1 of 57

Security Protocol

Staying safe: Practical Tools for Investigative Journalist

Luis Assardo | @luisssardo

Digital Security

2 of 57

Surveillance

Online harassment

Digital attacks

Legal harassment

Financial block

Evolution of the types of attacks to journalists

Increase the level of attacks

3 of 57

Capacity building

Hardening devices

Personal Protection Plan

Prepare for the worst

Community building

Risk Assessment

Advocacy for regulations

Internal activities

External activities

4 of 57

Awareness

5 of 57

6 of 57

7 of 57

8 of 57

Instinct + experience

9 of 57

How do we recognize a threat actor?

10 of 57

Like this?

11 of 57

Awareness

The skill we develop (in our brain) that allow us to recognize, identify and take action according to the level of risk we are facing.

12 of 57

Risks

13 of 57

Risks

A combination of threats and vulnerabilities.

Threat

+

Vulnerabilities

14 of 57

Risks

A combination of threats and vulnerabilities.

Vulnerabilities are our weaknesses.

Threat

+

Vulnerabilities

Threats are external and out of our control.

15 of 57

Risks

Establish what do you want to protect.

Identity

Data

Comms

16 of 57

Risks

Start profiling with data from every attack.

Proximity

Expertise

Resources

17 of 57

Threat actors

18 of 57

Threat actors

Individual, group, or entity that carries out malicious activities with the intent of causing harm, exploiting vulnerabilities, or gaining unauthorized access to computer systems, networks, data, or other valuable assets.

19 of 57

Threat actors

Threat actors are adversaries, but not all adversaries seek to do harm.

20 of 57

Attack vectors

21 of 57

Attack vector

Is the pathway an attacker (threat actor) reach us to cause harm. Usually they try to gain access, steal data, infect a device, delete data, etc. Any vulnerability can be exploited.

22 of 57

Attack vectors a journalists may face:

Phishing Attacks

  • Attackers send deceptive emails or messages impersonating legitimate sources, aiming to trick the journalist into revealing sensitive information, credentials, or clicking on malicious links.

Malware and Spyware

  • Malicious software may be embedded in documents or links sent to journalists, designed to compromise devices, monitor activity, steal sensitive data, or even remotely control systems.

23 of 57

Attack vectors a journalists may face:

Man-in-the-Middle (MitM) Attacks

  • Attackers intercept communication channels (email, chat apps, phone calls, or public Wi-Fi) used by journalists to capture sensitive information, conversations, or metadata.

Social Engineering

  • Attackers exploit personal information publicly available or gathered through deception, manipulating journalists into sharing confidential data or providing unauthorized access.

24 of 57

Attack vectors a journalists may face:

Credential Theft and Account Hijacking

  • Attackers target weak passwords, reused credentials, or leverage breached databases to gain unauthorized access to email accounts, cloud storage, or social media platforms, potentially compromising sensitive sources or reporting materials.

Physical Device Compromise

  • Attackers physically access or steal a journalist’s devices (laptop, smartphone, USB drives), install keyloggers or hardware implants, or tamper with devices to extract or compromise confidential information and communication.

25 of 57

Layers of security

26 of 57

Layers of security

The way you configure your protection according to the context and the risks you are facing

Awareness

+ Preparation

Strong Passwords

MFA

Encryption

Device updates

27 of 57

Managing passwords

28 of 57

Passwords

Factors to consider:

  • We want to memorize.

  • Too many accounts.

  • Standards according to platforms.

Group of symbols

Identity proof

Data Bases

29 of 57

Passwords

  • Weak passwords
  • Repeated
  • Recycled
  • Compromised
  • Easy to guess

Risks

30 of 57

Passwords

Risks

Audit your credentials

31 of 57

Passwords

Someone steal a data base

Black market

Data bases buyers

Data bases buyers

Harm

Service

32 of 57

Passwords Managers

Cloud base

Local

Encrypted data base

Encrypted connections

One Click solution

33 of 57

Passwords Managers

34 of 57

Authentication

35 of 57

Authentication

Username

Password

SMS

Time-based One Time Password (TOTP)

Security Key

Passkey (biometrics)

Prompt (Google)

Security Codes

36 of 57

Data and Privacy Hygiene

37 of 57

Digital footprint

  • Compromised credentials
  • Search engines
  • Reverse image search
  • Use OSINT

(Ask for assistance if you are not prepared to see what is out there)

Audit

38 of 57

Digital footprint

  • Secure all access
  • Use services to delete information
  • Anonymize personal data
  • Use available laws
  • Control your name in popular platforms

Actions

39 of 57

40 of 57

41 of 57

42 of 57

43 of 57

44 of 57

Basic Device Security Practices

45 of 57

Basic Security Practices

Devices locked with passphrase or biometrics

Physical Access

Vulnerabilities

Or device empty with data on the cloud

Keep all software updated (schedule sessions)

Internet connection

Firewall + data encrypted

46 of 57

Update software

Vulnerability discovered

Common Vulnerabilities and Exposures (CVE)

Report is public

Vendor fix the vulnerability

Vendor send updates

User update

47 of 57

Basic Security Practices

  • Avoid public WiFi

  • Delete old WiFi connections

  • Always prefer “ask before join”

  • Use Lockdown Mode (iOS users)

WiFi attacks:

  • evil twin (cloning)
  • Man-in-the-Midle (MitM)
  • Deauthentication

48 of 57

Encrypted Communications

49 of 57

https://www.securemessagingapps.com/

50 of 57

Phishing Prevention

51 of 57

Phishing Attacks

  • Get information
  • Steal credentials
  • Infect a device
  • Farming clicks

Target

52 of 57

Digital Threats Analysis

53 of 57

Website(s)

One or many websites in parallel or cascade to be used as source.

Digital Threats

Online harassment

Social Media

Fake Accounts in any social media platform. Hybrid or bot.

Newsletter

Using hired or fake sources to reach users as any other newsletter.

Brigading

Accounts use to flood comment section or reply in social media.

Podcasts

Owned and mentions in allied podcasters.

Printed Media

With fake authors using cascade of sources making difficult to trace back.

Messaging Apps

Groups and online communities spreading fabricated content.

Influencers

Allied and hired influencers to spread fabricated content.

They make a plan

They build an ecosystem

54 of 57

  • Emotional manipulation: Trolls often use emotionally charged language and provocative content to elicit strong reactions from users. So-called rage farming is very common.

  • Targeting influential individuals: Trolls may target celebrities, politicians, or high-profile individuals to capitalize on their followings and gain more attention.

  • Creating and spreading memes: Trolls use humorous or provocative memes to spread disinformation or offensive content. Memes go viral quickly, reaching large audiences.

  • Deepfakes and manipulated media: Trolls may use advanced technology to create fake videos, images, or audio recordings to spread disinformation, discredit individuals, or fuel conspiracy theories.

Digital Threats

Online harassment

55 of 57

Digital Threats

Funneling

Tactics

Doxxing

Brigading

56 of 57

  • Identify if is an isolated event or part of a campaign.

  • Identify if they are using external resources.

  • Document and preserve.

  • Prepare answers in advance.

  • Control the narrative.

  • Block pollution of your conversations.

Digital Threats

Response (basics to remember)

57 of 57

Thank you