New guide on secure communications

Secure communications

Make a communication plan

Explanation:

  • Why making a communication plan is the first step to secure communications.
  1. Who are you communicating with?
    • 1:1 communications
    • group communications
    • announcements to a larger private group
    • public announcements
  2. Do you need to communicate with people who don't have capacity for installing new tools or learning how to use them?
  3. Do you need to protect access to your communications platform?
    • Do you need to protect access with a password?
    • Do you need 2-factor authentication?
  4. Do you need synchronous or asynchronous communications?
    • What do you need asynchronous communications for?
    • What do you need synchronous communications for?
  5. What level of confidentiality?
    • Can these communications be disclosed to anyone or is it important to keep them restricted?
    • What would happen if these contents were disclosed to a larger public?
    • What would happen if the authorities wanted to access your communications? What would happen if they succeded?
    • What would happen if the authorities learned whom you are communicating with?
  6. Do you need to keep a record of your communications?
  7. Do you need to access these communications both on computers and phones?
    • What operating systems are being used?
  8. Do you need to exchange just text messages or more?
    • files
    • voice messages
    • images
    • videos
    • audio calls
    • video calls
    • interactive video calls for webinars (whiteboard, slideshows, breakout rooms)...
  9. Do you need tech support?
  10. What's your budget for your communications tool?
  11. Can you self-host your communications platform/s?

Basic concepts

  • When is E2E encryption needed
  • When is TLS sufficient
    • Trust the server
    • or just need protection from criminals, not from provider or authorities
  • You can trust a provider, or you can trust the technology

The guiding model is minimizing threats to 3 crucial components of information security:

  • Confidentiality - protecting information from unauthorized access - explain traffic light protocol
  • Integrity - being sure that data hasn't been tampered with
  • Availability - data is accessible when you need it
Edited by Wojtek Bogusz