-
-
-
+
diff --git a/_includes/scripts.html b/_includes/scripts.html
index cdc7e515..b5ed2d18 100644
--- a/_includes/scripts.html
+++ b/_includes/scripts.html
@@ -2,17 +2,7 @@
-
+
-
diff --git a/_includes/sections/browser-addons.html b/_includes/sections/browser-addons.html
index 7fb4028e..6bba6c32 100644
--- a/_includes/sections/browser-addons.html
+++ b/_includes/sections/browser-addons.html
@@ -94,7 +94,7 @@ chrome=""
%}
-
For Experts Only
+
For Power Users Only
These addons require quite a lot of interaction from the user. Some sites will not work properly until you have configured the add-ons.
diff --git a/_includes/sections/browser-fingerprint.html b/_includes/sections/browser-fingerprint.html
index 139351e6..810ffc19 100644
--- a/_includes/sections/browser-fingerprint.html
+++ b/_includes/sections/browser-fingerprint.html
@@ -4,7 +4,7 @@
Your Browser sends information that makes you unique amongst millions of users and therefore easy to identify.
-
+
When you visit a web page, your browser voluntarily sends information about its configuration, such as available fonts, browser type, and add-ons. If this combination of information is unique, it may be possible to identify and track you without using cookies. EFF created a Tool called Panopticlick to test your browser to see how unique it is.
diff --git a/_includes/sections/browser-tweaks.html b/_includes/sections/browser-tweaks.html
index 277bbd57..2fa29e1e 100644
--- a/_includes/sections/browser-tweaks.html
+++ b/_includes/sections/browser-tweaks.html
@@ -52,9 +52,6 @@
dom.event.clipboardevents.enabled = false
Disable that websites can get notifications if you copy, paste, or cut something from a web page, and it lets them know which part of the page had been selected.
-
geo.enabled = false
-
Disables geolocation.
-
media.eme.enabled = false
Disables playback of DRM-controlled HTML5 content, which, if enabled, automatically downloads the Widevine Content Decryption Module provided by Google Inc. Details
@@ -118,23 +115,8 @@
-
network.trr.mode = 2
-
- Use Trusted Recursive Resolver (DNS-over-HTTPS) first and if it fails, use the system resolver Source
-
- 0 = disabled by default, may change in the future
- 1 = use the faster resolver
- 2 = use DoH first, fallback to system resolver
- 3 = only use DoH. This may require network.trr.bootstrapAddress
or using an IP address in network.trr.uri
.
- 5 = explicitly disable DoH
-
-
-
-
network.trr.uri = CHANGEME
-
The address of your DNS-over-HTTPS provider, if you don't have one, check our encrypted DNS recommendations . It can also be changed in Settings, Network Settings, Enable DNS over HTTPS, Use Provider, Custom .
-
-
network.security.esni.enabled = true
-
Hide the address which you are requesting SSL certificate for if the server supports it. This requires DoH/TRR to be enabled even on Android 9+ when Private DNS is enabled .
+
Looking for TRR, DoH or ESNI?
+
They have moved to our DNS page .
webgl.disabled = true
WebGL is a potential security risk. Source
@@ -162,10 +144,9 @@
-
Firefox user.js Templates
+
Firefox user.js Templates
ghacks-user.js - An ongoing comprehensive user.js template for configuring and hardening Firefox privacy, security and anti-fingerprinting.
- pyllyukko/user.js - This is a user.js configuration file to harden Firefox's settings and make it more secure.
diff --git a/_includes/sections/cloud-storage.html b/_includes/sections/cloud-storage.html
index 90cbd5ff..f8a501c5 100644
--- a/_includes/sections/cloud-storage.html
+++ b/_includes/sections/cloud-storage.html
@@ -22,7 +22,7 @@ fire=""
{% include cardv2.html
title="Least Authority S4 - For Experts"
-image="/assets/img/provider/S4.jpg"
+image="/assets/img/provider/S4.png"
description="S4 (Simple Secure Storage Service) is Least Authority's verifiably secure off-site backup system for individuals and businesses. 100% client-side encryption and open source transparency. 250GB for $9.95/month or 5TB for $25.95/month. Servers are hosted with Amazon S3 in the US."
website="https://leastauthority.com/"
forum="https://forum.privacytools.io/t/discussion-least-authority-s4/288"
diff --git a/_includes/sections/dns.html b/_includes/sections/dns.html
index d8511966..765d83f6 100644
--- a/_includes/sections/dns.html
+++ b/_includes/sections/dns.html
@@ -1,30 +1,37 @@
Domain Name System (DNS)
-{% include cardv2.html
-title="OpenNIC - Service"
-image="/assets/img/tools/OpenNIC.png"
-description="OpenNIC is an alternate network information center/alternative DNS root which lists itself as an alternative to ICANN and its registries. Like all alternative root DNS systems, OpenNIC-hosted domains are unreachable to the vast majority of the Internet."
-website="https://www.opennic.org/"
-forum="https://forum.privacytools.io/t/discussion-opennic/338"
-github="https://github.com/OpenNIC"
+{%
+ include cardv2.html
+ title="OpenNIC - Service"
+ image="/assets/img/tools/OpenNIC.png"
+ description="OpenNIC is an alternate network information center/alternative DNS root which lists itself as an alternative to ICANN and its registries. Like all alternative root DNS systems, OpenNIC-hosted domains are unreachable to the vast majority of the Internet."
+ website="https://www.opennic.org/"
+ forum="https://forum.privacytools.io/t/discussion-opennic/338"
+ github="https://github.com/OpenNIC"
%}
-{% include cardv2.html
-title="Njalla - Domain Registration"
-image="/assets/img/provider/Njalla.png"
-description="Njalla only needs your email or jabber address in order to register a domain name for you. Created by people from The Pirate Bay and IPredator VPN. Accepted Payments: Bitcoin, Litecoin, Monero, DASH, Bitcoin Cash and PayPal. A privacy-aware domain registration service."
-website="https://njal.la/"
-tor="http://njalladnspotetti.onion"
-forum="https://forum.privacytools.io/t/discussion-njalla/339"
+{%
+ include cardv2.html
+ title="Njalla - Domain Registration"
+ image="/assets/img/provider/Njalla.png"
+ description="Njalla only needs your email or XMPP address in order to register a domain name for you. Created by people from The Pirate Bay and IPredator VPN. Accepted Payments: Bitcoin, Litecoin, Monero, DASH, Bitcoin Cash and PayPal. A privacy-aware domain registration service."
+ website="https://njal.la/"
+ tor="http://njalladnspotetti.onion"
+ forum="https://forum.privacytools.io/t/discussion-njalla/339"
%}
-{% include cardv2.html
-title="DNSCrypt - Tool"
-image="/assets/img/tools/DNSCrypt.png"
-description="A protocol for securing communications between a client and a DNS resolver. The DNSCrypt protocol uses high-speed high-security elliptic-curve cryptography and is very similar to DNSCurve, but focuses on securing communications between a client and its first-level resolver."
-website="https://dnscrypt.info/"
-forum="https://forum.privacytools.io/t/discussion-dnscrypt/340"
-github="https://github.com/jedisct1/dnscrypt-proxy"
+{%
+ include cardv2.html
+ title="DNSCrypt-Proxy - Tool"
+ image="/assets/img/tools/DNSCrypt-Proxy.png"
+ description="DNSCrypt-Proxy is a command-line DNS proxy with support for the encrypted DNS protocols, DNS over HTTPS and DNSCrypt. Can cache results to improve speed, and allows filtering, forwarding, and cloaking."
+ website="https://github.com/jedisct1/dnscrypt-proxy/"
+ forum="https://forum.privacytools.io/t/discussion-dnscrypt-proxy/1498"
+ github="https://github.com/jedisct1/dnscrypt-proxy/"
+ linux=""
+ mac=""
+ android=""
+ ios=""
%}
Encrypted ICANN DNS Providers
@@ -37,7 +44,7 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
- ICANN DNS Provider
+ ICANN DNS Provider
Server Locations
Privacy Policy
Type
@@ -47,6 +54,7 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
QNAME Minimization
Filtering
Source Code
+ Hosting Provider
@@ -54,7 +62,12 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
AdGuard
- Anycast (based in Cyprus)
+ Anycast (based in
+
+
+ Cyprus)
+
+
@@ -65,19 +78,44 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
DoH, DoT, DNSCrypt
Yes
Yes
- Ads, trackers, malicious domains
+
+
+ Ads, trackers,
+
+
+ malicious domains
+
+
+
+
+ Serveroid, LLC
+
+
BlahDNS
- Switzerland, Japan, Germany
+
+
+
+ Switzerland,
+
+
+
+ Japan,
+
+
+
+ Germany
+
+
@@ -85,22 +123,54 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
Hobby Project
No
- DoH, DoT, DNSCrypt
+
+
+ DoH,
+
+ DoT ,
+
+
+ DNSCrypt
+
Yes
Yes
- Ads, trackers, malicious domains
+
+
+ Ads, trackers,
+
+
+ malicious domains
+
+
+
+
+
+ Choopa, LLC ,
+
+
+ Data Center Light ,
+
+
+ Hetzner Online GmbH ,
+
+
Cloudflare
- Anycast (based in US)
+ Anycast (based in
+
+
+ US)
+
+
@@ -117,13 +187,19 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
+ Self
CZ.NIC
- Czech Republic
+
+
+
+ Czech Republic
+
+
@@ -136,13 +212,19 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
Yes
?
?
+ Self
dnswarden
- Germany
+
+
+
+ Germany
+
+
@@ -150,18 +232,40 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
Hobby Project
No
- DoH, DoT, DNSCrypt
+
+
+ DoH,
+
+ DoT ,
+
+
+ DNSCrypt
+
Yes
Yes
- Based on server choice
+
+
+ Based on server choice
+
+
?
+
+
+ Hetzner Online GmbH
+
+
Foundation for Applied Privacy
- Austria
+
+
+
+ Austria
+
+
@@ -169,37 +273,116 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
Non-Profit
Some
- DoH, DoT
+
+
+ DoH,
+
+ DoT
+
+
+
Yes
Yes
No
?
+
+
+ IPAX OG
+
+
- nextdns
+ NextDNS
+
+ Anycast (based in
+
+
+ US)
+
- Anycast (based in US)
Commercial
- Based on user choice
+
+ Based on user choice
+
DoH, DoT, DNSCrypt
Yes
Yes
- Based on user choice
+
+
+ Based on server choice
+
+
?
+ Self
+
+
+
+
+ NixNet
+
+
+
+ Anycast (based in
+
+ US),
+
+
+
+ US,
+
+
+
+ Luxembourg
+
+
+
+
+
+
+
+
+
+ Informal collective
+
+
+ No
+ DoT
+ Yes
+ Yes
+
+
+ Based on server choice
+
+
+
+
+
+
+
+
+
+ FranTech Solutions
+
+
PowerDNS
- The Netherlands
+
+
+
+ The Netherlands
+
+
@@ -216,13 +399,23 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
+
+
+ TransIP B.V. Admin
+
+
Quad9
- Anycast (based in US)
+ Anycast (based in
+
+
+ US)
+
+
@@ -233,15 +426,30 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
DoH, DoT, DNSCrypt
Yes
Yes
- Malicious domains
+
+
+ Malicious domains
+
+
?
+
+ Self,
+
+ Packet Clearing House
+
+
SecureDNS
- The Netherlands
+
+
+
+ The Netherlands
+
+
@@ -252,15 +460,39 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
DoH, DoT, DNSCrypt
Yes
Yes
- Based on server choice
+
+
+ Based on server choice
+
+
?
+
+
+ DigitalOcean, Inc. ,
+
+
UncensoredDNS
- Anycast (based in Denmark)
+ Anycast (based in
+
+
+ Denmark),
+
+
+
+
+ Denmark,
+
+
+
+
+ US
+
+
@@ -273,29 +505,93 @@ github="https://github.com/jedisct1/dnscrypt-proxy"
No
No
?
+
+ Self,
+
+ Telia Company AB
+
+
-
-
Terms
-
-
- DNS-over-TLS (DoT) - A security protocol for encrypted DNS on a dedicated port 853.
- DNS-over-HTTPS (DoH) - Similar to DoT, but uses HTTPS instead, being indistinguishable from "normal" HTTPS traffic on port 443.
- DNSCrypt - An older yet robust method of encrypting DNS.
-
-
-
Worth Mentioning and Additional Information
-
-
- Firefox comes with built-in DoH support with Cloudflare set as the default resolver, but can be configured to use any DoH resolver. Currently Mozilla is conducting studies before enabling DoH by default for all US-based Firefox users.
- Android 9 comes with a DoT client by default .
- DNSCloak - An open-source DNSCrypt and DoH client for iOS by the Center for the Cultivation of Technology gemeinnuetzige GmbH .
- Pi-hole - A network-wide DNS server mainly for the Raspberry Pi. Blocks ads, tracking, and malicious domains for all devices on your network.
- NoTrack - A network-wide DNS server like Pi-hole for blocking ads, tracking, and malicious domains.
- Stubby - An open-source application for Linux, macOS, and Windows that acts as a local DNS Privacy stub resolver using DoT.
- Namecoin - A decentralized DNS open-source information registration and transfer system based on the Bitcoin cryptocurrency.
- QNAME Minimization and Your Privacy by the Internet Systems Consortium (ISC)
- DNSSEC and BIND 9 by the ISC
-
+
+Terms
+
+
+ DNS-over-TLS (DoT) - A security protocol for encrypted DNS on a dedicated port 853. Some providers support port 443 which generally works everywhere while port 853 is often blocked by restrictive firewalls. DoT has two modes:
+
+ Oppurtunistic mode: the client attempts to form a DNS-over-TLS connection to the server on port 853 without performing certificate validation. If it fails, it will use unencrypted DNS.
+ Strict mode: the client connects to a specific hostname and performs certificate validation for it. If it fails, no DNS queries are made until it succeeds.
+
+ DNS-over-HTTPS (DoH) - Similar to DoT, but uses HTTPS instead, being indistinguishable from "normal" HTTPS traffic on port 443.
+ DNSCrypt - An older yet robust method of encrypting DNS.
+
+
+How to verify DNS is encrypted
+
+
+ DoH / DoT
+
+ Check DNSLeakTest.com .
+ Check the website of your DNS provider. They may have a page for telling "you are using our DNS." Examples include AdGuard and Cloudflare .
+ If using Firefox's trusted recursive resolver (TRR), navigate to about:networking#dns
. If the TRR column says "true" for some fields, you are using DoH.
+
+
+ dnscrypt-proxy - Check dnscrypt-proxy's wiki on how to verify that your DNS is encrypted .
+ DNSSEC - Check DNSSEC Resolver Test by Matthäus Wander .
+ QNAME Minimization - Run dig +short txt qnamemintest.internet.nl
from the command-line (taken from this NLnet Labs presentation ). If you are on Windows 10, run Resolve-DnsName -Type TXT -Name qnamemintest.internet.nl
from the PowerShell. You should see this display: "HOORAY - QNAME minimisation is enabled on your resolver :)!"
+
+
+Worth Mentioning and Additional Information
+
+
+ Encrypted DNS clients for desktop:
+
+ Firefox comes with built-in DoH support with Cloudflare set as the default resolver, but can be configured to use any DoH resolver. Currently Mozilla is conducting studies before enabling DoH by default for all US-based Firefox users.
+
+ DNS over HTTPS can be enabled in Menu -> Preferences (about:preferences
) -> Network Settings -> Enable DNS over HTTPS. Set "Use Provider" to "Custom", and enter your DoH provider's address.
+ Advanced users may enable it in about:config
by setting network.trr.custom_uri
and network.trr.uri
as the address you find from the documentation of your DoH provider and network.trr.mode
as 2
. It may also be desirable to set network.security.esni.enabled
to True
in order to enable encrypted SNI and make sites supporting ESNI a bit more difficult to track.
+
+
+
+ Encrypted DNS clients for mobile:
+
+ Android 9 comes with a DoT client by default .
+
+ We recommend selecting Private DNS provider hostname and entering the DoT address from documentation of your DoT provider to enable strict mode (see Terms above).
+
+ DNSCloak - An open-source DNSCrypt and DoH client for iOS by the Center for the Cultivation of Technology gemeinnuetzige GmbH .
+ Nebulo - An open-source application for Android supporting DoH and DoT. It also supports caching DNS responses and locally logging DNS queries.
+
+
+ Local DNS servers:
+
+ Namecoin - A decentralized DNS open-source information registration and transfer system based on the Bitcoin cryptocurrency.
+ Stubby - An open-source application for Linux, macOS, and Windows that acts as a local DNS Privacy stub resolver using DoT.
+ Unbound - a validating, recursive, caching DNS resolver. It can also be ran network-wide and has supported DNS-over-TLS since version 1.7.3.
+
+
+
+ Network wide DNS servers:
+
+ Pi-hole - A network-wide DNS server mainly for the Raspberry Pi. Blocks ads, tracking, and malicious domains for all devices on your network.
+ NoTrack - A network-wide DNS server like Pi-hole for blocking ads, tracking, and malicious domains.
+
+
+ Further reading:
+
+
+
diff --git a/_includes/sections/email-providers.html b/_includes/sections/email-providers.html
index afff5560..c12a00a3 100644
--- a/_includes/sections/email-providers.html
+++ b/_includes/sections/email-providers.html
@@ -30,7 +30,11 @@
2015
- Netherlands
+
+
+ Netherlands
+
+
1 GB
Free
Accepted
@@ -46,7 +50,11 @@
2010
- Switzerland
+
+
+ Switzerland
+
+
2 GB
$ 60
Accepted
@@ -63,7 +71,11 @@
2014
- Germany
+
+
+ Germany
+
+
2 GB
12 €
Accepted
@@ -79,7 +91,11 @@
2013
- Belgium
+
+
+ Belgium
+
+
500 MB
Free
Accepted
@@ -95,7 +111,11 @@
2003
- Switzerland
+
+
+ Switzerland
+
+
1 GB
$ 49.95
Accepted
@@ -111,7 +131,11 @@
2009
- Germany
+
+
+ Germany
+
+
2 GB
12 €
No
@@ -128,7 +152,11 @@
2013
- Switzerland
+
+
+ Switzerland
+
+
500 MB
Free
Accepted
@@ -145,7 +173,11 @@
1999
- Norway
+
+
+ Norway
+
+
1 GB
$ 19.95
Accepted
@@ -161,7 +193,11 @@
2015
- Netherlands
+
+
+ Netherlands
+
+
25 GB
29 €
No
@@ -177,7 +213,11 @@
2014
- Netherlands
+
+
+ Netherlands
+
+
10 GB
$ 59.95
Accepted
@@ -193,7 +233,11 @@
2011
- Germany
+
+
+ Germany
+
+
1 GB
Free
No
diff --git a/_includes/sections/operating-systems.html b/_includes/sections/operating-systems.html
index 17700fbf..9dc6d511 100644
--- a/_includes/sections/operating-systems.html
+++ b/_includes/sections/operating-systems.html
@@ -41,6 +41,33 @@ tor="http://sejnfjrq6szgca7v.onion"
Don't use Windows 10 - It's a privacy nightmare
+
Remember to check CPU vulnerability mitigations
+
+
This also affects Windows 10 , but it doesn't expose this information or mitigation instructions as easily. MacOS users check How to enable full mitigation for Microarchitectural Data Sampling (MDS) vulnerabilities on Apple Support .
+
+
When running a enough recent kernel, you can check the CPU vulnerabilities it detects by tail -n +1 /sys/devices/system/cpu/vulnerabilities/*
. By using tail -n +1
instead of cat
, the file names are also visible.
+
+
+ In case you have an Intel CPU, you may notice "SMT vulnerable" display after running the tail
command. To mitigate this, disable hyper-threading from the UEFI/BIOS. You can also take the following mitigation steps below if your system/distribution uses GRUB and supports /etc/default/grub.d/
:
+
+
+
+ sudo mkdir /etc/default/grub.d/
to create a directory for additional grub configuration
+ echo GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT mds=full,nosmt" | sudo tee /etc/default/grub.d/mds.conf
to create a new grub config file source with the echoed content
+ sudo grub-mkconfig -o /boot/grub/grub.cfg
to generate a new grub config file including this new kernel boot flag
+ sudo reboot
to reboot
+ after the reboot, check tail -n +1 /sys/devices/system/cpu/vulnerabilities/*
again to see that MDS now says "SMT disabled."
+
+
+
Further reading
+
+
+
Worth Mentioning
diff --git a/_includes/sections/password-managers.html b/_includes/sections/password-managers.html
index 14c153b4..c0f79ae6 100644
--- a/_includes/sections/password-managers.html
+++ b/_includes/sections/password-managers.html
@@ -44,7 +44,7 @@
description="LessPass is a free and open source password manager that generates unique passwords for websites, email accounts, or anything else based on a master password and information you know. No sync needed. Uses PBKDF2 and SHA-256. It's advised to use the browser addons for more security."
website="https://lesspass.com/"
forum="https://forum.privacytools.io/t/discussion-keepassxc/1344/2"
- github="https://github.com/keepassxreboot/keepassxc"
+ github="https://github.com/lesspass/lesspass"
firefox="https://addons.mozilla.org/en-US/firefox/addon/lesspass/"
chrome="https://chrome.google.com/webstore/detail/lesspass/lcmbpoclaodbgkbjafnkbbinogcbnjih"
android="https://play.google.com/store/apps/details?id=com.lesspass.android&hl=en"
diff --git a/_includes/sections/paste-services.html b/_includes/sections/paste-services.html
index 788d8210..3cb3b676 100644
--- a/_includes/sections/paste-services.html
+++ b/_includes/sections/paste-services.html
@@ -4,7 +4,7 @@
title="PrivateBin"
image="/assets/img/tools/PrivateBin.png"
description="PrivateBin is a minimalist, open source online pastebin where the server has zero knowledge of pasted data. Data is encrypted/decrypted in the browser using 256bit AES. It is the improved version of ZeroBin."
-website="https://bin.privacytools.io/"
+website="https://privatebin.info/"
forum="https://forum.privacytools.io/t/discussion-privatebin/296"
github="https://github.com/PrivateBin/PrivateBin"
%}
diff --git a/_includes/sections/privacy-resources.html b/_includes/sections/privacy-resources.html
index e4340e80..421c3bf2 100644
--- a/_includes/sections/privacy-resources.html
+++ b/_includes/sections/privacy-resources.html
@@ -14,14 +14,15 @@
Information
+ Freedom of the Press Foundation - Supporting and defending journalism dedicated to transparency and accountability since 2012.
+ Erfahrungen.com - German review aggregator website of privacy-related services.
+ Keybase.io - Get a public key, safely, starting just with someone's social media username.
+ privacy.net - What does the US government know about you?
r/privacytoolsIO Wiki - Our Wiki on reddit.com.
Security Now! - Weekly Internet Security Podcast by Steve Gibson and Leo Laporte.
TechSNAP - Weekly Systems, Network, and Administration Podcast. Every week TechSNAP covers the stories that impact those of us in the tech industry.
- Keybase.io - Get a public key, safely, starting just with someone's social media username.
- Freedom of the Press Foundation - Supporting and defending journalism dedicated to transparency and accountability since 2012.
- Erfahrungen.com - German review aggregator website of privacy-related services.
Terms of Service; Didn't Read - "I have read and agree to the Terms" is the biggest lie on the web. We aim to fix that.
- privacy.net - What does the US government know about you?
+ The Great Cloudwall - Critique and information on why to avoid Cloudflare, a big company with a huge portion of the internet behind it.
Tools
@@ -35,7 +36,6 @@
by the late Aaron Swartz and is currently managed by Freedom of the Press Foundation.
Reset The Net - Privacy Pack - Help fight to end mass surveillance. Get these tools to protect yourself and your friends.
Security First - Umbrella is an Android app that provides all the advice needed to operate safely in a hostile environment.
- Block Cloudflare MiTM Attack - Firefox add-on to detect and block Cloudflare MITM attack.
Osalt - A directory to help you find open source alternatives to proprietary tools.
AlternativeTo - A directory to help find alternatives to other software, with the option to only show open source software
diff --git a/_includes/sections/search-engines.html b/_includes/sections/search-engines.html
index 37e49982..d28f3f02 100644
--- a/_includes/sections/search-engines.html
+++ b/_includes/sections/search-engines.html
@@ -6,7 +6,7 @@
{% include cardv2.html
title="searx - Decentral"
-image="/assets/img/provider/searx.jpg"
+image="/assets/img/provider/searx.png"
description='An
open source metasearch engine, aggregating the results of other search engines while not storing information about its users. No logs, no ads and no tracking.
List of Instances or try
search.privacytools.io '
website="https://searx.me/"
tor="http://ulrn6sryqaifefld.onion"
@@ -24,7 +24,7 @@ forum="https://forum.privacytools.io/t/discussion-startpage/284"
{% include cardv2.html
title="DuckDuckGo - USA"
-image="/assets/img/provider/DuckDuckGo.jpg"
+image="/assets/img/provider/DuckDuckGo.png"
description='The search engine that doesn\'t track you. Some of DuckDuckGo\'s code is free software hosted at GitHub, but the core is proprietary.
The company is based in the USA. '
website="https://duckduckgo.com/"
tor="http://3g2upl4pq6kufc4m.onion"
@@ -34,7 +34,7 @@ github="https://github.com/duckduckgo"
{% include cardv2.html
title="Qwant - France"
-image="/assets/img/provider/qwant.jpg"
+image="/assets/img/provider/Qwant.png"
description='Qwants philosophy is based on two principles: no user tracking and no filter bubble. Qwant was launched in France in February 2013.
Privacy Policy. '
website="https://www.qwant.com/"
forum="https://forum.privacytools.io/t/discussion-qwant/286"
diff --git a/_includes/sections/teamchat.html b/_includes/sections/teamchat.html
index 345b8d0c..8196eba3 100644
--- a/_includes/sections/teamchat.html
+++ b/_includes/sections/teamchat.html
@@ -4,35 +4,38 @@
If your project or organization currently uses a platform like Discord or Slack you should pick an alternative here.
-{% include cardv2.html
-title="Rocket.chat"
-image="/assets/img/tools/rocket.chat.png"
-description="Rocket.chat is an self-hostable open source platform for team communication. It has optional federation and experimental E2EE."
-labels="warning: