Preparing for election-related security issues

Martin Shelton

Principal Researcher

“The Unblinking Eye” by Darron Birgenheier (CC BY SA 2.0)

It’s the Digital Security Training team at Freedom of the Press Foundation (FPF), with security news that keeps you, your sources, and your devices safe. If someone has shared this newsletter with you, please subscribe here.

In the news

Throughout this year, our digital security training team will share our thoughts on navigating security issues during the 2024 election season. Elections around the world experience distinct security issues that may change from year to year, but in the U.S. we look to 2020 for lessons on how to get ahead of likely issues, from surveillance of our sensitive communications to perennial phishing attacks and harassment for political reporting. Read our first 2024 election security roundtable to learn more.

What you can do

  • We often encourage journalists to think ahead of time about how our personal identities, as well as the coverage we produce, will impact the likelihood of experiencing digital attacks and harassment. The preparation looks different for everyone. You may be dealing with particularly elevated risk if you are doing politically sensitive reporting (e.g., concerning extremist groups) or work in volatile situations in the field, including covering the protests that many expect. We should be prepared, so we can approach these situations with more confidence. If your team is not currently talking about how to organize for expected reporting later in the year, now’s a great time to build coalitions and get started strategizing. If you are looking for help, reach out to our team here.
  • To begin learning how to mitigate against the security concerns you’d like to prioritize for this year, check out our guides and resources.

We are always ready to assist journalists with digital security concerns. Reach out here, and stay safe and secure out there.

Best,
Martin

Donate to support press freedom

Your support is more important than ever.

Read more about Digital Security Digest

Bill expands US spying powers

Last week, Congress reauthorized a controversial surveillance authority, Section 702 of the Foreign Intelligence Surveillance Act. While legislators considered reforms to FISA that would restrain the federal intelligence and law enforcement community’s abilities to spy on American communications without a warrant, they in fact expanded these surveillance powers to subject more electronic communications service providers, such as U.S. cloud computing data centers, to data collection.

Apple warns iPhone users of targeted malware

On April 10, Apple sent users in 92 countries warning of mercenary malware attacks targeting the iPhone. The notification did not provide details about the identities of the attackers. According to TechCrunch, Apple warned, “This attack is likely targeting you specifically because of who you are or what you do. Although it’s never possible to achieve absolute certainty when detecting such attacks, Apple has high confidence in this warning — please take it seriously.”

Google to delete old Chrome Incognito data

Following a class-action lawsuit over Google’s handling of user data in its Chrome browser’s “Incognito” private browsing mode, the search company will expunge “billions of event-level data records that reflect class members’ private browsing activities” improperly collected before January 2024. It also updated its Incognito landing page to highlight that even Google can discern your activities in private browsing mode. Additionally, the company will be required to delete data that makes users’ private browsing data personally identifiable, such as IP addresses.