcheudor 10y agoA number of years ago I found a crypto flaw in a Samsung component they shipped on their Android phones. Due to carrier update delays it took nearly two years for all the patches to roll out. Apple on the other hand can go from notice to patch available in weeks.
- tptacek 10y agoApple's not perfect about this stuff. Google and Apple both have strengths when it comes to systems security, including on mobile platforms. The key advantage Apple has is vertical integration. Google has to coordinate with third party vendors to ensure that an OS patch reaches Android users. Apple can just flip a switch.
- bmelton 10y ago"There is a vast amount of empirical data that shows patch adoption rates are far faster on iOS." Is that still true for the Google reference models? The Pixel, Nexus and other references devices tend to get updates in a much timelier fashion than, say, the Galaxies, Experias, and Notes of the world, and because the reference models aren't laden with proprietary bloatware, they tend to work more reliably after upgrading as well.
- tyoma 10y agoThis is a great article but only really covers half the issue. The other half is why journalists should use secure messaging applications, and not email. Sometimes the most succesful attacks are phishing attacks that no device will protect against. As an example, it is rumored that John Podesta used an iPad.
- dguido 10y agoGreat point, but this sounds like a topic for another blog post. I'm so glad that FIDO U2F is starting to catch on. I keep a drawer full of keys at work and hand them out to all our office visitors. The next generation of Bluetooth, NFC, and software tokens are exciting and a bright spot for the security industry.
- remx 10y agoBut if a journalist is going to use a secure desktop Operating System, he/she/they should investigate the current trio of recommendations which are as follows, and have different threat models baked into each: Subgraph. Currently in Alpha version, so be careful using this. Still has to be vetted by the wider infosec community, but worth downloading and playing around with. TailsOS. Very useful for journalists, but since it heavily relies on Tor it can be tricky dealing with mixed-anonymity workflows where sometimes you just need a Windows environment (preferably an airgapped Windows sandbox you can use to code / play around with files using Windows freeware). Qubes. Heavily reliant on compartmentalization, and this can sometimes prove too cumbersome if you typically do one type of activity on the web like chat / email / hang out on slack. Typically for when you need to insulate different activities from each other and to avoid contaminating different contextual environments / tasks.
- tptacek 10y agoI like Subgraph. I know a lot of people like Qubes (I have no opinions about it, but the people I know who like it are quite smart). I don't think I know anyone who recommends Tails. But none of these are reasonable suggestions for journalists and activists. We're not talking about people who are running conspiracies and can organize their working lives around opsec. You can barely get these people to the point where they aren't blindly clicking on attachments (and the attachments they open need to open in office software that is compatible with their existing workflows). They're simply not going to use Linux on their desktops. This is why security people like phones so much: they run secure operating systems that laypeople have accepted and can work with.
- remx 10y ago> that laypeople have accepted and can work with There is the caveat that it's hard to get things done in a timely manner on phones, or even tablets/phablets. If I need to crank out a lengthy blogpost, then I need a full desktop environment where I can do cross referencing, wikipedia lookups, file selection, photo editing, and all the other things that a desktop affords. I have tried writing a blogpost on an iPad and it took up my whole day when it should have taken 2-3 hours. I know people who have developed super-fast methods for working on iOS but they are such a rare creature, and I'm not so sure their workflow is even teachable enough to be widely adopted by journalists or professional bloggers. From my experience they're relying on all sorts of hacks to get a blogpost out the door like using some perfectly curated mix of apps, and being able to pass files to and fro different apps with ease. Hardly the stuff of laypeople.
- fiatjaf 10y agoJournalists shouldn't be trusted anyway. If you're journalist and you're honest, you're probably in the wrong job.
- r3bl 10y agoI've been trying to secure investigative journalists for about a year and a half, and this article kind of covers two of the points that I make on all of the security trainings. They usually go like this: * Do not have work-related emails on your Android (unless it's Google-made). iOS (9+) is okay. * Do not open random attachments on a Windows machine. (We always do our best to convince them to switch to a Ubuntu station with an AppArmor profile for LibreOffice set.) This is a good start. I think this article would be even better if it included some phishing tips (like HTTPS doesn't automatically mean "secure", and if you're suddenly logged out of Google for no apparent reason, don't just log into the webpage displayed to you, but instead, open Google by typing the address bar manually and log in there). Interesting side-note: Asshats spend days crafting phishing emails specifically targeted to our journalists, and they never get Google's postal address right in the footer.
- tptacek 10y agoI'm not sure I understand how switching someone from Windows+Office to Ubuntu+LibreOffice is a security win. LibreOffice is not an especially safe piece of software.
- bumblebeard 10y agoI imagine AppArmor is configured to minimize the access that LibreOffice has to the rest of the system. Otherwise yeah, vanilla LO is probably not any better than MS Office. VServer or similar could also work well but might be harder to configure correctly.
- tptacek 10y agoIf 90+% of a journalist's job is to open documents from sources in an office program, what good does it do to cage exploits in to LibreOffice? Those exploits still get virtually all the data an attacker wants from the journalist.
- bumblebeard 10y ago
- bubblethink 10y agoI wonder how helpful these sort of posts are for actual journalists or whistle blowers. It's one thing to tell a casual user to get an iphone as a reasonably secure choice compared to Android's fragmented mess, but for someone whose job and/or life is on the line, you need a more thorough coverage. You may even need like a mini course of sorts that covers basics of CS and infosec. Short of that, such cavalier advice can be misleading.
- pvg 10y agoThis was written as a response to a question from an actual journalist. It's quoted right at the top. What do you find 'cavalier' about it?
- bubblethink 10y agoBecause it fails to mention any downsides of running an ios based phone, and I'm sure that a balanced discussion would find many. Security is complex, and paraphrasing it this way may be fine as casual advice, but when you add "journalists" in the title of your post, it falls short.
- pvg 10y agoIt outlines many of the limits of the advice, describes a specific case in which an activist was targeted by multiple iOS zero days, etc. What are the downsides you think it omits and in what ways does Matthew Green misunderstand the complexities of security?
- bubblethink 10y agoNot so much about misunderstanding as it is about omitting other details. For one, IOS is a completely closed box whereas AOSP is completely open. You can argue for or against security by obscurity v/s security in open software, but at the very least it needs a mention in any fair comparison. Secondly, most of the blog focuses on average case behaviour. In Apple's case the average, best and worst case are all the same since they make only one device and one OS. In contrast, android is a vast spectrum. Now if you were to give out advice to people with sensitive data, you should compare the best case for both of them, which he briefly does, but not quite as detailed as it warrants. For instance, is iphone necessarily better than a Pixel running AOSP or something like CopperheadOS ? I'm not so sure. IOS's centralized behaviour also makes it an easier target in some ways. Want to attack all browsers on an iphone ? Attack webkit. There are other security fails such as relying on either itunes or icloud for getting data in and out of the phone. Much fuss was made over Cloudfare's lack of a bug bounty program. Apple didn't have one either until quite recently either.
- deleted 10y ago[deleted]