12 ms·
The Personal Security Checklist
- Hnrobert42 5y agoThe flaw with this list is that it treats all risks as equally likely and does not distinguish between various threat landscapes. Few people are high value enough to merit the effort required to capture a face from CCTV, generate a mask from the image, get physical access to their device, and use the mask to unlock. So for almost everyone, faceid is fine.
- schoen 5y agoMore common associated risk: Police detain you and point your phone at your face to unlock it (or unlock your access to some other resource). That is not a very high-tech or high-effort attack and could be relevant if you're concerned about the police. Someone might say that this concern is useless because the police can also coerce you to unlock your phone via a different method, but that depends on the law and culture in your particular environment (I guess ranging from "extremely unlikely" to "almost certain" depending on where you are). Edit: I don't mean to disagree with your overall point that understanding the threat landscape and threat model is very important, just to say that there is a very simple and plausible threat to which the precaution you used as an example can be relevant.
- InitialBP 5y agoDefinitely a good threat I hadn't considered. I imagine from someone who is less educated about technology in general, having a list of "example threats" that those items might protect against would be beneficial to help offer some more incentive to follow this list other than just "Good Security".
- astockwell 5y agoIf you press and hold both the lock button + the volume up button long enough to open the power-off screen, it will disable faceID (on iPhone) until you enter your passcode again. Handy to know and easy enough to do discreetly in a pinch.
- kingcharles 5y agoI know I've posted this a lot of times, so I'm sounding like a broken record, but you won't get a chance to do it. When the government came for me they pointed a loaded gun at my head. There was no way I could have moved my hands to start fannying around with my phone. I refused to cooperate when they threatened me, but they soon realized a new tactic and threatened my wife. You're probably tougher than you think. You might be able to take a spanner to your knee caps, but if the government puts a gun to your spouse or children (or even your dog), what are you going to do then? Certainly in the USA at least, I don't think the police are committing any misconduct by telling you they are going to take your wife outside and shoot her in the face if you don't give up your fifth amendment privilege.
- kdtsh 5y agoPressing the power button five times in quick succession does the same - another handy trick.
- zrail 5y agoOn my phone pressing the power button five times quickly starts a 10 second timer and then it auto-calls emergency services and I'm pretty sure this is the default.
- tomekf 5y agoI always feel that this should be promoted more. Simple but effective in sticky situations…
- suchire 5y agoClicking the side button five times will do the same
- pkingobject 5y agoI agree, it very much depends on who is targeting you. If it's the police on the street or at your home, say in russia or another third world country, then they can just lock you up or go as far as torture to get access. If they want to access your phone they will. But someone random on the internet trying to get your google photos? Completely different.
- InitialBP 5y agoDefinitely agree with you, there's no need to waste resources on protecting against threats that would never target you - like attempting to capture your face from CCTV and spending real money and resources to get a mask and then stealing your device... etc like you noted. The author does have face unlock listed as "Advanced" priority. The wording is a bit weird but I take it to mean, only someone who has "very advanced" security concerns would need to follow that recommendation. If I were going to recommend this to a friend/family member I would just tell them to stick to the basic priority items and not worry about the higher pieces.
- jjulius 5y ago>Few people are high value enough to merit the effort required to capture a face from CCTV, generate a mask from the image, get physical access to their device, and use the mask to unlock. So for almost everyone, faceid is fine. I feel like this point misses the first point you made, about things being a lot more circumstantial and nuanced. It all depends on what you have to hide and on what device. Someone may need to go to the level of effort you mentioned to access someone's iPhone, while someone else may need to just print out a mugshot and hold it in front of a laptop webcam to unlock their computer. Edit: I'll also second schoen's point about someone forcefully holding your own face up to the device.
- godmode2019 5y agoYou are missing the legal distinction forcing a password from someone is illegal because of the right to remain silent. But detaining someone and scanning their face is 100% allowed.
- Hnrobert42 5y agoYour point only underscores my point. The list doesn’t discuss your threat, so in my initial assessment of the list, I didn’t think of it.
- ozim 5y agoI don't see the flaw as there is obvious "recommended", "optional", "advanced". List is "personal security checklist" so it also gives some context that you can infer "threat landscape", which I understand would be average Joe, not journalist, not a CEO, not a drug dealer, just normal employee having one bank account buying stuff online and going on vacations in his own country. If you want to implement everything that is "optional" in your life it will be security larping.
- pseudobry 5y agoI'm glad I saw this, it looks like an excellent resource. However, I can't help but feel a bit of despair while looking at it. There is so much stuff to do / know about, that it's incredibly far beyond what the average person could understand, let alone follow. Most people won't get close. I'm capable of doing everything described (and I follow a good chunk of it), but I have hundreds of accounts. The shear effort required to thoroughly roll out these protections for just myself (let alone my less-technical-than-myself-technical-family) across a such a large digital surface area make it seem an insurmountable task. Maybe I need is a service that can automatically audit my networks / devices / accounts and give me security health scores, give me 1-click paths to enable protections, or even auto-fix security gaps. But that sounds like dropping an enterprise security blanket on my digital life, and any system capable of taking care of this for me is another single point of failure whose compromise would be catastrophic. Convenience and security must be inversely correlated.
- VPenkov 5y agoIt's better to start late than never. You probably have only a handful of high-value accounts. Emails, hosting, domain names, utility providers, social media. Then you can focus on anyone who has your private data. E-shops and such that store your address. Realistically those can be pretty damaging if they get breached - even if your password doesn't leak in plain text, your name and address would be up for grabs. But think about adopting the habit of gradually building up your discipline and addressing old issues as you revisit old accounts.
- euphetar 5y agoThis so much. It's good its all in one place, but come on, it's a checklist of four whole screens. I would prefer a minimal checklist instead: what measures give you the most (security) bang per buck (effort spent)?
- CalChris 5y agoWith respect to password managers, it doesn't mention Apple's iCloud Keychain. Any reason why?
- mateuszf 5y agoLooking at the other items it seems that the author prefers open source / cross-platform software / services where possible.
- loevborg 5y agoYou can't use it with Chrome, so you're locked into Safari forever.
- CalChris 5y agoApple released their iCloud Passwords extension [1] for Chrome last November. I actually moved away from Chrome to Safari when I migrated over to my new m1. It's actually pretty good. The one caveat is Google's Advanced Protection Program only works with Chrome. The article doesn't cover that as well. [1] https://loginlockdown.com/reviews/icloud-keychain/ https://loginlockdown.com/reviews/icloud-keychain/
- yewenjie 5y agoI would love a list like this which is geared towards more advanced users (and software developers who deal with a lot of sensitive data) and describes threat models more comprehensively.
- vinay_ys 5y agoFor software developers working for a corporate: Use your corp laptop and phone only for corp work. Don't do any personal stuff on it, including browsing the general web. Just this alone reduces the risks significantly.
- ozim 5y agoAdd to that "don't be smarter than your IT department", even if you know how to do something on your own. Remember that if you get compromised because you did something your IT dept should do or at least sign-off it will be your fault and one may face real consequences.
- bagels 5y agoI think this is just for information security, right? It doesn't cover personal physical safety. Things like: pay attention to your surroundings, lock your doors, etc.
- after_care 5y agoThis is covered under "Secure Perimeter" and "Stay Alert"
- gorgoiler 5y agoThis doesn’t talk about real world adversaries, only hypothetical countermeasures. It would be more useful to know how I’m likely to be attacked, not how to protect against every threat the author could possibly think of. For example, I want to know where the villains actually go when they want to dox someone. Then I can dox myself and do something about it. I have no idea where to start and wouldn’t want to pay money to criminals to get it.
- hsbauauvhabzb 5y agoThis. Browser based password saving is only a threat of device theft is a concern. The GitHub repo clearly doesn’t understand threat models or convencience-to-risk ratios.
- chrismarlow9 5y agoThe real villains will have access via gov agencies to make emergency data requests to tech companies. Maltego can also be used to pivot on any info you already have to collect more. I'd say the best you can reasonably do is to use this to find your trails and remove them or worst case obfuscate it with noise.
- Terry_Roll 5y ago> The real villains will have access via gov agencies to make emergency data requests to tech companies. The real villains are those entities which are not you. Survival of the fittest.
- smarmgoblin 5y agoThis is a great instinct and I recommend everyone do this. There’s a ton of resources on this, unfortunately subject to this predictable effect where spam proliferation easily overwhelms your ability to discover useful resources in reasonable time period. Michael Bazzell has a book on OSINT (and a blog/podcast) which I can recommend for an initial dive. Good starting point for action would be his data broker checklist.
- _wldu 5y ago
- gandalfff 5y agoTip #1 should be: determine your threat model. Who are you, and why should hackers care about hacking you? Who is doing the hacking? Is it a 3-letter organization or other nation-state adversary? Is it a corporate actor trying to commit corporate espionage? Someone trying to steal your identity? I am less valuable to hack than Vitalik Buterin, who in turn is less valuable to hack than President Biden.
- billdietrich1 5y agoI don't have a threat model. I just have typical data (financial, family, hobbies, etc) and want a reasonable level of protection against all threats (snoops, thieves, scammers, police, govt, etc). So I just use standard best practices: encryption, backups, password manager, 2FA, software updating, blockers in the browser, firewalls, VPN, etc. No need to identify specific threats, I don't have any. No need to list out all my data.
- alipitch 5y agoIs there a list issued by eff.org, nist or a similar organization, that is maintained and updated?
- Terretta 5y ago> This guide is an overview of digital security considerations specific to journalists covering protests. For EFF’s comprehensive guide to digital security, including advice for activists and protesters, visit ssd.eff.org. Legal advice in this post is specific to the United States. https://www.eff.org/nb/deeplinks/2020/06/digital-security-advice-journalists-covering-protests-against-police-killings https://www.eff.org/nb/deeplinks/2020/06/digital-security-ad... Also: SURVEILLANCE SELF-DEFENSE: TIPS, TOOLS AND HOW-TOS FOR SAFER ONLINE COMMUNICATIONS -- A PROJECT OF THE ELECTRONIC FRONTIER FOUNDATION https://ssd.eff.org https://ssd.eff.org
- alipitch 5y agoThank you. I will look at the sites.
- langsoul-com 5y agoA check list is pointless when there's 300+ items... Really needs to be extremely short, like 10 items tops. Then when sublists for specific situations.
- nonrandomstring 5y agoThis list is specific and parochial of course. Rudimentary thematic analysis of the list reveals common patterns fairly well known to security people: - Less is more. - Convenience works for you, and adversaries. - If it's old, maintain it. - Never tell the truth. - Keep moving. - Don't underestimate the enemy. - Have a plan B. In the literature these have fancy names like Dolev-Yeo, Minimal attack surface etc. Interestingly they also correspond to the five-S principles {shape, shine, speed, spacing, silhouette) of stealth and camouflage and many foundations of guerilla craft - maximal mobility, carrying minimal gear, least contact and taciturn communication, knowing the environment, maintaining you equipment.
- baxtr 5y agoGreat list! Could you expand on the items a bit?
- nonrandomstring 5y ago> Great list! Could you expand on the items a bit? That would be funny, as the list is an attempt to reduce things. Perhaps you mean - can we elaborate on the principles of reduction somewhat? Maybe. I am wondering. The problem with pithy lists is that, in the limit, they end up as a collection of mutually-contradictory idioms, like; "Many hands make light work" but "Too many cooks spoil the broth". Security is already a mess of theories in tension - "If in doubt don't." versus "Fortune favours the brave" Perhaps we could make a more focused list for our readers, for innovative developers, with items like: "Secure yourself before attempting to secure others." "Don't assume you know what people want" But I fear it would not be gladly received.
- moontear 5y agoCheck out the beautiful start page by the same author: https://github.com/Lissy93/dashy https://github.com/Lissy93/dashy
- midasz 5y agoJust set this up yesterday for my selfhosted services, it's a pleasure to use!
- DerSaidin 5y agoThis list should define the priority levels they're using. I think it goes: Basic, Recommended, Optional, Advanced (in increasing effort|security|paranoia).
- Aachen 5y ago> You could store [2fa backup codes] in your password manager Aaand we're down to single-factor authentication: your password from your password manager plus your backup codes from your password manager. I do recommend a password manager, but not to keep would-be-two factors in one vault. Also the very first item in the guide makes a blanket statement about dictionary words being really crackable. I forgave that one for simplification reasons (reality: passphrases are equally secure if you use enough random words, just like using a password with enough random characters), but I've now read the recommendation for 3 points and 2 are bad and mediocre advice.
- ihateolives 5y ago> statement about dictionary words being really crackable Every time I see this statement I immediately think: which dictionary? There are more languages than usual suspects (eg English, Spanish, French, Italian, German, Mandarin) and L1/L2 speakers of those make up sizable portion of internet users. Are Welsh/Hungarian/Slovak dictionary words really as easily crackable than English ones? If you have dictionary for those, yes, otherwise I suspect no.
- FabHK 5y agoSo, yes.
- PostOnce 5y agoExactly. I don't have to speak any of the languages on wikipedia to use wikipedia as dictionary for cracking. You can have every quote from every book, every place name, every wikipedia article, every song lyric, and a cheap GPU can buzz through it all ... fast. Kind of breathtaking that we have that power now, and kind of terrifying.
- Aachen 5y agoThis is exactly what I did for a research project in school: download Wikipedia, extract all combinations of iirc 2-5 words, do a few transformations like adding a lowercase variant and space-less variant, and run that set against the LinkedIn sha1 password dump. Quite effective for cracking passphrases that weren't randomly chosen words but an existing phrase.
- mxstbr 5y agoIf you haven't seen it, Brian Lovin also has a fantastic, in-depth security checklist on his website that links to many more valuable resources: https://brianlovin.com/security https://brianlovin.com/security It's aimed more at "the minimum any person should do", so isn't as wide-ranging as the OP and a bit more practical to share with family & friends who might not be as technical.
- PennRobotics 5y agoThere's an obvious tradeoff having an authenticator (2FA/OTP) separate from your secure password manager. If you lose the device with credentials, you're screwed. It's really easy to lose access to a device (and usually without advance notice). Or you can override the 2FA, and then you're back to hoping the verification procedure of overriding 2FA is stronger than a dedicated attacker. A password manager managing 10 OTP accounts means 10 attempts at social engineering to bypass the OTP. I realize having everything on the password manager goes against the "a thing you know plus a thing you have" security policy, but I imagine you'd have much more grief linking every account to a device (a smartphone, usually) you expect can (more likely: will) fail in the next 0 to 6 years. On the flip side, if you decide to make the thing you have a biometric feature, there's the downside that this thing can never be changed but could possibly be spoofed. In twenty years, you'll still have the same fingerprints, and you even have the same fingerprints, iris, face, etc. when you're unconscious. Maybe the best strategy is a hardware key with printed backup code? Then you really need to hide the printout somewhere only you know, where it won't get destroyed, where it can be accessed relatively quickly without a complicated lockout, where it won't get accidentally discovered by the HVAC repairman, and where you won't forget after 0 to 6 years. Solving this location riddle seems the most impossible of all...
- blfr 5y ago> Maybe the best strategy is a hardware key with printed backup code? Or register more than one (preferably three) hardware key. It sidesteps all of these issues. They are very resilient and act as backups.
- PennRobotics 5y agoYou still need to store one backup key somewhere safe, and then it's no longer something you have but something you hope stays where you left it.
- jamesmishra 5y agoBut then where do you put the hardware keys? Presumably you would need to obtain all three keys every time you register a new user account on a website.
- minroot 5y ago> Keep Email Address Private - Recommended Why? > Use Plaintext - Optional But this one is optional, why?
- kkfx 5y agoWhile I always prize people how invest time and share results of their work to the community I found that list a bit of a collection of common things, some not really good beliefs etc, so my two cents little contribution: - two factor auth depending on the secondary factor might be a vulnerability itself: suppose you use Google Authenticator on your Android "phone", what if a third party deliberate action DOS your phone (not functioning anymore, locked etc, no matter the reason): you are cut out of other available/working service because of the OTP SPOF, so at least chose recovery roads if the OTP can't be used in all cases, and test them regularly; - a "secure password manager" is something you read in code and understand everything, also is as secure as the environment it live on, for instance on Android/iOS/other proprietary OS you can't trust any password manager not because themselves but because you can't trust the environment you are in, the only option is using only community born and community developed FLOSS [1] witch is limited by the hw+firmware layer on top on nearly all modern common hw; - breach alerts are generally good BUT also a potential privacy issue, follow news on services you use is the good (and hard, not because of nature but because most services do not offer a simple very-low-traffic RSS feed/ML alerts with just critical infos) BUT remember you give personal infos, public, but still personal, to a third party witch maybe honest and/or maybe itself breached just to munge data from it; - safe backups are backups you restore regularly and that are stored offline. The offsite backup is for physical safety (earthquake, thief at home, etc) BUT it's not really "safe" since is not really under your control (unless you are big enough to have geographically distributed personal infra); - for emails, having many it's ok, as long as you give some to your contacts so they can know and trust that's still you who write from another address, but the main point are mails themselves: they are personal, you need to have them, witch means do sync/download your maildirs locally in an automated fashion and USE them locally with an MUA (or if you really need a personally hosted WebMUA, because emails does not matter only in terms of "current capacity to read and send" but also search through your maildirs, perhaps through all at once if they are many, having your MUA to work with not n-th different WebMails from different providers etc AND have mailbox portability witch means having personal domain names so to been able to switch from a hosting partner to another without changing address. Also a personal mail typically allow many aliases, witch are useful to give to services from retail to NL etc to been able to detach easily and to know where the spam came from (i.e. if a spam mail arrive to my ebay065 mail alias that means someone from ebay got mail mail), oh BTW there is no "secure email provider" (if you are yourself the provider) just different services you can choose to trust or not, without much data to decide; - for chat, I laugh a bit because if the author talk about chat on smartphones they do not matter how open or safe they are, they are on surveillance capitalism platform so NONE can be trusted for privacy, even one you write yourself; - "use a VPN", in the sense of commercial VPNs providers is a VERY BAD ADVISE, my ISP can spoof my connection but it's a company from my country subjects to laws I know, I can have a local litige with my local lawyer etc a third party VPN service based in British Virgin Island, Cayman or You-name-it remote -stan it's essentially protected by the impossibility in practice to sue it, so it's the opposite of safety: you voluntary give 100% of your network usage, perhaps with a unique account for multiple devices, to a third party renouncing to your local laws protection. VPNs have ONLY a safety purpose: connecting LANs across the internet, witch means if you have a homeserver and you want to route all your traffic through a VPN is safe, otherwise might just be a means to circumvent Geoblocking NOTHING for safety nor privacy. Oh, BTW forcing a LAN-wide VPN especially through a commercial router is again not a good idea but at minimum a SPOF. - for a safe LAN avoid wireless at all, at least limiting it to not-easy-to-connect-via-wires devices (smartphones) AND for ephemeral connections (guests at home etc). - for desktops: IMVHO do NOT USE any antivirus, simply use OSes that do not have "try-to-execute and fallback thereafter", antiviruses especially proprietary ones are extremely invasive and not trusted beasts. Backups MUST BE for all data, not "just for important ones" because restore MUST BE a full restore from the system/configs to data. Partials backups are good recipes to make disasters. [1] witch means code that many third parties with different interests, scattered around the world have seen from the start, when the codebase was small enough to be really understood ad a whole.
- agilob 5y agoShouldn't checklist contain... checkboxes?
- deleted 5y ago[deleted]
- ravenstine 5y ago> Don't reuse Passwords Nice in theory, and perhaps in practice if one uses a password manager that's unified across devices. In my opinion, password managers are a ticking time bomb. With maybe the exception of something like Firefox's built in password management, it's only a matter of time before these for-profit password managers are subject to significant exploits or data leaks. With strong 2FA, the necessity of not reusing passwords is much less relevant and hardly warrants forcing users to reset their password while disallowing use of previous passwords. If a user enables strong 2FA, they should be allowed to keep the same password indefinitely.
- euphetar 5y agoMy beef with all of these checklists: do you expect me to spend my whole managing my security?
- billdietrich1 5y agoYou could spend 20 minutes reading the list, and come up with 2 or 3 things you want to do right away. A lot of security things are one-and-done: install uBlock Origin browser extension, enable VPN, enable software auto-update. Then they just work in the background after that. Given that my entire net worth is accessible through my internet-accessible bank accounts, yes, I'm willing to spend SOME effort managing my security.
- alexklark 5y ago
- westurner 5y agoAlso good: "The SaaS CTO Security Checklist [Redux]" https://github.com/vikrum/SecurityChecklists https://github.com/vikrum/SecurityChecklists "The Personal Infosec & Security Checklist" https://www.goldfiglabs.com/guide/personal-infosec-security-checklist/ https://www.goldfiglabs.com/guide/personal-infosec-security-... "The DevOps Security Checklist Redux" https://www.goldfiglabs.com/guide/devops-security-checklist/ https://www.goldfiglabs.com/guide/devops-security-checklist/ ... Years ago, I helped develop a checklist app for a hospital (in Python and JS at the time). TIL checklists usually are justified, and may be the only process for collaboratively improving process controls that a healthy organization handling feedback has established; who gets to send PRs to the checklist, and what criteria should be applied such that evidence-based variations of process are objectively tested? "Post-surgical deaths in Scotland drop by a third, attributed to a checklist" (2019) https://news.ycombinator.com/item?id=19684376 https://news.ycombinator.com/item?id=19684376
- fy70 5y ago
- kube-system 5y agoI don't understand why anyone recommends disabling javascript. If you're making that much of a sacrifice in user experience, you might as well uninstall your web browser.
- lucakiebel 5y agoJust make the switch to w3m. No Js interpreter, no problem
- egberts1 5y agobecause malicious JS are abound! and it is going to get worse with the advent of WASM rollouts.
- billdietrich1 5y agoFor most sites I use, JS detracts from the "user experience". I just want to read an article, not deal with accept-cookie popups or ads or menus etc. Even on interactive sites such as my bank accounts, I'd rather have a plainer page that just worked in all browsers and worked in a simple way, than have some UI-designer's work of art with fancy coding and unique effects etc.
- aborsy 5y agoGood question: CEOs, executives, members of parliaments, journalists, researchers at industrial labs, those working in defense/military/aerospace, etc are at elevated risk of being hacked by governments and hacking companies such as NSO. Are there guidelines how should these individuals protect themselves against such powerful adversaries? Like if you work for the German or Chinese government in an important capacity, or lead a major company there, it’s a question whether you should use an iPhone (given that it’s a black box made by a US company), cloud services, etc. How about if both sides are within the same country? For example, is a Google executive using an iPhone at risk of being spied on by Apple?