HACKER Q&A
📣 botencat

My country is undergoing a coup, which encryption software should I use?


My country (Israel) is going through a coup d'état, which would result in a regime that can use surveillance without going through the courts.

Israel has one the most advanced surveillance capabilities, that has long been used to target other peoples and nations, but as far as is known, not its own people. This might now change.

I am trying to prepare in advance with encryption software, and optimally a way to communicate if traditional networks go down. Unfortunately other nations have gone through similar situations recently, so I'm wondering if there's a known guideline for these situations.


  👤 toast0 Accepted Answer ✓
A lot of this depends on your threat model and how much of a target you think you are.

If you are worried about your safety, it's better to leave than figure out workarounds. And it's likely easier to get out before things get bad; consider going on an international vacation --- if things look fine, enjoy your trip and go back; if not, figure out what comes next from there.

If you aren't really worried about your safety, but just want to avoid getting hassled about communications and don't want to lose communications with the outside world... Definitely do encrypted messenger stuff. But also, try to set up alternate communications. Even though they're not hard to block, many government shutdowns don't block fixed line internet service, land line telephones, or international voice calling. If you can setup a dial-up internet account with an ISP in another country, you may be able to use that from your landline even if internet via domestic ISPs is all shut down. Of course, if the regime is interested, your telephone company would have records of the calls (at least destination and length) and that might get you put on a list.

But also note, if most of your contacts are local, and local communications are disrupted; having access to international communications doesn't help you communicate with your contacts, unless they've done the same thing and the more people who have set it up, the more likely it is to be noticed.


👤 boeingUH60
Coup d'état - an illegal and overt attempt by the military or other government elites to unseat the incumbent leader.

How about not exaggerating first. I had to run to Google to see if Israel was actually having a coup, lol. A coup is not something I'll even wish on my worst enemy.


👤 farseer
State overreach and surveillance is a global trend. Don't mind me saying this: As a Jewish citizen with fair skin, a dual passport you would probably do fine, unless you are an Arab...

Even under the most tyrannical regimes such as Iran, Myanmar, Russia, China etc. The elite are rarely targeted by the state apparatus. If you are a majority ethnic group with family links in the military, bureaucracy, big business politics etc. You are mostly safe. If not, well encryption is not going to save you. Take your family and run.


👤 ecshafer
Is there an actual coup going on? I can't find any articles on this.

👤 gsatic
The thing is their tools are totally useless if traditional networks go down. And the prob with surveillance, in the age of the info tsunami, is not having enough people to go break down doors. There is no use if the dumb tool is flagging 20000 posts a minute and you have 1 poor jackass staring at the flood trying to work out who to pick on.

That's why however great their tools are they seem totally incapable of Controlling the protests.


👤 rabidonrails
Let's level set here a bit. There is no coup d'etat. Here's the definition of a coup: _a sudden, violent, and unlawful seizure of power from a government_ that is not what's happening here on either side.

Instead here's a quick review of what's happening. Currently the Israeli supreme court can strike down laws based on what they deem "reasonability." As you might guess, this is a pretty strong power for the court to hold because it's subjective. The new legislation would remove much of this power.

Those for this change argue that this is a good move because elected officials should be working for the people that they represent, not a court that gets to unilaterally make decisions.

The opposition argues that this power being handed to the elected officials without the oversight of the court's reasonability power and thus might allow bad actors to take additional control and do things that don't represent a substantial, but minority, population.

I'm not arguing for either side, but calling this a coup is wrong.


👤 sdfzguf
Technical subreddits often have up to date wiki entries.

- https://old.reddit.com/r/PrivacyGuides/

- https://old.reddit.com/r/privacy/

You can also look here:

- https://www.privacyguides.org/

All of this can only be seen as a starting point. The provided links will not give a thoroughly picture. Look further.


👤 nivertech
What you're mistakenly referring to as a "coup d'état" is actually an effort to prevent the use of Pegasus on innocent citizens by the judiciary, law enforcement, and the State Attorney General, who were appointed by previous governments.

There have been more than a thousand of unlawful Pegasus cases so far (tens or hundreds of thousands if you count text messages from other people on contact lists and WhatsApp group messages). It's possible that almost every smartphone user in Israel was affected in some way.

Some were even against the acting Prime Minister.

So, yes, you do need to protect your privacy, but for entirely diff. reasons. The only sure way to achieve this is by going off-the-grid.

--

Israel's Law Committee has approved a judge-led probe into the NSO Pegasus spyware.

https://www.jpost.com/israel-news/article-746164


👤 thrawa8387336
PGP but realistically just talk in person.

👤 cookiengineer
Use briar [1] for online+offline end-to-end encrypted messaging. Use LineageOS [2] without gapps (aka without Google Play Services) and get a device that is officially supported with current LineageOS version. Don't use any XDA developer builds, because they're known to be infected with malware.

Obviously don't use Meta or Google apps, because that's where the backdoors are for governments. Don't use WhatsApp, don't use Telegram, don't use Threema. They're compromised.

Use AppWarden [3] to enable/disable/verify the usage of known trackers in your apps.

Use NetGuard [4] as an Android firewall.

Use F-Droid [5] and Fennec builds [6], with uBlock Origin to protect your smartphone from malvertisements.

Never synchronize your contacts, block contacts access for all Apps; and make sure you don't use their real names. Contacts stored on or accessed by SIM cards (e.g. call history) can be downloaded via Class 0 SMS, remotely.

If possible, I'd avoid MediaTek based SoCs because their rootkit was leaked a couple years ago and it works still on newer chipsets. I would recommend an "as open source as possible" device, like the Google Pixel devices or the Fairphones.

On your Desktop or Laptop machines you should switch to a Linux distro of your choice. The most reasonable secure ones are Arch (not beginner friendly), Manjaro, OpenSUSE - or as a beginner friendly alternative - LinuxMint.

Would advise against Debian/Ubuntu though for security reasons (which would include LinuxMint).

The Arch maintainers (and therefore Manjaro, too) heavily reduced the attack surface of SUID binaries or LOL binaries that could be abused for privilege escalations and/or remote exploits/persistence etc. [7]

[1] https://briarproject.org/

[2] https://wiki.lineageos.org/devices

[3] https://gitlab.com/AuroraOSS/AppWarden

[4] https://netguard.me

[5] https://f-droid.org/

[6] https://f-droid.org/en/packages/org.mozilla.fennec_fdroid/

[7] https://gtfobins.github.io/

edit: clarification of LinuxMint


👤 grayhatter
Encryption is impossible* after the fact. The most important thing you could do today is read! Learn as much as you can. figure out the basics of both operational security, and bootstraping encryption. Then, and here's the important part, share everything you've learned as widely as you possibly can, write guides, write tutorials, make videos. All of information you need is available, but if the people you want to communicate with don't know it, or don't have access to it. It doesn't help either of you.

👤 throwawayadvsec
Israel will hack your devices, Mossad could come into your home when you're not there, encryption is kind of useless if you're actually targeted.

PGP and Luks could get you tortured.

Leave this hellhole or do nothing "incriminating".


👤 froster
Peer-to-peer Bluetooth messaging

https://usehyperlocal.com