4 ms·
Do you know his rationale for some of the blanket statements like "always use an iPhone, never an Android device" and "never use Safari on your laptop, but it's
by overkill28 7y ago
Do you know his rationale for some of the blanket statements like "always use an iPhone, never an Android device" and "never use Safari on your laptop, but it's ok to do so on your phone?" Presumably sophisticated opponents are targeting iPhones and mobile Safari as much as Android and desktop Safari
- tptacek 7y agoSophisticated attackers target everything. Desktop Safari is a much softer target than Mobile Safari, and, while flagship Android devices can be made asymptotically as secure as iPhones, the median Android phone held by a campaign staffer is much less secure than the median iPhone, which is something you quickly discover when you see the menagerie of devices campaign staffers use. The two biggest threats campaigns face are phishing and attachments. There are two good ways we know of to break attachment attacks: view attachments in cloud viewers, like Google's PDF viewer, or view them on mobile devices, where they can't trivially be clicked into monstrously insecure desktop productivity applications. Of the two approaches, the latter --- sticking to mobile devices --- is the one that can be deployed with the least amount of end-user training.
- packet_nerd 7y ago> Under no circumstances use the Tor browser (it's okay to use Tor, but do it with Chrome, and seek additional training on how to set it up). I'm not sure I get the rational behind this one? Is it just because they are already using Chrome, so it's better to reduce the attack avenues? Also, it seems to me if you need to use Tor, it's probably not a good idea to do so on your regular Windows desktop. Wouldn't Tails be better advice while also being more foolproof for less tech savy people?
- tptacek 7y agoTor Browser might be the least safe browser on the entire Internet: it's a very specific, always-behind version of Firefox (itself not the most hardened browser) selected preferentially by sensitive targets, who have opted in to being collapsed down to a single program for exploits to target.