personal-security-checklist/4_Privacy_And_Security_Links.md

53 KiB
Raw Blame History

Awesome Privacy & Securty Awesome PRs Welcome License Contributors

A curated list of notable guides, articles, tools and media - relating to digital security, internet freedom and online privacy

See also: Personal Security Checklist | Privacy-Respecting Software | Security Gadgets | Why Privacy Matters | TLDR🔐

How-To Guides

  • Threat Protection
    • Protect against SIM-swap scam: via wired
    • How to spot a phishing attack: via EFF
    • Protection from Identity Theft: via Restore Privacy
    • Harden your MacOS Security: via @drduh on GitHub
    • Protecting from key-stroke-logging, with KeyScrambler: via TechRepublic
    • Permanently and Securely Delete Files and Directories in Linux: via TechMint
  • Netowkring
    • How to enable DNS over HTTPS: via geekwire
    • How to resolve DNS leak issue: via DNSLeakTest
    • Protect against WebRTC Leaks: via Restore Privacy
    • ISP and DNS privacy tips: via bluz71
    • Complete guide to configureing Firefox for Privacy + Speed: via 12bytes
    • Beginners guide on getting started with Tor: via ProPrivacy
    • Beginners guide to I2P: via The Tin Hat
    • How to Use a VPN and Tor together: via ProPrivacy
    • How to use __nomap, to reduce public exposure of SSID: via ghacks
  • Communication
    • Email Self-Defense, Configure your mail client securly, from scratch - via FSF.org
    • How to avoid Phishing Attacks: via EFF
    • How to use PGP: Via EFF - Windows, MacOS and Linux
    • How to Maintain Anonyimity in BitCoin Transactions: coinsutra.com
  • Devices
  • Software
    • How to use Vera Crypt: via howtogeek
    • How to use KeePassXC: via EFF
    • How to use uMatrix browser addon to block trackers: via ProPrivacy
    • How to set up 2-Factor Auth on common websites: via The Verge
    • How to use DuckDuckGo advanced search features: via Ghacks
  • Physical Security
  • Enterprise
  • Reference Info

Articles

  • General
  • Encryption
    • Overview of projects working on next-generation secure email: via OpenTechFund
  • Surveillance
    • Twelve Million Phones, One Dataset, Zero Privacy: via NY Times
    • Windows data sending: via The Hacker News
    • Is your Anti-Virus spying on you: via Restore Privacy
    • What does your car know about you?: via Washington Post
    • Turns Out Police Stingray Spy Tools Can Indeed Record Calls: via Wired
    • UK Police Accessing Private Phone Data Without Warrant: via Restore Privacy
    • Rage Against Data Dominance: via Privacy International
    • NSA Files Decoded, What the revelations mean for you: via The Guardian
    • How to Track a Cellphone Without GPS—or Consent: via Gizmodo
    • Apps able to track device location, through power manager: via Wired
    • Hackers and governments can see you through your phones camera: via Business Insider
    • How a highly targeted ad can track your precise movements: via Wired
      • Based on the paper, Using Ad Targeting for Surveillance on a Budget: via Washington.edu
    • Law Enforcement Geo-Fence Data Requests- How an Innocent cyclist became a suspect when cops accessed his Google location data: via Daily Mail
  • Breaches
    • Wired guide to data breaches- past, present and future: via Wired
    • Grindr and OkCupid Spread Personal Details Study Says: via NY Times
    • The Asia-Pacific Cyber Espionage Campaign that Went Undetected for 5 Years: via TheHackerNews
  • Threats
    • 23 reasons not to reveal your DNA: via Internet Health Report
    • Security of Third-Party Keyboard Apps on Mobile Devices: via Lenny Zelster
    • Mobile Websites Can Tap Into Your Phone's Sensors Without Asking: via Wired
    • Non-admin accounts mitigate 94% of critical Windows vulnerabilities: via ghacks
    • Android Apps are able to monitor screen state, data usage, installed app details and more without any permissions: by @databurn-in, via GitHub
      • See also, PrivacyBreacher - an app developed by @databurn-in, which demonstrates these issues
    • How URL Previews in Apps can Leak Personal Info: via hunch.ly
    • Big data privacy risks: via CSO Online

Blogs

Books

  • Permanent Record by Edward Snowden
  • Sandworm by Andy Greenberg: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers
  • Extreme Privacy by Michael Bazzell: Thoroughly detailed guide for protecting your privacy both electronically and physically
  • Ghost in the Wires by Kevin Mitnick: Kevin tells his story of being the world's most wanted hacker
  • The Art of Invisibility, by Kevin Mitnick: You How to Be Safe in the Age of Big Brother
  • Eyes in the Sky: The Secret Rise of Gorgon Stare and How It Will Watch Us All, by Arthur Holla Michel: Outlines the capabilities of the digital imaging in continuous aerial and satellite surveillance, and discusses both the current systems that are deployed, and the technical feasibility of future plans

Podcasts

  • Darknet Diaries by Jack Rhysider: Stories from the dark sides of the internet.
    Stitcher iTunes Spotify Google Podcasts PocketCasts
  • CYBER by Motherboard: News and analysis about the latest cyber threats
    Stitcher iTunes Spotify SoundCloud PocketCasts
  • The Privacy, Security, & OSINT Show by Michael Bazzell: Comprehensive guides on Privacy and OSINT
    Stitcher iTunes Spotify SoundCloud PocketCasts
  • Smashing Security by Graham Cluley and Carole Theriault: Casual, opinionated and humerous chat about current cybersecurity news
    Stitcher iTunes Spotify Google Podcasts PocketCasts
  • IRL Podcast by Mozilla: Online Life is Real Life, Stories about the future of the Web
    Stitcher iTunes Spotify Google Podcasts PocketCasts
  • Random but Memorable by 1Password - A Security advice podcast
    Stitcher iTunes Spotify Google Podcasts PocketCasts

More Security Podcasts on player.fm

More Podcasts (Verification Required): Naked Security | Open Source Security Podcast | Defensive Security Podcast | Malicious Life | Down the Security Rabbit Hole | Cyber Wire | Hacking Humans | Security Now | Cyber Security Interviews | Security Weekly | The Shared Security Podcast | Risky Business | Crypto-Gram Security Podcast | Off the Hook

Videos

See also: awesome-sec-talks by @PaulSec

Online Tools

  • Check and Test
  • Utilities
    • ExifRemove - Remove Meta/ EXIF data online
    • Secure Password Check - Fun little tool, to demonstrate how long it could take to crack a password
    • 33Mail or Anonaddy or SimpleLogin Protect your email address, by auto-generating unique permeant aliases for each account, so all emails land in your primary inbox
    • Deseat Me - Clean up your online presence
  • Anti-Tracking Analysis
  • Phishing, Hacking and Abuse
    • VirusTotal - Analyse a suspicious web resource for malware
    • ScamAdviser - Check if a website is a scam, before buying from it
    • Abuse IP DB - Report an IP address for abuse, spam or attacks, and check the status of any IP
    • Phish Tank - Check if a link is a known phishing URL, Submit a phishing URL, browse recent phishing URLs
    • Is It Hacked? - Check if a website or page appears to be hacked, hijacked or generally suspicious
  • IP Tools
  • Public Domain and Website Scanning Tools
    • URL Scan - Scan and analyse websites, shows IP, DNS, domain and host data, as well as info about resources and requests
    • Security Trails - Shows all DNS records, historical DNS data and sub domains
    • crt.sh - Shows current and previous SSL/ TLS certificates for a given domain, has advanced search option
    • Virus Total - Scans any URL, web asset or file for malware
    • DomainTools WhoIs - Who Is Lookup. Check who registered a domain name, and find contact details
    • Pentest Tools Vulnerability Scanner - Light scan searches for client and server-side vulnerabilities and missing HTTP security headers
    • Qualys SSL Server Test - Perform a deep analysis of the configuration of any SSL web server on the public Internet
    • Abuse IP DB - Check if an IP or domain has been reported for abuse, or file a report
    • RIPEstat - Detailed analysis of IP Addresses (Routing, DNS, Abuse History, Activity etc)
    • Multirbl - Complete IP check for sending Mailservers
    • IPVoid - Full suit of Domain, IP, and DNS tools for Tracing, Lookup, Checking and Pinging
  • Net Neutrality
  • Anonymous Services - The following sites host a veriety of anonymous online services
  • Archives
    • The Way Back Machine - See previous versions of any website. An archive of 431 billion snapshots over 20 years
    • PolitiTweet - Archives Tweets from powerful public figures, and records silent retractions and deleted tweets
    • Internet Archive Software Collection - The largest vintage and historical software library
    • OpenLibrary - A free, digital library of over 2 million eBooks, and information on over 20 million books
    • Archive-It - Collecting and accessing cultural heritage on the web

Privacy-Respecting Software

This section has moved to here. Complete list of privacy-respecting software and services

Security Hardware

This section has moved to here. Products, gadgets and DIY projects to help improve security

Data, API's and Visualisations

Academic

  • Journals

    • Rethinking information privacysecurity: Does it really matter? By Waseem Afzal: via Wiley
    • Crypto Paper: Privacy, Security, and Anonymity For Every Internet User, by Crypto Seb: via GitHub
    • Challenges in assessing privacy impact, Tales from the Front Line: via Wiley
    • A privacypreserving multifactor authentication system: via Wiley
    • Web Browser Privacy: What Do Browsers Say When They Phone Home?: via scss.tcd.ie
    • Online Tracking, A 1-million-site Measurement and Analysis: via Princeton University
    • Detecting and Defending Against Third-Party Tracking on the Web: via Franziska Roesner
    • Is Google degrading search? Consumer Harm from Universal Search: via law.berkeley.edu
    • A Comprehensive Evaluation of Third-Party Cookie Policies: via WhoLeftOpenTheCookieJar.com
    • The Dangers of Surveillance: via Harvard Law Review
    • Recognizing Speech From Gyroscope Signals: via Stanford
    • A Study of Scripts Accessing Smartphone Sensors: via sensor-js.xyz
    • Pixel Perfect, Fingerprinting Canvas in HTML5: hovav.net
    • Shining the Floodlights on Mobile Web Tracking — A Privacy Survey: via semanticscholar.org
    • Characterizing the Use of Browser-Based Blocking Extensions To Prevent Online Tracking: via aruneshmathur.co.in
    • Privacy implications of email tracking: via senglehardt.com
    • Battery Status Not Included, Assessing Privacy in Web Standards: via princeton.edu
    • De-anonymizing Web Browsing Data with Social Networks: via princeton.edu
    • The Surveillance Implications of Web Tracking: via senglehardt.com
    • Understanding Facebook Connect login permissions: via jbonneau.com
    • Corporate Surveillance in Everyday Life, How Companies Collect, Combine, Analyze, Trade, and Use Personal Data on Billions: By Wolfie Christl, via crackedlabs.org
    • Using Ad Targeting for Surveillance on a Budget: via washington.edu
    • Cross-Site WebSocket Hijacking: via christian-schneider.net
    • Location Tracking using Mobile Device Power Analysis: scribd.com
    • Trackers Vs Firefox, Comparing different blocking utilities: via GitHub- @jawz101
  • Implementations and Standards

Foundations

Government Organisations

Mega Guides

  • Trusted software reccomendations and avice for privacy: privacytools.io
  • Tips and tricks, for internet freedom, data health and privacy: datadetoxkit.org
  • Digital security tools and tactics: securityinabox.org
  • Online privacy guide, and software reccomendations: via Fried
  • Guide to security through encryption: via ProPrivacy
  • Large collection of beginner security guides: Heimdal Security
  • The Motherboard guide to not getting hacked: via Vice
  • Online anonimity, and Tor + VPN tutorials: via ivpn

More Awesome GitHub Lists


Thanks for visiting, hope you found something useful here :) Contributions are welcome, and much appreciated - to propose an edit raise an issue, or open a PR. See: CONTRIBUTING.md.

Licensed under Creative Commons, CC BY 4.0, © Alicia Sykes 2020

Attribution 4.0 International


Found this helpful? Consider sharing it with others, to help them also improve their digital security 😇

Share on Twitter Share on LinkedIn Share on Facebook Share on Mastodon