Steps to improve digital security if you use protonmail
"[3ndarchy]" <[email protected]> Wed, 21 Oct 2020 15:45:05 -0500
| Newsgroups | alt.anarchism.syndicalist,alt.activism.underground,alt.anarchism,alt.anarchism.communist,alt.politics.socialism,alt.politics.socialism.libertarian |
|---|---|
| Organization | A noiseless patient Spider |
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --ojzBnPa0AYRs1a11dWCu4IW35rlPIH3nl Content-Type: multipart/mixed; boundary="2cEd72sB1L4XuuxvhCZOTHsgQPfwRX9Je"; protected-headers="v1" From: "[3ndarchy]" <[email protected]> Reply-To: [email protected] Newsgroups: alt.anarchism.syndicalist,alt.activism.underground,alt.anarchism,alt.anarchism.communist,alt.politics.socialism,alt.politics.socialism.libertarian Subject: Steps to improve digital security if you use protonmail --2cEd72sB1L4XuuxvhCZOTHsgQPfwRX9Je Content-Type: multipart/mixed; boundary="------------7FB9ED7CA982100DD45F5B8D" Content-Language: en-US This is a multi-part message in MIME format. --------------7FB9ED7CA982100DD45F5B8D Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Greetings Comrades, I am posting this that I sent to some local comrades directly, which may also be of interest to you. This document will contain steps you should take to improve your digital privacy. STEP ONE :: IMPROVE YOUR PROTONMAIL LOGIN SECURITY =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D I'm not going to write out all of the steps here as Protonmail has them well documented. The things that you need to do are as follows: 1) Configure your account to use Two-Step Authentication (they call it two-factor authentication, but TOTP is not a factor, but a step). https://protonmail.com/support/knowledge-base/two-factor-authentication/ 2) Configure your account to use Two-Password mode https://protonmail.com/support/knowledge-base/switch-two-password-mode/ Make sure you are using a very long password generated and managed though a password manager, such as KeePass, Bitwarden, or LastPass. STEP TWO :: UPDATE YOUR PROTONMAIL CERTIFICATES =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D When your protonmail accounts were created, they generated nominally secure 2048 Bit RSA Encryption Keys. These are WOEFULLY inadequate for security. Switching to higher-bit level RSA isn't much of an improvement,= see various articles you can find on why you should stop using RSA. Good news is, Protonmail supports ECC. ECC, or eliptical curve encrytion, uses a lighter weight key that provides stronger security. Combine with good password stength, these keys are nearly impossible to break by state level actors. To do this in Protonmail, go to Settings > Keys 1) Click Generate New Key 2) Choose your email address (you will need to repeat this for each email address on your account), and choose "State of the Art". Follow the prompts. 3) Once your new key is generated, you will see it in the list. Next to the EXPORT button is a carrot. Click the carrot, and mark your new ECC key as Primary. 4) The carrot is now on your old RSA Key. Click this new carrot and choose MARK AS OBSOLETE. This keeps your key usable for backwards compatibility, but is considered obsolete. There, you are done. You have taken huge steps toward improving your security via hardening your encryption. STEP THREE :: MOVE AWAY FRON PROTONMAIL AND SIGNAL =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D Protonmail and other similar types of 'easy encryption' services are great for beginners to communicate with people they already know. However, as Socialists, we need to start moving beyond this. How? I will explain as much as I can, but I will also task you with doing a little bit of research yourself. I don't know all of your individual hardware situations so I can't give exact instructions. Keep in mind services like Email, Signal, etc. generate HUGE amounts of metadata. Tha metadata can unravel network of socialists fast. They don't even need to know what you're talking about, only that you're talki= ng with so-and-so. Makes it really dangerous when we can't 100% rely on our comrades to practice good security hygiene or be able to withstand a $5 pipe wrench from Home Depot when someone wants to get their passwords. So, we're going to work on reducing metadata. STEP THREE A :: GET GPG ON YOUR DEVICE =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D A good idea is to start using one computer (yes, I said computer, not a mobile or tablet) for your secure thigns. Ideally you should use tails or whonix, second after that being Linux... if you can stop using MacOS or Windows OS do so. If you can't, you have to take steps to secure your data. Download VERACRYPT to create secure storage containers for your data and learn how to use it. Now, as the heading said, you need GPG on your device. Mac and Linux already have GPG, but you'll want some tools to go with it. - - MAC: GPGtools.org - - Linux: assuming debian/ubuntu: sudo apt update && sudo apt install kleopatra gnupg - - Windows: GPG4WIN You'll need to make sure you can generate ECC (ec/ev) keys using your installation. Generate a NEW keypair: you don't need to worry about an email address (although if you want to you can make one for your personal email accounts). You'll need to make additional keypairs later, so make sure you know how to do this. VERY IMPORTANT: Make sure you can create revocation keys for your keys, store them in a safe place. You need to be able to mark a key as revoked! Like I said, you will have to do a little reseach/DDGing/Playing Around here. Get comfortable with encryption software. Look around. poke around.= STEP THREE B :: GET ON THE OLD-FASHIONED NEWSGROUPS =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D To to eternal-september.org and sign up for an account. Next, using Thunderbird (also be sure to install the enigmail addon), and add the eternal-september news server to Thunderbird. You can subscribe to any newsgroups you want. I highly recommend the socialist, anarchist, syndicalist, ones, as well as all the ones in mn.*, and actually post/participate. One you do want to get is alt.anonymous.messages > this is essentially a huge shared inbox! Anyone on the internet can register at a Nym server and receive encrypted emails anonymously thorugh a Nym. They never actually go to you, so plausible deniability and the senders information is stripped, so again, plausible deniability, and finally, assuming everyone is pre-encrypting messages in advance, the messages are totally encrypted! STEP THREE C :: NYM SERVERS =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D Now, to be able to receive messages, you need to be able to send messages= =2E To do this, you have to register with a nym sever (such as mixnym.net, https://thinhose.net/, and others). To do this, you'll need YAMN: https://www.sec3.net/yamnhelp/index.html https://www.mixmin.net/yamn.html Sorry mac guys, you'll have to do some DDG searches for a Mac-compatible NYM Remailer. Once you are set up with a nym, and you can receive messages at your nym, you can now send out through YAMN and receive back through your NYM server. Cool thing is that the senders info in both directions is stripped and the messages are relayed through multiple remailers before delivery. This is all very technical and requires you to be comfortable with OpenGPG to really get the handle of, but if you can muster it, it's very worthwhile. I hope this helps. I know you're probably either trying to figure out who I am (or have). You can reply to this message via the email address [email protected] Please use the ECC key below to Encrypt the messages (You'll have to add the key manually to Protonmail via the Address Book. Check support docs if you don't know how to do this). Questions? Let me know. Take care, comrades. In Solidarity [3ndarchy] - -----BEGIN PGP PUBLIC KEY BLOCK----- mDMEX5BL2hYJKwYBBAHaRw8BAQdAFIae+C5LfU1VfkNCkOGpMphHfl4pzb7l/Y1u eOJFrLe0G0VuZGFyY2h5IFByaXZhdG1haWwgUkVMQVlFRIiQBBMWCAA4FiEEGxNf gkVaK2UxdNrkSEEwjdXYeH4FAl+QS9oCGwMFCwkIBwIGFQoJCAsCBBYCAwECHgEC F4AACgkQSEEwjdXYeH7EYQD8DtgOvAszEgsmezjwhV9gzb56bAvLDhMukTaAdt43 LxIBAM4F7WCcCGdkMqiPPzhtd6hpY/9vljXVzevpSv0QJ6cAuDgEX5BL2hIKKwYB BAGXVQEFAQEHQH6D2MGWUuwHb/aWUootarhN7cNq5HNcZZmOOGonP59SAwEIB4h4 BBgWCAAgFiEEGxNfgkVaK2UxdNrkSEEwjdXYeH4FAl+QS9oCGwwACgkQSEEwjdXY eH7KtQD+Jgq0wIg8ddDRtp5BLGyhcwgHu+Pt+/tsG9p+hECbdygBAKFvlPRI4yTF lWzsdiONF3l70v9WPGlJuIqoREATrXID =3DkSoQ - -----END PGP PUBLIC KEY BLOCK----- -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQQbE1+CRVorZTF02uRIQTCN1dh4fgUCX5CdOwAKCRBIQTCN1dh4 fngGAQDNZKinA973RZBujhRGguLbq090ava3lSerpRBBn7tHtAEA8L8tC1Zrp8ec rSjE3fw3irIhXmNKDMJaWvefrSqfvwI=3D =3D1ykm -----END PGP SIGNATURE----- --------------7FB9ED7CA982100DD45F5B8D Content-Type: application/pgp-keys; name="0xD790825620FF8FCF.asc" Content-Transfer-Encoding: quoted-printable Content-Disposition: attachment; filename="0xD790825620FF8FCF.asc" -----BEGIN PGP PUBLIC KEY BLOCK----- mDMEX1+myhYJKwYBBAHaRw8BAQdAfSdFUNohoE+A+6olup1uNfYjuj0IE7bjVy7Z m6fsKI60MWVuZGFyY2h5QHNpbGVudGRhcmsubmV0IDxlbmRhcmNoeUBzaWxlbnRk YXJrLm5ldD6IjwQQFgoAIAUCX1+mygYLCQcIAwIEFQgKAgQWAgEAAhkBAhsDAh4B ACEJENeQglYg/4/PFiEEd17IBHY9MGHBzGJn15CCViD/j89OvQEA3EQdNfWsXZUi 0QAAVKDl/oWqDbk7cAa74LsVe+Gi3R0A/jqCAJmZADkqjUGNjrGDZJlP4gQfZENv seFhenh/bMgHuDgEX1+myhIKKwYBBAGXVQEFAQEHQPUlHr85u14lHFz01JRxPHHw +2gxUKAX82A4A6uuePgtAwEIB4h4BBgWCAAJBQJfX6bKAhsMACEJENeQglYg/4/P FiEEd17IBHY9MGHBzGJn15CCViD/j88iuQEAijhitCpalBBX8PRFEsoWj36oxkDG 62h8tjupGkKk/F4A/29JiW2hrNSZiEHt17+oTPfhMemlG2mCTsAVwwQrN/QG =3DxQIV -----END PGP PUBLIC KEY BLOCK----- --------------7FB9ED7CA982100DD45F5B8D-- --2cEd72sB1L4XuuxvhCZOTHsgQPfwRX9Je-- --ojzBnPa0AYRs1a11dWCu4IW35rlPIH3nl Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQR3XsgEdj0wYcHMYmfXkIJWIP+PzwUCX5Cd0QAKCRDXkIJWIP+P z4crAQC20rMfOCMHg+S94lOjS1nN2huR+B0IrzCCWsLPSY1AeAEAjA+oWPwzExsp 6ZXhv6+2pM0M2uQL7YXFM9C+hSNXPwg= =YcSa -----END PGP SIGNATURE----- --ojzBnPa0AYRs1a11dWCu4IW35rlPIH3nl--