[HN Gopher] The protester's guide to smartphone security
___________________________________________________________________
The protester's guide to smartphone security
Author : nameequalsmain
Score : 217 points
Date : 2025-01-26 11:04 UTC (11 hours ago)
(HTM) web link (www.privacyguides.org)
(TXT) w3m dump (www.privacyguides.org)
| mtlynch wrote:
| > _Some law enforcement agencies use "stingrays," devices which
| can impersonate a cell tower to track visitors to an area. While
| the capabilities of the most modern ones isn't fully known, you
| should definitely protect yourself from the subset of stingrays
| which abuse the lower security standards of older, 2G networks._
|
| Good tip! I didn't know about disabling 2G support on my phone.
| diggan wrote:
| If you're attending a large-scale protest, it's likely that the
| cell-towers (or stingrays) won't be able to handle everyone who
| is connected anyways, so worth planning to use apps that can chat
| over P2P WiFi or Bluetooth together with the rest of your
| friends. This also allows you to continue using Airplane Mode the
| entire time, while being able to communicate with people nearby.
|
| Alternatively, investing in walkie-talkies that have encryption
| can be worth it as well, but unsure how legal they are around the
| world, think some countries put restrictions on those so you
| might have to acquire them while vacationing somewhere else.
|
| It's mentioned in the body of the article, but get the feeling
| most people could miss it: Absolute best idea is to leave your
| "personal" phone at home! Either get a secondary (burner) phone
| with nothing useful on it and no real names, or skip out on the
| phone fully. If you do get a secondary phone, make sure it has a
| removable battery and keep it out from the phone until you arrive
| at location and as soon as you move, remove battery again.
| qwerty_clicks wrote:
| What apps do you recommend with p2p messaging?
| diggan wrote:
| Lots of groups have used https://briarproject.org/
| successfully in the past, I've heard. Assumes you're using
| Android though which if you're using a burner, you most
| likely are.
| mmooss wrote:
| > successfully
|
| Successfully in terms of communication or in terms of
| security?
|
| Successful communication is easy if you don't worry about
| security. Just post it on Instagram.
|
| How do you know if your security is successful? How do you
| know if your messages were intercepted and read, your app
| was hacked, data was extracted from it, etc.? The attackers
| (authorities or otherwise) are not going to tell you.
| TheSpiceIsLife wrote:
| I'd go as far as to assume there's no _evading
| surveillance_ in a strict sense.
|
| If you attend, leave your phone home (atypical usage), go
| with other people / meet them there / other people you
| know are there (facial recognition / gait analysis /
| clothing preference) those are all good data points to
| predict with high probability where you are and what
| you're up to, especially given your typical movements,
| data usage patterns, purchasing habits, friends /
| acquaintances / social media interactions are all in at
| least a few databases.
|
| Take the security measures you're willing to make the
| tradeoffs for.
|
| If history is anything to go by, we're only ever an
| election, or other political churn, away from your
| particular sets of beliefs / identifiers being
| persecuted, or at least your least favourite political
| prisoners being released and coming after _you_.
|
| And, as you allude to, relying on the security practices
| of others has its own problems. Even Perfect Forward
| Secrecy etc etc provides little help against Rubber Hose
| Cryptography.
| DicIfTEx wrote:
| Here's a guide to PET (peer-to-peer, encrypted, through Tor)
| apps, focussing on Briar and Cwtch:
| https://itsgoingdown.org/the-guide-to-peer-to-peer-
| encryptio...
| morkalork wrote:
| How safe is Bluetooth really? Cities has scanners used to track
| devices for monitoring road congestion, malls have scanners to
| measure foot traffic. I have to believe that anyone with access
| to stingray type of device can track Bluetooth as well.
| theoreticalmal wrote:
| Don't both Apple and Android implement random BT MAC
| addresses specifically to prevent this kind of tracking?
| mmooss wrote:
| There could be other fingerprints besides MAC addresses.
| snypher wrote:
| How about my smartwatch, or my $29 earbuds? They are always
| conveniently near the 'random mac' and can be used to
| fingerprint.
| AlphaCerium wrote:
| don't bring them to a protest, simple :)
| diggan wrote:
| Usually, protests are located in one somewhat easily defined
| area, until you cannot be there anymore or the goal has moved
| somewhere else. So then you need to get to another spot, this
| is the moment you disconnect your battery until you've
| arrived at the other place.
|
| So yeah, they'd be able to say that "person A was at location
| B and later C", but not necessarily the way there or
| after/before those specific locations.
|
| I agree that the safest is to assume they can definitely
| track you no matter what protocol/antenna you use, so you
| have to chose what moment it's OK to be tracked (like large
| groups).
| tehjoker wrote:
| The battery thing can be important. One strategy law
| enforcement uses is to force your phone into a high energy
| state and zap the battery very quickly.
| theoreticalmal wrote:
| What does this mean? What does the zapping accomplish?
| Cpoll wrote:
| I'm guessing in this context it means drain the battery. I
| haven't heard of this technique, but it seems plausible, by
| tricking the phone into constantly transmitting over WiFi
| or cell.
| dinosaurdynasty wrote:
| I wonder how useful purism phones are for this (all
| external communication, including GPS, has hardware
| shutoffs).
|
| They are expensive though...
| DaSHacka wrote:
| Couldn't you achieve the same by just enabling airplane
| mode or similar on regular devices? I don't think niche
| devices with hardware killswitches should be necessary
| snypher wrote:
| My S23 enters airplane mode and the WiFi and Bluetooth
| are still connected... Airplane mode isn't what it used
| to be!
| tehjoker wrote:
| Reducing the ability for protestors to coordinate on the
| streets.
| dghlsakjg wrote:
| How do you force a phone into using more battery through
| external means?
| Groxx wrote:
| (I have no information and thus no opinion on this being a
| thing that happens but)
|
| constantly keeping the cell antenna and CPU awake would
| probably do it. it's a BIG part of why weak cell signal and
| lots of noise at e.g. conventions drains your phone many
| times faster than normal, even when you're not using it.
| you could probably do that just by sending junk data to
| everyone occasionally, or delaying valid data to prevent
| going into sleep modes for longer periods.
| a12k wrote:
| If iPhone, have a case of active AirTags in the vicinity.
| quesera wrote:
| If you ever forget to put your phone in Airplane Mode when
| flying (and you survive the flight!), you will notice that
| the battery is surprisingly depleted.
|
| I think it has to do with the phone constantly
| renegotiating with cell towers along the route.
|
| I've seen similar behaviour when a hurricane took out power
| to a local tower, and it was intermittently restored.
| uoaei wrote:
| Nitpick: it's _sap_ the battery, as in sapping energy.
| Onawa wrote:
| I think both 'sap' and 'zap' work in this context, and zap
| might be the better option because 'sap' can have the
| additional meaning of moving the energy somewhere else,
| whereas 'zap' can just mean to remove in general.
| mmooss wrote:
| > One strategy law enforcement uses is to force your phone
| into a high energy state and zap the battery very quickly.
|
| As a denial of service attack?
| nine_k wrote:
| No need for the law enforcement to do anything. I suspect
| that a large, thick crowd where everyone carries a phone
| creates enough radio interference that phones lose contact
| with the tower very often, and try to reconnect very often,
| especially when people send or receive messages, auto-upload
| photos, etc. This keeps the phones in the active state for
| longer, draining the batteries.
| timewizard wrote:
| Keep in mind "Mens rea." If you are implicated in the crimes of
| the crowd all of these actions may be used to increase the
| penalties you face. Even if you "trust" the crowd, somehow, you
| should remember that agent provocateurs exist.
|
| You might ask what attending a large scale protest is intended
| to achieve and decide for yourself if the personal risks are
| worth it.
| 6LLvveMx2koXfwn wrote:
| And if those risks are too great due to state over-reach,
| best stay at home.
| nonrandomstring wrote:
| That seems too lenient on yourself. Why not do the right
| thing and hand yourself into the Inquisitor General for
| wrong-think about protesting? Maybe they'll go easy on you.
| neilv wrote:
| > _You might ask what attending a large scale protest is
| intended to achieve and decide for yourself if the personal
| risks are worth it._
|
| True. But keep in mind that demonstration size can have an
| impact.
|
| Even just relatively large, not even a Million Man March.
|
| For example, relevant to recent news magnifying vile Nazi-
| saluting imbecile demographics: They tried to pull that at an
| event in Boston in 2017, but tens of thousands of counter-
| demonstrators showed up.
| https://en.wikipedia.org/wiki/Boston_Free_Speech_Rally
|
| We need more reminders that the US can be good people.
| timewizard wrote:
| > but tens of thousands of counter-demonstrators showed up
|
| What social change did this lead to? It sounds like two
| ideologically opposed groups showing up in the street to
| war with each other. In the end the organization just built
| a new group and moved everyone into it. What is this meant
| to be an example of?
|
| Seems like "Sound and fury. Signifying nothing." to me.
|
| > reminders that the US can be good people.
|
| The US /is/ good people. Will it ever be 100% "good
| people?" Of course not. Perhaps you shouldn't let salacious
| for profit media hyperventilation over the few bad apples
| that exist to tarnish your view of an entire country. Let
| alone allow this to encourage you to participate in
| meaningless street level shouting matches.
| neilv wrote:
| > _What social change did this lead to?_
|
| Even when obviously crazy/corrupt/malevolent people seize
| control of most branches of government, it tells some of
| the people who feel most threatened that they're not
| alone, that the people around them are not what the news
| would have them believe, and that many others will come
| out and stand up for them.
| giantg2 wrote:
| "investing in walkie-talkies that have encryption can be worth
| it as well"
|
| Generally not allowed in many bands in the US. Motorola sells
| some AES walkies. They're really the only ones I know of, and
| they're very expensive.
| echoangle wrote:
| Well the whole point of hiding your tracks is evading law
| enforcement, why would you care if it's illegal? Or is it
| because of the ,,only do one crime at a time" thing?
| giantg2 wrote:
| Why do you assume this is about doing illegal things? This
| is about protests, many of which never turn into riots or
| illegal acts.
| echoangle wrote:
| I was thinking along the lines of ,,the state wants to
| oppress the protestors and makes it illegal", but if you
| just want to avoid surveillance at a legal protest, yeah,
| you're right.
| JumpCrisscross wrote:
| Going into a protest with illegal communication devices
| is almost a direct sabotage of the protest's intent. It
| gives law enforcement a legitimate reason to act, even if
| almost certainly _ex post facto_. It also paints the
| entire protest as an illegal exercise--you went in
| intending to break the law.
| _DeadFred_ wrote:
| Burner phones aren't safe. Security through obscurity worked
| with the 1990s cell network but not with today's vast
| logging/geolocation tagging.
| djoldman wrote:
| > If you lose your phone, you may be able to locate or wipe your
| phone remotely depending on the model...
|
| > Please be aware of the legal consequences of these actions.
| Wiping your device or revoking online account access could lead
| to obstruction of justice or destruction of evidence charges in
| some jurisdictions.
|
| This can be really serious. It is far better to never
| have/collect/obtain data in the first place.
| diggan wrote:
| It got me curious; lets say I go to a protest, lose my phone
| and wipe it remotely. I couldn't possibly know who exactly got
| it (since I lost it) so if I remote wipe it while in police
| custody, could they really get you for "obstruction of justice"
| for example? Wouldn't that require intent?
| djoldman wrote:
| I am not a lawyer.
|
| You just don't even want to be at the "proving intent" stage.
|
| If you had a function/service that just automatically wiped
| your device at intervals, regardless of where you were and
| what you were doing, that might be more defensible than
| wiping manually.
|
| Best is if your device can't be locked and doesn't have any
| evidence of anything at all.
| layman51 wrote:
| There's a setting on iPhone called "Erase Data" which will
| erase the data on it after 10 consecutive failed passcode
| attempts. That seems like a recommended setting for any
| smartphone to be honest, especially if it is used for
| business.
| jsheard wrote:
| Most of this applies wherever but do check your local laws where
| applicable, I know that in the UK you can be compelled to provide
| a PIN/password under some circumstances.
| qwerty_clicks wrote:
| Almost too many steps to remember here. Would it be possible for
| an app to prompt you to do all this? An app can bring up settings
| to allow your camera access, why not to quickly change those
| other settings?
| tomphoolery wrote:
| > However, in this situation it may make more sense to disable
| biometric authentication.
|
| In Face ID, there's a setting that requires direct eye contact in
| order to open your phone. Highly recommend enabling this when
| feeling insecure about someone forcing you to open your phone (if
| it's not already on by default) because it means somebody forcing
| you to open your phone with Face ID can be easily defeated by
| simply closing your eyes. I tried this a number of times during
| the BLM protests, and I/nobody else could get my phone to unlock
| unless my eyes were open and looking right at it. So with Face
| ID, I think it's actually way more secure to have biometric
| authentication turned on, using this setting. The thumbprint
| stuff might be a good idea to avoid though.
|
| (WARNING: This will make your phone pretty much impossible to
| unlock with your face if you're inebriated on anything. Ask me
| how I know. xD You should probably disable it after the protest.)
| ryankrage77 wrote:
| This has failed me. I was mugged while black out drunk, and
| they succesfully unlocked my phone, unlocked my banking app,
| etc, despite me having the eye contact feature enabled.
| theoreticalmal wrote:
| While this is good info, it should also be known that in the
| USA, a judge (maybe and police officer?) can legally command
| you to unlock your phone via biometrics, but they cannot
| legally command you to unlock via password or passphrase.
| "Legally command" = command you to do something with the force
| of law, and legally punish you if you resist
| kevindamm wrote:
| The reasoning behind this is that your fingerprints and face
| etc. are public knowledge. Whereas you can retain your right
| to remain silent (about your password/PIN), failing to
| provide these aspects of your person can be viewed as not
| cooperating.
| HeatrayEnjoyer wrote:
| How does that mix with making direct eye contact
| gruez wrote:
| >The reasoning behind this is that your fingerprints and
| face etc. are public knowledge.
|
| Not really. You can be compelled to give blood sample for
| alcohol testing, but your blood is hardly "public
| knowledge". Same thing with strip searches.
| briHass wrote:
| That is usually due to 'implied consent' laws. Most
| states have it written into what you sign to get your
| license that you must submit to DUI testing. Generally,
| you can refuse, but the penalty for refusal is worse than
| the DUI penalty.
| arcanemachiner wrote:
| On an iPhone, you can click the power button 5 times to disable
| Face ID until the next time you enter your PIN.
|
| Depending on your settings, this may also call 911
| automatically, but that can be canceled.
| tehjoker wrote:
| If you're this worried, don't bring your phone lol. If you need
| to take pictures (and don't take identifiable pics of people
| without consent), just bring a camera.
|
| Otoh, the main function of protests is to get media attention, so
| if they don't get publicized there was basically no point unless
| they evolve into direct action.
|
| If you're interested in this second point, read
| https://www.amazon.com/If-We-Burn-Protest-Revolution/dp/1541...
| jMyles wrote:
| > don't take identifiable pics of people without consent
|
| Hard disagree. Public events are public events. My conclusion,
| based on experience at street protests, historic trends, and
| current political events, is that there have been significant
| actions by provocateurs over the past decade or more, and
| particularly in Portland in 2020. Taking and posting pictures
| of these people is an important act. It the internet age makes
| this tactic impossible, it will be a huge win.
|
| The upside is nonexistent anyway: the state is photographing
| everyone at these events, so you taking an additional photo
| does not change the risk surface for anyone with regard to
| state retaliation.
| nxobject wrote:
| As another Portlander, disagree with exceptions: surveillance
| footage made it harder to identify people from top down
| angles, and it meant that a lot of people had their charges
| dismissed because of that. (I will need to look it up.) The
| bigger risk to a protest movement, I would argue, is an
| opposing agent provocateurs trying to get people doxxed. That
| risk to more people outweighs getting minority of
| provocateurs shut down.
|
| (On the other hand, you're also right that agent provocateurs
| are old COINTELPRO-era tactics used by the state and right
| wingers against protest movements.)
|
| When it comes to tactics to keep yourself safe when
| protesting, there aren't ultimately too many hard beliefs to
| be had, especially when the right are perfectly happy to
| collaborate with the state.
| rightbyte wrote:
| >The bigger risk to a protest movement, I would argue, is
| an opposing agent provocateurs trying to get people doxxed.
|
| That wouldn't be an agent provocateur right?
| philwelch wrote:
| I mean there's two sets of social norms here, right? Set one
| is that whenever you see the first person advocating or
| starting to break windows or start fires or do something else
| illegal, you all point at the guy and chant "fed, fed, fed"
| until he slinks away in shame or maybe shove him out of the
| crowd and into the police lines and let the cops handle him.
| The other set of norms is that when you see people do those
| things, you don't snitch. Various protesters will adopt
| either set of norms.
|
| Maybe you'd argue that the second set of protesters are
| actually feds; I won't argue the point because I prefer the
| first set of norms myself.
| tehjoker wrote:
| I can definitely see this perspective. I'm a bit torn myself
| on the public event section. The second consideration is, yes
| they are filming, but just because someone is filming it's
| not necessarily a useful picture (blurry, low res, bad angle,
| obstructions, etc). Your picture might be useful especially
| since you may be closer to the action.
| hyperadvanced wrote:
| > there was basically no point
|
| Other good reads on this include the end of protest, the end of
| the end of history, capitalist realism
| nxobject wrote:
| Re: iPhones - these suggestions are really good, AND it shows how
| hard it is to keep track of the attack surface of all of modern
| iOS features. I wish Lockdown Mode also set these hardening
| features on: it seems useless to harden your phone against
| spyware if you can still be surveilled in other ways.
| upofadown wrote:
| Briar messenger is specifically designed for things like
| protests. I think I would prefer it over Signal. The article
| says:
|
| >Signal has responded to 6 government requests since 2016, and in
| each case the only information they were able to provide was at
| most: ...
|
| That is the all the information they claimed they had. We have no
| way to know what they actually collect. Briar runs P2P over Tor
| so they can't collect data, even if they should want to.
|
| Whatever is used, an article like this should remind the
| potential protester to turn on disappearing messages with an
| appropriately short interval. The powers that be might use
| something like a Cellebrite box to get all your old messages by
| cracking the phone security.
| fph wrote:
| Signal is open source and ships with verified builds, so yes,
| we have a way to know what they actually collect.
| upofadown wrote:
| I meant at the server. We have no way to know that is running
| there.
| mmooss wrote:
| The server is open source too. You could download it and
| run your own server, afaik.
| TiredOfLife wrote:
| Signal occasionally drops something that could be the
| server code.
|
| When they were working on their cryptocurrency they
| didn't release anything for over a year.
| chikere232 wrote:
| isn't that what the e2e encryption is for?
|
| I guess they could collect metadata of course
| Almondsetat wrote:
| How can the server collect data you aren't sending to it?
| mmooss wrote:
| > Briar runs P2P over Tor so they can't collect data, even if
| they should want to.
|
| That makes the common, dangerous, naive assumption that the
| implementation is secure. Correct, complete, secure
| implementations are very hard.
|
| (It also assumes the design is secure, which is impossible to
| tell based on that limited information. P2P is not any more
| secure than over the Internet: In fact, it's easier to identify
| (there are only a few Briar P2P signals and near-infinite
| Internet signals - you've outed yourself), and if you mean
| local mesh P2P networking, that doesn't help at a protest,
| where the authorities also are present.)
|
| In the more public app world, only Signal has done it well
| enough that experts trust it, and they have lots of free help
| from the expert security community.
| cmxch wrote:
| A sufficiently motivated state actor will have little issue with
| finding what they want/need, no matter what measures are taken.
| tonymet wrote:
| protesters deal with various agencies from private security,
| city police on up to federal FBI etc. These measures will help
| in the most common scenarios and prevent further escalation.
| 99.999% of protestors are not going against NSA counter-intel
| teams, they are encountering low-level private security or
| police who escalate the situation.
|
| Every security practice is a risk/reward. The measures being
| offered here are no-cost measures which can reduce the exposure
| of evidence to casual security / police.
| AtlasBarfed wrote:
| Th smartphone is the greatest mass surveillance device ever
| conceived, although AI monitored camera networks will probably
| exceed it very soon.
|
| There are basically no countermeasures. Which means freedom is
| truly at the discretion of the powerful, because once the
| government goes North Korea there is no going back.
|
| I actually think the biggest threat to humanity in the Great
| Filter sense is authoritarianism, more than nuclear Armageddon,
| grey too, or super AI.
|
| Nothing can stop by he centralization of power that AI provides
| to the powerful, and the fact the elite have been brazenly
| antidemocratic and anti- institutionalism in public and
| podcasting platform is this election cycle is frightening.
| mmooss wrote:
| > Nothing can stop by he centralization of power that AI
| provides to the powerful
|
| The social acceptance of defeatism and quitting is incredible -
| they couldn't have a more ideal opposition. You'll never win if
| you quit before you start. It's mass cowardice in the face of
| danger, with an excuse of course.
| unethical_ban wrote:
| It's unfortunate that Briar is android-only. I know it is due to
| Apple restrictions on battery usage (afaik). But it is
| decentralized and can operate locally over wifi and Bluetooth.
|
| These seem like good practical steps.
|
| GrapheneOS has duress pins (type it in, and the phone is wiped).
| It has secondary pins for biometric - the intent being that your
| real password is a long passphrase, and "quick " unlock is
| bio+pin.
|
| I would add to this list some method of uploading video live to
| another service, in a way that the video can't be deleted via the
| phone. I know those exist for the express purpose of civil
| rights, I think the aclu has a list somewhere.
| raybb wrote:
| 404 Media just released a great related article "The Powerful AI
| Tool That Cops (or Stalkers) Can Use to Geolocate Photos in
| Seconds"
|
| https://www.404media.co/the-powerful-ai-tool-that-cops-or-st...
| gruez wrote:
| What does this have to do with protests? Aren't protests by
| definition events where the organizers want people to be aware
| of?
| tejtm wrote:
| Protest also attract polarizing provocateurs, you may not
| want to be associated with all that is done in your name.
| dang wrote:
| HN had a thread about that tool last year:
|
| _AI Photo Geolocation_ -
| https://news.ycombinator.com/item?id=40232755 - May 2024 (102
| comments)
| WarOnPrivacy wrote:
| Old phones are an underappreciated resource, imo.
|
| I keep a few handsets around for apps I don't want on my daily
| driver (ex:food ordering, 2FA).
|
| More in line with the article: For alternate cell/SMS service I
| have a RedPocket SIM. (note: I see now it's $45/yr on ebay. I'm
| paying less, prob grandfathered).
| gruez wrote:
| >Old phones are an underappreciated resource, imo.
|
| Not really. Old phones don't receive security patches and can
| be trivially unlocked to extract all relevant information.
| Sure, it might not have your nudes or bank login, but if you're
| using it to coordinate the protest that's plenty of
| incriminating evidence for the police.
|
| >For alternate cell/SMS service I have a RedPocket SIM. (note:
| I see now it's $45/yr on ebay.
|
| You have to be very careful with this, otherwise it's trivial
| to tie the phone/SIM back to you. Off the top of my head:
|
| * the billing/shipping address used to order the SIM
|
| * any payment information used to top-up the account
|
| * location correlations with any other devices you own (for
| instance, if your burner phone pings the same towers as your
| primary phone for an extended period of time)
|
| * using it for anything other than protests (eg. as a "burner"
| number when applying for jobs to avoid spam)
| WarOnPrivacy wrote:
| > Not really. Old phones don't receive security patches.
|
| For a phone that was off until 2 hours ago and it's only
| login is the app they comm with, there don't seem to be a lot
| of meaningful risk vectors.
|
| > and can be trivially unlocked to extract all relevant
| information.
|
| The unlocker will maybe get one app login and 2 hours of
| location data.
|
| > if you're using it to coordinate the protest that's plenty
| of incriminating evidence for the police.
|
| It's one app login and 2 hours of location data. Most of that
| same info can be gleaned by directly observing the
| individual.
| iseanstevens wrote:
| Also Meshtastic.org is a cheap (various <$50 options) open source
| LoRa based hardware bridge (or standalone device) that can be
| used with an app over bluetooth (or WiFi web interface).
|
| It supports strong encryption layer and over 1 km/mile per "hop"
| in most circumstances.
|
| Designed originally for off grid, it's very flexible and pretty
| polished.
|
| Abstracts your phone into a UI. Has a whole ecosystem behind it.
| I've been using it for festivals and tracking my vehicles (high
| theft area) for years.
|
| Very handy should infra not be available. Should be great for
| protests also :)
| nightpool wrote:
| This would depend on your phone being able to permanently
| disable its radio, right? I don't know if I would trust my
| phone well enough for that, I would be worried even in airplane
| mode about it making some small beacon checks.
| _heimdall wrote:
| There are a few devices floating around with a hardware
| switch built in. If you use a Pixel, grapheme OS is probably
| pretty trustworthy so you at least no there's nothing
| nefarious down to the OS level.
|
| But yeah, in general if you take a phone just assume it's
| tracking you or at least making it possible for those with
| access to know you where there.
| red0point wrote:
| Do you have any information about the privacy achievable by
| Meshtastic?
|
| From a quick glance it looks like it's using static NodeIDs
| derived from the Bluetooth MAC address in the always
| unencrypted Packet Header.
|
| So not only can you sniff these messages from far away at
| greatly simplified complexity when comparing to cellular
| communication, but also tie it to the hardware that you carry
| with you.
|
| Mesh networks sure have its uses, but I'd be wary of their
| offered privacy in the presence of adversaries you could be
| facing at protests!
| liontwist wrote:
| I don't understand the issue. Protesting is legal. Are we
| advocating for illegal activity?
| Almondsetat wrote:
| >Protesting is legal
|
| first of all, where?
|
| secondly, what has legality of protest got to do with privacy?
| liontwist wrote:
| The concern of your phone being taken by authorities or
| capturing incriminating evidence
| Almondsetat wrote:
| Are you making the "if you've got nothing to hide"
| argument?
| liontwist wrote:
| That would be sharing your phone and password with the
| police because there is nothing to hide.
|
| I'm asking why you're expecting to be booked by
| authorities and your phone confiscated for attending a
| "protest".
| Almondsetat wrote:
| 1. because the U.S. is not the only country on Earth
|
| 2. because even in nations with strong constitutional
| protections, law enforcement likes to play dirty
| MengerSponge wrote:
| 1) Protesting is illegal in many parts of the world.
|
| 2) Authoritarians have been known to act illegally to solidify
| their power.
| liontwist wrote:
| Are we imagining only "good guys" will be the ones breaking
| the law?
| philwelch wrote:
| There's some strategic ambiguity going on here. If you're going
| to a protest that looks like the Women's March on Inauguration
| Day of 2017, you don't have to worry about this kind of thing.
| If you're starting fires or breaking into the Capitol building,
| you definitely do have to worry about this sort of thing. And
| just to make things even muddier, the exact same protest can
| radically change from one to the other based on specifics of
| time and place. In the summer of 2020, Seattle and Portland had
| mostly peaceful and uneventful protests by day in the exact
| same places where shootings and arsons would break out after
| dark, while on January 6th, just as some of the rioters were
| trying to force their way through the windows on one side of
| the Capitol building and clashing with Capitol Police, on the
| other side of the Capitol they were peacefully walking through
| wide open gates and doorways and milling around in the hallways
| as the Capitol Police looked on. And yeah, the peaceful ones
| get prosecuted sometimes too.
| georgeecollins wrote:
| I think the "strategic ambiguity" here is ethics. Civil
| rights protestors were clearly breaking the law when they sat
| at diners that wouldn't serve black people. But who today
| thinks they were wrong? When I was a kid, students protested
| at Universities to divest from Apartheid era South Africa.
|
| People can agree on what the law is, but they don't always
| agree on what is right. Sometimes a democratic government
| will zealously defend a law, war or principal that later
| generations of the same government will disavow.
| pjc50 wrote:
| That depends on whether the police like your protest.
| dpc050505 wrote:
| https://en.wikipedia.org/wiki/2012_Quebec_student_protests
|
| Mostly legal protests that got violently repressed by
| enforcement of unconstitutional laws in Quebec.
|
| https://en.wikipedia.org/wiki/2010_G20_Toronto_summit_protes...
|
| Same thing in Toronto.
|
| Canada rates very high on democracy indexes. Even if you beat
| the charge in court you can still get arrested on bullshit in
| every country.
| georgeecollins wrote:
| In the US, free speech is legal. You also have a right to
| congregate but lots of institutions find ways to subvert that,
| often by creating private spaces that seem public (and
| effectively are public but I am not a lawyer). The whole
| concept of civil disobedience in the US goes back to the
| Mexican American war, which many Americans felt was an
| opportunity to expand slavery to new states. Another example is
| the civil rights movement, where people thought it was
| acceptable to sit in the wrong part of the bus, even though it
| was against the law.
|
| I am not advocating for breaking the law. You have to
| understand that if a police person or a security guard violates
| your rights of free expression you may not get bailed out by
| the ACLU.
| giantg2 wrote:
| Most of this is everyday security.
|
| "Avoid External Storage"
|
| They missed part with this. You could use external storage just
| for your current recording purposes so you can pop the SD card
| and take it with you if you think your phone will be taken.
| scarface_74 wrote:
| This is what the other side is telling law enforcement about iOS
| devices.
|
| https://cellebrite.com/en/glossary/bfu-iphone-mobile-device-...
|
| iOS is amazing insecurely to a determined law enforcement agency
| after the first unlock when you turn your phone on.
|
| And a mitigation that Apple is doing.
|
| https://lonelybrand.com/blog/iphones-operating-on-ios-18-1-w...
|
| As far as having a strong pin to help protect you, it won't
| protect you from rubber hose decryption.
| echoangle wrote:
| > As far as having a strong pin to help protect you, it won't
| protect you from rubber hose decryption.
|
| I wonder why no one adds a ,,decoy pin" which looks like it
| unlocks the device but secretly deletes sensitive data.
|
| Probably, most people don't see rubber hose cryptography as a
| real threat, and in most cases, they're probably right.
| scarface_74 wrote:
| I don't have any trust in the police or even more so the
| various 3 letter agencies.
| idlewords wrote:
| Unfortunately this is a topic that attracts LARPers. Remember
| that if things get spicy, you are not going to settings nerd your
| way out of a bad interaction with the police.
|
| Tech advice for legal and illegal protests is pretty much
| diametrically opposite, and advice for countries like the United
| States is much different than for somewhere like Egypt.
|
| It's complicated!
| vueko wrote:
| The fact that rubber-hose cryptanalysis exists doesn't mean
| that cryptography is useless. While settings nerding is indeed
| probably of limited use if you have a direct encounter with
| authorities, settings nerding can prevent being caught up in a
| dragnet search for, say, every cell service subscriber present
| at a protest gone sour, just as ubiquitous cryptography
| probably can't keep you safe from dedicated NSA attention but
| can protect against warrantless dragnet fishing expeditions.
|
| As pointed out elsewhere, the line between legal and illegal
| protest is very blurry and can shift rapidly; if anything, the
| only way to be sure you're not going to a protest that could
| eventually be classed as illegal is to never go to a protest,
| regardless of how pure your intentions are.
| maybejustmaybe wrote:
| Technically you could piggy back on another protocol and
| obfuscate your comms. Like piggy backing in an envelope across
| https connections from server to server. Nobody is looking there.
| And even if they are, good luck decrypting that. Looks like a
| legit site but it is actually a proxy for delivery encrypted
| payloads.
___________________________________________________________________
(page generated 2025-01-26 23:00 UTC)