Digital Security for Citizens and Activists
Overview
This guide covers practical digital security measures for citizens, activists, organizers, and journalists. It does not require technical expertise — it is written for people who want to protect their communications, devices, and data without becoming security experts.
Audience: Citizens, activists, community organizers, journalists, anyone engaged in public advocacy Principle: Perfect security is unattainable. The goal is to raise the cost of surveillance enough that it protects against opportunistic monitoring and most government access.
Emergency Reference Card
| Threat | Immediate Action |
|---|---|
| Phone seized by police at a protest | Do not provide your passcode. Say “I assert my Fifth Amendment right.” Contact lawyer. |
| You believe your communications are monitored | Switch to Signal immediately. Assume anything on unencrypted channels has been read. |
| Crossing a US border | Power off your phone before crossing. Decline to provide passcode. Contact EFF for guidance. |
| You receive a legal demand for your data | Contact EFF (eff.org) or a lawyer before complying with anything. |
| Social media account compromised | Enable 2FA on all accounts immediately. Change passwords. Revoke connected apps. |
Part I: Your Threat Model
Before choosing security tools, think about your threat model — who is likely to be interested in your communications and what level of access they have.
Level 1: Basic Protection (Most People)
Threats: Data brokers, targeted ads, casual surveillance, hackers, doxxers Recommended: Strong passwords, 2FA, basic encrypted messaging, location awareness
Level 2: Activist / Organizer
Threats: Law enforcement monitoring, corporate surveillance, hostile individuals, doxxing campaigns Recommended: Signal, secure email, VPN, device encryption, compartmentalization
Level 3: High-Risk (Journalists, Whistleblowers, Lawyers in Sensitive Cases)
Threats: Sophisticated law enforcement surveillance, national security apparatus, state-level actors Recommended: All Level 2 tools + operational security, physical security, Tor, SecureDrop Note: If you are at Level 3, consult the Methodology — Source Protection and work with a security trainer
Part II: Device Security
Passwords and Biometrics
Use a strong PIN or passcode, not biometrics, for your phone’s lock screen.
Why this matters: Courts have ruled that you can be compelled to unlock your phone with your fingerprint or face (biometrics), because these are “non-testimonial.” Your PIN is different — the Fifth Amendment provides stronger protection against being compelled to provide a password you know.
Best practices:
- Use a 6+ digit PIN (not 4 digits) or alphanumeric passcode on your phone
- Disable Face ID and Touch ID before crossing a border or attending a high-risk event
- On iOS: Settings > Face ID & Passcode > turn off Face ID/Touch ID for unlocking
- On Android: Settings > Security > disable fingerprint and face unlock
Phone Encryption
Good news: All modern smartphones are encrypted by default.
- iOS devices are encrypted when you set a passcode (since iOS 8)
- Android devices have been encrypted by default since Android 6.0 (2015)
What this means: If police seize your phone and cannot obtain your passcode, the contents are inaccessible.
Device Software Updates
Keep your phone and computer software updated. Most successful hacking exploits target vulnerabilities that have already been patched in updates.
Laptop Security
- Enable full-disk encryption:
- Mac: FileVault (System Preferences > Security & Privacy > FileVault)
- Windows: BitLocker (search “BitLocker” in Start menu)
- Linux: Use LUKS (typically enabled at installation)
- Use a strong login password — not biometric-only
- Set auto-lock to activate after 1–5 minutes of inactivity
- Enable the firewall on your operating system
Part III: Encrypted Messaging
Signal
Signal is the gold standard for encrypted messaging and calls. It is used by journalists, lawyers, human rights workers, and security professionals worldwide.
Why Signal:
- End-to-end encrypted: only you and your recipient can read messages
- Open source and audited by security researchers
- Minimal metadata collection (Signal cannot see who you talk to or when)
- Available on iOS and Android (free)
- Note Messages and voice calls are both encrypted
Setup:
- Download Signal from the App Store or Google Play
- Register with your phone number (Signal uses phone numbers for identity)
- Enable disappearing messages (Settings > Privacy > Default Timer) — 1 week for most conversations
- Enable registration lock (Settings > Account > Registration Lock) — prevents someone from hijacking your number
- Enable Screen Security (iOS) or Screen Lock (Android) in Signal settings
When to use Signal:
- Sensitive organizing conversations
- Communications with sources (if journalist)
- Legal discussions with attorneys
- Any conversation you would not want read in a courtroom
Limitation: If the person you’re messaging has a compromised device, your messages are compromised regardless of Signal’s encryption.
Other Encrypted Messaging Apps
| App | Encryption | Metadata | Recommended Use |
|---|---|---|---|
| Signal | End-to-end (E2E) | Minimal | Primary secure messaging |
| E2E (Signal protocol) | Extensive metadata collected by Meta | Use for contacts who won’t use Signal; not for high-risk communications | |
| iMessage | E2E between Apple devices | Apple stores some metadata | Acceptable for low-risk communication between Apple users; not for high-risk |
| Telegram | NOT end-to-end by default | Metadata collected | Do not use for sensitive communication. “Secret Chats” are E2E but regular chats are not. |
| SMS / Text | Not encrypted | Metadata collected by carriers | Do not use for anything sensitive |
Encrypted Voice and Video Calls
Signal also encrypts voice and video calls. Standard phone calls are not encrypted and can be intercepted. If you need a secure call, use Signal.
Part IV: Email Security
The Reality About Email
Standard email (Gmail, Outlook, Yahoo, etc.) is NOT end-to-end encrypted. Your email provider can read your emails, and they are subject to government subpoenas. Law enforcement routinely obtains email records.
ProtonMail
ProtonMail is an end-to-end encrypted email service based in Switzerland.
- Free tier available at proton.me
- Emails between ProtonMail users are end-to-end encrypted
- Emails to non-ProtonMail users are standard (not E2E encrypted) but can be password-protected
- ProtonMail cannot read your emails (zero-knowledge architecture)
- Subject to Swiss law, which provides stronger privacy protections than US law
Use for: Sensitive communications with legal teams, organizational planning, source communications
Gmail and Google Workspace
Google can read your Gmail. Google complies with government subpoenas and warrants.
If you use Gmail for organizing, be aware:
- Law enforcement can obtain your email with a warrant
- Google may comply with emergency requests without a warrant in some circumstances
- Enable 2-Step Verification at minimum (accounts.google.com/security)
PGP Encryption
PGP (Pretty Good Privacy) can encrypt emails sent through any email provider, but it is complex to use correctly. Unless you have technical guidance, use ProtonMail instead.
Part V: Virtual Private Networks (VPNs)
What a VPN Does and Does Not Do
A VPN does:
- Encrypt your internet traffic between your device and the VPN server
- Hide your browsing from your internet service provider (ISP)
- Hide your IP address from websites you visit
- Help on public Wi-Fi where networks may be monitored
A VPN does NOT:
- Make you anonymous online
- Protect you if you are logged into your accounts
- Encrypt your communications (Signal does that)
- Prevent law enforcement from obtaining records from the VPN provider with a warrant
Choosing a VPN
- Use a VPN with a no-logs policy that has been independently audited
- Recommended: Mullvad (accepts cash, no account required), ProtonVPN (strong privacy policy), IVPN
- Avoid free VPNs — many sell your browsing data
- Understand that the VPN provider can still be subpoenaed if they keep logs
When to Use a VPN
- On public Wi-Fi at coffee shops, hotels, airports
- When you want to prevent your ISP from seeing your browsing activity
- When accessing information you prefer not to be associated with your IP address
Part VI: Social Media Hygiene
What Law Enforcement Can Access
Law enforcement can obtain from social media platforms with a warrant or subpoena:
- All public and private posts
- Direct messages
- Account registration information (email, phone, IP addresses)
- Location check-ins and tagged photos
- Who you follow and who follows you
- Login activity and IP addresses
Assume that anything you post on social media can eventually be seen by law enforcement.
Account Security
- Enable two-factor authentication (2FA) on all accounts — use an authenticator app (not SMS)
- Use a strong, unique password for each account (use a password manager: Bitwarden, 1Password)
- Review which apps have access to your social media accounts (Settings > Apps) and revoke unnecessary ones
- Review your account’s “active sessions” and revoke any unrecognized devices
What to Post and Not Post
Think before posting:
- Photos or videos taken at sensitive locations can reveal location metadata
- Photos of other activists at protests may expose them to identification
- Posts about future plans for civil disobedience may be used as evidence of intent
- Even deleted posts can be subpoenaed if platforms retain them
Strip metadata from photos before posting:
- iOS: Use a privacy app like Metapho to remove EXIF data
- Android: Use Photo Metadata Remover (free)
- Desktop: Use ExifTool (free, command-line) or Metadata Anonymisation Toolkit (MAT2)
Creating Separate Activist Accounts
Some activists maintain separate social media accounts for sensitive advocacy work, using a pseudonym and separate email. If you do this:
- Create the account from a network not linked to your home (coffee shop, public library)
- Use a ProtonMail address for registration, not your personal email
- Do not mix content — never log into both accounts from the same device simultaneously
- Understand this does not provide legal protection from subpoenas
Part VII: Location Data
Your Phone’s Location
Your phone generates location data constantly:
- Cell tower data: Your carrier tracks which towers your phone connects to (available to law enforcement via court order or IMSI catcher / “stingray” devices)
- GPS data: Apps with location permission track your precise location
- Wi-Fi data: Your phone logs nearby Wi-Fi networks even when not connected
- Apps: Many apps continuously collect location data (often sold to data brokers)
Reducing Location Exposure
- Turn off location services for most apps: Settings > Privacy > Location Services — set most apps to “Never” or “While Using”
- Disable precise location for social media apps
- Consider leaving your phone behind for sensitive meetings — or bring a “burner” phone with no accounts
- Disable Bluetooth when not in use — Bluetooth signals can be used for tracking
- Use airplane mode in sensitive contexts — this disables all radio signals
At a Protest
- If you are concerned about IMSI catchers (surveillance tools that mimic cell towers), the most effective countermeasure is turning off your phone or using a phone that is not registered to you
- At minimum, set your phone to airplane mode and use Signal over Wi-Fi (enable Wi-Fi calling in Signal settings)
Part VIII: Browsing and Web Privacy
Standard Browser Privacy
All major browsers offer some privacy features:
- Use private/incognito mode to avoid local tracking (does not hide activity from ISP or government)
- Install privacy extensions: uBlock Origin (ad/tracker blocking), Privacy Badger (EFF), HTTPS Everywhere
Tor Browser
Tor routes your internet traffic through multiple relays, making it much harder to link your browsing to your identity.
Download: torproject.org (free)
Use for: Anonymous browsing, accessing resources without revealing your identity, using .onion sites (like SecureDrop)
Limitations:
- Slower than regular browsing
- Some websites block Tor exit nodes
- Does not protect you if you log into accounts linked to your identity
- Not appropriate for large file downloads
Operational Security
- Do not search for sensitive information while logged into personal accounts
- Use Tor or a VPN when researching sensitive topics
- Clear browser history and cookies after sensitive research sessions, or use a browser set to clear everything on close
Part IX: The Border Crossing Scenario
When crossing a US border, CBP (Customs and Border Protection) has broad authority to search your devices without a warrant at the border.
Before Crossing
- Back up your data to an encrypted cloud service
- Delete sensitive communications and documents from your device (or use a travel device with minimal data)
- Turn off biometric unlock — use PIN only
- Log out of all apps and services
- Consider bringing a separate “travel phone” with minimal data
At the Border
- You are not legally required to provide your device passcode to CBP
- Refusing to provide it can result in your device being seized and detained
- If you refuse, you may be detained for additional questioning
- If you are a US citizen, you cannot be denied entry for refusing to provide a passcode (though devices may be seized)
- Non-citizens risk more serious consequences — consult an immigration attorney for guidance
After seizure: Contact EFF (eff.org) or a lawyer before your next border crossing.
Part X: If Your Phone Is Seized
- Do not provide your passcode — assert Fifth Amendment rights
- Document: when, where, by whom, what device(s) were taken, any paperwork provided
- Contact a lawyer before providing any access
- Report the seizure to EFF (eff.org/know-your-rights) and document the facts
- Change all passwords for accounts accessible on that device
- Alert people whose communications were on the device
- Revoke sessions for accounts on the device from another device
Additional Resources
| Organization | Focus | Contact |
|---|---|---|
| Electronic Frontier Foundation | Digital rights, surveillance law | eff.org |
| Access Now | Digital security help for activists | accessnow.org — Digital Security Helpline |
| EFF’s Surveillance Self-Defense | Comprehensive security guides | ssd.eff.org |
| Freedom of the Press Foundation | Journalist digital security | freedom.press |
| Center for Democracy and Technology | Policy and digital rights | cdt.org |
