Problems with the auntie network and centralized groups
By now the dust has settled over the ‘auntie network’ and many of its issues but this post is specifically about infoSec and why I left.
Decentralization has been used in various social movements like BLM, in WW II resistance and the IRA to create difficult to infiltrate social networks. The reason this works is if even one person is compromised, only a few others can be held accountable by law enforcement. Make no fucking mistake, if we truly end up in a situation where we’re having to move people who need abortions between independent members of a movement, there will be interest from law enforcement.
The last thing we need is to have a large list of people held in a central location.
2. Do not advertise where these records are being held on a platform known for privacy violations.
Facebook has and will be used by law enforcement and opposition groups to investigate and do intelligence recon. Posting in even a closed group about where you’re holding information on individuals willing to resist is contrary to the kind of mindset you need for a grassroots movement. You’ve just told everyone where it is they need to attack. And using the OSINT framework they will easily be able to figure out the username of the person holding that information.
3. Do not collect information in Google Forms.
For those not familiar, Google has a suite of applications that are designed to replace Microsoft applications. (More on why to use Libre Office and where to store that info in the cloud later.)
Google Forms can either contain that information within the application itself or you can generate a spreadsheet, which provides another surface for information leaks.
Both the form and the spreadsheet can be shared with the public using urls.
So if someone finds out who owns or has access to the form and manages to breach a Google account?
They have that list of people with locations, names and usernames. They can then use that information to breach those accounts.
4. Google and Facebook are both based in the United States and are required to abide by US laws.
So what are the solutions?
2. When planning and information gathering use tools known to be secure such as...
Signal - a secure text messaging app
Tor - protect your Internet privacy
If you have to use some kind of group chat, use an alternative to Discord or Slack NOT located in the United States.
3. If you have to collect information store it in an account that hasn’t previously been breached, not hosted in the US, not connected to your legal name and uses 2FA. FastMail, for example, is located in Australia and are known for good privacy.
(This is by no means an exhaustive list of products or vendors but the message here is just like, don’t use Google, Microsoft or Facebook for shit you want to keep secret.)