COMSEC: Get Security
COMSEC (communication security) is the securing of private communications against spying and sabotage. Because virtually everything activists do is communications, COMSEC is vital to the safety of activists.
Doers Need COMSEC
"EPA scientist Dr. David Lewis blew the whistle on abuse of power and disregard for sound science at EPA. After alleging that Dr. Lewis transgressed ethics rules and committed criminal violations of the Hatch Act, EPA cleared his name, apologized and paid him $115,000 in legal fees and damages. The Labor Department determined that EPA officials violated whistle blower provisions of six environmental statutes while trying to keep Dr. Lewis quiet. See NWI's report, The People v. Carol Browner: EPA on Trial, for more information."
—NMI
If the EPA would do this to a scientist, imagine what other powerful agencies will do to activists. Whistle Blowers have "some" protection under the law. In reality it is you that has to protect yourself. Dangerous Activism: Oppression, Government & OtherwiseEmpowerment is easiest for Americans doing safe, public, legal activism. Americans have constitutionally protected freedom of expression, so in theory they should be able to go about their business peaceably without fearing illegal government intrusion. However, citizens of oppressive regimes have a whole range of problems to deal with when confronting government opposition. Governments routinely skirt, ignore or legislate around legal limitations on their powers to spy and oppress. Non-governmental corporate and criminal groups may also use a variety of oppressive tactics, sometimes with government Legal AssessmentsNumerous groups track the human rights records of the many national and regional governments. Dangerous Countries
Be Just Paranoid EnoughOppression’s psychologically deterring ability to inspire fear usually far outstrips the actual physical ability to attack. If you are too paranoid, you will waste your efforts worrying about imaginary boogeymen. On the other hand, if you underestimate the risk of oppression & SpyingBeing followed, mail being opened, infiltrators Intelligence Agencies For Or Against Activists French Secret Service bombed Greenpeace’s ship and murdered crew. Companies have hired private investigators to harass activists. Eg. Ralph Nader & GM Espionage and government secrecy are part of activism for many reasons and issues. France Bombed Greenpeace Rainbow Warrior Ship Disinfo: Poisoning the wellSometimes false information is deliberately released or propagated to sow confusion or divert investigations into chasing red herrings. moon landings and pentagon missiles Information TheftEncryption is one way to help protect your privacy online, and also helps in communication between activists in the event that some is watching who does not have the best interests at heart. There have been cases with [Indymedia] where nazi's have hacked and read private emails between members of a collective. They managed to gather personal information from these emails, including home phone numbers. Encrypting online communications is one way to help prevent this from happening amoung activists. Identity Theft:GPG also allows for the signing, rather then encrypting of emails. This prevents others from pretending to be other member in a network. By creating a sig on an email, the author can be compared to the known nickname, thereby protecting the real identity of the author, and by insuring the messages are real. SEE ALSO: Identity_Theft Authentication
Insecurity
"Security is mostly a superstition. It does not exist in nature.... Life is either a daring adventure or nothing."
—Helen Keller
Security is never perfect. It is more a matter of risk management and minimizing insecurity. Secure SoftwareIt is important to use the most secure browser available, Firefox. Trusted ComputersA new computer is a new risk. All the steps used to secure your home computer come into question: Whose computer is it and can it be trusted?
Log & Cache Purging
LXPK: /Utilities/Keychain Access How Vulnerabilities WorkSomeone discovers a vulnerability. Sometimes they disclose it publically, sometimes they disclose it to the software developers quietly, sometimes they keep it to themselves to use in an attack. “Zero hour” is the time between when an exploit becomes available and when fixes are released. Servers are not yet patched for immunity to the vulnerability. Chaos may ensue. Someone develops an exploit for the vulnerability. Someone uses the exploit or releases a virus that Offshore HostingIn some cases it is advantageous to host your Internet servers in a foreign country where greater anonymity and freedom from censorship is available. For example, Sweden offers protection from American copyright law that shelters Pirate Bay because its operators are Swedish. You may not be protected from the law though if you live in the US. Death Threatshttp://www.nowpublic.com/node/128377
|
Basic COMSEC SkillsTo certify your Basic COMSEC integrity, a checklist of measures must be tracked to audit your security and gaps. Ideally an Advanced COMSEC specialist should help you implement your Basic COMSEC Checklist and train you in how to follow these simple "be calm" BCOM measures. If you have mastered the COMSEC checklist, you can take the COMSEC test to become Basic COMSEC Qualified. Advanced COMSEC Skills
Physical SecurityComputer systems are subject to physical attack.
Server Security
"Officials with U.S. Sen. Joe Lieberman's re-election campaign say that "dirty politics" and "Rovian tactics" are to blame for what they call an online attack on their campaign Web site as Connecticut voters headed to the polls Tuesday... The Web site, http://www.joe2006.com, has been unavailable since Monday afternoon, and Lieberman campaign manager Sean Smith suggested that the campaign of senator's primary opponent, Ned Lamont, or his supporters were responsible for the disruption."
Servers are high priority security assets at great risk of attack.
TrustKiosks = bad. "Most Spyware were nice enough to let me know they were there, in the form of advertisement for Spyware removals, while others just sat there an awaited who knows what… probably usernames and passwords for Hotmail/Gmail/etc accounts." Attacks
|





