Manageyourprivacy
Andsecurityonline
Metadata
Matters
For users and devs
« If you think technology can solve your security
problems, then you don’t understand the problems
and you don’t understand the technology »
(Bruce Schneier)
Whattoprotect?
●
What is your problem/threat ?
●
What do you want to protect ?
●
How can the opponent/threat reach you ?
●
What happens if you fail to protect ?
●
Rationalise risks
Humansecurity101
Humansecurity101
●
Use a password manager (KeepassX or LastPass)
Humansecurity101
●
Use a password manager (KeepassX or LastPass)
●
Think how and what you publish online
●
Deactivate geolocalisation & activate full-disk
encryption (just a button to toggle)
●
Use HTTPS everywhere (it’s also a plugin for your
browser)
●
Block ads and cookies ( Block Origin + Self-Destrucµ
cookies)
Humansecurity101
●
Use a password manager (KeepassX or LastPass)
●
Think how and what you publish online
●
Deactivate geolocalisation
●
Use HTTPS everywhere (it’s also a plugin for your
browser)
●
Block ads and cookies ( Block Origin + Self-Destrucµ
cookies)
●
Use open-source software (Firefox, VLC...)
security101(fordevs)
●
Encrypt everywhere, every time, the data you store and
handle (use Let’s encrypt to have HTTPS on your
website)
●
Minimize the data (a simple notepad app doesn’t need
my contacts permission)
●
Privacy by design: Data is not a resource, data is people.
You are responsible for your users’ privacy (careful with
CDN, 3rd-party dependencies, centralised platforms,
social trackers)
security101(fordevs)
●
Encrypt everywhere, every time, the data you store and
handle (use Let’s encrypt to have HTTPS on your
website for free) –> Privacy + GDPR
●
Minimize the data (a simple notepad app doesn’t need
contacts permission) –> Data Surface
●
Privacy by design: Data is not a resource, data is people.
You are responsible for your users’ privacy (careful with
CDN, 3rd-party dependencies, centralised platforms,
social trackers)
Encryptionmatters
●
For users :
– Secure chat : Signal
– Secure web browsing : Tor
●
For devs :
– Use tested and open protocols : Signal, GPG, OMEMO...
– Provide and use open-source and decentralised services
(aka don’t trust Google)
31/10/2017
Use
decentralised,
encryptedand
open-source
software.
Discussion&Sources
●
How your innocent smartphone passes on almost your entire life to the secret
service :
https://www.bof.nl/2014/07/30/how-your-innocent-smartphone-passes-on-almost-your-
entire-life-to-the-secret-service/
●
Everything is Broken – Quinn Norton :
https://medium.com/message/everything-is-broken-81e5f33a24e1
●
Me and my shadow : http://myshadow.org
●
Our dataselves : https://ourdataourselves.tacticaltech.org/
●
Databreaches Dataviz :
http://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches
-hacks/
●
We’re building a dystopia to make people click on ads – Zeynep Tufekci (TedGlobal)
●
Movies : Citizen Four, Nothing to Hide
Tutos101
●
Security Self Defense guide : https://ssd.eff.org
●
Password Managers for Beginners :
https://medium.com/@mshelton/password-managers-
for-beginners-d1f49866f80f
●
How to Lose Friends and Anger Journalists with
PGP :
https://medium.com/@mshelton/how-to-lose-friends
-and-anger-journalists-with-pgp-b5b6d078a315
●
Looking away from Google? https://framasoft.org/
Discussion&sources(advanced)
●
Bruce Schneier’s blog: https://www.schneier.com/
●
The Tor project: http://torproject.org/
●
The Anonymous Incognito Live System (tails):
https://tails.boum.org/
●
A DIY Guide to Feminist Cybersecurity:
https://hackblossom.org/cybersecurity/
●
Follow conferences : DEFCON, CCC, BlackHat, Fosdem...
Finally
●
Mass surveillance as a service & attention as a
product
●
What is the price to pay for security? What is the
price to pay for people to click on ads?
●
Alternatives exist
●
Nothing to hide?
Thanks <3
(don’t be too paranoïd, a little is
enough)

Manage your privacy and security online

  • 1.
  • 3.
  • 7.
    « If you thinktechnology can solve your security problems, then you don’t understand the problems and you don’t understand the technology » (Bruce Schneier)
  • 8.
    Whattoprotect? ● What is yourproblem/threat ? ● What do you want to protect ? ● How can the opponent/threat reach you ? ● What happens if you fail to protect ? ● Rationalise risks
  • 9.
  • 10.
    Humansecurity101 ● Use a passwordmanager (KeepassX or LastPass)
  • 12.
    Humansecurity101 ● Use a passwordmanager (KeepassX or LastPass) ● Think how and what you publish online ● Deactivate geolocalisation & activate full-disk encryption (just a button to toggle) ● Use HTTPS everywhere (it’s also a plugin for your browser) ● Block ads and cookies ( Block Origin + Self-Destrucµ cookies)
  • 14.
    Humansecurity101 ● Use a passwordmanager (KeepassX or LastPass) ● Think how and what you publish online ● Deactivate geolocalisation ● Use HTTPS everywhere (it’s also a plugin for your browser) ● Block ads and cookies ( Block Origin + Self-Destrucµ cookies) ● Use open-source software (Firefox, VLC...)
  • 15.
    security101(fordevs) ● Encrypt everywhere, everytime, the data you store and handle (use Let’s encrypt to have HTTPS on your website) ● Minimize the data (a simple notepad app doesn’t need my contacts permission) ● Privacy by design: Data is not a resource, data is people. You are responsible for your users’ privacy (careful with CDN, 3rd-party dependencies, centralised platforms, social trackers)
  • 19.
    security101(fordevs) ● Encrypt everywhere, everytime, the data you store and handle (use Let’s encrypt to have HTTPS on your website for free) –> Privacy + GDPR ● Minimize the data (a simple notepad app doesn’t need contacts permission) –> Data Surface ● Privacy by design: Data is not a resource, data is people. You are responsible for your users’ privacy (careful with CDN, 3rd-party dependencies, centralised platforms, social trackers)
  • 20.
    Encryptionmatters ● For users : – Securechat : Signal – Secure web browsing : Tor ● For devs : – Use tested and open protocols : Signal, GPG, OMEMO... – Provide and use open-source and decentralised services (aka don’t trust Google)
  • 21.
  • 22.
  • 23.
    Discussion&Sources ● How your innocentsmartphone passes on almost your entire life to the secret service : https://www.bof.nl/2014/07/30/how-your-innocent-smartphone-passes-on-almost-your- entire-life-to-the-secret-service/ ● Everything is Broken – Quinn Norton : https://medium.com/message/everything-is-broken-81e5f33a24e1 ● Me and my shadow : http://myshadow.org ● Our dataselves : https://ourdataourselves.tacticaltech.org/ ● Databreaches Dataviz : http://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches -hacks/ ● We’re building a dystopia to make people click on ads – Zeynep Tufekci (TedGlobal) ● Movies : Citizen Four, Nothing to Hide
  • 24.
    Tutos101 ● Security Self Defenseguide : https://ssd.eff.org ● Password Managers for Beginners : https://medium.com/@mshelton/password-managers- for-beginners-d1f49866f80f ● How to Lose Friends and Anger Journalists with PGP : https://medium.com/@mshelton/how-to-lose-friends -and-anger-journalists-with-pgp-b5b6d078a315 ● Looking away from Google? https://framasoft.org/
  • 25.
    Discussion&sources(advanced) ● Bruce Schneier’s blog:https://www.schneier.com/ ● The Tor project: http://torproject.org/ ● The Anonymous Incognito Live System (tails): https://tails.boum.org/ ● A DIY Guide to Feminist Cybersecurity: https://hackblossom.org/cybersecurity/ ● Follow conferences : DEFCON, CCC, BlackHat, Fosdem...
  • 26.
    Finally ● Mass surveillance asa service & attention as a product ● What is the price to pay for security? What is the price to pay for people to click on ads? ● Alternatives exist ● Nothing to hide?
  • 27.
    Thanks <3 (don’t betoo paranoïd, a little is enough)