New guide on secure communications
Secure communications
Make a communication plan
Explanation:
- Why making a communication plan is the first step to secure communications.
- Who are you communicating with?
- 1:1 communications
- group communications
- announcements to a larger private group
- public announcements
- Do you need to communicate with people who don't have capacity for installing new tools or learning how to use them?
- Do you need to protect access to your communications platform?
- Do you need to protect access with a password?
- Do you need 2-factor authentication?
- Do you need synchronous or asynchronous communications?
- What do you need asynchronous communications for?
- What do you need synchronous communications for?
- What level of confidentiality?
- Can these communications be disclosed to anyone or is it important to keep them restricted?
- What would happen if these contents were disclosed to a larger public?
- What would happen if the authorities wanted to access your communications? What would happen if they succeded?
- What would happen if the authorities learned whom you are communicating with?
- Do you need to keep a record of your communications?
- Do you need to access these communications both on computers and phones?
- What operating systems are being used?
- Do you need to exchange just text messages or more?
- files
- voice messages
- images
- videos
- audio calls
- video calls
- interactive video calls for webinars (whiteboard, slideshows, breakout rooms)...
- Do you need tech support?
- What's your budget for your communications tool?
- Can you self-host your communications platform/s?
Basic concepts
- When is E2E encryption needed
- When is TLS sufficient
- Trust the server
- or just need protection from criminals, not from provider or authorities
- You can trust a provider, or you can trust the technology
The guiding model is minimizing threats to 3 crucial components of information security:
- Confidentiality - protecting information from unauthorized access - explain traffic light protocol
- Integrity - being sure that data hasn't been tampered with
- Availability - data is accessible when you need it
Edited by Wojtek Bogusz