People need to understand that Eepsites exist and that proper encryption of disks and messages will go a long way. It’s no longer enough to use Signal and sticks with TailsOS. The latter is like thinking you’re eating healthily by sprinkling seaweed extract on your french fries if considerable volumes of communication are handled through Instagram DMs and GMail.

They’ll try to eliminate the brains of the movements and they’re doing that at the level of digital tech first. Consider what happened to Autistici in Italy. There are methods of dodging such attacks, but they need to be implemented ahead of time.

    • distal@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      14 hours ago

      I didn’t say anything is wrong with Tails. Reread my post, it’s about not doing enough to prevent surveillance.

      • calidris [he/him, comrade/them]@hexbear.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        11 hours ago

        It’s no longer enough to use Signal and sticks with TailsOS.

        I interpreted this as needing to move on from both signal and tails. Signal I agree with, beyond standard not sensitive communication. TailsOS is still secure as far as I’m aware.

        • distal@lemmy.mlOP
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          11 hours ago

          Signal appears to quite secure in terms of access to the concrete content of messages. The biggest problems I am able to identify seem to revolve around how metadata is handled, the need for a phone number, and Signal’s jurisdiction.

          There are chat clients I won’t mention here for strategic reasons that manage to handle or sidestep these three problems rather well. These however are more obscure and you might not be able to convince everyone you’re talking to to switch, though of course you should still try to inform people of better alternatives.

    • distal@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      16 hours ago

      I don’t know of any, that is why I wrote the post.

      I find it’s more of a question what not to do. Basically avoiding bad practices.

      Consider touching upon the following though:

      • QubesOS and full disk encryption on Linux if people are not ready to use Qubes
      • GrapheneOS
      • Basic anonymisation of photographs using GIMP and EXIF-Tool
      • PGP encryption
      • TOR and I2P, I2P is probably more secure
      • Alternative potocolls such as Meshtastic
      • Basic concepts like Locard’s principle and attack surface
      • Tiering of security
      • Why Instagram, Reddit and so on are beasts from hell (can still be used for promo and agitation but don’t shit where you eat, use seperate devices cf. previous point)
      • The eternal importance of degoogilng
      • Every relevant commercial OS being nothing less than spyware

      https://media.ccc.de/ is a good resource