mirror of
https://github.com/privacyguides/privacyguides.org.git
synced 2026-10-01 19:12:43 +00:00
Compare commits
24
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0a97e4cdd5 | ||
|
|
c3e1984cbd | ||
|
|
f7316b605e | ||
|
|
dbc140bd50 | ||
|
|
9262e3401b | ||
|
|
aca2cf49fe | ||
|
|
d077e5b66b | ||
|
|
b1441f5960 | ||
|
|
02620825ea | ||
|
|
31d4a3ad82 | ||
|
|
0f6eee20c9 | ||
|
|
e40376173a | ||
|
|
8be53ef24b | ||
|
|
4ad7b0d6a1 | ||
|
|
95f851315e | ||
|
|
3aef104a9d | ||
|
|
3b27fed149 | ||
|
|
2cba767aa1 | ||
|
|
7a0ff96a61 | ||
|
|
d52f5a4ee2 | ||
|
|
c0514c4b28 | ||
|
|
86b22a99f0 | ||
|
|
55460d4d26 | ||
|
|
4a3e1ab486
|
@@ -81,7 +81,7 @@
|
||||
},
|
||||
"extensions": [
|
||||
"EditorConfig.EditorConfig",
|
||||
"DavidAnson.vscode-markdownlint",
|
||||
"rvben.rumdl",
|
||||
"wholroyd.jinja",
|
||||
"mikestead.dotenv",
|
||||
"redhat.vscode-yaml",
|
||||
|
||||
+14
@@ -0,0 +1,14 @@
|
||||
[global]
|
||||
disable = ["md013", "md033", "md046", "md026"]
|
||||
|
||||
[md007]
|
||||
indent = 4
|
||||
|
||||
[md010]
|
||||
code_blocks = false
|
||||
|
||||
[md024]
|
||||
siblings_only = true
|
||||
|
||||
[md049]
|
||||
style = "asterisk"
|
||||
Vendored
+1
-1
@@ -21,7 +21,7 @@
|
||||
{
|
||||
"recommendations": [
|
||||
"EditorConfig.EditorConfig",
|
||||
"DavidAnson.vscode-markdownlint",
|
||||
"rvben.rumdl",
|
||||
"wholroyd.jinja",
|
||||
"mikestead.dotenv",
|
||||
"redhat.vscode-yaml",
|
||||
|
||||
Vendored
+1
-1
@@ -91,7 +91,7 @@
|
||||
},
|
||||
"editor.unicodeHighlight.ambiguousCharacters": true,
|
||||
"editor.unicodeHighlight.invisibleCharacters": true,
|
||||
"editor.defaultFormatter": "DavidAnson.vscode-markdownlint",
|
||||
"editor.defaultFormatter": "rvben.rumdl",
|
||||
"[yaml]": {
|
||||
"editor.defaultFormatter": "redhat.vscode-yaml",
|
||||
"editor.quickSuggestions": {
|
||||
|
||||
@@ -112,7 +112,7 @@ Committing to this repository requires [signing your commits](https://docs.githu
|
||||
|
||||
## Releasing
|
||||
|
||||
It is required to create a GitHub release to publish the current site to privacyguides.org. The current `main` branch can be previewed at [https://main.staging.privacyguides.dev](https://main.staging.privacyguides.dev) prior to release.
|
||||
It is required to create a GitHub release to publish the current site to privacyguides.org.
|
||||
|
||||
1. Create a new tag: `git tag -s YYYY.MM.DD -m 'Some message'`
|
||||
- Tag numbering: `YYYY.MM.DD` - if two+ releases are published on the same day, append short commit to the next release, e.g. `YYYY.MM.DD-6aa14e8`
|
||||
|
||||
@@ -45,7 +45,7 @@ A famous example is the AOL search log release. AOL had been logging its users s
|
||||
|
||||
#### Strava Heatmap Incident
|
||||
|
||||
In 2018, the fitness app Strava announced a major update to its heatmap, showing the the workout patterns of users of fitness trackers like Fitbit.
|
||||
In 2018, the fitness app Strava announced a major update to its heatmap, showing the workout patterns of users of fitness trackers like Fitbit.
|
||||
|
||||
Analyst [Nathan Ruser](https://x.com/Nrg8000/status/957318498102865920) indicated that these patterns can reveal military bases and troop movement patterns. This is obviously a huge op-sec problem and can endanger the lives of troops.
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@ tags:
|
||||
- Email
|
||||
license: BY-SA
|
||||
schema_type: BackgroundNewsArticle
|
||||
description: Email is ubiquitous. If you want to function in modern society, you pretty much have to have an email address. But is it really a good idea to still be relying on the same decades old techology? What can we do about replacing it?
|
||||
description: Email is ubiquitous. If you want to function in modern society, you pretty much have to have an email address. But is it really a good idea to still be relying on the same decades old technology? What can we do about replacing it?
|
||||
preview:
|
||||
cover: blog/assets/images/email-security/cover.png
|
||||
---
|
||||
|
||||
@@ -266,7 +266,7 @@ Confirm your choice by clicking on "Save changes" on the upper-right.
|
||||

|
||||
|
||||
<div class="admonition tip" markdown>
|
||||
<p class="admonition-title">Hide posted media (slighly)</p>
|
||||
<p class="admonition-title">Hide posted media (slightly)</p>
|
||||
|
||||
Additionally, you might want to check the "Always mark media as sensitive" option from the same section. This will label the media as "Sensitive content", and require others to click on it to view the image. This will **not stop anyone from clicking to view it**, including people without a Mastodon account from your account's public page, but it might *slightly* reduce the visibility for certain media.
|
||||
|
||||
|
||||
@@ -59,7 +59,7 @@ There are different levels to this. It could mean sharing a first name but not a
|
||||
|
||||
Using a pseudonym and a profile picture that isn't a self-portrait can help significantly to reduce digital footprints and improve online safety. It can also help to detach different accounts from each other, for example by using a certain name for a work account and a pseudonym for a personal alt account.
|
||||
|
||||
Remember that that this will not make you anonymous online, however. It will only help hide or separate your legal identity from your public-facing profile.
|
||||
Remember that this will not make you anonymous online, however. It will only help hide or separate your legal identity from your public-facing profile.
|
||||
|
||||
If you want to use more serious pseudonymity online, you will also need to consider using different email addresses to sign up, different phone numbers if required, different photos of course, but also different IP addresses, and so on and so forth.
|
||||
|
||||
|
||||
@@ -28,11 +28,12 @@ MAGIC Grants is our fiscal host, and their custom, open-source donation platform
|
||||
|
||||
<div class="mdx-specialthanks" markdown>
|
||||
|
||||
[![Power Up Privacy]](https://powerupprivacy.com){ rel=nofollow target=_blank title="Power Up Privacy" }
|
||||
[![DeleteMe]](https://joindeleteme.com){ rel=nofollow target=_blank title="DeleteMe" }
|
||||
![Power Up Privacy]{ title="Power Up Privacy" }
|
||||
[![Cape]](https://www.cape.co){ target=_blank title="Cape" }
|
||||
|
||||
[Power Up Privacy]: ../assets/img/donors/power-up-privacy.webp
|
||||
[DeleteMe]: ../assets/img/donors/deleteme.webp
|
||||
[Cape]: ../assets/img/donors/cape.webp
|
||||
|
||||
</div>
|
||||
|
||||
@@ -41,6 +42,7 @@ MAGIC Grants is our fiscal host, and their custom, open-source donation platform
|
||||
Thank you to these organizations who have substantially supported our project in the past.
|
||||
|
||||
- [Safing](https://safing.io){ rel=nofollow target=_blank }: 2019 – 2021
|
||||
- [DeleteMe](https://joindeleteme.com){ rel=nofollow target=_blank }: 2025
|
||||
|
||||
## Active Members
|
||||
|
||||
@@ -83,7 +85,7 @@ You can become an organizational member by reaching out to <info@magicgrants.org
|
||||
|
||||
### How are organizational members recognized?
|
||||
|
||||
Organizational members that choose to be recognized publicly are included in our organizational members section (above), and occasionally at other opportunities where appropriate. Organizational member links include the `rel="nofollow"` attribute: We adopted this policy to screen out potential abuse of our program and site to raise the rank of third parties in search algorithms. Unfortunately, this is a growing problem for nonprofits. This was a complex decision since we know many of the sincere supporters behind these companies, but we decided that it was the best choice for us.
|
||||
Organizational members that choose to be recognized publicly are included in our organizational members section (above), and occasionally at other opportunities where appropriate.
|
||||
|
||||
Organizational members have no ability to influence what content is recommended on the Privacy Guides website. Learn more about our [donation acceptance policy](donation-acceptance-policy.md).
|
||||
|
||||
|
||||
@@ -107,10 +107,10 @@ This topic has been discussed extensively within our communities in various loca
|
||||
|
||||
- [June 28, 2021 request for control of r/privacytoolsIO](https://reddit.com/comments/o9tllh)
|
||||
- [July 27, 2021 announcement of our intentions to move on the PrivacyTools blog, written by the team](https://web.archive.org/web/20210729184422/https://blog.privacytools.io/the-future-of-privacytools)
|
||||
- [Sept 13, 2021 announcement of the beginning of our transition to Privacy Guides on r/privacytoolsIO](https://reddit.com/pnql46)
|
||||
- [Sept 13, 2021 announcement of the beginning of our transition to Privacy Guides on r/privacytoolsIO](https://archive.ph/rMevJ)
|
||||
- [Sept 17, 2021 announcement on OpenCollective from Jonah](https://opencollective.com/privacyguides/updates/transitioning-to-privacy-guides)
|
||||
- [Sept 30, 2021 Twitter thread detailing most of the events now described on this page](https://twitter.com/privacy_guides/status/1443633412800225280)
|
||||
- [Oct 1, 2021 post by u/dng99 noting subdomain failure](https://reddit.com/comments/pymthv/comment/hexwrps)
|
||||
- [Apr 2, 2022 response by u/dng99 to PrivacyTools' accusatory blog post](https://reddit.com/comments/tuo7mm/comment/i35kw5a)
|
||||
- [May 16, 2022 response by @TommyTran732 on Twitter](https://twitter.com/TommyTran732/status/1526153497984618496)
|
||||
- [Sep 3, 2022 post on Techlore's forum by @dngray](https://discuss.techlore.tech/t/has-anyone-seen-this-video-wondering-your-thoughts/792/20)
|
||||
- [Sep 3, 2022 post on Techlore's forum by @dngray](https://web.archive.org/web/20260521005749/https://discuss.techlore.tech/t/has-anyone-seen-this-video-wondering-your-thoughts/792/20)
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
---
|
||||
title: Consider Everyone's Unique Situation
|
||||
description: To give actionable privacy advices, it's essential to consider everyone's situation. Learn more on how you can evaluate each person's unique threat model.
|
||||
description: To give actionable privacy advice, it's essential to consider everyone's situation. Learn more on how you can evaluate each person's unique threat model.
|
||||
icon: fontawesome/solid/users-between-lines
|
||||
cover: activism/banner-toolbox-tip-everyone.webp
|
||||
---
|
||||
|
||||
@@ -126,7 +126,7 @@ In this example we will record what happens when we make a DoH request:
|
||||
|
||||
We can see the [connection establishment](https://en.wikipedia.org/wiki/Transmission_Control_Protocol#Connection_establishment) and [TLS handshake](https://cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake) that occurs with any encrypted connection. When looking at the "application data" packets that follow, none of them contain the domain we requested or the IP address returned.
|
||||
|
||||
## Why **shouldn't** I use encrypted DNS?
|
||||
## Encrypted DNS Limitations
|
||||
|
||||
In locations where there is internet filtering (or censorship), visiting forbidden resources may have its own consequences which you should consider in your [threat model](../basics/threat-modeling.md). We do **not** suggest the use of encrypted DNS for this purpose. Use [Tor](../advanced/tor-overview.md) or a [VPN](../vpn.md) instead. If you're using a VPN, you should use your VPN's DNS servers. When using a VPN, you are already trusting them with all your network activity.
|
||||
|
||||
|
||||
@@ -92,7 +92,11 @@ It is critical to understand the difference between bypassing censorship and eva
|
||||
|
||||
### Tor Browser is not the most *secure* browser
|
||||
|
||||
Anonymity can often be at odds with security: Tor's anonymity requires every user to be identical, which creates a monoculture (e.g., the same bugs are present across all Tor Browser users). As a cybersecurity rule of thumb, monocultures are generally regarded as bad: Security through diversity (which Tor lacks) provides natural segmentation by limiting vulnerabilities to smaller groups, and is therefore usually desirable, but this diversity is also less good for anonymity.
|
||||
Anonymity can often be at odds with security. Tor achieves anonymity by ensuring more users appear [similar](https://support.torproject.org/tor-browser/features/fingerprinting-protections/#:~:text=Tor%20Browser%20is,individual%20users%20effectively.):
|
||||
|
||||
>Tor Browser is specifically engineered to minimize the uniqueness of each user's fingerprint across various metrics. While it is practically impossible to make all Tor Browser users identical, the goal is to reduce the number of distinguishable "buckets" for each metric. This approach makes it harder to track individual users effectively.
|
||||
|
||||
While this is effective at preserving anonymity, it also creates a digital monoculture where the same vulnerabilities exist across many installations. In cybersecurity, monocultures are generally considered a risk. Security through diversity provides natural segmentation by limiting the impact of an exploit to a smaller segment of users. While such diversity is structurally desirable for security, it inherently compromises user anonymity by making individuals trackable.
|
||||
|
||||
Additionally, Tor Browser is based on Firefox's Extended Support Release builds, which only receives patches for vulnerabilities considered *Critical* and *High* (not *Medium* and *Low*). This means that attackers could (for example):
|
||||
|
||||
|
||||
@@ -121,6 +121,6 @@ The [F-Droid](https://f-droid.org/en/packages) and [IzzyOnDroid](https://apt.izz
|
||||
<div class="admonition note" markdown>
|
||||
<p class="admonition-title">F-Droid Basic</p>
|
||||
|
||||
In some rare cases, the developer of an app will only distribute it through F-Droid ([Gadgetbridge](../health-and-wellness.md#gadgetbridge) is one example of this). If you really need an app like that, we recommend using the newer [F-Droid Basic](https://f-droid.org/en/packages/org.fdroid.basic) client instead of the original F-Droid app to obtain it. F-Droid Basic supports automatic background updates without privileged extension or root, and has a reduced feature set (limiting attack surface).
|
||||
In some rare cases, an app may only be available through F-Droid. If you really need an app like that, we recommend using the newer [F-Droid Basic](https://f-droid.org/en/packages/org.fdroid.basic) client instead of the original F-Droid app to obtain it, as it has a reduced feature set (limiting attack surface).
|
||||
|
||||
</div>
|
||||
|
||||
@@ -140,7 +140,7 @@ If the hostname of your system changes (such as due to DHCP), you would be unabl
|
||||
|
||||
</div>
|
||||
|
||||
The `pam_u2f` module on Linux can provide two-factor authentication for logging in on most popular Linux distributions. If you have a hardware security key that supports U2F, you can set up MFA authentication for your login. Yubico has a guide [Ubuntu Linux Login Guide - U2F](https://support.yubico.com/hc/articles/360016649099-Ubuntu-Linux-Login-Guide-U2F) which should work on any distribution. The package manager commands—such as `apt-get`—and package names may however differ. This guide does **not** apply to Qubes OS.
|
||||
The `pam_u2f` module on Linux can provide two-factor authentication for logging in on most popular Linux distributions. If you have a hardware security key that supports U2F, you can set up MFA authentication for your login. Yubico has a guide [Ubuntu Linux Login Guide - U2F](https://support.yubico.com/s/article/Ubuntu-Linux-login-guide-U2F) which should work on any distribution. The package manager commands—such as `apt-get`—and package names may however differ. This guide does **not** apply to Qubes OS.
|
||||
|
||||
### Qubes OS
|
||||
|
||||
|
||||
@@ -89,8 +89,6 @@ Tresorit has received a number of independent security audits:
|
||||
|
||||
[^1]: [ISO/IEC 27001](https://en.wikipedia.org/wiki/ISO/IEC_27001):2013 compliance relates to the company's [information security management system](https://en.wikipedia.org/wiki/Information_security_management) and covers the sales, development, maintenance and support of their cloud services.
|
||||
|
||||
They have also received the Digital Trust Label, a certification from the [Swiss Digital Initiative](https://efd.admin.ch/en/swiss-digital-initiative-en) which requires passing [35 criteria](https://swiss-digital-initiative.org/criteria) related to security, privacy, and reliability.
|
||||
|
||||
## Peergos
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@@ -74,7 +74,6 @@ There are numerous centralized exchanges (CEX) as well as P2P marketplaces where
|
||||
- [Kraken](https://kraken.com): A well-known CEX. Registration and KYC are mandatory. Card payments and bank transfers accepted. Make sure not to leave your newly purchased Monero on Kraken's platform after the purchase; withdraw them to a self-custody wallet. Monero is not available in all jurisdictions that Kraken operates in.[^1]
|
||||
- [Cake Wallet](https://cakewallet.com): A self-custody cross-platform wallet for Monero and other cryptocurrencies. You can buy Monero directly in the app using card payments or bank transfers (through third-party providers such as [Guardarian](https://guardarian.com) or [DFX](https://dfx.swiss)).[^2] KYC is usually not required, but it depends on your country and the amount you are purchasing. In countries where directly purchasing Monero is not possible, you can also use a provider within Cake Wallet to first buy another cryptocurrency such as Bitcoin, Bitcoin Cash, or Litecoin and then exchange it to Monero in-app.
|
||||
- [Monero.com](https://monero.com) is an associated website where you can buy Monero and other cryptocurrencies without having to download an app. The funds will simply be sent to the wallet address of your choice.
|
||||
- [RetoSwap](https://retoswap.com) (formerly known as Haveno-Reto) is a self-custody, decentralized P2P exchange platform based on the [Haveno](https://haveno.exchange) project which is available for Linux, Windows, and macOS. Monero can be bought and sold with maximum privacy, since most trading counterparties do not require KYC, trades are made directly between users (P2P), and all connections run through the Tor network. It is possible to buy Monero via bank transfer, PayPal, or even by paying in cash (meeting in person or sending by mail). Arbitrators can step in to resolve disputes between buyer and seller, but be careful when sharing your bank account or other sensitive information with your trading counterparty. Trading with some accounts may be against those accounts' terms of service.
|
||||
|
||||
## Criteria
|
||||
|
||||
|
||||
@@ -34,7 +34,6 @@ You should search for your information on these sites first, and submit an opt-o
|
||||
- InfoTracer ([Search](https://infotracer.com), [Opt-Out](https://infotracer.com/optout))
|
||||
- Intelius ([Search](https://intelius.com), [Opt-Out](https://suppression.peopleconnect.us/login))
|
||||
- PublicDataUSA ([Search](https://publicdatausa.com), [Opt-Out](https://publicdatausa.com/remove.php))
|
||||
- Radaris ([Search](https://radaris.com), [Opt-Out](https://radaris.com/page/how-to-remove))
|
||||
- Spokeo ([Search](https://spokeo.com/search), [Opt-Out](https://spokeo.com/optout))
|
||||
- That's Them ([Search](https://thatsthem.com), [Opt-Out](https://thatsthem.com/optout))
|
||||
- USPhonebook ([Search and Opt-Out](https://usphonebook.com/opt-out))
|
||||
|
||||
@@ -5,11 +5,19 @@ icon: material/tag-remove
|
||||
description: Use these tools to remove metadata like GPS location and other identifying information from photos and files you share.
|
||||
cover: data-redaction.webp
|
||||
---
|
||||
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
- [:material-account-search: Public Exposure](basics/common-threats.md#limiting-public-information){ .pg-green }
|
||||
|
||||
When sharing files, be sure to remove associated metadata. Image files commonly include [Exif](https://en.wikipedia.org/wiki/Exif) data. Photos sometimes even include GPS coordinates in the file metadata.
|
||||
When sharing files, be sure to remove associated metadata. Most common file types (including documents, images, and videos) include metadata. Image files, for example, commonly include Exif data. Photos sometimes even include GPS coordinates in the file metadata.
|
||||
|
||||
Windows has a built-in metadata remover, but unfortunately it cannot remove many types of data such as:
|
||||
|
||||
- Documents: Comments, author names, tracked changes, hidden worksheets, slide notes, custom XML, and document revision histories.
|
||||
- Images: Camera serial numbers, XMP/IPTC data, C2PA metadata, and image thumbnails (which can dangerously expose original details from cropped or erased areas).
|
||||
- Audio & Video: XMP metadata, C2PA metadata, and certain ID3v2 tag fields.
|
||||
- Embedded Files: Hidden metadata nested inside images that are embedded within documents.
|
||||
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">Warning</p>
|
||||
|
||||
@@ -62,7 +62,7 @@ schema:
|
||||
|
||||
These are our currently recommended **desktop web browsers** and configurations for standard/non-anonymous browsing. We recommend [Mullvad Browser](#mullvad-browser) if you are focused on strong privacy protections and anti-fingerprinting out of the box, [Firefox](#firefox) for casual internet browsers looking for a good alternative to Google Chrome, and [Brave](#brave) if you need Chromium browser compatibility.
|
||||
|
||||
If you need to browse the internet anonymously, you should use [Tor](tor.md) instead. We make some configuration recommendations on this page, but all browsers other than Tor Browser will be traceable by *somebody* in some manner or another.
|
||||
If you need to browse the internet anonymously, you should use [Tor Browser](tor.md) instead. We make some configuration recommendations on this page, but Tor Browser offers the best protections against online tracking.
|
||||
|
||||
## Mullvad Browser
|
||||
|
||||
@@ -88,7 +88,7 @@ If you need to browse the internet anonymously, you should use [Tor](tor.md) ins
|
||||
|
||||
</div>
|
||||
|
||||
Like [Tor Browser](tor.md), Mullvad Browser is designed to prevent fingerprinting by making your browser fingerprint identical to all other Mullvad Browser users, and it includes default settings and extensions that are automatically configured by the default security levels: *Standard*, *Safer* and *Safest*.
|
||||
Like [Tor Browser](tor.md), Mullvad Browser is designed to prevent fingerprinting by making your browser fingerprint similar to a large number of other Mullvad Browser users, and it includes default settings and extensions that are automatically configured by the default security levels: *Standard*, *Safer* and *Safest*.
|
||||
|
||||
Therefore, it is imperative that you do not modify the browser at all outside adjusting the default [security levels](https://tb-manual.torproject.org/security-settings). When adjusting the security level, you **must** always restart the browser before continuing to use it. Otherwise, [the security settings may not be fully applied](https://www.privacyguides.org/articles/2025/05/02/tor-security-slider-flaw), putting you at a higher risk of fingerprinting and exploits than you may expect based on the setting chosen.
|
||||
|
||||
@@ -98,7 +98,7 @@ Modifications other than adjusting this setting would make your fingerprint uniq
|
||||
|
||||
**Without** using a [VPN](vpn.md), Mullvad Browser provides protections against [naive fingerprinting scripts](https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#-fingerprinting) similar to other private browsers like Firefox+[Arkenfox](#arkenfox-advanced) or [Brave](#brave). Mullvad Browser provides these protections out of the box, at the expense of some flexibility and convenience that other private browsers can provide.
|
||||
|
||||
==For the strongest anti-fingerprinting protection, we recommend using Mullvad Browser in conjunction **with** a VPN==, whether that is Mullvad or another recommended VPN provider. When using a VPN with Mullvad Browser, you will share a fingerprint and a pool of IP addresses with many other users, giving you a "crowd" to blend in with. This strategy is the only way to thwart advanced tracking scripts, and is the same anti-fingerprinting technique used by Tor Browser.
|
||||
==For the strongest anti-fingerprinting protection, we recommend using Mullvad Browser in conjunction **with** a VPN==, whether that is Mullvad or another recommended VPN provider. When using a VPN with Mullvad Browser, you will share a fingerprint and a pool of IP addresses with many other users, giving you a "crowd" to blend in with. This strategy is the best way to defend against advanced tracking scripts, and is the same anti-fingerprinting technique used by Tor Browser.
|
||||
|
||||
Note that while you can use Mullvad Browser with any VPN provider, other people on that VPN must also be using Mullvad Browser for this "crowd" to exist, something which is more likely on Mullvad VPN compared to other providers. Mullvad Browser does not have built-in VPN connectivity, nor does it check whether you are using a VPN before browsing; your VPN connection has to be configured and managed separately.
|
||||
|
||||
@@ -329,6 +329,7 @@ Brave's Web3 features can potentially add to your browser fingerprint and attack
|
||||
|
||||
- Select **Extensions (no fallback)** under *Default Ethereum wallet*
|
||||
- Select **Extensions (no fallback)** under *Default Solana wallet*
|
||||
- Select **Extensions (no fallback)** under *Default Cardano wallet*
|
||||
|
||||
#### Extensions
|
||||
|
||||
|
||||
+1
-6
@@ -23,8 +23,7 @@ These are our favorite public DNS resolvers based on their privacy and security
|
||||
| [**AdGuard Public DNS**](https://adguard-dns.io/en/public-dns.html) | Cleartext <br>DoH/3 <br>DoT <br>DoQ <br>DNSCrypt | Anonymized[^1] | Anonymized | Based on server choice. Filter list being used can be found here. [:octicons-link-external-24:](https://github.com/AdguardTeam/AdGuardSDNSFilter) | Yes [:octicons-link-external-24:](https://adguard-dns.io/en/blog/encrypted-dns-ios-14.html) |
|
||||
| [**Cloudflare**](https://developers.cloudflare.com/1.1.1.1/setup) | Cleartext <br>DoH/3 <br>DoT | Anonymized[^2] | No | Based on server choice. | No [:octicons-link-external-24:](https://community.cloudflare.com/t/requesting-1-1-1-1-signed-profiles-for-apple/571846) |
|
||||
| [**Control D Free DNS**](https://controld.com/free-dns) | Cleartext <br>DoH/3 <br>DoT <br>DoQ | No[^3] | No | Based on server choice. | Yes <br>[:simple-apple: iOS](https://docs.controld.com/docs/ios-platform) <br>[:material-apple-finder: macOS](https://docs.controld.com/docs/macos-platform#manual-setup-profile) |
|
||||
| [**Mullvad**](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls) | DoH <br>DoT | No[^4] | No | Based on server choice. Filter list being used can be found here. [:octicons-link-external-24:](https://github.com/mullvad/dns-adblock) | Yes [:octicons-link-external-24:](https://github.com/mullvad/encrypted-dns-profiles) |
|
||||
| [**Quad9**](https://quad9.net) | Cleartext <br>DoH/3 <br>DoT <br>DoQ <br>DNSCrypt | Anonymized[^5] | Optional | Based on server choice. Malware blocking is included by default. | Yes <br>[:simple-apple: iOS](https://docs.quad9.net/Setup_Guides/iOS/iOS_14_and_later_(Encrypted)) <br>[:material-apple-finder: macOS](https://docs.quad9.net/Setup_Guides/MacOS/Big_Sur_and_later_(Encrypted)) |
|
||||
| [**Quad9**](https://quad9.net) | Cleartext <br>DoH/3 <br>DoT <br>DoQ <br>DNSCrypt | Anonymized[^4] | Optional | Based on server choice. Malware blocking is included by default. | Yes <br>[:simple-apple: iOS](https://docs.quad9.net/Setup_Guides/iOS/iOS_14_and_later_(Encrypted)) <br>[:material-apple-finder: macOS](https://docs.quad9.net/Setup_Guides/MacOS/Big_Sur_and_later_(Encrypted)) |
|
||||
|
||||
[^1]:
|
||||
AdGuard stores aggregated performance metrics of their DNS servers, namely the number of complete requests to a particular server, the number of blocked requests, and the speed of processing requests. They also keep and store the database of domains requested within the last 24 hours.
|
||||
@@ -41,10 +40,6 @@ These are our favorite public DNS resolvers based on their privacy and security
|
||||
|
||||
Control D: [*Privacy Policy*](https://controld.com/privacy)
|
||||
[^4]:
|
||||
Mullvad's DNS service is available to both subscribers and non-subscribers of Mullvad VPN. Their privacy policy explicitly claims they do not log DNS requests in any way.
|
||||
|
||||
Mullvad: [*No-logging of user activity policy*](https://mullvad.net/en/help/no-logging-data-policy)
|
||||
[^5]:
|
||||
Quad9 collects some data for the purposes of threat monitoring and response. That data may then be remixed and shared for purposes like furthering their security research. Quad9 does not collect or record IP addresses or other data they deem personally identifiable.
|
||||
|
||||
Quad9: [*Data and Privacy Policy*](https://quad9.net/privacy/policy)
|
||||
|
||||
@@ -4,6 +4,7 @@ icon: material/email-lock
|
||||
description: An email aliasing service allows you to easily generate a new email address for every website you register for.
|
||||
cover: email-aliasing.webp
|
||||
---
|
||||
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
- [:material-account-cash: Surveillance Capitalism](basics/common-threats.md#surveillance-as-a-business-model){ .pg-brown }
|
||||
@@ -119,9 +120,9 @@ If you cancel your subscription, you will still enjoy the features of your paid
|
||||
|
||||
</div>
|
||||
|
||||
SimpleLogin was [acquired by Proton AG](https://proton.me/news/proton-and-simplelogin-join-forces) as of April 8, 2022. If you use Proton Mail for your primary mailbox, SimpleLogin is a great choice. As both products are now owned by the same company you now only have to trust a single entity. We also expect that SimpleLogin will be more tightly integrated with Proton's offerings in the future. SimpleLogin continues to support forwarding to any email provider of your choosing.
|
||||
SimpleLogin was [acquired by Proton AG](https://proton.me/news/proton-and-simplelogin-join-forces) on April 8, 2022, making it an excellent option for users of [Proton Mail](email.md#proton-mail) as their primary mailbox. With this acquisition, you only need to trust a single entity for your email services. SimpleLogin still allows forwarding to any email provider of your choice.
|
||||
|
||||
You can link your SimpleLogin account in the settings with your Proton account. If you have Proton Pass Plus, Proton Unlimited, or any multi-user Proton plan, you will have SimpleLogin Premium for free. You can also purchase a voucher code for SimpleLogin Premium anonymously via their official reseller [ProxyStore](https://simplelogin.io/faq).
|
||||
You can link your SimpleLogin account in the settings with your Proton account. If you have Proton Pass Plus, Proton Unlimited, or any multi-user Proton plan, you will have SimpleLogin Premium for free. Likewise both the [Free and Premium tiers](https://simplelogin.io/pricing/) of SimpleLogin now include Proton Pass subscriptions. You can also purchase a voucher code for SimpleLogin Premium anonymously via their official reseller [ProxyStore](https://simplelogin.io/faq).
|
||||
|
||||
Securitum [audited](https://simplelogin.io/blog/security-audit) SimpleLogin in early 2022 and all issues [were addressed](https://simplelogin.io/audit2022/web.pdf).
|
||||
|
||||
|
||||
+3
-4
@@ -92,7 +92,7 @@ Proton Mail has internal crash reports that are **not** shared with third partie
|
||||
|
||||
From your inbox, select :gear: → **All Settings** → **Account** → **Security and privacy** → **Privacy and data collection**.
|
||||
|
||||
- [ ] Disable **Collect usage dignostics**
|
||||
- [ ] Disable **Collect usage diagnostics**
|
||||
- [ ] Disable **Send crash reports**
|
||||
|
||||
=== "Mobile"
|
||||
@@ -100,7 +100,7 @@ Proton Mail has internal crash reports that are **not** shared with third partie
|
||||
From your inbox, select :material-menu: → :gear: **Settings** → select your username.
|
||||
|
||||
- [ ] Disable **Send crash reports**
|
||||
- [ ] Disable **Collect usage dignostics**
|
||||
- [ ] Disable **Collect usage diagnostics**
|
||||
|
||||
#### :material-check:{ .pg-green } Custom Domains and Aliases
|
||||
|
||||
@@ -167,7 +167,7 @@ Mailbox Mail doesn't accept any cryptocurrencies as a result of their payment pr
|
||||
|
||||
#### :material-check:{ .pg-green } Account Security
|
||||
|
||||
Mailbox Mail supports [two-factor authentication](https://kb.mailbox.org/en/private/security-and-privacy/how-to-use-two-factor-authentication-2fa/) for their webmail only. You can use either TOTP or a [YubiKey](security-keys.md#yubikey) via the [YubiCloud](https://yubico.com/products/services-software/yubicloud). Web standards such as [WebAuthn](basics/multi-factor-authentication.md#fido-fast-identity-online) are not yet supported.
|
||||
Mailbox Mail supports [two-factor authentication](https://kb.mailbox.org/en/private/security-and-privacy/how-to-use-two-factor-authentication-2fa/) for their webmail only. You can use either TOTP or a [YubiKey](security-keys.md#yubikey-5) via the [YubiCloud](https://yubico.com/products/services-software/yubicloud). Web standards such as [WebAuthn](basics/multi-factor-authentication.md#fido-fast-identity-online) are not yet supported.
|
||||
|
||||
#### :material-information-outline:{ .pg-blue } Data Security
|
||||
|
||||
@@ -277,7 +277,6 @@ We regard these features as important in order to provide a safe and optimal ser
|
||||
|
||||
- Must encrypt email account data at rest with asymmetric encryption, where only the user has the private keys needed to decrypt it.
|
||||
- Must be capable of exporting emails as [Mbox](https://en.wikipedia.org/wiki/Mbox) or individual .EML with [RFC5322](https://datatracker.ietf.org/doc/rfc5322) standard.
|
||||
- Allow users to use their own [domain name](https://en.wikipedia.org/wiki/Domain_name). Custom domain names are important to users because it allows them to maintain their agency from the service, should it turn bad or be acquired by another company which doesn't prioritize privacy.
|
||||
- Must operate on owned infrastructure, i.e. not built upon third-party email service providers.
|
||||
|
||||
**Best Case:**
|
||||
|
||||
@@ -0,0 +1,79 @@
|
||||
---
|
||||
title: Hardware Wallets
|
||||
icon: material/cash-lock
|
||||
description: Cryptocurrency hardware wallets secure your private keys against adversaries.
|
||||
cover: hardware-wallets.webp
|
||||
---
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
- [:material-target-account: Targeted Attacks](basics/common-threats.md#attacks-against-specific-individuals){ .pg-red }
|
||||
- [:material-bug-outline: Passive Attacks](basics/common-threats.md#security-and-privacy){ .pg-orange }
|
||||
|
||||
A cryptocurrency **hardware wallet** is a dedicated physical device that stores the private keys used to access and authorize transactions from your cryptocurrency accounts. Unlike a software wallet on a phone or computer, it keeps those keys isolated from internet-connected devices, reducing the risk that malware, phishing, or a compromised operating system can steal them.
|
||||
|
||||
## Recommendations
|
||||
|
||||
Our top recommendations are full-featured products from the companies we list here, and support all major operating systems (notably including iOS).
|
||||
|
||||
### Ledger Nano Gen 5
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
The **Ledger Nano Gen 5** hardware wallet places the private keys, wallet operating system, and cryptocurrency applications inside a certified secure element. Unlike Trezor's devices, it is also a recommended [security key](security-keys.md#ledger) product.
|
||||
|
||||
</div>
|
||||
|
||||
Ledger runs its *entire* operating system and stores your private keys inside its CC EAL6+ certified secure element. This is a simpler configuration than [Trezor](#trezor-safe-7)'s multi-chip design (described in the next section), but that doesn't necessarily translate to greater or lesser security. In theory, it may provide a smaller attack surface and offer more resistance to offline attacks or some very sophisticated attacks against a running device, but that comes at the cost of Trezor's greater transparency.
|
||||
|
||||
Wallet apps installed on Ledger devices are [open-source](https://support.ledger.com/article/11132311094813-zd), as is the companion Ledger Wallet software you install on your computer. However, the Ledger OS/firmware and the secure element implementation are proprietary.
|
||||
|
||||
The **Ledger Flex** and **Ledger Stax** are near-identical devices you could also consider. There are no security or software functionality differences between all three of these devices. The Flex and Stax devices have increasingly larger, higher resolution displays; more premium materials; and the Stax has wireless Qi charging.
|
||||
|
||||
### Trezor Safe 7
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
The **Trezor Safe 7** is a modern touchscreen hardware wallet notable for using a dual secure element approach to security. It connects via USB-C or with Bluetooth.
|
||||
|
||||
</div>
|
||||
|
||||
The Safe 7 uses an industry-standard CC EAL6 secure element alongside an open architecture [TROPIC01](https://tropicsquare.com/tropic01) secure element to provide security. It also uses a general-purpose microcontroller unit (MCU), which is not a secure element but allows for better inspectability for developers and researchers.
|
||||
|
||||
In this setup, your seed is not stored in either secure element, it is stored *encrypted* in the general-purpose MCU. However, decrypting it requires key material stored by both secure elements. Trezor claims an attacker would need to compromise all three layers to recover the encrypted hardware data. Thus, Trezor's approach balances open-source and transparency in their MCU firmware and the less proven but more open TROPIC01 chip, alongside the more proven CC EAL6+ secure element from a commercial provider.
|
||||
|
||||
Trezor devices are not [recommended FIDO2 security keys](security-keys.md), although they do have security key functionality, because Trezor has not sought out certification from the FIDO Alliance to validate their security key software is implemented properly. Some websites/apps will require a key to have some level of FIDO certification, so you may experience compatibility issues using this device for that purpose.
|
||||
|
||||
## Budget Picks
|
||||
|
||||
Our budget recommendations are generally just as secure as our top recommendations, but neither support iOS. They also have more limited, button-based interfaces instead of touchscreens, making them well-suited for long-term storage, but more inconvenient for frequent use.
|
||||
|
||||
### Trezor Safe 3
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
The **Trezor Safe 3** is a simple and inexpensive USB-C only hardware wallet. Like the [Safe 7](#trezor-safe-7), it has open-source firmware and supporting software so that it can be independently inspected.
|
||||
|
||||
</div>
|
||||
|
||||
The **Trezor Safe 5** is a near-identical device you could also consider. There are no security or software functionality differences between the Safe 3 and Safe 5. However, the Safe 5 has a larger touchscreen for easier navigation, instead of the Safe 3's smaller display and two-button navigation.
|
||||
|
||||
The Safe 3/5 devices do **not** use the same dual secure enclave configuration as the Safe 7. Instead, they omit the TROPIC01 to run a single EAL CC6+ secure element, which stores material to unlock the private keys that are stored encrypted on the separate general-purpose MCU.
|
||||
|
||||
### Ledger Nano S Plus
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
The **Ledger Nano S Plus** is a small hardware wallet with a two-button interface, recommended by Ledger as a "backup signer" rather than a regular-use device. Compared to the [Nano Gen 5](#ledger-nano-gen-5) it only has USB connectivity, and it has no internal battery, which may provide an improvement in longevity.
|
||||
|
||||
</div>
|
||||
|
||||
The Nano S Plus lacks NFC connectivity, making it less suitable for [security key](security-keys.md#ledger) functionality on mobile devices, and making it incompatible with Ledger's Recovery Key backup solution. All four Ledger devices we recommend have essentially the same security properties, they only differ in interfaces.
|
||||
|
||||
Note we do **not** recommend the similar Ledger Nano X still in production. The Nano X uses an older secure element which is only CC EAL5 certified, while our minimum criteria requires EAL6. There are limited uses for the Nano X compared to all other devices Ledger offers, so it generally does not make sense as a new purchase.
|
||||
|
||||
## Criteria
|
||||
|
||||
**Please note we are not affiliated with any of the projects we recommend.** In addition to [our standard criteria](about/criteria.md), we have developed a clear set of requirements to allow us to provide objective recommendations. We suggest you familiarize yourself with this list before choosing to use a project, and conduct your own research to ensure it's the right choice for you.
|
||||
|
||||
- Must use a secure element which meets Common Criteria EAL6 or higher.
|
||||
- Must support a [recommended cryptocurrency](cryptocurrency.md).
|
||||
@@ -2,7 +2,7 @@
|
||||
meta_title: "Privacy-Respecting Health and Wellness apps for Android and iOS - Privacy Guides"
|
||||
title: "Health and Wellness"
|
||||
icon: material/heart-pulse
|
||||
description: These applications are what we currently recommend for all health- and fitness-related activites on your phone.
|
||||
description: These applications are what we currently recommend for all health- and fitness-related activities on your phone.
|
||||
cover: health.webp
|
||||
---
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Linux Overview
|
||||
icon: simple/linux
|
||||
description: Linux is an open-source, privacy-focused desktop operating system alternative, but not all distribitions are created equal.
|
||||
description: Linux is an open-source, privacy-focused desktop operating system alternative, but not all distributions are created equal.
|
||||
---
|
||||
**Linux** is an open-source, privacy-focused desktop operating system alternative. In the face of pervasive telemetry and other privacy-encroaching technologies in mainstream operating systems, desktop Linux has remained the clear choice for people looking for total control over their computers from the ground up.
|
||||
|
||||
@@ -67,16 +67,13 @@ Arch and Arch-based distributions are not recommended for those new to Linux (re
|
||||
|
||||
For a secure system, you are also expected to have sufficient Linux knowledge to properly set up security for their system such as adopting a [mandatory access control](#mandatory-access-control) system, setting up [kernel module](https://en.wikipedia.org/wiki/Loadable_kernel_module#Security) blacklists, hardening boot parameters, manipulating [sysctl](https://en.wikipedia.org/wiki/Sysctl) parameters, and knowing what components they need such as [Polkit](https://en.wikipedia.org/wiki/Polkit).
|
||||
|
||||
Anyone using the [Arch User Repository (AUR)](https://wiki.archlinux.org/title/Arch_User_Repository) **must** be comfortable auditing PKGBUILDs that they download from that service. AUR packages are community-produced content and are not vetted in any way, and therefore are vulnerable to software [:material-package-variant-closed-remove: Supply Chain Attacks](../basics/common-threats.md#attacks-against-certain-organizations){ .pg-viridian }, which has in fact happened [in the past](https://bleepingcomputer.com/news/security/malware-found-in-arch-linux-aur-package-repository).
|
||||
Arch-based derivatives designed to make Arch "easier to use" are not recommended, as they frequently encourage poor security practices while weakening the base system. These practices include bundling outdated packages in downstream repositories that are updated less frequently than Arch's official channels. Furthermore, these distributions usually fail to properly educate users on the risks associated with the Arch User Repository (AUR).
|
||||
|
||||
Anyone using the [Arch User Repository (AUR)](https://wiki.archlinux.org/title/Arch_User_Repository) **must** be comfortable auditing PKGBUILDs (the recipes that build packages) that they download from that service. AUR packages are community-produced content and are not vetted in any way, and therefore are vulnerable to software [:material-package-variant-closed-remove: Supply Chain Attacks](../basics/common-threats.md#attacks-against-certain-organizations){ .pg-viridian }, which has in fact happened [in the past](https://bleepingcomputer.com/news/security/malware-found-in-arch-linux-aur-package-repository) and more recently when [1500 packages](https://discuss.privacyguides.net/t/around-1-500-aur-packages-compromised-with-rootkit-like-malware/38517) were compromised.
|
||||
|
||||
The AUR should always be used sparingly, and often there is a lot of bad advice on various pages which direct people to blindly use [AUR helpers](https://wiki.archlinux.org/title/AUR_helpers) without sufficient warning. Similar warnings apply to the use of third-party Personal Package Archives (PPAs) on Debian-based distributions or Community Projects (COPR) on Fedora.
|
||||
|
||||
If you are experienced with Linux and wish to use an Arch-based distribution, we generally recommend mainline Arch Linux over any of its derivatives.
|
||||
|
||||
Additionally, we recommend **against** these two Arch derivatives specifically:
|
||||
|
||||
- **Manjaro**: This distribution holds packages back for 2 weeks to make sure that their own changes don’t break, not to make sure that upstream is stable. When AUR packages are used, they are often built against the latest [libraries](https://en.wikipedia.org/wiki/Library_(computing)) from Arch’s repositories.
|
||||
- **Garuda**: They use [Chaotic-AUR](https://aur.chaotic.cx) which automatically and blindly compiles packages from the AUR. There is no verification process to make sure that the AUR packages don’t suffer from supply chain attacks.
|
||||
If you are experienced with Linux and wish to use an Arch-based distribution, mainline Arch Linux is the **only** recommended option.
|
||||
|
||||
### Linux-libre kernel and “Libre” distributions
|
||||
|
||||
|
||||
@@ -127,6 +127,17 @@ This last setting disables OneDrive on your system; make sure to change it to **
|
||||
|
||||
- Improve inking and typing recognition: **Disabled**
|
||||
|
||||
#### Windows AI
|
||||
|
||||
<div class="admonition info" markdown>
|
||||
<p class="admonition-title">Windows Recall</p>
|
||||
|
||||
Windows 11 recently introduced a feature called **Recall**, which records all your activity and creates a searchable archive of that activity history. This is a massive privacy vulnerability, because those archives can potentially store highly sensitive information (essentially anything displayed on your screen), and malware without any special permissions or admin access can trivially [access](https://github.com/xaitax/TotalRecall) the full Recall database anytime after it is unlocked.
|
||||
|
||||
</div>
|
||||
|
||||
- Turn off saving snapshots for use with Recall: **Enabled**
|
||||
|
||||
#### Windows Error Reporting
|
||||
|
||||
- Do not send additional data: **Enabled**
|
||||
|
||||
@@ -73,7 +73,7 @@ If you use Android and your threat model requires protecting against [:material-
|
||||
|
||||
{ align=right }
|
||||
|
||||
**Molly** is an alternative Signal client for Android which allows you to encrypt the local database with a passphrase at rest, to have unused RAM data securely shredded, to route your connection via Tor, and [more](https://blog.privacyguides.org/2022/07/07/signal-configuration-and-hardening#privacy-and-security-features). It also has usability improvements including scheduled backups, automatic locking, and the ability to use your Android phone as a linked device instead of the primary device for a Signal account.
|
||||
**Molly** is an alternative Signal client for Android which allows you to encrypt the local database with a passphrase at rest, to have unused RAM data securely shredded, to route your connection via Tor, and [more](https://www.privacyguides.org/articles/2022/07/07/signal-configuration-and-hardening#privacy-and-security-features). It also has usability improvements including scheduled backups, automatic locking, and the ability to use your Android phone as a linked device instead of the primary device for a Signal account.
|
||||
|
||||
[:octicons-home-16: Homepage](https://molly.im){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://signal.org/legal/#privacy-policy){ .card-link title="Privacy Policy" }
|
||||
@@ -92,13 +92,9 @@ If you use Android and your threat model requires protecting against [:material-
|
||||
|
||||
</div>
|
||||
|
||||
Molly is updated every two weeks to include the latest features and bug fixes from Signal. The exception is security issues, which are patched as soon as possible. That said, you should be aware that there might be a slight delay compared to upstream, which may affect actions such as [migrating from Signal to Molly](https://github.com/mollyim/mollyim-android/wiki/Migrating-From-Signal#migrating-from-signal).
|
||||
|
||||
Note that you are trusting multiple parties by using Molly, as you now need to trust the Signal team *and* the Molly team to deliver safe and timely updates.
|
||||
|
||||
**Molly-FOSS** is a version of Molly which removes proprietary code like the Google services used by both Signal and Molly at the expense of some features (like battery-saving push notifications via Google Play Services). You can set up push notifications without Google Play Services in either version of Molly with [UnifiedPush](https://unifiedpush.org). Using this notification delivery method requires access to a [MollySocket](https://github.com/mollyim/mollysocket) server, but you can choose a public MollySocket instance for this.[^3]
|
||||
|
||||
Both versions of Molly provide the same security improvements and support [reproducible builds](https://github.com/mollyim/mollyim-android/tree/main/reproducible-builds), meaning it's possible to confirm that the compiled APKs match the source code.
|
||||
Molly provides support for [reproducible builds](https://github.com/mollyim/mollyim-android/tree/main/reproducible-builds), meaning it's possible to confirm that the compiled APKs match the source code.
|
||||
|
||||
## SimpleX Chat
|
||||
|
||||
|
||||
+41
-35
@@ -11,6 +11,16 @@ cover: multi-factor-authentication.webp
|
||||
|
||||
A physical **security key** adds a very strong layer of protection to your online accounts. Compared to [authenticator apps](multi-factor-authentication.md), the [FIDO2](basics/multi-factor-authentication.md#fido-fast-identity-online) security key protocol is immune to phishing, and cannot be compromised without physical possession of the key itself. Many services support FIDO2/WebAuthn as a multifactor authentication option for securing your account, and some services allow you to use a security key as a strong single-factor authenticator with passwordless authentication.
|
||||
|
||||
| Product | Price | Connector | Authentication | Android | iOS | Firmware Updates | Backup/Sync | Apps | FIDO Certification
|
||||
|:-:|:-:|:-:|:-:|:-:|:-:|:-:|:-:|:-:|:-:
|
||||
| [**Yubico Security Key**](#yubico-security-key) | $29 USD | NFC + USB-C, USB-A Options | Push Button Only, PIN Optional | NFC, USB | NFC, USB | No[^2] | No | FIDO2 | Level 2
|
||||
| **YubiKey Bio - FIDO Edition** | $98 USD | USB-C, USB-A Options | Biometric, PIN Fallback | USB Only | USB Only | No[^2] | No | FIDO2 | Level 2
|
||||
| **[YubiKey 5](#yubikey) NFC** | $58 USD | NFC + USB-C, USB-A Options | Push Button Only, PIN Optional | NFC, USB | NFC, USB | No[^2] | No | FIDO2, OpenPGP, PIV | Level 2
|
||||
| **YubiKey 5 Nano** | $68 USD | USB-C, USB-A Options | Push Button Only, PIN Optional | USB Only | USB Only | No[^2] | No | FIDO2, OpenPGP, PIV | Level 2
|
||||
| **[Ledger](#ledger) Nano S Plus** | $59 USD | USB-C Cable | 4-8 Digit PIN | USB Only | **No** | Yes | Both | FIDO2, OpenPGP, [Cryptocurrency](hardware-wallets.md) | Level 1
|
||||
| **Ledger Nano Gen5, Flex, Stax** | $179 - $399 USD | NFC + USB-C Cable | 4-8 Digit PIN | NFC, USB | NFC Only | Yes | Both | FIDO2, OpenPGP, [Cryptocurrency](hardware-wallets.md) | Level 1
|
||||
| [**Google Titan Key**](#google-titan-security-key) | $30 - $35 USD | NFC + USB-C, USB-A Options | Push Button Only, PIN Optional | NFC, USB | NFC, USB | No | No | FIDO2 | Level 1
|
||||
|
||||
## Yubico Security Key
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
@@ -29,24 +39,15 @@ The **Yubico Security Key** series is the most cost-effective hardware security
|
||||
|
||||
</div>
|
||||
|
||||
These keys are available in both USB-C and USB-A variants, and both options support NFC for use with a mobile device as well.
|
||||
Note that despite the name, the [YubiKey **Bio**](https://www.yubico.com/product/yubikey-bio-series/yubikey-c-bio/) series has a limited feature-set nearly identical to the Yubico Security Key series, rather than the full-fledged [YubiKey](#yubikey) series detailed in the next section. It is another option you could consider if you value biometric authentication.
|
||||
|
||||
This key provides only basic FIDO2 functionality, but for most people that is all you will need. Some notable features the Security Key series does **not** have include:
|
||||
Yubico's basic security keys provide only FIDO2 functionality, but for most people that is all you will need. Some notable features the Security Key series does **not** have include:
|
||||
|
||||
- [Yubico Authenticator](https://yubico.com/products/yubico-authenticator)
|
||||
- CCID Smart Card support (PIV-compatible)
|
||||
- OpenPGP
|
||||
|
||||
If you need any of those features, you should consider their higher-end [YubiKey](#yubikey) series instead.
|
||||
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">Warning</p>
|
||||
|
||||
The firmware of Yubico's Security Keys is not updatable. If you want features in newer firmware versions, or if there is a vulnerability in the firmware version you are using, you would need to purchase a new key.
|
||||
|
||||
</div>
|
||||
|
||||
## YubiKey
|
||||
## YubiKey 5
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@@ -64,7 +65,7 @@ The **YubiKey** series from Yubico are among the most popular security keys with
|
||||
|
||||
</div>
|
||||
|
||||
The [comparison table](https://yubico.com/store/compare) shows how the YubiKeys compare to each other and to Yubico's [Security Key](#yubico-security-key) series in terms of features and other specifications. One of the benefits of the YubiKey series is that one key can do almost everything you could expect from a hardware security key. We encourage you to take their [quiz](https://yubico.com/quiz) before purchasing in order to make sure you choose the right security key.
|
||||
This detailed [comparison table](https://yubico.com/store/compare) has more details about how the YubiKeys compare to each other and to Yubico's [Security Key](#yubico-security-key) series in terms of features and other specifications. One of the benefits of the YubiKey series is that one key can do almost everything you could expect from a hardware security key. We encourage you to take their [quiz](https://yubico.com/quiz) before purchasing in order to make sure you choose the right security key.
|
||||
|
||||
YubiKeys can be programmed using the [YubiKey Manager](https://yubico.com/support/download/yubikey-manager) or [YubiKey Personalization Tools](https://yubico.com/support/download/yubikey-personalization-tools). For managing TOTP codes, you can use the [Yubico Authenticator](https://yubico.com/products/yubico-authenticator). All of Yubico's clients are open source.
|
||||
|
||||
@@ -77,32 +78,39 @@ The firmware of YubiKey is not updatable. If you want features in newer firmware
|
||||
|
||||
</div>
|
||||
|
||||
## Nitrokey
|
||||
## Ledger
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
<figure markdown="span">
|
||||
{ width="300" }
|
||||
</figure>
|
||||
|
||||
**Nitrokey** has a cost-effective security key capable of FIDO2/WebAuthn and FIDO U2F called the **Nitrokey Passkey**. For support for features such as PIV, OpenPGP, and TOTP and HOTP authentication, you need to purchase one of their other keys like the **Nitrokey 3**. Currently, only the **Nitrokey 3A Mini** has [FIDO Level 1 Certification](https://nitrokey.com/news/2024/nitrokey-3a-mini-receives-official-fido2-certification).
|
||||
|
||||
[:octicons-home-16: Homepage](https://nitrokey.com){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://nitrokey.com/data-privacy-policy){ .card-link title="Privacy Policy" }
|
||||
[:octicons-info-16:](https://docs.nitrokey.com){ .card-link title="Documentation" }
|
||||
|
||||
</details>
|
||||
**Ledger** makes a number of [cryptocurrency hardware wallet](hardware-wallets.md) products and an optional, FIDO certified [Security Key](https://support.ledger.com/article/12350325732893-zd) app for those wallets which enables FIDO2 security key functionality. If you need a cryptocurrency wallet anyway, this could be an option to consider for security key functionality as well.
|
||||
|
||||
</div>
|
||||
|
||||
The [comparison table](https://nitrokey.com/products/nitrokeys#:~:text=The%20Nitrokey%20Family) shows how the different Nitrokey models compare to each other in terms of features and other specifications. Refer to Nitrokey's [documentation](https://docs.nitrokey.com/nitrokeys/features) for more details about the features available on your Nitrokey.
|
||||
Even if you don't need a cryptocurrency wallet, using Ledger devices as security keys has three key advantages over YubiKey you may wish to consider:
|
||||
|
||||
Nitrokey models can be configured using the [Nitrokey app](https://nitrokey.com/download).
|
||||
1. **Secure PIN authentication.**
|
||||
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">Warning</p>
|
||||
A 4-8 digit PIN is always required to operate Ledger devices. Additionally, that PIN is entered via the display on the device itself. YubiKey PIN authentication, in contrast, is a software prompt where you enter your PIN on the computer/phone you're using.
|
||||
|
||||
Starting with Nitrokey 3, HOTP and TOTP secrets are additionally encrypted at rest. Older Nitrokey devices like Nitrokey Pro 2 and Nitrokey Storage 2 did not encrypt OTP secrets at rest, which makes the OTP secrets on these devices potentially vulnerable to physical attacks.
|
||||
2. **Firmware updates.**
|
||||
|
||||
Both the operating system firmware and the Security Key app software can be updated via the Ledger Wallet app if new security improvements are released.
|
||||
|
||||
3. **Backups and sync.**
|
||||
|
||||
When setting up your Ledger device you will create a 24-word "seed phrase." Your security key credentials are tied to this seed phrase, meaning that if you lose/break your Ledger device, you can use the same 24-word phrase to set up a new Ledger device, and it will work with your existing accounts.
|
||||
|
||||
You can also use the same 24-word phrase to set up multiple Ledger devices simultaneously, and all of them will work with your accounts in a "synced" fashion, instead of needing to register each security key individually.
|
||||
|
||||
Some may consider the last two features to be downsides. Firmware updates can add additional attack surface and introduce new bugs at a later time. However, it is worth noting that many non-updatable security keys from various vendors have been recalled due to discovered security flaws which could not be patched. Backups can also be dangerous if your seed phrase is not properly secured, because it could be used by an attacker to create a duplicate security key if it is leaked.
|
||||
|
||||
Note that while all of Ledger's current products technically meet our criteria *for security keys*, the Ledger Nano X does **not** meet our separate [criteria for hardware wallets](hardware-wallets.md#criteria) because it uses an older secure element not certified to the same level as their other products. The Ledger Nano X has no advantages over any of their other devices for security key purposes, so we would not recommend purchasing one.
|
||||
|
||||
## Google Titan Security Key
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
Google Titan Security Keys are Yubico-manufactured FIDO2 USB/NFC keys very similar to the [Yubico Security Key](#yubico-security-key) lineup. However, Titan security keys use a different secure element than Yubico's, and they run firmware created by Google. There are generally no functional differences between the two options.
|
||||
|
||||
</div>
|
||||
|
||||
@@ -113,17 +121,15 @@ Starting with Nitrokey 3, HOTP and TOTP secrets are additionally encrypted at re
|
||||
### Minimum Requirements
|
||||
|
||||
- Must use high-quality, tamper-resistant hardware security modules.
|
||||
- Must support the latest FIDO2 specification.
|
||||
- Must not allow private key extraction.
|
||||
- Devices which cost over $35 must support handling OpenPGP and S/MIME.
|
||||
- Must be [certified](https://fidoalliance.org/certification/fido-certified-products/) by FIDO Alliance for the FIDO2 specification.
|
||||
- Must have USB-C and NFC connectivity options in product line.
|
||||
|
||||
### Best-Case
|
||||
|
||||
Our best-case criteria represents what we would like to see from the perfect project in this category. Our recommendations may not include any or all of this functionality, but those which do may rank higher than others on this page.
|
||||
|
||||
- Should be available in USB-C form factor.
|
||||
- Should be available with NFC.
|
||||
- Should support TOTP secret storage.
|
||||
- Should support secure firmware updates.
|
||||
|
||||
[^1]: Some governments or other organizations may require a key with Level 2 certification, but most people do not have to worry about this distinction.
|
||||
[^2]: The firmware of Yubico's Security Keys is not updatable. If you want features in newer firmware versions, or if there is a vulnerability in the firmware version you are using, you would need to purchase a new key.
|
||||
|
||||
@@ -179,7 +179,7 @@ As an end user on a public homeserver, you can consider unchecking the **Enable
|
||||
|
||||
- [ ] (Optional) Uncheck **Record the client name, version, and url to recognize sessions for easily in session manager**
|
||||
|
||||
Unchecking this option may make it more diffcult to discern your active sessions if you logged in to your Matrix account on multiple devices.
|
||||
Unchecking this option may make it more difficult to discern your active sessions if you logged in to your Matrix account on multiple devices.
|
||||
|
||||
#### Encryption
|
||||
|
||||
|
||||
+13
-3
@@ -276,7 +276,7 @@ If you're looking for added **security**, you should always ensure you're connec
|
||||
|
||||
#### DNS Providers
|
||||
|
||||
We [recommend](dns.md#recommended-providers) a number of encrypted DNS servers based on a variety of criteria, such as [Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls) and [Quad9](https://quad9.net) amongst others. We recommend for you to read our pages on DNS before choosing a provider. In many cases, using an alternative DNS provider is not recommended.
|
||||
We [recommend](dns.md#recommended-providers) a number of encrypted DNS servers based on a variety of criteria, such as [Quad9](https://quad9.net) amongst others. We recommend for you to read our pages on DNS before choosing a provider. In many cases, using an alternative DNS provider is not recommended.
|
||||
|
||||
[Learn more :material-arrow-right-drop-circle:](dns.md)
|
||||
|
||||
@@ -603,13 +603,23 @@ For encrypting your OS drive, we typically recommend using the encryption tool y
|
||||
|
||||
## Hardware
|
||||
|
||||
### Hardware Wallets
|
||||
|
||||
<div class="grid cards" markdown>
|
||||
|
||||
- [Ledger](hardware-wallets.md#ledger-nano-gen-5)
|
||||
- [Trezor](hardware-wallets.md#trezor-safe-7)
|
||||
|
||||
</div>
|
||||
|
||||
### Security Keys
|
||||
|
||||
<div class="grid cards" markdown>
|
||||
|
||||
- { .twemoji loading=lazy } [Yubico Security Key](security-keys.md#yubico-security-key)
|
||||
- { .twemoji loading=lazy } [YubiKey](security-keys.md#yubikey)
|
||||
- { .twemoji loading=lazy } [Nitrokey](security-keys.md#nitrokey)
|
||||
- { .twemoji loading=lazy } [YubiKey](security-keys.md#yubikey-5)
|
||||
- [Ledger](security-keys.md#ledger)
|
||||
- [Google Titan Security Key](security-keys.md#google-titan-security-key)
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
+1
-1
@@ -76,7 +76,7 @@ We also think it's better for the security of the VPN provider's private keys if
|
||||
|
||||
#### :material-check:{ .pg-green } Independently Audited
|
||||
|
||||
Independent security researcher Ruben Santamarta conducted audits for Proton VPN's [browser extensions](https://drive.proton.me/urls/RWDD2SHT98#v7ZrwNcafkG8) and [apps](https://drive.proton.me/urls/RVW8TXG484#uTXX5Fc9GADo) in September 2024 and January 2025, respectively. Proton VPN's infrastrcture has undergone [annual audits](https://protonvpn.com/blog/no-logs-audit) by Securitum since 2022.
|
||||
Independent security researcher Ruben Santamarta conducted audits for Proton VPN's [browser extensions](https://drive.proton.me/urls/RWDD2SHT98#v7ZrwNcafkG8) and [apps](https://drive.proton.me/urls/RVW8TXG484#uTXX5Fc9GADo) in September 2024 and January 2025, respectively. Proton VPN's infrastructure has undergone [annual audits](https://protonvpn.com/blog/no-logs-audit) by Securitum since 2022.
|
||||
|
||||
Previously, Proton VPN underwent an independent audit by SEC Consult in January 2020. SEC Consult found some medium and low risk vulnerabilities in Proton VPN's Windows, Android, and iOS applications, all of which were "properly fixed" by Proton VPN before the reports were published. None of the issues identified would have provided an attacker remote access to your device or traffic. You can view individual reports for each platform in their dedicated [blog post](https://web.archive.org/web/20250307041036/https://protonvpn.com/blog/open-source) on the audit.
|
||||
|
||||
|
||||
@@ -5,6 +5,7 @@
|
||||
*[attack surface]: The total number of possible entry points for unauthorized access to a system
|
||||
*[AVB]: Android Verified Boot
|
||||
*[cgroups]: Control Groups
|
||||
*[C2PA]: Coalition for Content Provenance and Authenticity
|
||||
*[CLI]: Command Line Interface
|
||||
*[CSV]: Comma-Separated Values
|
||||
*[CVE]: Common Vulnerabilities and Exposures
|
||||
@@ -48,6 +49,7 @@
|
||||
*[IPv6]: Internet Protocol version 6
|
||||
*[ISP]: Internet Service Provider
|
||||
*[ISPs]: Internet Service Providers
|
||||
*[IPTC]: International Press Telecommunications Council
|
||||
*[JNI]: Java Native Interface
|
||||
*[KYC]: Know Your Customer
|
||||
*[LLaVA]: Large Language and Vision Assistant (multimodal AI model)
|
||||
@@ -107,6 +109,7 @@
|
||||
*[VLAN]: Virtual Local Area Network
|
||||
*[VoIP]: Voice over IP (Internet Protocol)
|
||||
*[W3C]: World Wide Web Consortium
|
||||
*[XMP]: Extensible Metadata Platform
|
||||
*[XMPP]: Extensible Messaging and Presence Protocol
|
||||
*[PWA]: Progressive Web App
|
||||
*[PWAs]: Progressive Web Apps
|
||||
|
||||
+170
-143
@@ -18,25 +18,25 @@
|
||||
# FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
||||
# IN THE SOFTWARE.
|
||||
|
||||
docs_dir: !ENV [ BUILD_DOCS_DIR, "docs" ]
|
||||
site_url: !ENV [ BUILD_SITE_URL, "https://www.privacyguides.org/en/" ]
|
||||
site_dir: !ENV [ BUILD_SITE_DIR, "site/en" ]
|
||||
docs_dir: !ENV [BUILD_DOCS_DIR, "docs"]
|
||||
site_url: !ENV [BUILD_SITE_URL, "https://www.privacyguides.org/en/"]
|
||||
site_dir: !ENV [BUILD_SITE_DIR, "site/en"]
|
||||
|
||||
site_name: Privacy Guides
|
||||
site_description:
|
||||
!ENV [
|
||||
site_description: !ENV [
|
||||
SITE_DESCRIPTION,
|
||||
"Privacy Guides is your central privacy and security resource to protect
|
||||
yourself online.",
|
||||
yourself online.",
|
||||
]
|
||||
edit_uri_template: !ENV [ BUILD_EDIT_URI_TEMPLATE, "blob/main/docs/{path}?plain=1" ]
|
||||
edit_uri_template:
|
||||
!ENV [BUILD_EDIT_URI_TEMPLATE, "blob/main/docs/{path}?plain=1"]
|
||||
|
||||
extra:
|
||||
scope: /
|
||||
homepage: /
|
||||
generator: false
|
||||
context: !ENV [ BUILD_CONTEXT, "production" ]
|
||||
offline: !ENV [ BUILD_OFFLINE, false ]
|
||||
context: !ENV [BUILD_CONTEXT, "production"]
|
||||
offline: !ENV [BUILD_OFFLINE, false]
|
||||
deploy: !ENV DEPLOY_ID
|
||||
ghost:
|
||||
base_url: https://www.privacyguides.org
|
||||
@@ -45,99 +45,124 @@ extra:
|
||||
content_api_key: da9d77deb3e85ee73925167f3a
|
||||
privacy_guides:
|
||||
footer:
|
||||
intro:
|
||||
!ENV [
|
||||
intro: !ENV [
|
||||
FOOTER_INTRO,
|
||||
"Privacy Guides is a non-profit, socially motivated website that provides
|
||||
information for protecting your data security and privacy.",
|
||||
information for protecting your data security and privacy.",
|
||||
]
|
||||
note:
|
||||
!ENV [
|
||||
note: !ENV [
|
||||
FOOTER_NOTE,
|
||||
"We do not make money from recommending certain products, and we do not use
|
||||
affiliate links.",
|
||||
affiliate links.",
|
||||
]
|
||||
copyright:
|
||||
author: !ENV [ FOOTER_COPYRIGHT_AUTHOR, "Privacy Guides and contributors." ]
|
||||
date: !ENV [ FOOTER_COPYRIGHT_DATE, "2019-2025" ]
|
||||
author:
|
||||
!ENV [FOOTER_COPYRIGHT_AUTHOR, "Privacy Guides and contributors."]
|
||||
date: !ENV [FOOTER_COPYRIGHT_DATE, "2019-2025"]
|
||||
license:
|
||||
- fontawesome/brands/creative-commons
|
||||
- fontawesome/brands/creative-commons-by
|
||||
- fontawesome/brands/creative-commons-sa
|
||||
links:
|
||||
- name: !ENV [ FOOTER_PRIVACY_NOTICE, "Privacy notice." ]
|
||||
- name: !ENV [FOOTER_PRIVACY_NOTICE, "Privacy notice."]
|
||||
url: https://www.privacyguides.org/en/privacy/
|
||||
homepage:
|
||||
description:
|
||||
!ENV [
|
||||
description: !ENV [
|
||||
HOMEPAGE_DESCRIPTION,
|
||||
"A socially motivated website which provides information about protecting
|
||||
your online data privacy and security.",
|
||||
your online data privacy and security.",
|
||||
]
|
||||
hero:
|
||||
header: !ENV [ HOMEPAGE_HEADER, "The guide to restoring your online privacy." ]
|
||||
subheader:
|
||||
!ENV [
|
||||
header:
|
||||
!ENV [HOMEPAGE_HEADER, "The guide to restoring your online privacy."]
|
||||
subheader: !ENV [
|
||||
HOMEPAGE_SUBHEADER,
|
||||
"Massive organizations are monitoring your online activities. Privacy
|
||||
Guides is your central privacy and security resource to protect
|
||||
yourself online.",
|
||||
Guides is your central privacy and security resource to protect
|
||||
yourself online.",
|
||||
]
|
||||
buttons:
|
||||
- name: !ENV [ HOMEPAGE_BUTTON_GET_STARTED_NAME, "Start Your Privacy Journey" ]
|
||||
title: !ENV [ HOMEPAGE_BUTTON_GET_STARTED_TITLE, "The first step of your privacy journey" ]
|
||||
link: !ENV [ HOMEPAGE_BUTTON_GET_STARTED_LINK, "basics/why-privacy-matters/" ]
|
||||
- name:
|
||||
!ENV [
|
||||
HOMEPAGE_BUTTON_GET_STARTED_NAME,
|
||||
"Start Your Privacy Journey",
|
||||
]
|
||||
title:
|
||||
!ENV [
|
||||
HOMEPAGE_BUTTON_GET_STARTED_TITLE,
|
||||
"The first step of your privacy journey",
|
||||
]
|
||||
link:
|
||||
!ENV [
|
||||
HOMEPAGE_BUTTON_GET_STARTED_LINK,
|
||||
"basics/why-privacy-matters/",
|
||||
]
|
||||
class: md-button md-button--primary
|
||||
- name: !ENV [ HOMEPAGE_BUTTON_TOOLS_NAME, "Recommended Tools" ]
|
||||
- name: !ENV [HOMEPAGE_BUTTON_TOOLS_NAME, "Recommended Tools"]
|
||||
title:
|
||||
!ENV [
|
||||
HOMEPAGE_BUTTON_TOOLS_TITLE,
|
||||
"Recommended privacy tools, services, and knowledge",
|
||||
]
|
||||
link: !ENV [ HOMEPAGE_BUTTON_TOOLS_LINK, "tools/" ]
|
||||
link: !ENV [HOMEPAGE_BUTTON_TOOLS_LINK, "tools/"]
|
||||
class: md-button
|
||||
cta:
|
||||
- title: !ENV [ HOMEPAGE_CTA_TITLE, "We need you! Here's how to get involved:" ]
|
||||
- title:
|
||||
!ENV [
|
||||
HOMEPAGE_CTA_TITLE,
|
||||
"We need you! Here's how to get involved:",
|
||||
]
|
||||
links:
|
||||
- icon: simple/discourse
|
||||
name: !ENV [ HOMEPAGE_CTA_FORUM_NAME, "Join the forum" ]
|
||||
name: !ENV [HOMEPAGE_CTA_FORUM_NAME, "Join the forum"]
|
||||
link: https://discuss.privacyguides.net/
|
||||
- icon: simple/mastodon
|
||||
name: !ENV [ HOMEPAGE_CTA_MASTODON_NAME, "Follow us on Mastodon" ]
|
||||
name: !ENV [HOMEPAGE_CTA_MASTODON_NAME, "Follow us on Mastodon"]
|
||||
link: https://mastodon.neat.computer/@privacyguides
|
||||
- icon: simple/github
|
||||
name: !ENV [ HOMEPAGE_CTA_GITHUB_NAME, "Contribute on GitHub" ]
|
||||
name: !ENV [HOMEPAGE_CTA_GITHUB_NAME, "Contribute on GitHub"]
|
||||
link: https://github.com/privacyguides/privacyguides.org
|
||||
- icon: material/translate
|
||||
name: !ENV [ HOMEPAGE_CTA_TRANSLATE_NAME, "Help translate" ]
|
||||
name: !ENV [HOMEPAGE_CTA_TRANSLATE_NAME, "Help translate"]
|
||||
link: https://crowdin.com/project/privacyguides
|
||||
- icon: simple/matrix
|
||||
name: !ENV [ HOMEPAGE_CTA_MATRIX_NAME, "Join the Matrix chat" ]
|
||||
name: !ENV [HOMEPAGE_CTA_MATRIX_NAME, "Join the Matrix chat"]
|
||||
link: https://matrix.to/#/#privacyguides:matrix.org
|
||||
- icon: material/information-outline
|
||||
name: !ENV [ HOMEPAGE_CTA_ABOUT_NAME, "Learn more about us" ]
|
||||
link: !ENV [ HOMEPAGE_CTA_ABOUT_LINK, "about/" ]
|
||||
name: !ENV [HOMEPAGE_CTA_ABOUT_NAME, "Learn more about us"]
|
||||
link: !ENV [HOMEPAGE_CTA_ABOUT_LINK, "about/"]
|
||||
- icon: material/hand-coin
|
||||
name: !ENV [ HOMEPAGE_CTA_DONATE_NAME, "Donate to Privacy Guides" ]
|
||||
link: !ENV [ HOMEPAGE_CTA_DONATE_LINK, "about/donate/" ]
|
||||
description:
|
||||
!ENV [
|
||||
name: !ENV [HOMEPAGE_CTA_DONATE_NAME, "Donate to Privacy Guides"]
|
||||
link: !ENV [HOMEPAGE_CTA_DONATE_LINK, "about/donate/"]
|
||||
description: !ENV [
|
||||
HOMEPAGE_CTA_DESCRIPTION,
|
||||
"If you spot an error, think a provider should not be listed, notice a
|
||||
qualified provider is missing, believe a browser plugin is no
|
||||
longer the best choice, or uncover any other issue, please let
|
||||
us know.",
|
||||
qualified provider is missing, believe a browser plugin is no
|
||||
longer the best choice, or uncover any other issue, please let
|
||||
us know.",
|
||||
]
|
||||
rss:
|
||||
- title: !ENV [ HOMEPAGE_RSS_BLOG_TITLE, "Privacy Guides blog feed" ]
|
||||
- title: !ENV [HOMEPAGE_RSS_BLOG_TITLE, "Privacy Guides blog feed"]
|
||||
link:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_BLOG_LINK,
|
||||
"https://www.privacyguides.org/articles/feed_rss_created.xml",
|
||||
]
|
||||
- title: !ENV [ HOMEPAGE_RSS_FORUM_TITLE, "Latest Privacy Guides forum topics" ]
|
||||
link: !ENV [ HOMEPAGE_RSS_FORUM_LINK, "https://discuss.privacyguides.net/latest.rss" ]
|
||||
- title: !ENV [ HOMEPAGE_RSS_CHANGELOG_TITLE, "Privacy Guides release changelog" ]
|
||||
- title:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_FORUM_TITLE,
|
||||
"Latest Privacy Guides forum topics",
|
||||
]
|
||||
link:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_FORUM_LINK,
|
||||
"https://discuss.privacyguides.net/latest.rss",
|
||||
]
|
||||
- title:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_CHANGELOG_TITLE,
|
||||
"Privacy Guides release changelog",
|
||||
]
|
||||
link:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_CHANGELOG_LINK,
|
||||
@@ -145,29 +170,29 @@ extra:
|
||||
]
|
||||
translation_notice:
|
||||
notice: !ENV TRANSLATION_NOTICE
|
||||
cta: !ENV [ TRANSLATION_NOTICE_CTA, "Visit Crowdin" ]
|
||||
cta: !ENV [TRANSLATION_NOTICE_CTA, "Visit Crowdin"]
|
||||
language: !ENV SITE_LANGUAGE_ENGLISH
|
||||
translation_stylesheet: !ENV [ TRANSLATION_STYLESHEET ]
|
||||
translation_stylesheet: !ENV [TRANSLATION_STYLESHEET]
|
||||
social:
|
||||
- icon: simple/mastodon
|
||||
link: https://mastodon.neat.computer/@privacyguides
|
||||
name: !ENV [ SOCIAL_MASTODON, "Mastodon" ]
|
||||
name: !ENV [SOCIAL_MASTODON, "Mastodon"]
|
||||
- icon: simple/peertube
|
||||
link: https://neat.tube/c/privacyguides
|
||||
name: !ENV [ SOCIAL_PEERTUBE, "PeerTube" ]
|
||||
name: !ENV [SOCIAL_PEERTUBE, "PeerTube"]
|
||||
- icon: simple/matrix
|
||||
link: https://matrix.to/#/#privacyguides:matrix.org
|
||||
name: !ENV [ SOCIAL_MATRIX, "Matrix" ]
|
||||
name: !ENV [SOCIAL_MATRIX, "Matrix"]
|
||||
- icon: simple/discourse
|
||||
link: https://discuss.privacyguides.net/
|
||||
name: !ENV [ SOCIAL_FORUM, "Forum" ]
|
||||
name: !ENV [SOCIAL_FORUM, "Forum"]
|
||||
- icon: simple/github
|
||||
link: https://github.com/privacyguides
|
||||
name: !ENV [ SOCIAL_GITHUB, "GitHub" ]
|
||||
name: !ENV [SOCIAL_GITHUB, "GitHub"]
|
||||
- icon: simple/torbrowser
|
||||
link: http://www.xoe4vn5uwdztif6goazfbmogh6wh5jc4up35bqdflu6bkdc5cas5vjqd.onion/
|
||||
name: !ENV [ SOCIAL_TOR_SITE, "Hidden service" ]
|
||||
language_switcher: !ENV [ LANGUAGE_SWITCHER, true ]
|
||||
name: !ENV [SOCIAL_TOR_SITE, "Hidden service"]
|
||||
language_switcher: !ENV [LANGUAGE_SWITCHER, true]
|
||||
alternate:
|
||||
- name: English
|
||||
link: /en/
|
||||
@@ -207,46 +232,53 @@ extra:
|
||||
icon: https://raw.githubusercontent.com/twitter/twemoji/master/assets/svg/1f1f7-1f1fa.svg
|
||||
analytics:
|
||||
feedback:
|
||||
title: !ENV [ ANALYTICS_FEEDBACK_TITLE, "Was this page helpful?" ]
|
||||
title: !ENV [ANALYTICS_FEEDBACK_TITLE, "Was this page helpful?"]
|
||||
ratings:
|
||||
- icon: material/emoticon-happy-outline
|
||||
name: !ENV [ ANALYTICS_FEEDBACK_POSITIVE_NAME, "This page was helpful" ]
|
||||
name: !ENV [ANALYTICS_FEEDBACK_POSITIVE_NAME, "This page was helpful"]
|
||||
data: 1
|
||||
note: !ENV [ ANALYTICS_FEEDBACK_POSITIVE_NOTE, "Thanks for your feedback!" ]
|
||||
note:
|
||||
!ENV [ANALYTICS_FEEDBACK_POSITIVE_NOTE, "Thanks for your feedback!"]
|
||||
- icon: material/emoticon-sad-outline
|
||||
name: !ENV [ ANALYTICS_FEEDBACK_NEGATIVE_NAME, "This page could be improved" ]
|
||||
name:
|
||||
!ENV [
|
||||
ANALYTICS_FEEDBACK_NEGATIVE_NAME,
|
||||
"This page could be improved",
|
||||
]
|
||||
data: 0
|
||||
note: !ENV [ ANALYTICS_FEEDBACK_NEGATIVE_NOTE, "Thanks for your feedback!" ]
|
||||
note:
|
||||
!ENV [ANALYTICS_FEEDBACK_NEGATIVE_NOTE, "Thanks for your feedback!"]
|
||||
|
||||
repo_url: !ENV [ BUILD_REPO_URL, "https://github.com/privacyguides/privacyguides.org" ]
|
||||
repo_url:
|
||||
!ENV [BUILD_REPO_URL, "https://github.com/privacyguides/privacyguides.org"]
|
||||
repo_name: ""
|
||||
|
||||
theme:
|
||||
name: material
|
||||
language: !ENV [ BUILD_THEME_LANGUAGE, "en" ]
|
||||
language: !ENV [BUILD_THEME_LANGUAGE, "en"]
|
||||
custom_dir: theme
|
||||
font:
|
||||
text: !ENV [ BUILD_THEME_FONT_TEXT, "Public Sans" ]
|
||||
code: !ENV [ BUILD_THEME_FONT_CODE, "DM Mono" ]
|
||||
text: !ENV [BUILD_THEME_FONT_TEXT, "Public Sans"]
|
||||
code: !ENV [BUILD_THEME_FONT_CODE, "DM Mono"]
|
||||
palette:
|
||||
- media: "(prefers-color-scheme)"
|
||||
scheme: default
|
||||
accent: deep purple
|
||||
toggle:
|
||||
icon: material/brightness-auto
|
||||
name: !ENV [ THEME_DARK, "Switch to dark mode" ]
|
||||
name: !ENV [THEME_DARK, "Switch to dark mode"]
|
||||
- media: "(prefers-color-scheme: dark)"
|
||||
scheme: slate
|
||||
accent: amber
|
||||
toggle:
|
||||
icon: material/brightness-2
|
||||
name: !ENV [ THEME_LIGHT, "Switch to light mode" ]
|
||||
name: !ENV [THEME_LIGHT, "Switch to light mode"]
|
||||
- media: "(prefers-color-scheme: light)"
|
||||
scheme: default
|
||||
accent: deep purple
|
||||
toggle:
|
||||
icon: material/brightness-5
|
||||
name: !ENV [ THEME_AUTO, "Switch to system theme" ]
|
||||
name: !ENV [THEME_AUTO, "Switch to system theme"]
|
||||
favicon: assets/brand/logos/png/favicon-32x32.png
|
||||
icon:
|
||||
repo: simple/github
|
||||
@@ -278,29 +310,29 @@ plugins:
|
||||
tags: {}
|
||||
search: {}
|
||||
privacy:
|
||||
enabled: !ENV [ BUILD_PRIVACY, true ]
|
||||
enabled: !ENV [BUILD_PRIVACY, true]
|
||||
offline:
|
||||
enabled: !ENV [ BUILD_OFFLINE, false ]
|
||||
enabled: !ENV [BUILD_OFFLINE, false]
|
||||
group:
|
||||
enabled: !ENV [ BUILD_INSIDERS, false ]
|
||||
enabled: !ENV [BUILD_INSIDERS, false]
|
||||
plugins:
|
||||
macros: {}
|
||||
meta: {}
|
||||
git-authors:
|
||||
enabled: !ENV [ GITAUTHORS, PRODUCTION, NETLIFY, false ]
|
||||
enabled: !ENV [GITAUTHORS, PRODUCTION, NETLIFY, false]
|
||||
sort_authors_by: contribution
|
||||
show_contribution: true
|
||||
fallback_to_empty: true
|
||||
authorship_threshold_percent: 1
|
||||
git-revision-date-localized:
|
||||
enabled: !ENV [ GITREVISIONDATE, PRODUCTION, NETLIFY, false ]
|
||||
enabled: !ENV [GITREVISIONDATE, PRODUCTION, NETLIFY, false]
|
||||
exclude:
|
||||
- index.md
|
||||
fallback_to_build_date: true
|
||||
enable_creation_date: true
|
||||
typeset: {}
|
||||
social:
|
||||
cards: !ENV [ CARDS, true ]
|
||||
cards: !ENV [CARDS, true]
|
||||
cards_dir: assets/img/social
|
||||
cards_layout_dir: theme/layouts
|
||||
cards_layout: page
|
||||
@@ -313,7 +345,7 @@ markdown_extensions:
|
||||
custom_fences:
|
||||
- name: mermaid
|
||||
class: mermaid
|
||||
format: !!python/name:pymdownx.superfences.fence_code_format
|
||||
format: !!python/name:pymdownx.superfences.fence_code_format
|
||||
pymdownx.tabbed:
|
||||
alternate_style: true
|
||||
pymdownx.arithmatex:
|
||||
@@ -325,7 +357,7 @@ markdown_extensions:
|
||||
pymdownx.tilde: {}
|
||||
pymdownx.snippets:
|
||||
auto_append:
|
||||
- !ENV [ BUILD_ABBREVIATIONS, "includes/abbreviations.en.txt" ]
|
||||
- !ENV [BUILD_ABBREVIATIONS, "includes/abbreviations.en.txt"]
|
||||
pymdownx.tasklist:
|
||||
custom_checkbox: true
|
||||
attr_list: {}
|
||||
@@ -334,8 +366,8 @@ markdown_extensions:
|
||||
meta: {}
|
||||
abbr: {}
|
||||
pymdownx.emoji:
|
||||
emoji_index: !!python/name:material.extensions.emoji.twemoji
|
||||
emoji_generator: !!python/name:material.extensions.emoji.to_svg
|
||||
emoji_index: !!python/name:material.extensions.emoji.twemoji
|
||||
emoji_generator: !!python/name:material.extensions.emoji.to_svg
|
||||
options:
|
||||
custom_icons:
|
||||
- theme/icons
|
||||
@@ -345,50 +377,49 @@ markdown_extensions:
|
||||
toc_depth: 4
|
||||
|
||||
nav:
|
||||
- ? !ENV [ NAV_HOME, "Home" ]
|
||||
: "index.md"
|
||||
- ? !ENV [ NAV_KNOWLEDGE_BASE, "Knowledge Base" ]
|
||||
: - "basics/why-privacy-matters.md"
|
||||
- !ENV [NAV_HOME, "Home"]: "index.md"
|
||||
- !ENV [NAV_KNOWLEDGE_BASE, "Knowledge Base"]:
|
||||
- "basics/why-privacy-matters.md"
|
||||
- "basics/threat-modeling.md"
|
||||
- "basics/common-threats.md"
|
||||
- "basics/common-misconceptions.md"
|
||||
- "basics/account-creation.md"
|
||||
- "basics/account-deletion.md"
|
||||
- ? !ENV [ NAV_TECHNOLOGY_ESSENTIALS, "Technology Essentials" ]
|
||||
: - "basics/passwords-overview.md"
|
||||
- !ENV [NAV_TECHNOLOGY_ESSENTIALS, "Technology Essentials"]:
|
||||
- "basics/passwords-overview.md"
|
||||
- "basics/multi-factor-authentication.md"
|
||||
- "basics/hardware.md"
|
||||
- "basics/email-security.md"
|
||||
- "basics/vpn-overview.md"
|
||||
- ? !ENV [ NAV_ADVANCED_TOPICS, "Advanced Topics" ]
|
||||
: - "advanced/dns-overview.md"
|
||||
- !ENV [NAV_ADVANCED_TOPICS, "Advanced Topics"]:
|
||||
- "advanced/dns-overview.md"
|
||||
- "advanced/tor-overview.md"
|
||||
- "advanced/payments.md"
|
||||
- "advanced/communication-network-types.md"
|
||||
- ? !ENV [ NAV_OPERATING_SYSTEMS, "Operating Systems" ]
|
||||
: - "os/index.md"
|
||||
- !ENV [NAV_OPERATING_SYSTEMS, "Operating Systems"]:
|
||||
- "os/index.md"
|
||||
- "os/android-overview.md"
|
||||
- "os/ios-overview.md"
|
||||
- "os/linux-overview.md"
|
||||
- "os/macos-overview.md"
|
||||
- "os/qubes-overview.md"
|
||||
- ? !ENV [ NAV_OPERATING_SYSTEMS_WINDOWS, "Windows" ]
|
||||
: - "os/windows/index.md"
|
||||
- !ENV [NAV_OPERATING_SYSTEMS_WINDOWS, "Windows"]:
|
||||
- "os/windows/index.md"
|
||||
- "os/windows/group-policies.md"
|
||||
- ? !ENV [ NAV_RECOMMENDATIONS, "Recommendations" ]
|
||||
: - "tools.md"
|
||||
- ? !ENV [ NAV_SELF_HOSTING, "Self-Hosting" ]
|
||||
: - "self-hosting/index.md"
|
||||
- !ENV [NAV_RECOMMENDATIONS, "Recommendations"]:
|
||||
- "tools.md"
|
||||
- !ENV [NAV_SELF_HOSTING, "Self-Hosting"]:
|
||||
- "self-hosting/index.md"
|
||||
- "self-hosting/dns-filtering.md"
|
||||
- "self-hosting/email-servers.md"
|
||||
- "self-hosting/file-management.md"
|
||||
- ? !ENV [ NAV_INTERNET_BROWSING, "Internet Browsing" ]
|
||||
: - "tor.md"
|
||||
- !ENV [NAV_INTERNET_BROWSING, "Internet Browsing"]:
|
||||
- "tor.md"
|
||||
- "desktop-browsers.md"
|
||||
- "mobile-browsers.md"
|
||||
- "browser-extensions.md"
|
||||
- ? !ENV [ NAV_PROVIDERS, "Providers" ]
|
||||
: - "cloud.md"
|
||||
- !ENV [NAV_PROVIDERS, "Providers"]:
|
||||
- "cloud.md"
|
||||
- "data-broker-removals.md"
|
||||
- "dns.md"
|
||||
- "email-aliasing.md"
|
||||
@@ -397,8 +428,8 @@ nav:
|
||||
- "photo-management.md"
|
||||
- "search-engines.md"
|
||||
- "vpn.md"
|
||||
- ? !ENV [ NAV_SOFTWARE, "Software" ]
|
||||
: - "ai-chat.md"
|
||||
- !ENV [NAV_SOFTWARE, "Software"]:
|
||||
- "ai-chat.md"
|
||||
- "calendar.md"
|
||||
- "cryptocurrency.md"
|
||||
- "data-redaction.md"
|
||||
@@ -418,24 +449,25 @@ nav:
|
||||
- "pastebins.md"
|
||||
- "real-time-communication.md"
|
||||
- "social-networks.md"
|
||||
- ? !ENV [ NAV_HARDWARE, "Hardware" ]
|
||||
: - "mobile-phones.md"
|
||||
- !ENV [NAV_HARDWARE, "Hardware"]:
|
||||
- "hardware-wallets.md"
|
||||
- "mobile-phones.md"
|
||||
- "security-keys.md"
|
||||
- ? !ENV [ NAV_OPERATING_SYSTEMS, "Operating Systems" ]
|
||||
: - ? !ENV [ NAV_ANDROID, "Android" ]
|
||||
: - "android/index.md"
|
||||
- !ENV [NAV_OPERATING_SYSTEMS, "Operating Systems"]:
|
||||
- !ENV [NAV_ANDROID, "Android"]:
|
||||
- "android/index.md"
|
||||
- "android/distributions.md"
|
||||
- "android/general-apps.md"
|
||||
- "android/obtaining-apps.md"
|
||||
- "desktop.md"
|
||||
- "router.md"
|
||||
- ? !ENV [ NAV_ADVANCED, "Advanced" ]
|
||||
: - "alternative-networks.md"
|
||||
- !ENV [NAV_ADVANCED, "Advanced"]:
|
||||
- "alternative-networks.md"
|
||||
- "device-integrity.md"
|
||||
- ? !ENV [ NAV_ACTIVISM, "Activism" ]
|
||||
: - "activism/index.md"
|
||||
- ? !ENV [ NAV_ACTIVISM_TOOLBOX, "Activist Toolbox" ]
|
||||
: - "activism/toolbox/index.md"
|
||||
- !ENV [NAV_ACTIVISM, "Activism"]:
|
||||
- "activism/index.md"
|
||||
- !ENV [NAV_ACTIVISM_TOOLBOX, "Activist Toolbox"]:
|
||||
- "activism/toolbox/index.md"
|
||||
- "Check Your Laws":
|
||||
- "activism/toolbox/tip-know-your-privacy-laws.md"
|
||||
- "activism/toolbox/tip-report-privacy-violations.md"
|
||||
@@ -472,48 +504,43 @@ nav:
|
||||
- "Take Action!":
|
||||
- "activism/toolbox/tip-engage-boosts-and-contribute.md"
|
||||
- "activism/toolbox/tip-level-up-assemble-and-organize.md"
|
||||
- ? !ENV [ NAV_ACTIVISM_LEGAL, "Legal Resources" ]
|
||||
: - "activism/legal/dpa-directory.md"
|
||||
- ? !ENV [ NAV_BLOG, "Articles" ]
|
||||
: !ENV [ ARTICLES_SITE_BASE_URL, "/articles/" ]
|
||||
- ? !ENV [ NAV_VIDEOS, "Videos" ]
|
||||
: !ENV [ VIDEOS_SITE_BASE_URL, "/videos/" ]
|
||||
- ? !ENV [ NAV_NEWS, "News" ]
|
||||
: !ENV [ NEWS_SITE_BASE_URL, "/news/" ]
|
||||
- ? !ENV [ NAV_FORUM, "Forum" ]
|
||||
: !ENV [ NAV_FORUM_LINK, "https://discuss.privacyguides.net/" ]
|
||||
- ? !ENV [ NAV_WIKI, "Wiki" ]
|
||||
: !ENV [
|
||||
- !ENV [NAV_ACTIVISM_LEGAL, "Legal Resources"]:
|
||||
- "activism/legal/dpa-directory.md"
|
||||
- !ENV [NAV_BLOG, "Articles"]: !ENV [ARTICLES_SITE_BASE_URL, "/articles/"]
|
||||
- !ENV [NAV_VIDEOS, "Videos"]: !ENV [VIDEOS_SITE_BASE_URL, "/videos/"]
|
||||
- !ENV [NAV_NEWS, "News"]: !ENV [NEWS_SITE_BASE_URL, "/news/"]
|
||||
- !ENV [NAV_FORUM, "Forum"]:
|
||||
!ENV [NAV_FORUM_LINK, "https://discuss.privacyguides.net/"]
|
||||
- !ENV [NAV_WIKI, "Wiki"]:
|
||||
!ENV [
|
||||
NAV_WIKI_LINK,
|
||||
"https://discuss.privacyguides.net/c/community-wiki/9411/none",
|
||||
]
|
||||
- ? !ENV [ NAV_ABOUT, "About" ]
|
||||
: - "about.md"
|
||||
- !ENV [NAV_ABOUT, "About"]:
|
||||
- "about.md"
|
||||
- "about/donate.md"
|
||||
- ? !ENV [ NAV_ABOUT_TEAM_MEMBERS, "Team Members" ]
|
||||
: https://discuss.privacyguides.net/u?group=team&order=solutions&period=all
|
||||
- ? !ENV [ NAV_ABOUT_POLICIES, "Policies" ]
|
||||
: - "about/criteria.md"
|
||||
- !ENV [NAV_ABOUT_TEAM_MEMBERS, "Team Members"]:
|
||||
https://discuss.privacyguides.net/u?group=team&order=solutions&period=all
|
||||
- !ENV [NAV_ABOUT_POLICIES, "Policies"]:
|
||||
- "about/criteria.md"
|
||||
- "about/donation-acceptance-policy.md"
|
||||
- "about/executive-policy.md"
|
||||
- "privacy.md"
|
||||
- "about/notices.md"
|
||||
- ? !ENV [ NAV_COMMUNITY, "Community" ]
|
||||
: - "about/jobs.md"
|
||||
- !ENV [NAV_COMMUNITY, "Community"]:
|
||||
- "about/jobs.md"
|
||||
- "about/contributors.md"
|
||||
- ? !ENV [ NAV_ONLINE_SERVICES, "Online Services" ]
|
||||
: "about/services.md"
|
||||
- ? !ENV [ NAV_CODE_OF_CONDUCT, "Code of Conduct" ]
|
||||
: "CODE_OF_CONDUCT.md"
|
||||
- !ENV [NAV_ONLINE_SERVICES, "Online Services"]: "about/services.md"
|
||||
- !ENV [NAV_CODE_OF_CONDUCT, "Code of Conduct"]: "CODE_OF_CONDUCT.md"
|
||||
- "about/statistics.md"
|
||||
- ? !ENV [ NAV_CONTRIBUTING, "Contributing" ]
|
||||
: - ? !ENV [ NAV_WRITING_GUIDE, "Writing Guide" ]
|
||||
: - "meta/writing-style.md"
|
||||
- !ENV [NAV_CONTRIBUTING, "Contributing"]:
|
||||
- !ENV [NAV_WRITING_GUIDE, "Writing Guide"]:
|
||||
- "meta/writing-style.md"
|
||||
- "meta/admonitions.md"
|
||||
- "meta/brand.md"
|
||||
- "meta/translations.md"
|
||||
- ? !ENV [ NAV_TECHNICAL_GUIDES, "Technical Guides" ]
|
||||
: - "meta/uploading-images.md"
|
||||
- !ENV [NAV_TECHNICAL_GUIDES, "Technical Guides"]:
|
||||
- "meta/uploading-images.md"
|
||||
- "meta/git-recommendations.md"
|
||||
- "meta/commit-messages.md"
|
||||
- "meta/pr-comments.md"
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 1.9 KiB |
Reference in New Issue
Block a user