# The Protesters' Guide to Smartphone Security

**URL:** https://discuss.privacyguides.net/t/the-protesters-guide-to-smartphone-security/24316
**Category:** Articles
**Created:** 2025-01-23T19:16:04Z
**Posts:** 83

## Post 1 by @jonah — 2025-01-23T19:16:05Z

> **[The Protesters' Guide to Smartphone Security](https://www.privacyguides.org/articles/2025/01/23/activists-guide-securing-your-smartphone/)**
>
> Your phone is an essential tool, but it also represents a huge risk to your privacy and security. Understanding these best practices when it comes to securing your smartphone will help keep you and your data safe.

I was feeling inspired to write this morning after looking through a lot of this type of article and noticing they all omitted kind of important information. This includes all of the basics, and the stuff I thought was under-discussed, like AirDrop and the importance of security patches.

---

## Post 2 by @phnx — 2025-01-23T19:45:22Z

That was an enjoyable read. If I may offer some feedback:

> Additionally, even if it’s encrypted, it still won’t benefit from the same security protections that your phone’s built-in storage provides, such as advanced brute-force protections.

I could be mistaken, but I don’t think this is strictly true. See [Adoptable storage &nbsp;|&nbsp; Android Open Source Project](https://source.android.com/docs/core/storage/adoptable#security).

> Google is frequently tapped by law enforcement to provide location data, because they don’t protect your personal information with strong, zero-knowledge encryption.

This is / will no longer be the case (I’m not super clear on whether it is fully rolled out yet). See [Google Maps is making a big privacy change to protect your location history | The Verge](https://www.theverge.com/2024/6/5/24172204/google-maps-delete-location-history-timeline).

---

## Post 3 by @KevPham — 2025-01-23T19:59:41Z

Great article! I found this part really funny.

> Please be aware of the **legal consequences** of these actions. Wiping your device or revoking online account access could lead to obstruction of justice or destruction of evidence charges in some jurisdictions. You should always speak with your licensed attorney before deciding how to proceed. If your phone was taken by law enforcement you may have legal recourse to get it back.

During my time at FPF, I once had a bunch of lawyers _strongly discourage_ this idea in a protest security toolkit. As in they wrote entire essays to me during work hours :confused:

---

## Post 4 by @overdrawn98901 — 2025-01-23T20:13:20Z

Great article! I think this was very much needed, especially appreciate how it’s written for the target audience.

---

## Post 5 by @jerm — 2025-01-23T20:24:58Z

Didn’t cover cell towers tracking (IMSI & IMEI).

---

## Post 6 by @Cyber-Typhoon — 2025-01-23T20:35:38Z

Great article @Jonah. like I said before those articles are nice additions to the content available. This one in specific I think can expand much more but is good to have a starting point (which normally is the most difficult part).

> [@phnx](#):
>
> This is / will no longer be the case (I’m not super clear on whether it is fully rolled out yet). See [Google Maps is making a big privacy change to protect your location history - The Verge](https://www.theverge.com/2024/6/5/24172204/google-maps-delete-location-history-timeline).

It is up to us to believe that the setting is really working since there is no way to validate the code.

---

## Post 7 by @phnx — 2025-01-23T20:54:49Z

> [@Cyber-Typhoon](#):
>
> It is up to us to believe that the setting is really working since there is no way to validate the code.

Which do you think is more likely?

A) That the feature works as intended, dramatically lowering the administrative load for Google associated with complying with geofence warrants.

B) That Google is lying to both its users and law enforcement in hundreds of countries by secretly keeping location data unencrypted on its cloud. Meanwhile, refusing to comply with geofence warrants from law enforcement despite possessing the requested data, exposing Google to significant legal liability (a pretty poor business strategy).

This is fairly good reason to believe Google not to mention the fact that:

> A current Google employee who **was not authorized to speak publicly** told _[Forbes](https://www.forbes.com/sites/cyrusfarivar/2023/12/14/google-just-killed-geofence-warrants-police-location-data/)_ that along with the obvious privacy benefits of encrypting location data, Google made the move to explicitly bring an end to such dragnet location searches.

---

## Post 8 by @Cyber-Typhoon — 2025-01-23T21:27:47Z

It could be something in between. It doesn’t need to be necessarily the A and B that you mentioned.

They can on their side turn the feature to keep the location on because their were coerced to cooperate.

---

## Post 9 by @Astatine — 2025-01-24T00:49:42Z

Thanks for creating the article, although I won’t be protesting anytime soon, but I got some key takeaways from it :slightly_smiling_face:.

---

## Post 10 by @jordan — 2025-01-24T10:25:56Z

This is a really important topic to cover! Most of the stuff I have read about this mostly focuses on physical aspects to consider during a protest; not many cover digital aspects so expansively.

---

## Post 11 by @ignoramous — 2025-01-24T10:34:28Z

> [@Astatine](#):
>
> won’t be protesting anytime

It isn’t as simple as this guide isn’t laying out a threat model.

In some jurisdictions, body-hugging devices (like smartphones) may come pre-installed with spyware apps.

For instance, I was sent this tip on use of Rethink, an app I co-develop, to _block_ such spyware [by protestors in Hong Kong](https://matters.news/@whisper/192579-%E5%9C%A8%E5%BC%B7%E5%88%B6%E4%BD%BF%E7%94%A8-%E5%AE%89%E5%BF%83%E5%87%BA%E8%A1%8C-%E7%9A%84%E6%99%82%E4%BB%A3%E4%BF%9D%E8%AD%B7%E8%87%AA%E5%B7%B1-%E6%8A%B5%E6%8A%97%E6%94%BF%E5%BA%9C%E8%BF%BD%E8%B9%A4-bafyreic2vr7onrpok6ivx3lhh3arxqusnar7ldba2e56u25b6fyggjpzd4) ([mirror](https://archive.vn/Xvp3B)).

Also, I’m not sure disabling 2G is enough. Govts are known to retroactively arrest based on location triangulated via Cell towers. Some speculate ([ex](https://www.reddit.com/r/GrapheneOS/comments/11op7yz/remote_hijacking_via_baseband_processor/) / [mirror](https://archive.vn/pNB7W)) that _basebands_ may be turned ON on remotely (even if is switched off, like via airplane mode), though unsure if that’s a valid attack vector these days.

---

## Post 12 by @ihateKYC — 2025-01-24T12:09:10Z

I’d add more data disposal tips. Delete cloud storage apps that you don’t need access to while at the protest. If you can reinstall the app , login, and your data is back, you don’t need the app always on your phone. Don’t need your password manager that you protect with Face ID sitting there waiting to be extracted after your keychain gets snatched exposing all of your identities.

Cellebrite Premium basically bypasses every security measure on iOS device. Stolen device protection , lockdown mode, etc. are essentially just UI blocks that only affect the basic extraction methods, which does nothing when you literally have access to the file system. You must focus on keeping limited amounts of data on your iPhone and understanding the forensic nature of your applications.

---

## Post 16 by @ignoramous — 2025-01-24T14:44:35Z

> [@anon39279085](#):
>
> Also instead of advicing them to “leave your phone at home” Maybe you should advice them on how to protect themselves like Jonah is doing here

They have a valid point.

Leaving phones behind or using burner phones is a _very_ practical advise. I’d ask the same of vulnerable folks, especially those who can be made examples out of by powers-that-be: They can be detained for arbitrarily long periods, get declared a traitor, have their livelihood destroyed, and the life of their loved ones jeopardised for eternity. This stuff is serious in some jurisdictions.

> [@anon39279085](#):
>
> you want more people reading your articles, Maintain a non-onion one too alongside the onion one

True. Though, Firefox can talk onion, if you turn OFF `network.dns.blockDotOnion` in `about:config`? I think, Brave has built-in support? Ages ago, volunteer-run gateways (onion to www) like `tor2web.org` were popular.

---

## Post 18 by @jonah — 2025-01-24T15:50:48Z

Thanks for the feedback everyone! I’m glad this guide has been very well received :slight_smile:

I will be updating it with some changes on Monday based on some comments I’ve seen here and on social media, drafting here:

[https://github.com/privacyguides/privacyguides.org/pull/2860](https://github.com/privacyguides/privacyguides.org/pull/2860)

---

## Post 19 by @TinFoilHat — 2025-01-24T16:31:24Z

> [@ignoramous](#):
>
> Also, I’m not sure disabling 2G is enough. Govts are known to retroactively arrest based on location triangulated via Cell towers. Some speculate ([ex](https://www.reddit.com/r/GrapheneOS/comments/11op7yz/remote_hijacking_via_baseband_processor/) / [mirror](https://archive.vn/pNB7W)) that _basebands_ may be turned ON on remotely (even if is switched off, like via airplane mode), though unsure if that’s a valid attack vector these days.

I think it really depends on the risk of the “protest”, the same thing can be either “no big deal” or “if you get caught you are done”, depending on where you are. It would be nice if the article could bring this up.

---

## Post 20 by @Valynor — 2025-01-24T17:01:23Z

> [@ignoramous](#):
>
> Leaving phones behind or using burner phones is a _very_ practical advise.

Considering the amount of very personal data that a phone (usually) has on you I think it’s the **only** advice that makes sense **IF** you really are in that high-risk position and have to assume your items will be seized with a certain likelihood.

Either that or having a burner phone - or at least a 2nd phone that has zero unnecessary apps/information on it and that you use just for occasions like this (and factory reset regularly).

---

## Post 21 by @ActivistChecklist.org — 2025-01-24T17:45:38Z

Thanks @jonah for this guide!

I’ve been working for the past 6 months to build a series of guides for activists (US-focused). And there are a few recommendations on your guide that I want to use to polish up [our prepare for protest checklist](https://activistchecklist.org/protest).

> **[Digital Security Checklists for Activists](https://activistchecklist.org/)**
>
> Plain language steps for digital security, because protecting yourself helps keep your whole community safer. Built by activists, for activists with field-tested, community-verified guides.

---

## Post 22 by @siren — 2025-01-24T17:55:19Z

Yes, go kick rocks. It is irresponsible to disseminate that you could possibly have ANY private phone use, i.e. related to attending a protest, when, on top of proof that nation states are targeting iPhone users., there is no app sandboxing, reproducibly.

Apps that are bought and sold (everything on the app store) can access other processes on the device, with the matching api even in the case of googled devices (anything with g in the name on any device).

This is fixed only by using open source operating systems and nothing less. Throw that app in a box (user profile). Practice privacy with your iphone, but an iphone is not a tool of privacy.

---

## Post 23 by @Niek-de-Wilde — 2025-01-24T18:09:10Z

Not everyone has this high of a threatmodel. Telling folks to kick rocks because they are unable to flash graphene or even afford a pixels, and they are better off not protesting way to extreme.

You have to threatmodel, in some countries this mindset might be needed, but in others this is completely over the top.

---

## Post 24 by @overdrawn98901 — 2025-01-24T18:12:41Z

> [@Niek-de-Wilde](#):
>
> You have to threatmodel, in some countries this mindset might be needed, but in others this is completely over the top.

I think this is the core misunderstanding and nuance, where it may be a hard requirement or not depending on the threat model. I believe Jonah will include this in the next draft of the article.

---

## Post 25 by @anon48875053 — 2025-01-24T18:36:55Z

For those who prefer a video format, there are two videos by The Hated One on both digital and physical aspects of attending a protest, and both are covered in a lot of detail.

The goal is extreme anonymity, with no compromises allowed.

Digital:

> **[How To be Anonymous In A Protest | Burner Phone Tutorial](https://www.youtube.com/watch?feature=shared&v=vMJH-UJyENs)**
>
> If you want to attend a protest, you have to become unidentifiable. This is how you do it. Become a producer of independent research and analysis by joining ...

Physical:

> **[How To Be Anonymous In The Streets](https://www.youtube.com/watch?app=desktop&v=x_5y1jIWPjc)**
>
> Support independent research and analysis by joining my Patreon page: https://www.patreon.com/thehatedone The 21st century has erased the relative anonymity ...

---

## Post 26 by @siren — 2025-01-24T18:46:56Z

The threat model is:  
Achieving privacy-thus-plausible deniability that you did !not attend a protest, having left your phone at home, some hours after liking a post on insta (or \*literally anything) about the protest. Sandboxing.

---

## Post 27 by @yes — 2025-01-24T18:47:30Z

> [@anon48875053](#):
>
> For those who prefer a video format

speaking of videos.. @jordan

---

## Post 28 by @ignoramous — 2025-01-24T18:53:00Z

> [@Niek-de-Wilde](#):
>
> Not everyone has this high of a threatmodel.

By definition, protestors are vulnerable (almost always regardless of where they are), whether or not they know how “model threats”.

The law enforcement won’t hesitate to throw the book at you, if you happen to be at the wrong place at the wrong time, which has a high chance of happening if you’re at protests (think: the US Capitol riots) that unexpectedly (out of your control!) go high-octane. Can’t _model_ that.

In short, regardless of threat models, imo folks reading such guides would rather be safe than sorry.

---

## Post 29 by @Niek-de-Wilde — 2025-01-24T18:53:58Z

That would be anonymity technically, not privacy. Anyhow, its not a black and white, its on a spectrum. For some it might be fine to be known that you were at at protest, but not everything thats on your phone?

Lots of different models for lots of different people.

---

## Post 30 by @TinFoilHat — 2025-01-24T19:52:28Z

IMO it would make much better sense try not to get caught, rather than plausible deniability.

This guide (so far) do little to help on that end.

---

## Post 31 by @TinFoilHat — 2025-01-24T20:25:58Z

Welcome to PG and your website seems very informative, will have a look in a bit. :+1:

* * *

Just took a brief look, I really like your idea of incorporating different protest stages and roles in your checklists, I think it is a very good approach as the tasks and risks associated in each stage and role varies a lot.

However, to keep **this thread** on track, I will be focusing on part of “security essentials” and “prepare for a protest”, as PG’s guideline seems targeting casual protesters that participate mostly peaceful and well organised protests, not activists, meaning “protest planning”, “R&R”, “scouting”, “logistic support”, etc. are out of scope. Many of the ideas below are also relevant to the PG Protester guide so hope PG Team will also consider.

## (A) Security Essentials

- Baseline security: Assuming it is for casual protesters, I would suggest adding  
(i) (Browser) Always use forgetful / incognito browsing,  
(ii) (Browser) Avoid using Browsers’ built-in autologin / autofill / password manager features  
(iii) (Signal) Get a secondary account using burner numbers for protesting related matters, with all security and privacy enhancements settings esp. hiding phone numbers and username enabled.  
(iv) (In general) Do not keep protest related materials on your devices.  
(v) (In general) Do not use real social media accounts to browse, share, like or publish protest related contents.  
(vi) (In general) Only use browser **with VPN turned on** to log in secondary social media accounts mentioned in (v) and always log off immediately after use.  
(vii) Do not install / keep unnecessary applications on your devices  
(viii) (In general) Incorporate other PG recommendations.

- Enhanced security: Assuming it is for **Entry Level Activists (Experienced people know what to do already)**, I would suggest  
(ix) VPN, 2FA, sign in with Google, Click bait should be moved to baseline security  
(x) Change “Install a VPN” to “Always on VPN”  
(xi) (In General) Add APP profile compartmentalization for protest related apps and usages  
(xii) (Phones) Add Apple iphone with lockdown mode enabled / pixel with GOS with duress password/ PIN enabled (please do point out additional risks discussed in this thread)  
(xiii) (Computers) Add For all protest related files, keep them in an encrypted drive, and only use portable apps which stored in the encrypted drive to open.  
(xiv) (Computers) Add Disable file history, set up Ram Drive as as OS Temp Folder  
(xv) (Computers) Add computer security hardening  
(xvi) (Computers) Add Software Firewall section  
(xvii) (Computers) Add Home Router section  
(xviii) (Phones) Add Phone number rotation and phone number compartmentalisation section (preferably activism related numbers should be a number outside your country)

I personally don’t think TOR is commonly required here unless the community coordinate through dark web, or they need to obtain / distribute intel or “material” through dark web.

## (B) Prepare for a Protest

- Add Sections  
(i) “Don’t Get Caught” Section, keep checking with news and be vigilant, leave protest zone ASAP if you feel something not right or too risky  
(ii) “Work not Talk” Section i.e. Do not talk unless necessary, and DO NOT EVER share any personal information, not even remotely personal  
(iii) “Bring your trash with you” section i.e. whatever food or drinks you consumed, take the packaging or bottle with you and bin it after you are far away from protest zone.

- Secure your phone (baseline): I assume it is for casual protesters, I would suggest  
(iv) Signal is terrible for real time protest coordination and info update as it lacks channel feature, and prob. protesters will create their own map type info platform for info sharing. Moreover, they usually have no control over communication platform.  
(v) Some recommendation seems over kill for peaceful and well organised protests. For heated protests (e.g. On highly controversial e.g. Pro/Anti Palestine, BLM) , they should use enhanced section just like activists.  
(vi) Add disable NFC, BT, AirDrop, Nearby share  
(vii) Add remove emergency contact (if applicable)  
(viii) Change Disable SIgnal Notification to Hide notifications from lock screen.  
(ix) Add keep screen locked whenever not using the phone

- Secure your phone (enhanced)  
(x) Move Signal configuration checklist, Disable voice assistant, Backup your phone to Security Essentials - Baseline security  
(xi) Add use a **Protest Only** burner SIM and burner phone  
(xii) Add Set phone to vibrate mode  
(xiii) Add use walkie talkie apps rather than actual walkie talkie  
(xiv) Add “Delegated emergency digital power of attorney” i.e. delegate someone you can trust to kick all loged in sessions from all your accounts if you fail to report in after certain time.

- Other protest safety tips  
(xv) For Plan your trip with surveillance in mind, add avoid direct commute from and to protest zone  
(xvi) Add bring extra outfit and pre-plan safe changing locations before and after protest, dispose them if necessary  
(xvii) Add beware of covert cops

* * *

It became much longer than I originally thought, hope you don’t mind.

Being an Activist / Journalist, it is more important to protect the Team / Asset (Sources) in case of arrest, it would involve some more extreme measures which are definitely OT.

---

## Post 32 by @jordan — 2025-01-24T20:30:53Z

That’s a great idea! Added it to the video ideas list :heart_hands:

---

## Post 33 by @brinerustle — 2025-01-25T09:56:07Z

some recommendations from: [GrapheneOS for human rights defenders](https://cryptpad.fr/pad/#/2/pad/view/lqcUG98M8NCg3PZnmwcIzo8wmNx34Il2u5PcJA2pV7c/)

1. If you leave your phone at home, turn it off. BFU is much harder to crack.
2. Use autoreboot. A rebooted phone is much more difficult to crack. After an arrest, the phone will be more likely to auto-reboot before it reaches the hands of a hostile IT team. from Settings \> Security & privacy \> Exploit protection \> Auto Reboot - set the minimum time you are comfortable with. (phone is much harder to attack BFU)
3. Enable: Settings \> Security & privacy \> Device unlock \> Screen lock \> Scramble pin input layout - this will make microscopic analysis of the screen surface more difficult. This is one of the reasons for not using a password and using a 6+ digitpin.
4. 
  - Settings \> Security \> Security & privacy \> Exploit protection \> USB-C port \> charging only. If you need to use the USB-C for other uses choose the next option down with caution..

5. if possible (available on GrapheneOS) enable a duress password, and store a copy on paper inside the phone case, It is a pin that when used, will immediately wipe the phone and all data.

---

## Post 34 by @LoSee21 — 2025-01-25T11:50:27Z

I think, these two pages could also be of value for the guide @jonah

Mostly grapheneOS oriented

> **[AnarSec | GrapheneOS for Anarchists](https://www.anarsec.guide/posts/grapheneos/)**

Encrypted massaging

> **[AnarSec | Encrypted Messaging for Anarchists](https://www.anarsec.guide/posts/e2ee/)**

---

## Post 37 by @TinFoilHat — 2025-01-25T12:47:14Z

> [@anon39279085](#):
>
> where they said they recommend an iPhone

I think he got this sense because there are recommended settings for iPhone i.e. [Lock Down Mode](https://www.privacyguides.org/articles/2025/01/23/activists-guide-securing-your-smartphone/#lock-down-your-network), [Disable AirDrop](https://www.privacyguides.org/articles/2025/01/23/activists-guide-securing-your-smartphone/#disable-airdrop), etc. In this regard, I do feel the same, and I do feel that PG is treating all Android devices the same in this topic, which I strongly disagree. Imagine bringing a Chiese brand android phone with stock ROM to protest in China.

> [@anon39279085](#):
>
> where in the part is a problem about guiding a user especially if they still need their phone especially?

It seems like @nihilist assumed protesting as a VERY high risk activity, and many others here do not. PG’s guideline appears to be not written nor suitable for high risk situations. I think not everyone here are on the same page.

@nihilist I do appreciate your genuine concerns, they are mostly valid, and it seems that you are experienced in protesting / activism, toning down a little bit and bring more context in your message might help you deliver your ideas better. Again, this is the internet, people here are from many different countries, with different backgrounds.

---

## Post 38 by @anon39279085 — 2025-01-25T12:56:49Z

> [@TinFoilHat](#):
>
> I think he got this sense because there are recommended settings for iPhone i.e. [Lock Down Mode](https://www.privacyguides.org/articles/2025/01/23/activists-guide-securing-your-smartphone/#lock-down-your-network), [Disable AirDrop](https://www.privacyguides.org/articles/2025/01/23/activists-guide-securing-your-smartphone/#disable-airdrop), etc. In this regard, (…)

Yeah this is recommending ways to protect if the protester so happens to have an iPhone, This is _ **not recommending an iPhone** _ in any capacity, again why the argument here is pointless.  
I disagree about PG treating Android equally not being a good thing but I do agree not bringing a Chinese phone to protest in China thing. So a agree to disagree.  
of course if the protester so can avoid it, otherwise yes implement secure ways where you can with it or don’t bother bringing a phone simply put.

> [@TinFoilHat](#):
>
> It seems like @nihilist assumed protesting as a VERY high risk activity, and many others here do not. PG’s guideline appears to be not written nor suitable for high risk situations. I think not everyone here are on the same page.
> 
> @nihilist I do appreciate your genuine concerns, they are mostly valid, and it seems that you are experienced in protesting / activism, toning down a little bit and bring more context in your message might help you deliver your ideas better. Again, this is the internet, people here are from many different countries, with different backgrounds.

Appreciate it!

---

## Post 40 by @jerm — 2025-01-25T16:31:42Z

The link provided have a lot of wrong and terrible recommendations that doesn’t align with PG’s recommendations.

---

## Post 41 by @ignoramous — 2025-01-25T19:28:43Z

> [@Niek-de-Wilde](#):
>
> P.s. , The approach is not called “laxist” but realisitic

Not really. A motorist can take no precaution (laxist) as they’re driving super slowly but there’s zero guarantee a 2 tonne SUV won’t ram into them.

When stakes are high (life/death), regardless of the risk, safetyism is more pragmatic.

* * *

Edit: To quote Raphael Mimoun, a Human Rights activist ([source](https://blog.mozilla.org/en/internet-culture/raphael-mimoun-mozilla-rise-25-human-rights-justice-journalists/)):

> People have no idea what the regulations are, what the rules are, what’s allowed, what’s not allowed. And when they abuse those powers, is there any recourse? Most places in the world, at least, where we are working, there is definitely no recourse. And so I think that connection between thinking you’re just taking a photo for social media but actually the repercussion is so real because you’re going to have someone take your phone, and maybe they’re going to delete the photo, or maybe they’re going to detain you. Or maybe they’re going to beat you up — like all of those different things.

---

## Post 42 by @TinFoilHat — 2025-01-25T20:56:07Z

I would say some of the suggestions are outdated such as the use of shelter, but the rest seems not really deviating from PG’s general suggestions.

One thing that mentioned in the cryptpad page has potential usecase i.e. SIM lock, though it can be bypassed (reset) if LE really wanted to, but that would take some effort. With eSIM become more and more common, using eSIM could be a superior option as it is immune to physical extraction, also it could be remotely disabled if necessary.

---

## Post 43 by @Niek-de-Wilde — 2025-01-25T21:08:48Z

I could be perfectly happy to share that I live in the Netherlands, while not comfortable with sharing my precise home address. As you see here: ite a spectrum, sharing some details does not mean i have no privacy at all.

Just because someone does not use graphene OS on their phone and Qubes OS on their computer does not mean that all other attempts at security are useless, these platforms may not even be needed for their threat model, also here you see a spectrum.

This black and white thinking that lots of people seem to have in the privacy community is a big reason why its hard to get privacy into the mainstream, and are completly counterproductive on what we are trying to do here.

Ofcourse on should error on the side of caution when its practical and reasonable to do so, but this extremist view that @nihilist is trying to push here only pushes folks away from improving themselves as they WILL become overwhelmed.

---

## Post 44 by @TinFoilHat — 2025-01-25T22:10:28Z

I would say the minimum safety requirement should be set according to he risk of the protest (and your personal profile), treat it like hiking.

What you need for a short walk on the hill near your house is totally different from aiming at the top of mount everest.

---

## Post 45 by @ignoramous — 2025-01-25T23:03:57Z

> [@Niek-de-Wilde](#):
>
> This black and white thinking that lots of people seem to have in the privacy community

My points were solely on the topic of protestors, nothing more.

> [@Niek-de-Wilde](#):
>
> pushes folks away from improving themselves as they WILL become overwhelmed

You’re right. What’s the saying about half knowledge is a dangerous thing? Ominous for those seeking solutions yet getting overwhelmed. For folks who write “guides” however, it beehoves them to be thorough.

> [@Niek-de-Wilde](#):
>
> this extremist view that @nihilist is trying to push here

If “extremists” are not welcome, consider putting it up in community’s guidelines, so they’ll know to shut up.

---

## Post 46 by @anon39279085 — 2025-01-25T23:39:46Z

> [@ignoramous](#):
>
> If “extremists” are not welcome, consider putting it up in community’s guidelines, so they’ll know to shut up.

It’s not they aren’t welcome, it’s when they’re pushing their views as “facts” is the problem, not something PG wants to add in code of conduct if they can. It’s why they also never get reported, just downvoted and pushed from a different more rational perspective.

---

## Post 47 by @Astatine — 2025-01-26T01:26:45Z

> [@ignoramous](#):
>
> If “extremists” are not welcome, consider putting it up in community’s guidelines, so they’ll know to shut up.

Or one can simply clarify. If after, they _still_ want to push their agenda, that’s _their_ issue, since one already did their part in trying to reach a solution.

---

## Post 48 by @Niek-de-Wilde — 2025-01-26T01:54:58Z

Couldn’t have put it better.

I think it is self evident that we want to allow different opinions on this forum. Having different voices continues to challenge the status quo and forces us to be on edge withbour recommendations, you know, preventing the whole sacred cows thing.

We even allow them to promote their own blogs and all. We just ask folks to respect the way we do things here. And coming in out of nowhere claiming that our communities consensus is wrong and that your own opinion is fact just crosses a line.

You are allowed to give your opinion, we love it if you do so and we might even change our own opinion because you brought in a fresh perspective that we haven’t considered before. All we ask is just to be respectfull on here.

---

## Post 51 by @TinFoilHat — 2025-01-26T11:17:08Z

Hmm, actually the bar @nihilist set for “wild protest” is essential and mostly appropriate, thats by my pereonal experience and by how thousands of protesters who got persecuted during a specific movement. Doing anything below that bar would have serious consequences, if you are taking part in “wild protest” or “movement”.

And when you got arrested, your “team”, friends and family will go down with you. That is not something you can afford to risk.

For kicking rocks part, if someone wants to participate in a political movement or wild protest but thinking those measures / suggestions are unnecessary, they probably really should go kick rocks, so they wont bring massive collectoral damage, to everyone in their lives.

I apologise if anyone feel bad for my tone, but the things @nihilist mentioned are mostly FIELD TESTED, and I have seen more than enough people trying do the right thing but ended up really bad because of lax opsec.

For peaceful, nom-controversial, well organised protests, most measures are overkill and counterproductive, that includes some recommendation listed in PG.

---

## Post 52 by @Niek-de-Wilde — 2025-01-26T11:41:04Z

Thanks for sharing your thoughts, we will just have to agree to disagree in this case.

Also I just wanted to add, we are open to suggestions and improvents to the guide, if you were to post a list of exact concrete things that you feel should be changef with your rationale, then we can talk over them.

My disagreement is mostly about the black and white view of privacy and security and the lack of nuance in the discussion :).

---

## Post 53 by @ignoramous — 2025-01-26T12:20:31Z

> [@Niek-de-Wilde](#):
>
> All we ask is just to be respectfull on here

Pratice.

Not respectful is it (as a _mod_!) to paint someone’s genuine views as “extremist”.[[1]](#footnote-77190-1) The dissonance here boggles the mind.

> [@anon39279085](#):
>
> it’s when they’re pushing their views as “facts” is the problem

Thought @nihilist’s discussing a blog post not a community recommendation.

> [@anon39279085](#):
>
> It’s why they also never get reported, just downvoted

Not sure what you’re advocating for, but monoculture / cult-following is a _bad_ sign.

* * *

1. I mean, this is what you replied to, and claim is extremism? “neither privacy, nor anonymity, nor deniability have ever been a spectrum. To consider either of those as a spectrum means that you have a laxist approach to it.” [↩︎](#footnote-ref-77190-1)

---

## Post 55 by @ActivistChecklist.org — 2025-01-26T16:56:45Z

> [@TinFoilHat](#):
>
> Just took a brief look, I really like your idea of incorporating different protest stages and roles in your checklists, I think it is a very good approach as the tasks and risks associated in each stage and role varies a lot.

Thanks for the detailed and thoughtful reply. I agree with a number of the points you made here. We’re going to be doing a big revision over the next couple of weeks. So keep an eye out.

I think one of the best things we can do is emphasize “don’t bring your phone” more heavily on the phone guide. And to give folks better guidance about assessing risk so they can decide if they can live without the convenience of the phone.

---

## Post 56 by @ignoramous — 2025-01-27T02:57:08Z

> [@jonah](#):
>
> I think it assumes you’re in a situation where 1) you’re facing the highest possible risk

I don’t understand this at all.

For one, would PG feel comfortable recommending Password Managers that don’t assume highest possible risk? Or VPNs that don’t take in to account the highest possible risk? Or Android ROMs that don’t? Or Messengers that don’t?

If you read up the papers on the design of the Signal protocol, the risk they assume is _highest_ possible risk. Same goes for the design of Pixel phones. And that of Mullvad’s network. These are what PG recommends & stands by.

How is it any different when it comes to what the protestors should use? Any protestor looking to level up on digital literacy is likely going for “highest risk”, or they wouldn’t be at all.

A regular user most certainly is “overwhelmed” if you point out things like “root of trust”, “certificate chains”, “public key cryptography”, but that isn’t a criteria to _not_ recommend using those. _Usable security_ has nothing to do with the **why** (reasons). It has to do with the **what** (toolkit). Unfortunately, in some cases, the _what_ involves multiple steps and careful setup (think: messaging with PGP vs Signal), but if PG was set in 2000s, it’d have been comical for its tutorials to not recommend using PGP over plain text, just because \<insert something about spectrum\>.

---

## Post 57 by @brinerustle — 2025-01-27T07:15:31Z

in [hacker news](https://news.ycombinator.com/item?id=42829317) a few more guides came up, worth visiting

---

## Post 58 by @ignoramous — 2025-01-27T10:04:06Z

> [@brinerustle](#):
>
> worth visiting

Of course! The kind of solutions proposed there wouldn’t fly in this community because “extremism”. There is some kind of weird resistance to setups the team here thinks is too much for whatever definition of “lay person” they have in mind.

I mean, the first draft of the post didn’t even talk about _burner_ phones, fwiw.

Point:

> As pointed out elsewhere, the line between legal and illegal protest is very blurry and can shift rapidly; if anything, the only way to be sure you’re not going to a protest that could eventually be classed as illegal is to never go to a protest, regardless of how pure your intentions are.

Thanks for sharing.

---

## Post 59 by @TinFoilHat — 2025-01-27T11:42:04Z

One thing people often overlook, is whether their job allows them to protest or express opinions on government policies. So even in a non-illegal protests, many people shuould consider covering their face and be extremely cautious about being interview by press.

For example, civil servants, NGO employees, employees of government contractors, marketing companies, etc. They need to check their internal policies, so they wont get into law suits or lossing their job.

---

## Post 60 by @fria — 2025-01-27T19:16:59Z

> [@ignoramous](#):
>
> If you read up the papers on the design of the Signal protocol, the risk they assume is _highest_ possible risk. Same goes for the design of Pixel phones. And that of Mullvad’s network. These are what PG recommends & stands by.

Well they all have a defined threat model. Signal doesn’t defend against someone shoulder surfing you reading your messages. It also doesn’t try to defend against malware reading your message database. You can’t really say they defend against the “highest possible risk” because risks don’t come in a clean hierarchy. You have to define specifically what the threat that you’re defending against is.

---

## Post 61 by @ignoramous — 2025-01-27T22:12:57Z

> [@fria](#):
>
> Signal doesn’t defend against someone shoulder surfing you reading your messages.

Rank refrigerator on how good it bakes bread?

> [@fria](#):
>
> also doesn’t try to defend against malware reading your message database

What?!

I’m tired, man.

---

## Post 62 by @flow — 2025-01-31T09:23:39Z

Thank you for this great article.

I hope i didn’t miss this feedback scrolling over 60 replies already:

> On a Google Pixel and most other Android devices, double-tapping the power button will open the camera without needing to unlock your device.

With Graphene OS you are able to block your microphones and your cameras Through the notification bar. Although you may have to unlock your phone for that

> You might also want to consider local radios like walkie-talkies, although keep in mind these devices are nearly always unencrypted and can be easily monitored by others, so you won’t want to use them to transmit sensitive information.

Law enforcement may look for people using walkie talkies and you might be able to get located using walkie talkies.  
This might also apply for extra devices like meshtestic radios but since they are stored in the pocket or a backpack and the frequencies are very special I think it’s unlikely they are looking for stuff like this and are able to locate such devices by looking for radio signals.

---

## Post 63 by @phnx — 2025-01-31T09:53:42Z

> [@flow](#):
>
> With Graphene OS you are able to block your microphones and your cameras Through the notification bar. Although you may have to unlock your phone for that

This is a standard AOSP feature. You can of course use it but it’s better not to grant the camera / microphone permissions to apps you don’t trust in the first place.

---

## Post 64 by @ignoramous — 2025-01-31T14:09:08Z

> [@flow](#):
>
> Graphene OS you are able to block your microphones

If the _Baseband_ chipset can control the mic, then Graphene can only do _so much_. Not sure if Google allows this on Pixels. For other OEMs, this totally depends on what goes into their SoCs.

---

## Post 65 by @anon48875053 — 2025-02-01T09:56:09Z

Airplane mode, camera access, and microphone access toggles work very well on Google Pixel devices. To bypass them, it would require an exploit that 99.99% of people will never be touched with in their lives.

---

## Post 66 by @TinFoilHat — 2025-02-01T17:28:02Z

> [@ignoramous](#):
>
> If the _Baseband_ chipset can control the mic

Hm I think what is more probable would be [Baseband-related vulns for RCE](https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html), Baseband is unlikely to have direct control over other phone hardware.

---

## Post 67 by @anon6848291 — 2025-02-01T18:56:48Z

Depends on SoC architecture and isolation. True for most modern devices. @ignoramous makes another relevant point here: [For those who don't eat and breathe this stuff, "basebands" are the processors t... | Hacker News](https://news.ycombinator.com/item?id=38618722#38620716)

---

## Post 69 by @Anon365 — 2025-02-18T00:38:21Z

Thoughts on using a faraday bag to keep a phone/other devices in when not in use?

---

## Post 70 by @fria — 2025-02-18T01:05:42Z

It really depends a lot on the brand they can have wildly different quality, and you likely don’t have the proper equipment to test it and make sure no signals are getting through.

> **[Matt Blaze: Testing Phone-Sized Faraday Bags](https://www.mattblaze.org/blog/faraday/)**

---

## Post 71 by @KevPham — 2025-02-27T20:36:12Z

> **[How to secure your phone before attending a protest](https://www.theverge.com/21276979/phone-protest-demonstration-activism-digital-how-to-security-privacy)**
>
> Here are some privacy measures you can take

The Verge had just updated their old protest security guide! I still think yours is a bit more comprehensive :blush:

---

## Post 72 by @ignoramous — 2025-03-02T19:30:28Z

> [@KevPham](#):
>
> still think yours is a bit more comprehensive

I’m sorry, both these “guides” are no where close to being “comprehensive”.

I personally know and work with activist journalists. Y’all will get someone jailed if you sell your version as “more comprehensive”.

---

## Post 73 by @phnx — 2025-03-02T20:00:16Z

“More comprehensive” is a relative term; it does not indicate any specific degree of comprehensiveness. Nothing is perfectly comprehensive.

If you are unhappy with the guide in its current state and have valuable insights to share, it would be more productive to suggest further changes.

---

## Post 74 by @Niek-de-Wilde — 2025-03-02T20:01:36Z

You can also kindly contribute with your wonderous insights instead of standing there and complaining about every single thing we publish :).

---

## Post 75 by @ignoramous — 2025-03-02T20:48:22Z

> [@Niek-de-Wilde](#):
>
> your wonderous insights instead of standing there and complaining about every single thing we publish

With such attitude, how are you folks still in the “mod” team? Despicable.

> [@Seeking Feedback: ActivistCheckist.org - digital security guides](https://discuss.privacyguides.net/t/seeking-feedback-activistcheckist-org-digital-security-guides/25147/8):
>
> I left some comments on Jonah’s article on GitHub (you may have to click “show resolved” to see some of those): [update(blog): Update protesters guide based on feedback by jonaharagon · Pull Request #2860 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/pull/2860)

> [@phnx](#):
>
> Nothing is perfectly comprehensive

Words mean things, no? If not, let’s throw the dictionary to the wolves. smh. [COMPREHENSIVE Definition & Meaning - Merriam-Webster](https://www.merriam-webster.com/dictionary/comprehensive)

---

## Post 76 by @Niek-de-Wilde — 2025-03-02T20:51:29Z

And did, or did we not include your feedback? :slight_smile:

---

## Post 77 by @ignoramous — 2025-03-03T00:26:10Z

You should ask Jonah if he even read the half of it.

If there was genuine effort here at all to be “comprehensive”, it is likely that it’d have taken a lifetime of work & review. Given it is a “basic” blog post as Jonah points out … it is totally okay (even if incomplete) in its current form. But to pass off this guide as “comprehensive” by the _Staff_ here is self-serving and diabolical (given the threats protestors face).

But all of it is besides the point… thar you’ve repeatedly second guessed and downplayed other people discussing here on this thread. And you don’t stop. That’s diabolical, too.

---

## Post 78 by @overdrawn98901 — 2025-03-03T13:58:30Z

> [@ignoramous](#):
>
> But to pass off this guide as “comprehensive” by the _Staff_ here is self-serving and diabolical (given the threats protestors face).

If we are being pedantic about the original term, it was said to be “more comprehensive”, not “comprehensive”, likely in place of saying “more detailed”. It wasn’t said it was comprehensive. The usage was relative, not precise. Perhaps another word should have been used as it leaves an assumption both are baseline comprehensive, and that the PG one is even more so. I get we should just words that correctly convey the right meaning, but I really don’t think the intent was that sinister.

> [@Niek-de-Wilde](#):
>
> You can also kindly contribute with your wonderous insights instead of standing there and complaining about every single thing we publish :).

Non staff will not always behave in the manner you expect, or even like, but how staff reacts to those situations determines the perception of the staff themselves. I don’t disagree with your frustration, but I also see ignoramous as a knowledgeable hot head.

---

## Post 79 by @Niek-de-Wilde — 2025-03-03T14:27:37Z

Oh I understand him completely and respect his knowledge, all I am trying to get at is that he can work on his way of bringing his point across, being overly negative and having an attitude.

I saw that he left some feedback, which i really appriciate, and I know we have improved the guide based on multiple feedback points that we got. If he still sees things which he believes are missing, he is free to again point it out.

Edit: my first message was more hostile then needed, I have edited it to tone it down.

---

## Post 81 by @jonah — 2025-03-03T16:07:08Z

Guys… what are we trying to accomplish with this discussion? Can we just accept feedback and share knowledge instead of trying to litigate/debate who’s “right”?

---

## Post 82 by @overdrawn98901 — 2025-03-03T16:10:14Z

To go back to the confusion, I really think it’s tough to have a general guide for all protestors, when say a protestors really have wildly different threat models. I think the post is a good way to dip into a base line level of security and begin to understand what could impact users. I don’t think we should treat this as an end-all be-all guide. If the post leaves that ambiguous, it should be updated to clearly reflect that.

With that, it’s still good it exists, and I would definitely share it with people not in life or death threat models, and especially people who just wing it. I’d also share with protest coordinators and say “this is the START of what you all should be doing”.

---

## Post 83 by @TinFoilHat — 2025-03-03T16:26:35Z

Yeah I guess one of the main points @ignoramous trying to raise, is that PG should consider be explicit about this by emphasizing this guide is merely a starting point and is not “comprehensive”

I think the guide actually kind of already covered this by saying

> Like all of our guides, we are going to cover the general best practices and provide helpful tips, but your individual situation may be different. You should always research and plan according to what you specifically are doing

But maybe not as clear as @ignoramous expected.

Many protestors got flagged on scene and traced back to them for their online activities. Being a protester / activist, you need to separate your online / protest / real life identity. This is not something can be included in this guide, but crucial for your safety.

---

## Post 84 by @system — 2025-07-22T19:16:58Z

This topic was automatically closed after 180 days. New replies are no longer allowed.
