mirror of
https://github.com/privacyguides/i18n.git
synced 2025-06-21 18:24:22 +00:00
New Crowdin translations by GitHub Action
This commit is contained in:
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Da in Mull im Vergleich zu den meisten Browsern standardmäßig ein erweiterter
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
Unter iOS [muss](https://developer.apple.com/app-store/review/guidelines) jede App, auf welcher man im Web surfen kann, das [WebKit-Framework](https://developer.apple.com/documentation/webkit) von Apple zu verwenden. Es gibt deshalb wenig Gründe, den Browser eines Drittanbieters zu verwenden.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ Wir empfehlen die Installation von [AdGuard](browser-extensions.md#adguard), wen
|
||||
|
||||
Die folgenden datenschutz- und sicherheitsrelevanten Optionen findest du unter :gear: **Einstellungen** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Suche
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Indem du die Suchvorschläge deaktivierst, kannst du präziser kontrollieren, welche Daten an den Suchmaschinenanbieter gesendet werden.
|
||||
|
||||
#### Profile
|
||||
|
||||
Safari ermöglicht es, dein Browsing mit verschiedenen Profilen zu trennen. Alle deine Cookies, dein Verlauf und deine Website-Daten werden für jedes Profil separat gespeichert. Du solltest verschiedene Profile für verschiedene Zwecke verwenden, z. B. Einkaufen, Arbeit oder Schule.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
Mit dieser Einstellung kannst du deine privaten Tabs bei Nichtgebrauch mit Biometrie/PIN sperren.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Andere Datenschutzeinstellungen
|
||||
|
||||
Diese Optionen sind zu finden unter :gear: **Einstellungen** → **Apps** → **Safari** → **Erweitert**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Αναζήτηση
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Η απενεργοποίηση των προτάσεων αναζήτησης σας επιτρέπει να ελέγχετε με μεγαλύτερη ακρίβεια τα δεδομένα που στέλνετε στον πάροχο της μηχανής αναζήτησης.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Debido a que Mull tiene protecciones más avanzadas y estrictas activadas por de
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
En iOS, cualquier aplicación que puede navegar en internet está [limitada](https://developer.apple.com/app-store/review/guidelines) a utilizar un sistema que provee Apple, [llamado WebKit](https://developer.apple.com/documentation/webkit), por lo que hay pocos motivos para utilizar un navegador de terceros.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ Te sugerimos instalar [AdGuard](browser-extensions.md#adguard) si quieres un blo
|
||||
|
||||
Las siguientes opciones relacionadas con la privacidad y la seguridad se encuentran en :gear: **Ajustes** → **Aplicaciones** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Buscar
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Desactivar las sugerencias de búsqueda te permite controlar con mayor precisión los datos que envías al proveedor de tu motor de búsqueda.
|
||||
|
||||
#### Perfiles
|
||||
|
||||
Safari te permite separar tu navegación con diferentes perfiles. Todas tus cookies, historial y datos del sitio web están separados para cada perfil. Deberías utilizar diferentes perfiles para diferentes propósitos, por ejemplo, ir de compras, trabajar o uso escolar.
|
||||
@ -263,6 +280,32 @@ Esto habilita la [Protección de Seguimiento Inteligente](https://webkit.org/tra
|
||||
|
||||
Este ajuste te permite bloquear tus pestañas privadas detrás de los datos biométricos/PIN cuando no las estés utilizando.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Otros Ajustes de Privacidad
|
||||
|
||||
Estas opciones se encuentran en :gear: **Ajustes** → **Aplicaciones** → **Safari** → **Avanzado**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### جستجو
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. غیرفعال کردن پیشنهادهای جستجو به شما اجازه میدهد که با دقت بیشتری کنترل کنید که چه دادههایی را به ارائهدهنده موتور جستجو ارسال میکنید.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Les protections de la vie privée activées par défaut sur Mull étant plus ava
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
Sur iOS, toute application capable de naviguer sur le web est [](https://developer.apple.com/app-store/review/guidelines) limitée à l'utilisation du cadre WebKit [fourni par Apple](https://developer.apple.com/documentation/webkit), de sorte qu'il y a peu de raisons d'utiliser un navigateur web tiers.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Recherche
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. La désactivation des suggestions de recherche vous permet de contrôler plus précisément les données que vous envoyez à votre fournisseur de moteur de recherche.
|
||||
|
||||
#### Profils
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
ב-iOS, כל אפליקציה שיכולה לגלוש באינטרנט [מוגבלת](https://developer.apple.com/app-store/review/guidelines) לשימוש ב[מסגרת WebKit](https://developer.apple.com/documentation/webkit), כך שאין סיבה קטנה להשתמש בדפדפן אינטרנט של צד שלישי.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### חיפוש
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. השבתת הצעות חיפוש מאפשרת לך לשלוט בצורה מדויקת יותר באילו נתונים אתה שולח לספק מנועי החיפוש שלך.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Poiché Mull ha attivato come impostazione predefinita protezioni della privacy
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
Su iOS, qualsiasi app che possa navigare sul web è [limitata](https://developer.apple.com/app-store/review/guidelines) all'utilizzo di un [quadro WebKit](https://developer.apple.com/documentation/webkit) fornito da Apple, quindi, non ci sono molti motivi per utilizzare un browser web di terze parti.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Ricerca
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabilitare i suggerimenti di ricerca ti consente di controllare più precisamente quali dati invii al fornitore del tuo motore di ricerca.
|
||||
|
||||
#### Profili
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### 検索
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. 検索提案機能を無効にすることで、検索エンジンプロバイダーに送信するデータを、より正確に制御することができます。
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
iOS에서는 웹 브라우징이 가능한 모든 앱이 Apple에서 제공하는 [Webkit 프레임워크](https://developer.apple.com/documentation/webkit)를 사용하도록 [강제되기 때문에](https://developer.apple.com/app-store/review/guidelines), 타사 웹 브라우저를 사용할 이유가 거의 없습니다.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### 검색
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. 검색 제안을 비활성화하여 검색 엔진 제공 업체에 전송하는 데이터를 보다 신중하게 조절할 수 있습니다.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
Op iOS is elke app die op het web kan surfen beperkt tot [](https://developer.apple.com/app-store/review/guidelines) het door Apple geleverde [WebKit framework](https://developer.apple.com/documentation/webkit), dus er is weinig reden om een webbrowser van een derde partij te gebruiken.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Zoeken
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Door zoeksuggesties uit te schakelen, kun je nauwkeuriger bepalen welke gegevens je naar jouw zoekmachineprovider stuurt.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
W systemie iOS każda aplikacja, która umożliwia przeglądanie Internetu [ma obowiązek](https://developer.apple.com/app-store/review/guidelines) korzystać z [platformy WebKit](https://developer.apple.com/documentation/webkit) dostarczonej przez Apple, więc nie ma zbyt wielu powodów na używanie zewnętrznych przeglądarek.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Wyszukiwarka
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Wyłączenie sugestii wyszukiwania pozwala bardziej precyzyjnie kontrolować dane wysyłane do dostawcy wyszukiwarki.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Pesquisa
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Desabilitar sugestões de busca permite que você controle com mais precisão quais dados você envia para o seu provedor de mecanismo de pesquisa.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
No iOS, qualquer aplicação que possa navegar na Web está [limitada](https://developer.apple.com/app-store/review/guidelines) à utilização de uma estrutura WebKit fornecida pela Apple [](https://developer.apple.com/documentation/webkit), pelo que não há nenhuma vantagem em utilizar um navegador diferente de outro fornecedor.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Pesquisa
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. A desativação das sugestões de pesquisa permite-lhe controlar com maior precisão os dados que envia ao seu fornecedor de motores de pesquisa.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
На iOS любое приложение, которое может открывать веб-страницы, [использует](https://developer.apple.com/app-store/review/guidelines) только предоставляемый Apple [движок WebKit](https://developer.apple.com/documentation/webkit), поэтому нет особых причин использовать сторонний браузер.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Поиск
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Отключение поисковых предложений позволяет более точно контролировать данные, которые вы отправляете поисковой системе.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Eftersom att Mull har mer avancerade och strikta integritetsskyddsinställningar
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
I iOS är alla appar som kan surfa på webben [](https://developer.apple.com/app-store/review/guidelines) begränsade till att använda Apples WebKit-ramverk [WebKit](https://developer.apple.com/documentation/webkit), så det finns få skäl att använda en tredjepartswebbläsare.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiler
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### Search
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. Disabling search suggestions allows you to more precisely control what data you send to your search engine provider.
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
@ -7,7 +7,7 @@ description: 完整的貢獻者名單,這些貢獻者共同對 Privacy Guides
|
||||
|
||||
<!-- Do NOT manually edit this file, please add yourself to the .all-contributorsrc file instead. See our GitHub Issues for more details -->
|
||||
|
||||
本專案遵循 [all-contributors](https://github.com/all-contributors/all-contributors) 規範。 歡迎將**各種**類型的貢獻添加到[此列表](https://github.com/privacyguides/privacyguides.org/blob/main/.all-contributorsrc),包括對 Privacy Guides 的存儲庫外部貢獻,與內容無關的貢獻(例如分享想法、推廣項目、在論壇上回答問題等)。
|
||||
本專案遵循 [all-contributors](https://github.com/all-contributors/all-contributors) 規範。 歡迎將**各種**類型的貢獻添加到[此列表](https://github.com/privacyguides/privacyguides.org/blob/main/.all-contributorsrc),包括對 Privacy Guides 的儲存庫外部貢獻,與內容無關的貢獻(例如分享想法、推廣項目、在論壇上回答問題等)。
|
||||
|
||||
| 表情符號 | 類別 | 敘述 |
|
||||
| ---- | ------------- | ------------------------------------------------------------------------------ |
|
||||
|
@ -13,7 +13,7 @@ PrivacyTools.io 建立了一個信譽良好的網站和一系列服務後,這
|
||||
|
||||
PrivacyTools 由 BurungHantu 於 2015年創建,在斯諾登洩密事件後,他希望建立一個隱私資源的有用工具。 該網站成長為一個蓬勃發展的開源專案,有 [許多貢獻者](https://github.com/privacytools/privacytools.io/graphs/contributors),某些最終賦予各種組織職責,例如運營 Matrix 和 Mastodon 等線上服務,管理和審查 GitHub網站變更,為項目尋找贊助商,撰寫部落格文章和運營 Twitter 等社交媒體外展平臺等。
|
||||
|
||||
從2019年開始, BurungHantu 與網站和社區的積極發展越來越疏遠,並開始推遲運營服務器的相關付款。 為避免本站系統管理員自掏腰包支付網站的伺服器成本,我們自[2019年10月31日起變動](https://web.archive.org/web/20210729184557/https://blog.privacytools.io/privacytools-io-joins-the-open-collective-foundation)了網頁上的捐款方式,從過去 BurungHantu 私人的 l PayPal 與加密貨幣帳戶改成 OpenCollective 帳戶。 這有額外的好處,使財務完全透明,這是我們堅信的價值,並且在美國可以免稅,因為它們由 Open Collective Foundation 501 (c) 3 持有。 這一變化得到了團隊的一致同意,沒有爭議。
|
||||
從2019年開始, BurungHantu 與網站和社區的積極發展越來越疏遠,並開始推遲運營伺服器的相關付款。 為避免本站系統管理員自掏腰包支付網站的伺服器成本,我們自[2019年10月31日起變動](https://web.archive.org/web/20210729184557/https://blog.privacytools.io/privacytools-io-joins-the-open-collective-foundation)了網頁上的捐款方式,從過去 BurungHantu 私人的 l PayPal 與加密貨幣帳戶改成 OpenCollective 帳戶。 這有額外的好處,使財務完全透明,這是我們堅信的價值,並且在美國可以免稅,因為它們由 Open Collective Foundation 501 (c) 3 持有。 這一變化得到了團隊的一致同意,沒有爭議。
|
||||
|
||||
## 為什麼我們要繼續前進
|
||||
|
||||
|
@ -14,13 +14,13 @@ description: 簡介常見的即時通訊應用程式網路架構。
|
||||
|
||||
集中式信使是指所有參與者都在同一伺服器或同一組織所控制的伺服器網路。
|
||||
|
||||
有些自託管信使允許設置自己的伺服器。 自託管可以提供額外的隱私保證,例如不用記錄或限制讀取元數據(關於誰與誰交談的資料)。 自託管的集中式信使是隔離的,每個人都必須在同一個伺服器上進行通信。
|
||||
有些自託管信使允許設定自己的伺服器。 自託管可以提供額外的隱私保證,例如不用記錄或限制讀取元數據(關於誰與誰交談的資料)。 自託管的集中式信使是隔離的,每個人都必須在同一個伺服器上進行通訊。
|
||||
|
||||
**優點**
|
||||
|
||||
- 新功能和變更可以更快地實施。
|
||||
- 更容易使用和查找聯系人。
|
||||
- 近乎成熟和穩定的生態系統,因為集中式軟件更容易編程。
|
||||
- 近乎成熟和穩定的生態系統,因為集中式軟件更容易編譯。
|
||||
- 當您信任自我託管的伺服器時,隱私問題可能會減少。
|
||||
|
||||
**缺點**
|
||||
@ -37,7 +37,7 @@ description: 簡介常見的即時通訊應用程式網路架構。
|
||||
|
||||
聯合信使使用多個獨立的分散式伺服器,這些伺服器能夠彼此通訊(電子郵件是聯合服務的一個例子)。 聯邦讓系統管理員控制自己的伺服器,成為更大通訊網路中的一員。
|
||||
|
||||
當自行託管時,聯邦伺服器的成員可以發現並與其他伺服器的成員進行通信,而有些伺服器可能會選擇保持私密而不加入聯邦(例如工作團隊伺服器)。
|
||||
當自行託管時,聯邦伺服器的成員可以發現並與其他伺服器的成員進行通訊,而有些伺服器可能會選擇保持私密而不加入聯邦(例如工作團隊伺服器)。
|
||||
|
||||
**優點**
|
||||
|
||||
|
@ -136,7 +136,7 @@ Apple不提供用於建立加密DNS設定檔的原生介面。 [Secure DNS profi
|
||||
|
||||
確定瀏覽活動的最簡單方法可能是查看您的設備正在訪問的 IP 位址。 例如,如果觀察者知道 `privacyguides.org` 位於 `198.98.54.105`,而您的裝置正在請求 `198.98.54.105`的數據,則很有可能您正在訪問隱私指南。
|
||||
|
||||
此方法僅在 IP 位址屬於僅託管少數網站的伺服器時才有用。 如果網站託管在共享平臺(例如 Github Pages , Cloudflare Pages , Netlify , WordPress , Blogger等),它就不太有用。 如果服務器託管在 [反向代理](https://en.wikipedia.org/wiki/Reverse_proxy)之後,這也不是很有用,這在現代互聯網上非常常見。
|
||||
此方法僅在 IP 位址屬於僅託管少數網站的伺服器時才有用。 如果網站託管在共享平臺(例如 Github Pages , Cloudflare Pages , Netlify , WordPress , Blogger等),它就不太有用。 如果伺服器託管在 [反向代理](https://en.wikipedia.org/wiki/Reverse_proxy)之後,這也不是很有用,這在現代網路上非常常見。
|
||||
|
||||
### 伺服器名指示(SNI)
|
||||
|
||||
@ -347,7 +347,7 @@ graph TB
|
||||
|
||||
DNSSEC 簽署過程類似於無法仿製的個人獨特簽名於法律文件,法院專家透過簽名驗證該文件效力須依據簽名的真假判定。 這些數位簽名確保資料不會被篡改。
|
||||
|
||||
DNSSEC 在所有 DNS 層中實施分級數位簽名政策。 例如,查詢 `privacyguides.org` ,根 DNS 伺服器將簽署尾綴 `.org` 伺服器密鑰,然後 `.org` 伺服器再簽署 `privacyguides.org`的授權名稱伺服器的密鑰。
|
||||
DNSSEC 在所有 DNS 層中實施分級數位簽名政策。 例如,查詢 `privacyguides.org` ,根 DNS 伺服器將簽署後綴 `.org` 伺服器金鑰,然後 `.org` 伺服器再簽署 `privacyguides.org`的授權名稱伺服器的金鑰。
|
||||
|
||||
<small>改編自 Google 的 [DNS 安全擴充 (DNSSEC) 概述](https://cloud.google.com/dns/docs/dnssec) 和 Cloudflare 提供的[DNSSEC:簡介](https://blog.cloudflare.com/dnssec- an -introduction),兩者皆以 [CC BY 4.0](https://creativecommons.org/licenses/by/4.0) 授權。</small>
|
||||
|
||||
|
@ -73,7 +73,7 @@ description: 您的購買習慣是用於廣告定位的絕佳資料,但在私
|
||||
|
||||
### 錢包保管
|
||||
|
||||
加密貨幣有兩種形式的錢包:託管錢包和非託管錢包。 託管錢包由集中式公司/交易所運營,錢包的私鑰由該公司持有,您可以使用用戶名和密碼從任何地方存取。 非託管錢包是您自己控制和管理錢包的私鑰。 假如可以保管好錢包的私鑰安全並備份,非保管錢包比保管錢包具有更大的安全性和審查抵抗力,因為您的加密貨幣不會被保管的公司竊取或凍結。 密鑰保管在隱私貨幣上尤其重要:保管錢包使運營公司能夠查看您的交易,否定了這些加密貨幣的隱私優勢。
|
||||
加密貨幣有兩種形式的錢包:託管錢包和非託管錢包。 託管錢包由集中式公司/交易所運營,錢包的私鑰由該公司持有,您可以使用用戶名和密碼從任何地方存取。 非託管錢包是您自己控制和管理錢包的私鑰。 假如可以保管好錢包的私鑰安全並備份,非保管錢包比保管錢包具有更大的安全性和審查抵抗力,因為您的加密貨幣不會被保管的公司竊取或凍結。 金鑰保管在隱私貨幣上尤其重要:保管錢包使運營公司能夠查看您的交易,否定了這些加密貨幣的隱私優勢。
|
||||
|
||||
### 取得
|
||||
|
||||
|
@ -8,7 +8,7 @@ description: Tor 是一個免費使用的去中心化網路,其讓用戶在使
|
||||
|
||||
[Tor </strong>](../alternative-networks.md#tor)是一個免費使用的去中心化網路,其讓用戶在使用網際網路之際盡可能地保護自己的隱私。 如果使用得當,該網路可以實現私人和匿名瀏覽和通訊。 很難阻止和追蹤 Tor 流量,因此它是一種有效的審查規避工具。
|
||||
|
||||
Tor 的工作原理是通過志願者運營的服務器來引導您的網際網路路徑,而不是直接連接到您試圖訪問的網站。 這樣可以混淆流量來源,所連接的伺服器都無法看到流量來去的完整路徑,也意味著即使您連接的伺服器無法破壞您的匿名性。
|
||||
Tor 的工作原理是通過志願者運營的伺服器來引導您的網際網路路徑,而不是直接連接到您試圖訪問的網站。 這樣可以混淆流量來源,所連接的伺服器都無法看到流量來去的完整路徑,也意味著即使您連接的伺服器無法破壞您的匿名性。
|
||||
|
||||
[:octicons-home-16:](https://torproject.org){ .card-link title=首頁 }
|
||||
[:simple-torbrowser:](http://2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion){ .card-link title="洋蔥服務" }
|
||||
@ -145,15 +145,15 @@ Tor 網路並非在任何情況下都是完美的隱私保護工具,其存在
|
||||
|
||||
## 加密
|
||||
|
||||
Tor 使用來自出口,中間和入口節點的密鑰對每個封包(傳輸數據區塊)依序進行三次加密。
|
||||
Tor 使用來自出口,中間和入口節點的金鑰對每個封包(傳輸數據區塊)依序進行三次加密。
|
||||
|
||||
一旦 Tor 構建了電路,數據傳輸將按照以下方式進行:
|
||||
|
||||
1. 首先:當數據包到達入口節點時,第一層加密被移除。 在這個加密封包中,入口節點將找到另一個具有中間節點地址的加密封包。 然後,入口節點將將封包轉發到中間節點。
|
||||
|
||||
2. 其次:當中間節點從入口節點接收到封包時,它也會利用其密鑰刪除一層加密,找到具有出口節點地址的加密數據包。 然後中間節點將數據包轉發到出口節點。
|
||||
2. 其次:當中間節點從入口節點接收到封包時,它也會利用其金鑰刪除一層加密,找到具有出口節點位址的加密資料包。 然後中間節點將數據包轉發到出口節點。
|
||||
|
||||
3. 最後:當退出節點收到其數據包時,它將使用其密鑰移除最後一層加密。 出口節點將看到目的地地址,並將封包轉發到該地址。
|
||||
3. 最後:當退出節點收到其資料包時,它將使用其金鑰移除最後一層加密。 出口節點將看到目的地地址,並將封包轉發到該地址。
|
||||
|
||||
下面是顯示此過程的圖表。 每個節點都會移除自己的加密層,當目的地伺服器傳回數據時,同樣過程會再反向發生。 例如,出口節點不知道你是誰,但它確實知道封包來自哪個節點,因此添加了自己的加密層並將其發送回來。
|
||||
|
||||
@ -189,7 +189,7 @@ Tor 橋接器通常被認為是向 ISP 隱藏 Tor 使用情況的替代方法,
|
||||
|
||||
對比我們所推薦的場景,透過 VPN 連接到 Tor。 假設 4 個月後,您的 ISP 再次想要識別 4 個月前使用過 Tor 的任何人。 他們的日誌幾乎肯定可以識別 4 個月前的流量,他們可能僅能看到所連接的 VPN IP 位址。 大多數 ISP 僅長期保留元數據,而不是您要求的流量完整內容。 儲存全部流量資料需要大量空間,而幾乎所有威脅行為者都不具備這種能力。
|
||||
|
||||
ISP 肯定不會截取所有資料包級資料與將其永久存儲,他們*無法利用深度資料包檢查等先進技術* 來確認通過VPN 連接的內容,因此你有合理的推諉能力。
|
||||
ISP 肯定不會截取所有資料包級資料與將其永久儲存,他們*無法利用深度資料包檢查等先進技術* 來確認通過VPN 連接的內容,因此你有合理的推諉能力。
|
||||
|
||||
因此,橋接器在規避網路審查時提供了最大的好處,但*目前*它們還未能充分取代**所有</em >結合使用 VPN 和 Tor 的好處。 再次強調,這並不是*反對*使用 Tor 橋接器,但在做出決定時應該了解其限制。 在某些情況下,橋接器可能是*唯一*選項(例如,如果所有VPN 提供者都被封鎖),因此您仍然可以在這些情況下使用它們,但請記住此限制。</p>
|
||||
|
||||
|
@ -97,7 +97,7 @@ Snowflake 無法加強隱私,也不會在個人瀏覽器中連接 Tor 網路
|
||||
|
||||
</div>
|
||||
|
||||
不同於 Tor ,所有 I2P 流量都是 I2P 網路內部的,這意味著常規互聯網網站**不能**直接從 I2P 存取。 相反,可以連接到直接在 I2P 網路上匿名託管的網站,這些網站稱為“eepsites”,並且具有以“.i2p”結尾的網域。
|
||||
不同於 Tor ,所有 I2P 流量都是 I2P 網路內部的,這意味著常規網站**不能**直接從 I2P 存取。 相反,可以連接到直接在 I2P 網路上匿名託管的網站,這些網站稱為“eepsites”,並且具有以“.i2p”結尾的網域。
|
||||
|
||||
<div class="admonition example" markdown>
|
||||
<p class="admonition-title">試用一下!</p>
|
||||
|
@ -66,7 +66,7 @@ GrapheneOS 支援 [沙盒化 Google Play](https://grapheneos.org/usage#sandboxed
|
||||
|
||||
[Google Pixel系列](../mobile-phones.md#google-pixel) 是目前唯一符合 GrapheneOS [硬體安全要求](https://grapheneos.org/faq#future-devices) 的裝置。
|
||||
|
||||
預設情況下,Android 會與 Google 進行許多網路連線,以執行 DNS 連線檢查、同步目前的網路時間、檢查您的網路連線,以及其他許多背景工作。 GrapheneOS 不這麼做,他們通過讓作業系統與由其團隊所擁有的伺服器通信來完成上述工作,這些伺服器遵守他們的隱私權政策 這能向 [Google](.../basics/common-threats.md#privacy-from-service-providers) 隱藏您的資訊(例如:IP位置),但這意味著您的網路管理員或 ISP 的很容易看到您正在連線到 `grapheneos.network`、`grapheneos.org` 等,並推斷出您使用的作業系統。
|
||||
預設情況下,Android 會與 Google 進行許多網路連線,以執行 DNS 連線檢查、同步目前的網路時間、檢查您的網路連線,以及其他許多背景工作。 GrapheneOS 不這麼做,他們通過讓作業系統與由其團隊所擁有的伺服器通訊來完成上述工作,這些伺服器遵守他們的隱私權政策 這能向 [Google](.../basics/common-threats.md#privacy-from-service-providers) 隱藏您的資訊(例如:IP位置),但這意味著您的網路管理員或 ISP 的很容易看到您正在連線到 `grapheneos.network`、`grapheneos.org` 等,並推斷出您使用的作業系統。
|
||||
|
||||
如果您想要隱藏類似此類的資訊,以避免被您網路上或 ISP 上的對手發現,除了將連線檢查設定變更為 **Standard (Google)** 之外,您還 **必須** 使用 [可信賴的 VPN](../vpn.md)。 它可以在 :gear: **設定** → **網路與網際網路** → **Internet connectivity checks** 中找到. 此選項可讓您連線至 Google 伺服器進行連線檢查,加上 VPN 的使用,可協助您混入更多的 Android 裝置中。
|
||||
|
||||
|
@ -7,7 +7,7 @@ description: 創建帳戶為實際連線網際網路所必要,請採取下列
|
||||
|
||||
人們經常不假思索地註冊網路服務。 這些帳號也許是一個串流媒體服務可觀看人人都在談論的新節目,或是取得喜歡的快餐店折扣。 無論在什麼樣的場景,您都應該考慮現在和以後對個資的影響。
|
||||
|
||||
在新的服務申請帳號時,都伴著相關風險。 資料洩露;向第三方披露客戶資訊、員工有不當的權限可以訪問所有資料,在給出您的個資時都必須考慮的接下來可能的狀況。 您需要確信足夠信任該服務,這就是為什麼我們建議把重要資料儲放在最成熟且通過測試的產品。 這通常意味著提供 E2EE 並經過加密審計的服務。 審計增加了產品設計的保證,減低因開發人員缺乏經驗所導致的安全問題。
|
||||
在新的服務申請帳號時,都伴著相關風險。 資料洩露;向第三方披露客戶資訊、員工有不當的權限可以訪問所有資料,在給出您的個資時都必須考慮的接下來可能的狀況。 您需要確信足夠信任該服務,這就是為什麼我們建議把重要資料儲存在最成熟且通過測試的產品。 這通常意味著提供 E2EE 並經過加密審計的服務。 審計增加了產品設計的保證,減低因開發人員缺乏經驗所導致的安全問題。
|
||||
|
||||
某些網路服務並不容易刪除帳號 有時可能會 [覆寫與帳戶相關聯的資料](account-deletion.md#overwriting-account-information) ,但在其他情況下,該服務將保留帳戶變更的完整記錄。
|
||||
|
||||
@ -66,7 +66,7 @@ OAuth 是一種驗證協定可在註冊服務時無須對供應商分享註冊
|
||||
|
||||
OAuth 在那些服務之間深度整合情況下,可以特別有用。 我們建議將 OAuth 限制在需要的地方,用 [MFA](multi-factor-authentication.md)來保護主帳戶。
|
||||
|
||||
所有使用 OAuth 的服務都將與您的基礎提供商帳戶一樣安全。 例如,想用硬體密鑰保護某個帳戶,但該服務不支持硬體密鑰,則可用硬體密鑰保護您的 OAuth 帳戶,現在您所有帳戶基本上都有硬體 MFA。 但值得注意的是,OAuth 帳戶的弱認證意味著與該登入方式相關的其它帳戶也會很弱。
|
||||
所有使用 OAuth 的服務都將與您的基礎提供商帳戶一樣安全。 例如,想用實體安全金鑰保護某個帳戶,但該服務不支援實體安全金鑰,則可用實體安全金鑰保護您的 OAuth 帳戶,現在您所有帳戶基本上都有硬體 MFA。 但值得注意的是,OAuth 帳戶的弱認證意味著與該登入方式相關的其它帳戶也會很弱。
|
||||
|
||||
使用* Google 登入*、*Facebook* 或其他服務時還有額外的危險,通常是OAuth 流程允許*雙向*資料共享。 例如,使用 Twitter 帳戶登入論壇可授予該論壇存取權限,以便在您的 Twitter 帳戶上執行操作,例如發佈、閱讀您的訊息或存取其他個人資料。 OAuth 提供者通常會向您提供要授予外部服務存取權限的內容列表,應確保仔細閱讀該列表,不會無意中授予外部服務存取不需要的任何內容的權限。
|
||||
|
||||
|
@ -13,7 +13,7 @@ schema:
|
||||
acceptedAnswer:
|
||||
"@type": Answer
|
||||
text: |
|
||||
是否公開原始碼以及軟體的授權方式本身並不會影響其安全性。 開源軟體有可能比專有軟體更安全,但絕對不能保證一定如此。 評估軟體時,應該根據個別情況來評估每個工具的聲譽和安全性。
|
||||
是否公開原始碼以及軟體的授權方式本身並不會影響其安全性。 開源軟體有可能比專有軟體更安全,但絕對不能保證一定如此。 評估軟體時,應該根據個別情況來評估每個工具的名譽和安全性。
|
||||
-
|
||||
"@type": Question
|
||||
name: 將信任轉移到另一個提供者可以增加隱私嗎?
|
||||
@ -40,7 +40,7 @@ schema:
|
||||
|
||||
## 「開源軟體永遠是安全的」或「專有軟體更安全」
|
||||
|
||||
這些迷思源於許多偏見,但原始碼是否開放以及軟體的許可並不會以任何方式影響其安全性。 ==開源軟體*可能*比專有軟體更安全,但不能保證絕對如此。== 在評估軟體時,應逐個檢視每個工具的聲譽和安全性。
|
||||
這些迷思源於許多偏見,但原始碼是否開放以及軟體的許可並不會以任何方式影響其安全性。 ==開源軟體*可能*比專有軟體更安全,但不能保證絕對如此。== 在評估軟體時,應逐個檢視每個工具的名譽和安全性。
|
||||
|
||||
開源軟體*可以*由第三方審查,並且在潛在漏洞這一方面比專有軟體更加透明。 它還可以讓您檢閱程式碼,並自行停用任何可疑的功能。 然而,*除非您真的這樣做了*,否則不能保證程式碼曾經被審查過,尤其是較小的軟體項目。 公開的開發程序有時也會被利用—用以引入新的漏洞,稱為 [:material-package-variant-closed-remove: 供應鏈攻擊](common-threats.md#attacks-against-certain-organizations ""){.pg-viridian} ,我們的 [常見威脅](common-threats.md) 頁面會進一步討論。[^1]
|
||||
|
||||
|
@ -130,14 +130,14 @@ description: 您的威脅模型雖說是個人的事,但它也是本站許多
|
||||
|
||||
顯而易見的問題是,服務提供商(或破壞伺服器的駭客)可以隨時隨地訪問您的對話,而您永遠不會知道。 這適用於許多常見的服務,例如 SMS 訊息、Telegram 和 Discord。
|
||||
|
||||
慶幸的是, E2EE 可以加密您與收件人之間的通信,甚至在訊息送到伺服器之前,緩解此問題。 假設服務提供商無法訪問任何一方的私鑰,您的訊息保密性得到保證。
|
||||
慶幸的是, E2EE 可以加密您與收件人之間的通訊,甚至在訊息送到伺服器之前,緩解此問題。 假設服務提供商無法訪問任何一方的私鑰,您的訊息保密性得到保證。
|
||||
|
||||
<div class="admonition note" markdown>
|
||||
<p class="admonition-title">Web 加密備註提醒</p>
|
||||
|
||||
實際上,不同 E2EE 操作的效力各不相同。 應用程式,例如 [Signal](../real-time-communication.md#signal),會在您的裝置上原生執行,且此應用程式在不同設備的安裝上都是如此。 如果服務提供商在他們的應用程序中引入[後門](https://zh.wikipedia.org/wiki/Backdoor_(computing)) ----試圖竊取您的私鑰----它稍後可以通過[逆向工程](https://zh.wikipedia.org/wiki/Reverse_engineering)檢測。
|
||||
實際上,不同 E2EE 操作的效力各不相同。 應用程式,例如 [Signal](../real-time-communication.md#signal),會在您的裝置上原生執行,且此應用程式在不同設備的安裝上都是如此。 如果服務提供商在他們的應用程式中植入[後門](https://zh.wikipedia.org/wiki/Backdoor_(computing)) ----試圖竊取您的私鑰----它稍後可以通過[逆向工程](https://zh.wikipedia.org/wiki/Reverse_engineering)偵測。
|
||||
|
||||
另一方面,基於網頁的 E2EE 實作,例如 Proton Mail 的網頁應用程式或 Bitwarden 的 *Web Vault* ,則依賴伺服器動態提供 JavaScript 程式碼給瀏覽器來處理加密。 惡意伺服器可以針對您發送惡意 JavaScript 代碼以竊取您的加密密鑰(這將非常難以察覺)。 因為伺服器可以選擇為不同的人提供不同的網頁用戶端,即使您注意到攻擊也很難證明提供商有罪。
|
||||
另一方面,基於網頁的 E2EE 實作,例如 Proton Mail 的網頁應用程式或 Bitwarden 的 *Web Vault* ,則依賴伺服器動態提供 JavaScript 程式碼給瀏覽器來處理加密。 惡意伺服器可以針對您發送惡意 JavaScript 代碼以竊取您的加密金鑰(這將非常難以察覺)。 因為伺服器可以選擇為不同的人提供不同的網頁用戶端,即使您注意到攻擊也很難證明提供商有罪。
|
||||
|
||||
因此,您應該盡可能使用原生軟體程式多於網頁客戶端。
|
||||
|
||||
@ -211,7 +211,7 @@ description: 您的威脅模型雖說是個人的事,但它也是本站許多
|
||||
|
||||
對企業平臺的審查越來越普遍,如Twitter 和 Facebook 等平臺屈服於公眾需求、市場和政府機構的壓力。 政府對企業的施壓可能是隱蔽的,例如白宮私下 [要求拿掉](https://nytimes.com/2012/09/17/technology/on-the-web-a-fine-line-on-free-speech-across-globe.html) 某個勯動的 Youtube 影片,或是公開者如中國政府命令企業要遵循嚴厲的審查制度。
|
||||
|
||||
關注審查威脅的人可以使用像 [Tor](../advanced/tor-overview.md) 這樣的技術來規避它,並支持像 [Matrix](../real-time-communication.md#element)這樣的抗審查通信平臺,該平臺沒有可以任意關閉帳戶的集中帳戶權限。
|
||||
關注審查威脅的人可以使用像 [Tor](../advanced/tor-overview.md) 這樣的技術來規避它,並支援像 [Matrix](../real-time-communication.md#element)這樣的抗審查通訊平臺,該平臺沒有可以任意關閉帳戶的集中帳戶權限。
|
||||
|
||||
<div class="admonition tip" markdown>
|
||||
<p class="admonition-title">溫馨提示</p>
|
||||
|
@ -15,7 +15,7 @@ description: 從許多方面來看電子郵件本質上是不安全的,這也
|
||||
|
||||
還有另一種標準被稱為 [S/MIME](https://en.wikipedia.org/wiki/S/MIME),但它需要由 [憑證機構](https://en.wikipedia.org/wiki/Certificate_authority) 頒發的憑證(並非所有憑證都發行S/MIME憑證)。 [Google Workplace](https://support.google.com/a/topic/9061730) 和[Outlook Web 或 Exchange Server 2016、2019 版](https://support.office.com/article/encrypt-messages-by-using-s-mime-in-outlook-on-the-web-878c79fc-7088-4b39-966f-14512658f480)可用加密訊息。
|
||||
|
||||
即使您使用OpenPGP ,它也不支持 [向前保密](https://en.wikipedia.org/wiki/Forward_secrecy),這意味著如果您或收件人的私鑰被盜,所有先前加密的消息都將被曝光。 這就是為什麼我們建議 [即時通訊](../real-time-communication.md) ,只要有可能,就實現電子郵件的前向保密性,以進行個人對個人的通信。
|
||||
即使您使用OpenPGP ,它也不支援 [向前保密](https://en.wikipedia.org/wiki/Forward_secrecy),這意味著如果您或收件人的私鑰被盜,所有先前加密的消息都將被曝光。 這就是為什麼我們建議 [即時通訊](../real-time-communication.md) ,只要有可能,就實現電子郵件的前向保密性,以進行個人對個人的通信。
|
||||
|
||||
## Web Key Directory 網頁金鑰目錄標準介紹
|
||||
|
||||
@ -25,13 +25,13 @@ description: 從許多方面來看電子郵件本質上是不安全的,這也
|
||||
|
||||
如果使用自訂網域,則需另外設定 WKD。 如果你可控制自定域名,則無論電子郵件提供者為何,都可以設定 WKD。 一個簡單的方法是使用 [WKD as a Service](https://keys.openpgp.org/about/usage#wkd-as-a-service) 功能,透過指向`wkd.keys.openpgp.org` 網域的`openpgpkey` 子網域來設定CNAME記錄,然後將金鑰上傳到 [keys.openpgp.org](https://keys.openpgp.org) 。 或者你可以 [在自己的 Web 伺服器搭建 WKD](https://wiki.gnupg.org/WKDHosting) 。
|
||||
|
||||
如使用不支援 WKD 供應商的共用網域(例如 @gmail.com),則無法透過此方法與其他人共用你的 OpenPGP 密鑰。
|
||||
如使用不支援 WKD 供應商的共用網域(例如 @gmail.com),則無法透過此方法與其他人共用你的 OpenPGP 金鑰。
|
||||
|
||||
### 哪些郵件客戶端支持 E2EE?
|
||||
|
||||
電子郵件服務供應商讓您能使用標準訪問協議如 IMAP 與SMTP,以便應用[我們推薦的電子郵件客戶端軟體](../email-clients.md)。 根據驗證方法的不同,如果提供者或電子郵件用戶端不支持OAT或橋接應用程序,這可能會導致安全性降低,因為 [多因素驗證](multi-factor-authentication.md) 在純密碼驗證中是不可能的。
|
||||
|
||||
### 我要怎樣保護自己的私密鑰匙?
|
||||
### 我該如何保護自己的私鑰?
|
||||
|
||||
智慧卡(例如 [YubiKey](https://support.yubico.com/hc/articles/360013790259-Using-Your-YubiKey-with-OpenPGP) 或 [Nitrokey](../security-keys.md#nitrokey) )的工作原理是透過執行 電子郵件/網頁郵件 客戶端的裝置(手機、平板電腦、電腦等)接收加密的電子郵件訊息。 智慧卡會解密該訊息再把解開的內容傳到設備。
|
||||
|
||||
@ -41,7 +41,7 @@ description: 從許多方面來看電子郵件本質上是不安全的,這也
|
||||
|
||||
電子郵件中繼資料儲存在電子郵件的 [個訊息標題](https://en. wikipedia. org/wiki/Email#Message_header) 中,並包含您可能已經看到的一些可見標題,例如: `To`、 `From`、 `Cc`、 `Date`、 `Subject`。 許多電子郵件客戶端和提供商還包含一些隱藏的標題,可以揭示有關您的帳戶的信息。
|
||||
|
||||
客戶端軟體可能會使用電子郵件中繼資料來顯示來自誰以及收到訊息的時間。 服務器可以使用它來確定電子郵件消息必須發送的位置,其中 [個其他目的](https://en.wikipedia.org/wiki/Email#Message_header) 並不總是透明的。
|
||||
客戶端軟體可能會使用電子郵件中繼資料來顯示來自誰以及收到訊息的時間。 伺服器可以使用它來確定電子郵件消息必須發送的位置,其中 [個其他目的](https://en.wikipedia.org/wiki/Email#Message_header) 並不總是透明的。
|
||||
|
||||
### 誰可以查看電子郵件中繼資料?
|
||||
|
||||
|
@ -15,7 +15,7 @@ description: 隱私保護不能僅聚焦於軟體方面;了解您每天使用
|
||||
有些裝置會有「硬體安全認證」,例如在設計硬體時,廠商之間會就最佳實務和建議進行合作:
|
||||
|
||||
- [Windows 安全核心電腦](https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-highly-secure-11) 符合 Microsoft 指定的更高安全性標準。 這些保護並不只適用於 Windows 使用者;其他作業系統的使用者仍可利用其 [DMA 保護](https://learn.microsoft.com/en-us/windows/security/information-protection/kernel-dma-protection-for-thunderbolt) 以及 完全不信任 Microsoft 證書 等功能。
|
||||
- [Android Ready SE](https://developers.google.com/android/security/android-ready-se) 是廠商之間的合作,以確保其裝置遵循 [最佳實踐](https://source.android.com/docs/security/best-practices/hardware) ,並包含基於硬體的可防篡改儲存設備,例如加密金鑰。
|
||||
- [Android Ready SE](https://developers.google.com/android/security/android-ready-se) 是廠商之間的合作,以確保其裝置遵循 [最佳實踐](https://source.android.com/docs/security/best-practices/hardware) ,並包含基於硬體的可防篡改儲存裝置,例如加密金鑰。
|
||||
- 在 Apple SoC 上執行的 macOS 可利用 [硬體安全性](../os/macos-overview.md#hardware-security) ,第三方作業系統可能無法使用此類功能。
|
||||
- [ChromeOS 的安全性](https://chromium.org/chromium-os/developer-library/reference/security/security-whitepaper) 在 Chromebook 上可發揮最佳效果,因為它能利用可用的硬體功能,例如 [硬體信任根](https://chromium.org/chromium-os/developer-library/reference/security/security-whitepaper/#hardware-root-of-trust-and-verified-boot) 。
|
||||
|
||||
@ -63,7 +63,7 @@ Android 為生物辨識定義了三種 [安全等級](https://source.android.com
|
||||
|
||||
### 裝置加密
|
||||
|
||||
如果您的裝置已進行 [加密](../encryption.md) ,在裝置完全關機 (而非僅是睡眠狀態) 時,也就是在您第一次輸入加密金鑰或鎖屏密碼之前,您的資料是最安全的(相較於其他狀態)。 在手機上,這種較高安全性的狀態稱為 “Before First Unlock(首次解鎖之前)(BFU)”,而一旦您在重新開機/開機後輸入正確密碼,則稱為 “After First Unlock(首次解鎖之後)(AFU)”。 相較於 BFU,AFU 對於數位鑑識工具套件和其他攻擊的防禦能力要低得多。 因此,如果您擔心攻擊者可以實體存取您的裝置(即 可直接取得您的設備實體 ),您應該在不使用裝置時將其關機。
|
||||
如果您的裝置已進行 [加密](../encryption.md) ,在裝置完全關機 (而非僅是睡眠狀態) 時,也就是在您第一次輸入加密金鑰或鎖定螢幕密碼之前,您的資料是最安全的(相較於其他狀態)。 在手機上,這種較高安全性的狀態稱為 “Before First Unlock(首次解鎖之前)(BFU)”,而一旦您在重新開機/開機後輸入正確密碼,則稱為 “After First Unlock(首次解鎖之後)(AFU)”。 相較於 BFU,AFU 對於數位鑑識工具套件和其他攻擊的防禦能力要低得多。 因此,如果您擔心攻擊者可以實體存取您的裝置(即 可直接取得您的設備實體 ),您應該在不使用裝置時將其關機。
|
||||
|
||||
這可能不切實際,所以請考慮是否值得;但無論如何,只要您使用強大的加密金鑰,即使是 AFU 模式也能有效對抗大多數威脅。
|
||||
|
||||
@ -71,11 +71,11 @@ Android 為生物辨識定義了三種 [安全等級](https://source.android.com
|
||||
|
||||
有些威脅單靠您的內部元件無法防範。 這些選項中有許多都是高度情境性的;請評估您的威脅模型是否真的需要這些選項。
|
||||
|
||||
### 硬體安全金鑰
|
||||
### 實體安全金鑰
|
||||
|
||||
硬體金鑰是使用強大加密技術來驗證您的設備或帳戶的裝置。 其原理是:由於金鑰無法被複製,您可以使用金鑰來保護帳戶,使帳戶只有在實際擁有金鑰的情況下才能被存取,從而消除許多遠端攻擊。
|
||||
硬體金鑰是使用強大加密技術來驗證您的裝置或帳戶的裝置。 其原理是:由於金鑰無法被複製,您可以使用金鑰來保護帳戶,使帳戶只有在實際擁有金鑰的情況下才能被存取,從而消除許多遠端攻擊。
|
||||
|
||||
[建議的硬體金鑰 :material-arrow-right-drop-circle:](../security-keys.md){ .md-button .md-button--primary } [了解更多有關硬體金鑰的事 :material-arrow-right-drop-circle:](multi-factor-authentication.md#hardware-security-keys){ .md-button }
|
||||
[建議的實體金鑰 :material-arrow-right-drop-circle:](../security-keys.md){ .md-button .md-button--primary } [了解更多有關實體金鑰的事 :material-arrow-right-drop-circle:](multi-factor-authentication.md#hardware-security-keys){ .md-button }
|
||||
|
||||
### 相機/麥克風
|
||||
|
||||
|
@ -30,7 +30,7 @@ TOTP 是最常見的 MFA 形式之一。 當您設置TOTP時,您通常需要
|
||||
|
||||
然後,時間限制代碼從共享機密和當前時間衍生出來。 由於代碼僅在短時間內有效,無法訪問共享機密,因此對手無法生成新代碼。
|
||||
|
||||
如果持有支援 TOTP 的硬體安全金鑰(例如具有 [Yubico Authenticator](https://yubico.com/products/yubico-authenticator)的YubiKey ),建議將「共享機密」儲存在硬體上。 像 YubiKey 這類硬體就是為了讓“共享祕密”難以提取、複製而開發的工具。 YubiKey 也不會連接到網際網路,不像使用 TOTP 應用程式的手機。
|
||||
如果持有支援 TOTP 的實體安全金鑰(例如具有 [Yubico Authenticator](https://yubico.com/products/yubico-authenticator)的YubiKey ),建議將「共享機密」儲存在硬體上。 像 YubiKey 這類硬體就是為了讓“共享祕密”難以提取、複製而開發的工具。 YubiKey 也不會連接到網際網路,不像使用 TOTP 應用程式的手機。
|
||||
|
||||
與 [WebAuthn](#fido-fast-identity-online)不同, TOTP 無法應對 [網路釣魚](https://en.wikipedia.org/wiki/Phishing) 或重複使用攻擊。 如果對手從您身上取得有效的登錄碼,他們可以隨意多次使用它,直到過期(通常是60秒)。
|
||||
|
||||
@ -38,7 +38,7 @@ TOTP 是最常見的 MFA 形式之一。 當您設置TOTP時,您通常需要
|
||||
|
||||
儘管未瑧完美,但TOTP 對於大多數人已足夠安全,且無[硬體安全金鑰](../security-keys.md)支援時,[驗證應用程式](../multi-factor-authentication.md)仍然是不錯的選擇。
|
||||
|
||||
### 硬體安全金鑰
|
||||
### 實體安全金鑰
|
||||
|
||||
YubiKey 將資料存在防纂改的強固晶片, 除非運用先進實驗室等級的取證程序,一般非破壞方式[很難存取](https://security.stackexchange.com/a/245772) 。
|
||||
|
||||
@ -46,9 +46,9 @@ YubiKey 將資料存在防纂改的強固晶片, 除非運用先進實驗室
|
||||
|
||||
#### Yubico OTP
|
||||
|
||||
Yubico OTP 的驗證協議通常是執行在硬體安全金鑰上。 當決定使用 Yubico OTP 時,該密鑰將產生公用 ID ,私有 ID 和祕密密鑰,然後密鑰日上傳到 Yubico OTP 伺服器。
|
||||
Yubico OTP 的驗證協議通常是執行在實體安全金鑰上。 當決定使用 Yubico OTP 時,該密鑰將產生公用 ID ,私有 ID 和祕密金鑰,然後將密鑰上傳到 Yubico OTP 伺服器。
|
||||
|
||||
在登入網站時,需要做的就是實際觸摸安全金鑰。 安全金鑰將模擬鍵盤並將一次性密碼列印到密碼欄位中。
|
||||
在登入網站時,需要做的就是實際觸摸安全金鑰。 安全金鑰將模擬鍵盤並將一次性密碼輸入到密碼欄位中。
|
||||
|
||||
它會將一次性密碼轉發到 Yubico OTP 伺服器進行驗證。 在密鑰和 Yubico 驗證伺服器上的計數器都會迭加。 OTP 只能使用一次,當成功驗證後,計數器會增加,以防止重複使用 OTP。 Yubico 提供了此過程的 [詳細文件](https://developers.yubico.com/OTP/OTPs_Explained.html) 。
|
||||
|
||||
@ -74,7 +74,7 @@ WebAuthn是最安全、最私密的第二要素驗證形式。 雖然驗證體
|
||||

|
||||
</figure>
|
||||
|
||||
當您創建一個帳戶時,公鑰會發送到服務,然後當您登錄時,服務會要求您使用您的私鑰“簽署”一些數據。 這樣做的好處是,服務不會儲存密碼資料,因此對手無從竊取任何東西。
|
||||
當您創建一個帳戶時,公鑰會發送到服務,然後當您登錄時,服務會要求您使用您的私鑰“簽署”一些資料。 這樣做的好處是,服務不會儲存密碼資料,因此對手無從竊取任何東西。
|
||||
|
||||
這份簡報將討論密碼驗證的歷史、隱憂(例如密碼重複使用),以及 FIDO2 和 [WebAuthn](https://webauthn.guide) 的標準:
|
||||
|
||||
@ -84,7 +84,7 @@ WebAuthn是最安全、最私密的第二要素驗證形式。 雖然驗證體
|
||||
|
||||
對於 Web 服務,它通常與 WebAuthn 一起使用,WebAuthn 是[W3C 建議](https://en.wikipedia.org/wiki/World_Wide_Web_Consortium#W3C_recommendation_(REC))的一部分。 它使用公鑰驗證,並且比在 Yubico OTP 和 TOTP 使用的共享機密更安全,因為它在驗證期間包括原始名稱(通常是域名)。 提供證明以保護您免受網路釣魚攻擊,以幫助您確定使用真實服務而不是假網站服務。
|
||||
|
||||
與 Yubico OTP不同,WebAuthn不使用任何公共ID ,因此密鑰 **無法** 被不同網站識別。 它也不使用任何第三方雲端伺服器進行驗證。 所有通訊都已在密鑰和所登入的網站之間完成。 FIDO 還使用計數器,該計數器在使用時會增加,以防止期間重用和克隆密鑰。
|
||||
與 Yubico OTP不同,WebAuthn不使用任何公共ID ,因此金鑰 **無法** 被不同網站識別。 它也不使用任何第三方雲端伺服器進行驗證。 所有通訊都已在金鑰和所登入的網站之間完成。 FIDO 還使用計數器,該計數器在使用時會增加,以防止期間重用和複製金鑰。
|
||||
|
||||
如果網站或服務支援 WebAuthn 驗證,強烈建議您使用它而不是其他形式的 MFA。
|
||||
|
||||
@ -98,7 +98,7 @@ WebAuthn是最安全、最私密的第二要素驗證形式。 雖然驗證體
|
||||
|
||||
### 備份
|
||||
|
||||
您應該始終備份您的 MFA 方法。 硬體安全金鑰可能會丟失、被盜或隨著時間的推移而停止運作。 建議您擁有一對具有相同帳戶存取權限的硬體安全金鑰,而不僅僅是一個。
|
||||
您應該始終備份您的 MFA 方法。 實體安全金鑰可能會丟失、被盜或隨著時間的推移而停止運作。 建議您擁有一對具有相同帳戶存取權限的硬體安全金鑰,而不僅僅是一個。
|
||||
|
||||
使用TOTP 和驗證器應用程式時,請確保備份恢復金鑰或應用程式,或將"共享密文"複製到不同手機上的另一個應用程式實例或加密容器中(例如[VeraCrypt](../encryption.md#veracrypt-disk))。
|
||||
|
||||
@ -116,13 +116,13 @@ WebAuthn是最安全、最私密的第二要素驗證形式。 雖然驗證體
|
||||
|
||||
## 更多設定MFA的地方
|
||||
|
||||
除了保護您的網站登錄外,多因素身份驗證還可用於保護您的本地設備的登錄、 SSH 密鑰甚至密碼資料庫。
|
||||
除了保護您的網站登錄外,多因素身份驗證還可用於保護您的本機裝置的登錄、 SSH 金鑰甚至密碼資料庫。
|
||||
|
||||
### macOS
|
||||
|
||||
macOS 具有 [原生支援](https://support.apple.com/guide/deployment/intro-to-smart-card-integration-depd0b888248/web) 用於使用智慧卡(PIV)進行驗證。 如果您有支援 PIV 介面的智慧卡或硬體安全金鑰(例如 YubiKey) ,建議您遵循智慧卡/硬體安全供應商的文件,為您的macOS 電腦設定第二要素驗證。
|
||||
macOS 具有 [原生支援](https://support.apple.com/guide/deployment/intro-to-smart-card-integration-depd0b888248/web) 用於使用智慧卡(PIV)進行驗證。 如果您有支援 PIV 介面的智慧卡或實體安全金鑰(例如 YubiKey) ,建議您遵循智慧卡/實體安全供應商的文件,為您的macOS 電腦設定第二要素驗證。
|
||||
|
||||
Yubico 指南 [在macOS](https://support.yubico.com/hc/articles/360016649059) 中使用 YubiKey 作為智慧卡,可幫助您在 macOS 設置 YubiKey。
|
||||
Yubico 指南 [在macOS](https://support.yubico.com/hc/articles/360016649059) 中使用 YubiKey 作為智慧卡,可幫助您在 macOS 設定 YubiKey。
|
||||
|
||||
設定智慧卡/安全金鑰後,我們建議您在終端機中執行此命令:
|
||||
|
||||
@ -141,17 +141,17 @@ sudo defaults write /Library/Preferences/com.apple.loginwindow DisableFDEAutoLog
|
||||
|
||||
</div>
|
||||
|
||||
Linux 上的 `pam_u2f` 模組可以提供雙因素驗證,以便在最流行的 Linux 發行版上登錄。 如果您有支援 U2F 的硬體安全金鑰,可以為您的登入設定 MFA 驗證。 Yubico 有 [Ubuntu Linux 登入指南 - U2F](https://support.yubico.com/hc/articles/360016649099-Ubuntu-Linux-Login-Guide-U2F) 應該適用於任何發佈版本。 軟體包管理器指令(例如 `apt-get`)和軟體包名稱可能不同。 本指南 **不適用於** Qubes OS.
|
||||
Linux 上的 `pam_u2f` 模組可以提供雙因素驗證,以便在最流行的 Linux 發行版上登錄。 如果您有支援 U2F 的實體安全金鑰,可以為您的登入設定 MFA 驗證。 Yubico 有 [Ubuntu Linux 登入指南 - U2F](https://support.yubico.com/hc/articles/360016649099-Ubuntu-Linux-Login-Guide-U2F) 應該適用於任何發佈版本。 軟體包管理器指令(例如 `apt-get`)和軟體包名稱可能不同。 本指南 **不適用於** Qubes OS.
|
||||
|
||||
### Qubes OS
|
||||
|
||||
Qubes OS 支援 YubiKeys 進行 Challenge-Response 驗證。 若有具 Challenge-Response 驗證支援的 YubiKey ,請查看 Qubes OS [YubiKey 文檔](https://qubes-os.org/doc/yubikey) ,以在Qubes OS 設置 MFA。
|
||||
Qubes OS 支援 YubiKeys 進行 Challenge-Response 驗證。 若有具 Challenge-Response 驗證支援的 YubiKey ,請查看 Qubes OS [YubiKey 文件](https://qubes-os.org/doc/yubikey) ,以在Qubes OS 設定 MFA。
|
||||
|
||||
### SSH
|
||||
|
||||
#### 硬件安全金鑰
|
||||
#### 實體安全金鑰
|
||||
|
||||
SSH MFA 可以使用多種不同的身份驗證方法進行設置,這些方法在硬體安全金鑰中很受歡迎。 建議查看 Yubico [文件檔](https://developers.yubico.com/SSH) ,了解如何設置此功能。
|
||||
SSH MFA 可以使用多種不同的身份驗證方法進行設定,這些方法在實體安全金鑰中很受歡迎。 建議查看 Yubico [文件檔](https://developers.yubico.com/SSH) ,了解如何設置此功能。
|
||||
|
||||
#### TOTP
|
||||
|
||||
|
@ -24,7 +24,7 @@ description: 以下是關於如何建立最強密碼並確保帳戶安全的一
|
||||
|
||||
應避免經常更改必須記住的密碼(例如密碼管理器的主密碼) ,除非有理由相信它已被破壞,否則頻繁更改它往往會使您面臨忘記密碼的風險。
|
||||
|
||||
對於無需記住的密碼(例如存儲在密碼管理器中的密碼)時,如果您的 [威脅模型](threat-modeling.md) 需要它,建議每隔幾個月查看一次重要帳戶(特別是沒使用多因素身份驗證的帳戶)並更改其密碼,以防它們在尚未公開的資料洩露中遭到破壞。 大多數密碼管理器可為密碼設定到期日期,以便更容易管理。
|
||||
對於無需記住的密碼(例如儲存在密碼管理器中的密碼)時,如果您的 [威脅模型](threat-modeling.md) 需要它,建議每隔幾個月查看一次重要帳戶(特別是沒使用多因素身份驗證的帳戶)並更改其密碼,以防它們在尚未公開的資料洩露中遭到破壞。 大多數密碼管理器可為密碼設定到期日期,以便更容易管理。
|
||||
|
||||
<div class="admonition tip" markdown>
|
||||
<p class="admonition-title">檢查資料洩露</p>
|
||||
@ -104,7 +104,7 @@ Diceware 是一種創建密碼短語的方法,這些密短口令易於記憶
|
||||
|
||||
### 密碼管理器。
|
||||
|
||||
儲存密碼的最佳方式是使用密碼管理器。 可將密碼存儲在檔案或雲端,使用單個主密碼保護與開啟它們。 這樣,您只需要記住一個強大的密碼,就可以訪問其餘密碼。
|
||||
儲存密碼的最佳方式是使用密碼管理器。 可將密碼儲存在檔案或雲端,使用單個主密碼保護與開啟它們。 這樣,您只需要記住一個強大的密碼,就可以訪問其餘密碼。
|
||||
|
||||
有許多好的選項可參考,不管是雲端和本地設備安裝。 選擇任一推薦的密碼管理器,利用它為所有帳戶建立強密碼。 建議利用至少七個單詞的 [diceware 口令密語](#diceware-passphrases) 來保護密碼管理器的安全。
|
||||
|
||||
@ -115,9 +115,9 @@ Diceware 是一種創建密碼短語的方法,這些密短口令易於記憶
|
||||
|
||||
當使用 TOTP 代碼作為 [多因素驗證](multi-factor-authentication.md#time-based-one-time-password-totp) 時,最好的安全措施是將 TOTP 代碼保存在 [分開的應用程序](../multi-factor-authentication.md) 中。
|
||||
|
||||
將您的 TOTP 令牌存儲在與密碼相同的位置,雖然方便,但假若對手可以存取密碼管理器,則帳戶安全驗證則減少為單一因素。
|
||||
將您的 TOTP 令牌儲存在與密碼相同的位置,雖然方便,但假若對手可以存取密碼管理器,則帳戶安全驗證則減少為單一因素。
|
||||
|
||||
此外,我們不建議把一次性修復代碼存在密碼管理器。 它們應分開儲存,例如放在離線儲存設備的加密容器中。
|
||||
此外,我們不建議把一次性修復代碼儲存在密碼管理器。 它們應分開儲存,例如放在離線儲存設備的加密容器中。
|
||||
|
||||
</div>
|
||||
|
||||
|
@ -115,7 +115,7 @@ Tresorit 已獲得多項獨立安全稽核:
|
||||
|
||||
Peergos 主要是網頁應用程式,但您可以自行託管伺服器,將其作為遠端 Peergos 帳戶的本機快取,或作為獨立的儲存伺服器,省去註冊遠端帳戶和訂閱的麻煩。 Peergos 伺服器是 `.jar` 檔案,這表示您必須將 Java 17+ 執行環境([OpenJDK 下載](https://azul.com/downloads))安裝在電腦上以使其正常工作。
|
||||
|
||||
透過註冊帳戶在其付費託管服務上運行本地版本的 Peergos ,用戶可在不依賴 DNS 或 TLS 憑證授權單位的情況下存取 Peergos 存儲,並將資料副本備份到其雲端。 無論運行他們的桌面伺服器還是僅使用他們的託管 Web 介面,使用者體驗都應該是相同的。
|
||||
透過註冊帳戶在其付費託管服務上運行本機版本的 Peergos ,用戶可在不依賴 DNS 或 TLS 憑證授權單位的情況下存取 Peergos 儲存,並將資料副本備份到其雲端。 無論運行他們的桌面伺服器還是僅使用他們的託管 Web 介面,使用者體驗都應該是相同的。
|
||||
|
||||
Peergos was [audited](https://cure53.de/pentest-report_peergos.pdf) by Cure53 in June 2019, and all found issues were subsequently fixed.
|
||||
|
||||
|
@ -41,7 +41,7 @@ cover: cryptocurrency.webp
|
||||
|
||||
使用 Monero ,外部觀察者無法破譯 Monero 交易地址、交易金額、地址餘額或交易歷史。
|
||||
|
||||
為了獲得最佳的隱私,請務必使用非保管錢包,讓查看密鑰保留在設備上。 這意味著只有您能夠花費資金並查看交易進出。 若使用託管錢包,則服務商可看到**全部活動** ;如果用的是"輕量"錢包,則服務商保存了您的私鑰並看到您全部的交易活動。 一些非保管錢包包括:
|
||||
為了獲得最佳的隱私,請務必使用非保管錢包,讓查看金鑰保留在裝置上。 這意味著只有您能夠花費資金並查看交易進出。 若使用託管錢包,則服務商可看到**全部活動** ;如果用的是"輕量"錢包,則服務商保存了您的私鑰並看到您全部的交易活動。 一些非保管錢包包括:
|
||||
|
||||
- [官方Monero客戶端](https://getmonero.org/downloads) (桌面)
|
||||
- [Cake Wallet](https://cakewallet.com) (iOS, Android, macOS)
|
||||
|
@ -174,7 +174,7 @@ iMazing 會自動並以互動方式引導完成使用 [MVT](#mobile-verification
|
||||
|
||||
</div>
|
||||
|
||||
Auditor 並不像本頁上的其他工具一樣是掃描/分析工具。 相反地,它使用由裝置硬體支持的 keystore ,讓您可以驗證裝置的身份,並確保作業系統本身沒有被竄改或遭到 verified boot 降級攻擊。 這為裝置本身提供了非常強大的完整性檢查,但不一定檢查裝置上執行的使用者級應用程式是否是惡意的。
|
||||
Auditor 並不像本頁上的其他工具一樣是掃描/分析工具。 相反的,它使用由裝置硬體支持的 keystore ,讓您可以驗證裝置的身份,並確保作業系統本身沒有被竄改或遭到 verified boot 降級攻擊。 這為裝置本身提供了非常強大的完整性檢查,但不一定檢查裝置上執行的使用者級應用程式是否是惡意的。
|
||||
|
||||
Auditor 使用 **兩個** 設備執行證明和入侵檢測,即一個 _被驗證者(auditee)_ 和一個 _驗證者(auditor)_。 驗證者 可以是任何 Android 10+ 裝置(或是由 [GrapheneOS](android/distributions.md#grapheneos) 所持有的遠端網路服務),而 被驗證者 必須是特定 [支援的裝置](https://attestation.app/about#device-support)。 Auditor 運行原理:
|
||||
|
||||
|
@ -32,7 +32,7 @@ global:
|
||||
|
||||
## 自行託管 DNS 過濾器
|
||||
|
||||
在被控制平臺,自主託管 DNS 可提供有用的過濾,例如智能電視和其他物聯網裝置,因為不需要客戶端軟體。
|
||||
在被控制平臺,自主託管 DNS 可提供有用的過濾,例如智慧電視和其他物聯網裝置,因為不需要客戶端軟體。
|
||||
|
||||
### Pi-hole
|
||||
|
||||
|
@ -2,7 +2,7 @@
|
||||
meta_title: "加密私人電子郵件建議 - Privacy Guides"
|
||||
title: "電子郵件服務"
|
||||
icon: material/email
|
||||
description: 這些電子郵件提供商提供了一個好地方來安全地存儲您的電子郵件,也有不少能與其他供應商相互操作的 OpenPGP 加密。
|
||||
description: 這些電子郵件提供商提供了一個好地方來安全的儲存您的電子郵件,也有不少能與其他供應商相互操作的 OpenPGP 加密。
|
||||
cover: email.webp
|
||||
global:
|
||||
-
|
||||
@ -34,7 +34,7 @@ global:
|
||||
|
||||
## OpenPGP 兼容服務
|
||||
|
||||
這些供應商原生支援 OpenPGP 加密以及 [Web Key Directory 標準](basics/email-security.md#what-is-the-web-key-directory-standard),可進行 provider-agnostic E2EE 電郵。 例如, Proton Mail 用戶可以向 Mailbox.org 用戶發送 E2EE 消息,或者您可以從它支援的網際網路服務接收 OpenPGP 加密通知。
|
||||
這些供應商原生支援 OpenPGP 加密以及 [Web Key Directory 標準](basics/email-security.md#what-is-the-web-key-directory-standard),可進行 provider-agnostic E2EE 電子郵件。 例如, Proton Mail 用戶可以向 Mailbox.org 用戶發送 E2EE 消息,或者您可以從它支援的網際網路服務接收 OpenPGP 加密通知。
|
||||
|
||||
<div class="grid cards" markdown>
|
||||
|
||||
@ -97,17 +97,17 @@ Proton Mail 除了[支持](https://proton.me/support/payment-options)郵寄現
|
||||
|
||||
#### :material-check:{ .pg-green } 帳號安全
|
||||
|
||||
Proton Mail 支援使用 TOTP [雙因素驗證](https://proton.me/support/two-factor-authentication-2fa) 和採用 FIDO2 或 U2F 標準的 [硬體安全金鑰](https://proton.me/support/2fa-security-key)。 使用硬體安全金鑰需要先設定 TOTP 雙因素驗證。
|
||||
Proton Mail 支援使用 TOTP [兩步驟驗證](https://proton.me/support/two-factor-authentication-2fa) 和採用 FIDO2 或 U2F 標準的 [硬體安全金鑰](https://proton.me/support/2fa-security-key)。 使用實體安全金鑰需要先設定 TOTP 兩步驟驗證。
|
||||
|
||||
#### :material-check:{ .pg-green } 資料安全
|
||||
|
||||
Proton Mail 使用「[零存取加密技術](https://proton.me/blog/zero-access-encryption)」來保護電子郵件和[行事曆](https://proton.me/news/protoncalendar-security-model)的資料安全。 使用「零存取加密技術」保護的數據只能由您訪問。
|
||||
|
||||
存儲在 [Proton 通錄](https://proton.me/support/proton-contacts)中的某些資訊,例如顯示名稱和電子郵件地址,並未使用零存取加密進行保護。 支援零存取加密的聯絡人欄位(例如電話號碼)會以掛鎖圖示顯示。
|
||||
儲存在 [Proton 通錄](https://proton.me/support/proton-contacts)中的某些資訊,例如顯示名稱和電子郵件位址,並未使用零存取加密進行保護。 支援零存取加密的聯絡人欄位(例如電話號碼)會以掛鎖圖示顯示。
|
||||
|
||||
#### :material-check:{ .pg-green } 電子郵件加密
|
||||
|
||||
Proton Mail 網頁郵件整合了 [OpenPGP 加密](https://proton.me/support/how-to-use-pgp) 。 發送到其他 Proton Mail 帳號的電子郵件會自動加密,並且可以在您的帳號設置中輕鬆啟用「使用 OpenPGP 金鑰對非 Proton Mail 地址進行加密」。 Proton 也支援透過 [Web 金鑰目錄 (WKD)](https://wiki.gnupg.org/WKD) 自動發現外部金鑰。 因此發送到使用 WKD 的其他供應商的電子郵件也將使用 OpenPGP 自動加密,無需與聯絡人手動交換公共 PGP 金鑰。 它可以 [加密非 Proton Mail 郵件地址的訊息](https://proton.me/support/password-protected-emails),不必非得使用帶OpenPGP 的 Proton Mail 帳戶。
|
||||
Proton Mail 網頁郵件整合了 [OpenPGP 加密](https://proton.me/support/how-to-use-pgp) 。 發送到其他 Proton Mail 帳號的電子郵件會自動加密,並且可以在您的帳號設定中輕鬆啟用「使用 OpenPGP 金鑰對非 Proton Mail 位位址進行加密」。 Proton 也支援透過 [Web 金鑰目錄 (WKD)](https://wiki.gnupg.org/WKD) 自動發現外部金鑰。 因此發送到使用 WKD 的其他供應商的電子郵件也將使用 OpenPGP 自動加密,無需與聯絡人手動交換公共 PGP 金鑰。 它可以 [加密非 Proton Mail 郵件地址的訊息](https://proton.me/support/password-protected-emails),不必非得使用帶OpenPGP 的 Proton Mail 帳戶。
|
||||
|
||||
Proton Mail 也透過 HTTP 從其 WKD 發布 Proton 帳戶的公鑰。 這可讓非 Proton Mail 使用者可以輕鬆找到 Proton Mail 帳戶的 OpenPGP 金鑰,以利跨供應商進行 E2EE 。 這僅限於使用 Proton 自身網域別名 (例如 @proton.me) 的電子郵件。 如果使用自定域名,則須另行[設定 WKD](./basics/email-security.md#what-is-the-web-key-directory-standard) 。
|
||||
|
||||
@ -162,9 +162,9 @@ Mailbox.org 允許使用 [加密郵箱](https://kb.mailbox.org/en/private/e-mail
|
||||
|
||||
#### :material-check:{ .pg-green } 電子郵件加密
|
||||
|
||||
Mailbox.org 在他們的網頁郵件中 [整合了加密功能](https://kb.mailbox.org/en/private/e-mail-article/send-encrypted-e-mails-with-guard) ,這簡化了向具有公開OpenPGP密鑰的人發送訊息。 它們也讓遠端收件者可以在 Mailbox.org 的伺服器上[解密電子郵件](https://kb.mailbox.org/en/private/e-mail-article/my-recipient-does-not-use-pgp)。 當遠端收件人沒有 OpenPGP 無法解密自己郵箱中的電子郵件時,此功能非常有用。
|
||||
Mailbox.org 在他們的網頁郵件中 [整合了加密功能](https://kb.mailbox.org/en/private/e-mail-article/send-encrypted-e-mails-with-guard) ,這簡化了向具有公開OpenPGP金鑰的人發送訊息。 它們也讓遠端收件者可以在 Mailbox.org 的伺服器上[解密電子郵件](https://kb.mailbox.org/en/private/e-mail-article/my-recipient-does-not-use-pgp)。 當遠端收件人沒有 OpenPGP 無法解密自己郵箱中的電子郵件時,此功能非常有用。
|
||||
|
||||
Mailbox.org 還支持通過 HTTP 的 [Web密鑰目錄( WKD )](https://wiki.gnupg.org/WKD)發現公鑰。 因此其它人可以輕鬆找到 Mailbox.org 帳戶的 OpenPGP 金鑰,便於跨提供者使用 E2EE。 這僅限於使用 Mailbox.org 自身網域(例如 @mailbox.org) 的電子郵件。 如果使用自定域名,則須另行[設定 WKD](./basics/email-security.md#what-is-the-web-key-directory-standard) 。
|
||||
Mailbox.org 還支援通過 HTTP 的 [Web金鑰目錄( WKD )](https://wiki.gnupg.org/WKD)發現公鑰。 因此其它人可以輕鬆找到 Mailbox.org 帳戶的 OpenPGP 金鑰,便於跨提供者使用 E2EE。 這僅限於使用 Mailbox.org 自身網域(例如 @mailbox.org) 的電子郵件。 如果使用自定域名,則須另行[設定 WKD](./basics/email-security.md#what-is-the-web-key-directory-standard) 。
|
||||
|
||||
#### :material-information-outline:{ .pg-blue } 終止帳號
|
||||
|
||||
@ -180,7 +180,7 @@ Mailbox.org 所有方案都提供了數位遺產功能。 你可以選擇是否
|
||||
|
||||
## 更多供應商
|
||||
|
||||
這些提供商以零知識加密方式儲存您的電子郵件,使其成為保護儲存電子郵件安全的絕佳選擇。 但是,它們不支持供應商之間可相互操作 E2EE 通信的加密標準。
|
||||
這些提供商以零知識加密方式儲存您的電子郵件,使其成為保護儲存電子郵件安全的絕佳選擇。 但是,它們不支援供應商之間可相互操作 E2EE 通信的加密標準。
|
||||
|
||||
<div class="grid cards" markdown>
|
||||
|
||||
|
@ -22,7 +22,7 @@ cover: encryption.webp
|
||||
|
||||
{ align=right }
|
||||
|
||||
**Cryptomator** 是一種加密方案,專為私密的將檔案儲存至任何雲端 [:material-server-network: 服務提供商](basics/common-threats.md#privacy-from-service-providers){ .pg-teal } 而設計,讓您無需相信他們不會存取您的檔案。 它允許您創建存儲在虛擬驅動器上的保管庫,其內容已加密並與雲端儲存供應商同步。
|
||||
**Cryptomator** 是一種加密方案,專為私密的將檔案儲存至任何雲端 [:material-server-network: 服務提供商](basics/common-threats.md#privacy-from-service-providers){ .pg-teal } 而設計,讓您無需相信他們不會存取您的檔案。 它允許您創建儲存在虛擬驅動器上的保管庫,其內容已加密並與雲端儲存供應商同步。
|
||||
|
||||
[:octicons-home-16: 首頁](https://cryptomator.org){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://cryptomator.org/privacy){ .card-link title="隱私權政策" }
|
||||
@ -61,7 +61,7 @@ Cryptomator 的文件詳細介紹它的預期[安全目標](https://docs.cryptom
|
||||
|
||||
{ align=right }
|
||||
|
||||
**Picocrypt** 是一個小而簡單的加密工具,提供現代加密。 Picocrypt 使用安全的 XChaCha20 密碼和 Argon2id 密鑰派生功能來提供高級別的安全性。 它使用 Go 標準x/crypto 模塊作為其加密功能。
|
||||
**Picocrypt** 是一個小而簡單的加密工具,提供現代加密。 Picocrypt 使用安全的 XChaCha20 密碼和 Argon2id 金鑰派生功能來提供高級別的安全性。 它使用 Go 標準x/crypto 模塊作為其加密功能。
|
||||
|
||||
[:octicons-repo-16: 儲存庫](https://github.com/Picocrypt/Picocrypt){ .md-button .md-button--primary }
|
||||
[:octicons-code-16:](https://github.com/Picocrypt/Picocrypt){ .card-link title="原始碼" }
|
||||
@ -156,7 +156,7 @@ BitLocker [僅支援](https://support.microsoft.com/windows/turn-on-device-encry
|
||||
powershell Get-WmiObject -Namespace "root/cimv2/security/microsofttpm" -Class WIN32_tpm
|
||||
```
|
||||
|
||||
3. 造訪[進階啟動選項](https://support.microsoft.com/windows/advanced-startup-options-include-safe-mode-b90e7808-80b5-a291-d4b8-1a1af602b617)。 重新啟動時需要在 Windows 啟動前按下F8 鍵,然後進入 *命令提示符* in **疑難排解** → **進階選項** → **命令提示符**。
|
||||
3. 造訪[進階啟動選項](https://support.microsoft.com/windows/advanced-startup-options-include-safe-mode-b90e7808-80b5-a291-d4b8-1a1af602b617)。 重新啟動時需要在 Windows 啟動前按下F8 鍵,然後進入 *命令提示字元* in **疑難排解** → **進階選項** → **命令提字元**。
|
||||
4. 使用管理員帳戶登入並在命令提示符中輸入指令以開始加密:
|
||||
|
||||
```powershell
|
||||
@ -195,7 +195,7 @@ BitLocker [僅支援](https://support.microsoft.com/windows/turn-on-device-encry
|
||||
|
||||
</div>
|
||||
|
||||
我們建議您將本地恢復金鑰存放在安全的地方,而不是使用您的iCloud 帳戶進行恢復。
|
||||
我們建議您將本機復原金鑰存放在安全的地方,而不是使用您的 iCloud 帳號進行復原。
|
||||
|
||||
### Linux Unified Key設定
|
||||
|
||||
|
@ -5,9 +5,9 @@ description: 網站撰稿人如何更好利用 Git 的指南。
|
||||
|
||||
如果想直接在 github.com 網頁編輯器對本站進行修改,則無須擔心此處的建議。 如您使用本地端開發或者您是一位常駐的網站編輯者(可能使用本地端開發),請參考以下建議。
|
||||
|
||||
## 開啟 SSH 密鑰提交簽署
|
||||
## 開啟 SSH 金鑰提交簽署
|
||||
|
||||
可使用現有的SSH 密鑰簽署或 [建立新密鑰one](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/generating-a-new-ssh-key-and-adding-it-to-the-ssh-agent)。
|
||||
可使用現有的SSH 金鑰簽署或 [建立新金鑰one](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/generating-a-new-ssh-key-and-adding-it-to-the-ssh-agent)。
|
||||
|
||||
1. 設置 Git 客戶端以預設簽署提交與標籤(移除 `--global` 以便只對此存取庫作簽署):
|
||||
|
||||
@ -17,13 +17,13 @@ description: 網站撰稿人如何更好利用 Git 的指南。
|
||||
git config --global tag.gpgSign true
|
||||
```
|
||||
|
||||
2. 透過下方指令來設定簽署 Git 的 SSH 密鑰,把 `/PATH/TO/.SSH/KEY.PUB` 替換成存放公鑰的路徑,如 `/home/user/.ssh/id_ed25519.pub`:
|
||||
2. 透過下方指令來設定簽署 Git 的 SSH 金鑰,把 `/PATH/TO/.SSH/KEY.PUB` 替換成存放公鑰的路徑,如 `/home/user/.ssh/id_ed25519.pub`:
|
||||
|
||||
```bash
|
||||
git config --global user.signingkey /PATH/TO/.SSH/KEY.PUB
|
||||
```
|
||||
|
||||
確認 [加入您 GitHub 帳戶中的 SSH 密鑰](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/adding-a-new-ssh-key-to-your-github-account#adding-a-new-ssh-key-to-your-account) **簽署密鑰** (其不同於驗證密鑰)。
|
||||
確認 [加入您 GitHub 帳戶中的 SSH 金鑰](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/adding-a-new-ssh-key-to-your-github-account#adding-a-new-ssh-key-to-your-account) **簽署金鑰** (其不同於驗證金鑰)。
|
||||
|
||||
## Rebase on Git pull
|
||||
|
||||
|
@ -227,7 +227,7 @@ Mull 隨附預設配置的隱私保護設定。 如果想在退出應用程式
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
在 iOS 上,任何可以瀏覽網頁的應用程式都被[限制](https://developer.apple.com/app-store/review/guidelines)使用 Apple 提供的 [WebKit 框架](https://developer.apple.com/documentation/webkit),因此沒有理由使用第三方瀏覽器。
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ Mull 隨附預設配置的隱私保護設定。 如果想在退出應用程式
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### 搜尋
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. 停用搜尋建議可讓您更精確地控制您傳送給搜尋引擎供應商的資料。
|
||||
|
||||
#### 主題類別
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### 其他隱私設定
|
||||
|
||||
這些選項可以在 :gear: **設定** → **應用程式** → **Safari** → **進階**
|
||||
|
@ -10,9 +10,9 @@ cover: multi-factor-authentication.webp
|
||||
- [:material-target-account: 針對性攻擊](basics/common-threats.md#attacks-against-specific-individuals ""){.pg-red}
|
||||
|
||||
<div class="admonition note" markdown>
|
||||
<p class="admonition-title">硬體金鑰</p>
|
||||
<p class="admonition-title">實體金鑰</p>
|
||||
|
||||
[硬體安全金鑰推薦](security-keys.md) 已移至其本身的類別。
|
||||
[實體安全金鑰推薦](security-keys.md) 已移至其本身的類別。
|
||||
|
||||
</div>
|
||||
|
||||
|
@ -108,7 +108,7 @@ Standard Notes 已於 2024 年 4 月 10 日 [加入 Proton AG](https://standardn
|
||||
|
||||
</div>
|
||||
|
||||
Joplin 不 [支援](https://github.com/laurent22/joplin/issues/289) 應用程式自身或個別筆記的 password/PIN 保護。 但是您的資料在傳輸與同步過程中仍會使用主密鑰加密。 2023 年 1 月起 Joplin [支援](https://github.com/laurent22/joplin/commit/f10d9f75b055d84416053fab7e35438f598753e9) Android 和 iOS 生物辨識應用鎖。
|
||||
Joplin 不 [支援](https://github.com/laurent22/joplin/issues/289) 應用程式自身或個別筆記的 password/PIN 保護。 但是您的資料在傳輸與同步過程中仍會使用主金鑰加密。 2023 年 1 月起 Joplin [支援](https://github.com/laurent22/joplin/commit/f10d9f75b055d84416053fab7e35438f598753e9) Android 和 iOS 生物辨識應用鎖。
|
||||
|
||||
### Cryptee
|
||||
|
||||
@ -117,7 +117,7 @@ Joplin 不 [支援](https://github.com/laurent22/joplin/issues/289) 應用程式
|
||||
{ align=right }
|
||||
{ align=right }
|
||||
|
||||
**Cryptee** 是一個開源的,基於網頁的 E2EE 文件編輯器和照片存儲應用程式。 Cryptee 為漸進式網路應用程式(PWA) ,這意味著它可以在所有現代設備上無縫工作,而無需為每個平臺提供原生應用程序。
|
||||
**Cryptee** 是一個開源的,基於網頁的 E2EE 文件編輯器和照片儲存應用程式。 Cryptee 為漸進式網路應用程式(PWA) ,這意味著它可以在所有現代設備上無縫工作,而無需為每個平臺提供原生應用程序。
|
||||
|
||||
[:octicons-home-16: 首頁](https://crypt.ee){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://crypt.ee/privacy){ .card-link title="隱私權政策" }
|
||||
|
@ -94,7 +94,7 @@ Android 13:
|
||||
|
||||
多重**使用者設定檔**可在 :gear: **設定** → **系統** → **使用者** 中找到,是 Android 中最簡單的隔離方式。
|
||||
|
||||
您可以對特定設定檔施加限制,例如:撥打電話、使用 SMS 或安裝應用程式。 每個使用者設定檔皆使用個自密鑰加密,無法訪問設置上其它用戶的任何資料。 即使是裝置擁有者也無法在不知道用戶密碼的情況下查看其他身份的資料。 多重使用者設定檔是一種更安全的隔離方法。
|
||||
您可以對特定設定檔施加限制,例如:撥打電話、使用 SMS 或安裝應用程式。 每個使用者設定檔皆使用個自密鑰加密,無法訪問其它用戶的任何資料。 即使是裝置擁有者也無法在不知道用戶密碼的情況下查看其他身份的資料。 多重使用者設定檔是一種更安全的隔離方法。
|
||||
|
||||
### 工作設定檔
|
||||
|
||||
@ -128,7 +128,7 @@ Android 7 及以上版本支援 VPN kill switch,無需安裝第三方應用程
|
||||
|
||||
### 進階保護計劃
|
||||
|
||||
如果您有 Google 帳戶,我們建議您加入[進階保護計劃](https://landing.google.com/advancedprotection)。 任何人只要擁有兩個或以上支援 [FIDO](../basics/multi-factor-authentication.md#fido-fast-identity-online) 的硬體安全金鑰,即可免費使用。 或者,您可以使用[密碼金鑰](https://fidoalliance.org/passkeys)。
|
||||
如果您有 Google 帳戶,我們建議您加入[進階保護計劃](https://landing.google.com/advancedprotection)。 任何人只要擁有兩個或以上支援 [FIDO](../basics/multi-factor-authentication.md#fido-fast-identity-online) 的實體安全金鑰,即可免費使用。 或者,您可以使用[密碼金鑰](https://fidoalliance.org/passkeys)。
|
||||
|
||||
進階防護計劃提供強化的威脅監控,並能夠:
|
||||
|
||||
|
@ -32,9 +32,9 @@ The only source for apps on iOS is Apple's App Store, which requires an Apple Ac
|
||||
|
||||
### iCloud
|
||||
|
||||
Apple 產品的大多數隱私和安全問題與其雲服務有關,而不是其硬體或軟體。 當使用 iCloud 等 Apple 服務時,大部分資訊都存儲在他們的伺服器上以密鑰保護,且預設情況下 Apple 可以取用該密鑰。 您可以查看 [Apple 文檔](https://support.apple.com/HT202303),了解哪些服務是端到端加密的。 任何列為“傳輸中”或“伺服器上”的內容都意味著 Apple 可以在未經您許可下訪問存取該資料。 這種訪問級別偶爾會被執法部門濫用,儘管您的資料在設備上還是安全加密的狀態。當然,Apple 與任何其他公司一樣容易遭受資料洩露。
|
||||
Apple 產品的大多數隱私和安全問題與其雲服務有關,而不是其硬體或軟體。 當使用 iCloud 等 Apple 服務時,大部分資訊都儲存在他們的伺服器上以金鑰保護,且預設情況下 Apple 可以取用該金鑰。 您可以查看 [Apple 文檔](https://support.apple.com/HT202303),了解哪些服務是端到端加密的。 任何列為“傳輸中”或“伺服器上”的內容都意味著 Apple 可以在未經您許可下訪問存取該資料。 這種訪問級別偶爾會被執法部門濫用,儘管您的資料在設備上還是安全加密的狀態。當然,Apple 與任何其他公司一樣容易遭受資料洩露。
|
||||
|
||||
因此,如果使用 iCloud,則應[啟用**進階資料保護**](https://support.apple.com/HT212520)。 這會使用存儲在您設備上的的密鑰對 iCloud 數據加密(端到端加密)而不是放在 Apple 伺服器的密鑰,以便 iCloud 在發生數據洩露時得到保護,且不會被 Apple 發現。
|
||||
因此,如果使用 iCloud,則應[啟用**進階資料保護**](https://support.apple.com/HT212520)。 這會使用儲存在您裝置上的的金鑰對 iCloud 數據加密(端對端加密)而不是放在 Apple 伺服器的金鑰,以便 iCloud 在發生數據洩露時得到保護,且不會被 Apple 發現。
|
||||
|
||||
進階資料保護所用的加密法雖然強大,但[仍然*比不上*](https://discuss.privacyguides.net/t/apple-advances-user-security-with-powerful-new-data-protections/10778/4)其他[雲端服務](../cloud.md)的加密,特別是涉及到 iCloud Drive 時。 雖然我們強烈建議在使用 iCloud 時使用進階資料保護,但我們也建議考慮從更加[注重隱私的服務提供商](../tools.md)尋找 iCloud 的替代品,儘管 大多數人不太可能受到這些加密怪癖的影響。
|
||||
|
||||
@ -42,7 +42,7 @@ Apple 產品的大多數隱私和安全問題與其雲服務有關,而不是
|
||||
|
||||
#### iCloud+
|
||||
|
||||
付費 **iCloud+** 訂閱(任何 iCloud 存儲方案)附帶一些隱私保護功能。 雖然這些能為當前 iCloud 客戶提供足夠服務,但不建議通過 [VPN](../vpn.md) 購買 iCloud 方案,和將 [獨立電子郵件別名服務](../email-aliasing.md)僅用在這些功能。
|
||||
付費 **iCloud+** 訂閱(任何 iCloud 儲存方案)附帶一些隱私保護功能。 雖然這些能為當前 iCloud 客戶提供足夠服務,但不建議通過 [VPN](../vpn.md) 購買 iCloud 方案,和將 [獨立電子郵件別名服務](../email-aliasing.md)僅用在這些功能。
|
||||
|
||||
[**Private Relay**](https://apple.com/legal/privacy/data/en/icloud-relay) 是一項代理服務,可透過兩個伺服器轉發您裝置上所有 Safari 、DNS 查詢和未加密流量:一個由 Apple 擁有,另一個由第三方供應商(包括 Akamai、Cloudflare 和 Fastly)擁有。 理論上這應該可以防止鏈中的任何單一提供商(包括 Apple)完全了解您連線訪問的網站。 與 VPN 不同,Private Relay 不保護已加密的流量。
|
||||
|
||||
@ -215,7 +215,7 @@ iPhone 可以抵禦暴力攻擊,在多次嘗試失敗後,需要等待很長
|
||||
|
||||
The [color of the message bubble](https://support.apple.com/en-us/104972) in the Messages app indicates whether your messages are E2EE or not. A blue bubble indicates that you're using iMessage with E2EE, while a green bubble indicates the other party is using either the outdated SMS and MMS protocols or RCS. RCS on iOS is **not** E2EE. Currently, the only way to have E2EE in Messages is for both parties to be using iMessage on Apple devices.
|
||||
|
||||
如果您或您的訊息傳遞夥伴在沒有進階資料保護下啟用 iCloud 備份,則加密密鑰會存儲在 Apple 伺服器,這意味著他們可以訪問您的訊息。 Additionally, iMessage's key exchange is not as secure as alternative implementations like Signal's (which allows you to view the recipients key and verify by QR code), so it shouldn't be relied on for particularly sensitive communications.
|
||||
如果您或您的訊息傳遞夥伴在沒有進階資料保護下啟用 iCloud 備份,則加密金鑰會儲存在 Apple 伺服器,這意味著他們可以訪問您的訊息。 Additionally, iMessage's key exchange is not as secure as alternative implementations like Signal's (which allows you to view the recipients key and verify by QR code), so it shouldn't be relied on for particularly sensitive communications.
|
||||
|
||||
### Photo Permissions
|
||||
|
||||
|
@ -99,9 +99,9 @@ description: Linux 是一種開放原始碼、注重隱私的桌面作業系統
|
||||
|
||||
### Swap
|
||||
|
||||
考慮使用 [ZRAM](https://wiki.archlinux.org/title/Zram#Using_zram-generator) 而不是傳統的 swap 檔案或分區,以避免將潛在敏感的記憶資料寫入持久存儲(並提高性能)。 基於 Fedora 的發行版 [預設使用 ZRAM](https://fedoraproject.org/wiki/Changes/SwapOnZRAM)。
|
||||
考慮使用 [ZRAM](https://wiki.archlinux.org/title/Zram#Using_zram-generator) 而不是傳統的 swap 檔案或分區,以避免將潛在敏感的記憶資料寫入持久儲存(並提高性能)。 基於 Fedora 的發行版 [預設使用 ZRAM](https://fedoraproject.org/wiki/Changes/SwapOnZRAM)。
|
||||
|
||||
如果需要 suspend-to-disk (磁盤休眠)功能,則仍然需要使用傳統的swap 檔案或分區。 確保持久存儲設備上的任何交換空間予以[加密](https://wiki.archlinux.org/title/Dm-crypt/Swap_encryption),以減輕一些威脅。
|
||||
如果需要 suspend-to-disk (磁盤休眠)功能,則仍然需要使用傳統的swap 檔案或分區。 確保持久儲存設備上的任何交換空間予以[加密](https://wiki.archlinux.org/title/Dm-crypt/Swap_encryption),以減輕一些威脅。
|
||||
|
||||
### 商用靭體(Microcode更新)
|
||||
|
||||
@ -150,7 +150,7 @@ MAC 地址隨機化主要有利於 Wi-Fi 連接。 對於乙太網路連接,
|
||||
|
||||
- **主機名稱 **,系統的主機名稱會分享到所連接的網路。 應避免主機名稱像你的名字或作業系統等具識別度的術語,最好用一般術語或隨機字符串。
|
||||
- **用戶名稱 ** 。同樣地,用戶名稱會在系統中以各種方式使用。 考慮用 "用戶 "這樣一般常見字,而不是您的真實姓名。
|
||||
- **機器 ID**:在安裝過程中,會生成一個獨特的機器ID 並存儲在您的設備上。 考慮 [將它設置為一個通用 ID](https://madaidans-insecurities.github.io/guides/linux-hardening.html#machine-id)。
|
||||
- **機器 ID**:在安裝過程中,會生成一個獨特的機器ID 並儲存在您的裝置上。 考慮 [將它設置為一個通用 ID](https://madaidans-insecurities.github.io/guides/linux-hardening.html#machine-id)。
|
||||
|
||||
### 系統計數
|
||||
|
||||
|
@ -34,9 +34,9 @@ Apple 的 OCSP 服務使用 HTTPS 加密,因此只有他們能夠看到您開
|
||||
|
||||
### iCloud
|
||||
|
||||
當使用 iCloud 等 Apple 服務時,大部分資訊都存儲在他們的伺服器上以密鑰保護,且預設情況下 Apple 可以取用該密鑰。 Apple 將此稱為 [標準資料保護](https://support.apple.com/en-us/102651)。
|
||||
當使用 iCloud 等 Apple 服務時,大部分資訊都儲存在他們的伺服器上以金鑰保護,且預設情況下 Apple 可以取用該金鑰。 Apple 將此稱為 [標準資料保護](https://support.apple.com/en-us/102651)。
|
||||
|
||||
因此,如果使用 iCloud,則應[啟用**進階資料保護**](https://support.apple.com/HT212520)。 它利用存在設備上的密鑰對您的iCloud 數據(端到端)加密,此密鑰並不在Apple 伺服器,因此發生數據洩露時您的 iCloud 數據可得到保護與隱匿。
|
||||
因此,如果使用 iCloud,則應[啟用**進階資料保護**](https://support.apple.com/HT212520)。 它利用存在設備上的金鑰對您的 iCloud 資料(端對端)加密,此金鑰並不在Apple 伺服器,因此發生數據洩露時您的 iCloud 數據可得到保護與隱匿。
|
||||
|
||||
如果您希望能夠從 App Store 安裝應用程式,但不想啟用 iCloud,您可以從 App Store 登入 Apple 帳戶,而非 **系統設定**。
|
||||
|
||||
@ -122,7 +122,7 @@ Apple 的 OCSP 服務使用 HTTPS 加密,因此只有他們能夠看到您開
|
||||
|
||||
##### FileVault
|
||||
|
||||
在具有安全隔離區(Apple T2 安全晶片、Apple 晶片)的現代設備上,您的數據會保持加密。如果設備未檢測到數據遭篡改,則會通過硬體密鑰自動解密。 啟用 FileVault 還需要輪入密碼來解密資料,大大提高了安全性,尤其是在關機時或開機後首次登錄時。
|
||||
在具有安全隔離區(Apple T2 安全晶片、Apple 晶片)的現代裝置上,您的數據會保持加密。如果裝置未偵測到數據遭篡改,則會通過硬體金鑰自動解密。 啟用 FileVault 還需要輪入密碼來解密資料,大大提高了安全性,尤其是在關機時或開機後首次登錄時。
|
||||
|
||||
在較舊的 Intel 的 Mac 電腦,FileVault 是預設唯一可用的磁盤加密形式,應始終啟用。
|
||||
|
||||
@ -153,13 +153,13 @@ macOS 通過不同屬性的多層軟體和硬體保護來進行深度防禦。
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">警告</p>
|
||||
|
||||
macOS 可以安裝測試版更新。 但它們是不穩定的,可能帶有額外遙測,因為其用於測試目的。 因此,我們建議避免使用測試版軟件。
|
||||
macOS 可以安裝測試版更新。 但它們是不穩定的,可能帶有額外遙測,因為其用於測試目的。 因此,我們建議避免使用測試版軟體。
|
||||
|
||||
</div>
|
||||
|
||||
#### 簽署系統卷宗
|
||||
|
||||
macOS 的系統組件受到唯讀簽署系統卷宗之保護,這意味著您和惡意軟件都無法更改重要的系統檔案。
|
||||
macOS 的系統組件受到唯讀簽署系統卷宗之保護,這意味著您和惡意軟體都無法更改重要的系統檔案。
|
||||
|
||||
系統卷宗在運行時會予以驗證,任何未使用 Apple 的有效加密簽名進行簽署的數據都將遭拒絕。
|
||||
|
||||
@ -234,7 +234,7 @@ macOS 提供兩種惡意軟體防禦形式:
|
||||
|
||||
##### 備份
|
||||
|
||||
macOS 自帶[時光機](https://support.apple.com/HT201250) 的自動備份軟件,因此您可以在損壞/損壞的情況下將加密備份建立到外接或網路磁碟已刪除的檔案。
|
||||
macOS 自帶[時光機](https://support.apple.com/HT201250) 的自動備份軟體,因此您可以在損壞/損壞的情況下將加密備份建立到外接或網路磁碟已刪除的檔案。
|
||||
|
||||
### 硬體安全
|
||||
|
||||
@ -248,7 +248,7 @@ Apple SoC 專注於通過將安全功能轉移到功能有限的專用硬體以
|
||||
|
||||
#### Boot ROM
|
||||
|
||||
macOS 通過僅允許官方 Apple 軟件在啟動時運行以防止惡意軟體持久存在; 此稱為安全開機。 Mac 電腦利用 SoaC 上稱為啟動 ROM 唯讀存儲器來驗證這一點,該存儲器是在晶片製造過程中放置的。
|
||||
macOS 通過僅允許官方 Apple 軟體在啟動時運行以防止惡意軟體持久存在; 此稱為安全開機。 Mac 電腦利用 SoaC 上稱為啟動 ROM 唯讀儲存器來驗證這一點,該儲存器是在晶片製造過程中放置的。
|
||||
|
||||
開機 ROM 構成了硬體信任根。 這確保惡意軟體無法篡改開機過程。 Mac 啟動時,開機 ROM 第一個運行,為信任鏈中的第一個環節。
|
||||
|
||||
@ -256,15 +256,15 @@ Mac 電腦有三種安全模式啟動:*完全安全*、*降低安全性*和*
|
||||
|
||||
#### 安全隔離區
|
||||
|
||||
安全隔離區是內置於 Apple silicon 設備的安全晶片,負責存儲和生成靜態資料以及 Face ID 和 Touch ID 資料的加密密鑰。 它包含自己獨立的開機 ROM。
|
||||
安全隔離區是內建於 Apple silicon 裝置的安全晶片,負責儲存和生成靜態資料以及 Face ID 和 Touch ID 資料的加密金鑰。 它包含自己獨立的開機 ROM。
|
||||
|
||||
您可以將安全隔離區想成設備的安全中心:它具有 AES 加密引擎和安全存儲加密密鑰機制,它與系統的其餘部分分開,因此即使主處理器受到損害,也仍然保持安全。
|
||||
您可以將安全隔離區想成裝置的安全中心:它具有 AES 加密引擎和安全儲存加密金鑰機制,它與系統的其餘部分分開,因此即使主處理器受到損害,也仍然保持安全。
|
||||
|
||||
#### Touch ID
|
||||
|
||||
Apple Touch ID 功能可使用生物識別技術安全地解鎖設備。
|
||||
|
||||
您的生物識別資料永遠不會離開您的設備; 它僅存儲在安全隔離區。
|
||||
您的生物識別資料永遠不會離開您的裝置; 它僅儲存在安全隔離區。
|
||||
|
||||
#### 硬體麥克風斷線
|
||||
|
||||
@ -283,7 +283,7 @@ Apple Touch ID 功能可使用生物識別技術安全地解鎖設備。
|
||||
- 遵循最低加密標準
|
||||
- 確保正確撤銷已知的不良韌體
|
||||
- 已禁用其調試介面
|
||||
- 使用 Apple 的加密密鑰簽名
|
||||
- 使用 Apple 的加密金鑰簽名
|
||||
|
||||
#### 直接記憶體存取保護
|
||||
|
||||
|
@ -161,7 +161,7 @@ schema:
|
||||
|
||||
{ align=right }
|
||||
|
||||
**Bitwarden** 是一個免費的開源密碼與密鑰管理器。 它旨在解決個人、團隊和商業組織的密碼管理問題。 Bitwarden 是最佳和最安全的解決方案之一,可儲存所有登錄名和密碼,同時方便地在所有設備之間保持同步。
|
||||
**Bitwarden** 是一個免費的開源密碼與金鑰管理器。 它旨在解決個人、團隊和商業組織的密碼管理問題。 Bitwarden 是最佳和最安全的解決方案之一,可儲存所有登錄名和密碼,同時方便地在所有設備之間保持同步。
|
||||
|
||||
[:octicons-home-16: 首頁](https://bitwarden.com){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://bitwarden.com/privacy){ .card-link title="隱私權政策" }
|
||||
@ -204,7 +204,7 @@ Bitwarden 伺服器端代碼是 [開源的](https://github.com/bitwarden/server)
|
||||
|
||||
{ align=right }
|
||||
|
||||
**Proton Pass** 是由 [Proton Mail] (email.md#protonmail) 背後的團隊 Proton 所開發的開放原始碼、端對端加密的密碼管理器。 它能安全地儲存您的登入憑證、產生獨特的電子郵件別名,並支援和儲存密碼。
|
||||
**Proton Pass** 是由 [Proton Mail] (email.md#protonmail) 背後的團隊 Proton 所開發的開放原始碼、端對端加密的密碼管理器。 它能安全地儲存您的登入憑證、產生獨特的電子郵件別名,並支援儲存密碼。
|
||||
|
||||
[:octicons-home-16: 首頁](https://proton.me/pass){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://proton.me/pass/privacy-policy){ .card-link title="隱私權政策" }
|
||||
@ -246,7 +246,7 @@ Proton Pass 行動應用程式和瀏覽器擴充功能於 2023 年 5 月和 6
|
||||
|
||||
{ align=right }
|
||||
|
||||
**1Password** 是強調安全性與易用性的密碼管理器,可讓您將密碼、密鑰、信用卡、軟體許可證以及其他任何敏感資訊儲存於安全的數位保險庫中。 您的保管庫託管在 1Password 伺服器,費用為 [每月收取](https://1password.com/sign-up/)。 1Password 定期 [接受審計](https://support.1password.com/security-assessments/) 並提供卓越的客戶支援。 1Password 是封閉原始碼;但是,產品的安全性已徹底記錄在他們的 [安全白皮書](https://1passwordstatic.com/files/security/1password-white-paper.pdf)。
|
||||
**1Password** 是強調安全性與易用性的密碼管理器,可讓您將密碼、金鑰、信用卡、軟體許可證以及其他任何敏感資訊儲存於安全的數位保險庫中。 您的保管庫託管在 1Password 伺服器,費用為 [每月收取](https://1password.com/sign-up/)。 1Password 定期 [接受審計](https://support.1password.com/security-assessments/) 並提供卓越的客戶支援。 1Password 是封閉原始碼;但是,產品的安全性已徹底記錄在他們的 [安全白皮書](https://1passwordstatic.com/files/security/1password-white-paper.pdf)。
|
||||
|
||||
[:octicons-home-16: 首頁](https://1password.com){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://1password.com/legal/privacy){ .card-link title="隱私權政策" }
|
||||
|
@ -182,7 +182,7 @@ Briar 利用[^1] Bramble[Handshake](https://code.briarproject.org/briar/briar-sp
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">警告</p>
|
||||
|
||||
這些通訊軟體無向前保密[^1],雖然它們達成我們之前建議的某些需求,但不推薦將其用於長期或敏感通信。 訊息收件人之間的任何密鑰洩露都會影響* *所有* *過去通信的機密性。
|
||||
這些通訊軟體無向前保密[^1],雖然它們達成我們之前建議的某些需求,但不推薦將其用於長期或敏感通信。 訊息收件人之間的任何密鑰洩露都會影響* *所有* *過去通訊的機密性。
|
||||
|
||||
</div>
|
||||
|
||||
@ -287,4 +287,4 @@ Session [白皮書](https://arxiv.org/pdf/2002.04609.pdf) ,描述了應用程
|
||||
- 支援多平台 Linux、macOS、Windows、Android 和 iOS。
|
||||
|
||||
[^1]: [前向保密](https://en.wikipedia.org/wiki/Forward_secrecy) 是指密鑰會非常頻繁地輪換,因此如果目前的加密密鑰被洩露,也不會暴露**過去的**訊息。
|
||||
[^2]: 未來保密(或洩漏後安全)是防止攻擊者利用洩露的私鑰解密**未來**訊息,除非攻擊者將來也能取得更多會話金鑰。 這有效地迫使攻擊者攔截各方間的所有通訊,因為一旦發生未被攔截的密鑰交換,他們就會失去訪問權限。 [ ↩](#fnref:2){.footnote-backref}
|
||||
[^2]: 未來保密(或洩漏後安全)是防止攻擊者利用洩露的私鑰解密**未來**訊息,除非攻擊者將來也能取得更多會話金鑰。 這有效地迫使攻擊者攔截各方間的所有通訊,因為一旦發生未被攔截的金鑰交換,他們就會失去訪問權限。 [ ↩](#fnref:2){.footnote-backref}
|
||||
|
@ -10,7 +10,7 @@ cover: multi-factor-authentication.webp
|
||||
- [:material-target-account: 針對性攻擊](basics/common-threats.md#attacks-against-specific-individuals){ .pg-red }
|
||||
- [:material-bug-outline: 被動攻擊](basics/common-threats.md#security-and-privacy){ .pg-orange }
|
||||
|
||||
實體**安全密鑰**可為線上帳戶添加強大的保護層。 與[驗證器應用程式](multi-factor-authentication.md) 相比,FIDO2 安全密鑰協定不受網路釣魚的影響,在沒持有金鑰的情況下不會受到損害。 許多服務支援 FIDO2/WebAuthn 作為保護帳戶安全的多因素驗證選項,且某些服務可用安全金鑰作為無密碼身份驗證的強大單因素驗證器。
|
||||
實體**安全金鑰**可為線上帳戶添加強大的保護層。 與[驗證器應用程式](multi-factor-authentication.md) 相比,FIDO2 安全金鑰協定不受網路釣魚的影響,在沒持有金鑰的情況下不會受到侵害。 許多服務支援 FIDO2/WebAuthn 作為保護帳戶安全的多因素驗證選項,且某些服務可用安全金鑰作為無密碼身份驗證的強大單因素驗證器。
|
||||
|
||||
## YubiKey 安全金鑰
|
||||
|
||||
@ -20,7 +20,7 @@ cover: multi-factor-authentication.webp
|
||||
{ width="315" }
|
||||
</figure>
|
||||
|
||||
**Yubico Security Key**系列是最佳成本效益的硬體安全金鑰,擁有 FIDO 2 級認證。 它支援 FIDO2/WebAuthn 和 FIDO U2F,並且可以與大多數支援安全密鑰作為第二因素的服務以及許多密碼管理器一起使用。
|
||||
**Yubico Security Key**系列是最佳成本效益的實體安全金鑰,擁有 FIDO 2 級認證。 它支援 FIDO2/WebAuthn 和 FIDO U2F,並且可以與大多數支援安全金鑰作為第二因素的服務以及許多密碼管理器一起使用。
|
||||
|
||||
[:octicons-home-16: 首頁](https://yubico.com/products/security-key){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://yubico.com/support/terms-conditions/privacy-notice){ .card-link title="隱私權政策" }
|
||||
@ -65,13 +65,13 @@ Yubico 的 **YubiKey** 系列是最受歡迎的安全金鑰之一。 YubiKey 5
|
||||
|
||||
</div>
|
||||
|
||||
[比較表](https://yubico.com/store/compare) 顯示 YubiKey 的功能以及與 Yubico [安全密鑰](#yubico-security-key) 系列之間相互比較。 YubiKey 好處之一是,一支可以滿足對安全密鑰硬體的全部期待。 建議購買前先 [作個小測驗](https://yubico.com/quiz/) ,確保做出正確的選擇。
|
||||
[比較表](https://yubico.com/store/compare) 顯示 YubiKey 的功能以及與 Yubico [安全金鑰](#yubico-security-key) 系列之間相互比較。 YubiKey 好處之一是,一支可以滿足對安全金鑰硬體的全部期待。 建議購買前先 [作個小測驗](https://yubico.com/quiz/) ,確保做出正確的選擇。
|
||||
|
||||
Yubikey 5系列具有FIDO 1級認證,這是最常見的。 不過,有些政府或其他組織可能需要具備第二級認證的金鑰,在這種情況下,您就必須購買 [Yubikey 5 **FIPS** 系列](https://yubico.com/products/yubikey-fips) ,或 [Yubico Security Key 系列](#yubico-security-key) 金鑰。 大多數人不必擔心這種差異。
|
||||
|
||||
YubiKey 可以使用 [YubiKey Manager](https://yubico.com/support/download/yubikey-manager) 或 [YubiKey Personalization Tools](https://yubico.com/support/download/yubikey-personalization-tools) 來設定它。 若要管理 TOTP 程式碼,可用 [Yubico Authenticator](https://yubico.com/products/yubico-authenticator)。 Yubico 所有客戶端軟體都是開源的。
|
||||
|
||||
支持 HOTP 和 TOTP 的機型, OTP 介面中有2個插槽可用於HOTP 和32個插槽來存儲 TOTP 機密。 這些機密經加密後存儲在密鑰上,永遠不會將它們暴露在插入的設備上。 一旦向 Yubico Authenticator 提供種子(共享祕密) ,它將只會給出六位數的代碼,但永遠不會提供種子。 此安全模型有助於限制攻擊者,即便運行 Yubico Authenticator的設備受到破壞,讓受到物理攻擊時 Yubikey 仍具抵抗力。
|
||||
支援 HOTP 和 TOTP 的機型, OTP 介面中有2個插槽可用於HOTP 和32個插槽來儲存 TOTP 機密。 這些機密經加密後存儲在金鑰上,永遠不會將它們暴露在插入的設備上。 一旦向 Yubico Authenticator 提供種子(共享祕密) ,它將只會給出六位數的代碼,但永遠不會提供種子。 此安全模型有助於限制攻擊者,即便運行 Yubico Authenticator的設備受到破壞,讓受到物理攻擊時 Yubikey 仍具抵抗力。
|
||||
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">警告</p>
|
||||
@ -100,14 +100,14 @@ Yubikey 安全金鑰的韌體不可更新。 如果您想要使用較新韌體
|
||||
|
||||
[比較表](https://nitrokey.com/#comparison) 顯示 Nitrokey 模式的功能以及比較方式。 **Nitrokey 3** 具有組合的功能集。
|
||||
|
||||
Nitrokey 模式可用 [Nitrokey 應用程式](https://nitrokey.com/download) 來配置。
|
||||
Nitrokey 模式可用 [Nitrokey 應用程式](https://nitrokey.com/download) 來設定。
|
||||
|
||||
支持 HOTP 和 TOTP 的型號,有3個 HOTP 插槽,15 個 TOTP 插槽。 有些 Nitrokeys 可以充當密碼管理器。 可以存儲 16 組憑證,並使用與 OpenPGP 接口相同的密碼對憑證加密。
|
||||
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">警告</p>
|
||||
|
||||
雖然 Nitrokeys 不會將 HOTP/TOTP 機密釋放給所插入的設備,但HOTP 和 TOTP存儲\* _未經加密_ \* ,容易受到物理攻擊。 如果需要存儲 HOTP 或 TOTP 這類祕密,強烈建議使用Yubikey 代替。
|
||||
雖然 Nitrokeys 不會將 HOTP/TOTP 機密釋放給所插入的裝置,但HOTP 和 TOTP 儲存\* _未經加密_ \* ,容易受到物理攻擊。 如果需要存儲 HOTP 或 TOTP 這類機密,強烈建議使用Yubikey 代替。
|
||||
|
||||
</div>
|
||||
|
||||
|
@ -568,7 +568,7 @@ description: Privacy Guides 社群所推薦的隱私工具、服務、軟體及
|
||||
|
||||
## 硬體
|
||||
|
||||
### 安全密鑰
|
||||
### 安全金鑰
|
||||
|
||||
<div class="grid cards" markdown>
|
||||
|
||||
|
@ -72,7 +72,7 @@ Proton VPN [在 112 個國家設有伺服器](https://protonvpn.com/vpn-servers)
|
||||
|
||||
1. 最近檢查日期: 2024-08-06
|
||||
|
||||
我們認為,如果 VPN 提供商使用[專用伺服器](https://en.wikipedia.org/wiki/Dedicated_hosting_service),而不是更便宜、與其他客戶共享的解決方案 (例如[虛擬服務器](https://en.wikipedia.org/wiki/Virtual_private_server)),對其私鑰的安全性會更好。
|
||||
我們認為,如果 VPN 提供商使用[專用伺服器](https://en.wikipedia.org/wiki/Dedicated_hosting_service),而不是更便宜、與其他客戶共享的解決方案 (例如[虛擬伺服器](https://en.wikipedia.org/wiki/Virtual_private_server)),對其私鑰的安全性會更好。
|
||||
|
||||
#### :material-check:{ .pg-green } 獨立稽核
|
||||
|
||||
@ -152,7 +152,7 @@ IVPN 在 [37 個國家/地區設有伺服器](https://ivpn.net/status)。 (1)
|
||||
|
||||
1. 最近檢查日期: 2024-08-06
|
||||
|
||||
我們認為,如果 VPN 提供商使用[專用伺服器](https://en.wikipedia.org/wiki/Dedicated_hosting_service),而不是更便宜、與其他客戶共享的解決方案 (例如[虛擬服務器](https://en.wikipedia.org/wiki/Virtual_private_server)),對其私鑰的安全性會更好。
|
||||
我們認為,如果 VPN 提供商使用[專用伺服器](https://en.wikipedia.org/wiki/Dedicated_hosting_service),而不是更便宜、與其他客戶共享的解決方案 (例如[虛擬伺服器](https://en.wikipedia.org/wiki/Virtual_private_server)),對其私鑰的安全性會更好。
|
||||
|
||||
#### :material-check:{ .pg-green } 獨立稽核
|
||||
|
||||
@ -227,7 +227,7 @@ Mullvad 在 [45 個國家/地區設有伺服器](https://mullvad.net/servers)。
|
||||
|
||||
1. 最近檢查日期: 2024-08-06
|
||||
|
||||
我們認為,如果 VPN 提供商使用[專用伺服器](https://en.wikipedia.org/wiki/Dedicated_hosting_service),而不是更便宜、與其他客戶共享的解決方案 (例如[虛擬服務器](https://en.wikipedia.org/wiki/Virtual_private_server)),對其私鑰的安全性會更好。
|
||||
我們認為,如果 VPN 提供商使用[專用伺服器](https://en.wikipedia.org/wiki/Dedicated_hosting_service),而不是更便宜、與其他客戶共享的解決方案 (例如[虛擬伺服器](https://en.wikipedia.org/wiki/Virtual_private_server)),對其私鑰的安全性會更好。
|
||||
|
||||
#### :material-check:{ .pg-green } 獨立稽核
|
||||
|
||||
|
@ -227,7 +227,7 @@ Because Mull has more advanced and strict privacy protections enabled by default
|
||||
|
||||
## Safari (iOS)
|
||||
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
|
||||
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so a browser like [Brave](#brave) does not use the Chromium engine like its counterparts on other operating systems.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@ -249,6 +249,23 @@ We would suggest installing [AdGuard](browser-extensions.md#adguard) if you want
|
||||
|
||||
The following privacy/security-related options can be found in :gear: **Settings** → **Apps** → **Safari**.
|
||||
|
||||
#### Allow Safari to Access
|
||||
|
||||
Under **Siri**:
|
||||
|
||||
- [ ] Disable **Learn from this App**
|
||||
- [ ] Disable **Show in App**
|
||||
- [ ] Disable **Show on Home Screen**
|
||||
- [ ] Disable **Suggest App**
|
||||
|
||||
This prevents Siri from using content from Safari for Siri suggestions.
|
||||
|
||||
#### 搜索
|
||||
|
||||
- [ ] Disable **Search Engine Suggestions**
|
||||
|
||||
This setting sends whatever you type in the address bar to the search engine set in Safari. 禁用搜索建议可以让你更精确地控制你向搜索引擎供应商发送的数据。
|
||||
|
||||
#### Profiles
|
||||
|
||||
Safari allows you to separate your browsing with different profiles. All of your cookies, history, and website data are separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
|
||||
@ -263,6 +280,32 @@ This enables WebKit's [Intelligent Tracking Protection](https://webkit.org/track
|
||||
|
||||
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
|
||||
|
||||
- [ ] Disable **Fraudulent Website Warning**
|
||||
|
||||
This setting uses Google Safe Browsing (or Tencent Safe Browsing for users in mainland China or Hong Kong) to protect you while you browse. As such, your IP address may be logged by your Safe Browsing provider. Disabling this setting will disable this logging, but you might be more vulnerable to known phishing sites.
|
||||
|
||||
- [ ] Disable **Highlights**
|
||||
|
||||
Apple's privacy policy for Safari states:
|
||||
|
||||
> When visiting a webpage, Safari may send information calculated from the webpage address to Apple over OHTTP to determine if relevant highlights are available.
|
||||
|
||||
#### Settings for Websites
|
||||
|
||||
Under **Camera**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Microphone**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
Under **Location**
|
||||
|
||||
- [x] Select **Ask**
|
||||
|
||||
These settings ensure that websites can only access your camera, microphone, or location after you explicitly grant them access.
|
||||
|
||||
#### Other Privacy Settings
|
||||
|
||||
These options can be found in :gear: **Settings** → **Apps** → **Safari** → **Advanced**.
|
||||
|
Reference in New Issue
Block a user