home | tags


A question on my usage of certain popular apps and ecosystems

tags: #intro #stay-safe

One of my students asked me this:

Can you tell me about the ecosystem of devices/tools/OS you use. I’m a bit curious about it from a cybersecurity perspective – you seem to avoid certain applications and solutions that are everywhere and many people use.

Specifically, he was asking about Google, Meta, and other SaaS stuff.

Let’s deal with the simplest ones first.

Github

I’m moving away from Github, in a non-urgent, as-and-when-I-get-time, manner. Github has done a lot for us, and I didn’t even think of moving when Microsoft bought it. But the whole AI thing – especially Microsoft pushing it so aggressively – has me a little ticked off.

For those who know what gitolite is, another reason is here.

I don’t see Github as a villain as big as Meta and such. In fact I still like the service. But it’s time to move on.

Microsoft

Other than Github, Microsoft has no role in my personal life. I haven’t had Windows at home since 1995 – and that’s not a typo. (Both my TCS and my Amrita accounts use Office 365, but I’m not paying for them and I don’t use them for personal emails and such).

Meta

I have no Facebook account nor an Instagram account.

I resisted using WhatsApp for several years until a family event forced me to install it, simply because it was required to communicate with various vendors. So I installed it on a second phone. That phone has no “contacts”.

Once that family event was over I didn’t completely stop using it, but it’s mostly either silent or off, and I check it very rarely. Which, naturally, means unless the phone is with me and switched on, I can’t take calls on that phone, and don’t see SMSes. I also don’t link it to a bank account or aadhaar or anything else.

(I do use it for things like Uber and IRCTC Rail Connect and the Cleartrip app etc – in fact, since the phone has very little personal info I am free to use any app that I suspect would normally be spying on my calls and SMSs! I also use it when I am forced to give a number to a shop or a service that I don’t want to get messages from.)

Anyone who wants me to respond in a more timely fashion will either use normal calls or SMS, or use Signal Messenger, on my main number. Even email is faster than Whatsapp, to reach me!

If you must use Whatsapp, use it for specific purposes (for example, I know someone whose housing society only communicates via whatsapp, so they have no choice), and do not read or acknowledge the usual “forwarded joke/cartoon/video” crap even from people you know. It is also good to deny Whatsapp access to your contacts.

Android actually allows you to have multiple “user profiles”, and that is even simpler – just install WA on that second profile. But remember you still need a second SIM card because you are protecting your primary phone number from the scourge of Whatsapp (so using the same number would be pointless).

In my case, I had to use a second phone because my primary phone is a Samsung. And for some reason, the privacy-hating people at Samsung decided that they would disable this very nice Android feature on their phones. They allow it on their tabs, but not on their phones. Needless to say, I did not know this when I bought that phone and equally needless to say my next phone is not going to be a Samsung. (Which means, for an anti-China nut like me, the choice is even more limited! Nothing seems to fit the bill (pun intended!))

You might be thinking that having a second phone is expensive, but it doesn’t have to be. Any phone that you were going to throw or give away when you buy a new one would be fine. It doesn’t have to have a lot of RAM or disk for just this and a few other apps.

Google

I have several rules for my primary Google mail account.

First, I check mail using Thunderbird on the laptop or Thunderbird on Android.

Second, I never log into my Android phone using my primary email. I create a throwaway one for each Android device I have. I definitely do not use it to watch youtube. (I only watch YouTube anonymously using the Librewolf browser).

Third, I never log into Google permanently using my web browser. I only login temporarily, using a dedicated browser profile, when I need to do something that can only be done on the website. (Most commonly, this is “report spam”, but sometimes also when I need to setup a mail rule, add a new mail label, etc. Another one is if I have to use google meet).

I also disable google’s smart features that they use to train their AI with. Google will try to scare you into not doing this by saying that if you do so you will also lose spell checking and grammar checking (and some other features I can’t remember) but since I don’t use the website for composing my emails anyway, this is not relevant. Thunderbird has its own spelling check, and if an email is really important I can compose the message in LibreOffice (which has grammar checking) and copy paste.

I also use Thunderbird on the laptop to pull emails off of their servers and store them on my local hard disk. Unfortunately, Thunderbird on the phone cannot do this. For technical people, you can use termux and mutt, and I do have that setup, but it’s painful to do it on a small screen/keyboard, thus I use it only in emergencies.

Attachments in emails

In the old days we used to say “don’t open attachments from unknown senders.” This has now changed. Even a known sender might be hacked or tricked into sending you a malicious attachment.

For many years I had a somewhat complex system in which any attachment that I would open in Thunderbird would actually get copied to a second user ID and be opened under that user ID (all done via ssh).

The rationale is that this user ID does not have any sensitive information, so if the incoming document was malicious and somehow managed to trick my PDF reader or my image viewer or my document editor into doing something nasty, it would not be able to do anything to my real files which are on my real user ID.

But this is way too complex for me to recommend to anybody except the most hardcore geeks! A better solution is to use flatpaks.

(I’m talking about Linux here, I don’t know anything about Windows.)

Installing my favorite PDF viewer (in my case, Okular), as a flatpak, allows me to use the command flatseal to allow the tool to access only certain directories. (Files explicitly chosen by the user, via “File -> Open”, are always allowed).

So even if somebody sends me a malicious PDF file, (PDFs contain JavaScript and can be executable), the code in the PDF file cannot read or write any other files.

Obviously, this is a lot simpler than using a second user ID, and achieves the same protections.


Sidenote: Having said that, I will mention for the technically-minded here that this method is not as obviously secure as the more complicated one.

Why? Well, you’ll often hear the phrase “security is inversely proportional to complexity”. This method relies upon certain relatively new features, with complex specifications and implementations, working correctly without any bugs or security holes in them. In contrast, my previous method (using a second userid) works on the simple principle of user-to-user separation, which has been a standard part of all Unix systems since the 1970s. There is absolutely no way that can go wrong.

Still, I think using flatpaks is a decent way to achieve this, for most people. Even I am warming to it for the simplicity of use.