From 481bc432469615706dac1e6ed48094b2a2fd65cd Mon Sep 17 00:00:00 2001 From: Mikaela Suomalainen Date: Sun, 22 Mar 2020 09:11:36 +0200 Subject: [PATCH 01/42] VoIP: Jitsi Meet: warn about E2EE, GA & link public instances list (#1793) --- _includes/sections/voice-video-messenger.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_includes/sections/voice-video-messenger.html b/_includes/sections/voice-video-messenger.html index 0887cff5..51db578a 100644 --- a/_includes/sections/voice-video-messenger.html +++ b/_includes/sections/voice-video-messenger.html @@ -36,7 +36,7 @@ ios="https://apps.apple.com/us/app/mumble/id443472808?ls=1"

Worth Mentioning

Related Information

From 3539fc3f14d0eed1cf01df445af99a3b24597e3f Mon Sep 17 00:00:00 2001 From: Stephen Karl Larroque Date: Sun, 22 Mar 2020 11:30:33 +0100 Subject: [PATCH 02/42] add partial centralization warning for Jami (#1752) --- _includes/sections/instant-messenger.html | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/_includes/sections/instant-messenger.html b/_includes/sections/instant-messenger.html index ad70a863..88779ff5 100644 --- a/_includes/sections/instant-messenger.html +++ b/_includes/sections/instant-messenger.html @@ -163,8 +163,8 @@ include cardv2.html title="Jami" image="/assets/img/svg/3rd-party/jami.svg" - description="Encrypted instant messaging and video calling software. Uses TLS 1.3 for encryption." - labels="success:VoIP" + description="Encrypted instant messaging and video calling software. All communications are E2EE using TLS 1.3 and never stored elsewhere than on user's devices, even when TURN servers are used." + labels="warning:Warning:This software is partially centralized but can be self-hosted.|success:VoIP" website="https://jami.net/" forum="https://forum.privacytools.io/t/discussion-jami/2116" gitlab="https://git.jami.net/savoirfairelinux" From bd50e952b5068de9061284ab8036f60ba8c9095b Mon Sep 17 00:00:00 2001 From: blacklight447 Date: Thu, 26 Mar 2020 14:26:11 +0100 Subject: [PATCH 03/42] remove bad vpn link (#1798) removes a link on the vpn page which spread miss information about Tor. --- pages/providers/vpn.html | 1 - 1 file changed, 1 deletion(-) diff --git a/pages/providers/vpn.html b/pages/providers/vpn.html index e19b1215..6cf05899 100644 --- a/pages/providers/vpn.html +++ b/pages/providers/vpn.html @@ -230,7 +230,6 @@ breadcrumb: "VPN"
  • Beware of False Reviews - VPN Marketing and Affiliate Programs
  • -
  • I am Anonymous When I Use a VPN - 7 Myths Debunked
    (Note: While this is a good read, they also use the article for self-promotion)
  • Proxy.sh VPN Provider Sniffed Server Traffic to Catch Hacker
  • Ethical policy - All of the reasons why Proxy.sh might enable logging
  • IVPN.net will collect your email and IP address after sign up
    Read the Email statement from IVPN.
  • From 95d167c61888150c89b735bdd583e9851cc3f94b Mon Sep 17 00:00:00 2001 From: Daniel Nathan Gray Date: Thu, 26 Mar 2020 13:40:04 +0000 Subject: [PATCH 04/42] Add warning, E2EE alpha Nextcloud (#1799) --- _includes/sections/cloud-storage.html | 31 +++++++------- _includes/sections/selfhosted-cloud.html | 53 ++++++++++++------------ 2 files changed, 43 insertions(+), 41 deletions(-) diff --git a/_includes/sections/cloud-storage.html b/_includes/sections/cloud-storage.html index 434caacf..402bc071 100644 --- a/_includes/sections/cloud-storage.html +++ b/_includes/sections/cloud-storage.html @@ -5,21 +5,22 @@ {% include cardv2.html -title="Nextcloud - Choose your hoster" -image="/assets/img/svg/3rd-party/nextcloud.svg" -description="Nextcloud is a suite of client-server software for creating your own file hosting services on a private server you control. Nextcloud is free and open-source, and supports end-to-end encryption with many of its clients. The only limits on storage and bandwidth are the limits on the server provider you choose." -website="https://nextcloud.com/" -forum="https://forum.privacytools.io/t/discussion-nextcloud/287" -github="https://github.com/nextcloud" -windows="https://nextcloud.com/install/#install-clients" -mac="https://nextcloud.com/install/#install-clients" -linux="https://nextcloud.com/install/#install-clients" -freebsd="https://www.freshports.org/www/nextcloud/" -openbsd="http://openports.se/www/nextcloud" -netbsd="http://pkgsrc.se/www/php-nextcloud" -ios="https://itunes.apple.com/us/app/nextcloud/id1125420102?mt=8" -fdroid="https://f-droid.org/packages/com.nextcloud.client/" -googleplay="https://play.google.com/store/apps/details?id=com.nextcloud.client" + title="Nextcloud - Choose your hoster" + image="/assets/img/svg/3rd-party/nextcloud.svg" + description="Nextcloud is a suite of free and open-source client-server software for creating your own file hosting services on a private server you control. The only limits on storage and bandwidth are the limits on the server provider you choose." + labels="warning:Experimental E2EE:Regarding E2EE their description states 'End-to-end encryption is still in alpha state, don't use this in production and only with test data!'." + website="https://nextcloud.com/" + forum="https://forum.privacytools.io/t/discussion-nextcloud/287" + windows="https://nextcloud.com/install/#install-clients" + mac="https://nextcloud.com/install/#install-clients" + linux="https://nextcloud.com/install/#install-clients" + freebsd="https://www.freshports.org/www/nextcloud/" + openbsd="http://openports.se/www/nextcloud" + netbsd="http://pkgsrc.se/www/php-nextcloud" + fdroid="https://f-droid.org/packages/com.nextcloud.client/" + googleplay="https://play.google.com/store/apps/details?id=com.nextcloud.client" + ios="https://itunes.apple.com/us/app/nextcloud/id1125420102" + github="https://github.com/nextcloud" %} diff --git a/_includes/sections/selfhosted-cloud.html b/_includes/sections/selfhosted-cloud.html index 79626244..fc4a0418 100644 --- a/_includes/sections/selfhosted-cloud.html +++ b/_includes/sections/selfhosted-cloud.html @@ -5,35 +5,36 @@ {% include cardv2.html -title="Nextcloud" -image="/assets/img/svg/3rd-party/nextcloud.svg" -description="Nextcloud is a suite of client-server software for creating your own file hosting services on a private server you control. Nextcloud is free and open-source, and supports end-to-end encryption with many of its clients. The only limits on storage and bandwidth are the limits on the server provider you choose." -website="https://nextcloud.com/" -forum="https://forum.privacytools.io/t/discussion-nextcloud/287" -windows="https://nextcloud.com/install/#install-clients" -mac="https://nextcloud.com/install/#install-clients" -linux="https://nextcloud.com/install/#install-clients" -freebsd="https://www.freshports.org/www/nextcloud/" -openbsd="http://openports.se/www/nextcloud" -netbsd="http://pkgsrc.se/www/php-nextcloud" -fdroid="https://f-droid.org/packages/com.nextcloud.client/" -googleplay="https://play.google.com/store/apps/details?id=com.nextcloud.client" -ios="https://itunes.apple.com/us/app/nextcloud/id1125420102?mt=8" -github="https://github.com/nextcloud" + title="Nextcloud" + image="/assets/img/svg/3rd-party/nextcloud.svg" + description="Nextcloud is a suite of free and open-source client-server software for creating your own file hosting services on a private server you control. The only limits on storage and bandwidth are the limits on the server provider you choose." + labels="warning:Experimental E2EE:Regarding E2EE their description states 'End-to-end encryption is still in alpha state, don't use this in production and only with test data!'." + website="https://nextcloud.com/" + forum="https://forum.privacytools.io/t/discussion-nextcloud/287" + windows="https://nextcloud.com/install/#install-clients" + mac="https://nextcloud.com/install/#install-clients" + linux="https://nextcloud.com/install/#install-clients" + freebsd="https://www.freshports.org/www/nextcloud/" + openbsd="http://openports.se/www/nextcloud" + netbsd="http://pkgsrc.se/www/php-nextcloud" + fdroid="https://f-droid.org/packages/com.nextcloud.client/" + googleplay="https://play.google.com/store/apps/details?id=com.nextcloud.client" + ios="https://itunes.apple.com/us/app/nextcloud/id1125420102" + github="https://github.com/nextcloud" %} {% include cardv2.html -title="Tahoe-LAFS" -image="/assets/img/svg/3rd-party/tahoe-lafs.svg" -image-dark="/assets/img/svg/3rd-party/tahoe-lafs-dark.svg" -website="https://www.tahoe-lafs.org/" -forum="https://forum.privacytools.io/t/discussion-tahoe-lafs/1662" -description="Tahoe-LAFS is a free and open decentralized cloud storage system. It distributes your data across multiple servers. Even if some of the servers fail or are taken over by an attacker, the entire file store continues to function correctly, preserving your privacy and security." -windows="https://github.com/tahoe-lafs/tahoe-lafs#via-pip" -mac="https://github.com/tahoe-lafs/tahoe-lafs#via-pip" -linux="https://github.com/tahoe-lafs/tahoe-lafs#using-os-packages" -netbsd="http://pkgsrc.se/filesystems/tahoe-lafs" -git="https://www.tahoe-lafs.org/trac/tahoe-lafs/browser" + title="Tahoe-LAFS" + image="/assets/img/svg/3rd-party/tahoe-lafs.svg" + image-dark="/assets/img/svg/3rd-party/tahoe-lafs-dark.svg" + website="https://www.tahoe-lafs.org/" + forum="https://forum.privacytools.io/t/discussion-tahoe-lafs/1662" + description="Tahoe-LAFS is a free and open decentralized cloud storage system. It distributes your data across multiple servers. Even if some of the servers fail or are taken over by an attacker, the entire file store continues to function correctly, preserving your privacy and security." + windows="https://github.com/tahoe-lafs/tahoe-lafs#via-pip" + mac="https://github.com/tahoe-lafs/tahoe-lafs#via-pip" + linux="https://github.com/tahoe-lafs/tahoe-lafs#using-os-packages" + netbsd="http://pkgsrc.se/filesystems/tahoe-lafs" + git="https://www.tahoe-lafs.org/trac/tahoe-lafs/browser" %}

    Worth Mentioning

    From a4c14b9efb2fe54b3cd735ce79eb0cb3256e314c Mon Sep 17 00:00:00 2001 From: Daniel Nathan Gray Date: Fri, 27 Mar 2020 04:07:17 +0000 Subject: [PATCH 05/42] Add 7zip, remove Peazip, Keka not FOSS (#1797) --- _includes/sections/file-encryption.html | 25 +++++++++++++------------ assets/img/svg/3rd-party/7zip.svg | 2 ++ assets/img/svg/3rd-party/peazip.svg | 2 -- 3 files changed, 15 insertions(+), 14 deletions(-) create mode 100644 assets/img/svg/3rd-party/7zip.svg delete mode 100644 assets/img/svg/3rd-party/peazip.svg diff --git a/_includes/sections/file-encryption.html b/_includes/sections/file-encryption.html index 2cec41a4..544f7b9e 100644 --- a/_includes/sections/file-encryption.html +++ b/_includes/sections/file-encryption.html @@ -38,17 +38,17 @@ {% include cardv2.html - title="PeaZip - File Archive Encryption" - image="/assets/img/svg/3rd-party/peazip.svg" - description="PeaZip is a free and open-source file manager and file archiver made by Giorgio Tani. It supports its native PEA archive format (featuring compression, multi volume split and flexible authenticated encryption and integrity check schemes) and other mainstream formats, with special focus on handling open formats. It also supports 180+ archive formats." - website="http://www.peazip.org" - forum="https://forum.privacytools.io/t/discussion-peazip-file-encryption/1534" - source="https://osdn.net/projects/peazip" - windows="https://www.peazip.org/peazip-64bit.html" - linux="https://www.peazip.org/peazip-linux.html" - freebsd="https://www.freshports.org/archivers/peazip/" - openbsd="https://www.peazip.org/peazip-bsd.html" - netbsd="https://www.peazip.org/peazip-bsd.html" + title="7 Zip" + image="/assets/img/svg/3rd-party/7zip.svg" + description='7-Zip is a free and open-source file archiver, a utility used to place groups of files within compressed containers. On Linux, MacOS etc. the command-line tool p7zip is used and integrates into various interfaces such as FileRoller, Xarchiver, Ark.' + website="https://7-zip.org" + forum="https://forum.privacytools.io/t/discussion-7-zip/3024" + source="https://sourceforge.net/projects/sevenzip/files/" + windows="https://7-zip.org/download.html" + linux="https://sourceforge.net/projects/p7zip/files" + freebsd="https://www.freshports.org/archivers/p7zip" + openbsd="https://sourceforge.net/projects/p7zip" + netbsd="https://sourceforge.net/projects/p7zip" %}

    Worth Mentioning

    @@ -57,5 +57,6 @@
  • Cryptomator - Free client-side AES encryption for your cloud files. Open source software: No backdoors, no registration.
  • Linux Unified Key Setup (LUKS) - A full disk encryption system for Linux using dm-crypt as the disk encryption backend. Included by default in Ubuntu. Available for Windows and Linux.
  • Hat.sh - A cross-platform, serverless JavaScript web application that provides secure file encryption using the AES-256-GCM algorithm in your browser. It can also be downloaded and run offline.
  • -
  • Keka - A macOS-only, open-source file archiver with the ability to encrypt files.
  • +
  • Keka - A macOS-only, file archiver with the ability to encrypt files. +
diff --git a/assets/img/svg/3rd-party/7zip.svg b/assets/img/svg/3rd-party/7zip.svg new file mode 100644 index 00000000..024ac0b9 --- /dev/null +++ b/assets/img/svg/3rd-party/7zip.svg @@ -0,0 +1,2 @@ + + diff --git a/assets/img/svg/3rd-party/peazip.svg b/assets/img/svg/3rd-party/peazip.svg deleted file mode 100644 index 4aca3733..00000000 --- a/assets/img/svg/3rd-party/peazip.svg +++ /dev/null @@ -1,2 +0,0 @@ - - From a5ec15d5e90c90688772b78bb0bac9f7a2d3bd26 Mon Sep 17 00:00:00 2001 From: szTheory Date: Fri, 27 Mar 2020 11:19:36 +0000 Subject: [PATCH 06/42] Added ExifCleaner to the Metadata Removal Tools section on the Productivity Tools page (#1802) * Added ExifCleaner to the Metadata Removal Tools section on the Productivity Tools page * ExifCleaner logo: Convert PNG to SVG with vectorizer.io and export as optimized SVG using Inkscape. * Remove redundent text * Mention ExifTool * Oops missing " * Replace svg with one that isn't retarded * Change canvas to 128x128 px Co-authored-by: Daniel Nathan Gray Co-authored-by: Dawid Potocki --- _includes/sections/productivity-tools.html | 15 +++++++++++++-- assets/img/svg/3rd-party/exifcleaner.svg | 2 ++ 2 files changed, 15 insertions(+), 2 deletions(-) create mode 100644 assets/img/svg/3rd-party/exifcleaner.svg diff --git a/_includes/sections/productivity-tools.html b/_includes/sections/productivity-tools.html index c189abc9..a3c5522d 100644 --- a/_includes/sections/productivity-tools.html +++ b/_includes/sections/productivity-tools.html @@ -65,7 +65,6 @@ Metadata Removal Tools -
{% include cardv2.html title="MAT2" @@ -81,4 +80,16 @@ openbsd="https://pypi.org/project/mat2/" netbsd="https://pypi.org/project/mat2/" %} -
+ +{% + include cardv2.html + title="ExifCleaner" + image="/assets/img/svg/3rd-party/exifcleaner.svg" + description='ExifCleaner is a freeware, open source graphical app that uses ExifTool to remove exif metadata from images, videos, and PDF documents using a simple drag and drop interface. It supports multi-core batch processing and dark mode.' + website="https://exifcleaner.com" + forum="https://forum.privacytools.io/t/discussion-mat/TODOADDTHIS" + github="https://github.com/szTheory/exifcleaner" + windows="https://github.com/szTheory/exifcleaner/releases" + mac="https://github.com/szTheory/exifcleaner/releases" + linux="https://github.com/szTheory/exifcleaner/releases" +%} diff --git a/assets/img/svg/3rd-party/exifcleaner.svg b/assets/img/svg/3rd-party/exifcleaner.svg new file mode 100644 index 00000000..4c0d59d5 --- /dev/null +++ b/assets/img/svg/3rd-party/exifcleaner.svg @@ -0,0 +1,2 @@ + + From acff7555194284e2d42fcf981439e3ab63221ce1 Mon Sep 17 00:00:00 2001 From: Mikaela Suomalainen Date: Fri, 27 Mar 2020 17:32:10 +0200 Subject: [PATCH 07/42] participate.html: mention the Matrix rooms / XMPP bridge (#1775) Resolves: #1674 --- _includes/sections/participate.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_includes/sections/participate.html b/_includes/sections/participate.html index dc5e936b..57ac6b4b 100644 --- a/_includes/sections/participate.html +++ b/_includes/sections/participate.html @@ -2,7 +2,7 @@

Participate with suggestions and constructive criticism

-

It's important for a website like {{ site.name }} to stay up-to-date. Keep an eye on software updates for the applications listed on our site. Follow recent news about providers that we recommend. We try our best to keep up, but we're not perfect and the internet is changing fast. If you find an error, or you think a provider should not be listed here, or a qualified service provider is missing, or a browser plugin is not the best choice anymore, or anything else... Talk to us please. You can also find us on Matrix at #general:privacytools.io. When using our services, users should follow our Code of Conduct.

+

It's important for a website like {{ site.name }} to stay up-to-date. Keep an eye on software updates for the applications listed on our site. Follow recent news about providers that we recommend. We try our best to keep up, but we're not perfect and the internet is changing fast. If you find an error, or you think a provider should not be listed here, or a qualified service provider is missing, or a browser plugin is not the best choice anymore, or anything else... Talk to us please. You can also find us on several Matrix rooms mainly #general:privacytools.io. XMPP users can join there through #general#privacytools.io@matrix.org. When using our services, users should follow our Code of Conduct.

From c4eadf3e7e7db2fe389db54c731a80c7d18f57c7 Mon Sep 17 00:00:00 2001 From: Mikaela Suomalainen Date: Fri, 27 Mar 2020 20:42:51 +0200 Subject: [PATCH 08/42] privacy-resources: delist The Great Cloudwall (#1804) --- _includes/sections/privacy-resources.html | 1 - 1 file changed, 1 deletion(-) diff --git a/_includes/sections/privacy-resources.html b/_includes/sections/privacy-resources.html index fc4009a6..c8ebe0d7 100644 --- a/_includes/sections/privacy-resources.html +++ b/_includes/sections/privacy-resources.html @@ -22,7 +22,6 @@
  • Security Now! - Weekly Internet Security Podcast by Steve Gibson and Leo Laporte.
  • TechSNAP - Weekly Systems, Network, and Administration Podcast. Every week TechSNAP covers the stories that impact those of us in the tech industry.
  • Terms of Service; Didn't Read - "I have read and agree to the Terms" is the biggest lie on the web. We aim to fix that.
  • -
  • The Great Cloudwall - Critique and information on why to avoid Cloudflare, a big company with a huge portion of the internet behind it.
  • Tools

    From b29b500781753041377ac2f65937abaa952f04a2 Mon Sep 17 00:00:00 2001 From: Daniel Nathan Gray Date: Thu, 2 Apr 2020 21:09:48 +0000 Subject: [PATCH 09/42] Fix Joplin GooglePlay link (#1812) --- _includes/sections/notebooks.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_includes/sections/notebooks.html b/_includes/sections/notebooks.html index e7dda0ef..d637f869 100644 --- a/_includes/sections/notebooks.html +++ b/_includes/sections/notebooks.html @@ -14,7 +14,7 @@ windows="https://joplinapp.org/#desktop-applications" mac="https://joplinapp.org/#desktop-applications" linux="https://joplinapp.org/#desktop-applications" freebsd="https://www.npmjs.com/package/joplin" -googleplay="https://joplinapp.org/images/BadgeAndroid.png" +googleplay="https://play.google.com/store/apps/details?id=net.cozic.joplin" android="https://joplinapp.org/#mobile-applications" ios="https://itunes.apple.com/us/app/joplin/id1315599797" firefox="https://addons.mozilla.org/en-US/firefox/addon/joplin-web-clipper/" From b84f5741cf0f82867c74bb06baa4d9b78c61eb74 Mon Sep 17 00:00:00 2001 From: Zenithium <48525551+Zenithium@users.noreply.github.com> Date: Sun, 5 Apr 2020 04:12:14 +0000 Subject: [PATCH 10/42] Remove Sparkleshare from File Sync (#1771) --- _includes/sections/file-sync.html | 12 ------------ 1 file changed, 12 deletions(-) diff --git a/_includes/sections/file-sync.html b/_includes/sections/file-sync.html index e8dabdff..bdf50f45 100644 --- a/_includes/sections/file-sync.html +++ b/_includes/sections/file-sync.html @@ -20,18 +20,6 @@ googleplay="https://play.google.com/store/apps/details?id=com.github.catfriend1.syncthingandroid" %} -{% - include cardv2.html - title="SparkleShare" - image="/assets/img/svg/3rd-party/sparkleshare.svg" - description="SparkleShare creates a special folder on your computer. You can add remotely hosted folders (or \"projects\") to this folder. These projects will be automatically kept in sync with both the host and all of your peers when someone adds, removes, or edits a file." - website="https://sparkleshare.org/" - forum="https://forum.privacytools.io/t/discussion-sparkleshare/1626" - github="https://github.com/hbons/SparkleShare" - linux="https://www.sparkleshare.org/" - mac="https://github.com/hbons/SparkleShare/releases/" -%} -

    Worth Mentioning

      From 78cc88397d7423fd1fab8615ae7e019938653050 Mon Sep 17 00:00:00 2001 From: Mikaela Suomalainen Date: Sun, 5 Apr 2020 15:19:54 +0300 Subject: [PATCH 11/42] VoIP warning: sort + mention Zoom (#1817) Co-authored-by: dngray --- _includes/sections/voice-video-messenger.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_includes/sections/voice-video-messenger.html b/_includes/sections/voice-video-messenger.html index 51db578a..50755ef7 100644 --- a/_includes/sections/voice-video-messenger.html +++ b/_includes/sections/voice-video-messenger.html @@ -1,7 +1,7 @@

      Video/Voice Calling

      {% include cardv2.html From 080edbfa3a482173013558a30482a309820cd151 Mon Sep 17 00:00:00 2001 From: Mikaela Suomalainen Date: Sun, 5 Apr 2020 15:20:19 +0300 Subject: [PATCH 12/42] VoIP: remove Google Analytics warning of Jitsi Meet (#1816) --- _includes/sections/voice-video-messenger.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_includes/sections/voice-video-messenger.html b/_includes/sections/voice-video-messenger.html index 50755ef7..0bef82ee 100644 --- a/_includes/sections/voice-video-messenger.html +++ b/_includes/sections/voice-video-messenger.html @@ -36,7 +36,7 @@ ios="https://apps.apple.com/us/app/mumble/id443472808?ls=1"

      Worth Mentioning

      Related Information

      From ff7cdbe8a1dcef81fe84bcc9545dda724910c9cf Mon Sep 17 00:00:00 2001 From: xelarate86 Date: Sat, 11 Apr 2020 22:03:45 -0400 Subject: [PATCH 13/42] Updated Mullvad VPN details with Play Store and App Store Links (#1824) --- _includes/sections/vpn.html | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/_includes/sections/vpn.html b/_includes/sections/vpn.html index 0defdacf..b1a3b28e 100644 --- a/_includes/sections/vpn.html +++ b/_includes/sections/vpn.html @@ -40,8 +40,8 @@

      Mullvad supports the future of networking IPv6. Their network allows users to access services hosted on IPv6 as opposed to other providers who block IPv6 connections.

      Remote Port Forwarding

      Remote port forwarding is allowed on Mullvad, see Port forwarding with Mullvad VPN.

      -
      No Mobile Clients
      -

      While iOS and Android clients are reportedly in the works, mobile users will need to use a traditional OpenVPN client and configuration files, which are a bit more difficult to configure.

      +
      Mobile Clients
      +

      Mullvad has published iOS and Android clients, both supporting an easy-to use interface as opposed to requiring users to manual configure their WireGuard connections.

      Extra Functionality

      The Mullvad VPN clients have a built-in killswitch to block internet connections outside of the VPN. They also are able to automatically start on boot. The Mullvad website is also accessible via Tor at xcln5hkbriyklr6n.onion.

    @@ -67,7 +67,7 @@
    Accepts Bitcoin

    ProtonVPN does technically accept Bitcoin payments; however, you either need to have an existing account, or contact their support team in advance to register with Bitcoin.

    Mobile Clients
    -

    In addition to providing standard OpenVPN configuration files, ProtonVPN has mobile clients for iOS or Android allowing for easy connections to their servers.

    +

    In addition to providing standard OpenVPN configuration files, ProtonVPN has mobile clients for iOS and Android allowing for easy connections to their servers.

    No Port Forwarding

    ProtonVPN does not currently support remote port forwarding, which may impact some applications. Especially Peer-to-Peer applications like Torrent clients.

    Extra Functionality
    @@ -99,7 +99,7 @@
    Remote Port Forwarding

    Remote port forwarding is possible with a Pro plan. Port forwarding can be activated via the client area. Port forwarding is only available on IVPN when using OpenVPN and is disabled on US servers.

    Mobile Clients
    -

    In addition to providing standard OpenVPN configuration files, IVPN has mobile clients for iOS or Android allowing for easy connections to their servers.

    +

    In addition to providing standard OpenVPN configuration files, IVPN has mobile clients for iOS and Android allowing for easy connections to their servers.

    Extra Functionality

    The IVPN clients have a built-in killswitch to block internet connections outside of the VPN. They also are able to automatically start on boot. IVPN also provides "AntiTracker" functionality, which blocks advertising networks and trackers from the network level.

    From 4eae9a7fb71d18c11199bd5842084db7f3756b01 Mon Sep 17 00:00:00 2001 From: Mikaela Suomalainen Date: Mon, 13 Apr 2020 05:18:59 +0300 Subject: [PATCH 14/42] assets: update signal.svg (#1826) --- assets/img/svg/3rd-party/signal.svg | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/assets/img/svg/3rd-party/signal.svg b/assets/img/svg/3rd-party/signal.svg index 69263c0a..d1f1ee56 100644 --- a/assets/img/svg/3rd-party/signal.svg +++ b/assets/img/svg/3rd-party/signal.svg @@ -1,2 +1,2 @@ - + From 49cfda170bc0069c3277ed24e11e6d093209900c Mon Sep 17 00:00:00 2001 From: Daniel Nathan Gray Date: Tue, 14 Apr 2020 01:36:07 +0000 Subject: [PATCH 15/42] Fixed pricing for ProtonVPN (#1829) --- _includes/sections/email-providers.html | 10 +++++----- _includes/sections/vpn.html | 11 ++++++----- 2 files changed, 11 insertions(+), 10 deletions(-) diff --git a/_includes/sections/email-providers.html b/_includes/sections/email-providers.html index 8d9a4984..09b292d6 100644 --- a/_includes/sections/email-providers.html +++ b/_includes/sections/email-providers.html @@ -19,7 +19,7 @@

    ProtonMail Free

    ProtonMail.com is an email service with a focus on privacy, encryption, security, and ease of use. They have been in operation since 2013. ProtonMail is based in Genève, Switzerland. Accounts start with 500 MB storage with their free plan.

    -

    Free accounts have some limitations and do not allow the use of the ProtonMail Bridge, which is required to use a recommended email client (e.g. Thunderbird) or to search email by body text. Paid accounts are available starting at €48/Year which include features like ProtonMail Bridge, additional storage, custom domain support, and more. The webmail and mobile apps can only search To:, From:, Date: and Subject: (this is likely to change when v4.0 of ProtonMail is released).

    +

    Free accounts have some limitations and do not allow the use of the ProtonMail Bridge, which is required to use a recommended email client (e.g. Thunderbird) or to search email by body text. Paid accounts are available starting at €48/y which include features like ProtonMail Bridge, additional storage, custom domain support, and more. The webmail and mobile apps can only search To:, From:, Date: and Subject: (this is likely to change when v4.0 of ProtonMail is released).

    Domains and Aliases

    Paid ProtonMail users can use their own domain with the service. Catch-all addresses are supported with custom domains for Professional and Visionary plans. ProtonMail also supports subaddressing, which is useful for users who don't want to purchase a domain.

    @@ -54,7 +54,7 @@ alt="Mailbox">
    -

    Mailbox.org €12/Year

    +

    Mailbox.org €12/y

    Mailbox.org is an email service with a focus on being secure, ad-free, and privately powered by 100% eco-friendly energy. They have been in operation since 2014. Mailbox.org is based in Berlin, Germany. Accounts start with 2 GB of storage, which can be upgraded as needed.

    Domains and Aliases
    @@ -91,7 +91,7 @@ alt="Posteo">
    -

    Posteo €12/Year

    +

    Posteo €12/y

    Posteo.de is an email provider that focuses on anonymous, secure, and private email. Their servers are powered by 100% sustainable energy. They have been in operation since 2009. Posteo is based in Germany and has a free 14-day trial. Posteo comes with 2 GB for the monthly cost and an extra gigabyte can be purchased for €0.25 per month.

    Domains and Aliases
    @@ -127,7 +127,7 @@ alt="Soverin">
    -

    Soverin €29/Year

    +

    Soverin €29/y

    Soverin.net is an email provider which focuses on being private, ad-free, and powered by sustainable energy. They have been in operation since 2015. Soverin is based in Amsterdam and does not have a free trial. Accounts start at 25 GB.

    Domains and Aliases
    @@ -229,7 +229,7 @@
    Extra Functionality

    Tutanota offers the business version of Tutanota to non-profit organizations for free or with a heavy discount.

    -

    Tutanota also has a business feature called Secure Connect. This ensures customer contact to the business uses E2EE. The feature costs €240/year.

    +

    Tutanota also has a business feature called Secure Connect. This ensures customer contact to the business uses E2EE. The feature costs €240/y.

    diff --git a/_includes/sections/vpn.html b/_includes/sections/vpn.html index b1a3b28e..fc831271 100644 --- a/_includes/sections/vpn.html +++ b/_includes/sections/vpn.html @@ -19,7 +19,7 @@

    Mullvad - EUR €60/Year + EUR €60/y

    Mullvad.net is a fast and inexpensive VPN with a serious focus on transparency and security. They have been in operation since 2009. Mullvad is based in Sweden and does not have a free trial.

    35 Countries
    @@ -54,9 +54,10 @@

    ProtonVPN Free - USD $96/year + Basic USD $48/y + Plus USD $96/y

    -

    ProtonVPN.com is a strong contender in the VPN space, and they have been in operation since 2016. ProtonVPN is based in Switzerland and offers a limited free pricing tier, as well as premium options.

    +

    ProtonVPN.com is a strong contender in the VPN space, and they have been in operation since 2016. ProtonVPN is based in Switzerland and offers a limited free pricing tier, as well as premium options. They offer a further 14% discount for buying a 2 year subscription.

    44 Countries

    ProtonVPN has servers in 44 countries at the time of writing this page. Picking a VPN provider with a server nearest to you will reduce latency of the network traffic you send. This is because of a shorter route (less hops) to the destination.

    We also think it's better for the security of the VPN provider's private keys if they use dedicated servers, instead of cheaper shared solutions (with other customers) such as virtual private servers.

    @@ -81,8 +82,8 @@

    IVPN - Standard USD $60/Year - Pro USD $100/Year + Standard USD $60/y + Pro USD $100/y

    IVPN.net is another premium VPN provider, and they have been in operation since 2009. IVPN is based in Gibraltar and offers a 3 day free trial.

    32 Countries
    From 94629b75f76d50065a77cd41d41f198066f26a69 Mon Sep 17 00:00:00 2001 From: Daniel Nathan Gray Date: Sun, 19 Apr 2020 05:51:34 +0000 Subject: [PATCH 16/42] Cleanup 2.0 instant messenger page (#1836) --- _includes/sections/instant-messenger.html | 226 ++++++++++---------- _includes/sections/teamchat.html | 20 +- assets/img/svg/3rd-party/bitmessage.svg | 2 - assets/img/svg/3rd-party/tox-dark.svg | 2 - assets/img/svg/3rd-party/tox.svg | 2 - pages/software/real-time-communication.html | 44 ++-- 6 files changed, 144 insertions(+), 152 deletions(-) delete mode 100644 assets/img/svg/3rd-party/bitmessage.svg delete mode 100644 assets/img/svg/3rd-party/tox-dark.svg delete mode 100644 assets/img/svg/3rd-party/tox.svg diff --git a/_includes/sections/instant-messenger.html b/_includes/sections/instant-messenger.html index 88779ff5..e33e9438 100644 --- a/_includes/sections/instant-messenger.html +++ b/_includes/sections/instant-messenger.html @@ -1,4 +1,7 @@ -

    Encrypted Instant Messengers

    +

    + + Encrypted Instant Messengers +

    @@ -9,42 +12,28 @@

    We have described the three main types of messaging programs that exist: Centralized, Federated and Peer-to-Peer (P2P), with the advantages and disadvantages of each.

    -

    Centralized

    +

    + + Centralized +

    Centralized messengers are those where every participant is on the same server or network of servers controlled by the same organization.

    -

    Advantages

    -
      -
    • New features and changes can be implemented more quickly.
    • -
    • Easier to get started with and to find contacts.
    • -
    - -

    Disadvantages

    - - {% - include cardv2.html - title="Signal" - image="/assets/img/svg/3rd-party/signal.svg" - description='Signal is a mobile app developed by Signal Messenger LLC. The app provides instant messaging, as well as voice and video calling. All communications are E2EE unless you choose to send as SMS. Its protocol has also been indepedently audited (PDF)' - labels="warning:Requires phone number:Signal requires your phone number as an personal identifier which means anyone you communicate with will see it.|success:VoIP" - website="https://signal.org/" - forum="https://forum.privacytools.io/t/discussion-signal/664" - github="https://github.com/signalapp" - windows="https://signal.org/download/" - mac="https://signal.org/download/" - linux="https://signal.org/download/" - googleplay="https://play.google.com/store/apps/details?id=org.thoughtcrime.securesms" - android="https://signal.org/android/apk/#apk-danger" - ios="https://apps.apple.com/app/signal-private-messenger/id874139669" + include cardv2.html + title="Signal" + image="/assets/img/svg/3rd-party/signal.svg" + description='Signal is a mobile app developed by Signal Messenger LLC. The app provides instant messaging, as well as voice and video calling. All communications are E2EE unless you choose to send as SMS. Its protocol has also been indepedently audited (PDF)' + labels="warning:Requires phone number:Signal requires your phone number as an personal identifier which means anyone you communicate with will see it.|success:VoIP" + website="https://signal.org/" + forum="https://forum.privacytools.io/t/discussion-signal/664" + github="https://github.com/signalapp" + windows="https://signal.org/download/" + mac="https://signal.org/download/" + linux="https://signal.org/download/" + googleplay="https://play.google.com/store/apps/details?id=org.thoughtcrime.securesms" + android="https://signal.org/android/apk/#apk-danger" + ios="https://apps.apple.com/app/signal-private-messenger/id874139669" %} {% @@ -67,37 +56,45 @@ chrome="https://chrome.google.com/webstore/detail/keybase-for-reddit/ognfafcpbkogffpmmdglhbjboeojlefj" %} -
    -

    Federated

    - -

    Federated messengers use multiple, independent servers that are able to talk to each other (email is one example of a federated service). Federation allows system administrators to control their own server and still be a part of the larger communications network.

    - +
    +
    +

    Advantages

      -
    • Allows for greater control over your own data when running your own server.
    • -
    • Allows you to choose who to trust your data with by choosing between multiple "public" servers.
    • -
    • Often allows for third party clients which can provide a more native, customized, or accessible experience.
    • -
    • Generally a less juicy target for governments wanting backdoor access to everything as the trust is decentralized. The server may be hosted independently from the organization developing the software.
    • -
    • Server software can be verified that it matches public source code, assuming you have access to the server or you trust the person who does (e.g., a family member)
    • -
    • Third-party developers can contribute code and add new features, instead of waiting for a private development team to do so.
    • +
    • New features and changes can be implemented more quickly.
    • +
    • Easier to get started with and to find contacts.
    - +
    +

    Disadvantages

      -
    • Adding new features is more complex, because these features need to be standardized and tested to ensure they work with all servers on the network.
    • -
    • Some metadata may be available (e.g., information like "who is talking to whom," but not actual message content if E2EE is used).
    • -
    • Federated servers generally require trusting your server's administrator. They may be a hobbyist or otherwise not a "security professional," and may not serve standard documents like a privacy policy or terms of service detailing how your data is utilized.
    • -
    • Server administrators sometimes choose to block other servers, which are a source of unmoderated abuse or break general rules of accepted behavior. This will hinder your ability to communicate with users on those servers.
    • +
    • Centralized services could be more susceptible to legislation requiring backdoor access.
    • +
    • Can include restricted control or access. This can include things like:
    • +
        +
      • Being forbidden from connecting third-party clients to the centralized network that might provide for greater customization or better user experience. Often defined in Terms and Conditions of usage.
      • +
      • Poor or no documentation for third-party developers.
      • +
      +
    • The ownership, privacy policy, and operations of the service can change easily when a single entity controls it, potentially compromising the service later on.
    +
    +
    +
    +

    + + Federated +

    + +

    Federated messengers use multiple, independent servers that are able to talk to each other (email is one example of a federated service). Federation allows system administrators to control their own server and still be a part of the larger communications network.

    + {% include cardv2.html - title="Matrix" - image="/assets/img/svg/3rd-party/matrix.svg" - image-dark="/assets/img/svg/3rd-party/matrix-dark.svg" - description='Matrix is an open-source project that publishes the Matrix open standard for secure, decentralized, real-time communication.
    - Riot.im is the popular reference client produced by the Matrix.org team. It offers optional E2EE for 1:1 and group conversations that must be turned on by the user. (This can be done by clicking on the toggle switch which is accessed by clicking the room name or user name of the chat → Security & Privacy → Encrypted). In the future it will be on by default.' + title="Riot" + image="/assets/img/svg/3rd-party/riotim.svg" + description='Riot.im is the reference client for the Matrix network. The Matrix open standard is an open-source standard for secure, decentralized, real-time communication.
    ' + labels="warning:Warning:Riot offers optional E2EE for 1:1 and group conversations that must be turned on by the user. + (This can be done by clicking on the toggle switch which is accessed by clicking the room name or user name of the chat → Security & Privacy → Encrypted).|success:VoIP" website="https://about.riot.im/" forum="https://forum.privacytools.io/t/discussion-riot-im/665/" github="https://github.com/vector-im/riot-web/" @@ -110,43 +107,45 @@ web="https://riot.im/app/" %} -
    -

    Worth Mentioning

    - -
      -
    • Other Matrix clients, that may however be less feature complete than Riot.im.
    • -
    • XMPP (Extensible Messaging and Presence Protocol) is an open-source communications protocol that began development in 1999. Since then, XMPP has been extended by the publishing of XEPs (XMPP Extension Protocols). OMEMO is the most popular XEP (XMPP extension) for E2EE. Clients are developed by the community and not by the XSF (XMPP Standards Foundation). Inconsistent E2EE
    • - -
    • Kontalk is a community-driven instant messaging network based on XMPP.
    • -
    - -

    Peer to Peer (P2P)

    - -

    Peer-to-Peer instant messengers connect directly to each other without requiring third-party servers. Clients (peers) usually find each other through the use of a distributed computing network. Examples of this include DHT (distributed hash table) (used with technologies like torrents and IPFS, for example), or Ethereum's Whisper protocol (used with some newer DApps). Another approach is proximity based networks, where a connection is established over WiFi or Bluetooth (for example, Briar or the Scuttlebutt social networking protocol). Once a peer has found a route to its contact via any of these methods, a direct connection between them is made.

    - - -

    Advantages

    -
      -
    • Minimal information is exposed to third parties.
    • -
    • Modern P2P platforms implement end-to-end encryption by default. There are no servers that could potentially intercept and decrypt your transmissions, unlike centralized and federated models.
    • -
    - -

    Disadvantages

    -
      -
    • Reduced feature set:
    • -
        -
      • Messages can only be sent when both peers are online, however, your client may store messages locally to wait for the contact to return online.
      • -
      • Generally increases battery usage on mobile devices, because the client must stay connected to the distributed network to learn about who is online.
      • -
      -
    • Your IP address and that of the contacts you're communicating with may be visible if you do not use the software in conjunction with a self contained network, such as Tor or I2P. Many countries have some form of mass surveillance and/or metadata retention.
    • -
    +
    +
    +
    +

    Advantages

    +
      +
    • Allows for greater control over your own data when running your own server.
    • +
    • Allows you to choose who to trust your data with by choosing between multiple "public" servers.
    • +
    • Often allows for third party clients which can provide a more native, customized, or accessible experience.
    • +
    • Generally a less juicy target for governments wanting backdoor access to everything as the trust is decentralized. The server may be hosted independently from the organization developing the software.
    • +
    • Server software can be verified that it matches public source code, assuming you have access to the server or you trust the person who does (e.g., a family member)
    • +
    • Third-party developers can contribute code and add new features, instead of waiting for a private development team to do so.
    • +
    +
    +
    +

    Disadvantages

    +
      +
    • Adding new features is more complex, because these features need to be standardized and tested to ensure they work with all servers on the network.
    • +
    • Some metadata may be available (e.g., information like "who is talking to whom," but not actual message content if E2EE is used).
    • +
    • Federated servers generally require trusting your server's administrator. They may be a hobbyist or otherwise not a "security professional," and may not serve standard documents like a privacy policy or terms of service detailing how your data is utilized.
    • +
    • Server administrators sometimes choose to block other servers, which are a source of unmoderated abuse or break general rules of accepted behavior. This will hinder your ability to communicate with users on those servers.
    • +
    +
    +
    +
    +

    Worth Mentioning

    + + + +

    + + Peer to Peer (P2P) +

    + +

    Peer-to-Peer instant messengers connect directly to each other without requiring third-party servers. Clients (peers) usually find each other through the use of a distributed computing network. Examples of this include DHT (distributed hash table) (used with technologies like torrents and IPFS, for example). Another approach is proximity based networks, where a connection is established over WiFi or Bluetooth (for example, Briar or the Scuttlebutt social networking protocol). Once a peer has found a route to its contact via any of these methods, a direct connection between them is made.

    + {% include cardv2.html title="Briar" @@ -176,30 +175,25 @@ ios="https://itunes.apple.com/app/ring-a-gnu-package/id1306951055?mt=8" %} -{% - include cardv2.html - title="Tox" - image="/assets/img/svg/3rd-party/tox.svg" - image-dark="/assets/img/svg/3rd-party/tox-dark.svg" - description='Encrypted instant messaging and video calling software. Uses its own encryption protocol that has not yet been officially audited by cryptographers.' - labels="warning:Experimental:Encryption has not been audited by professional cryptographers|success:VoIP" - website="https://tox.chat" - forum="https://forum.privacytools.io/t/discussion-tox/2115" - windows="https://tox.chat/download.html#oses" - mac="https://tox.chat/download.html#oses" - linux="https://tox.chat/download.html#oses" - freebsd="https://tox.chat/download.html#oses" - openbsd="http://openports.se/search.php?so=tox" - netbsd="http://pkgsrc.se/search.php?so=tox" - fdroid="https://tox.chat/download.html#oses" - googleplay="https://tox.chat/download.html#oses" - ios="https://tox.chat/download.html#oses" -%} - -

    Worth Mentioning

    - -
      -
    • Status.im - Encrypted instant messenger with an integrated Ethereum wallet (cryptocurrency) that also includes support for DApps (decentralized apps) (web apps in a curated store). Uses the Whisper protocol for P2P communication. Experimental
    • -
    • Retroshare - Encrypted instant messaging and voice/video call client. RetroShare supports both Tor and I2P.
    • -
    • Bitmessage is a decentralized, encrypted, peer-to-peer, trustless communications protocol that can be used by one person to send encrypted messages to another person, or to multiple subscribers.
    • -
    +
    +
    +
    +

    Advantages

    +
      +
    • Minimal information is exposed to third parties.
    • +
    • Modern P2P platforms implement end-to-end encryption by default. There are no servers that could potentially intercept and decrypt your transmissions, unlike centralized and federated models.
    • +
    +
    +
    +

    Disadvantages

    +
      +
    • Reduced feature set:
    • +
        +
      • Messages can only be sent when both peers are online, however, your client may store messages locally to wait for the contact to return online.
      • +
      • Generally increases battery usage on mobile devices, because the client must stay connected to the distributed network to learn about who is online.
      • +
      +
    • Your IP address and that of the contacts you're communicating with may be visible if you do not use the software in conjunction with a self contained network, such as Tor or I2P. Many countries have some form of mass surveillance and/or metadata retention.
    • +
    +
    +
    +
    diff --git a/_includes/sections/teamchat.html b/_includes/sections/teamchat.html index 21cd9064..6df7e9d0 100644 --- a/_includes/sections/teamchat.html +++ b/_includes/sections/teamchat.html @@ -1,16 +1,20 @@ -

    Team Chat Platforms

    +

    + + + Team Chat Platforms +

    {% include cardv2.html - title="Matrix" - image="/assets/img/svg/3rd-party/matrix.svg" - image-dark="/assets/img/svg/3rd-party/matrix-dark.svg" - description='Matrix is an open-source project that publishes the Matrix open standard for secure, decentralized, real-time communication.
    - Riot.im is the popular reference client produced by the Matrix.org team. It offers optional E2EE for 1:1 and group conversations that must be turned on by the user. (This can be done by clicking on the toggle switch which is accessed by clicking the room name or user name of the chat → Security & Privacy → Encrypted). In the future it will be on by default.' + title="Riot" + image="/assets/img/svg/3rd-party/riotim.svg" + description='Riot.im is the reference client for the Matrix network. The Matrix open standard is an open-source standard for secure, decentralized, real-time communication.
    ' + labels="warning:Warning:Riot offers optional E2EE for 1:1 and group conversations that must be turned on by the user. + (This can be done by clicking on the toggle switch which is accessed by clicking the room name or user name of the chat → Security & Privacy → Encrypted).|success:VoIP" website="https://about.riot.im/" forum="https://forum.privacytools.io/t/discussion-riot-im/665/" github="https://github.com/vector-im/riot-web/" @@ -28,7 +32,7 @@ title="Rocket.chat" image="/assets/img/svg/3rd-party/rocketchat.svg" description="Rocket.chat is an self-hostable open source platform for team communication. It has optional federation and experimental E2EE." - labels="warning:Experimental E2EE:Regarding E2EE their documentation states 'This feature is currently in alpha. It's also not yet supported on mobile'. There is no forward secrecy so compromised decryption password would leak all messages. Federation was also added afterwards, potentially causing room for mistakes." + labels="warning:Experimental E2EE:Regarding E2EE their documentation states 'This feature is currently in alpha. It's also not yet supported on mobile'. There is no forward secrecy so compromised decryption password would leak all messages. Federation was also added afterwards, potentially causing room for mistakes.|success:VoIP" website="https://rocket.chat/" forum="https://forum.privacytools.io/t/discussion-rocket-chat/1223" github="https://github.com/rocketchat/" diff --git a/assets/img/svg/3rd-party/bitmessage.svg b/assets/img/svg/3rd-party/bitmessage.svg deleted file mode 100644 index b4dd6814..00000000 --- a/assets/img/svg/3rd-party/bitmessage.svg +++ /dev/null @@ -1,2 +0,0 @@ - - diff --git a/assets/img/svg/3rd-party/tox-dark.svg b/assets/img/svg/3rd-party/tox-dark.svg deleted file mode 100644 index 13f26fe2..00000000 --- a/assets/img/svg/3rd-party/tox-dark.svg +++ /dev/null @@ -1,2 +0,0 @@ - - diff --git a/assets/img/svg/3rd-party/tox.svg b/assets/img/svg/3rd-party/tox.svg deleted file mode 100644 index 18433b42..00000000 --- a/assets/img/svg/3rd-party/tox.svg +++ /dev/null @@ -1,2 +0,0 @@ - - diff --git a/pages/software/real-time-communication.html b/pages/software/real-time-communication.html index 180e45fe..e06237d7 100644 --- a/pages/software/real-time-communication.html +++ b/pages/software/real-time-communication.html @@ -8,73 +8,73 @@ description: "Discover secure and private ways to communicate with others online {% include sections/instant-messenger.html %}

    - - + + - Recent news about breaking E2EE on centralized instant messengers + Recent news about breaking E2EE on centralized instant messengers

    March 2020
    January 2020
    November 2019
    October 2019
    August 2019
    July 2019
    May 2019
    January 2019
    December 2018

    Complete Comparison

    Independent security audits


    From f1878a80eb1c1cd42d071440f7e1cdb1c3d11b75 Mon Sep 17 00:00:00 2001 From: Daniel Nathan Gray Date: Sun, 19 Apr 2020 05:53:43 +0000 Subject: [PATCH 17/42] Re-add StartMail (#1830) --- _includes/sections/email-providers.html | 40 ++++++++++++++++++++- assets/img/svg/3rd-party/startmail-dark.svg | 2 +- assets/img/svg/3rd-party/startmail.svg | 2 +- 3 files changed, 41 insertions(+), 3 deletions(-) diff --git a/_includes/sections/email-providers.html b/_includes/sections/email-providers.html index 09b292d6..d0d5f2c8 100644 --- a/_includes/sections/email-providers.html +++ b/_includes/sections/email-providers.html @@ -104,7 +104,7 @@

    Posteo supports two factor authentication for their webmail only. You can use either TOTP a Yubikey with TOTP. Web standards such as U2F and WebAuthn are not yet supported.

    Data Security
    -

    Posteo has zero access encryption for email storage. This means the messages stored in your account are only readable by you.

    +

    Posteo has zero access encryption for email storage. This means the messages stored in your account are only readable by you.

    Posteo also supports the encryption of your address book contacts and calendars at rest. However, Posteo still uses standard CalDAV and CardDAV for calendars and contacts. These protocols do not support E2EE (End-To-End Encryption). A standalone option may be more appropiate.

    Email Encryption
    @@ -232,4 +232,42 @@

    Tutanota also has a business feature called Secure Connect. This ensures customer contact to the business uses E2EE. The feature costs €240/y.

    +
    +
    + StartMail +
    +
    +

    StartMail Personal USD $59.95/y

    +

    StartMail.com is an email service with a focus on security and privacy through the use of standard OpenPGP encryption. StartMail has been in operation since 2014 and is based in Boulevard 11, Zeist Netherlands. Accounts start with 10GB. They offer a 30-day trial.

    + +
    Domains and Aliases
    +

    Personal accounts can use Custom or Generated aliases. Business accounts can use Domain aliases.

    + +
    Payment Methods
    +

    StartMail accepts Visa, MasterCard, American Express and Paypal. StartMail also has other payment options such as Bitcoin (currently only for Personal accounts) and SEPA Direct Debit for accounts older than a year.

    + +
    Account Security
    +

    StartMail supports TOTP two factor authentication for webmail only. They do not allow U2F security key authentication.

    + +
    Data Security
    +

    StartMail has zero access encryption at rest, using their "user vault" system. When a user logs in, the vault is opened, and the email is then moved to the vault out of the queue where it is decrypted by the corresponding private key.

    + +

    StartMail supports importing contacts however, they are only accessible in the webmail and not through protocols such as CalDAV. Contacts are also not stored using zero knowledge encryption, so a standalone option may be more appropriate.

    + +
    Email Encryption
    +

    StartMail has integrated encryption in their webmail, which simplifies sending messages to users with public OpenPGP keys.

    + +
    .onion Service
    +

    StartMail does not operate a .onion service.

    + +
    Extra Functionality
    +

    StartMail allows for proxying of images within emails. If a user allows the remote image to be loaded, the sender won't know what the user's IP address is.

    +
    +
    diff --git a/assets/img/svg/3rd-party/startmail-dark.svg b/assets/img/svg/3rd-party/startmail-dark.svg index 73d2b18c..7d8d46dd 100644 --- a/assets/img/svg/3rd-party/startmail-dark.svg +++ b/assets/img/svg/3rd-party/startmail-dark.svg @@ -1,2 +1,2 @@ - + diff --git a/assets/img/svg/3rd-party/startmail.svg b/assets/img/svg/3rd-party/startmail.svg index eb7afde7..ef3edb86 100644 --- a/assets/img/svg/3rd-party/startmail.svg +++ b/assets/img/svg/3rd-party/startmail.svg @@ -1,2 +1,2 @@ - + From 4c601a07f7c96c531e75414b5c8be086ac4dcee5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sun, 19 Apr 2020 11:04:39 -0700 Subject: [PATCH 18/42] Bump nokogiri from 1.10.4 to 1.10.8 (#1737) Bumps [nokogiri](https://github.com/sparklemotion/nokogiri) from 1.10.4 to 1.10.8. - [Release notes](https://github.com/sparklemotion/nokogiri/releases) - [Changelog](https://github.com/sparklemotion/nokogiri/blob/master/CHANGELOG.md) - [Commits](https://github.com/sparklemotion/nokogiri/compare/v1.10.4...v1.10.8) Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index a6b97838..2dce18a7 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -205,7 +205,7 @@ GEM jekyll-seo-tag (~> 2.1) minitest (5.11.3) multipart-post (2.1.1) - nokogiri (1.10.4) + nokogiri (1.10.8) mini_portile2 (~> 2.4.0) octokit (4.14.0) sawyer (~> 0.8.0, >= 0.5.3) From a1ab2d2daab2c38d82d733aa863e031aabeb2e4c Mon Sep 17 00:00:00 2001 From: Jonah Aragon Date: Mon, 20 Apr 2020 18:38:19 -0500 Subject: [PATCH 19/42] Site Cleanup (#1840) --- .gitignore | 2 + _includes/footer.html | 3 +- _includes/head.html | 2 +- _includes/team.html | 11 +++-- assets/img/png/team/dawid.png | Bin 27233 -> 0 bytes assets/img/png/team/mikaela.png | Bin 106229 -> 0 bytes assets/img/svg/team/dawid.svg | 2 + pages/about.html | 70 +++++++++++++++++++------------- pages/services.html | 6 +++ 9 files changed, 60 insertions(+), 36 deletions(-) delete mode 100644 assets/img/png/team/dawid.png delete mode 100644 assets/img/png/team/mikaela.png create mode 100644 assets/img/svg/team/dawid.svg diff --git a/.gitignore b/.gitignore index e6cb179f..bb836e13 100644 --- a/.gitignore +++ b/.gitignore @@ -6,3 +6,5 @@ font/assets/ font/_sass/ font/.fontcustom-manifest.json assets/webfonts/ptio-font-preview.html +vendor +.bundle diff --git a/_includes/footer.html b/_includes/footer.html index 3baff154..aebf3140 100644 --- a/_includes/footer.html +++ b/_includes/footer.html @@ -89,7 +89,8 @@ Privacy Statement | Notices & Disclaimers | - Brand Assets & Guidelines + Brand Assets & Guidelines | + Status Page
    diff --git a/_includes/head.html b/_includes/head.html index c072a19d..8595b009 100644 --- a/_includes/head.html +++ b/_includes/head.html @@ -22,7 +22,7 @@ - {% if page.url == "/" or page.url == "/about/" %} + {% if page.url == "/" %}