Citizens Privacy Coalition
of Santa Clara County
If you want to follow along with slides
Curriculum largely taken from ssd.eff.org
Roughly 80% of surveillance can be avoided by taking 20% of precautions.
(This statistic is for illustration purposes, not exact)
A tool that produces randomly generated passwords and stores thems securely, allowing you to have a different password for each login. This makes your life easier and more secure simultaneously.
Using the same password for every login is a bad idea. Sites get hacked and passwords get leaked. If you’re using the same password on Instagram that you use for your email and banking, those logins are also compromised.
It’s impossible to remember a different password for the hundreds of logins you have. A password remembers them for you.
Requires you to enter a randomly generated PIN after successfully entering your password. PIN changes every 30 seconds.
Free: Duo Security, Google Authenticator, Authy, tons more options
Last resort: Text message
Won’t protect from physical attacks or more sophisticated attackers.
The process of converting messages in ordinary language, or other information into a secret coded form that cannot be interpreted without knowing the secret method for interpretation, called the key.
It will not protect you from data you submit to a website or reveal to a third party
The easiest option.
Swiss email provider that encrypts your inbox so they can’t even read it.
All emails sent between Protonmail addresses cannot be accessed by anyone other than who they are intended for.
Metadata not encrypted:
Source, destination, time, subject
An email sent from Protonmail to any non-Protonmail address will be viewable by the other email provider (i.e., Gmail, Yahoo, etc.)
“Pretty Good Privacy” or PGP is an encryption algorithm developed explicitly for email. It has a steep learning curve with dozens of ways to implement it.
The easiest way to use it for Gmail is to install the browser plugin FlowCrypt.
flowcrypt.com
No encryption and easily intercepted.
Santa Clara County Sheriff’s Department submitted a proposal to buy a stingray, a device to intercept phone calls and text messages.
By far, the absolute best option, hands down.
E2E that Signal’s servers can’t even read your messages or your metadata.
They don’t know who your messaging or when. If they don’t know, they can’t give that information to law enforcement.
Better than nothing, but not ideal.
Encrypts the content using the same algorithm as Signal, but Facebook actively analyzes metadata.
Pretty solid, but just acquired by Zoom, which has censored activists in the past.
I do not recommend this app at all. Their encryption has been proven to be less than ideal.
Your location is being tracked in several different ways.
Your cellular service provider can triangulate your general location based on what tower your phone is using at any given time.
When you share your location with an app on your phone, they know where you are. Choose carefully.
Next workshop February 25 @ 6 pm
@cpcscc_ @cpcscc @cpcscc