1 of 22

Digital Security Training: �Operational Security

@geminiimatt | cryptoharlem |� Independent researcher & opsec trainer at�global journalist security

2 of 22

$whoami:Matt

  • 2016/2017 Mozilla/Ford Open Web fellow at Color of Change
  • 2017 Internet Freedom Festival fellow
  • 2016/2017 New America Cybersecurity Initiative fellow
  • Institute For The Future Future for Good fellow
  • advisor to the Open Technology Fund
  • hacker, security researcher
  • Information & operational security�trainer to NGOs & journalists (via Global Journalist Security)
  • developer and data journalist (formerly of NY Times)
  • founder/lead Crypto Harlem

3 of 22

WHY ARE WE HERE?

https://wikileaks.org/sony/press/

4 of 22

What Is Operational Security?

Information Security (infosec): �the technology used to circumvent surveillance.

Operational Security (OPSEC):

The methods , Practices, approaches to best secure yourself.

Including the best way to use information security to properly circumvent surveillance.

5 of 22

WHERE DO WE GET STARTED?

THREAT MODEL

  • What are we trying to protect ?
  • Who are we protecting it from?
  • WHAT is their capabilities (money, resources, expertise)?
  • What would happen if they did get access to this thing?
  • What Can We Do about IT?

6 of 22

WHERE DO WE GET STARTED?

  • WEAKEST LINK
  • PROTECT FUTURE YOU
  • SCORE SOME REAL WINS
  • PROTECT YOUR MEMBERSHIP: data retention

7 of 22

WHERE DO WE GET STARTED?

  • Warrants, Subpoenas, National Security Letters
  • Federal Rules of Criminal Procedure's Rule 41 / think as Digital Search and Seizure, changes allow district judge shopping
  • Digital safety vs. digital security
  • Defense in depth: multiple defenses of different types used together
  • Protect Yourself from Social Engineer:Contact Mobile, Internet, & Power providers to secure accounts with a pin numbers or other info to make changes

8 of 22

WHAT DO WE DO?

  • USE AN IPHONE OR ENCRYPT YOUR ANDROID PHONE
  • SWITCH TO A PASSCODE INSTEAD OF TOUCHID
  • USE AN 11 DIGIT PASSCODE
  • USE SIGNAL FOR ENCRYPTED CALLS TO/FROM PEOPLE WE TRUST
  • USE WIRE FOR ENCRYPTED CALLS TO/FROM PEOPLE WE DON'T TRUST YET
  • USE SIGNAL FOR ENCRYPTED MESSAGES TO/FROM PEOPLE WE TRUST
  • USE WICKR FOR ENCRYPTED MESSAGES TO/FROM PEOPLE WE DONT TRUST YET
  • Consider a virtual number FOR using signal (google voice,covermeapp,burner app, phone.com, etc.)

9 of 22

DEFENDING OURSELVES!

10 of 22

Operational security

DEFENDING OURSELVES!

Challenge // response: A METHOD TO VERIFY THAT THE PERSON YOU ARE COMMUNICATING WITH ARE REALLY THEMSELVES, (NOT A SPOOFED VERSION OF OR BAD ACTOR).

11 of 22

Operational security

DEFENDING OURSELVES!

DURESS CODE: A WAY YOU CAN FLAG TO OTHERS THAT YOU HAVE BEEN OR BELIEVE THAT YOU HAVE BEEN COMPROMISED OR CAN NOT COMMUNICATE FREELY.

12 of 22

Operational security

DEFENDING OURSELVES!

WEATHER (GUT) CHECK: a way to check in without making it obvious, “whats the weather like?”, “HOW SPICY WAS LUNCH?”

13 of 22

INFORMATION security

DEFENDING OURSELVES!

LAST PASS: SECURE PLACE TO STORE & SHARE GENERATED PASSWORDS

14 of 22

INFORMATION security

DEFENDING OURSELVES!

KEEP SOFTWARE UP TO DATE !

15 of 22

INFORMATION security

DEFENDING OURSELVES!

2 factor auth: IN ADDITION TO A USERNAME & PASSWORD (something you know), AN ADDITIONAL ALWAYS CHANGING PIECE OF INFORMATION (something you have), IS NEEDED. Opsec tip: Instead of reciving an sms to your phone or using an app...BUY a HARDWARE TOKEN...YUBICO YUBIKEYS

16 of 22

INFORMATION security

DEFENDING OURSELVES!

TURN OFF MICROSOFT OFFICE MACROS �OR AVOID MICROSOFT OFFICE:

17 of 22

INFORMATION security

DEFENDING OURSELVES!

Use a secure sandbox to open potenTially dangerous emails, links, and attachments:�open ATTACHMENTS IN GOOGLE DRIVE �or ON a CHROMEBOOK. Consider USING a secure operating system like QUBES Which creates a sandbox locally.

18 of 22

Operational security

DEFENDING OURSELVES!

NO ATTACHMENT POLICY: NO FILE TO CLICK, NO MALWARE. DROPBOX SHARE ONLY. DONT CLICK ON OR SHARE ATTACHMENTS.

Data retention & EMAIL retention policy:

DIGITAL SECURITY POLICY:

19 of 22

INFORMATION security

DEFENDING OURSELVES!

VIRUSTOTAL: a place you can look up suspicious links��MALWAREBYTES: PROVIDES FAST FREE QUICK MALWARE SCANNER FOR ANDROID & COMPUTER

SOPHOS: PROVIDES FREE QUICK MALWARE SCANNER FOR ANDROID & COMPUTER

20 of 22

INFORMATION security

DEFENDING OURSELVES!

HAVEIBEENPWNED: Lets you know if your email & PASSWORD ARE LISTED ONLINE AS PART OF A DATA BREACH

21 of 22

DEFENDING OURSELVES!

Secure your google account from google & marketers.

MyActivity.google.com:every thing google knows about your “profile”

maps.google.com/locationHistory: everywhere google knows you were�www.google.com/settings/ads/authenticated:TURN OFF Ad Profiles

22 of 22

Contact me: Matt

email: matt.mitchell@colorofchange.orgemail: geminiimatt@gmail.com�GPG: 0x0b8770aa07046231�Keyid: 0x78913ff0a3008385�fingerprint: 381A B2F0 0378 2939 B00C 467F 0B87 70AA 0704 6231�keybase.io: geminiimatt�wickr.com: geminiimattx�threema: geminiimattx ( D7MMDUZ8 )�whatsapp: geminiimatt�ricochet: ricochet:snlxgyf2nxm3gp7p <- subject to change�otr/XMPP: geminiimatt@jabber.calyxinstitute.org�peerio: geminiimattx�semaphor: geminiimatt�twitter.com: geminiimatt