Every day, internet users share personal information, communicate through digital platforms, and rely on online services without fully understanding the security risks involved. Journalists, activists, researchers, community organisers, and even ordinary users increasingly face threats such as phishing attacks, account compromise, device theft, online harassment, surveillance, data breaches, and AI-enabled scams.
Open source is not only about software development; it is also about empowering people with tools that promote autonomy, privacy, security, and freedom. Digital security is a critical component of digital rights and digital self-determination.
While awareness of digital threats has grown, practical digital security skills remain inaccessible to most people. Existing training resources are often highly technical, proprietary, or designed for specialist audiences. By introducing participants to practical security practices through open-source tools and community-driven resources, this workshop aligns with IndiaFOSS's broader vision of strengthening digital commons, promoting user freedom, and building resilient technology communities.
This workshop seeks to bridge that gap through a practical, beginner to intermediate-friendly, and open-source-focused introduction to digital security. Participants will learn how to identify common digital threats, assess their personal risk, and implement simple but effective security measures using Free and Open Source Software (FOSS) tools.
Drawing on SFLC.in's experience in providing digital security assistance and training to over 12,000 journalists, human rights defenders, civil society organisations, and vulnerable communities across India, this session will provide practical skills that attendees can immediately apply in their personal and professional lives.
Workshop Structure:
Part 1: Understanding Digital Threats (20 Minutes)
How digital attacks happen
Real-world examples from India
Surveillance, phishing, account takeovers, and data breaches
Threat modelling for ordinary users and journalists
Part 2: Account Security Essentials (25 Minutes)
Password hygiene and common mistakes
Introduction to password managers
Multi-factor authentication
Hands-on exercise: strengthening account security
Part 3: Spotting and Defeating Phishing (20 Minutes)
Anatomy of phishing attacks
AI-generated scams and impersonation attempts
Identifying malicious emails, messages, and links
Interactive phishing detection exercise
Part 4: Secure Communication and Privacy (20 Minutes)
End-to-end encrypted communication
Metadata and privacy considerations
Practical comparison of common messaging platforms
Using privacy-respecting alternatives
Part 5: Device Security Basics (20 Minutes)
Mobile phone security
Laptop security essentials
Updates, backups, encryption, and safe browsing
Practical security checklist
Part 6: Open-Source Security Toolkit (15 Minutes)
Participants will be introduced to a curated set of FOSS tools and resources, including: