Security Info for Newbies

@Jstew318   Cheers buddy, you are more than welcome. The whole point of this post is to try and help people

feel more safe and secure when being online. 

NOW Two more steps to make people safer again...

1-) TOR   -  TOR

2-) PGP  -  OpenPGP

Tor is pretty much self explanatory while PGP is a bit more technical and requires a higher level of computer understanding.

If there is a demand, i can go into PGP in more detail, but i would first ask that you do a DuckDuckGo search for info

because there are literally hundreds of guides out there and all i would ask is that you do some reading and then some more reading..

Best Regards,  T.

 
@Toker I’ve been using Sav¥S0da as my tor and duckduck. 

Do you know of any more user friendly alternatives to PGP? I understand it, but for those in the DBG fam that may not be as tech savvy but want to feel safe? 

 
@Jstew318  Hi there.

As you probably know PGP needs a Lot of reading and then some, for the non tech savvy..

There are some good videos out there and plenty of Guides but still a bit complicated for some.

I came across THIS tutorial and it's probably the most easy to understand for DBG members..

Hope it helps somewhat..

Regards..☮️

 
@Jstew318  Hi there.

As you probably know PGP needs a Lot of reading and then some, for the non tech savvy..

There are some good videos out there and plenty of Guides but still a bit complicated for some.

I came across THIS tutorial and it's probably the most easy to understand for DBG members..

Hope it helps somewhat..

Regards..☮️
@Toker my apologies for this extremely delayed response. I simply forgot. I wanted to post something in the other security section, I realized I never responded. 

Now my next tackle is to find a better VPN. I’m using Open, but I think that the ping packets are either being lost or blocked on the path because it never stays connected very long. Rather annoying lol

 
@Jstew318  No worries my friend. Life in general is busy this time of year!  Lol

I'm currently using AirVPN which utilises Open VPN but it's done automatically through there

'Eddie' client which is fairly user friendly and has been faultless for me since i started using it.

I honestly don't think you will be disappointed if you give it a go.

Hope this helps you somewhat.

Regards...☮️

 
@Jstew318  No worries my friend. Life in general is busy this time of year!  Lol

I'm currently using AirVPN which utilises Open VPN but it's done automatically through there

'Eddie' client which is fairly user friendly and has been faultless for me since i started using it.

I honestly don't think you will be disappointed if you give it a go.

Hope this helps you somewhat.

Regards...☮️
@Toker...thank you. I’m going to give that a try. I don’t have time to always check to make sure I’m connected lol. Much appreciated. Have a great day. 

 
Question - when vendors are using gmail, what difference does it make if users are using an encryption-based email service? All the feds have to do is request records from google and google will supply them with all vendors’ emails older than 180 days. Newer than 180 days requires a warrant (which wouldn’t be difficult). I guess what I’m saying is that all the security in the world won’t matter as long as vendors are using Gmail, and aren’t AT A MINIMUM changing their addresses every six months. @2earls Is this something we could suggest our vendors to do? Either use encrypted email, or have them trash their email addresses every so often?

Hi all, just thought i'd start a topic that may help out newbies along the road to securing there online activities.

1) Get yourself a safe and secure email provider. (Protonmail is MY preferred choice)

2) Get yourself a decent VPN. (Trust.Zone is MY preferred choice)

3) Use a decent up to date browser. (Firefox is MY preferred choice)

Now, some explanation. Protonmail is a Secure email provider that sends only encrypted mail which can not be read by any "Man in the Middle" attacks. I.E. When the mail leaves your device it's transferred in a mumbo jumbo of code until it reaches the recipient.

A decent VPN like Trust.Zone will protect all your online activities as it creates a secure encrypted connection to a server in a country of your choice.

A decent browser like Firefox lets you use a "Private Window" meaning no data like Browsing history, Cookies, Logins etc are kept on your device.

Don't use g@@gle to do your searching, use something like DuckDuckGo which has No tracking, no ad targeting and no Data collection policy's

There are many VPN's on the market, have a look here - Simple-VPN-Comparison-Chart

In my mind these are just three of the Starting steps that people should practice to keep there online activities safe and secure from prying eyes.

There is more that i could go into like using PGP and so forth, but for your average person the 3 points above will suffice.

Other members please feel free to add any additional information you feel may be of use to others.

Regards,  T

 
Last edited by a moderator:
@Toker it was downloaded from Mozilla and it worked fine for the first couple years, then we did one of our system upgrades and my Firefox didn't seem to like the improvements. 

I still would try it as a first choice for browsing and if members are having problems  (I have had a few who complained about the same problem ) then switching to a different browser should solve it.
@2earls Not sure if this will address your problem but are you running a script / ad blocker with Firefox by any chance?

I logged in the other day from a different device and the site was awfully slow due to the amount of JavaScript that runs

in the background.   I've not noticed this until now because i always use Firefox with uBlock and NoScript extensions running.

It could be the answer to your problems..

Regards,  T.

Question - when vendors are using gmail, what difference does it make if users are using an encryption-based email service? All the feds have to do is request records from google and google will supply them with all vendors’ emails older than 180 days. Newer than 180 days requires a warrant (which wouldn’t be difficult). I guess what I’m saying is that all the security in the world won’t matter as long as vendors are using Gmail, and aren’t AT A MINIMUM changing their addresses every six months. @2earls Is this something we could suggest our vendors to do? Either use encrypted email, or have them trash their email addresses every so often?
@tableforseven The short answer is No Difference whatsoever.  However you can send an encrypted mail from Proton to gMail but you

must use a password so the receiver can Decrypt that message on Proton's own server.

As for Vendors, there in this game long enough to know how to look after there own security. Rest assured they know the ropes.

Regards,  T.

 
i have airvpn too. for anyone new 2 the game, those list are BS..those companies are paying people to advertise them..You want a vpn that is located outside of the country, their privacy policy should state that they do not keep logs of everything and if they do, then it shouldnt be for more than a feew weeks if that. Also, never pay with credit card, always crypto. even then, the reality is the PEOPLE should all throw in money for their own ISP, like this small company in New York did...

 
@Toker I hope you’re doing well my friend. I have two questions for you:

1) In DuckDuckGo, I can set it to be iOS’ Safari search engine. Does that mean when iOS force opens Safari versus my tor, it’s routing through DuckDuckGo? And if so, is that adding a layer of protection? I never use Safari, I have it set to incognito and all the settings are locked down.

2) I recently setup oCloud and I’ve established my own server, but can’t seem to get them to speak to each other. Any suggestions?

I thank you kindly sir!

Jstew

 
Hello my friend @Jstew318 

Regarding the first part of your post, yes it should be utilizing the Duck as your
'Default' search engine. Is it adding a layer of protection?, only in the way that your
browser (Safari) is not opening you up to search & add tracking like g@@gle would do.
Have a read over this - LINK when you have a sec.

As for your second question, i'm afraid i can't answer that as i despise anything @pple related,
never work with them and heck won't even repair them for colleagues.
Maybe someone else with @pple experience may be able to help you with that one.
Sorry i couldn't be of more help..

Take care & stay safe,

Regards,  T.

 
@Toker thank you my man. I read through the link and the only thing I haven’t done is wiping the advertising  I’ll add them to my routine. Thanks man! 

I’m not too keen on fruit or g000gl1es myself. I don’t like to use them for anything if necessary. I would like my own type of server and cloud though. Any recommendations versus this 0hNOcloud?

Thanks again! 

Jstew

 
Last edited:
Hi @Jstew318  my friend,

It all depends on what purpose you require the server for.

Are you looking for shared hosting, dedicated hosting, cloud or vps hosting?

It really does boil down to what purpose you need a server for.

I'm not sure if i've got the right end of the stick, so to speak. 🙃

Maybe have a read thru THIS and see if it helps, but again i'm not sure

if i'm on the same page as your good self. My apologies if i've picked you up wrong..

Regards,  T.

 
@Toker...hey my man. My apologies I wasn’t more clear. I’m looking for a good option for storage vs that thing in the sky and the g0oG1€ dr1ve. 

I’ve developed a nice little system based on your rec’s. Very solid, thank you! And thank you for the great information, always, and keeping it all up-to-date for us. I’m always checking for your updates. 

Peace!

Jstew

 
OMG how will I ever navigate this new world and lingo!!!  You guys are very bright!!!

I feel like a broken bulb reading this.

 
@mountaincat9, lol...that’s why we have this awesome thread and our brilliant sir @Toker!

I’ve learned so much from Toker over the past year. I’m learning still! I’d be glad to help if I can but the brains are all with that guy lol

jstew

 
Last edited:
Will be receiving a refurbished dell xps w/win10 64 bit os next wk. Id like to set it up out of the box so it is secure & activity is anonymous. 

Is there a goo step by step forum / topic summary that advises a process?

It's refurb, so i suuppose i gotta ck 1st to see if something was left behind - .

what do friends know od windscribe as vpn. I have it, dont know much.

I am also confused: when i turn on laptp it connects to isp. so wen i turn on vpn, the isp knows?

But cannot access nor see any site search history. This about right?

Thanks.

 
Following on from a convo in the chat box..

Everyone here has / has use of a Smartphone these days.

Here's some info on how to Secure your online activities.

Install a Secure Safe & Trusted private messaging app like Signal  LINK

If your not using a VPN you should be if you value your privacy  VPN Comparison Chart  (Please be Patient it May take time to load!)

Most VPN providers also offer a Mobile version for Android & to a lesser extent IOS. 

If you have a VPN on your PC, then you should have one on your phone too. (Makes sense right?)

Wickr  -  LINK  is seen as some as the go to private messaging app, but it has proven problems *Ref Needed*

Signal  -  LINK  on the other hand is more secure and if it's good enough for Edward Snowden, it's good enough for me!

Stay Safe,  Regards  T.
I sure appreciate this info-I read this then right out and did some reading. I do have several of the ones you recommended. If I could figure out how to configure Lavabit,  would use it. (I read how they closed down their business, rather than hand over the encrypt  keys to LE for access to some 'suspicious' emails. They would have been able to read everyone's emails in the entire database (like Google does) if they had done that-gotta love someone who stands up for what they think is right. To the point of harm!  But for now, Tutanota is one I use. Duck Duck Go is my search w/Firefox. Then I use Telegram for wifi calls, texts, files and docs (for my work). Been using a VPN called Express VPN and I really like the support but I find myself having to turn it off just to connect-both on PC and iPhone. I need to go back and find a good vpn...Thank you for the great info @Toker

 
Returned the device. 

It wasnt exactly as described ...

One mistake i may have made was after setting protonmail up. I used it as my my new microsoft account. 

So, still seeking an out of the box, step by step process that covers all of the above in proper install sequence. 

I came across a reference to tails while processing info from this thread.

This program is loaded on a portable drive of choice - and,  litle if any activity can be accessed by third-party while using the programs from that drive. Is that about right? 

If so, the easy solution to privacy/security is having a tails, plus other apps on a portable device? Cortana's friend until betrayal in Drive __?

 
Drugbuyersguide Shoutbox
  1. S @ soupson: What happened to chem genie?
  2. D @ drdrizzy13: LSU is trash and has always been trash but a night game in death valley is unlike anything I've experienced. Except the first game back to the superdome reopened after Katrina destroyed it. Everybody was crying and drunk as shit lol. All time favorite in person sports moment ever.
  3. M @ meepmoopmeep: Kiffin is a traitor and he and LSU deserve each other since they’re both complete trash
  4. D @ drdrizzy13: yea he's a joke lol. Can't stand him.
  5. L @ Layne_Cobain: You know who rly sucks…lane kiffin 😂 dude is all that’s wrong with college sports or at least a big chunk of it…and he lied about being told he could still coach ole miss in the playoffs
  6. D @ drdrizzy13: Hey at least Ole Miss got in. I can't stand LSU. They really sucked this year.
  7. M @ meepmoopmeep: as an A&M fan I’m content with us missing the SECCG for that reason. Georgia about to fuck Alabama up
  8. D @ drdrizzy13: Yeah I agree if bama loses I think they are out. That would be 3 losses. I don't see a 3 loss team getting in this year.
  9. L @ Layne_Cobain: Yeah that’s why sark was pleading his case about that Texas shouldn’t be punished for scheduling a non conference game against the best team and losing if they hadn’t done that they’d probably be in but oh well way it goes there’s always gonna be a few teams who get robbed or feel they got robbed even with a 12 team playofff…if bama loses to Georgia I’d think they’d be out but who knows
  10. D @ drdrizzy13: Alabama also lost to Florida State pretty bad. Whom Florida beat. I just think if they didn't decide to play ohio state the first game. They would be in with 2 losses instead of Alabama.
  11. M @ meepmoopmeep: @drdrizzy13 Texas lost to Florida of all teams, they weren’t heading for the playoffs anyways imo. At least not this year
  12. D @ drdrizzy13: Texas is offically out of the playoffs they didn't make the top 12. I do wish they were in it. They showed up against Texas AM. But there fatal flaw was scheduling Ohio State for their opening. Which would have been great if they won but they are a 3 loss team now.
  13. L @ Layne_Cobain: Yeah idk about arch I could see him staying with Sark for another year but if he plays rly well in the playoff who knows that is if they get in
  14. D @ drdrizzy13: Man a lot of Saints fan want Arch but I think he said he is playing another year. I would take him probably. But if Texas AM QB comes out or Ohio State's I think you gotta take one if your picking top 2.
  15. L @ Layne_Cobain: Is the qb class supposed to be stacked or thin for draft in April I follow college ball but I can’t think right now I think there’s def at least a few high potential qb declaring
  16. D @ drdrizzy13: Right now I believe we pick 2nd. ATM.
  17. D @ drdrizzy13: At first I figured he might be able to do something but our position players suck. We are playing a rookie QB. O-line sucks. It needs to be blown up. I hope we tank for the first pick
  18. L @ Layne_Cobain: Hopefully you guys maybe find a solid qb option in the draft you should end up with a very good pick
  19. L @ Layne_Cobain: Yeah dude Moore def does not seem like the guy for yall need to clean house
  20. D @ drdrizzy13: I should say our receivers suck
Back
Top