Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Digital Security for Everyone

redshiftzero
November 11, 2015

Digital Security for Everyone

introductory digital security talk for broad audience

redshiftzero

November 11, 2015
Tweet

More Decks by redshiftzero

Other Decks in Technology

Transcript

  1. Digital Security for Everyone
    Jennifer Helsby
    @redshiftzero
    Chicago Hack Night
    November 10, 2015
    @CryptopartyChi

    View Slide

  2. But I have nothing
    to hide.

    View Slide

  3. But I have nothing
    to hide.
    Yes, you do.

    View Slide

  4. But I have nothing
    to hide.
    Yes, you do.
    Your medical information, your financial information, your
    political beliefs, your sexual identity, nudity, …

    View Slide

  5. View Slide

  6. View Slide

  7. View Slide

  8. View Slide

  9. People have been defending their
    own privacy for centuries with
    whispers, darkness, envelopes,
    closed doors, secret handshakes,
    and couriers.
    - Eric Hughes

    View Slide

  10. There is nothing illegal or
    subversive
    about using a tool to
    protect your privacy online.

    View Slide

  11. What is Cryptoparty?
    • A grassroots international movement to
    provide spaces for people of all types to get
    training in digital security
    • Non-commercial and free
    • Significant interest among activism, law,
    journalism, LGBT communities

    View Slide

  12. View Slide

  13. Threat Modeling
    • What information am I trying to protect?
    • Who am I trying to protect it from (my
    adversary)?
    • What is my adversary able and willing to do
    to find out?
    • What happens if I fail?

    View Slide

  14. • Goal is NOT: Perfect security
    • Goal is: Make surveillance significantly more
    difficult and costly
    • Win: Exert slightly more effort than your
    adversary is willing to commit

    View Slide



  15. HTTP

    View Slide


  16. https://www.eff.org/https-everywhere
    HTTPS

    View Slide


  17. End-to-End (e2e) Encryption
    • Off-the-Record (OTR) messaging: IM encryption
    • Clients: Pidgin/Adium
    • PGP “Pretty Good Privacy”: Email encryption
    • Clients: Enigmail, Mailvelope

    View Slide

  18. Signal Private Messenger
    • End-to-end
    encrypted calls and
    messages
    • Encrypted content,
    not metadata
    • Support on Android
    and Apple IOS
    • Free and open-
    source

    View Slide

  19. Anonymity
    • Anonymity means you can’t tell who did what
    • Tor anonymizes your identity from the
    destination website, your ISP, employer,
    government, etc.
    • Browse the web anonymously with the Tor
    Browser Bundle
    https://www.torproject.org

    View Slide

  20. View Slide

  21. Entry node or
    “guard” relay Middle relay
    Exit node
    Encrypted
    Unencrypted

    View Slide

  22. protect your privacy
    help teach
    support these tools and
    the orgs that make them
    HTTPS Everywhere Signal Tor

    View Slide

  23. protect your privacy
    help teach
    support these tools and
    the orgs that make them

    View Slide

  24. Thanks!
    Next Cryptoparty: 2pm Saturday December 5th, 2015 at South Side
    Hackerspace
    HTTPS Everywhere Signal Tor

    View Slide