Steps to improve digital security if you use protonmail

"[3ndarchy]" <[email protected]> Wed, 21 Oct 2020 15:45:05 -0500
Newsgroups alt.anarchism.syndicalist,alt.activism.underground,alt.anarchism,alt.anarchism.communist,alt.politics.socialism,alt.politics.socialism.libertarian
Organization A noiseless patient Spider
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--ojzBnPa0AYRs1a11dWCu4IW35rlPIH3nl
Content-Type: multipart/mixed; boundary="2cEd72sB1L4XuuxvhCZOTHsgQPfwRX9Je";
 protected-headers="v1"
From: "[3ndarchy]" <[email protected]>
Reply-To: [email protected]
Newsgroups: alt.anarchism.syndicalist,alt.activism.underground,alt.anarchism,alt.anarchism.communist,alt.politics.socialism,alt.politics.socialism.libertarian
Subject: Steps to improve digital security if you use protonmail

--2cEd72sB1L4XuuxvhCZOTHsgQPfwRX9Je
Content-Type: multipart/mixed;
 boundary="------------7FB9ED7CA982100DD45F5B8D"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------7FB9ED7CA982100DD45F5B8D
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Greetings Comrades,

I am posting this that I sent to some local comrades directly, which may
also be of interest to you.

This document will contain steps you should take to improve your digital
privacy.

STEP ONE :: IMPROVE YOUR PROTONMAIL LOGIN SECURITY
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D
I'm not going to write out all of the steps here as Protonmail has them
well documented. The things that you need to do are as follows:

1) Configure your account to use Two-Step Authentication (they call it
two-factor authentication, but TOTP is not a factor, but a step).
https://protonmail.com/support/knowledge-base/two-factor-authentication/
2) Configure your account to use Two-Password mode
https://protonmail.com/support/knowledge-base/switch-two-password-mode/

Make sure you are using a very long password generated and managed
though a password manager, such as KeePass, Bitwarden, or LastPass.


STEP TWO :: UPDATE YOUR PROTONMAIL CERTIFICATES
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D

When your protonmail accounts were created, they generated nominally
secure 2048 Bit RSA Encryption Keys. These are WOEFULLY inadequate for
security. Switching to higher-bit level RSA isn't much of an improvement,=

see various articles you can find on why you should stop using RSA.

Good news is, Protonmail supports ECC. ECC, or eliptical curve
encrytion, uses a lighter weight key that provides stronger security.
Combine with good password stength, these keys are nearly impossible to
break by state
level actors.

To do this in Protonmail, go to Settings > Keys

1) Click Generate New Key
2) Choose your email address (you will need to repeat this for each
email address on your account), and choose "State of the Art". Follow
the prompts.
3) Once your new key is generated, you will see it in the list. Next to
the EXPORT button is a carrot. Click the carrot, and mark your new ECC
key as Primary.
4) The carrot is now on your old RSA Key. Click this new carrot and
choose MARK AS OBSOLETE. This keeps your key usable for backwards
compatibility, but is considered obsolete.

There, you are done. You have taken huge steps toward improving your
security via hardening your encryption.

STEP THREE :: MOVE AWAY FRON PROTONMAIL AND SIGNAL
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D
Protonmail and other similar types of 'easy encryption' services are
great for beginners to communicate with people they already know.
However, as Socialists, we need to start moving beyond this.

How? I will explain as much as I can, but I will also task you with
doing a little bit of research yourself. I don't know all of your
individual hardware situations so I can't give exact instructions.

Keep in mind services like Email, Signal, etc. generate HUGE amounts of
metadata. Tha metadata can unravel network of socialists fast. They
don't even need to know what you're talking about, only that you're talki=
ng
with so-and-so. Makes it really dangerous when we can't 100% rely on our
comrades to practice good security hygiene or be able to withstand a $5
pipe wrench from Home Depot when someone wants to get their passwords.

So, we're going to work on reducing metadata.

STEP THREE A :: GET GPG ON YOUR DEVICE
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D
A good idea is to start using one computer (yes, I said computer, not a
mobile or tablet) for your secure thigns. Ideally you should use tails
or whonix, second after that being Linux... if you can stop using
MacOS or Windows OS do so. If you can't, you have to take steps to
secure your data. Download VERACRYPT to create secure storage containers
for your data and learn how to use it.

Now, as the heading said, you need GPG on your device. Mac and Linux
already have GPG, but you'll want some tools to go with it.
- - MAC: GPGtools.org
- - Linux: assuming debian/ubuntu: sudo apt update && sudo apt install
kleopatra gnupg
- - Windows: GPG4WIN

You'll need to make sure you can generate ECC (ec/ev) keys using your
installation. Generate a NEW keypair: you don't need to worry about an
email address (although if you want to you can make one for your
personal email accounts).

You'll need to make additional keypairs later, so make sure you know how
to do this. VERY IMPORTANT: Make sure you can create revocation keys for
your keys, store them in a safe place. You need to be able to mark a key
as revoked!

Like I said, you will have to do a little reseach/DDGing/Playing Around
here. Get comfortable with encryption software. Look around. poke around.=


STEP THREE B :: GET ON THE OLD-FASHIONED NEWSGROUPS
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D
To to eternal-september.org and sign up for an account. Next, using
Thunderbird (also be sure to install the enigmail addon), and add the
eternal-september news server to Thunderbird.

You can subscribe to any newsgroups you want. I highly recommend the
socialist, anarchist, syndicalist, ones, as well as all the ones in
mn.*, and actually post/participate.
One you do want to get is alt.anonymous.messages > this is essentially a
huge shared inbox! Anyone on the internet can register at a Nym server
and receive encrypted emails anonymously thorugh a Nym. They never
actually go to you, so plausible deniability
and the senders information is stripped, so again, plausible
deniability, and finally, assuming everyone is pre-encrypting messages
in advance, the messages are totally encrypted!

STEP THREE C :: NYM SERVERS
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D

Now, to be able to receive messages, you need to be able to send messages=
=2E

To do this, you have to register with a nym sever (such as mixnym.net,
https://thinhose.net/, and others). To do this, you'll need YAMN:
https://www.sec3.net/yamnhelp/index.html
https://www.mixmin.net/yamn.html
Sorry mac guys, you'll have to do some DDG searches for a Mac-compatible
NYM Remailer.

Once you are set up with a nym, and you can receive messages at your
nym, you can now send out through YAMN and receive back through your NYM
server. Cool thing is that the senders info in both directions is
stripped and the messages are relayed through multiple remailers before
delivery.

This is all very technical and requires you to be comfortable with
OpenGPG to really get the handle of, but if you can muster it, it's very
worthwhile.

I hope this helps. I know you're probably either trying to figure out
who I am (or have). You can reply to this message via the email address
[email protected]
Please use the ECC key below to Encrypt the messages (You'll have to add
the key manually to Protonmail via the Address Book. Check support docs
if you don't know how to do this).


Questions? Let me know.

Take care, comrades.

In Solidarity

[3ndarchy]
- -----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEX5BL2hYJKwYBBAHaRw8BAQdAFIae+C5LfU1VfkNCkOGpMphHfl4pzb7l/Y1u
eOJFrLe0G0VuZGFyY2h5IFByaXZhdG1haWwgUkVMQVlFRIiQBBMWCAA4FiEEGxNf
gkVaK2UxdNrkSEEwjdXYeH4FAl+QS9oCGwMFCwkIBwIGFQoJCAsCBBYCAwECHgEC
F4AACgkQSEEwjdXYeH7EYQD8DtgOvAszEgsmezjwhV9gzb56bAvLDhMukTaAdt43
LxIBAM4F7WCcCGdkMqiPPzhtd6hpY/9vljXVzevpSv0QJ6cAuDgEX5BL2hIKKwYB
BAGXVQEFAQEHQH6D2MGWUuwHb/aWUootarhN7cNq5HNcZZmOOGonP59SAwEIB4h4
BBgWCAAgFiEEGxNfgkVaK2UxdNrkSEEwjdXYeH4FAl+QS9oCGwwACgkQSEEwjdXY
eH7KtQD+Jgq0wIg8ddDRtp5BLGyhcwgHu+Pt+/tsG9p+hECbdygBAKFvlPRI4yTF
lWzsdiONF3l70v9WPGlJuIqoREATrXID
=3DkSoQ
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----

iHUEARYIAB0WIQQbE1+CRVorZTF02uRIQTCN1dh4fgUCX5CdOwAKCRBIQTCN1dh4
fngGAQDNZKinA973RZBujhRGguLbq090ava3lSerpRBBn7tHtAEA8L8tC1Zrp8ec
rSjE3fw3irIhXmNKDMJaWvefrSqfvwI=3D
=3D1ykm
-----END PGP SIGNATURE-----

--------------7FB9ED7CA982100DD45F5B8D
Content-Type: application/pgp-keys;
 name="0xD790825620FF8FCF.asc"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: attachment;
 filename="0xD790825620FF8FCF.asc"

-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEX1+myhYJKwYBBAHaRw8BAQdAfSdFUNohoE+A+6olup1uNfYjuj0IE7bjVy7Z
m6fsKI60MWVuZGFyY2h5QHNpbGVudGRhcmsubmV0IDxlbmRhcmNoeUBzaWxlbnRk
YXJrLm5ldD6IjwQQFgoAIAUCX1+mygYLCQcIAwIEFQgKAgQWAgEAAhkBAhsDAh4B
ACEJENeQglYg/4/PFiEEd17IBHY9MGHBzGJn15CCViD/j89OvQEA3EQdNfWsXZUi
0QAAVKDl/oWqDbk7cAa74LsVe+Gi3R0A/jqCAJmZADkqjUGNjrGDZJlP4gQfZENv
seFhenh/bMgHuDgEX1+myhIKKwYBBAGXVQEFAQEHQPUlHr85u14lHFz01JRxPHHw
+2gxUKAX82A4A6uuePgtAwEIB4h4BBgWCAAJBQJfX6bKAhsMACEJENeQglYg/4/P
FiEEd17IBHY9MGHBzGJn15CCViD/j88iuQEAijhitCpalBBX8PRFEsoWj36oxkDG
62h8tjupGkKk/F4A/29JiW2hrNSZiEHt17+oTPfhMemlG2mCTsAVwwQrN/QG
=3DxQIV
-----END PGP PUBLIC KEY BLOCK-----

--------------7FB9ED7CA982100DD45F5B8D--

--2cEd72sB1L4XuuxvhCZOTHsgQPfwRX9Je--

--ojzBnPa0AYRs1a11dWCu4IW35rlPIH3nl
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iHUEARYIAB0WIQR3XsgEdj0wYcHMYmfXkIJWIP+PzwUCX5Cd0QAKCRDXkIJWIP+P
z4crAQC20rMfOCMHg+S94lOjS1nN2huR+B0IrzCCWsLPSY1AeAEAjA+oWPwzExsp
6ZXhv6+2pM0M2uQL7YXFM9C+hSNXPwg=
=YcSa
-----END PGP SIGNATURE-----

--ojzBnPa0AYRs1a11dWCu4IW35rlPIH3nl--