Brushing your Teeth
A quick breakdown of security hygiene steps. Each of these tasks will move you towards better digital security and privacy. Try to knock out 2 a day and in a week you'll be in a great place! Pass it along and help others go through this guide. We keep us safe. - JT
Currently, one of the easiest ways to get geolocation data on an individual is through data brokers. These companies work to grab as much data about individuals as possible.
Often times this is done though what is called finger printing.
The process of creating a distinct digital profile of a user though elements of their digital life. Things like
- The browser you're using
- The phone you're using
- The operating system you have installed
- Language
- Timezone
With enough of this data, someone like a data broker can know that you are a specific individual, even if they don't know exactly who you are. This is called an anonymized profile. If they then connect that to a name or email, a data broker can know who you are, even if you're only de-anonymized once.
The ads that are served to you through the apps on your phone are often used to help create these finger prints, specifically because they have a unique ID associated with them, your Ad ID. Selling this Ad ID for de-anonymization is technically illegal, but that's never stopped the data brokers from selling it.
On Android: Settings > Privacy > Ads > Delete advertising ID iOS: Settings > Privacy & Security > Tracking > Allow Apps to Request To Track
On Android, Google Play > your profile picture > Settings > Network Preferences > Auto-update apps > choose an auto update option
Also on Android, go to System > Software Update > Software Updates to make sure your Android versions are up to date. On iOS, Settings > General > Software Updates > Turn on automatic updates
When apps and OS are written, they are written by humans and humans are fallible. Often the software developers will inadvertently introduce bugs into the software.
When bugs are found, the software developers release patches to fix the bugs. These patches are introduced in the updated versions of apps.
Keeping apps up to date is especially important after a major version is released, because there may be lots of code changes, and therefore lots of bugs introduced. Some of those bugs may be security vulnerabilities that you want to fix right away.
Instagram: Settings > Account Privacy > Private account Facebook:
- Settings > Privacy Center
- Audience Settings
- Profile Information > 'Only Me' or 'Friends'
- Posts > 'Friends'
- Review tags before they appear on your profile > 'On'
- Ad Preferences > Manage in Account Center
- Categories used to reach you > 'off'
- Activity information from ad partners > 'Review Setting' > 'No, don’t make my ads more relevant by using this information'
- 'Ads from ad partners in other apps' > 'Don’t show me ads from ad partners'
- Social Interactions > 'Select an account' > 'Only Me'
- Audience Settings
Twitter:
- '...' icon > 'Settings and Privacy > 'Privacy and Safety' > 'Audience and tagging' > 'Protect your posts'
If someone wants to know who you're friends with, and what sorts of things matter to you, the easiest way is to check out someones instagram. Most of the time, someone looking at your pictures is a friend or family, but nothing is requiring that to be true. Some things to understand:
- All likes on a public post are public.
- All of those following and are followed by a public account are public.
- Public tags are public to everyone.
The more accounts are private, the harder it is for someone to build a profile of your information, and the harder it is for someone to build a profile of information on someone you care about.
On all of those now private social media accounts, spend some time going through that list and ask yourself
- Do I really know this person?
- Do I know that this account is actually tied to the person I think it is?
- Does this person need to have access to everything about me?
A private account is only private if the people who shouldn't have access aren't following you. If you accept every follow request without thinking about it, the friction you're creating for someone creating a profile of your information is minimal. Security through obscurity isn't perfect, but every step helps.
Use Bitwarden, LastPass, ProtonPass to store your passwords.
Bitwarden is free for personal use.
Password managers attempt to solve common problems with passwords:
- Reusing the same password across multiple accounts is not secure, because one site could be breached and your password for other sites would be leaked.
- At the same time, having a different password for multiple sites is hard to remember.
- Strong passwords are even harder for humans to remember than weak passwords, adding to the security problem.
A password manager solves the problem by putting all your passwords in one well-protected place. A password manager may only be accessed on devices you approve, and requires a strong password to open. This way, you only need to memorize one strong password to get to many different strong passwords for all your accounts.
The risk of this one strong password leaking is minimized by only being to access your passwords from approved devices.
Use Google Authenticator or another authenticator app when logging into accounts.
Avoid using SMS authentication when possible, as it is significantly less secure than an authentication app. There are several approaches to gaining codes sent through SMS such as SMS sniffing and SIM swapping.
Security often refers to factors of authentication as "something you know", "something you have", and "something you are". Something you know might be a password, something you have might be your phone, and something you are might be a FaceID or fingerprint.
If we rely on a single one of these factors, your account may be easily broken into. For example, if a website incorrectly stored your password and it leaked to the public, that factor could be used elsewhere. Similarly, phones with FaceID can be opened by holding the phone up to your face.
When we use more than one factor, an account becomes much more secure. A bad actor might get your password, but if you have an authenticator app, they would need your password and your phone to get into your account. More work for the bad actor means you are more secure.
iOS and Android encrypt automatically if you have a pin set
Windows: settings > privacy & security > device encryption > on
Mac OS: search 'File Vault' > turn on
If a device is ever taken from you, sold, lost, or given away, you'd not want that person to have access to everything that is currently on your device. Encryption means that anyone who has access to the locked version of your device cannot see any of the files that you have.
iOS:
Android:
- Settings > Security & Privacy > Biometrics
- Face Unlock > off
- Fingerprint unlock > off
" If law enforcement have your phone, it is legal for them to unlock your phone using your fingerprint or your face. However, if your phone has a numerical password on it, it is illegal for them to compel you to tell them the code access your phone." - twincities.fyi
Often you hear that this is something to turn on and off when you're at a protest, but law enforcement doesn't only exist at a protest.
Android: Settings > Security & Privacy > Lock screen > Screen lock > PIN > set a 6 digit pin
iOS: Settings > Face ID & Pin > Turn Passcode on (or Change Passcode) > custom numeric pin > set a 6 digit pin
If a device is taken, and it has been encrypted, the only way to get into that device is by guessing the password. For a 4 digit pin, there are 10,000 possible guesses, for a 6 digit pin, that number jumps to 1,000,000. Phone companies and hackers are in a perpetual arms race around password cracking, but you never want to make it easy for them, those 2 extra numbers make that guessing process significantly harder.
Password cracking is an ancient technique of getting into somewhere you're not supposed to be, and folks have gotten really good at it. Some things to know
- Longer doesn't always mean better, ^Y66u&A is better than mypassword111
- On old hardware, an okay can mean nothing if an exploit has been found to either bypass that password or allowing someone to throw an incredible amount of attempts/sec at your password
- Often password guessing uses a dictionary of words, so not using words, or using at least 3 (with characters and numbers), will currently put your password into a place where it is 'uncrackable'
Manual: Screenshot a picture before sharing it
Android: Settings > Location > App Location Permissions > Camera: Set the location to not allowed.
Apple permissions: Go to Settings > Privacy & Security > Location Services > Camera, then tap Never.
NOTE: only screenshotting (or using an exif removal app like https://www.exifdata.com/) remove what kind of camera took the picture, which can be used for finger printing
Every picture you take when you have location data enabled on your camera puts a bit of metadata about where the picture was taken in the photo file.
When you create a file on a computer, it is often filled with data things like
- An image
- A bunch of words in a google doc
- Code for a program
But on top of that data, there's something called metadata. This is data that the computer uses to know how to handle that file. This is things like
- What kinda file it is (an image, text)
- When it was made
- When it was last updated
This is all really helpful for managing But it also can store information that can limit a users privacy (like exif data).
If someone then finds that picture, even if it's an indoor image with no way of telling visually where you are, that metadata (called exif data) can be used to know exactly where the photo was taken. This could leak
- your address
- your friends addresses
- the fact that you're not near your address
- etc.
https://haveibeenpwned.com/ > put in your email > change the passwords for any site that has come up > sign up for notifications
If an account has been hacked and either the passwords or password hashes have been leaked, that account can now be compromised by anyone who can find that leaked data.
When you make an account on a website, your password is not stored as the text of the password, but as a jumble of characters called a password hash. This is a one way cryptographic string of characters, meaning that if you know the password, you can get the hash, but if you know the hash, you can't go backwards to the password.
One issue with having a leaked hash though is that means that it is easier to do faster brute force password cracking on said password, because they can run the guessing on their machine instead of the password entry field for the website.
This is also where password managers come into play. If one account is hacked, and you're using that same password elsewhere, someone can now access more than just that one account. That password manager makes it easy to not have to think about all those different passwords, and makes switching to a new secure password easy.
uBlock Origin - Free, open-source ad content blocker.
uBlock Origin is not just an “ad blocker“, it's a wide-spectrum content blocker with CPU and memory efficiency as a primary feature. Developed by Raymond Hill.
Privacy Badger
Privacy Badger is a browser extension that stops advertisers and other third-party trackers from secretly tracking where you go and what pages you look at on the web. If an advertiser seems to be tracking you across multiple websites without your permission, Privacy Badger automatically blocks that advertiser from loading any more content in your browser. To the advertiser, it’s like you suddenly disappeared.
Mobile: https://adguard-dns.io/en/welcome.html
The web will become significantly less cluttered, allowing you to see what's real and what's an ad more easily.
Privacy badger helps remove the ability for you to be as easily finger printed while using the internet.
twincities.fyi
Every place on the main street of my neighborhood is either closed indefinitely or posts a guard at the door to keep it locked and unlock it for patrons. Volunteers often stand outside during opening and closing to keep people safe on their way to and from their cars.
Electronic Frontier Foundation
Defending your rights in the digital world
Mullvad VPN - Privacy is for the people
Free the internet from mass surveillance and censorship. Fight for privacy with Mullvad VPN and Mullvad Browser.
Neocities
Create and surf awesome websites for free.
Signal Messenger: Speak Freely
Say "hello" to a different messaging experience. An unexpected focus on privacy, combined with all of the features you expect.
Doxcare
A step-by-step guide explaining how to protect yourself from online stalkers, why it's important, and what to do if you are targeted for doxxing.
Surveillance Self-Defense
We’re the Electronic Frontier Foundation, a member-supported non-profit working to protect online privacy for over thirty-five years. This is Surveillance Self-Defense: our expert guide to protecting you and your friends from online spying. Read the BASICS to find out how online surveillance works. Dive into our TOOL GUIDES for instructions...
Security Essentials | Digital Security Checklists for Activists
Every click, message, and location ping creates a digital trail that can be used against activists and organizers. Law enforcement regularly demands data from t...
Stuff to add? email jt@yet.earth
Did you enjoy this article?
Recommend it — Standard Reader surfaces well-loved writing to more readers across the network.