[Paper Review] Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong
This study investigates information security practices among participants in Hong Kong's 2019 Anti-Extradition Law Amendment Bill protests through in-depth interviews with 11 activists. It reveals that protesters relied heavily on Telegram and WhatsApp for secure, decentralized communication, used pseudonymity and device compartmentalization, and developed collective strategies for detecting compromises and achieving forward secrecy—particularly through remote message deletion and offline onboarding—while group administrators emerged as de facto leaders in leaderless movements.
The Anti-Extradition Law Amendment Bill protests in Hong Kong present a rich context for exploring information security practices among protesters due to their large-scale urban setting and highly digitalised nature. We conducted in-depth, semi-structured interviews with 11 participants of these protests. Research findings reveal how protesters favoured Telegram and relied on its security for internal communication and organisation of on-the-ground collective action; were organised in small private groups and large public groups to enable collective action; adopted tactics and technologies that enable pseudonymity; and developed a variety of strategies to detect compromises and to achieve forms of forward secrecy and post-compromise security when group members were (presumed) arrested. We further show how group administrators had assumed the roles of leaders in these 'leaderless' protests and were critical to collective protest efforts.
Motivation & Objective
- To understand the information security needs and practices of participants in large-scale, urban protest movements, particularly in high-risk digital environments.
- To investigate how protesters negotiate security in decentralized, leaderless movements where trust and anonymity coexist with operational coordination.
- To identify the role of digital platforms like Telegram and WhatsApp in enabling secure, collective action amid state surveillance and arrest risks.
- To explore how protesters detect and respond to compromises, especially following arrests, and how they achieve forward secrecy and post-compromise security.
- To inform the design of secure messaging tools by identifying real-world security requirements and tensions between anonymity, confidentiality, and group coordination.
Proposed method
- Conducted in-depth, semi-structured interviews with 11 participants from the Hong Kong Anti-ELAB protests to gather grounded insights on security practices.
- Used inductive thematic analysis to synthesize findings into five core categories: tool adoption, organizational roles, compromise detection, workarounds for tool limitations, and security negotiation processes.
- Focused on real-world practices such as remote message deletion, use of burner phones, and offline onboarding to assess perceived and actual security outcomes.
- Mapped communication patterns across small private groups (for trust and secrecy) and large public groups (for anonymity and mobilization).
- Analyzed how group administrators exercised leadership in decentralized movements, despite the absence of formal hierarchies.
- Evaluated the perceived effectiveness of tactics like anonymous polls and live location sharing in enabling collective decision-making and tactical coordination.
Experimental results
Research questions
- RQ1How do protesters in large-scale urban protests like Hong Kong’s Anti-ELAB movement select and use digital communication tools for collective action?
- RQ2What strategies do protesters employ to detect and respond to compromises, especially when group members are arrested?
- RQ3How do participants balance conflicting security needs such as anonymity in public groups and confidentiality in private groups?
- RQ4In what ways do group administrators function as leaders in ostensibly leaderless protest movements?
- RQ5What are the perceived and actual limitations of existing messaging platforms in supporting collective information security in high-risk environments?
Key findings
- Participants predominantly used Telegram and WhatsApp for internal communication, citing their end-to-end encryption and group functionality as key reasons for adoption.
- Protesters organized in a dual structure of small private groups (for trust and secrecy) and large public groups (for anonymity and mobilization), each with distinct security needs.
- Remote message deletion was widely seen as critical for post-compromise security, especially when members were arrested, to prevent evidence from being retrieved from devices.
- A rigorous offline onboarding process was used to verify new members and reduce the risk of infiltration, demonstrating a collective approach to trust-building.
- Participants developed tactics such as using multiple devices and burner phones to maintain pseudonymity and compartmentalize identities across different protest roles.
- Despite the absence of formal leadership, group administrators emerged as de facto leaders, coordinating decisions through anonymous polls and managing group participation, highlighting the paradox of leadership in leaderless movements.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.