| I worked on this project and we've been quite concerned with this issue. I definitely hope people will come away with a clear sense of their risks and of what the tools do and don't do. I wrote most of this section https://ssd.eff.org/en/module/problem-mobile-phones which is about threats and risks which in many cases we don't have good ways to mitigate, and I tried to be fairly thorough. For example, we don't have an unambiguously good and convenient way to mitigate handset location tracking, burner phone detection, or compromise of baseband processors. So I hope people will read those parts too and get a sense of perspective! I also tried to make sure that the sections about PGP mention unprotected metadata, unprotected subject lines, and the lack of forward secrecy (compromising your private key will let someone go back and read your old messages). The PGP sections still need another editing pass to unify the content better across platforms, but a lot of those risks do get mentioned somewhere. If you can think of other analogous sections we should write about risks that are hard to mitigate, I'm glad to write them! And if you can find things in the existing document that you feel give people a false sense of security, please let us know and we can try to fix them. I realize that there's a pretty serious risk that any security guide will make people feel like they "did the right thing" and are communicating safely, then still get compromised. We are always struggling with the pull of "privacy nihilism" that would lead people to simply use plaintext communications over the Internet and GSM network because there are (for example) vulnerabilities in their OS or baseband, or because most encryption tools don't protect metadata. It's challenging to know what to say about risk when surveillance is a multi-billion-dollar industry and a lot of very smart people have made an entire career out of it. One point of view is that a lot of the mitigations really need to come from the platform developers, so desktop and mobile OSes need to ship with more crypto out of the box, turned on by default, in the default communication tools, etc., and hire a lot more vulnerability researchers. If you favor that point of view, I definitely encourage you to try to push things along from that direction too! |
http://infobot.rikers.org/%23neo900/20140904.html.gz http://infobot.rikers.org/%23neo900/20140910.html.gz