<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Focus Determines Reality</title>
    <link rel="self" type="application/atom+xml" href="https://yawnbox.eu/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://yawnbox.eu"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2026-07-13T00:00:00+00:00</updated>
    <id>https://yawnbox.eu/atom.xml</id>
    <entry xml:lang="en">
        <title>Analysis: United States v. Peter Stokes, Microsoft Windows surveillance via GDID</title>
        <published>2026-07-13T00:00:00+00:00</published>
        <updated>2026-07-13T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/microsoft-gdid-surveillance/"/>
        <id>https://yawnbox.eu/blog/microsoft-gdid-surveillance/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/microsoft-gdid-surveillance/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;This blog post is my technical threat-risk analysis of &lt;a rel=&quot;external&quot; href=&quot;https://www.justice.gov/usao-ndil/media/1450651/dl?inline&quot;&gt;the court document&lt;/a&gt; (PDF) concerning United States v. Peter Stokes, Case No. 25 CR 812. I am publishing a draft version of my analysis for initial feedback. Feedback and criticism is highly welcomed. I will make updates as I find additional facts and evidence. Unlike the majority of related, public research since the publication of this court document, I did not use generative AI to do this work. News articles and claimed &quot;research&quot; about this topic contain blatant, thoughtless misinformation.&lt;/p&gt;
&lt;p&gt;This personal analysis should be read in the context of global dragnet surveillance impacting people, lawyers, journalists, human rights defenders, companies, and governments who use Microsoft (NSA) Windows 10 and Windows 11 systems. Not network- or internet-level surveillance, but local, on-device surveillace. It should be understood in the context of &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/PRISM&quot;&gt;PRISM-like programs by NSA/FVEY&lt;/a&gt; whereby the Snowden revelations made very clear that Micrososft and the NSA work together to conduct global surveillance.&lt;/p&gt;
&lt;p&gt;Throughout this article, I refer to Microsoft as NSA. This is intentional to remind readers the factual relationships that Microsoft has with federal cops. When FBI needs help from Microsoft, Microsoft gives help. NSA is no different, except NSA investigations don&#39;t go through public court.&lt;/p&gt;
&lt;h1 id=&quot;tl-dr&quot;&gt;TL;DR&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Microsoft (NSA) conducts dragnet surveillance on all Windows 10 and Windows 11 systems worldwide by default.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Microsoft&#39;s (NSA&#39;s) dragnet surveillance tracks Edge browser identifiers and Global Device Identifiers.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Microsoft&#39;s (NSA&#39;s) dragnet surveillance somehow captures full URL data even when a device uses a VPN, which is likely exfiltrated from everyone&#39;s &quot;personal computer&quot; via malicious software called Edge browser and Defender SmartScreen.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;global-device-identifier-gdid-impacting-windows-10-and-11&quot;&gt;Global Device Identifier (GDID) impacting Windows 10 and 11&lt;/h1&gt;
&lt;p&gt;The court document makes clear several facts:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;According to a Microsoft representative, a Global Device Identifier in the Windows ecosystem is a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;A GDID is a globally unique identifier tied to the installation of Windows on a device.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Tied to a Windows installation, so not exclusive to installs that sign in with a Microsoft account. This also means Xbox.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;A GDID remains consistent across Windows operating system updates on a device, but a reinstall of Windows, either on the same device or on a different device, will be tied to a new unique GDID.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If a user signs into a Microsoft account, or uses the same VPN or IP addresses, Microsoft (NSA) can more easily tie GDIDs together to a specific person. Microsoft (NSA) then also can more easily coorelate users of specific personal systems, business systems or government systems.&lt;/p&gt;
&lt;p&gt;Microsoft documentation makes clear several other, related facts:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/ucdostatus&quot;&gt;GlobalDeviceId&lt;/a&gt; is defined as &quot;Microsoft global device identifier. This is a identifier used by Microsoft internally.&quot;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://learn.microsoft.com/en-us/windows/deployment/update/wufb-reports-schema-ucclientreadinessstatus&quot;&gt;UCClientReadinessStatus&lt;/a&gt; includes the GDID, confirming that the GDID been around since Windows 10.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;There are several &lt;a rel=&quot;external&quot; href=&quot;https://learn.microsoft.com/en-us/windows/privacy/required-diagnostic-events-fields-windows-11-24h2&quot;&gt;required diagnostic events fields&lt;/a&gt; that indicate (isVpn) &quot;Is the device connected to a Virtual Private Network?&quot;, but Microsoft does not disclose surveillance of VPN traffic in their legal/privacy statements.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This expands current, fact-based knowledge of the capabilities of Microsoft (NSA) being able to tie specific users of Windows systems together simply via IP -- since at least Windows 10, Microsoft (NSA) links people to a precise Windows system, its patch level (Windows Update &quot;diagnostics&quot;), and all system configurations (required &quot;diagnostics&quot; including &quot;opt-in&quot; (selected yes by default) &quot;diagnostics&quot;).&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Cybersecurity researchers at Microsoft, through the course of their job, have access to data, such as computer machine IDs, IP addresses, and malware samples associated with sophisticated cybergroups. The researchers’ function is to identify groups of hackers who appear to operate as a team/cohesive unit (i.e., an Advanced Persistent Threat or APT group).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This paragraph strongly influences the judge of this case, and us, the public, that Microsoft researchers just happen to have collected this data from passive collection techniques -- Windows diagnostic data. If this is true, then this should be broadly understood as, &quot;Cybersecurity researchers at Microsoft, through the course of their job, have access to data, such as computer machine IDs, IP addresses, and malware samples for all Windows 10 and Windows 11 users&quot; because Microsoft (NSA) collects &quot;diagnostic data&quot; first, then perform analysis on that data. Or, Microsoft and the FBI are lying to a judge about the source of this evidence.&lt;/p&gt;
&lt;h1 id=&quot;vpn-traffic-surveillance&quot;&gt;VPN traffic surveillance&lt;/h1&gt;
&lt;p&gt;Jumping back to the court document, there are three possibly alarming statements read together:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;According to Microsoft records, the ngrok account was set up through Global Device Identifier g:6755467234350028 (“the GDID”).&quot; and &quot;According to Microsoft records, [...] the device with the GDID accessed, among other ngrok pages, “https://dashboard.ngrok.com/signup,” the ngrok page to set up an ngrok account.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Microsoft records also indicate: (1) the user of the device assigned the GDID accessed multiple sites from Tzulo servers in May 2025, including the .168 server (the IP address used to create the ngrok account) on May 12, 2025; and (2) the user of the device assigned the GDID, [...] a little more than three hours after the ngrok account was created, the user visited “[Company F].com” from the .168 proxy server.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;According to Tzulo records, that server is in Mount Prospect, Illinois, and that IP address is assigned to a VPN proxy service.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This indicates Microsoft (NSA) exfiltrates (from your Windows device) the destinations of VPN traffic from Windows 10 and 11 devices. The full URL and time/date metadata.&lt;/p&gt;
&lt;p&gt;Given the above conclusions about data-linkability, Microsoft knows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;When you use a VPN from any Windows 10 or Windows 11 system.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The originating, real IPs, including LAN and WAN IPs.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The VPN egress IP, and which internet endpoints and/or URLs are visited via the VPN tunnel.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Including NSA. This level of detail is via local system logs, not internet-based global passive adversary logs.&lt;/p&gt;
&lt;h1 id=&quot;assumptions-and-questions&quot;&gt;Assumptions and Questions&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;At first read, it sounded like there was a possibility that Stokes&#39; web browssing resulted in Microsoft (NSA) obtaining full URLs of sites visited because, possibly, Stokes was using Microsoft Edge, which was not disclosed in this document. However, if full URLs are obtained by Microsoft surveillance via third-party VPN tunnels, then one can assume that Microsoft can extract this level of data irrespective of the web browser. This causes serious alarm because, depending on how Windows provides Microsoft this data, Tor Browser may be compromised due to use of Windows 10 and Windows 11. It&#39;s critical to understand what Windows sub-component collects full URL data to understand the full scope of risk.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The phrase &quot;globally unique identifier&quot; was stated by the Microsoft (NSA) representative and exists in vastly more Microsoft documentation than &quot;Global Device Identifier&quot;. Further, other documentation appears to state &quot;global device ID&quot;, but it is not clear if this also is the GDID. If yes, then a &lt;a rel=&quot;external&quot; href=&quot;https://learn.microsoft.com/en-us/troubleshoot/windows-client/installing-updates-features-roles/windows-update-issues-troubleshooting&quot;&gt;Windows Update troubelshooting document&lt;/a&gt; also states: &quot;Microsoft Account Sign In Assistant (MSA or wlidsvc) is the service in question. The DCAT Flighting service [...] relies on MSA to get the global device ID for the device. Without the MSA service running, the global device ID won&#39;t be generated and sent by the client and the search for feature updates never completes successfully.&quot; That mechnism could only be for Windows Update, however.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Does Microsoft (NSA) track this granularity before or after FBI issues a legal order? This &quot;passive&quot; (according to Microsoft and FBI (casual access to data)) collection was of an American citizen and also an Estonian (EU/GDPR) citizen. Based on the statements in the court document, Microsoft (NSA) may have been investigating hacks performed by Stokes&#39; colleagues beforehand. It&#39;s not clear what specific legal authority Microsoft (NSA) had in collecting Stokes&#39; Windows device data. Or, worse, is Microsoft (NSA) collecting full URLs of all HTTP traffic of every Windows 10 and Windows 11 device on the planet, by default?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;What is not clear is the scope. If all of this data that Microsoft (NSA) used is solely based on &quot;required diagnositc data&quot;, then this level of surveillance is dragnet surveillance, and no Windows 10 or Windows 11 system is secure or private. If Microsoft blended &quot;required diagnostic data&quot; with additional, targeted collection via valid legal authoirty, it&#39;s also safe to assume that Microsoft can reach into our Windows 10 and Windows 11 devices at any time to collect this data.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Depending on the scope of &quot;required diagnostic data&quot;, this may affect Microsoft (NSA) enterprise customers. Is this global data collection of diagnostic data tied to the legal agreements between Microsoft and third-party companies? In other words, is full URL (with and without a VPN) traffic data by enterprise users collected regardless of any assumed, contractual legal agreement?&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;probable-hypothetical&quot;&gt;Probable hypothetical&lt;/h1&gt;
&lt;p&gt;What Microsoft (NSA) Windows application or sub-component has visibility into full URL and records a timestamp that is exfiltrated by Microsoft (NSA)? Microsoft (NSA) documentation points to Edge browser. Edge handles full URLs, and if Edge was used while using a VPN, then it means Microsoft (NSA) gets full URL and metadata even when a VPN is enabled. The terrifying issue is that this is the default for Windows 10 and 11, worldwide.&lt;/p&gt;
&lt;p&gt;From &lt;a rel=&quot;external&quot; href=&quot;https://support.microsoft.com/en-US/edge/microsoft-edge-browsing-data-and-privacy&quot;&gt;Microsoft Edge, browsing data, and privacy&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Microsoft Edge also has features to help you and your content stay safe online. Windows Defender SmartScreen automatically blocks websites and content downloads that are reported to be malicious. Windows Defender SmartScreen checks the address of the webpage you&#39;re visiting against a list of webpage addresses stored on your device that Microsoft believes to be legitimate. Addresses that aren&#39;t on your device&#39;s list and the addresses of files you&#39;re downloading will be sent to Microsoft and checked against a frequently updated list of webpages and downloads that have been reported to Microsoft as unsafe or suspicious.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;From &lt;a rel=&quot;external&quot; href=&quot;https://learn.microsoft.com/en-us/legal/microsoft-edge/privacy&quot;&gt;User data and privacy in Microsoft Edge&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The following information is sent to your default search provider [Bing / Microsoft / NSA]:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A list of Address bar entries, categorized as a URL, search, or unknown.&lt;/li&gt;
&lt;li&gt;Which suggestion you select.&lt;/li&gt;
&lt;li&gt;The position of the selection.&lt;/li&gt;
&lt;li&gt;Other Address bar data.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;If your search provider is Bing [Microsoft / NSA], a resettable identifier that&#39;s unique to your browser is sent with the data. This helps Bing [Microsoft  / NSA] understand the search query and query session. Other autosuggest service identifiers are sent to your default search engine [Bing / Microsoft / NSA], to complete the search suggestions. Your IP address and cookies are sent to your default search provider [Bing / Microsoft / NSA], to increase the relevance of the search results.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;When you select the Address bar, a signal is sent to your default search provider [Bing / Microsoft / NSA]. The signal tells the provider [Bing / Microsoft / NSA] to prepare suggestions. The typed characters and search queries aren&#39;t sent to Microsoft unless your search provider is Bing [Microsoft / NSA].&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Reading the court document, Stokes had absolutely terrible opsec. There&#39;s a high probability he was using Windows 11 defaults with Edge. So Microsoft security researchers likely:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Had an ongoing investigation into Scattered Spider / Octo Tempest.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Was given IP addresses associated with Stokes to reverse engineer with other Microsoft dragnet surveillance data.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Found relavent data in Edge / Bing surveillance data in the Microsoft (NSA) exfiltrated dataset made up of everyone worldwide and found the &quot;unique to your browser&quot; identifier.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Cross referenced the Edge ID with GDIDs, and Edge ID IPs and GDID IPs with Snapchat, etc.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Or some combination of those events. VPNs don&#39;t keep you safe and neither does Microsoft (NSA) Windows.&lt;/p&gt;
&lt;h1 id=&quot;from-the-court-document&quot;&gt;From the court document&lt;/h1&gt;
&lt;p&gt;Below are the relavent sections pertaining to Microsoft data based on &lt;a rel=&quot;external&quot; href=&quot;https://www.justice.gov/usao-ndil/media/1450651/dl?inline&quot;&gt;the court document&lt;/a&gt; (PDF).&lt;/p&gt;
&lt;h2 id=&quot;page-7&quot;&gt;Page 7&lt;/h2&gt;
&lt;h3 id=&quot;section-7&quot;&gt;Section 7&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;As set forth below, criminal referrals from Microsoft, provider records, records from previous victim-company intrusions, and records from Subject Server 1 show that STOKES has engaged in the Subject Offenses. In addition, and more specifically, STOKES and likely other coconspirators breached Company F, a luxury-jewelry retailer, exfiltrated data from Company F, and made a ransom demand of approximately $8 million in cryptocurrency, between on or about May 12 and on or about May 15, 2025. More specifically, according to records from providers, STOKES opened an account with a provider of a secure-tunneling, data-transfer tool used to access and exfiltrate data from Company F’s computer network. STOKES created this account from a Virtual Private Network (VPN) proxy service IP address ending in .168. A Microsoft device identifier (a Global Device ID, or GDID, described below) associated with STOKES is linked to the .168 address.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;page-9&quot;&gt;Page 9&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Cybersecurity researchers at Microsoft, through the course of their job, have access to data, such as computer machine IDs, IP addresses, and malware samples associated with sophisticated cybergroups. The researchers’ function is to identify groups of hackers who appear to operate as a team/cohesive unit (i.e., an Advanced Persistent Threat or APT group).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;note-1&quot;&gt;Note 1&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Cybersecurity researchers at Microsoft, through the course of their job, have access to data, such as computer machine IDs, IP addresses, and malware samples associated with sophisticated cybergroups. The researchers’ function is to identify groups of hackers who appear to operate as a team/cohesive unit (i.e., an Advanced Persistent Threat or APT group). The researchers do this by identifying malicious activity (malware attacks, spear-phishing, etc.) conducted against innocent victims, and then identify the computers used to conduct the attacks. The researchers then identify colleagues of the hacker by finding other computers also accessed from the same IP addresses used by the initially identified hacker. This process enables the source’s organization to identify unique groups of hackers and then track those groups to determine new IP addresses the hackers are observed connecting to the Internet from, such as leased server IPs. This also allows the researchers to determine whether these IP addresses are being used to target victims. Microsoft’s referrals and reports related to computer intrusions—such as the report about Subject Server 1—have been reliable. In fact, multiple, similar referrals from Microsoft in this and related investigations have been corroborated by later legal process issued by the government.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;page-14&quot;&gt;Page 14&lt;/h2&gt;
&lt;h3 id=&quot;section-14&quot;&gt;Section 14&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;On or December 22, 2025, the Court signed a search warrant for a storage device containing downloads from a Virtual Private Server ending in .191 (“Subject Server 1”), which Microsoft had identified as a facility used to further the Subject Offenses.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;note-9&quot;&gt;Note 9&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;More specifically, on or about June 23, 2025, Chief Judge Virginia M. Kendall signed a reverse 18 U.S.C. § 2703(d) order for two Tallin, Estonia IP addresses believed to have been used by STOKES, based on Microsoft records. See 25 M 60220. Such an order required Microsoft, among other providers, to search for all accounts that may have used those Tallin IP addresses and provide associated IP addresses for the accounts that did. Microsoft returns from that order show additional IP addresses that were accessed by the underlying, true IP addresses, indicating STOKES’s use of them.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;page-20&quot;&gt;Page 20&lt;/h2&gt;
&lt;h3 id=&quot;note-10&quot;&gt;Note 10&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;According to Company H’s referral, the Bouquet account included two images, which, according to Company H, were purportedly of STOKES, which I have compared to STOKES’s State Department passport photograph; they do not appear to be the same individual. In addition, however, the “Bouquet” account posted an image in or about January 2023, apparently of homework, with the name “Peter William Stokes” written in the top, right-hand corner. According to a referral provided by Microsoft on October 29, 2024, Microsoft analysts assessed the email address jordanspencer@riseup.net was used by STOKES. Also, as noted above, Coconspirator A confirmed to the FBI that STOKES used the moniker Bouquet.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;page-30&quot;&gt;Page 30&lt;/h2&gt;
&lt;h3 id=&quot;section-25&quot;&gt;Section 25&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;According to Microsoft records, the ngrok account was set up through Global Device Identifier g:6755467234350028 (“the GDID”). According to a Microsoft representative, a Global Device Identifier in the Windows ecosystem is a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios. A GDID is a globally unique identifier tied to the installation of Windows on a device. A GDID remains consistent across Windows operating system updates on a device, but a reinstall of Windows, either on the same device or on a different device, will be tied to a new unique GDID.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;section-26&quot;&gt;Section 26&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;According to Microsoft records, on or about May 12, 2025, at 19:21 UTC—when, according to ngrok records, the ngrok account was created—the device with the GDID accessed, among other ngrok pages, “https://dashboard.ngrok.com/signup,” the ngrok page to set up an ngrok account.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;section-27&quot;&gt;Section 27&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Microsoft records also indicate: (1) the user of the device assigned the GDID accessed multiple sites from Tzulo servers in May 2025, including the .168 server (the IP address used to create the ngrok account) on May 12, 2025; and (2) the 23 Thus, one Microsoft user could have multiple GDIDs. user of the device assigned the GDID, on May 12, 2025 at 22:47 UTC, a little more than three hours after the ngrok account was created, the user visited “[Company F].com” from the .168 proxy server.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;page-31&quot;&gt;Page 31&lt;/h2&gt;
&lt;h3 id=&quot;section-28a&quot;&gt;Section 28a&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;On June 4, 2024, at 2:01 PM UTC, the device with the GDID used the IP address 91.129.97.29, geolocated to Tallinn, Estonia, where STOKES lived. On the same date, this IP address was also used to access the Subject Facebook Account at 3:21 PM UTC and the Subject Snapchat Account at 1:57 PM UTC.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;section-28b&quot;&gt;Section 28b&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;On November 18, 2024, at 7:31 AM UTC, the device with the GDID used the IP address 207.237.190.238, geolocated to New York, New York. On the same date, this IP address was also used to access Subject Apple Account 1 at 8:34 AM UTC and the Subject Snapchat Account at 3:22 PM UTC. The device with the GDID also used this IP address on November 17, 2024 at 9:21 PM UTC. According to State Department travel records, STOKES travelled to New York, New York from November 15, 2024, and November 18, 2024. Images from the Subject Snapchat Account confirm STOKES was in New York in November 2024, including between approximately November 16 and 18, 2024. These images include ones taken from the Four Seasons Hotel New York and Waldorf Astoria New York, as well as images taken from a UFC fight that occurred in New York on November 16, 2024.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;section-28c&quot;&gt;Section 28c&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;On November 26, 2024, the device with the GDID visited the URL empirehotelnyc.com. This is the website for a hotel named &quot;Empire Hotel&quot;, located in New York, New York. According to State Department travel records, STOKES travelled from Frankfurt, Germany to New York, New York, on November 23, 2024, and returned to Frankfurt, Germany on November 29, 2024. On or about November 25, 2024, STOKES sent the image below via his Subject Snapchat Account. According to Empire Hotel New York’s public website, the carpet, wallpaper, and furniture match an Empire Hotel suite, as depicted below.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;section-28d&quot;&gt;Section 28d&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;On February 2, 2025, at 2:37 PM UTC, the device with the GDID used the IP address 110.170.208.226, geolocated to Thailand. On the same date, this IP address was also used to access the Subject Snapchat Account at 7:21 PM UTC and the Subject Apple Account 1 at 9:28 AM UTC and Subject Apple Account 2 at 1:30 PM UTC. The device with the GDID also used this IP address on January 31, 2025, at 12:45 PM UTC. Confirming that STOKES was in Thailand around this time, on or about January 31, 2025, he sent an image holding a “WALDORF ASTORIA BANGKOK” water bottle; on or about February 1, 2025, he posted an image of himself captioned “WALDORF ASTORIA BANGKOK.”&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;page-33&quot;&gt;Page 33&lt;/h2&gt;
&lt;h3 id=&quot;section-29&quot;&gt;Section 29&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;On January 8, 2025, the device with the GDID used the IP address 213.35.168.5024, geolocated to Tallinn, Estonia, where STOKES lived, to visit the 24 According to public IP records, this IP address is assigned to “Telia Eesti AS” a major  URL https://login.growtopiagame.com/player/login/dashboard?valKey=40db4045f2d8c572efe8c4a060605726. Based on my training and experience, this indicates the user logged into an online account for the game Growtopia.25 According to records from Ubisoft, this login accessed a Ubisoft account with the account identifier ACC03E1B-D54F-4EC5-BA63-68276DFF16AD (the &quot;Ubisoft account&quot;). On January 7, 2025, the same IP address (IP Address 213.35.168.50) was used to access Subject Apple Account 2 at 5:17 AM UTC and the Ubisoft account two minutes later, at 5:19 AM UTC. Also, the same IP address was used to access the Subject Snapchat Account, the Subject Facebook Account, and the Subject Apple Accounts on several dates from May 31, 2024, through July 16, 2025.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;page-34&quot;&gt;Page 34&lt;/h2&gt;
&lt;h3 id=&quot;section-30&quot;&gt;Section 30&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Therefore, based on my training and experience, and overlapping use of the same IP addresses by accounts and devices used by STOKES, I believe that the user of the GDID (who, as discussed above, set up the ngrok account used in the Company F intrusion) is the same person as the user of the Subject Accounts (STOKES). In addition, as explained above, the Subject Google Account was used to set up the ngrok account used in the Subject Offenses and the Subject Google Account was also used to set up the 2742 phone number’s account and the Teleport.sh accounts used in the attack. Based on my training and experience, this indicates that STOKES also operated the Subject Google Account used in the Subject Offenses.&lt;/p&gt;
&lt;/blockquote&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>How to Use an iPad as a Secure Calling and Messaging Device</title>
        <published>2026-07-02T00:00:00+00:00</published>
        <updated>2026-07-02T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/how-to-use-an-ipad-as-a-secure-calling-and-messaging-device/"/>
        <id>https://yawnbox.eu/blog/how-to-use-an-ipad-as-a-secure-calling-and-messaging-device/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/how-to-use-an-ipad-as-a-secure-calling-and-messaging-device/">&lt;p&gt;&lt;img src=&quot;/images/20150922-ipod-signal.jpg&quot; alt=&quot;Alt Text: An Apple iPod from 2015 showing a new Signal message&quot; /&gt;
&lt;em&gt;Back in September 2015, I took this photo of my Apple iPod showing a new Signal message.&lt;/em&gt;&lt;/p&gt;
&lt;h1 id=&quot;related-work&quot;&gt;Related Work&lt;/h1&gt;
&lt;p&gt;You may like my highly related article, &quot;&lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/how-to-use-an-pixel-tablet-as-a-secure-calling-and-messaging-device/&quot;&gt;How to Use a Pixel Tablet as a Secure Calling and Messaging Device&lt;/a&gt;&quot;.&lt;/p&gt;
&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;This is a human-made and peer-reviewed article.&lt;/p&gt;
&lt;p&gt;This guide is aimed at providing a detailed method for maximizing security and privacy on an Apple iPad (non-cellular). This guide should be adapted to fit your threat model, including using this guide on cellular iPads that support iPadOS 26 or iPhones that support iOS 26. While this guide aims to provide a high level of operational security, I am not &lt;em&gt;your&lt;/em&gt; security engineer. If you&#39;d like to hire me to talk about your threat model, please email me.&lt;/p&gt;
&lt;p&gt;Legacy phone calling and texting (SMS, MMS) are &lt;a rel=&quot;external&quot; href=&quot;https://ssd.eff.org/playlist/privacy-breakdown-of-mobile-phones&quot;&gt;inherently insecure&lt;/a&gt;. Communications content and metadata is collected and stored by various organizations and for many years. All people, but especially those in at-risk professions, have a responsibility to safeguard their communications with strong encryption technologies because only then will your coworkers, friends, and family be able to collectively defend your rights. In professions where privacy is expected between you and clients like in law and journalism, policy should dictate to either communicate securely or not at all.&lt;/p&gt;
&lt;p&gt;Encryption technology is not new but default strong encryption in mass-market devices is. The political cost of default privacy and security is at an all-time low while the social expectations of strong encryption are at an all-time high. Modern telecommunications largely depend on legacy and vulnerable communications infrastructure, which is by design:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All cell phones (baseband processor) transmit insecure content and metadata because cell networks were designed for connectivity and surveillance of said connectivity.&lt;/li&gt;
&lt;li&gt;All cell phones (baseband processor) not broken, off, or in Airplane Mode can be easily tracked.&lt;/li&gt;
&lt;li&gt;The majority of SIM cards require registration using government-issued ID.&lt;/li&gt;
&lt;li&gt;Most Androids get slowly patched, if at all.&lt;/li&gt;
&lt;li&gt;Carrier modified versions of Android are poorly developed and maintained.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;“Nobody is listening to your telephone calls”&lt;/strong&gt; –President Obama, 2013&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;President Obama was not &lt;em&gt;lying&lt;/em&gt; when he said this. It is not possible for the US government to &quot;listen&quot; to every phone call. However, the technical requirements for recording phone calls (&lt;a rel=&quot;external&quot; href=&quot;https://www.washingtonpost.com/world/national-security/nsa-surveillance-program-reaches-into-the-past-to-retrieve-replay-phone-calls/2014/03/18/226d2646-ade9-11e3-a49e-76adc9210f19_story.html&quot;&gt;MYSTIC&lt;/a&gt;, &lt;a rel=&quot;external&quot; href=&quot;https://theintercept.com/2015/02/19/great-sim-heist/&quot;&gt;DAPINO GAMMA&lt;/a&gt;) and text messages (&lt;a rel=&quot;external&quot; href=&quot;https://www.theguardian.com/world/2014/jan/16/nsa-collects-millions-text-messages-daily-untargeted-global-sweep&quot;&gt;DISHFIRE&lt;/a&gt;) is more than feasible. It is cheaper and more effective to transcribe voice data to text, transcriptions that can be stored forever. The solution is easy: don’t give it to them.&lt;/p&gt;
&lt;p&gt;What is bad for U.S. Intelligence, &lt;a rel=&quot;external&quot; href=&quot;https://archive.ph/8CSB4&quot;&gt;China&lt;/a&gt;, or enemies of the &lt;a rel=&quot;external&quot; href=&quot;https://archive.ph/LDvRl&quot;&gt;Netherlands&lt;/a&gt; is also bad for all other malicious actors. It is up to us to cause the social change that in turn lowers the personal costs of default privacy and security and the financial risk of businesses to support what we need.&lt;/p&gt;
&lt;p&gt;The financial cost of surveillance equipment is also at an all-time low. Mobile IMSI catchers can be built and deployed by anyone technically savvy enough to learn how to build one, and law enforcement has large budgets for more feature rich devices. The most effective way to assure that you are not a victim of cell tracking or attack is to not use those systems.&lt;/p&gt;
&lt;h2 id=&quot;not-the-ipod-anymore&quot;&gt;Not the iPod anymore&lt;/h2&gt;
&lt;p&gt;Due to a massive lapse in judgement by Apple to put the &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Apple_A10&quot;&gt;A10 Fusion chip&lt;/a&gt; from 2016 in the 2019 iPod Touch, no version of iPod Touch is secure. Also, as of 2022, the iPod has been discontinued.&lt;/p&gt;
&lt;h1 id=&quot;the-apple-ipad&quot;&gt;The Apple iPad&lt;/h1&gt;
&lt;p&gt;The iPad fills a much needed space:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Wi-Fi only&lt;/strong&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The new &lt;strong&gt;Apple M5 SoC&lt;/strong&gt; with Enhanced Memory Tagging Extension (EMTE, hardware) and Memory Integrity Enforcement (MIE, software).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Wired headsets&lt;/strong&gt; for audio/video calls using a USB-C adapter.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://apps.apple.com/us/app/signal-private-messenger/id874139669&quot;&gt;&lt;strong&gt;Signal&lt;/strong&gt;&lt;/a&gt; which now has robust quantum resistance. See &lt;a rel=&quot;external&quot; href=&quot;https://signal.org/blog/pqxdh/&quot;&gt;Quantum Resistance and the Signal Protocol&lt;/a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https://signal.org/blog/spqr/&quot;&gt; Signal Protocol and Post-Quantum Ratchets&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;iPadOS 26&lt;/strong&gt; as of writing in June 2026.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;advised-ipads&quot;&gt;Advised iPads&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Ranked&lt;/strong&gt;, as of June 2026, in order of security then cost:&lt;/p&gt;
&lt;h3 id=&quot;most-secure&quot;&gt;Most secure&lt;/h3&gt;
&lt;p&gt;Apple&#39;s hardware-backed, synchonous memory tagging exploit mitigation technology is finally here! Read about Apple&#39;s new &lt;a rel=&quot;external&quot; href=&quot;https://security.apple.com/blog/memory-integrity-enforcement/&quot;&gt;EMTE and MIE&lt;/a&gt; that objectively reduces the effectiveness of local and remote exploitation attack chains. Apple also &lt;a rel=&quot;external&quot; href=&quot;https://www.youtube.com/watch?v=iYUMr3Y9fAU&quot;&gt;published a Youtube video&lt;/a&gt; about the importance of apps implementing EMTE/MIE also. As of June 2026, Signal has not stated that they support EMTE/MIE yet.&lt;/p&gt;
&lt;p&gt;If you are in the market for buying an iPad, get an M5 with EMTE/MIE.&lt;/p&gt;
&lt;p&gt;The M5 and M4 iPad Pros have a new hardware feature called &lt;a rel=&quot;external&quot; href=&quot;https://lifehacker.com/tech/m4-ipad-pro-hidden-security-feature&quot;&gt;Secure Indicator Light&lt;/a&gt; (SIL). A security researcher &lt;a rel=&quot;external&quot; href=&quot;https://mastodon.social/@_inside/112552696723119626&quot;&gt;writes&lt;/a&gt;: &quot;When using the microphone or camera, the corresponding indicator dot is effectively rendered in hardware (using the display), making it a lot less likely that any malware or user space app would be able to access those sensors without the user’s knowledge.&quot; There are two main scenarios where SIL is clearly valuable:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;When a user is installing random, untrustworthy apps. If you are going to follow all of the advice in this article and only use your iPad for Signal, the SIL feature is less valuable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If you are a potential target of mercenary spyware, and if it is possible that your adversary could know your Signal number or Signal username, they may attempt to exploit your Signal app itself, making the SIL feature critical in this scenario. It&#39;s important that Signal implement EMTE/MIE into their app as soon as possible because if the underlying device is exceptionally secure with EMTE/MIE, then the remotely-addressable app could become the easiest target.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The M5 iPad Pro is also the first version of the iPad to use Apple&#39;s own N1 wireless chipset. For the cellular version, it&#39;s also the first version to use the C1X baseband. Both of these Apple chipsets offer security enhancements over prior chipsets.&lt;/p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th style=&quot;text-align: right&quot;&gt;Rank&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Chipset&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Model&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Release Year&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Reference&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;1&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M5&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Pro 11-inch&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2025&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/125406&quot;&gt;125406&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;2&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M5&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Pro 13-inch&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2025&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/125407&quot;&gt;125407&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br&gt;
&lt;h3 id=&quot;reasonably-secure&quot;&gt;Reasonably secure&lt;/h3&gt;
&lt;p&gt;Everyting before M5 does not support EMTE and MIE. Only the M5 and M4 support SIL. However, A15 to A17 Pro, and M2 to M4 do use the more modern Secure Page Table Monitor (SPTM) + Trusted Execution Monitor (TXM) that replaces Apple&#39;s older Page Protection Layer (PPL). These security technologies are described below.&lt;/p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th style=&quot;text-align: right&quot;&gt;Rank&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Chipset&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Model&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Release Year&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Reference&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;3&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M4&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Pro 11-inch&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2024&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/119892&quot;&gt;119892&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;4&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M4&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Pro 13-inch&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2024&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/119891&quot;&gt;119891&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;5&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;A17 Pro&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Mini&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2024&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/121456&quot;&gt;121456&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;6&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M3&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Air 11-inch&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2025&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/122241&quot;&gt;122241&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;7&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M3&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Air 13-inch&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2025&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/122242&quot;&gt;122242&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;8&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;A16&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad (11th gen, 2025)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2025&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/122240&quot;&gt;122240&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;9&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M2&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Air 11-inch&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2024&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/119894&quot;&gt;119894&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;10&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M2&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Air 13-inch&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2024&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/119893&quot;&gt;119893&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;11&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M2&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Pro 11-inch (4th gen)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2022&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/kb/SP882&quot;&gt;SP882&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;12&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M2&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Pro 12.9-inch (6th gen)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2022&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/kb/SP883&quot;&gt;SP883&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;13&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;A15&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Mini (6th gen)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2021&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/kb/SP850&quot;&gt;SP850&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br&gt;
&lt;p&gt;Notes on the &lt;strong&gt;A18 chipset&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;As of June 2026, there is no A18 iPad.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;iPhone 16e, with its A18, has better SPTM/TXM exploit mitigations compared the M4 and before. If exploit mitigation is more important to you than avoiding the use of a baseband, A18, A19, and M5 are better choices, but A18 does not support EMTE.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;br&gt;
&lt;h3 id=&quot;questionably-secure&quot;&gt;Questionably secure&lt;/h3&gt;
&lt;p&gt;The A14 and M1 chipsets utilize Apple&#39;s older PPL featue. I advise people with any of these models to start planning an upgrade. I advise this, in part, because of the release of the M5 iPad Pro with EMTE/MIE, which is a huge leap in exploit mitigation and overall platform security, and worth your money.&lt;/p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th style=&quot;text-align: right&quot;&gt;Rank&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Chipset&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Model&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Release Year&lt;/th&gt;&lt;th style=&quot;text-align: left&quot;&gt;Reference&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;14&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M1&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Air (5th gen)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2022&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/kb/SP866&quot;&gt;SP866&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;15&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M1&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Pro 11-inch (3rd gen)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2021&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/kb/SP843&quot;&gt;SP843&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;16&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;M1&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Pro 12.9-inch (5th gen)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2021&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/kb/SP844&quot;&gt;SP844&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;15&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;A14&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad (10th gen)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2022&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/kb/SP884&quot;&gt;SP884&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: right&quot;&gt;16&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;A14&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;iPad Air 10.9” (4th gen)&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;2020&lt;/td&gt;&lt;td style=&quot;text-align: left&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/kb/SP828&quot;&gt;SP828&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;Eight iPads have been removed from the &quot;questionably secure&quot; table as of June 2026 due to an unpatchable bootloader vulnerability and exploit &lt;a rel=&quot;external&quot; href=&quot;https://ps.tc/pages/blog-usbliter8.html&quot;&gt;made public&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Generally speaking, the newer the chip --in generation, not year of sale-- the longer that Apple will likely support it with security patches. Do not use a device no longer getting the latest version iPadOS. Validate the latest iPadOS is supported &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/guide/ipad/supported-models-ipad213a25b2/&quot;&gt;here&lt;/a&gt;. See if I&#39;ve missed any newer models &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/108043&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;why-is-the-a12-or-greater-chip-so-important&quot;&gt;Why is the A12 (or greater) chip so important?&lt;/h2&gt;
&lt;p&gt;Prior to the A12 chipset, Apple devices did not have the following critical technologies, making them vulnerable to easy-to-perform physical and remote exploits:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/guide/security/operating-system-integrity-sec8b776536b/web&quot;&gt;Page Protection Layer (PPL)&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Page Protection Layer (PPL) in [iPadOS] is designed to prevent user space code from being modified after code signature verification is complete. Building on Kernel Integrity Protection and Fast Permission Restrictions, PPL manages the page table permission overrides to make sure only the PPL can alter protected pages containing user code and page tables. The system provides a massive reduction in attack surface by supporting systemwide code integrity enforcement, even in the face of a compromised kernel. This protection isn’t offered in macOS because PPL is only applicable on systems where all executed code must be signed.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol start=&quot;2&quot;&gt;
&lt;li&gt;&lt;strong&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/guide/security/operating-system-integrity-sec8b776536b/web&quot;&gt;Secure Page Table Monitor (SPTM) and Trusted Execution Monitor (TXM)&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Secure Page Table Monitor (SPTM) and Trusted Execution Monitor (TXM) on [iPadOS] are designed to work together to help protect page tables for both user and kernel processes against modification, even when attackers have kernel write capabilities and can bypass control flow protections. SPTM does this by utilizing a higher privilege level than the kernel, and utilizing the lower privileged TXM to actually enforce the policies that govern code execution. This system is designed so that a TXM compromise doesn’t automatically translate to an SPTM bypass due to this privilege separation and the governing of trust between them. In the A15 or later and M2 or later SOCs, SPTM (in combination with TXM) replaces the PPL, providing a smaller attack surface that doesn’t rely on trust of the kernel, even during early boot. SPTM relies on new silicon primitives that are an evolution of the Fast Permission Restrictions that PPL utilizes, and are available only on the processors listed in the table above.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol start=&quot;3&quot;&gt;
&lt;li&gt;&lt;strong&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/guide/security/operating-system-integrity-sec8b776536b/web&quot;&gt;Pointer Authentication Codes (PAC)&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Pointer Authentication Codes (PACs) are used to protect against exploitation of memory corruption bugs. System software and built-in apps use PAC to help prevent modification of function pointers and return addresses (code pointers).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;See more in Apple&#39;s high-level breakdown of &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/guide/security/apple-soc-security-sec87716a080/web&quot;&gt;SoC Security&lt;/a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/guide/security/operating-system-integrity-sec8b776536b/web&quot;&gt;Operating system integrity&lt;/a&gt;. For more details, see Apple&#39;s &lt;a rel=&quot;external&quot; href=&quot;https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf&quot;&gt;Pratform Security Guide (version 5)&lt;/a&gt; (PDF), updated December 2024. All of the technical details of these low-level technologies are out of scope from this publication, but there are many resources to learn about them:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Black Hat 2016 &lt;a rel=&quot;external&quot; href=&quot;https://www.youtube.com/watch?v=BLGFriOKz6U&quot;&gt;Behind the Scenes of iOS Security&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;BlueHat IL 2019 &lt;a rel=&quot;external&quot; href=&quot;https://www.youtube.com/watch?v=_YAmsAwSEHA&quot;&gt;Life as an iOS Attacker&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;BSides Canberra 2019 &lt;a rel=&quot;external&quot; href=&quot;https://www.youtube.com/watch?v=31azOpD7DmI&quot;&gt;What&#39;s in a Jailbreak? Hacking the iPhone: 2014 - 2019&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;37C3 &lt;a rel=&quot;external&quot; href=&quot;https://media.ccc.de/v/37c3-12168-predator_files_how_european_spyware_threatens_civil_society_around_the_world&quot;&gt;Predator Files: How European spyware threatens civil society around the world&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;38C3 &lt;a rel=&quot;external&quot; href=&quot;https://media.ccc.de/v/38c3-from-pegasus-to-predator-the-evolution-of-commercial-spyware-on-ios&quot;&gt;From Pegasus to Predator - The evolution of Commercial Spyware on iOS&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://arxiv.org/abs/2510.09272&quot;&gt;Modern iOS Security Features -- A Deep Dive into SPTM, TXM, and Exclaves&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.youtube.com/live/ch1l45uKcAs?si=9Uk-3jZPVAjIQVvS&amp;amp;t=2760&quot;&gt;What&#39;s at the Bottom of the C1 Baseband?&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;why-not-use-a-phone-in-airplane-mode-why-does-it-need-to-be-a-wi-fi-only-device&quot;&gt;Why not use a phone in Airplane Mode? Why does it need to be a Wi-Fi-only device?&lt;/h1&gt;
&lt;p&gt;Threats related to modern basebands also include Low Earth Orbit satellites. Please read my new article, &lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/threat-modeling-starlink-satellite-cellular-risks/&quot;&gt;Threat modeling Starlink satellite cellular risks&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Modern cellular iPads (and iPhones) contain baseband firmware as part of iPadOS instead of on a dedicated flash chip inside baseband (&quot;flashless&quot; baseband). In the case of the M5 iPad Pro cellular version, this means the C1X chip. At boot, the A-series or M-series SoC loads a signed baseband image into the baseband’s RAM (iPadOS won&#39;t load the image if it is unsigned), the baseband verifies it with its own secureboot chain, and then the radio stack runs. In other words, modern Apple basebands do not carry its own OS. iPadOS (cellular) hands baseband a signed binary at every boot. This happens about one second before the user sees the Before First Unlock (BFU) lock screen. If Airplane Mode is enabled at the time of BFU, the baseband binary is not loaded.&lt;/p&gt;
&lt;p&gt;That being said, iPadOS software patches from Apple very often or always, after the device reboot, disables Airplane Mode. &lt;strong&gt;This means that, with a cellular iPad (or iPhone), it must be presumed that the device will always disclose IMEI data, and in effect, disclose physical location metadata to cell towers after their iPad software patch is applied.&lt;/strong&gt; Worse, if a SIM card or eSIM is activated and used in such a device, that means disclosure of your IMSI&#39;s physical location to anyone with an IMSI catcher within proximity, disclosure to any agency working with your cellular carrier, and disclosure to anyone capable of abusing the SS7 network.&lt;/p&gt;
&lt;p&gt;I presume that Apple does this for its own security considerations; having routine check-ins to Apple allows Apple, and allows mainstream Apple users, the ability track devices in more situations.&lt;/p&gt;
&lt;p&gt;Even without a SIM card, baseband can and does connect to cell towers, including the disclosure of the device&#39;s IMEI along with &quot;when&quot; and &quot;where&quot; metadata &lt;a rel=&quot;external&quot; href=&quot;https://www.fcc.gov/document/rosenworcel-shares-mobile-carrier-responses-data-privacy-probe&quot;&gt;read more here&lt;/a&gt;. This is how a SIM-less phone can call emergency phone services (112 in the EU, or 911 in the US). It&#39;s impossible to avoid cellular data disclosure without resorting to Faraday cages.&lt;/p&gt;
&lt;h1 id=&quot;apple-the-national-security-agency-and-data-link-ability&quot;&gt;Apple, the National Security Agency, and Data Link-Ability&lt;/h1&gt;
&lt;p&gt;Apple is an American company that works with the NSA and is part of the &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/PRISM_(surveillance_program)&quot;&gt;PRISM program&lt;/a&gt;. If you are, or ever could be a target of U.S. intelligence or U.S. military organizations, you are already playing difficult game by choosing an Apple product. However, you probably aren&#39;t defending against the NSA. Not all adversaries are the NSA, nor do they have the budgets and reach as the NSA. Risk minimization should not always be compared to NSA-style actors. Care about your threat model, not someone else&#39;s.&lt;/p&gt;
&lt;p&gt;Just turning on an Apple product, the device is working against you by collecting all WiFi and Bluetooth network information around you to attempt to &quot;streamline&quot; a user&#39;s setup experience. Some of that data is uploaded to Apple&#39;s servers as soon as the device is connected to the internet. Every Apple device uploads its unique hardware identifiers to Apple, along with surrounding network metadata that can disclose physical location information to Apple, and thus to US government agencies and other FVEY entities.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Your device&#39;s hardware identifiers.&lt;/li&gt;
&lt;li&gt;Your public IP address used to connect to *.apple.com services.&lt;/li&gt;
&lt;li&gt;All other information that you input into the device for device setup and account sign-in, which are both required in order to access the Apple Store.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;From Apple&#39;s &lt;a rel=&quot;external&quot; href=&quot;https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf&quot;&gt;Legal Process Guidelines - Government &amp;amp; Law Enforcement within the United States&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;When a customer activates an iOS device with a cellular service provider or upgrades the software, certain information is provided to Apple from the service provider or from the device, depending on the event. IP addresses of the event, ICCID numbers, and other device identifiers may be available. IP address information may be limited to the most recent 18 months. This information, if available, may be obtained with a subpoena or greater legal process.&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;If Apple, or any of the U.S. intelligence or military organizations, have any other data that links anything about you to the this Apple device, your identity can be tracked by these organizations.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Your credit card or debit card used to make the purchase.&lt;/li&gt;
&lt;li&gt;Your physical address for device delivery.&lt;/li&gt;
&lt;li&gt;Your car license plate seen by Automatic License Plate Readers (ALPR) going to pick up the device.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;apple-push-notification-service-apns&quot;&gt;Apple Push Notification Service (APNS)&lt;/h2&gt;
&lt;p&gt;When you&#39;re using Signal on iPadOS, this requires use of &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Apple_Push_Notification_service&quot;&gt;APNS&lt;/a&gt;. This means that Apple has a metadata record of when, where, and what service you&#39;re using. NSA/FVEY &lt;a rel=&quot;external&quot; href=&quot;https://techcrunch.com/2023/12/06/us-senator-warns-governments-spying-apple-google-smartphone-users-via-push-notifications/&quot;&gt;is spying on and storing this data&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://mastodon.world/@Mer__edith/111563866152334347&quot;&gt;Per&lt;/a&gt; Meredith Whittaker, Signal&#39;s President, &quot;In Signal, push notifications simply act as a ping that tells the app to wake up. They don&#39;t reveal who sent the message or who is calling (not to Apple, Google, or anyone). Notifications are processed entirely on your device.&quot;&lt;/p&gt;
&lt;p&gt;That &quot;ping&quot; is more than just a ping, and requires Apple to have a lot of data about the target service and the target device. Apple is able to see, and thus FVEY is able to make a permanent record of:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;APN identifiers, such as hardware identifiers, of who is receiving a message.&lt;/li&gt;
&lt;li&gt;The messaging application; in this case, Signal.&lt;/li&gt;
&lt;li&gt;The date and time associated with received messages.&lt;/li&gt;
&lt;li&gt;Any network metadata, such as IP, associated with receiving messages.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;All of this can and will be used with FVEY&#39;s other records, such as internet backbone or ISP metadata, and will be used to confirm assumptions made when identifying who is talking to whom.&lt;/p&gt;
&lt;p&gt;To further break this down:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A Signal user sends a message to an Apple user via Signal (the receiver).&lt;/li&gt;
&lt;li&gt;Signal&#39;s servers notify APNS that there is a message or call waiting for a specific user.&lt;/li&gt;
&lt;li&gt;APNS &quot;pings&quot; the specific user&#39;s Apple device.&lt;/li&gt;
&lt;li&gt;The receiver&#39;s Apple device receives the &quot;ping&quot; and notifies the end user that there are new Signal messages, or a call.&lt;/li&gt;
&lt;li&gt;The receiver&#39;s Signal application then activates and requests any new messages (or calls) from Signal&#39;s servers.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;There are ways to deal with APNS metadata leakage, but it is not for the average user. I&#39;ll go into more detail in the &lt;strong&gt;DEFCON ONE&lt;/strong&gt; section below.&lt;/p&gt;
&lt;h1 id=&quot;critical-notes&quot;&gt;Critical Notes&lt;/h1&gt;
&lt;h2 id=&quot;blending-in&quot;&gt;Blending In&lt;/h2&gt;
&lt;p&gt;Blend in. Using obscure devices sticks out. Using commodity hardware like an Apple iPad does not. This has important value for both physical surveillance and network surveillance. For example, if you own a device that only criminal networks use, the software on that device is going to be talking to network endpoints that only owners of that obscure device talk to. If you pass through security check points and a security professional recognizes an obscure device, that&#39;s going to raise your profile.&lt;/p&gt;
&lt;h2 id=&quot;wi-fi-ipad-signal-advantages&quot;&gt;Wi-Fi iPad + Signal Advantages&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Wi-Fi iPads do not have baseband processors, SIM cards, or SIM card port insecurities.&lt;/li&gt;
&lt;li&gt;You can control which Wi-Fi networks to expose your device to, if you choose to use Wi-Fi.&lt;/li&gt;
&lt;li&gt;Wi-Fi iPads employs default Full Disk Encryption that is dependent on hardware and firmware cryptographic integrity controls.&lt;/li&gt;
&lt;li&gt;Apple publishes security patches quickly and are not dependent on carrier restrictions.&lt;/li&gt;
&lt;li&gt;Signal uses only modern, always-on, end-to-end cryptography. As of September 2023, Signal now has quantum resistance.&lt;/li&gt;
&lt;li&gt;Signal allows users to verify encryption key fingerprints.&lt;/li&gt;
&lt;li&gt;Signal is free, open source, and has public security audits.&lt;/li&gt;
&lt;li&gt;Signal supports interoperability, meaning that other people can use Signal on iOS or Android devices.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;wi-fi-ipad-signal-disadvantages&quot;&gt;Wi-Fi iPad + Signal Disadvantages&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;The default settings for iOS devices are bad for operational security. To use Signal anonymously or pseudo-anonymously requires great effort.&lt;/li&gt;
&lt;li&gt;Wired or Wi-Fi internet access is not as abundant as cellular internet access. These days, people depend heavily on having an always-connected device to function.&lt;/li&gt;
&lt;li&gt;iPadOS/iOS require an AppleID to download and update apps.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;notes-on-charging&quot;&gt;Notes on Charging&lt;/h2&gt;
&lt;p&gt;Only use genuine Apple chargers and charging cables that you have purchased yourself, ideally in-person with cash. Do not use friend&#39;s, family&#39;s, or borrow stranger&#39;s chargers or charging cables. Do not use third-party chargers or charging cables. Do not let anyone else use your chargers or charging cables. &lt;a rel=&quot;external&quot; href=&quot;https://www.bitdefender.com/blog/hotforsecurity/youtuber-demonstrates-fake-charging-cable-that-can-hack-your-computer/&quot;&gt;Read more here&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;notes-about-ios-updates&quot;&gt;Notes about iOS Updates&lt;/h2&gt;
&lt;p&gt;Update iOS always. Update as soon as possible. Every update comes with very important security patches.&lt;/p&gt;
&lt;p&gt;Be aware that privacy settings may be reconfigured without your knowledge when you perform iOS updates. Review all settings after every update.&lt;/p&gt;
&lt;p&gt;Airplane Mode gets disabled automatically after every iOS update. This &quot;feature&quot; is great for idiots, but terrible for operational security. Presume that after every iOS update + reboot, Airplane Mode will be disabled upon startup until you reactive Airplane Mode. See my &lt;strong&gt;DEFCON ONE&lt;/strong&gt; section below if this matters to your threat model.&lt;/p&gt;
&lt;h2 id=&quot;notes-on-inactivity-reboot-before-first-unlock-bfu-and-after-first-unlock-afu-states&quot;&gt;Notes on &quot;Inactivity Reboot&quot;, Before First Unlock (BFU) and After First Unlock (AFU) states&lt;/h2&gt;
&lt;p&gt;In iOS 18, Apple &lt;a rel=&quot;external&quot; href=&quot;https://9to5mac.com/2024/11/11/ios-18-1-inactivity-reboot-iphone/&quot;&gt;silently released&lt;/a&gt; a security feature being called &quot;Inactivity Reboot&quot; that was &lt;a rel=&quot;external&quot; href=&quot;https://archive.is/rlrm8&quot;&gt;discovered&lt;/a&gt; and independently verified (&lt;a rel=&quot;external&quot; href=&quot;https://chaos.social/@jiska/113447894119816217&quot;&gt;see 1&lt;/a&gt;, &lt;a rel=&quot;external&quot; href=&quot;https://chaos.social/@jiska/113486387693060891&quot;&gt;see 2&lt;/a&gt;) that iPhones, when left locked for 72-hours, reboot themselves to force BFU.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;It&#39;s not clear to me if this is also a feature of iPadOS that is on by default.&lt;/strong&gt; In some of Apple&#39;s MDM documentation for iPadOS 18.4, a feature called &quot;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-mo/guide/deployment/dep789n2k1qp/web&quot;&gt;idle reboot&lt;/a&gt;&quot; is avaialble for enablement via MDM. Again, it&#39;s not clear if this is enabled by default on non-MDM-enrolled devices.&lt;/p&gt;
&lt;p&gt;An excellent learning resource on this topic is from the Dakota State University DigForCE Lab in a post titled &quot;&lt;a rel=&quot;external&quot; href=&quot;https://blogs.dsu.edu/digforce/2023/08/23/bfu-and-afu-lock-states/&quot;&gt;BFU and AFU Lock States&lt;/a&gt;&quot;. Some excerps:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;BFU Extractions&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;In the case that a device is locked with a passcode that is not known, examiners may have an option to receive an extraction based on the device’s lock state. When a device is in the BFU lock state, a BFU extraction is able to be created. This type of extraction contains a somewhat limited amount of information, but may be useful in certain cases. Information contained within a BFU extraction mainly includes system data; However, there may be a small amount of user-generated data found within the extraction that may provide new leads for certain cases. This type of extraction is small, and a majority of the information is either system/application data, as well as cached images and videos that are not user-generated. Generally, iOS devices seem to give a larger amount of data than Android in the BFU state.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;AFU Extractions&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;When a device is in the AFU lock state, an AFU extraction may be created. Compared to a BFU extraction, an AFU extraction contains a vast majority of all user-generated data, which can be seen as about 95% of a Full Filesystem extraction (these extractions will be discussed in the next section). This means an AFU extraction will contain user-generated chats, images, videos, web-browsing data, and much more. Compared to a Full Filesystem extraction, an AFU extraction does not contain Apple Mail, Apple Health, or significant location information. The amount of information you can receive from a device in the AFU lock state can be substantial, so it is important to keep an AFU device powered on. If the device is powered off, the lock state will switch to BFU which could lead to the loss of a lot of potential information.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;Full Filesystem Extractions&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The ideal situation is when the passcode of the device is known or can be bruteforced. The device may be able to have its passcode bruteforced using validated forensic tools such as GrayKey or Cellebrite. Once the passcode is known, a Full File System extraction of the device is able to be created, which is the most comprehensive type of extraction you can receive from a mobile device. This type of extraction will give you all the data included within the filesystem of the device.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;notes-on-lockdown-mode-ldm&quot;&gt;Notes on &quot;Lockdown Mode&quot; (LDM)&lt;/h2&gt;
&lt;p&gt;Should you use &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/HT212650&quot;&gt;LDM&lt;/a&gt;? Yes, absolutely. LDM has two features that improve the security of a device that this guide is written for: device connections hardening and configuration profiles hardening. All the other features of LDM are for people who do not take privacy and security as seriously as this guide is intended for; meaning, people who use an iPhone more normally by using iMessage, iCloud, and who browse the internet with Safari.&lt;/p&gt;
&lt;p&gt;LDM should be enabled before your device is ever networked. Particularly, if you are using an iPad with cellular or using an iPhone, and your SIM card is inserted, malicious SMS messages or iMessages can be received by your device before LDM is enabled, potentially opening up your device to remote exploitation before the mitation can be implemented. Even SIM-less devices, like a Wi-Fi iPad that this guide focuses on, malicious actors might be able to perform remote or local network attacks (Wi-Fi or Bluetooth), or physical attacks if threat actors have physical access to your device, that might be mitigated by LDM.&lt;/p&gt;
&lt;p&gt;iPadOS and iOS 17 have some Lockdown Mode improvements. &lt;em&gt;Devices won&#39;t automatically join non-secure WiFi networks&lt;/em&gt; (open, WEP or WPA encrypted, etc) &lt;em&gt;and will disconnect from a non-secure Wi-Fi network when you turn on Lockdown Mode. 2G cellular support is turned off&lt;/em&gt;. 2G being disabled by default is an evolution of LDM, one that I hope gets further enhanced to mitigate cellular insecurities. Of course, this doesn&#39;t help a Wi-fi iPad. However, by disabling 2G by default in cellular devices, Apple is attempting to better protect at-risk users from IMSI catchers or fraudulent cell towers performing MitM attacks. By disabling automatic joining to insecure Wi-fi is also very important to protect against similair MitM attacks within Wi-Fi range.&lt;/p&gt;
&lt;h2 id=&quot;notes-on-advanced-data-protection-adp&quot;&gt;Notes on Advanced Data Protection (ADP)&lt;/h2&gt;
&lt;p&gt;Since &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/guide/security/advanced-data-protection-for-icloud-sec973254c5f/&quot;&gt;ADP&lt;/a&gt; only applies to data uploaded to Apple&#39;s servers (iCloud), ADP, while amazing for a lot of people, is not in scope of this guide.&lt;/p&gt;
&lt;h2 id=&quot;notes-on-security-keys&quot;&gt;Notes on Security Keys&lt;/h2&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/HT213154&quot;&gt;Security Keys&lt;/a&gt; is an iCloud security feature. Don&#39;t use iCloud, so you should not need Security Keys for this device.&lt;/p&gt;
&lt;h1 id=&quot;device-setup-directions&quot;&gt;Device Setup Directions&lt;/h1&gt;
&lt;p&gt;Set up a new or recently wiped device. Please perform steps 1 - 5 before doing anything else on the device.&lt;/p&gt;
&lt;p&gt;(!) Critical notes if you are adapting this guide for an iPhone or cellular iPad:
_ Remove the SIM card before powering on the device. Ideally this would be a brand new device having never been connected to a network.
_ If the device is cellular but does not have a SIM tray, be sure that the device is brand new and will NOT self-activate. In other words, do NOT have Apple of your cellular carrier automatically transfer your phone number to the new device until AFTER steps 1 - 5 are complete. * It is critical to understand that Lockdown Mode is imperative to have turned on before a cell device can be remotely messaged (SMS, MMS, iMessage, etc). Apple&#39;s designed the new device setup process to active in the background BEFORE at-risk people can go into settings and enable Lockdown Mode. A failure on Apple&#39;s part to best protect at-risk people. Because the cell device will attempt to active in the background during the new device setup process, SMS, MMS, and iMessage can work and potentially allow a remote attacker to compromise a cell device before you are able to get into Settings, enable Lockdown Mode, and restart.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Create a &amp;gt;= 12 digit PIN or alpha-numeric passphrase (see &lt;a rel=&quot;external&quot; href=&quot;https://theintercept.com/2016/02/18/passcodes-that-can-defeat-fbi-ios-backdoor/&quot;&gt;Upgrade Your iPhone Passcode to Defeat the FBI’s Backdoor Strategy&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;AppleID&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click &quot;Forgot password or don&#39;t have an Apple ID?&quot;&lt;/li&gt;
&lt;li&gt;Click &quot;Set Up Later in Settings&quot; then &quot;Don&#39;t Use&quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click &quot;Customize Settings&quot;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Location Services: Disable&lt;/li&gt;
&lt;li&gt;Siri: Set Up Later in Settings&lt;/li&gt;
&lt;li&gt;Screen Time: Set Up Later in Settings&lt;/li&gt;
&lt;li&gt;iPad Analytics: Don&#39;t Share&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Disable the Network&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Settings &amp;gt; Airplane Mode: Enabled&lt;/li&gt;
&lt;li&gt;Settings &amp;gt; Wi-Fi: Off&lt;/li&gt;
&lt;li&gt;Settings &amp;gt; Bluetooth: Off&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enable Lockdown Mode&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Settings &amp;gt; Privacy &amp;amp; Security &amp;gt; Lockdown Mode &amp;gt; Turn On Lockdown Mode, then immediately restart.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Perform steps 6 and 7 below before setting up your AppleID, and before connecting to any network of any kind (Wifi, Bluetooth, or cellular).&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;Other Settings&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Notifications - Show Previews: Never&lt;/li&gt;
&lt;li&gt;General - AirDrop: Off&lt;/li&gt;
&lt;li&gt;General - AirDrop - NameDrop: Off&lt;/li&gt;
&lt;li&gt;General - AirPlay and Handoff - Automatically AirPlay to TVs: Never&lt;/li&gt;
&lt;li&gt;General - AirPlay and Handoff - Handoff: Off&lt;/li&gt;
&lt;li&gt;General - Background App Refresh: Turn every app off independently because you will want background refresh on once Signal is installed&lt;/li&gt;
&lt;li&gt;Control Center - Remove all controls&lt;/li&gt;
&lt;li&gt;Siri &amp;amp; Search - Siri Suggestions: Disable all&lt;/li&gt;
&lt;li&gt;Touch ID &amp;amp; Passcode - Allow Access When Locked: Disable all&lt;/li&gt;
&lt;li&gt;Privacy - Tracking: Disable&lt;/li&gt;
&lt;li&gt;Privacy - Motion &amp;amp; Fitness: Disable&lt;/li&gt;
&lt;li&gt;Privacy - Apple Advertising - Personalized Ads: Disable&lt;/li&gt;
&lt;li&gt;Safari - Advanced - JavaScript: Disable&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Delete any iPadOS/iOS apps that you feel you will not need.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;appleid-setup-and-configuration&quot;&gt;AppleID setup and configuration&lt;/h2&gt;
&lt;p&gt;Before you can setup your AppleID, you need to create a new email address that:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Has no ties to your identity. Don&#39;t use any names, pseudonyms, passwords, or &lt;a rel=&quot;external&quot; href=&quot;https://www.schneier.com/blog/archives/2015/04/cell_phone_opse.html&quot;&gt;anchor points&lt;/a&gt; that you&#39;ve ever used.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Supports two-factor authentication (2FA).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Is created and only accessed via Tor Browser; ideally, &lt;a rel=&quot;external&quot; href=&quot;https://tails.net&quot;&gt;Tails Linux&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ol start=&quot;8&quot;&gt;
&lt;li&gt;
&lt;p&gt;Open the App Store app on your iPad.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click the Profile icon in the top-right corner.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Create a New AppleID.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Signing into the App Store app is important for being able to install Signal and perform app updates. Signing into the App Store app will not automatically sign into iCloud. Never sign into iCloud.&lt;/p&gt;
&lt;ol start=&quot;11&quot;&gt;
&lt;li&gt;Install &lt;a rel=&quot;external&quot; href=&quot;https://apps.apple.com/us/app/signal-private-messenger/id874139669&quot;&gt;Signal&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;setting-up-signal&quot;&gt;Setting up Signal&lt;/h2&gt;
&lt;p&gt;There are lots of choices to be made here. What&#39;s most important when choosing a Signal number is that you have long-term, secure control of the phone number, or trust the person or organization managing the phone number. Choosing the right method really depends on your threat model and your goals for your publicity or anonymity.&lt;/p&gt;
&lt;p&gt;Journalists, lawyers, and other professionals might have an already-public phone number given to them from their employer. You can use that phone number in Signal on this device, and on this device only.&lt;/p&gt;
&lt;p&gt;Americans can leverage Google Voice. Digital phone number services might be a good solution for a Signal phone number, but only if access and control of that phone number is legitimately secure. Google Voice, for example, leverages the same nation-state defenses that Gmail accounts use. Two-factor authentication must be used to access these services. Americans with access to Google Voice can also pay Google $20 to transfer in a phone number to Google Voice, and doing so will make it a permanent number on your Google account and will not get purged due to lack of activity.&lt;/p&gt;
&lt;p&gt;You can request that a friend or family member add a new phone number to their cellular provider&#39;s plan. Active the phone number on an old cell phone and get the Signal registration SMS, then destroy that phone and SIM card, and remember &lt;a rel=&quot;external&quot; href=&quot;https://www.schneier.com/blog/archives/2015/04/cell_phone_opse.html&quot;&gt;anchor points&lt;/a&gt; (dont activate the phone number and use cellular services in places where you regularly go).&lt;/p&gt;
&lt;p&gt;Note: The updated Signal app has a bad user interface when it is the first and only device for your Signal number. When you have a fresh install of Signal, in the first couple of setup screens there is an &lt;em&gt;unlink&lt;/em&gt; icon in the top right corner that you have to click.&lt;/p&gt;
&lt;h2 id=&quot;notes-on-the-use-of-the-contacts-calendars-and-notes-apps&quot;&gt;Notes on the use of the Contacts, Calendars, and Notes apps&lt;/h2&gt;
&lt;p&gt;You have two choices when it comes to managing your contacts list, calendars, and notes data. There are many pros and cons with these two options and will depend on your threat model, so please think very carefully about your operational security practices.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Offline data: Since you are not signed into iCloud, you cannot risk disclosing your contacts, calendars, and notes data to Apple or your local government willingly (if your government has forced Apple to host iCloud data in your country instead of, or in addition to, the USA). This means it is relatively safe to use the Contacts, Calendar, and Notes apps, depending on your threat model. Using Apple&#39;s Contacts app is seamless since you can safely grant Signal access to contacts.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;You have to trust Signal to continue to implement trustworthy cryptographic security mechanisms that continue to prevent themselves from ever having cleartext access to your contacts. This risk is low, since you are already trusting Signal with the confidentiality and integrity of the content of your communications and whom you communicate with via Signal. This risk is also low because Signal does not have any financial motivation to collect your contacts in any way. In fact, data storage is expensive, and responding to government requests for users data is expensive, so it is cheaper for Signal to never have this data.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Apple native apps are the default places to look for this data if you ever are stopped and searched by government or private security agents. If this risk applies to you, store your data in a trustworthy offline password manager that supports a &quot;key file&quot; like &lt;a rel=&quot;external&quot; href=&quot;https://apps.apple.com/us/app/strongbox-keepass-pwsafe/id897283731&quot;&gt;Strongbox&lt;/a&gt;. Strongbox is like KeypassXC but for iOS, where the database is encrypted in addition to iOS disk encryption, but you can use a key file to make bruteforcing of this database impossible. Keep your key file online somewhere so you can remotely download it when you need access to your Strongbox database contents. Like your passphrase to the database, the key file should never be shared.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Online data: If you are technically savvy, or have access to trustworthy technical friends or coworkers, you can self host your contacts, calendars, and notes. I use Mail-in-a-Box to self host these things, but there are many open source, self-host solutions out there.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Since data is remotely available, you can easily wipe your phone when crossing security check points, including regional borders like at airports, and re-setup your device and re-download your data from anywhere in the world after you have safely cross these types of high-risk areas.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Since data is remotely available, it may be possible for your adversaries to know of the existence of where your data is stored online. In my example of using Mail-in-a-Box, this setup requires a public domain name that is registered to my name. Government and private entities can buy full access to domain registry data. Online storage is a risk for remote exploitation by way of illegal or legal (government warrant) means.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Running your own Tor hidden service, like from a Raspberry Pi hosted in a secure location, means that you can use &lt;a rel=&quot;external&quot; href=&quot;https://apps.apple.com/us/app/onion-browser/id519296448&quot;&gt;Onion Browser&lt;/a&gt; by Mike Tigas to safely and privately access or download remote data.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;defcon-one-configuration&quot;&gt;DEFCON ONE configuration&lt;/h1&gt;
&lt;p&gt;There are two options that can be used independently, or combined, to enhance operational security.&lt;/p&gt;
&lt;h2 id=&quot;why-defcon-one-might-be-critical-for-you&quot;&gt;Why DEFCON ONE might be critical for you&lt;/h2&gt;
&lt;p&gt;Are you worried about, or have you ever experienced, attackers physically stalking, harassing, or assaulting you? If the answer is yes, then you have a high risk of those same abusers conducting wireless attacks against your wireless device.&lt;/p&gt;
&lt;p&gt;Wireless (Wi-Fi or Bluetooth) attacks are &quot;physical&quot; attacks. They require an attacker to be physically near and aim to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Capture your wireless packets in order to conduct surveillance. Your abusers might be trying to determine:
&lt;ul&gt;
&lt;li&gt;Are you nearby?&lt;/li&gt;
&lt;li&gt;When are you online and active?&lt;/li&gt;
&lt;li&gt;How long are your conversations?&lt;/li&gt;
&lt;li&gt;How often do you have conversations?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Capture your wireless packets in order to attempt to hack the security vulnerabilities in wireless protocols. Your abusers might be trying to determine:
&lt;ul&gt;
&lt;li&gt;What type of device are you using?&lt;/li&gt;
&lt;li&gt;What methods are you using in order to communicate with others?&lt;/li&gt;
&lt;li&gt;Are there any vulnerabilities that could be taken advantage of?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;DoS (Denial of Service) your device to prevent you from being able to communicate.&lt;/li&gt;
&lt;li&gt;Hack the wireless protocols allowing active surveillance of wireless transmissions or to hack the device through protocol, driver, or operating system vulnerabilities. Your abusers might be trying to determine:
&lt;ul&gt;
&lt;li&gt;What apps are you using?&lt;/li&gt;
&lt;li&gt;Do those apps have any vulnerabilities?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Hack the wireless device directly through unknown or unpatched vulnerabilities in the wireless service, driver, and/or operating system. Your abusers might be trying to:
&lt;ul&gt;
&lt;li&gt;Have complete access to your device, including apps like Signal.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;defcon-one-setup-directions&quot;&gt;DEFCON ONE setup directions&lt;/h2&gt;
&lt;p&gt;The &lt;a rel=&quot;external&quot; href=&quot;https://www.gl-inet.com/products/gl-mt1300/&quot;&gt;GL-iNet Beryl&lt;/a&gt; is a router that supports some outstanding features:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Wi-Fi can be disabled&lt;/li&gt;
&lt;li&gt;Supports a WAN port and LAN port for wired-only networking&lt;/li&gt;
&lt;li&gt;Supports transparent Tor proxying&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The &lt;a rel=&quot;external&quot; href=&quot;https://www.apple.com/shop/product/HJKF2ZM/A/belkin-usb-c-to-gigabit-ethernet-adapter&quot;&gt;Belkin USB-C to Gigabit Ethernet Adapter&lt;/a&gt; or &lt;a rel=&quot;external&quot; href=&quot;https://www.apple.com/shop/product/HMJU2ZM/A/belkin-ethernet-power-adapter-with-lightning-connector&quot;&gt;Belkin Ethernet + Power Adapter with Lightning Connector&lt;/a&gt; allows you to mitigate all wireless attacks when the iPad is in persistant Airplane Mode.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Connect an ethernet cable to the ethernet adapter.&lt;/li&gt;
&lt;li&gt;Connect the ethernet adapter to a new, out-of-box iPad without turning the iPad on.&lt;/li&gt;
&lt;li&gt;Power on the iPad for the firs time&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Following steps 1-3, upon iPad boot-up, the iPad will not go searching for Wi-Fi access points and will automatically use the wired connection.&lt;/p&gt;
&lt;p&gt;Combine the GL-iNet Beryl with a wired ethernet adapter, and you can then Torify the iPad initialization and all future use, in effect never disclosing your physical location metadata to Apple or Signal.&lt;/p&gt;
&lt;h2 id=&quot;notes-on-defcon-one-configuration&quot;&gt;Notes on DEFCON ONE configuration&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;If you do this, be sure that the wired ethernet connection is always active before, during, and after all iOS updates because of the unfortunate automatic disabling of Airplane Mode after iOS updates.&lt;/li&gt;
&lt;li&gt;The Belkin USB-C adapter does not support USB-C charging. You will not be able to leave the iPad with an always-on internet connection, but this is not necessarily a bad thing.&lt;/li&gt;
&lt;li&gt;Assure that Airplane Mode is enabled immediately after setting up the iPad for the first time. Assure that Airplane Mode is always enabled. Assure that you never connect to any Wi-Fi access point, ever, so that if Airplane Mode ever becomes disabled accidentally, it will not broadcast any Wi-Fi connect packets.&lt;/li&gt;
&lt;li&gt;If you are not worried about physical wireless attacks (attackers who physically stalk you and try to break into your iPad via wireless hacks), then you can use the GL-iNet Beryl as a wireless device while leveraging the transparent Tor proxy.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;yawnbox&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>modern nginx cryptography</title>
        <published>2026-04-02T00:00:00+00:00</published>
        <updated>2026-04-02T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/modern-nginx-crypto/"/>
        <id>https://yawnbox.eu/blog/modern-nginx-crypto/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/modern-nginx-crypto/">&lt;h1 id=&quot;intro&quot;&gt;Intro&lt;/h1&gt;
&lt;p&gt;Even though this post was originally published in 2017, I&#39;ve been nerding out over Apache and Nginx TLS crypto for over 15 years. This post simply aims to document the current best settings for nginx transport cryptograhy that I use for the many sites that I maintain.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;OpenSSL &lt;strong&gt;3.5.x&lt;/strong&gt; - &lt;strong&gt;4.0-beta&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Tested working on &lt;strong&gt;nginx 1.29.x&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Tested working on &lt;strong&gt;Debian 13.x&lt;/strong&gt; (and should work on &lt;strong&gt;Ubuntu 26.04&lt;/strong&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Tested working on Nginx Proxy Manager (NPM), but i&#39;ve stopped using NPM.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;install-nginx&quot;&gt;Install nginx&lt;/h1&gt;
&lt;p&gt;Per &lt;a rel=&quot;external&quot; href=&quot;https://nginx.org/en/linux_packages.html#Debian&quot;&gt;the instructions&lt;/a&gt; for mainline nginx on Debian:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt install curl gnupg2 ca-certificates lsb-release debian-archive-keyring certbot&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;curl https://nginx.org/keys/nginx_signing.key | gpg --dearmor \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    | sudo tee /usr/share/keyrings/nginx-archive-keyring.gpg &amp;gt;/dev/null&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;quot;deb [signed-by=/usr/share/keyrings/nginx-archive-keyring.gpg] \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https://nginx.org/packages/mainline/debian `lsb_release -cs` nginx&amp;quot; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    | sudo tee /etc/apt/sources.list.d/nginx.list&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;code&gt;sudo apt update &amp;amp;&amp;amp; sudo apt install nginx -V&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;stronger-let-s-encrypt-certs&quot;&gt;Stronger Let&#39;s Encrypt certs&lt;/h1&gt;
&lt;p&gt;Instead of the default &lt;strong&gt;RSA-2048&lt;/strong&gt;, choose &lt;strong&gt;RSA-4096&lt;/strong&gt;. I strongly advise RSA-4096 because of the &lt;a rel=&quot;external&quot; href=&quot;https://ml4q.de/wp-content/uploads/2024/10/Entwicklungstand_QC_V_2_0.pdf&quot;&gt;report made by the German BSI&lt;/a&gt; (PDF):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;At comparable classical security levels … elliptic curves appear to require less resources than factoring an RSA modulus with Shor’s approach.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Also see Dan Goodin&#39;s ArsTechnica article: &lt;a rel=&quot;external&quot; href=&quot;https://arstechnica.com/security/2026/03/new-quantum-computing-advances-heighten-threat-to-elliptic-curve-cryptosystems/&quot;&gt;Quantum computers need vastly fewer resources than thought to break vital encryption&lt;/a&gt;&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;To issue &lt;strong&gt;shortlived&lt;/strong&gt; + &lt;strong&gt;RSA-4096&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo certbot certonly -d yawnbox.eu --key-type rsa --rsa-key-size 4096 --required-profile shortlived&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;short-lived-certs&quot;&gt;Short-lived certs&lt;/h2&gt;
&lt;p&gt;Let&#39;s Encrypt now offers short-lived, 6-day certificates. Read about them &lt;a rel=&quot;external&quot; href=&quot;https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued&quot;&gt;here&lt;/a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Why? Per Let&#39;s Encrypt:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If a certificate&#39;s private key is compromised, that compromise can&#39;t last as long.&lt;/li&gt;
&lt;li&gt;With shorter life spans for the certificates, automation is encouraged. Which facilitates robust security of web servers.&lt;/li&gt;
&lt;li&gt;Certificate revocation is historically flaky. Lifetimes 10 days and under prevent the need to invoke the revocation process and deal with continued usage of a compromised key.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In other words, this buys us a little bit more time before quantumn supremecy, and we can all finally stop using CRL and OCSP. Combined with ML-KEM -prioritized or ML-KEM -only configurations, this is the best that we have right now (from OpenSSL).&lt;/p&gt;
&lt;p&gt;When certbot is installed via &#39;apt&#39;, it&#39;s critical to automate renewal with, for example, a systemd service and timer. Create a systemd service + timer for renewal automation for every 4 days.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo tee /etc/systemd/system/certbot.service &amp;lt;&amp;lt; &amp;#39;EOF&amp;#39; &amp;gt; /dev/null&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Unit]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Description=Automatically renew Let&amp;#39;s Encrypt short-lived certificates&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Service]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Type=oneshot&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExecStart=/usr/bin/certbot certonly -d yawnbox.eu --key-type rsa --rsa-key-size 4096 --required-profile shortlived --keep --quiet --non-interactive&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExecStartPost=/usr/bin/systemctl reload nginx&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;EOF&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo tee /etc/systemd/system/certbot.timer &amp;lt;&amp;lt; &amp;#39;EOF&amp;#39; &amp;gt; /dev/null&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Unit]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Description=Renew Let&amp;#39;s Encrypt short-lived certificates every 4 days&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Timer]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;OnCalendar=*-*-1/4 03:00:00&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RandomizedDelaySec=3600&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Persistent=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Install]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;WantedBy=timers.target&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;EOF&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo systemctl daemon-reload&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo systemctl enable --now certbot.timer&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&quot;template-conf-file&quot;&gt;Template conf file&lt;/h1&gt;
&lt;p&gt;Adapt this as a secure starting point for your nginx conf file. Note that my blog is a static site, so I don&#39;t need any PHP or extra proxy configs.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo tee /etc/nginx/conf.d/default.conf &amp;lt;&amp;lt; &amp;#39;EOF&amp;#39; &amp;gt; /dev/null&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;server {&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    server_name yawnbox.eu;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    root /var/www/public;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # no logs&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    access_log off;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # hsts and hsts-preload including sub-domains&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header Strict-Transport-Security &amp;quot;max-age=31536000; includeSubDomains; preload&amp;quot; always;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # certs&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_certificate /etc/letsencrypt/live/yawnbox.eu/fullchain.pem; &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_certificate_key /etc/letsencrypt/live/yawnbox.eu/privkey.pem; &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # http/3&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    listen [::]:443 quic reuseport;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    listen 443 quic reuseport;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    http3 on;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    quic_gso on;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    quic_retry on;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header Alt-Svc &amp;#39;h3=&amp;quot;:443&amp;quot;; ma=86400&amp;#39;;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # http/2&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    listen [::]:443 ssl;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    listen 443 ssl;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    http2 on;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # TLS 1.3 only, hybrid key exchange groups are prioritized w/ strong legacy groups, no AES-128 cipher suite&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_protocols TLSv1.3;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_conf_command Groups X25519MLKEM768:SecP384r1MLKEM1024:X25519:secp384r1;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_conf_command Options +ServerPreference;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_conf_command Options +PrioritizeChaCha;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_conf_command Ciphersuites TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # security over performance&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_early_data off;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_session_tickets off;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ssl_session_cache off;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;EOF&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo nginx -t&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If all looks good, restart nginx:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo service nginx restart&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;bleeding-edge-modern&quot;&gt;Bleeding edge modern!&lt;/h1&gt;
&lt;p&gt;The next phase in modern nginx cryptography is to remove the legacy key exchange groups (remove &#39;:X25519:secp384r1&#39;). All mainstream desktop borwsers in 2026 support hybrid/ ML-KEM groups, but mobile browsers and systems with older cryptographic libraries will fail negotiation.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ssl_conf_command Groups X25519MLKEM768:SecP384r1MLKEM1024;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Note that legacy-only tools like Qualys SSL Labs will fail connections if legacy groups are disabled.&lt;/p&gt;
&lt;h1 id=&quot;ech&quot;&gt;ECH!&lt;/h1&gt;
&lt;p&gt;TBD&lt;/p&gt;
&lt;h1 id=&quot;security-headers&quot;&gt;Security Headers&lt;/h1&gt;
&lt;p&gt;Unrelated, but don&#39;t forget all of your other security headers. Be sure to change them based on your needs... watch for errors in Firefox &amp;gt; Tools &amp;gt; Browser Tools &amp;gt; Console. Use &lt;a rel=&quot;external&quot; href=&quot;https://securityheaders.com&quot;&gt;https://securityheaders.com&lt;/a&gt; for more testing.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header Content-Security-Policy &amp;quot;default-src &amp;#39;self&amp;#39;; base-uri &amp;#39;self&amp;#39;; object-src &amp;#39;none&amp;#39;; frame-ancestors &amp;#39;none&amp;#39;; img-src &amp;#39;self&amp;#39; data:; font-src &amp;#39;self&amp;#39;; style-src &amp;#39;self&amp;#39;; script-src &amp;#39;self&amp;#39;; connect-src &amp;#39;self&amp;#39;; form-action &amp;#39;self&amp;#39;; frame-src &amp;#39;none&amp;#39;; manifest-src &amp;#39;self&amp;#39;; worker-src &amp;#39;self&amp;#39;; upgrade-insecure-requests&amp;quot; always;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header Cross-Origin-Embedder-Policy &amp;quot;require-corp&amp;quot; always;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header Cross-Origin-Opener-Policy &amp;quot;same-origin&amp;quot; always;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header Cross-Origin-Resource-Policy &amp;quot;same-origin&amp;quot; always;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header Permissions-Policy &amp;quot;geolocation=(), microphone=(), camera=(), payment=(), usb=(), bluetooth=(), interest-cohort=()&amp;quot; always;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header Referrer-Policy &amp;quot;strict-origin-when-cross-origin&amp;quot; always;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header X-Content-Type-Options &amp;quot;nosniff&amp;quot; always;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    add_header X-Frame-Options &amp;quot;DENY&amp;quot; always;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>The Fedizen</title>
        <published>2025-11-01T00:00:00+00:00</published>
        <updated>2025-11-01T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/the-fedizen/"/>
        <id>https://yawnbox.eu/blog/the-fedizen/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/the-fedizen/">&lt;h1 id=&quot;what-i-need-from-you&quot;&gt;What I need from you&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Critical feedback and ideas&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Founding members&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Grants and donations to get started&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;history&quot;&gt;History&lt;/h1&gt;
&lt;p&gt;As a developing photojournalist, with only minimal on-the-job experience working for a university news paper, I&#39;ve found it difficult to gain journalistic access to many events. Reasons for denial include because I&#39;m not a full-time journalist or working on behalf of an established outlet. I want to change this, remain a freelancer, and in a way that it benefits others. A top priority is that I want to make it easier for anyone to get a legitimate press credential.&lt;/p&gt;
&lt;p&gt;Desperate to attend the NATO Summit 2025 in The Hague, Netherlands, in May 2025 I started emailing several media outlets in and around the Netherlands if I could exchange my time and photographic media for a &quot;letter from the editor&quot; for NATO&#39;s press pass application. I had learned that President Zelenskyy and President Trump would be in attendance, and it seemed like an incredible opportunity to photograph them at such a pivitol time in European history. Sadly, all of my emails were ignored. Even my email to a Maastricht University newspaper, where I would be a law student starting in Septmeber. Still determined, I took the chance to apply for my own media pass on behalf of my Dutch freelance company. With only two days before the NATO Summit, I received approval! My NATO Summit expereince pushed me into a new phase of development-- development of a simple idea that I&#39;d been working on for a little over a year.&lt;/p&gt;
&lt;h1 id=&quot;the-idea&quot;&gt;The idea&lt;/h1&gt;
&lt;p&gt;&lt;strong&gt;The Fedizen&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Future home: &lt;a rel=&quot;external&quot; href=&quot;https://fedizen.org&quot;&gt;fedizen.org&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;My evolving idea for The Fedizen is to create a new type of news organization made up of anyone who agrees to a set of principles -- based on the International Federation of Journalist&#39;s &lt;a rel=&quot;external&quot; href=&quot;https://www.ifj.org/who/rules-and-policy/global-charter-of-ethics-for-journalists&quot;&gt;Global Charter of Ethics for Journalists&lt;/a&gt;. That&#39;s it. A completely decentralized organization made up of volunteers who want to help change the world by documenting what goes on around us and holding the powerful to account. The organization&#39;s purpose includes:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Provide a media credential to anyone who meets baseline criteria (see the Baseline Critera below).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Provide fediverse hosting training, legal training, and operational security training to members.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Provide a publishing platform that will:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Highlight journalist&#39;s work that is hosted on their fediverse platforms.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Host anonymous journalists who are working in dangerous places.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Host an offline-by-default copy of journalist&#39;s work that can be put online in the event journalist&#39;s work is taken offline due to regional legal issues.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Host a SecureDrop instance for whistleblowers that wish to anonymously leak documents to the press.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Because I have a background in cybersecurity, I have a particular interest in getting a press credential into the hands of hackers and security researchers who want to publish their work in a more legally defensible way. I also have a long history of being an activist, online and offline. Getting press credentials into the hands of activists to help them uncover truths is also very important to me.&lt;/p&gt;
&lt;h1 id=&quot;legal-protections&quot;&gt;Legal protections&lt;/h1&gt;
&lt;p&gt;I&#39;ve had success with &lt;a rel=&quot;external&quot; href=&quot;https://emeraldonion.org&quot;&gt;Emerald Onion&lt;/a&gt;, my first U.S. 501(c)(3) human rights not-for-profit. Emerald Onion started with healthy design princicples centered on U.S. law and transparency. I moved to the Netherlands to start a Dutch freelance company, &lt;a rel=&quot;external&quot; href=&quot;https://polyhedra.nl&quot;&gt;Polyhedra B.V.&lt;/a&gt;, and so The Fedizen will at first be incubated as a program under Polyhedra where a goal is to reach a minimum level of sustainability. I anticipate The Fedizen to eventually spin off into its own legal structure and nonprofit foundation or collective. However, since I am still learning about EU law and Dutch law, doing it this way for now will keep things simple.&lt;/p&gt;
&lt;p&gt;The Fedizen will design itself to be resistant to abuses of legal systems. The Netherlands has:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Clearly established freedom of expression in &lt;a rel=&quot;external&quot; href=&quot;https://www.government.nl/topics/discrimination/prohibition-of-discrimination&quot;&gt;Article 7 of the Dutch Constitution&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Strong press freedom being ranked third in the &lt;a rel=&quot;external&quot; href=&quot;https://rsf.org/en/index&quot;&gt;World Press Freedom Index by Reporters Without Borders&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Strong source protection according to the &lt;a rel=&quot;external&quot; href=&quot;https://globalfreedomofexpression.columbia.edu/cases/sanoma-uitgevers-b-v-v-the-netherlands/&quot;&gt;Columbia Global Freedom of Expression&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Strong whistleblower protection according to the &lt;a rel=&quot;external&quot; href=&quot;https://www.huisvoorklokkenluiders.nl/english&quot;&gt;Dutch Whistleblowers Authority&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;baseline-criteria&quot;&gt;Baseline criteria&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The Fedizen has voluntary membership and members must sign a contract limiting the liability of The Fedizen and agreeing to the Charter. The Fedizen will also have permission to republish the work of their members.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Individual members are fully autonomous and are able to individually profit from their work so long as they agree to and follow the baseline criteria. Members may self-identify as being their own journalistic entity or they may self-identify as being a journalist of The Fedizen, whatever helps them and their situation. If members self-identify as being their own entity, members should identify somewhere they they ascribe to The Fedizen Charter.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Members must have a fediverse account from which they publish news, interviews, or research content. Their fediverse account does not need to be their primary audience.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Members are encouraged to form partnerships and help each other. For example, as a photojournalist, i&#39;d be interested to contribute still media to other&#39;s work.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;steps-to-establish&quot;&gt;Steps to Establish&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Find two or four other co-founders&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Agree on and develop the core documents: Mission, Vission, Purpose, Principles, and Charter based on the International Federation of Journalist&#39;s &lt;a rel=&quot;external&quot; href=&quot;https://www.ifj.org/who/rules-and-policy/global-charter-of-ethics-for-journalists&quot;&gt;Global Charter of Ethics for Journalists&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Apply for IFJ associate membership&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Send statutes, membership list, and ethics charter to the International Federation of Journalists.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Pay first-year dues.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Order IFJ International Press Cards for members.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;br&gt;
&lt;br&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Online dating with dignity</title>
        <published>2025-10-16T00:00:00+00:00</published>
        <updated>2025-10-16T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/online-dating-with-dignity/"/>
        <id>https://yawnbox.eu/blog/online-dating-with-dignity/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/online-dating-with-dignity/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;This is my idea for how a decentralized, federated, end-to-end encrypted dating app could work taking into account the probabilities of violence against minority groups. This high level design document of a theoretical app aims to balance human rights (privacy) with usability; however, privacy is more important than usability, and privacy must not be sacrificed in order to increase user adoption. This app doesn&#39;t aim to solve societal problems, only to reduce tech harms. Inspiration for this app includes: Ricochet, Cwtch, Ricochet Refresh, and Tinder.&lt;/p&gt;
&lt;p&gt;This blog post is licesned as &lt;a rel=&quot;external&quot; href=&quot;https://creativecommons.org/licenses/by-sa/4.0/deed.en&quot;&gt;Attribution-ShareAlike 4.0 International&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you like this idea, i&#39;d appreciate it if you would Signal me, provide a clear introduction of yourself if I don&#39;t already know you, so I can add you to a Signal group for any future discussions around this idea&#39;s development. I am not a developer -- so I will not be building this app. However, I can help facilitate, educate, and help fundraise.&lt;/p&gt;
&lt;h1 id=&quot;principles&quot;&gt;Principles&lt;/h1&gt;
&lt;p&gt;PR1. The use of Tor onion services is paramount to protect physical location data and must be used.&lt;/p&gt;
&lt;p&gt;PR2. Users must be in full control of their data.&lt;/p&gt;
&lt;p&gt;PR3. Application controls must use privacy-first defaults.&lt;/p&gt;
&lt;p&gt;PR4. Nodes (client or relay) must maximize decentralization and federation principles.&lt;/p&gt;
&lt;p&gt;PR5. Disabled people are a huge part of society and accessibliity must be designed with care.&lt;/p&gt;
&lt;p&gt;PR6. The client and relay applications must be cop resistant, both in terms of data and metadata. See PR1.&lt;/p&gt;
&lt;h1 id=&quot;high-level-data-flows&quot;&gt;High level data flows&lt;/h1&gt;
&lt;p&gt;HL1. There must be a client app and a server app (a relay).&lt;/p&gt;
&lt;p&gt;HL2. A user opens the app. Creating a profile is local, and the app generates a Tor onion service address, automatically connecting the user to the Tor network. At this point, there is no connection to any other users since no other user identities are known.&lt;/p&gt;
&lt;p&gt;HL3. Since Tor onion services cannot discover each other, an intermediary application server (herein called a relay, not to be confused with a normal Tor relay) is necessary to kickstart federation.&lt;/p&gt;
&lt;p&gt;HL4. A different (or the same) user can create a relay. See the relay section below.&lt;/p&gt;
&lt;p&gt;HL5. All connectivity, be it client-to-client, client-to-relay, or relay-to-relay is only performed over Tor onion services except in the scenario where a client or relay is provided a clearnet identity. Once a first connection is made from a client-to-relay, or a relay-to-relay via a clearnet connection, the associated Tor onion domain is shared with the client or relay, and all future connectivity is only ever made via Tor onion services. Client-to-client and relay-to-client connectivity is only possible via Tor onion services.&lt;/p&gt;
&lt;p&gt;HL6. This specification is platform agnostic; however, due to the design of clients, relays, and offline private messaging, phone apps must not be designed to be always online. When online, consider bell-shaped-curve network-metadata surveillance resistance (see &lt;a rel=&quot;external&quot; href=&quot;https://web.archive.org/web/20151101081526/https://pond.imperialviolet.org/&quot;&gt;Pond&lt;/a&gt;.)&lt;/p&gt;
&lt;h1 id=&quot;the-relay-application&quot;&gt;The relay application&lt;/h1&gt;
&lt;p&gt;RE1. Hosting a relay always requires hosting a Tor onion service, which can happen from anywhere and does not require a static IP or publicly-accessible server.&lt;/p&gt;
&lt;p&gt;RE2. Optionally, a relay operator may use a clearnet domain name (for example, disobey.net) if the relay operator and/or community wishes to use a clearnet domain. Clearnet domains greatly reduce barriers to entry since they offer email-address like identities (for example, something@disobey.net), while still providing Tor network physical location metadata safety for all users. See more in RE3b below for more details. Clearnet domains allow operators to create identities and cultures around their relay, similair to how ActivityPub-based fediverse communities exit. For example, someone could use the clearnet domain &quot;gay.paris&quot;, emphasizing a community centered on gay people in Paris. Users, of couse, can pick and choose any relay identity that they wish.&lt;/p&gt;
&lt;p&gt;RE3. A user, knowing a relay domain, either its Tor onion domain or its clearnet domain, adds a domain to their client application. Doing this joins a user to relay for application discoverability and federation.&lt;/p&gt;
&lt;p&gt;RE3a. If a relay has authenticated itself via DNS in order to establish a clearnet identity, the relay must be directly available on the internet like a normal DNS- or dynamic-DNS-based HTTP server. TLS certificate automation should be used.&lt;/p&gt;
&lt;p&gt;RE3b. If a relay has authenticated itself via DNS (for example, disobey.net) in order to establish a clearnet identity, the user (user 1) of the relay will be prompted to adopt the relay&#39;s clearnet identity (for example, something@disobey.net). However, the clearnet identity is only superficial, and only ever used for other users (user 2) to become aware of the relay&#39;s associated Tor onion domain, whereas all future communications will only ever take place over Tor onion servies. Clients are never accessible over clearnet. If a user (user 2) enters a clearnet domain into their app to discover its user (user 1), user 2&#39;s client first obtains the relay&#39;s Tor onion domain, then communicates over Tor onion services to the relay, and the relay provides the Tor onion identity of the user 1 to user 2. Going forward, federation is direct, user to user, if and when user 1 permits any data or metadata sharing (see CL0 below).&lt;/p&gt;
&lt;p&gt;RE4. Attaching a client to a relay allows a user to establish themself with a memorable identity beyond an onion domain. A user can detach themselves from a relay at any time. For example, if disobey.net is an application relay, users can establish themselves as someone@disobey.net for easier identification.&lt;/p&gt;
&lt;p&gt;RE5. The relay will temporarily cache client Tor onion domains, for up to one week, of clients in an end to end encrypted way so that the relay cannot know anything about any clients. However, client ephemeral public keys, not relayed to their Tor onion identity, will persist on relays forever, allowing clients to reclaim their prior user identity.&lt;/p&gt;
&lt;p&gt;RE6. Clients connecting to this relay will be provided a current listing of other known Tor onion domains. These onion domains are client addresses or relay addresses.&lt;/p&gt;
&lt;p&gt;RE6a. A client, with a list of other client addresses, will store the list of addresses for up to one month. This includes profiles that the user has &quot;swiped left&quot; or &quot;swiped right&quot; on, allowing a user to change their mind about someone else&#39;s profile.&lt;/p&gt;
&lt;p&gt;RE6b. Other user&#39;s domain identities are not visible to users by deffualt. This is to minimize abuse. However, in either limited profiles or full pofiles (see CL0 below), users can opt-into sharing their clearnet or onion identities on their profiles.&lt;/p&gt;
&lt;p&gt;RE6c. A client, with a list of relay addresses, will allow users to opt-into federating with other relays. Tor onion domains that are relay domains will be made clear in the UI, and if an associated clearnet domain exists for the Tor onion domain relay, the clearnet domain will become the emphasized domain in a client list, with an ability to see the associated Tor onion domain, and with an ability to opt-into federating with any number of known, online, relays.&lt;/p&gt;
&lt;p&gt;RE7. The relay, similair to how clients work, can manually add other known public relays. Doing so allows relays to share and load-balance other relay identities and other client identities.&lt;/p&gt;
&lt;p&gt;RE8. Relay operators can either explicitly set a list of known, trusted relays for federation, or, relay operators can set a maxmimum limit of relay hop trust. In the case of setting a relay hop trust number, relay operators, who trust one relay, who set a trust hop number of 1, will in effect automatically trust any relays trusted by the relay that they explicitly trust. This aims to reduce complete trust of all relays and minimize the use of malicious relays. Relay operators can also enable automatic trusting of all relays.&lt;/p&gt;
&lt;p&gt;RE9. The function of a public relay can also act as closed community. By default, relays do not know of other relays, and so they cannot talk to other relays. A group of people can host their own private relay, and in doing so, allow communities to mingle among themselves in an isolated way. See CL0a - CL0c below.&lt;/p&gt;
&lt;p&gt;RE10. Relays must support block lists. They can defederate from either a clearnet domain or from a Tor onion domain, or both. Defederating then applies automatically to any client using the identity of the relay. This is an attempt to slow down and avoid serial stalkers.&lt;/p&gt;
&lt;p&gt;RE11. Relays are responsible for keeping track of, in an end-to-end encrypted way, clearnet identities to onion identities. This way, even relay operators cannot connect identities to real people, and users have absolute control over how and when they share their identities with people (see CL0 below).&lt;/p&gt;
&lt;h1 id=&quot;private-messages-and-private-caches&quot;&gt;Private messages and private caches&lt;/h1&gt;
&lt;p&gt;PM1. The relay, in an end-to-end encrypted way, acts as a private message cache. Private messages are only ever possible after two or more people &quot;swipe right&quot; on the other, assuring mutual consent.&lt;/p&gt;
&lt;p&gt;PM2. The relay will automatically purge private cache data after 28 days if no client downloads the private message. Relay operators can lower the maximum period of retention to not less than 7 days.&lt;/p&gt;
&lt;p&gt;PM3. If clients come online and download their private messages, the client wipes the cached private messages from the relays.&lt;/p&gt;
&lt;p&gt;PM4. Private messages can be text, media, or any file type, but limited to safe file types that the client app can reliably wipe file metadata. No file types will be supported if file metadata cannot be safely removed before sharing.&lt;/p&gt;
&lt;p&gt;PM4a. Any user media added into to the client app, locally, must wipe all file metadata, before being end-to-end encrypted and shared with other users.&lt;/p&gt;
&lt;p&gt;PM4b. Users have absolute control over what file types they consent to receiving. This way, users can automatically reject anything other than plain text.&lt;/p&gt;
&lt;p&gt;PM5. Relays can set a max message size quota and will default to 1 MiB. This quota is per message, not per user. Relays are not aware of any metadata associted with messages or clients. These quotas will always be filled up to the quota size, filled by the client. This way, relays only ever see 1 MiB, end-to-end encrypted message data, attempting to lessen the risk of a malicious relay operator from at extracting message metadata.&lt;/p&gt;
&lt;p&gt;PM6. Relays can opt-into temporarily matching a quota size of a federated relay when one relay is acting on behalf of an offline client engaged in private messaging. This way, users who are engaged in private messaging, will not be limited by file size quotas of their relay.&lt;/p&gt;
&lt;p&gt;PM7. Outbound private messages are first directed toward the consenting client. If said client is not online, the user&#39;s client will store the private message in their relay&#39;s private cache. If the outbound private message is for a user with a different relay identity, the outbound private message is also stored in the other relay&#39;s private cache. Therefore, outbound private messages can be stored in two different private caches. When the receiving client automatically downloads one or both identical private messages, their client will discard duplicate private messages. Therefore, if one of the two relays goes offline, one copy of a private message will remain avaible online.&lt;/p&gt;
&lt;p&gt;PM8. When clients come online, they will periodically check their relay&#39;s private cache for private messages. Also, for any consented connections from any time in the history of their profile, a client will periodically check the other relay&#39;s private cache for private messages, based on the identity of consenting matches or established private messages. However, if any relay goes offline, including the user&#39;s identity-relay, after 30 days of being offline, clients will cease attempting to query the associated relay&#39;s private cache.&lt;/p&gt;
&lt;p&gt;PM9. If and when relays opt-into being globally federated (not just a community relay), in an end-to-end encrypted manner, private caches will federate with each other to help inform connecting clients of any private messages and automatically share end-to-end encrypted private messages belonging to the associated client of a consenting conversation. This way, if a client was able to store an outbound private message with one relay but not the other, based on consenting client relationships, private messages will federate to the associated relay. Therefore, private messages should always be redundantly available while clients are offline.&lt;/p&gt;
&lt;h1 id=&quot;the-client-application&quot;&gt;The client application&lt;/h1&gt;
&lt;p&gt;CL0. By default, the user can opt-into:&lt;/p&gt;
&lt;p&gt;CL0a. No profile sharing, and only limited profile sharing with manual approval. Before selecting a CL0 option, the client will default to this option. In this scenario, other users have no access to data or metadata, which includes seeing if and when the user is online.&lt;/p&gt;
&lt;p&gt;CL0b. Limited profile sharing (automatic) to clients using the linked/community relay only.&lt;/p&gt;
&lt;p&gt;CL0c. Full profile sharing (automatic) to clients using the linked/community relay only.&lt;/p&gt;
&lt;p&gt;CL0d. Limited profile sharing (automatic) to any client.&lt;/p&gt;
&lt;p&gt;CL0e. Full profile sharing (automatic) to any client.&lt;/p&gt;
&lt;p&gt;CL1. Once the client has discoverability via a relay, and the relay provides a list of other clients to the connecting client, the client will connect directly to other clients for client-to-client discoverability. At this stage, it is not necessary for the the other clients to be online. Also at this stage, relay connectivity is not necessary, but still maintained for periodic checking of new clients. The user&#39;s client will periodically check to see if the other clients are online. However, depending on the other client&#39;s settings defined in CL0 of this section, the user&#39;s client may or may not receive profile data from other users.&lt;/p&gt;
&lt;p&gt;CL2. Once the client has discoverability, either via relay or direct clients, depending on their CL0 setting:&lt;/p&gt;
&lt;p&gt;CL2a. (in the case of CL0a) The user is always in full control of their data. The user will see other client profiles who have opted into CL0b - CL0e. The user will not be sharing any of their user data with anyone by default. All other clients can know about the user is that there is an unknown client and there will be no way for another user to be aware of the user&#39;s data or online presence. At this stage, the user is able to &quot;swipe left&quot; or &quot;swipe right&quot;. If the user swipes right, the user will be prompted to share data (CL0b, or CL0c) with only this user.&lt;/p&gt;
&lt;p&gt;CL2b. (in the case of CL0b) The user will automatically share limited profile data with any other discovered and online clients provided by the community relay. Any other clients that the user&#39;s client may have discovered, if they were not dicovered via the community relay, will never establish connection to said client. The user will see other client profiles who have opted into CL0b or CL0c. At this stage, the user is able to &quot;swipe left&quot; or &quot;swipe right&quot; on profiles. Also at this stage, even if a user has not swiped right on a profile, other discovered clients will be able to &quot;swipe left&quot; or &quot;swipe right&quot; on the user&#39;s limited profile. If there&#39;s a mutually consenting match (when both users have &quot;swiped right&quot; on the other), the user is prompted to opt-into sharing their full profile with this user, or not. At this stage, the two consenting users are able to private message each other (see P7 above).&lt;/p&gt;
&lt;p&gt;CL2c. (in the case of CL0c) see CL2b, but instead a client will share full profile data instead of limited profile data.&lt;/p&gt;
&lt;p&gt;CL2d. (in the case of CL0d) The user will automatically share limited profile data with any other discovered and online clients. The user will see other client profiles who have opted into CL0d or CL0e. At this stage, the user is able to &quot;swipe left&quot; or &quot;swipe right&quot;. Also at this stage, even if a user has not swiped right on a profile, other discovered clients will be able to &quot;swipe left&quot; or &quot;swipe right&quot; on the user&#39;s limited profile. If there&#39;s a mutually consenting match (when both users have &quot;swiped right&quot; on the other), the user is prompted to opt-into sharing their full profile with a user, or not. At this stage, the two consenting users are able to direct message each other.&lt;/p&gt;
&lt;p&gt;CL2e. (in the case of CL0e) see CL2d, but instead a client will share full profile data instead of full profile data.&lt;/p&gt;
&lt;p&gt;CL3. Users can create any number of Tor onion domains for their client, effectively giving them unlimited identities. Once a user deletes an identity, the user cannot be contacted via that identity. This is to enable users to hand out identities to different people or groups. See RE11.&lt;/p&gt;
&lt;h1 id=&quot;user-risks&quot;&gt;User risks&lt;/h1&gt;
&lt;p&gt;UR1. Using privacy apps requires careful understanding by its user. Education is paramount and good UI/UX is paramount. Users may accidently overshare not fully understanding the consequences.&lt;/p&gt;
&lt;p&gt;UR2. Anyone in the world can sign up and use this network. Liars. Cheaters. Government agents. Stalkers. Rapists. Murderers. A huge amount of insecure and insecurely-attached people. It&#39;s dangerous. See UR1. There is no central organization to complain to, no central organization to ban people, to central organization to demand fundamental rights from. It&#39;s all on you and your communities to stay safe.&lt;/p&gt;
&lt;h1 id=&quot;relay-risks&quot;&gt;Relay risks&lt;/h1&gt;
&lt;p&gt;RR1. Typical government user data demands or server seizure, even though there&#39;s literally no user data and no metadata that can be obtained, stored, shared, or seized. This is mainly an issue if and when a relay has an associted clearnet domain, or if a publishing relay operator makes it clear who hosts a relay and from where.&lt;/p&gt;
&lt;p&gt;RR2. If relay operators make themselves known, they also become a target of users who may think that the relay operator is responsible for their safety. Even if claims made against the relay operator are not based in facts, lawsuits can happen.&lt;/p&gt;
&lt;p&gt;RR3. Storing private caches, even if limited to 1 MiB in file size, scales. An abusive client or clients may intentionally aim to fill your relay&#39;s private cache, possibly shutting down the relay.&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Peertube security</title>
        <published>2025-10-04T00:00:00+00:00</published>
        <updated>2025-10-04T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/peertube-security/"/>
        <id>https://yawnbox.eu/blog/peertube-security/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/peertube-security/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;Peertube is something I&#39;m trying to learn and adapt to. I hate some of their UI/UX decisions; but since it&#39;s the leading and most mature ActivityPub-based Youtube alternative, I&#39;m giving it a third try.&lt;/p&gt;
&lt;p&gt;This guide demonstrates how to fix a bad default systemd security score. It presumes you already have a fully-functional Peertube instance deployed on a systemd system.&lt;/p&gt;
&lt;h1 id=&quot;system-dee-security&quot;&gt;system-dee security&lt;/h1&gt;
&lt;p&gt;Use systemd&#39;s built in security audit tool:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo systemd-analyze security peertube.service&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This is the default score I got which is not good:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;→ Overall exposure level for peertube.service: 8.3 EXPOSED 🙁&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Edit the service:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo systemctl edit peertube.service&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Add these lines -- be sure to change the ReadWritePaths line:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Service]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NoNewPrivileges=yes&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;UMask=007&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;LockPersonality=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictRealtime=yes&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RemoveIPC=yes&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictSUIDSGID=yes&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;CapabilityBoundingSet=&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;AmbientCapabilities=&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictNamespaces=yes&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SystemCallArchitectures=native&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SystemCallFilter=~@mount @swap @reboot @raw-io @module @debug @obsolete @privileged @cpu-emulation @keyring&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectSystem=strict&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectHome=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateTmp=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateDevices=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectControlGroups=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelModules=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelTunables=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelLogs=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectClock=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectHostname=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProcSubset=pid&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectProc=invisible&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadWritePaths=/zfspool/peertube&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;LimitNOFILE=65536&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo systemctl daemon-reload&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo systemctl restart peertube&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo systemctl status peertube --no-pager&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Re-run the audit:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo systemd-analyze security peertube.service&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;→ Overall exposure level for peertube.service: 1.7 OK 🙂&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Any score of 1.x is much better!&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>The full Dutch American Friendship Treaty</title>
        <published>2025-09-17T00:00:00+00:00</published>
        <updated>2025-09-17T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/dutch-american-friendship-treaty/"/>
        <id>https://yawnbox.eu/blog/dutch-american-friendship-treaty/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/dutch-american-friendship-treaty/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;The following post is a reformatted version of the &quot;&lt;a rel=&quot;external&quot; href=&quot;https://zoek.officielebekendmakingen.nl/trb-1956-40.pdf&quot;&gt;Treaty of Friendship, Commerce and Navigation — Netherlands &amp;amp; United States&lt;/a&gt;&quot; (PDF), in English only. It&#39;s been reformatted in markdown and so the full English text is lumped together for easier reading, including for text-to-speech.&lt;/p&gt;
&lt;p&gt;As someone who is using the DAFT visa, I&#39;d like to highlight some interesting sections that seem really useful:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Article XI - DAFT users do not need to pay international student tuition.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;What other articles are interesting to you, and why?&lt;/p&gt;
&lt;h1 id=&quot;treaty-of-friendship-commerce-and-navigation-between-the-kingdom-of-the-netherlands-and-the-united-states-of-america&quot;&gt;Treaty of Friendship, Commerce and Navigation between the Kingdom of the Netherlands and the United States of America&lt;/h1&gt;
&lt;p&gt;The Hague, 27 March 1956&lt;/p&gt;
&lt;p&gt;The Kingdom of the Netherlands and the United States of America, desirous of strengthening the bonds of peace and friendship traditionally existing between them and of encouraging closer economic and cultural relations between their peoples, and being cognizant of the contributions which may be made toward these ends by arrangements promoting mutually advantageous commercial intercourse, encouraging mutually beneficial investments, and establishing mutual rights and privileges, have resolved to conclude a Treaty of Friendship, Commerce and Navigation, based in general upon the principles of national and unconditional most-favored-nation treatment reciprocally accorded, and for that purpose have appointed as their Plenipotentiaries:&lt;/p&gt;
&lt;p&gt;Her Majesty the Queen of the Netherlands: H.E. Dr. J. W. Beyen, Minister of Foreign Affairs, and H.E. Dr. J. M. A. H. Luns, Minister without Portfolio, and the President of the United States of America: H.E. Mr. H. Freeman Matthews, Ambassador extraordinary and plenipotentiary of the United States of America at The Hague, who, having communicated to each other their full powers found to be in due form, have agreed as follows:&lt;/p&gt;
&lt;h2 id=&quot;article-i&quot;&gt;Article I&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Each Party shall at all times accord fair and equitable treatment to the nationals and companies of the other Party, and to their property, enterprises and other interests.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Between the territories of the two Parties there shall be, in accordance with the provisions of the present Treaty, freedom of commerce and navigation.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-ii&quot;&gt;Article II&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals of either Party shall be permitted to enter the territories of the other Party and to remain therein: (a) for the purpose of carrying on trade between the territories of the two Parties and engaging in related commercial activities; (h) for the purpose of developing and directing the operations of an enterprise in which they have invested, or in which they are actively in the process of investing, a substantial amount of capital; and (c) for other purposes subject to the laws relating to the entry and sojourn of aliens.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Each Party undertakes to make available the best facilities practicable for travel by tourists and other visitors with respect to their entry, sojourn and departure, and for the distribution of information for tourists.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals of either Party, within the territories of the other Party, shall be permitted: (a) to travel therein freely, and to reside at places of their choice; (b) to enjoy liberty of conscience; (c) to hold both private and public religious services; (d) to gather and to transmit material for dissemination to the public abroad; and (e) to communicate with other persons inside and outside such territories by mail, telegraph and other means open to general public use.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of the present Article shall be subject to the right of either Party to apply measures that are necessary to maintain public order and protect the public health, morals and safety.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-iii&quot;&gt;Article III&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals of either Party within the territories of the other Party shall be free from molestations of every kind, and shall receive the most constant protection and security. They shall be accorded in like circumstances treatment no less favorable than that accorded nationals of such other Party for the protection and security of their persons and their rights. The treatment accorded in this respect shall in no case be less favorable than that accorded nationals of any third country or that required by international law.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If, within the territories of either Party, a national of the other Party is taken into custody, the nearest consular representative of his country shall on the demand of such national be immediately notified and shall have the right to visit and communicate with such national. Such national shall: (a) receive reasonable and humane treatment; (b) be promptly informed of the accusations against him; (c) be brought to trial as promptly as is consistent with the proper preparation of his defense; and (d) enjoy all means reasonably necessary to his defense, including the services of competent counsel of his choice.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-iv&quot;&gt;Article IV&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals of either Party shall be accorded national treatment in the application of laws and regulations within the territories of the other Party that establish a pecuniary compensation or other benefit or service, on account of disease, injury or death arising out of and in the course of employment or due to the nature of employment.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In addition to the rights and privileges provided in paragraph 1 of the present Article, nationals of either Party shall, within the territories of the other Party, be accorded national treatment in the application of laws and regulations establishing compulsory systems of social security, under which benefits are paid without an individual test of financial need in the following cases: (a) sickness, including temporary disability for work, and maternity; (b) invalidity, or occupational disability; (c) death of father, spouse, or any other person liable for maintenance; (d) unemployment.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-v&quot;&gt;Article V&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded national treatment with respect to access to the courts of justice and to administrative tribunals and agencies within the territories of the other Party, in all degrees of jurisdiction, both in pursuit and in defense of their rights. It is understood that companies of either Party not engaged in activities within the territories of the other Party shall enjoy such access therein without any requirement of registration or domestication.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;(a) Contracts entered into between nationals or companies of either Party and nationals or companies of the other Party, that provide for the settlement by arbitration of controversies, shall not be deemed unenforceable within the territories of such other Party merely on the grounds that the place designated for the arbitration proceedings is outside such territories or that the nationality of one or more of the arbitrators is not that of such other Party, (b) In conformity with subparagraphs (1) and (2) hereof, awards duly rendered pursuant to any such contracts, which are final and enforceable under the laws of the place where rendered, shall be deemed conclusive in enforcement proceedings brought before the courts of competent jurisdiction of either Party. (1) As regards recognition and enforcement in the United States of America, such awards shall be entitled in any court in any State thereof only to the same measure of recognition and enforcement as awards rendered in other States thereof. (2) As regards enforcement in the Kingdom of the Netherlands, such awards shall be dealt with in the same way as awards as referred to in the Convention on the execution of foreign arbitral awards concluded at Geneva on September 26, 1927.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-vi&quot;&gt;Article VI&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Property of nationals and companies of either Party shall receive the most constant protection and security within the territories of the other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The dwellings, offices, warehouses, factories and other premises of nationals and companies of either Party located within the territories of the other Party shall not be subject to molestation or to entry without just cause. Official searches and examinations of such premises and their contents, when necessary, shall be made only according to law and with careful regard for the convenience of the occupants and the conduct of business.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Neither Party shall take unreasonable or discriminatory measures that would impair the rights or interests within its territories of nationals and companies of the other Party, whether in their capital, or in their enterprises and the property thereof, or in the skills, arts or technology which they have supplied.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Property of nationals and companies of either Party shall not be taken within the territories of the other Party except for a public interest, nor shall it be taken without the prompt payment of just compensation. Such compensation shall be in an effectively realizable form and shall represent the equivalent of the property taken; and adequate provision shall have been made at or prior to the time of taking for the determination and payment thereof.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall in no case be accorded, within the territories of the other Party, less than national treatment and most-favored-nation treatment with respect to the matters set forth in paragraphs 2 and 4 of the present Article. Moreover, enterprises in which nationals and companies of either Party have a substantial interest shall be accorded, within the territories of the other Party, not less than national treatment and most-favorednation treatment in all matters relating to the taking of privately owned enterprises into public ownership and to the placing of such enterprises under public control or administration.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-vii&quot;&gt;Article VII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded national treatment with respect to engaging in all types of commercial, industrial, financial and other activity for gain (business activities) within the territories of the other Party, whether directly or by agent or through the medium of any form of lawful juridical entity. Accordingly, such nationals and companies shall be permitted within such territories: (a) to establish and maintain branches, agencies, offices, factories and other establishments appropriate to the conduct of their business; (b) either directly or indirectly through one or more intermediaries, to organize companies under the general company laws of such other Party and to acquire the controlling interest in companies of such other Party; and (c) to control and manage enterprises which they have established or acquired. Moreover, enterprises which they control, whether in the form of individual proprietorships, companies or otherwise, shall in all that relates to the conduct of the activities thereof, be accorded treatment no less favorable than that accorded like enterprises controlled by nationals and companies of such other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Each Party reserves the right to limit the extent to which aliens may within its territories establish, acquire interests in, or carry on enterprises engaged in communications, air or water transport, banking involving depository or fiduciary functions, or the exploitation of land or other natural resources. However, new limitations imposed by either Party upon the extent to which aliens are accorded national treatment, with respect to carrying on such activities within its territories, shall not be applied as against enterprises which are engaged in such activities therein at the time such new limitations are adopted and which are owned or controlled by nationals and companies of the other Party. Moreover, neither Party shall deny to transportation, communications and banking companies of the other Party the right to maintain branches and agencies, in conformity with the applicable laws and regulations, to perform functions necessary for essentially international operations in which they engage.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of paragraph 1 of the present Article shall not prevent either Party from prescribing special formalities in connection with the establishment of alien-controlled enterprises within its territories; but such formalities may not impair the substance of the rights set forth in said paragraph.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party, as well as enterprises controlled by such nationals and companies, shall in any event be accorded most-favored-nation treatment with reference to the matters treated in the present Article.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-viii&quot;&gt;Article VIII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be permitted to engage, within the territories of the other Party, accountants and other technical experts, executive personnel, attorneys, agents and other specialists of their choice. Moreover, such nationals and companies shall be permitted to engage accountants and other technical experts regardless of the extent to which they may have qualified for the practice of a profession within the territories of such other Party, for the particular purpose of making examinations, audits and technical investigations for, and rendering reports to, such nationals and companies in connection with the planning and operation of their enterprises, and enterprises in which they have a financial interest, within such territories.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded national treatment and most-favored-nation treatment with respect to engaging in scientific, educational, religious and philanthropic activities within the territories of the other Party, and shall be accorded the right to form associations for that purpose under the laws of such other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-ix&quot;&gt;Article IX&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of the Kingdom of the Netherlands shall be accorded, within the territories of the United States of America: (a) national treatment with respect to leasing land, buildings and other real property appropriate to the conduct of activities in which they are permitted to engage pursuant to Articles VII and VIII and for residential purposes and with respect to occupying and using such property; and (b) other rights in real property permitted by the applicable laws of the States, Territories and possessions of the United States of America.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of the United States of America shall be accorded, within the territories of the Kingdom of the Netherlands, national treatment with respect to acquiring by purchase, lease, or otherwise, and with respect to owning, occupying and using land, buildings and other real property. However, in the case of any such national domiciled in, or any such company constituted under the laws of, any State, Territory or possession of the United States of America that accords less than national treatment to nationals and companies of the Kingdom of the Netherlands in this respect, the Kingdom of the Netherlands shall not be obligated to accord to such national or company treatment more favorable in this respect than such State, Territory or possession accords to nationals and companies of the Kingdom of the Netherlands.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded within the territories of the other Party national treatment and most-favored-nation treatment with respect to acquiring, by purchase, lease, or otherwise, and with respect to owning and possessing, personal property of all kinds, both tangible and intangible. However, either Party may impose restrictions on alien ownership of materials dangerous from the standpoint of public safety and alien ownership of interests in enterprises carrying on particular types of activity, but only to the extent that this can be done without impairing the rights and privileges secured by #### Article VII or by other provisions of the present Treaty.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded national treatment within the territories of the other Party with respect to acquiring property of all kinds by testate or intestate succession or through judicial process. Should they because of their alienage be ineligible to continue to own any such property, they shall be allowed a reasonable period in which to dispose of it, in a normal manner at its market value.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded within the territories of the other Party national treatment and most-favored-nation treatment with respect to disposing of property of all kinds. Furthermore, with respect to the acquisition, ownership, use and disposition of property of all kinds within the territories of either Party, companies constituted under the laws of that Party, which are controlled by nationals and companies of the other Party, shall be accorded treatment no less favorable than that accorded within such territories to companies of such other Party or to companies similarly constituted which are controlled by nationals and companies of any third country.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-x&quot;&gt;Article X&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded, within the territories of the other Party, national treatment with respect to obtaining and maintaining patents of invention, and with respect to rights in trade marks, trade names, trade labels and industrial property of every kind.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Parties agree as to the desirability of furthering, through cooperative or other appropriate means, the interchange and use of scientific and technical knowledge, particularly in the interest of increasing productivity and improving standards of living within their respective territories.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xi&quot;&gt;Article XI&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals of either Party residing within the territories of the other Party, and nationals and companies of either Party engaged in trade or other gainful pursuit or in scientific, educational, religious or philanthropic activities within the territories of the other Party, shall not be subject to the payment of taxes, fees or charges imposed upon or applied to income, capital, transactions, activities or any other object, or to requirements with respect to the levy and collection thereof, within the territories of such other Party, more burdensome than those borne by nationals and companies of such other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;With respect to nationals of either Party who are neither resident nor engaged in trade or other gainful pursuit within the territories of the other Party, and with respect to companies of either Party which are not engaged in trade or other gainful pursuit within the territories of the other Party, it shall be the aim of such other Party to apply in general the principle set forth in paragraph 1 of the present Article.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall in no case be subject, within the territories of the other Party, to the payment of taxes, fees or charges imposed upon or applied to income, capital, transactions, activities or any other object, or to requirements with respect to the levy and collection thereof, more burdensome than those borne by nationals, residents and companies of any third country.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In the case of companies and of non-resident nationals of either Party engaged in trade or other gainful pursuit within the territories of the other Party, such other Party shall not impose or apply any tax, fee or charge upon any income, capital or other basis in excess of that reasonably allocable or apportionable to its territories, nor grant deductions and exemptions less than those reasonably allocable or apportionable to its territories. A comparable rule shall apply also in the case of companies organized and operated exclusively for scientific, educational, religious or philanthropic purposes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Each Party reserves the right to: (a) extend specific tax advantages on the basis of reciprocity; (b) accord special tax advantages by virtue of agreements for the avoidance of double taxation or the mutual protection of revenue; and (c) accord to its own nationals and to residents of contiguous countries more favorable exemptions of a personal nature with respect to income and inheritance taxes than are accorded to other non-resident persons.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xii&quot;&gt;Article XII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded by the other Party national treatment and most-favored-nation treatment with respect to payments, remittances and transfers of funds or financial instruments between the territories of the two Parties as well as between the territories of such other Party and of any third country.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Neither Party shall impose exchange restrictions as defined in paragraph 5 of the present Article except to the extent necessary to maintain or restore adequacy in its monetary reserves, particularly in relation to its external commercial and financial requirements. It is understood that the provisions of the present Article do not alter the obligations either Party may have to the International Monetary Fund or preclude imposition of particular restrictions whenever the Fund specifically authorizes or requests a Party to impose such particular restrictions.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If either Party imposes exchange restrictions in accordance with paragraph 2 of the present Article, it shall, after making whatever provision may be necessary to assure the availability of foreign exchange for goods and services essential to the health and welfare of its people, make reasonable provision for the withdrawal, in foreign exchange in the currency of the other Party, of: (a) the compensation referred to in #### Article VI, paragraph 4, (b) earnings, whether in the form of salaries, interest, dividends, commissions, royalties, payments for technical services, or otherwise, and (c) amounts for amortization of loans, depreciation of direct investments, and capital transfers to the extent feasible, giving consideration to special needs for other transactions. If more than one rate of exchange is in force, the rate applicable to such withdrawals shall be a rate which is specifically approved by the International Monetary Fund for such transactions or, in the absence of a rate so approved, an effective rate which, inclusive of any taxes or surcharges on exchange transfers, is just and reasonable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Exchange restrictions shall not be imposed by either Party in a manner unnecessarily detrimental or arbitrarily discriminatory to the claims, investments, transport, trade, and other interests of nationals and companies of the other Party, nor to the competitive position thereof. Each Party shall afford the other Party adequate opportunity for consultation at any time regarding application of the present Article.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The term &quot;exchange restrictions&quot; as used in the present Article includes all restrictions, regulations, charges, taxes, or other requirements imposed by either Party which burden or interfere with payments, remittances, or transfers of funds or of financial instruments between the territories of the two Parties. control are governed by the provisions of the present Article.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xiii&quot;&gt;Article XIII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Commercial travelers representing nationals and companies of either Party engaged in business within the territories thereof shall, upon their entry into and departure from the territories of the other Party and during their sojourn therein, be accorded most-favored-nation treatment in respect of the customs and other matters, including, subject to the exceptions in paragraph 5 of #### Article XI, taxes and charges applicable to them, their samples and the taking of orders, and regulations governing the exercise of their functions.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xiv&quot;&gt;Article XIV&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Each Party shall accord most-favored-nation treatment to products of the other Party, from whatever place and by whatever type of carrier arriving, and to products destined for exportation to the territories of such other Party, by whatever route and by whatever type of carrier, with respect to customs duties and charges of any kind imposed on or in connection with importation or exportation or imposed on the international transfer of payments for imports or exports, and with respect to the method of levying such duties and charges, and with respect to all rules and formalities in connection with importation and exportation.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Neither Party shall impose restrictions or prohibitions on the importation of any product of the other Party, or on the exportation of any product to the territories of the other Party, unless the importation of the like product of, or the exportation of the like product to, all third countries is similarly restricted or prohibited.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If either Party imposes quantitative restrictions on the importation or exportation of any product in which the other Party has an important interest: (a) it shall as a general rule give prior public notice of the total amount of the product, by quantity or value, that may be imported or exported during a specified period, and of any change in such amount or period; and (b) if it makes allotments to any third country, it shall afford such other Party a share proportionate to the amount of the product, by quantity or value, supplied by or to it during a previous representative period, due consideration being given to any special factors affecting the trade in such product.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Either Party may impose prohibitions or restrictions on sanitary or other customary grounds of a non-commercial nature, or in the interest of preventing deceptive or unfair practices, provided such prohibitions or restrictions do not arbitrarily discriminate against the commerce of the other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals and companies of either Party shall be accorded national treatment and most-favored-nation treatment by the other Party with respect to all matters relating to importation and exportation.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Notwithstanding the provisions of paragraphs 2 and 3 (b) of the present Article, a Party may apply restrictions or controls on importation and exportation of goods that have effect equivalent to, or which are necessary to make effective, exchange restrictions applied pursuant to #### Article XII. However, such restrictions or controls shall depart no more than necessary from the aforesaid paragraphs and shall be conformable with a policy designed to promote the maximum development of nondiscriminatory foreign trade and to expedite the attainment both of a balance-of-payments position and of monetary reserves which will obviate the necessity of such restrictions.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xv&quot;&gt;Article XV&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Each Party shall promptly publish laws, regulations and administrative rulings of general application pertaining to rates of duty, taxes or other charges, to the classification of articles for customs purposes, and to requirements or restrictions on imports and exports or the transfer of payments therefor, or affecting their sale, distribution or use; and shall administer such laws, regulations and rulings in a uniform, impartial and reasonable manner. As a general practice, new administrative requirements or restrictions affecting imports, with the exception of those imposed on sanitary grounds or for reasons of public safety, shall not go into effect before the expiration of a reasonable time, in the light of circumstances.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Each Party shall provide an appeals procedure under which nationals and companies of the other Party, and importers of products of such other Party, shall be able to obtain prompt and impartial review, and correction when warranted, of administrative action relating to customs matters, including the imposition of fines and penalties, confiscations, and rulings on questions of customs classification and valuation by the administrative authorities.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Penalties imposed by either Party for infractions of the customs and shipping laws and regulations concerning documentation shall be no greater than necessary to serve merely as a warning in the case of clerical errors and of errors made without fraudulent intent or gross negligence.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;With reference to marking requirements applicable to imported products, each Party shall as a general practice: (a) allow required marks of origin to be affixed after importation; (b) not permit markings that result in misrepresenting the true origin of the products; and (c) not apply requirements that entail an expense which is economically prohibitive or that result in seriously damaging the product.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Neither Party shall impose any measure of a discriminatory nature that hinders or prevents the importer or exporter of products of either country from obtaining marine insurance on such products in companies of either Party.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xvi&quot;&gt;Article XVI&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Products of either Party shall be accorded, within the territories of the other Party, national treatment and most-favored-nation treatment in all matters affecting internal taxation, sale, distribution, storage and use.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Articles produced by nationals and companies of either Party within the territories of the other Party, or by companies of the latter Party controlled by such nationals and companies, shall be accorded therein treatment no less favorable than that accorded to like articles of national origin by whatever person or company produced, in all matters affecting exportation, taxation, sale, distribution, storage and use.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xvii&quot;&gt;Article XVII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Each Party undertakes (a) that enterprises owned or controlled by its Government, and that monopolies or agencies granted exclusive or special privileges within its territories, shall make their purchases and sales involving either imports or exports affecting the commerce of the other Party solely in accordance with commercial considerations, including price, quality, availability, marketability, transportation and other conditions of purchase or sale; and (b) that the nationals, companies and commerce of such other Party shall be afforded adequate opportunity, in accordance with customary business practice, to compete for participation in such purchases and sales.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Each Party shall accord to the nationals, companies and commerce of the other Party fair and equitable treatment, as compared with that accorded to the nationals, companies and commerce of any third country, with respect to: (a) the governmental purchase of supplies; (b) the awarding of concessions and other government contracts; and (c) the sale of any service sold by the Government or by any monopoly or agency granted exclusive or special privileges.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xviii&quot;&gt;Article XVIII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The Parties recognize that conditions of competitive equality should be maintained in situations in which publicly owned or controlled trading or manufacturing enterprises of either Party engage in competition, within the territories thereof, with privately owned and controlled enterprises of nationals and companies of the other Party. Accordingly, such state-owned enterprises should not be given special economic privileges in order to injure the competitive position of such private enterprises. However, this principle shall not be construed to prevent either Party from making such special concessions in aid of state-owned enterprises as it deems necessary during periods of economic crisis, especially to relieve unemployment. This principle, moreover, is without prejudice to special advantages given in connection with: (a) manufacturing goods for government use, or supplying goods and services to the Government for government use; or (b) supplying, at prices substantially below competitive prices, the needs of particular population groups for essential goods and services not otherwise practically obtainable by such groups.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;No enterprise of either Party, including corporations, associations, and government agencies and instrumentalities, which is publicly owned or controlled shall, to the extent that it engages in commercial, industrial, shipping or other business activities within the territories of the other Party, claim or enjoy, either for itself or for its property, immunity therein from taxation, suit, execution of judgment or other liability to which privately owned and controlled enterprises are subject therein.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xix&quot;&gt;Article XIX&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Vessels under the flag of either Party, and carrying the papers required by its laws in proof of nationality, shall be deemed to be vessels of that Party both on the high seas and within the ports, places and waters of the other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Vessels of either Party shall have liberty, on equal terms with vessels of the other Party and on equal terms with vessels of any third country, to come with their cargoes to all ports, places and waters of such other Party open to foreign commerce and navigation. Such vessels and cargoes shall in all respects be accorded national treatment and most-favored-nation treatment within the ports, places and waters of such other Party; but each Party may reserve exclusive rights and privileges to its own vessels with respect to the coasting trade and inland navigation.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Vessels of either Party shall be accorded national treatment and most-favored-nation treatment with respect to the right to carry all cargo that may be carried by vessel to or from the territories of the other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Goods carried by vessels under the flag of either Party to or from the territories of the other Party shall enjoy the same favors as when transported in vessels sailing under the flag of such other Party. This applies especially with regard to customs duties and all other fees and charges, to bounties, drawbacks and other privileges of this nature, as well as to the administration of the customs and to transport to and from port by rail and other means of transportation.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If a vessel of either Party runs aground or is wrecked on the coasts of the other Party, or if it is in distress and must put into a port of the other Party, the latter Party shall extend to the vessel as well as to the crew, the passengers, the personal property of crew and passengers, and to the cargo of the vessel, the same protection and assistance as would have been extended to a vessel under its own flag in like circumstances; and shall permit the vessel after repairs to proceed with its voyage upon conformity with the laws applicable alike to vessels under its own flag. Articles salvaged from the vessel shall be exempt from all customs duties unless they pass into internal consumption; but articles not entered for consumption may be subject to measures for the protection of the revenue pending their exit from the country.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The term &quot;vessels&quot;, as used herein, means all types of vessels, whether privately owned or operated, or publicly owned or operated, except vessels of war. This term does not, except with reference to paragraphs 1 and 5 of the present Article and #### Article XX, include fishing vessels.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xx&quot;&gt;Article XX&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;In all ports of either Party the masters of all vessels under the flag of the other Party, whose crews have ceased to be fully constituted on account of illness or for any other cause, shall be permitted to engage such seamen as may be necessary for the continuation of the voyage.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals of either Party who are seamen may be sent to ports of the other Party to join national vessels, in care of consular officers, either individually or in groups on the basis of seamen&#39;s papers issued in lieu of passports. Likewise, nationals of either Party shall be permitted to travel through the territory of the other Party on their way to join vessels or to be repatriated on the basis of seamen&#39;s papers used in lieu of passports.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xxi&quot;&gt;Article XXI&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;There shall be freedom of transit through the territories of each Party by the routes most convenient for international transit: (a) for nationals of the other Party, together with their baggage; (b) for other persons, together with their baggage, en route to or from the territories of such other Party; and (c) for products of any origin en route to or from the territories of such other Party. Such persons and things in transit shall be exempt from customs duties, from duties imposed by reason of transit, and from unreasonable charges and requirements; and shall be free from unnecessary delays and restrictions. They shall, however, be subject to measures referred to in paragraph 4 of Article II, and to nondiscriminatory regulations necessary to prevent abuse of the transit privilege.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xxii&quot;&gt;Article XXII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The present Treaty shall not preclude the application of measures by either Party: (a) regulating the importation or exportation of gold or silver; (b) relating to fissionable materials, to radioactive by-products of the utilization or processing thereof, or to materials that are the source of fissionable materials; (c) regulating the production of or traffic in arms, ammunition and implements of war, or traffic in other materials carried on directly or indirectly for the purpose of supplying a military establishment; (d) necessary to fulfil its obligations for the maintenance or restoration of international peace and security, or necessary to protect its essential security interests; (e) denying to any company in which nationals of any third country or countries enjoy directly or indirectly the controlling interest, the advantages of the present Treaty, except with respect to recognition of juridical status and with respect to access to courts; and (f) regarding its national fisheries and the landing of the products thereof.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The most-favored-nation provisions of the present Treaty shall not apply to advantages accorded by: (a) the United States of America or its Territories and possessions to one another, to the Republic of Cuba, to the Republic of the Philippines, to the Trust Territory of the Pacific Islands or to the Panama Canal Zone; or (b) by the Parts of the Kingdom of the Netherlands to one another, by the Netherlands to its Benelux-partners (Belgium, including its Overseas and Trust Territories, and Luxembourg), or by the Kingdom of the Netherlands to the Republic of Indonesia.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The most-favored-nation treatment provisions of the present Treaty shall not apply to advantages accorded by either Party to adjacent countries in order to facilitate frontier traffic, or by virtue of a customs union or free trade area of which either Party may become a member, after hatving informed the other Party of its plans and having afforded it opportunity to express its views thereon.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of the present Treaty relating to the treatment of goods shall not preclude action by either Party which is required or specifically permitted under the General Agreement on Tariffs and Trade during such time as such Party is a contracting party to the General Agreement. Similarly, the most-favored-nation provisions of the present Treaty shall not apply to special advantages accorded by virtue of the aforesaid Agreement.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nationals of either Party admitted into the territories of the other Party for limited purposes shall not enjoy rights to engage in gainful occupations in contravention of limitations expressly imposed, according to law, as a condition of their admittance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nothing in the present Treaty shall be deemed to grant or imply any right to engage in political activities.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xxiii&quot;&gt;Article XXIII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The term &quot;national treatment&quot; means treatment accorded within the territories of a Party upon terms no less favorable than the treatment accorded therein, in like situations, to nationals, companies, products, vessels or other objects, as the case may be, of such Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The term &quot;most-favored-nation treatment&quot; means treatment accorded within the territories of a Party upon terms no less favorable than the treatment accorded therein, in like situations, to nationals, companies, products, vessels or other objects, as the case may be, of any third country.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;As used in the present Treaty, the term &quot;companies&quot; means corporations, partnerships, companies, foundations, associations, and other legal entities or juridical persons, whether or not with limited liability and whether or not for pecuniary profit. Companies constituted under the applicable laws and regulations within the territories of either Party shall be deemed companies thereof and shall have their juridical status recognized within the territories of the other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;National treatment accorded under the provisions of the present Treaty to companies shall: (a) as regards companies of the Kingdom of the Netherlands, in any State, Territory or possession of the United States of America, be the treatment accorded therein to companies created or organized in other States, Territories and possessions of the United States of America; and (h) as regards companies of the United States of America, in any Part of the Kingdom of the Netherlands, be the treatment accorded therein to companies created or organized in any other Part of the Kingdom. Furthermore, in any Part of the Kingdom of the Netherlands outside Europe, national treatment accorded to nationals of the United States of America shall be the treatment accorded in such Part to Netherlands nationals not born in that Part.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xxiv&quot;&gt;Article XXIV&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;The territories to which the present Treaty extends shall comprise all areas of land and water under the jurisdiction of each Party, as well as any territory for which it has international responsibility, other than the Panama Canal Zone and the Trust Territory of the Pacific Islands, provided that it shall not apply with respect to Surinam or the Netherlands Antilles, respectively, until one month after the receipt by the Government of the United States of America of notifications of such application by the Kingdom of the Netherlands.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xxv&quot;&gt;Article XXV&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Each Party shall accord sympathetic consideration to, and shall afford adequate opportunity for consultation regarding, such representations as the other Party may make with respect to any matter affecting the operation of the present Treaty.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Any dispute between the Parties as to the interpretation or application of the present Treaty, not satisfactorily adjusted by diplomacy, shall be submitted to the International Court of Justice, unless the Parties agree to settlement by some other peaceful means.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xxvi&quot;&gt;Article XXVI&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;The present Treaty shall replace the convention of commerce and navigation signed at Washington August 26, 1852, and the agreement in regard to trade marks effected by ### Exchange of Notes signed at Washington February 10 and 16, 1883.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;article-xxvii&quot;&gt;Article XXVII&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The present Treaty shall be ratified, and the ratifications thereof shall be exchanged at Washington as soon as possible.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The present Treaty shall enter into force one month after the day of exchange of ratifications. It shall remain in force for ten years and shall continue in force thereafter until terminated as provided herein.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Either Party may, by giving one year&#39;s written notice to the other Party, terminate the present Treaty at the end of the initial ten-year period or at any time thereafter with respect to all the territories to which it applies or with respect to Surinam or the Netherlands Antilles.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;IN WITNESS WHEREOF the respective Plenipotentiaries have signed the present Treaty and have affixed hereunto their seals.&lt;/p&gt;
&lt;p&gt;DONE in duplicate, in the Netherlands and English languages, both texts being equally authentic, at The Hague, this 27th day of March, one thousand nine hundred fifty-six.&lt;/p&gt;
&lt;p&gt;For the Kingdom of the Netherlands:&lt;/p&gt;
&lt;p&gt;(sd.) J. LUNS (sd.) J. W. BEYEN&lt;/p&gt;
&lt;p&gt;For the United States of .America:&lt;/p&gt;
&lt;p&gt;(sd.) H. FREEMAN MATTHEWS&lt;/p&gt;
&lt;h1 id=&quot;protocol&quot;&gt;Protocol&lt;/h1&gt;
&lt;p&gt;At the time of signing the Treaty of Friendship, Commerce and Navigation between the Kingdom of the Netherlands and the United States of America, the undersigned Plenipotentiaries, duly authorized by their respective Governments, have further agreed on the following provisions, which shall be considered integral parts of the aforesaid Treaty:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The spouse and unmarried minor children of a person permitted entry under the provisions of Article II, paragraph 1 (a) and (b), shall also be permitted entry if accompanying him or following to join him.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of Article II, paragraph 1 (h), shall be construed to extend to persons who represent nationals and companies of the same nationality which have invested or are actively in the process of investing a substantial amount of capital in an enterprise in the territories of the other Party, and who are employed by such nationals and companies in a responsible capacity.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;With respect to Article II, paragraph 1, and the first sentence of Article VIII, paragraph 1, nationals of the United States of America shall be accorded in any Part of the Kingdom of the Netherlands outside Europe the treatment accorded therein to Netherlands nationals not born in that Part.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of Article IV, paragraph 2, refer only to laws or regulations which either are national laws or regulations or are based in whole or in part on requirements of national laws or regulations. Moreover, that paragraph shall not be construed to prevent a Party from relieving aliens temporarily resident within its territories from coverage under its contributory social security system.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The term &quot;access&quot; as used in Article V, paragraph 1, comprehends, among other things, legal aid, costfree access to the courts and exemption from security for costs.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of Article VI, paragraph 4, providing for the payment of compensation shall extend to interests held directly or indirectly by nationals and companies of either Party in property which is taken within the territories of the other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of Article VII do not obligate either Party to permit nationals and companies of the other Party to carry on businesses in its territories without fulfilling the requirements which are generally applicable by law.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The activities referred to in Article VII, paragraph 1, do not include the practice of professions.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;With reference to Article VII, paragraph 1, it is understood that either Party may, consistently with the terms and intent of the Treaty, apply special requirements to alien insurance companies with a view to assuring that such companies maintain standards of accountability and solvency comparable with those required of like domestic companies, so long.as such requirements do not have the effect of discrimination in substance against such alien companies.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;It is agreed that, on a reciprocity basis, the first sentence of Article VII, paragraph 2, shall not apply to the establishment of, or the acquisition of interests in, or the control, operation and management of, companies of either Party for engaging in the exploration for and exploitation of petroleum and other mineral resources within the territories of that Party, by national or companies of the other Party.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of the first sentence of Article VIII, paragraph 1, shall not be construed to affect the right of the Netherlands to require that aliens may not be employed in the Netherlands unless the appropriate permits have been granted. However, in keeping with the terms of that paragraph, the regulations governing employment shall be applied in a liberal fashion.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nothing in the present Treaty shall be construed to supersede any provision of the Convention between the Kingdom of the Netherlands and the United States of America with respect to taxes on income and certain other taxes, signed at Washington April 29, 1948.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The treatment provided in Article XII, paragraph 1, as clarified by reference to Article XXIII, paragraphs 1 and 2, is designed only to preclude discrimination on the ground of nationality and does not, for instance, preclude different treatment of different currencies or the application of residence requirements.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Either Party may impose restrictions on the introduction of foreign capital as may be necessary to protect its monetary reserves as provided in Article XII, paragraph 2, or to prevent serious monetary disturbances arising from speculative financial operations.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;It is understood that for the purposes of Article XVII, paragraph 1, availability of means of patment is considered to be a commercial consideration.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of Article XVII, paragraph 2 (b) and (c), and of Article XIX, paragraph 3, shall not apply to postal services.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;It is understood that the word &quot;cargoes&quot; as used in paragraph 2 and the word &quot;cargo&quot; as used in paragraph 3, of Article XIX, shall be deemed to comprehend passengers as well as goods.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;With reference to Article XXII, paragraph 1 (d), it is understood that it is not the purpose of the security reservation to create a basis for unduly prolonged departures from any provision of the Treaty. On the other hand, each Party determines, according to its own best judgment, the measures deemed necessary to protect its essential security interests.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The provisions of Article XXII, paragraphs, shall apply in the case of Puerto Rico regardless of any change that may take place in its political status.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Article XXIV does not apply to territories under the authority of either Party solely as a military base or by reason of temporary military occupation.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;IN WITNESS WHEREOF the respective Plenipotentiaries have signed the present Protocol and have affixed hereunto their seals.&lt;/p&gt;
&lt;p&gt;DONE in duplicate, in the English and Netherlands languages, both texts being equally authentic, at The Hague, this 27th day of March, one thousand nine hundred fifty-six.&lt;/p&gt;
&lt;p&gt;For the Kingdom of the Netherlands:&lt;/p&gt;
&lt;p&gt;(sd.) J. LUNS   (sd.) J. W. BEYEN&lt;/p&gt;
&lt;p&gt;For the United States of America:&lt;/p&gt;
&lt;p&gt;(sd.) H. FREEMAN MATTHEWS&lt;/p&gt;
&lt;h1 id=&quot;no-i&quot;&gt;No. I&lt;/h1&gt;
&lt;p&gt;MINISTRY OF FOREIGN AFFAIRS&lt;/p&gt;
&lt;p&gt;The Hague, 27th March 1956.&lt;/p&gt;
&lt;p&gt;Excellency:&lt;/p&gt;
&lt;p&gt;We have the honor to refer to the negotiations leading to the conclusion of the Treaty of Friendship, Commerce and Navigation signed this day, during the course of which extensive conversations were held between the representatives of the two countries concerning the most-favored-nation aspects of the Treaty in relation to forwardlooking regional arrangements designed to bring closer cooperation, or integration, among European countries.&lt;/p&gt;
&lt;p&gt;The common view emerging from these conversations is that European regional arrangements which do not involve the raising of barriers of any kind to intercourse with the rest of the world but which are designed to promote peace and prosperity, to expand trade, to increase productivity and to raise standards of living, are mutually advantageous. Accordingly, it is recognized in principle that the Netherlands should continue to be able to participate in European regional arrangements which serve these aims and the broad interests of both Parties, even though the Netherlands may thereunder be obliged to grant some reciprocal advantages to other participating countries which it is unable to grant to non-participating countries.&lt;/p&gt;
&lt;p&gt;It is determined that any necessary reconciliation between the terms of the Treaty and existing European arrangements in which the Netherlands now participates is adequately provided in Article XXII, paragraph 4. It is agreed that, should this provision be insufficient to meet future contingencies, the two Parties will at the request of either Party consult with a view to determining what further adjustments might be necessary. Should such consultation fail to lead to a mutually satisfactory result, either Party, notwithstanding the provisions of Article XXVII, shall be entitled to suspend the operation of particular most-favored-nation provisions of the Treaty to the extent deemed appropriate to the situation, upon giving two months’ written notice to the other Party. With respect to the subject matter of any provision so affected, however, it would be the policy of the Parties to proceed in general as follows: The United States of America would accord to the Kingdom of the Netherlands treatment no less favorable in like situations than that accorded other countries participating in the arrangement in question, and the Kingdom of the Netherlands would accord to the United States of America treatment no less favorable in like situations than that accorded countries not so participating.&lt;/p&gt;
&lt;p&gt;If the above is acceptable to the United States Government, we have the honor to suggest that this note and your Excellency&#39;s reply to that effect shall be considered as constituting an agreement between our two Governments, forming an integral part of the above-mentioned Treaty.&lt;/p&gt;
&lt;p&gt;Please accept, Excellency, the renewed assurances of our highest consideration and esteem.&lt;/p&gt;
&lt;p&gt;(sd.) J. LUNS   (sd.) J. W. BEYEN&lt;/p&gt;
&lt;p&gt;To His Excellency&lt;br&gt;
Mr. H. Freeman Matthews,&lt;br&gt;
Ambassador extraordinary and plenipotentiary&lt;br&gt;
of the United States of America&lt;br&gt;
at The Hague.&lt;/p&gt;
&lt;h1 id=&quot;no-ii&quot;&gt;No. II&lt;/h1&gt;
&lt;p&gt;AMERICAN EMBASSY&lt;/p&gt;
&lt;p&gt;The Hague, March 27, 1956&lt;/p&gt;
&lt;p&gt;Excellencies:&lt;/p&gt;
&lt;p&gt;I have the honor to acknowledge the receipt of your Excellencies’ note of today, which reads as follows:&lt;/p&gt;
&lt;p&gt;&quot;We have the honor to refer to the negotiations lealing to the conclusion of the Treaty of Friendship, Commerce and Navigation signed this day, during the course of which extensive conversations were held between the representatives of the two countries concerning the most-favored-nation aspects of the Treaty in relation to forwardlooking regional arrangements designed to bring closer cooperation, or integration, among European countries.&lt;/p&gt;
&lt;p&gt;&quot;The common view emerging from these conversations is that European regional arrangements which do not involve the raising of barriers of any kind to intercourse with the rest of the world but which are designed to promote peace and prosperity, to expand trade, to increase productivity and to raise standards of living, are mutually advantageous. Accordingly, it is recognized in principle that the Netherlands should continue to be able to participate in European regional arrangements which serve these aims and the broad interests of both Parties, even though the Netherlands may thereunder be obliged to grant some reciprocal advantages to other participating countries which it is unable to grant to non-participating countries.&lt;/p&gt;
&lt;p&gt;&quot;It is determined that any necessary reconciliation between the terms of the Treaty and existing European arrangements in which the Netherlands now participates is adequately provided in #### Article XXII, paragraph 4. It is agreed that, should this provision be insufficient to meet future contingencies, the two Parties will at the request of either Party consult with a view to determining what further adjustments might be necessary. Should such consultation fail to lead to a mutually satisfactory result, either Party, notwithstanding the provisions of #### Article XXVII, shall be entitled to suspend the operation of particular most-favored-nation provisions of the Treaty to the extent deemed appropriate to the situation, upon giving two months&#39; written notice to the other Party. With respect to the subject matter of any provision so affected, however, it would be the policy of the Parties to proceed in general as follows: The United States of America would accord to the Kingdom of the Netherlands treatment no less favorable in like situations than that accorded other countries participating in the arrangement in question, and the Kingdom of the Netherlands would accord to the United States of America treatment no less favorable in like situations than that accorded countries not so participating.&lt;/p&gt;
&lt;p&gt;&quot;If the above is acceptable to the United States Government, we have the honor to suggest that this note and your Excellency&#39;s reply to that effect shall be considered as constituting an agreement between our two Governments, forming an integral part of the above-mentioned Treaty.&quot;&lt;/p&gt;
&lt;p&gt;I have the honor to inform your Excellencies that the contents of your Excellencies&#39; note are acceptable to my Government and I herewith confirm that your Excellencies&#39; note and the present reply thereto shall be considered as constituting an agreement between our two Governments, forming an integral part of the above-mentioned Treaty.&lt;/p&gt;
&lt;p&gt;As your Excellencies are aware, the United States Government welcomes progress in the development of European cooperation and integration insofar as arrangements for cooperation and integration contribute to a freer flow of trade, a more efficient use of manpower and materials, and greater unity. In this connection, it may be recalled that the United States Government has given concrete support to such organizations as the European Coal and Steel Community and concurred in the waiver relative thereto granted by the CONTRACTING PARTIES to the General Agreement on Tariffs and Trade, bearing in mind the benefits expected to accrue from arrangements designed to create a dynamic competitive common market within the Community and to insure sound economic relations between the Community and outside countries. The United States Government is prepared to consider sympathetically in the same spirit other proposals which the Kingdom of the Netherlands might make.&lt;/p&gt;
&lt;p&gt;Please accept, Excellencies, the renewed assurances of my highest consideration and esteem.&lt;/p&gt;
&lt;p&gt;(sd.) H. FREEMAN MATTHEWS&lt;/p&gt;
&lt;p&gt;To Their Excellencies&lt;br&gt;
Mr. J. W. Beyen, Minister of Foreign Affairs, and&lt;br&gt;
Mr. J. M. A. H. Luns, Minister without Portfolio,&lt;br&gt;
at The Hague.&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Digital Cameras with C2PA Support</title>
        <published>2025-08-30T00:00:00+00:00</published>
        <updated>2025-08-30T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/c2pa-camera/"/>
        <id>https://yawnbox.eu/blog/c2pa-camera/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/c2pa-camera/">&lt;p&gt;My domain, c2pa.camera, now redirects here. I&#39;m a security researcher and it&#39;s easier for me to maintain this list on my blog. I maintain this list out of genuine interest in supporting photojournalists like me who want cryptographic verifiability for their critical work. If you have feedback about this list, please email me.&lt;/p&gt;
&lt;p&gt;Please don&#39;t be upset with me for listing the Google Pixel 10. It is a digital camera, it&#39;s below $1000, which matters, in part because it&#39;s now the cheapest device that supports the protocol. You must use the official Google camera app to take advantage of C2PA on any Pixel 10. Another reason why this is significant is because we will not always have our nice camera gear on us when we need to document something. Having the Google Pixel 10 lowers the bar for journalists holding power to account.&lt;/p&gt;
&lt;p&gt;Please read the Coalition for Content Provenance and Authenticity&#39;s &lt;a rel=&quot;external&quot; href=&quot;https://c2pa.org/specifications/specifications/1.4/explainer/Explainer.html&quot;&gt;C2PA Explainer&lt;/a&gt; directly from c2pa.org. The following digital cameras have been advertised as having, or will be getting, support for the C2PA authentication protocol.&lt;/p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Model&lt;/th&gt;&lt;th&gt;Released&lt;/th&gt;&lt;th&gt;Firmware&lt;/th&gt;&lt;th&gt;Reference&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Google Pixel 10&lt;/td&gt;&lt;td&gt;2025 August&lt;/td&gt;&lt;td&gt;any&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://blog.google/products/pixel/tensor-g5-pixel-10/&quot;&gt;Google blog&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Leica SL3-S&lt;/td&gt;&lt;td&gt;2025 January&lt;/td&gt;&lt;td&gt;any&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://leica-camera.com/en-US/photography/content-credentials&quot;&gt;Leica product page&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Sony Alpha 1 II&lt;/td&gt;&lt;td&gt;2024 November&lt;/td&gt;&lt;td&gt;v2.00 update or later&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.sony.eu/presscentre/sony-announces-firmware-updates-for-alpha-1-ii-alpha-1-and-alpha-9-iii&quot;&gt;Sony press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Leica M11-D&lt;/td&gt;&lt;td&gt;2024 September&lt;/td&gt;&lt;td&gt;any&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://leica-camera.com/en-US/photography/content-credentials&quot;&gt;Leica product page&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Canon EOS R1&lt;/td&gt;&lt;td&gt;2024 July&lt;/td&gt;&lt;td&gt;any&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.canon-europe.com/press-centre/press-releases/2025/07/eos-r1-and-eos-r5-mark-ii-powerful-new-firmware-and-system-updates/&quot;&gt;Canon press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Canon EOS R5 Mark II&lt;/td&gt;&lt;td&gt;2024 July&lt;/td&gt;&lt;td&gt;any&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.canon-europe.com/press-centre/press-releases/2025/07/eos-r1-and-eos-r5-mark-ii-powerful-new-firmware-and-system-updates/&quot;&gt;Canon press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Fujifilm X-T50&lt;/td&gt;&lt;td&gt;2024 June&lt;/td&gt;&lt;td&gt;any&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.fujifilm-x.com/de-de/news/pressemeldung-fujifilm-gfx100s-ii/&quot;&gt;Fujifilm press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Nikon Z6 III&lt;/td&gt;&lt;td&gt;2024 June&lt;/td&gt;&lt;td&gt;v2.00 update or later&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.nikon.com/company/news/2025/0827_imaging_01.html&quot;&gt;Nikon press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Fujifilm GFX100S II&lt;/td&gt;&lt;td&gt;2024 May&lt;/td&gt;&lt;td&gt;any&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.fujifilm.com/us/en/news/digital-cameras/fujifilm-introduces-gfx100sii-mirrorless-digital-camera&quot;&gt;Fujifilm press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Sony Alpha 9 III&lt;/td&gt;&lt;td&gt;2024 February&lt;/td&gt;&lt;td&gt;v2.00 update or later&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.sony.eu/presscentre/sony-delivers-highly-anticipated-firmware-updates-including-c2pa-compliancy-and-ensuring-authenticity-of-images&quot;&gt;Sony press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Leica M11-P&lt;/td&gt;&lt;td&gt;2023 October&lt;/td&gt;&lt;td&gt;any&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://leica-camera.com/en-US/photography/content-credentials&quot;&gt;Leica product page&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Sony Alpha 7 IV&lt;/td&gt;&lt;td&gt;2021 December&lt;/td&gt;&lt;td&gt;v3.00 update or later&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.sony.eu/presscentre/sony-delivers-highly-anticipated-firmware-updates-including-c2pa-compliancy-and-ensuring-authenticity-of-images&quot;&gt;Sony press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Sony Alpha 1&lt;/td&gt;&lt;td&gt;2021 January&lt;/td&gt;&lt;td&gt;v2.00 update or later&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.sony.eu/presscentre/sony-delivers-highly-anticipated-firmware-updates-including-c2pa-compliancy-and-ensuring-authenticity-of-images&quot;&gt;Sony press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Sony Alpha 7S III&lt;/td&gt;&lt;td&gt;2020 October&lt;/td&gt;&lt;td&gt;v3.00 update or later&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.sony.eu/presscentre/sony-delivers-highly-anticipated-firmware-updates-including-c2pa-compliancy-and-ensuring-authenticity-of-images&quot;&gt;Sony press release&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br&gt;
&lt;br&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Hacker Event Photography</title>
        <published>2025-08-13T00:00:00+00:00</published>
        <updated>2025-08-13T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/hacker-event-photography/"/>
        <id>https://yawnbox.eu/blog/hacker-event-photography/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/hacker-event-photography/">&lt;h1 id=&quot;intro&quot;&gt;Intro&lt;/h1&gt;
&lt;p&gt;This month, August 2025, I attened &lt;a rel=&quot;external&quot; href=&quot;https://why2025.org/&quot;&gt;WHY2025&lt;/a&gt;. I also volunteered for the Press Team. It was my first hacker camp, and it was the first time I was able to contribute to the hacker community as a photographer.&lt;/p&gt;
&lt;h1 id=&quot;goals&quot;&gt;Goals&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Provide free portrait photography for WHY speakers, and other presenters, such as workshop organizers and DJs.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Maximize privacy and consent: take no shot that has any part of any non-consenting person. Require explicit permission to take photos of the subject, and clearly define the when, where, and how.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;why-not-why&quot;&gt;Why? (not WHY)&lt;/h1&gt;
&lt;p&gt;When I spoke at &lt;a rel=&quot;external&quot; href=&quot;https://defcon.org/html/defcon-26/dc-26-index.html&quot;&gt;DEF CON 26&lt;/a&gt;, I did not have my own professional photographer to capture the critical moment of my public speech and life-long memory in high-quality still media. Worse, I had asked some friends to take shots of me, and there were not many, and the photos taken were not high quality.&lt;/p&gt;
&lt;h1 id=&quot;lessons-leaarned-from-why&quot;&gt;Lessons Leaarned from WHY&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Take HIF (HEIF) files by default. taking 10 - 30 FPS of compressed raw (ARW) leads to way too large of datasets to manage. Perhaps offer ARW if they want to work with compressed raw.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Use appropriate gear, such as high-speed USB, for quick file management - which I did not have.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Use multiple SD/CFexpress cards for easier compartmentalization - which i did not have.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Create scripts for moving the data more quickly between devices/website.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Create a public blog post or advertisement to be clear about the voluntary mission and privacy upfront so there is less ambiguity.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Establish a website that allows easier photo sharing, not just ssh&#39;ing zip files to my blog.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;proposal&quot;&gt;Proposal&lt;/h1&gt;
&lt;p&gt;Having learned a lot from this experieince, and from being a photojournalist at the NATO Summit in The Hague ealier this year, I now want to envolve this idea into an organization for the hacker community. Later this year, I plan to attend CCC in Germany again. This is where I would like to launch this new effort.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Establish as a non-heirarchical community of photojournalists from within the hacker community.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Agree on a not-for-profit mission, vission, and principles.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Attend hacker events around the world, coordinate with event organizers, and advertise to speakers.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Organize at said hacker events to share responsibilities of advertising, communication, scheduling, photojournalism, and data management.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Offer suggestions for subjects to donate money to other not-for-profit community efforts.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;draft-mission-vission-and-principles&quot;&gt;DRAFT Mission, Vission, and Principles&lt;/h1&gt;
&lt;p&gt;&lt;strong&gt;Mission&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;To provide free, high-quality, consent-based photography for speakers, organizers, and performers at hacker events, while protecting individual privacy and empowering the community through visual storytelling.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Vision&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;To build a global, volunteer-driven photojournalist collective that documents hacker culture with integrity.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Principles&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Consent before capture.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Transparency in purpose and process.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Privacy by default. Data is not shared with anyone but the subject. By default, data is deleted after given to the subject, and subjects may opt-in to organization-managed data retention for organizaiton publicity.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Ownership of media is waived and given absolutely to the subject.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;feedback&quot;&gt;Feedback&lt;/h1&gt;
&lt;p&gt;Please provide feedback and let me know if you have interest in this effort.&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;
&lt;p&gt;yawnbox&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Setting up a Wireguard VPN with DNS ad blocking</title>
        <published>2025-05-05T00:00:00+00:00</published>
        <updated>2025-05-05T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/wireguard-dns-ad-blocking/"/>
        <id>https://yawnbox.eu/blog/wireguard-dns-ad-blocking/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/wireguard-dns-ad-blocking/">&lt;h2 id=&quot;overview&quot;&gt;Overview&lt;/h2&gt;
&lt;p&gt;One critical way to improve privacy outcomes when using a single-hop Virtual Private Network (VPN) is to perform Domain Name System (DNS) advertisement (ad) blocking in tandem with a VPN. This article attemps to improve the privacy posture of a single-hop VPN user by setting up a self-hosted Virtual Private Server (VPS) that funtions both as a VPN gateway and as an ad blocking DNS resolver.&lt;/p&gt;
&lt;p&gt;I also want to make clear that when I say &quot;ad blocking,&quot; this technical security feature also means blocking DNS-based web traffic to data brokers when web browsers or phone apps want to upload data directly from devices to data brokers. It&#39;s not just about preventing ads from displaying. This is particularly important when there is background HTTP/HTTPS traffic occuring from phones and computers-- stuff you never see and is not from visiting a web page. Web browser plugins such as uBlock Origin are great. But they only cover the web browser, not everything else that happens on your phone or computer, like traffic generated from apps or from the operating system.&lt;/p&gt;
&lt;h2 id=&quot;virtual-private-server-vps&quot;&gt;Virtual Private Server (VPS)&lt;/h2&gt;
&lt;p&gt;A VPS has exceptionally little privacy since it&#39;s running on someone else&#39;s hardware. VPS operators have real-time access to data in memory, data at rest, and data in motion (network traffic in and out of the VPS). In other words, VPS&#39;s are exceptionally cop-friendly. However, the profit motive of VPS providers is typically selling you a VPS, not profiling you and selling you out to data brokers as is the case with your home Internet Service Provider (ISP.) While hosted services companies do in fact have business relationships with data brokers when using their websites, they probably do not have relationships with data brokers for the general use of their compute and network infrastructure.&lt;/p&gt;
&lt;h2 id=&quot;virtual-private-network-vpn&quot;&gt;Virtual Private Network (VPN)&lt;/h2&gt;
&lt;p&gt;A VPN is not private at all since it&#39;s just moving egress traffic from one ISP to another with no other obfuscation. In real-world practice, a single-hop VPN is as fake as any mainstream web browser&#39;s &quot;private browser mode&quot; from a network perspective. Your home ISP is selling all of the data it has about you to data brokers, including your real IP, your VPN IP, your physical location, and the time/date metdata with your VPN useage. Data brokers always win in this situation; they see when you (your VPN IP) visit websites with absolute confirmation from your ISP of what your physical IP and your virtual IP is so they can trivially correlate all the data to know when and where you go on the HTTP web.&lt;/p&gt;
&lt;h2 id=&quot;the-goal-less-is-more&quot;&gt;The Goal -- Less is more.&lt;/h2&gt;
&lt;p&gt;Combining a single-hop VPN with adblocking aims to increase the cost of surveillance, and to make safer defaults when using personal phones and computers. The theory here is that a VPN with ad blocking will make it so &quot;less&quot; data brokers will be able to see your website visits or collect data about what your devices are doing, and if and when said data brokers obtain metadata about you, &quot;less&quot; data will be captured by them.&lt;/p&gt;
&lt;h2 id=&quot;the-bad&quot;&gt;The Bad&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;A single-hop VPN is still a single-hop VPN. As I&#39;ve mentioned, your ISPs (home internet, mobile internet, etc) know when you&#39;re using a VPN. VPNs are not designed to obfuscate the fact that it&#39;s a VPN, as is the case with &lt;a rel=&quot;external&quot; href=&quot;https://torproject.github.io/manual/circumvention/&quot;&gt;Tor pluggable transports&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;ISPs know your real, physical IP. They know when (time/date) you enable and disable your VPN. They sell all of this data to data brokers, and give it to governments freely. Data brokers can perform easy correlation attacks against other data that they have about you, and other data they will be given from other third-parties in the future.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;ISPs know when and where you physically are. Home-based ISPs serve... your home. That address will never change. Mobile service / cellular ISPs track your movements via cell tower triangulation. Especially with 5G, they can pinpoint you down to feet/meters in accuracy, including movement, in real time.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Ad-blocking is based on block lists. That&#39;s not safety by default, like &lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/counter-surveillance-with-tor/&quot;&gt;with Tor Browser&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;the-good&quot;&gt;The Good&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Using an ad-blocking VPN raises the cost of surveillance by a small, measureable amount.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;A DNS ad-blocking Wireguard tunnel is a whole-device security feature. It is not only affecting a web browser. A system-wide Wireguard tunnel will control web browser web requests, app web requests, and operating system (OS) web requests.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If you employ the use of a Wireguard-client config on your home internet router, you&#39;ll be able to ad-block for things on your home network that cannot use Wireguard. Smart TVs, IoT systems, etc.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Sharing Wiregaurd profiles with friends and family also helps obfuscate who is doing what, since multiple uers will be sharing the same egress IP.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;pi-hole provides a web interface for seeing real-time DNS queries. It allows a user to see what domains are blocked, allows a user to add domains including wildcard domains to a block list, or to safelist domains. This fine grain control also allows users to self-educate about what their devices are doing in near real time.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Mobile network throttling is real. Wireguard protects high-qaulity network streams like from Youtube.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Having a Wireguard server means a user can hand out Wireguard-client profiles to friends and family. Having a Wireguard LAN accross your devices makes it easy to run &quot;local&quot; game servers while allowing remote friends and family to join without exposting game servers to the internet.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Having a Wireguard bastion server gives a user a trusted source IP from which to connect to other inernet-connected servers. This means a user can completely block port 22 on internet-facing servers and simply allow one trusted IP to log in from.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;my-tech-choices&quot;&gt;My tech choices&lt;/h2&gt;
&lt;p&gt;My choice in technologies aims to make it easy (presuming you&#39;re comfortable with linux CLI) to setup and manage stuff:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;OS&lt;/strong&gt;: Ubuntu Server 24.04 or later (because of the built-in firewall app UFW)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;VPN&lt;/strong&gt;: pi-vpn (makes Wireguard easy)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DNS&lt;/strong&gt;: pi-hole (makes DNS ad blocking easy)&lt;/p&gt;
&lt;p&gt;Once setup is complete, a user will have a Wireguard-server (pi-vpn) on the cloud VPS. Free and trustworthy Wireguard-client applications for macOS, Windows, Android, and iOS/iPadOS can all have their own Wireguard profiles. Wireguard-client profiles generated from the Wireguard-server is made easy with pi-vpn. Once a personal device has a valid Wireguard-client profile and is active, all traffic will be tunneled to the user&#39;s Wireguard-server (pi-vpn). In addition, the VPS will also have pi-hole, so all DNS requests made from any device with a user&#39;s Wireguard profile will get filtered at the DNS layer.&lt;/p&gt;
&lt;p&gt;In other words, when a user&#39;s laptop&#39;s web browser makes a DNS request to democracynow.org, the user&#39;s internet will be tunneled to their pi-vpn server where pi-hole also exists. pi-hole will resolve the DNS request, and the user&#39;s web browser will then know what IP address to resolve democracynow.org to, and your web browser will load democracynow.org. When loading democracynow.org, which uses Google Analytics, all of the other web resources loaded from democracynow.org, including those from Google Analytics, also have to make their own DNS requests, all of which will be resolved by your pi-hole server. However, because Google Analytics is block-listed in pi-hole, the DNS response will deny the request, so Google Analystics will not load in your web browser.&lt;/p&gt;
&lt;p&gt;There are also Wi-Fi routers that support Wiregaurd-client profiles. Hardware routers like from &lt;a rel=&quot;external&quot; href=&quot;https://www.gl-inet.com/products/&quot;&gt;GL iNet&lt;/a&gt;, custom-flashed routers with &lt;a rel=&quot;external&quot; href=&quot;https://openwrt.org&quot;&gt;OpenWRT&lt;/a&gt;, and I believe &lt;a rel=&quot;external&quot; href=&quot;https://opnsense.org&quot;&gt;OPNsense&lt;/a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https://www.pfsense.org&quot;&gt;pfSense&lt;/a&gt; both support Wireguard-client configs. This means that you can setup a home router with a Wireguard-client profile, and all internet traffic from all devices in your home will automatically and transparently get ad blocking, even for devices that don&#39;t support Wireguard. Unless of course any of your devices or web browsers are already setup to use DoH or DoT, etc.&lt;/p&gt;
&lt;p&gt;All legacy DNS (53/UDP) requests will remain secure since they will be Wireguard-tunneled to the pi-vpn/pi-hole server.&lt;/p&gt;
&lt;h2 id=&quot;vultr-referal&quot;&gt;Vultr Referal&lt;/h2&gt;
&lt;p&gt;This is not a sponsored post, I just like Vultr. They are like Linode or Digital Ocean, and similairly priced. If you&#39;re interested in trying out Vultr, here is a referal link for $100 when openings a new account: https://www.vultr.com/?ref=7189872. I use their $6 /mo VPS there, including for my own Wireguard + ad blocking VPS that this article is based on.&lt;/p&gt;
&lt;h1 id=&quot;ubuntu-deployment-guide&quot;&gt;Ubuntu Deployment Guide&lt;/h1&gt;
&lt;h2 id=&quot;basic-stuff&quot;&gt;Basic Stuff&lt;/h2&gt;
&lt;p&gt;When setting up a new Ubuntu Linux system on the internet, it&#39;s critical that it&#39;s patched and restarted.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt update &amp;amp;&amp;amp; sudo apt dist-upgrade -V &amp;amp;&amp;amp; sudo apt autoremove -y &amp;amp;&amp;amp; sudo apt autoclean &amp;amp;&amp;amp; sudo shutdown -r now&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Vultr has my public SSH key, an ED25519 key, but I still need to log in with root at first:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ssh root@88.88.88.88&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Make a new user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;adduser username&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Add the new user to the sudo group:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;adduser username sudo&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;If you don&#39;t already have your SSH pubkey in Vultr, you can upload it to your VPS directly from your client:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ssh-copy-id username@88.88.88.88&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Ordinarily I&#39;d harden SSH a bit, but I&#39;m going to skip that in this post since we&#39;re instead going to focus on blocking SSH access.&lt;/p&gt;
&lt;p&gt;Change from the root user to your new username:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;su username&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;setup-pi-vpn-wireguard-and-pi-hole&quot;&gt;Setup pi-vpn (Wireguard) and pi-hole&lt;/h2&gt;
&lt;p&gt;Install pi-vpn first:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;curl -L https://install.pivpn.io | bash&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Setup pi-vpn to operate using your new user, not root or system.&lt;/p&gt;
&lt;p&gt;Setup pi-vpn to use Wireguard.&lt;/p&gt;
&lt;p&gt;Setup pi-vpn to use any port above 1024 that you&#39;d like. Wireguard will configure UFW automatically to allow this port. The default port works fine.&lt;/p&gt;
&lt;p&gt;Setup pi-vpn to use a publicly available DNS server at first, like Quad9. Note: You can later change this by editing Wireguard configs or by reinstalling pi-vpn and setting a custom DNS server.&lt;/p&gt;
&lt;p&gt;Now install pi-hole:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;curl -sSL https://install.pi-hole.net | bash&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Setup pi-hole to operate on the network interface &lt;strong&gt;wg0&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Change the randomly-generated yet short password to something better (you have a password manager, right?):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo pihole setpassword&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;configure-the-firewall-with-ufw&quot;&gt;Configure the Firewall with UFW&lt;/h2&gt;
&lt;p&gt;My Ubuntu 24.04 VPS deployed with UFW enabled and allowing port 22 for remote SHH access. Validate this by looking at the UFW rules:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw status numbered verbose&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;You should see IPv4 and IPv6 rules for 22/tcp. Leave those alone for now, we will delete these SSH rules later.&lt;/p&gt;
&lt;p&gt;If for some reason you do not have the firewall UFW enabled, and in which case SSH is implicitly allowed, explicitly allow SSH access then enable UFW:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw allow 22/tcp&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw start&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Having SSH allowed and blocking all other inbound traffic is essential to safely host your own DNS server and the soon-to-be pi-hole web server.&lt;/p&gt;
&lt;p&gt;Find the network interface name on your VPS. Classically this is &quot;eth0&quot; but for Ubuntu virtual machines it&#39;s usually something else:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ip a&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Here I see &quot;1: lo&quot; (loopback), &quot;2: &lt;strong&gt;enp1s0&lt;/strong&gt;&quot; (virtual machine interface), and &quot;3: &lt;strong&gt;wg0&lt;/strong&gt;&quot; (Wireguard). So enp1s0 is what I need, and we need to configure UFW to allow forwarding traffic from &lt;strong&gt;wg0&lt;/strong&gt; to &lt;strong&gt;enp1s0&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw route allow in on wg0 out on enp1s0&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Next we need to configure UFW to allow SSH (port 22) traffic from wg0 (Wireguard). This is critical so that we can later delete the inbound rules allowing any port 22 access. SSH access to this server will be allowed only when using the Wireguard tunnel to the system:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw allow in on wg0 from any to any port 22 proto tcp&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Next we need to configure UFW to allow legacy DNS (port 53) traffic from Wireguard:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw allow in on wg0 from any to any port 53 proto udp&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;We also need to configure UFW to allow in HTTP (port 80) web traffic from Wireguard so that the pi-hole web interface can be accessed when using Wiregaurd:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw allow in on wg0 from any to any port 80 proto tcp&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Review the UFW rules:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw status verbose&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Once validated, restart UFW:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw reload&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;configure-wireguard-client&quot;&gt;Configure Wireguard-client&lt;/h2&gt;
&lt;p&gt;Check out the &lt;a rel=&quot;external&quot; href=&quot;https://docs.pivpn.io/wireguard/&quot;&gt;Wireguard documentation&lt;/a&gt; for setting up client configs from the Wireguard server. For example:&lt;/p&gt;
&lt;p&gt;Create a client profile:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;pivpn -a&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;View the new client profile QR code, easy for setting up on a phone:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;pivpn -qr&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;For setting up a Wiregaud-client for a laptop or router, view the config and copy+paste it to a new empty tunnel in Wiregaurd-client:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;cat configs/your-client.conf&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;It&#39;s that simple.&lt;/p&gt;
&lt;p&gt;After you add your Wireguard-client config to your device(s), edit the Wireguard-client config by changeing the DNS server to your pi-hole IP. Doing it this way makes it so default Wireguard profiles have working DNS. Users can opt-in to using the pi-hole ad blocking feature. If you want default configs to use the custom DNS, you&#39;ll simply resinstall pi-vpn and select a custom DNS server, and set the same IP as the pi-vpn server. Note: reinstalling pi-vpn will require issuing new Wireguard-client profiles to folks.&lt;/p&gt;
&lt;h2 id=&quot;validation&quot;&gt;Validation&lt;/h2&gt;
&lt;p&gt;Test your Wireguard-client VPN by activiating it on your first device. Check that your egressing out of the Vultr VPS IP by going to &lt;a rel=&quot;external&quot; href=&quot;https://myip.is&quot;&gt;myip.is&lt;/a&gt; in a web browser.&lt;/p&gt;
&lt;p&gt;You should also be able to SSH to your Vultr VPS while using the Wireguard tunnel.&lt;/p&gt;
&lt;p&gt;View the pi-hole web interface in a web browser: http://88.88.88.88/admin (or the Wireguard LAN gateway IP).&lt;/p&gt;
&lt;h2 id=&quot;complete-the-firewall-config&quot;&gt;Complete the Firewall Config&lt;/h2&gt;
&lt;p&gt;Delete any premade SSH rules (change the number based on the rule you want to delete):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw status numbered verbose&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw delete 1&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw reload&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Again, the point here is to remove public SSH access to the system (zero trust). No need for fail2ban or any response-based security measures. Wireguard is the only way in. If things mess up somehow, you&#39;ll always have terminal access via the Vultr web console.&lt;/p&gt;
&lt;p&gt;yawnbox&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Counter-surveillance with Tor</title>
        <published>2025-04-21T00:00:00+00:00</published>
        <updated>2025-04-21T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/counter-surveillance-with-tor/"/>
        <id>https://yawnbox.eu/blog/counter-surveillance-with-tor/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/counter-surveillance-with-tor/">&lt;p&gt;Happy Valentine&#39;s day! In this article I will discuss one simple but powerful strategy for better protecting your privacy.&lt;/p&gt;
&lt;h1 id=&quot;some-problems&quot;&gt;Some Problems&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;News websites are some of the absolute worst when it comes to violating people&#39;s privacy.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Ad-blockers generally work the same way that anti-malware software works. If there&#39;s no definition, or if the heuristic doesn&#39;t appear hostile, the tool won&#39;t block the bad stuff.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;One-hop proxies &lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/wireguard-dns-ad-blocking/#virtual-private-network-vpn&quot;&gt;do not&lt;/a&gt; protect privacy from abusers.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Abusers (news websites, data companies including artificial intelligence companies, stalkers who buy data from data companies, governments, etc) are everywhere. Not just now, but maybe when a new President of the United States takes office, and you&#39;re part of a marginalized and/or abused community.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Once your data is gathered, it&#39;s gone into a thousands black boxes, and thousands of other black box algorithms force content to you or censor content from you in ways you will never, ever know about.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;a-solution&quot;&gt;A Solution&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/nsa-tor-stinks.png&quot; alt=&quot;NSA: Tor Stinks&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I&#39;ve been running Tor relays for over 14 years. Emerald Onion has been online for nearly 8 of those. Emerald Onion would not receive requests for user data from the US federal government if the US federal government had a way to get that data on their own. The NSA wouldn&#39;t have clearly stated (&lt;a rel=&quot;external&quot; href=&quot;https://ia801204.us.archive.org/7/items/nsa-tor-stinks/nsa-tor-stinks.pdf&quot;&gt;Snowden docs&lt;/a&gt;) that they will never be able to mass-deanonymize Tor users if they thought there might be some possibility to do so. And that&#39;s aside from the fact that the NSA is not the threat actor most people need to be worried about. Abusers like data brokers that enable other abusers are not global passive adversaries.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;A global passive adversary is a threat actor who has visibility over a large percentage of the world&#39;s internet traffic, who has the funding to permanently store metadata associated with encrypted traffic, and who has the funding to develop tooling to automate the analysis of said captured traffic.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Problem #2 above is not often understood in the context of Tor Browser. Tor Browser, by default, provides false metadata to all resources loaded in the browser.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;If an ad-blocker doesn&#39;t have a heuristic or definition of a malicious web resource, the ad-blocker will fail you.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If an ad-blocker doesn&#39;t or can&#39;t block HTTP GETs or POSTs to IP addresses without DNS, the ad-blocker will fail you.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If an ad-blocker doesn&#39;t or can&#39;t block protocols like WebRTC or others built into the browser, the ad-blocker will fail you.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Tor Browser, by default, without any configuration or payments for services, blocks or prevents the vast majority of privacy-invasive HTTP risks. Further, ad-blockers don&#39;t change your IP or IP subnet every 10 minutes.&lt;/p&gt;
&lt;h1 id=&quot;safety-by-default&quot;&gt;Safety By Default&lt;/h1&gt;
&lt;p&gt;Take back your power. Find ways to use Tor. Find ways to improve some of your habits. Start changing your habits when interacting with news websites.&lt;/p&gt;
&lt;p&gt;Only ever download Tor Browser from the source: &lt;a rel=&quot;external&quot; href=&quot;http://torproject.org/download/&quot;&gt;http://torproject.org/download/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Tor&#39;s anonymity is most effective when you treat the internet as read-only. Meaning, minimize signing into web services in Tor Browser unless the service you&#39;re using is safe, like most fediverse (Mastodon, etc) instances.&lt;/p&gt;
&lt;p&gt;Yes, Tor Browser has issues accessing many websites online. What you can do to help this situation is to start using websites in Tor Browser that do not block Tor. My biggest source of news is from what is shared on Mastodon. What I do is I log into Mastodon in Tor Browser so that the links that I click from Mastodon open in Tor Browser.&lt;/p&gt;
&lt;p&gt;But now that my news is being opened in Tor Browser by default, how do I assure I can access it?&lt;/p&gt;
&lt;h2 id=&quot;reader-view&quot;&gt;Reader View&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;/images/tor-browser-reader-view.png&quot; alt=&quot;Reader View in Tor Browser&quot; /&gt;&lt;/p&gt;
&lt;p&gt;A simple yet invaluable tool is built into Tor Browser: Reader View.&lt;/p&gt;
&lt;p&gt;Very often, pop-ups about cookies and other web surveillance get in the way of the content we&#39;re trying to read. Simply clicking on Reader View can quickly and effortlessly ignore that and move you straight into a user-friendly reading pane.&lt;/p&gt;
&lt;h2 id=&quot;archive-is&quot;&gt;Archive.is&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;/images/tor-browser-archive-is.png&quot; alt=&quot;Archive.is in Tor Browser&quot; /&gt;&lt;/p&gt;
&lt;p&gt;If a news site doesn&#39;t load in Tor Browser, I can easily copy the link into &lt;a rel=&quot;external&quot; href=&quot;https://archive.is/&quot;&gt;archive.is&lt;/a&gt;. I keep archive.is favorited in my favorite&#39;s bar along with Mastodon. Archive.is is sadly in love with Captchas, but once you move past one, it&#39;s worth it.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Archive.is will commonly have the news articles that you want to read captured, and without paywalls, Javascript, vidoes, and other noise.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If archive.is doesn&#39;t have the article you need, you can have it get it for you. It will take a minute for it to cache the target news article, but once it has it, you can read it. Privately in Tor Browser.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Note: I know it&#39;s tempting, but do not install any browser extensions into Tor Browser. Adding extensions makes your browser more identifiable to surveillance networks.&lt;/p&gt;
&lt;h1 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h1&gt;
&lt;p&gt;These are just some of the simple but powerful ways that I use Tor Browser. The more that I use Tor Browser, the more I am taking back my power to have privacy online.&lt;/p&gt;
&lt;p&gt;Be safe out there!&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>A Collection of Digital Rights Talks</title>
        <published>2025-04-15T00:00:00+00:00</published>
        <updated>2025-04-15T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/a-collection-of-digital-rights-talks/"/>
        <id>https://yawnbox.eu/blog/a-collection-of-digital-rights-talks/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/a-collection-of-digital-rights-talks/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;I&#39;m starting this catalogging project looking at the past ~30 years of interviews, talks, presentations, documentaries, etc on the broad topic of digital rights.&lt;/p&gt;
&lt;p&gt;For each video link, i&#39;m including an explicit &lt;a rel=&quot;external&quot; href=&quot;https://github.com/yt-dlp/yt-dlp&quot;&gt;Youtube Download (yt-dlp)&lt;/a&gt; command to more easily offline-archive the content to allow watching without as much digital surveillance. yt-dlp is not limited to downloading Youtube content.&lt;/p&gt;
&lt;p&gt;For macOS users, &lt;code&gt;brew install yt-dlp&lt;/code&gt; is all you need to install it.&lt;/p&gt;
&lt;h1 id=&quot;video-catalog&quot;&gt;Video Catalog&lt;/h1&gt;
&lt;h2 id=&quot;microsoft-worker-fired-for-israel-protest-cloud-ai-are-the-bombs-bullets-of-the-21st-century&quot;&gt;Microsoft Worker Fired for Israel Protest: &quot;Cloud &amp;amp; AI Are the Bombs &amp;amp; Bullets of the 21st Century&quot;&lt;/h2&gt;
&lt;p&gt;2025 April 11
&lt;br&gt;Vaniya Agrawal, Amy Goodman
&lt;br&gt;Democracy Now!
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=9jY5rbSfh_Y&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;this-is-what-a-digital-coup-looks-like&quot;&gt;This Is What a Digital Coup Looks Like&lt;/h2&gt;
&lt;p&gt;2025 April 9
&lt;br&gt;Carole Cadwalladr
&lt;br&gt;TED
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=TZOoT8AbkNE&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;jon-stewart-maria-ressa-on-the-us-s-authoritarian-slide&quot;&gt;Jon Stewart &amp;amp; Maria Ressa On the US’s Authoritarian Slide&lt;/h2&gt;
&lt;p&gt;2025 March 6
&lt;br&gt;Maria Ressa, Jon Stewart
&lt;br&gt;The Weekly Show with Jon Stewart
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=jsHoX9ZpA_M&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;israel-s-use-of-ai-in-gaza-should-terrify-us-all&quot;&gt;Israel’s use of AI in Gaza should terrify us all&lt;/h2&gt;
&lt;p&gt;2025 February 12
&lt;br&gt;Antony Loewenstein
&lt;br&gt;Middle East Eye
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=xQKgwGPqhVc&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;maria-ressa-speech-at-vatican-hope-comes-from-action&quot;&gt;Maria Ressa speech at Vatican: Hope comes from action&lt;/h2&gt;
&lt;p&gt;2025 January 25
&lt;br&gt;Maria Ressa
&lt;br&gt;Rappler
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=t0kHvIeYN5M&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;big-brother-and-big-data&quot;&gt;Big Brother and Big Data&lt;/h2&gt;
&lt;p&gt;2025 January 14
&lt;br&gt;Barry Friedman
&lt;br&gt;Stanford Law School, Stanford Constitutional Law Center
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=CVSgjIqiAbw&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;maria-ressa-on-meta-scrapping-fact-checking-program-in-the-us&quot;&gt;Maria Ressa on Meta scrapping fact-checking program in the US&lt;/h2&gt;
&lt;p&gt;2025 January 8
&lt;br&gt;Maria Ressa
&lt;br&gt;Rappler, Rappler Talk
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=oGbzkDDdX4s&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-gaza-laboratory-how-battle-tested-ai-is-a-threat-to-the-world&quot;&gt;The Gaza Laboratory: How “battle-tested” AI is a Threat to the World&lt;/h2&gt;
&lt;p&gt;2024 June 13
&lt;br&gt;Antony Loewenstein
&lt;br&gt;7amleh, Palestine Digital Activism Forum 2024
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=DSg4WGBE1ys&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;maria-ressa-delivers-the-commencement-address&quot;&gt;Maria Ressa delivers the Commencement Address&lt;/h2&gt;
&lt;p&gt;2024 May 23
&lt;br&gt;Maria Ressa
&lt;br&gt;Harvard University, Harvard Commencement 2024
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=7dETo7ECQKc&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;courting-censorship&quot;&gt;Courting Censorship&lt;/h2&gt;
&lt;p&gt;2024 May 23
&lt;br&gt;Philip Hamburger
&lt;br&gt;Stanford Law School
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=2PTG1w6Sf0s&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-ai-series-ai-and-surveillance-capitalism&quot;&gt;The AI series: AI and Surveillance Capitalism&lt;/h2&gt;
&lt;p&gt;2024 February 22
&lt;br&gt;Camille Francois, Meredith Whittaker
&lt;br&gt;Al Jazeera English, Studio B: Unscripted
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=iLzQXWq_Sp0&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;ai-and-its-implications-on-elections-nobel-peace-prize-laureate-maria-ressa-in-interview&quot;&gt;AI and its implications on elections: Nobel Peace Prize laureate Maria Ressa in interview&lt;/h2&gt;
&lt;p&gt;2023 December 20
&lt;br&gt;Maria Ressa
&lt;br&gt;DW News
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=u8AUdqpJTcI&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;maria-ressa-how-social-media-uses-free-speech-to-stifle-free-speech&quot;&gt;Maria Ressa: How Social Media Uses Free Speech To Stifle Free Speech&lt;/h2&gt;
&lt;p&gt;2022 November 30
&lt;br&gt;Maria Ressa, Stephen Colbert
&lt;br&gt;The Late Show with Stephen Colbert
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=xpWevZ5yQz8&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;is-big-tech-the-new-empire&quot;&gt;Is Big Tech the New Empire?&lt;/h2&gt;
&lt;p&gt;2020 March 27
&lt;br&gt;Maria Ressa, Christopher Wylie
&lt;br&gt;Al Jazeera English, Studio B: Unscripted
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=7OLUfA6QJlE&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;facebook-s-role-in-brexit-and-the-threat-to-democracy&quot;&gt;Facebook&#39;s role in Brexit — and the threat to democracy&lt;/h2&gt;
&lt;p&gt;2019 April
&lt;br&gt;Carole Cadwalladr
&lt;br&gt;TED
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=OQSMr-3GGvQ&quot;&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;let-s-take-back-the-internet&quot;&gt;Let&#39;s take back the Internet!&lt;/h2&gt;
&lt;p&gt;2011 July 14
&lt;br&gt;Rebecca MacKinnon
&lt;br&gt;TED
&lt;br&gt;&lt;code&gt;yt-dlp &quot;https://www.youtube.com/watch?v=pFDoCLf96Kg&quot;&lt;/code&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>What to do if your phone gets compromised</title>
        <published>2025-03-09T00:00:00+00:00</published>
        <updated>2025-03-09T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/what-to-do-if-your-phone-gets-compromized/"/>
        <id>https://yawnbox.eu/blog/what-to-do-if-your-phone-gets-compromized/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/what-to-do-if-your-phone-gets-compromized/">&lt;h1 id=&quot;intro&quot;&gt;Intro&lt;/h1&gt;
&lt;p&gt;Generally speaking, for Apple iPhone users, &quot;if the concerned person did not get an &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/102174&quot;&gt;Apple cyber mercenary alert&lt;/a&gt;, it&#39;s likely not highly invasive spyware.&quot; -- a Technologist at Amnesty Tech - Security Lab&lt;/p&gt;
&lt;h1 id=&quot;phase-one-shutdown-and-validate&quot;&gt;Phase One - Shutdown and Validate&lt;/h1&gt;
&lt;p&gt;Stay calm and turn off your phone. If possible, remove the battery, or put the phone into a &lt;a rel=&quot;external&quot; href=&quot;https://youtu.be/PlB4LGLtRQM?feature=shared&amp;amp;t=1660&quot;&gt;faraday cage with &amp;gt;60dB of attenuation&lt;/a&gt; to prevent the phone from continuing any network activity even if you think you&#39;ve turned off your phone. The cheapest, quickest method of a DIY faraday cage is with tinfoil and a couple of Zip Lock bags.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Wrap the phone in a layer or two of tinfoil. Wrap it very tightly, and fold the foil over itself and crimp it as tightly as possible. The goal is to minimize any air gaps and to create a complete seal around the device.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Drop that foiled phone into a Zip Lock bag. Zip it up.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Wrap that foiled-then-zipped up phone in one more tight layer or two of tin foil. Make it as tight as possible.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Drop that into another Zip Lock, just to further protect the layers of tinfoil from damage from movement.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The phone needs to get into the hands of a qualified organization who can verify device compromise. Depending on who you are, the field you work in, or depending on the organizations for which you work, there are several organizations who may be able to perform this assessment:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https://securitylab.amnesty.org&quot;&gt;Amnesty International Security Lab&lt;/a&gt;, who published the &lt;a rel=&quot;external&quot; href=&quot;https://docs.mvt.re/en/latest/index.html&quot;&gt;Mobile Verification Toolkit&lt;/a&gt;, has &lt;a rel=&quot;external&quot; href=&quot;https://securitylab.amnesty.org/partners-and-support/&quot;&gt;several regional partners&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https://citizenlab.ca/about/&quot;&gt;Citizen Lab&lt;/a&gt; and Consumer Reports has the &lt;a rel=&quot;external&quot; href=&quot;https://securityplanner.consumerreports.org/tool/emergency-resources&quot;&gt;Security Planner&lt;/a&gt; with links to &lt;a rel=&quot;external&quot; href=&quot;https://www.accessnow.org/help/&quot;&gt;Access Now&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Installing &quot;threat detection&quot; apps do not work, do not do that. Enterprise Mobile Device Management also cannot detect mercenary spyware. Depending on the outcome of a conversation that you have with an above organization, it may be determined that you are low risk, and a full wipe of your phone may be enough to mitigate risk.&lt;/p&gt;
&lt;h1 id=&quot;phase-two-response&quot;&gt;Phase Two - Response&lt;/h1&gt;
&lt;p&gt;If you are a high risk, or it&#39;s been proven that your device has been compromised, it should be presumed that the attacker now has:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;All of the details from everyone in your phone&#39;s Contacts app -- everyone&#39;s name, phone numbers, emails, addresses, birthdate, etc.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;From a safe device or in person, begin to contact the people in your network who have a high risk of also being targets of compromise. This includes immediate family members and loved ones, not just people who are professionally or organizationally related to you. Warn them about what could happen next.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What could happen next:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;1a. The attacker could use contact information copied from your phone to attack the phones of your contacts if remote exploitation is within their threat model. Those high risk people should be provided this guide, stop using their phone, and seek similar &quot;is my phone hacked&quot; services as described above.&lt;/p&gt;
&lt;p&gt;1b. The attacker could pose to be you by social engineering them to divulge information using data taken from #2, #3, #4, and #5 below.&lt;/p&gt;
&lt;p&gt;At the very least, your high risk contacts should be provided instruction on how to enable security features like &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/guide/iphone/use-lockdown-mode-iph049680987/ios&quot;&gt;Lockdown Mode&lt;/a&gt; (iOS), and begin to treat their phone as if it&#39;s an always-on listening microphone and physical location tracking device, until proven otherewise. When in doubt, throw the phone into a faraday cage and forever consider it permanently compromised, and obtain a new phone right away.&lt;/p&gt;
&lt;p&gt;Not only does your network need to be informed about the danger and risks, but you need to validate your identity in a real-time video call with various question and answer challenges from a new, trustworthy device, or better, in person. Establish a trustworthy communication pathway with new devices that have been hardened to reduce the risk of future compromize. Again, consulting the above organizations can help.&lt;/p&gt;
&lt;ol start=&quot;2&quot;&gt;
&lt;li&gt;All of the content and metadata stored in the apps of end to end encrypted (e2ee) messengers.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;It&#39;s important to understand two facts about e2ee messengers:&lt;/p&gt;
&lt;p&gt;2a. e2ee provides security for data in transit. It does not protect against local compromise.&lt;/p&gt;
&lt;p&gt;2b. e2ee should be maximized. Compromising a device, especially remotely, is not cheap or easy.&lt;/p&gt;
&lt;ol start=&quot;3&quot;&gt;
&lt;li&gt;
&lt;p&gt;Any authentication tokens on the compromised device -- authentication into various services and apps -- could have been copied off the device and then used without your knowledge from an attacker-controlled device. In other words: apps you&#39;ve signed into, like Gmail, Facebook, Outlook, etc, all of those apps keep an authentication token within the app&#39;s database to help reauthenticate you into those services anytime you open the app. It&#39;s like a key to open a front door. Those keys can be coppied by an attacker who has compromised your phone. It&#39;s important to go into each of those services from a trustworthy computer and terminate all existing authenticated sessions, if possible.  And of course, reset all of those service&#39;s passwords, 2FA tokens, and the listed email address after said email has been reset and hardened.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Any secrets (passwords, 2FA tokens, passkeys, etc) saved in a password manager -- those should all be considered owned since the attacker likely had system access while the encrypted database was unlocked. It would be critical to go through all of those accounts and perform resets ASAP, even if you weren&#39;t actively signed into those services.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Any locally stored media or documents should be considered copied and out of your control. Content and metadata of media and docs could be used against you in any way the attacker wishes, now or in the future. Blackmail, doxxing, etc are all risks, but that stuff will also be used to learn more about your life and used against you.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;It&#39;s very important to think very critically about what is/was on your phone and think: if I were the attacker, what would I do, how would I use all of this data in order to cause futher damage or compromise. Create a list and turn that list into an action plan to help mitigate high, then medium, then low risks, depending on your threat model.&lt;/p&gt;
&lt;h1 id=&quot;phase-three-prevention&quot;&gt;Phase Three - Prevention&lt;/h1&gt;
&lt;p&gt;It&#39;s important to obtain a new device and make sure it is setup in a way that won&#39;t lead to further compromise. Depending on how the original compromise happened, there are certain steps one should take to make sure they cannot be compromised again. For example, if it was a remote attack, setting up Lockdown Mode and restarting a new iPhone before a SIM is inserted is important.&lt;/p&gt;
&lt;p&gt;What should be obvious with all of this is that our phone&#39;s are treasure troves of our lives. High risk people may want to proactively minimize their risk by keeping less data on their phones. Compartmentalization and data minimization are important security practices that can only protect you before a compromise.&lt;/p&gt;
&lt;p&gt;How to setup a secure phone is out of scope of this article, but again, seek the assistance of trustworthy organizations that I&#39;ve listed above.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat modeling Starlink satellite cellular risks</title>
        <published>2024-12-17T00:00:00+00:00</published>
        <updated>2024-12-17T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/threat-modeling-starlink-satellite-cellular-risks/"/>
        <id>https://yawnbox.eu/blog/threat-modeling-starlink-satellite-cellular-risks/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/threat-modeling-starlink-satellite-cellular-risks/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;In this article, I&#39;m going to discuss Starlink satellite capabilities because of how prolific they are. As you may know, I&#39;ve been writing about the technical risks associated with cell phones for the past 10+ years. What I discuss here is not limited to SpaceX Starlink and are capabilities probably used by any well-funded threat actor with modern, &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Low_Earth_orbit&quot;&gt;low Earth orbit&lt;/a&gt; (LEO) satellites.&lt;/p&gt;
&lt;p&gt;We already know that &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/SpaceX&quot;&gt;SpaceX&lt;/a&gt;, an American company, &lt;a rel=&quot;external&quot; href=&quot;https://www.reuters.com/technology/space/musks-spacex-is-building-spy-satellite-network-us-intelligence-agency-sources-2024-03-16/&quot;&gt;cooperates with US intelligence agencies&lt;/a&gt;, so these capabilities are shared across &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Five_Eyes&quot;&gt;FVEY&lt;/a&gt; entities. Read more about &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/SpaceX_Starshield&quot;&gt;Starshield&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This content was going to be published in my &lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/how-to-use-an-ipad-as-a-secure-calling-and-messaging-device/&quot;&gt;How to Use an iPad as a Secure Calling and Messaging Device&lt;/a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/how-to-use-an-pixel-tablet-as-a-secure-calling-and-messaging-device/&quot;&gt;How to Use a Pixel Tablet as a Secure Calling and Messaging Device&lt;/a&gt; publications to further convince high-risk people to abandon cell phones. However, this research and risk analysis, using Starlink as an example, is so complex and nuanced that it fell out of scope of those articles.&lt;/p&gt;
&lt;p&gt;Given the outcome of the November 2024 US election, it&#39;s not difficult to think that Starlink satellites might be used to target people while sweeping up data about American citizens. While SpaceX is not any worse than a typical, terrestrial cellular provider in terms of technical privacy and security risks, there are a lot of terrestrial places where there is no cell service, places where undocumented people live. &lt;a rel=&quot;external&quot; href=&quot;https://arstechnica.com/tech-policy/2024/12/t-mobile-opens-beta-registration-for-starlink-enabled-cell-phone-service/&quot;&gt;Per T-mobile&lt;/a&gt; on December 16th 2024:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Coming on the heels of FCC approval, T-Mobile has opened registration for a beta program for T-Mobile Starlink, a direct-to-cell satellite service that will help eliminate dead zones by providing coverage for the 500,000 square miles of land in the United States not covered by earth-bound cell towers.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1 id=&quot;terrestrial-location-tracking&quot;&gt;Terrestrial Location Tracking&lt;/h1&gt;
&lt;p&gt;SpaceX uses features of the LTE protocol that were intended for high speed trains in order to offer Direct to Cell coverage. With &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Doppler_shift_compensation&quot;&gt;Doppler shift compensation&lt;/a&gt; from a Starlink satellite, SpaceX can make any modern LTE phone think that the timing and Doppler is within specification in order to establish communication between satellite and cellular baseband devices.&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.frequencycheck.com/bands/lte-band-25-1900&quot;&gt;Band 25&lt;/a&gt; (&lt;a rel=&quot;external&quot; href=&quot;https://www.t-mobile.com/business/industry-solutions/connected-vehicle-network/direct-to-cell-communications-in-remote-areas&quot;&gt;1900 MHz&lt;/a&gt;) is used by Starlink satellites in the United States. &lt;a rel=&quot;external&quot; href=&quot;https://docs.fcc.gov/public/attachments/DA-24-1193A1.pdf&quot;&gt;Band 7&lt;/a&gt; (&lt;a rel=&quot;external&quot; href=&quot;https://www.frequencycheck.com/bands/lte-band-7-2600&quot;&gt;2600 MHz&lt;/a&gt;) is used outside the United States, but SpaceX is more broadly approved for 1429-2690 MHz globally. Any cell phone or cellular tablet must support &lt;a rel=&quot;external&quot; href=&quot;https://www.3gpp.org/specifications-technologies/releases/release-13&quot;&gt;3GPP Release 13&lt;/a&gt; or newer (requires &lt;a rel=&quot;external&quot; href=&quot;https://www.nrexplained.com/ta&quot;&gt;Timing Advance&lt;/a&gt;) in order to connect to Starlink services. These 3G/LTE and 4G/LTE devices can communicate with Starlink satellites, and SpaceX and other companies are working on 5G methods. 5G has non-terrestrial networking built into the protocol so it won&#39;t be long before 5G is supported.&lt;/p&gt;
&lt;p&gt;Cellular baseband devices typically maintain only one active connection at a time, either to a terrestrial cell tower or to a satellite. In most scenarios, a &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Mobile_network_operator&quot;&gt;mobile network operator&lt;/a&gt; (MNO) subscriber—-such as a T-Mobile user—-whose phone is configured for satellite connectivity will attempt to connect to SpaceX satellites when terrestrial tower coverage is lost, ensuring the device can maintain a cellular connection.&lt;/p&gt;
&lt;p&gt;Prior to November 26th 2024, SpaceX was not yet authorized to service these requests. SpaceX fielded and rejected hundreds of thousands of cellular attach requests per day from T-mobile cellular tablets and phones and logged those connection attempts. Logging includes hardware identifiers, network data, and physical location data associated with all requests. This is also true for any 3GPP R13 cell device that supports satellite connectivity, globally, for any carrier. SpaceX can negotiate, reject, and log all connection attempts when a device loses terrestrial service.&lt;/p&gt;
&lt;p&gt;As of November 26th 2024, &lt;a rel=&quot;external&quot; href=&quot;https://docs.fcc.gov/public/attachments/DA-24-1193A1.pdf&quot;&gt;the FCC has authorized&lt;/a&gt; SpaceX to field T-mobile subscriber&#39;s requests in the United States. If a user&#39;s device is not authorized, wether or not it&#39;s from a T-mobile subscribed device or not, SpaceX still gets device, network, and physical location metadata. As of writing, T-mobile has &lt;a rel=&quot;external&quot; href=&quot;https://www.t-mobile.com/coverage/satellite-phone-service&quot;&gt;opened a public beta&lt;/a&gt; of subscribers to begin testing Starlink&#39;s offering.&lt;/p&gt;
&lt;p&gt;Like &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Dirtbox_(cell_phone)&quot;&gt;dirtboxes&lt;/a&gt;, satellite cells can force a user&#39;s device to connect to it directly, or force all users within said satellite&#39;s broadcast beam, depending on which &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Public_land_mobile_network&quot;&gt;public land mobile network&lt;/a&gt; (PLMN) it broadcasts. It can do this in one of two ways:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Starlink satellites can present itself as a SpaceX PLMN directly to a target device, or&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Starlink satellites can pretend to be a specific MNO tower, like as a T-mobile tower, directly to a target device. This can be done in a way that, to a user, it appears as though they are connected to a T-mobile cell tower, but in reality they will have a direct connection to a Starlink satellite.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In October 2024, the FCC allowed SpaceX to temporarily &lt;a rel=&quot;external&quot; href=&quot;https://archive.ph/RGdiz&quot;&gt;inject cell service&lt;/a&gt; in areas affected by Hurricane Helene and Hurricane Milton.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;T-Mobile customers in areas affected by both hurricanes will be able to send SMS texts over Starlink DTC /D2D (direct-to-device) satellites at no cost, according to SpaceX.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The greatest location tracking concern with threat actors such as SpaceX and their partners is being outside and visible from above. Some companies already have millimeter-resolution &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Synthetic-aperture_radar&quot;&gt;synthetic-aperture radars&lt;/a&gt; (SAR) performing multiple imaging passes per day. SpaceX observability is lower, but software capabilities to watch devices of interest is a significant risk.&lt;/p&gt;
&lt;h1 id=&quot;satellite-limitations&quot;&gt;Satellite Limitations&lt;/h1&gt;
&lt;p&gt;Certain limitations (physics) apply that don&#39;t apply to terrestrial cell towers. Any one Starlink satellite uses ~250 focused cellular beams that are formed and pointed using a phased array antenna. They can either be targeted to a fixed point on the surface of the Earth, or given a path to follow (a sliding beam).&lt;/p&gt;
&lt;p&gt;The timing between users and satellites cannot be more than a couple hundreds microseconds, which limits the beam size and scan angle of a satellite. In other words, the beams can&#39;t be too big, and Starlink satellites can&#39;t service devices at too low of elevation angles. But the Starlink network is being made to never have gaps in coverage.&lt;/p&gt;
&lt;p&gt;Like terrestrial cell networks, satellite cellular operators are acutely aware of which &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/ENodeB&quot;&gt;eNodeB&lt;/a&gt; a user&#39;s cellular device is connected to. Starlink satellites orbit at &lt;a rel=&quot;external&quot; href=&quot;https://api.starlink.com/public-files/DIRECT_TO_CELL_FIRST_TEXT_UPDATE.pdf&quot;&gt;speeds of 7.7 km/s&lt;/a&gt;, so their beams slide across the Earth&#39;s surface at a slower rate. SpaceX is aware of which beam is on which area.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;For high-gain terrestrial antennas, SpaceX can estimate where a device is within a roughly 10 to 20 km radius within any beam. With multiple passes, SpaceX could triangulate a finer point of a stationary or moving device.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;For low powered cell phones, it&#39;s only possible for SpaceX to track devices within a satellite&#39;s beam.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There are many conditions that impede connectivity and thus surveillance of LEO satellites. Being under heavy ground cover such as dense forests, high atmospheric moisture, or the lack of line-of-site are challenges for LEO satellites. Baseband devices inside buildings can sometimes establish a link with Starlink satellites but you&#39;d need to be near a window.&lt;/p&gt;
&lt;h1 id=&quot;satellite-attacks&quot;&gt;Satellite Attacks&lt;/h1&gt;
&lt;p&gt;Each of the Starlink&#39;s beams has its own cell. So if a satellite wanted to mess with transport protocols, any one satellite could limit disruption to any covered area by manipulating cellular coverage on a per-beam basis. Further, static (non-sliding) beams perform better.&lt;/p&gt;
&lt;p&gt;Even simple attacks, like disruption attacks that intentionally maintain a satellite connection in order to drain a target&#39;s battery is possible.&lt;/p&gt;
&lt;p&gt;Lastly, cellular basebands are extremely trusting in order to support interoperability. Satellite LTE connectivity suffers from the same attacks that SS7 and Diameter allows. If SpaceX wanted to attack any particular device, they would likely utilize existing SS7/Diameter networks.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Add more profile metadata fields to Mastodon</title>
        <published>2024-12-06T00:00:00+00:00</published>
        <updated>2024-12-06T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/add-more-profile-metadata-fields-to-mastodon/"/>
        <id>https://yawnbox.eu/blog/add-more-profile-metadata-fields-to-mastodon/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/add-more-profile-metadata-fields-to-mastodon/">&lt;meta name=&quot;fediverse:creator&quot; content=&quot;@yawnbox@disobey.net&quot;&gt;
&lt;h1 id=&quot;join-our-open-fedi-relay&quot;&gt;Join our open fedi relay!&lt;/h1&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://relay.disobey.net/&quot;&gt;relay.disobey.net&lt;/a&gt;&lt;/p&gt;
&lt;h1 id=&quot;related-documentation&quot;&gt;Related Documentation&lt;/h1&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/change-mastodon-post-and-bio-max-count/&quot;&gt;Increase the post and bio character limit in Mastodon&lt;/a&gt;&lt;/p&gt;
&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;I run the &lt;a rel=&quot;external&quot; href=&quot;https://disobey.net/&quot;&gt;disobey.net&lt;/a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https://nautical.social/home&quot;&gt;nautical.social&lt;/a&gt; Mastodon instances. I self-host these as standalone servers built from source, not Docker. This configuration change I&#39;ve only performed since upgrading to Mastodon v4.3.1, so I cannot guarantee that it will work on Mastodon v4.2.x or earlier.&lt;/p&gt;
&lt;p&gt;All file editing below is from my Mastodon root directory, &quot;&lt;strong&gt;~/live&lt;/strong&gt;&quot;.&lt;/p&gt;
&lt;h1 id=&quot;directions-for-mastodon-v4-3-2&quot;&gt;Directions for Mastodon v4.3.2&lt;/h1&gt;
&lt;p&gt;You will only need to edit &lt;a rel=&quot;external&quot; href=&quot;https://github.com/mastodon/mastodon/blob/main/app/models/account.rb#L70&quot;&gt;this&lt;/a&gt; one file:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim app/models/account.rb&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Find the &quot;DEFAULT_FIELDS_SIZE&quot; line. Change the &quot;4&quot; at the end of that line to however many fields you&#39;d like:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DEFAULT_FIELDS_SIZE = 4&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I changed it to 9 fields:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/account-profile-field-number.jpg&quot; alt=&quot;edit number of profile fields screenshot&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Save and quit, if you&#39;re using vim:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;:wq&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;finally&quot;&gt;Finally&lt;/h1&gt;
&lt;p&gt;As the &lt;strong&gt;mastodon&lt;/strong&gt; user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;RAILS_ENV=production bundle exec rails assets:precompile&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;As &lt;strong&gt;root&lt;/strong&gt; user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemctl restart mastodon-web mastodon-sidekiq mastodon-streaming&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;validation&quot;&gt;Validation&lt;/h1&gt;
&lt;p&gt;After the restart, you&#39;ll see this in https://domain.tld/settings/profile:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/account-profile-fields.jpg&quot; alt=&quot;profile fields screenshot&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Thanks for making the fediverse better!&lt;/p&gt;
&lt;h1 id=&quot;notes&quot;&gt;Notes&lt;/h1&gt;
&lt;p&gt;Ivory (mobile app) does not currently recognize any more fields than 4, but any desktop browser user will still see them. So it&#39;s my opinion that after the 4th field, less important links/text should go there. It does not break Ivory, it&#39;s just an inconvenience. I hope Ivory fixes it!&lt;/p&gt;
&lt;br&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>My #TA3M talk on Tor, Onion Services, and why browser plug-ins and VPNs don’t protect your privacy</title>
        <published>2024-11-10T00:00:00+00:00</published>
        <updated>2024-11-10T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/ta3m-why-browser-plugins-and-vpn-dont-protect-your-privacy/"/>
        <id>https://yawnbox.eu/blog/ta3m-why-browser-plugins-and-vpn-dont-protect-your-privacy/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/ta3m-why-browser-plugins-and-vpn-dont-protect-your-privacy/">&lt;h1 id=&quot;related-articles&quot;&gt;Related Articles&lt;/h1&gt;
&lt;p&gt;In my &lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/wireguard-dns-ad-blocking/&quot;&gt;Setting up a Wireguard VPN with DNS ad blocking&lt;/a&gt; article, I discuss some more advanced issues with VPNs along with some possible mitigations.&lt;/p&gt;
&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.eff.org/event/techno-activism-third-mondays-1&quot;&gt;Techno-Activism Third Mondays&lt;/a&gt; (TA3M) is a meetup I helped coordinate in Seattle and occasionally presented in.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Techno-Activism Third Mondays (TA3M) are informal meetups that occur on the same date in many cities worldwide. It is designed to connect techno-activists and hacktivists who work on or with circumvention tools, and/or are interested in anti-censorship and anti-surveillance technology. Currently, TA3M are held in New York, Washington, DC, Amsterdam, Portland, Tokyo, and more.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This presentation was given at the University of Washington on &lt;strong&gt;January 18, 2016&lt;/strong&gt; and the original slide deck is available on &lt;a rel=&quot;external&quot; href=&quot;https://docs.google.com/presentation/d/1fuSLWxT44WkxqIWShLu5fIKP7bWN2nuGPRe9fyn78SE/edit#slide=id.g820f0d0a2_0_175&quot;&gt;Google Docs&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This presentation is geared toward helping people understand some basics about VPNs and Tor.&lt;/p&gt;
&lt;p&gt;Please remember 2016: there were still many very slow adopters of basic HTTPS on mainstream websites. That&#39;s why one slide below says things like &quot;&lt;strong&gt;http&lt;/strong&gt;://bbc.co.uk&quot; and not &quot;&lt;strong&gt;https&lt;/strong&gt;://bbc.co.uk&quot; -- because I&#39;m explaining the differences between a HTTP connection without TLS encryption, and one with TLS encryption. Today, in 2024, thankfully, the BBC uses HTTPS.&lt;/p&gt;
&lt;p&gt;Two interesting facts about this presentation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;At the time, in January 2016, I was an intern at the ACLU of Washington, consulting on their communication practices, and helping deploy SecureDrop for secure and anonymous legal intake.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;A former Executive Director of The Tor Project was in the audience of this TA3M, and they later approached me to offer me a job as their full-time Grant Writer.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;if-you-re-not-using-tor-you-re-doing-it-wrong&quot;&gt;If you&#39;re not using Tor you&#39;re doing it wrong&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-01.jpg&quot; alt=&quot;Alt Text: Slide 01&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This quote is from a November 2015 interview of Edward Snowden by Micah Lee in Moscow titled, &quot;&lt;a rel=&quot;external&quot; href=&quot;https://theintercept.com/2015/11/12/edward-snowden-explains-how-to-reclaim-your-privacy/&quot;&gt;Edward Snowden Explains How To Reclaim Your Privacy&lt;/a&gt;&quot;.&lt;/p&gt;
&lt;p&gt;This talk is for everyone. You don’t need to be an activist, journalist or a lawyer to need Tor. Even the most boring, uninteresting person in the world should be defending their right to privacy and freedom of expression by using Tor.&lt;/p&gt;
&lt;p&gt;The aim of this ~30 minute talk (plus Q/A) is to help make it easier for people to understand Tor and Onion Services. It is not a highly technical talk, but it is technical. I expect that users that wish to gain knowledge of how technical systems work, to take advantage of them, must learn some basic technical material.&lt;/p&gt;
&lt;p&gt;My talk discusses how the Tor network works to protect your privacy by juxtaposing plain HTTP, HTTPS, and also mainstream VPN technology. I will be discussing why the advertising industry is an even greater threat than even the NSA to most people, and why VPNs just can’t cut it. Lastly, I will discuss how Onion services is a paradigm shift from standard client-server communications, how it works to protect your privacy, and why Onion services is an important application for service providers concerned about uptime and security.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;http-postcard&quot;&gt;HTTP / Postcard&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-03.jpg&quot; alt=&quot;Alt Text: Slide 03&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Sending a postcard in the mail allows anyone that handles the postcard to view and retain both the metadata:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;who&lt;/li&gt;
&lt;li&gt;what&lt;/li&gt;
&lt;li&gt;where&lt;/li&gt;
&lt;li&gt;when&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;and any content:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;personal messages to the receiver&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Plain HTTP over the internet is no different, except that digital content is much easier and cheaper to collect and store.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-04.jpg&quot; alt=&quot;Alt Text: Slide 04&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This clear-text content and metadata is represented here in purple. It is completely defenseless in transit. Anyone connecting to &lt;strong&gt;http://bbc.co.uk&lt;/strong&gt; allows any network operator between you and the BBC service provider to view, retain, and maybe even change the metadata or content in transit.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;https-letter&quot;&gt;HTTPS / letter&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-05.jpg&quot; alt=&quot;Alt Text: Slide 05&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Sending a letter in the mail has one layer of protection, the envelope, and is analogous to HTTPS. The NSA considers HTTPS encrypted traffic “clear text” because metadata is still clear text, and a lot can be learned about the content of HTTPS encrypted traffic through automated analysis. NSA can also make assumptions about what content is in the TLS-encrypted data with captured HTTPS traffic.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-06.jpg&quot; alt=&quot;Alt Text: Slide 06&quot; /&gt;&lt;/p&gt;
&lt;p&gt;HTTPS is two different protocols: HTTP + TLS. TLS is basically a encrypted tunnel for HTTP traffic to go through. Combined, it&#39;s called HTTPS.&lt;/p&gt;
&lt;p&gt;HTTPS protected content is represented here by a red circle protecting the purple content at the center. Connecting to &lt;strong&gt;https://yandex.ru&lt;/strong&gt;--even though encrypted with TLS--still divulges a great deal of information (metadata) to anyone handling your traffic as it traverses the Internet.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;virtual-private-network-vpn-a-1-hop-proxy&quot;&gt;Virtual Private Network (VPN): a 1-hop proxy&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-07.jpg&quot; alt=&quot;Alt Text: Slide 07&quot; /&gt;&lt;/p&gt;
&lt;p&gt;VPNs are typically one-hop proxies. It is possible to set up your own multi-hop VPN proxy, just like you can set up your own private Tor network if you have the time, expertise, and money. But mainstream VPN providers, to keep the time it takes to send your traffic back and forth across the Internet, only use one proxy. In other words, VPN providers, to keep most people happy, focus on speed rather than privacy.&lt;/p&gt;
&lt;p&gt;Purchasing a private mailbox (PO Box, etc) from a UPS store is analogous to purchasing VPN service from a provider. You are paying someone to “one-hop” proxy your mail so that the destination of your mail cannot know your real home address.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;vpn-postcard&quot;&gt;VPN / postcard&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-08.jpg&quot; alt=&quot;Alt Text: Slide 08&quot; /&gt;&lt;/p&gt;
&lt;p&gt;In this example, you are using the Ipredator (ipredator.se) VPN service provider in order to connect to &lt;strong&gt;http://amazon.com&lt;/strong&gt;. (2016) Amazon still does not provide transport security and thus content privacy for users of their service when searching for products to buy. Your Amazon-bound Internet traffic has one layer of protection, the orange circle, only up until the VPN service provider. Once your Amazon-bound traffic leaves the VPN provider (the one-and-only one-hop proxy), Amazon searches are as naked as postcards to the people handling that internet traffic.&lt;/p&gt;
&lt;p&gt;If network adversaries, observing your Amazon searches somewhere between the VPN provider and Amazon, may also be able to determine who is doing the searches based on the content of the internet traffic. These Amazon searches are just like sending postcards in the mail. Said adversaries can view, record, and change any of the metadata or content.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;vpn-letter&quot;&gt;VPN / letter&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-09.jpg&quot; alt=&quot;Alt Text: Slide 09&quot; /&gt;&lt;/p&gt;
&lt;p&gt;In this example, when connecting to &lt;strong&gt;https://wikipedia.org&lt;/strong&gt; and using the Ipredator VPN service, the data (purple) is protected by by a layer of TLS (red) and also the VPN (orange). Once the Wikipedia-bound internet traffic is proxied by Ipredator, it loses the VPN-encrypted (orange) layer, and your traffic’s content is still protected by Wikipedia’s TLS-encrypted (red) layer.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;vpn-circuits&quot;&gt;VPN circuits&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-10.jpg&quot; alt=&quot;Alt Text: Slide 10&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Remember, VPNs are one-hop proxies. The “circuit” that is made between you and the VPN service provider is static — the operator and the IP network (called an IP subnet) never changes. The “IP subnet” of the VPN provider determines the IP address that your Internet traffic uses and is constrained by the pool of available IP addresses the VPN provider has available.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;For example: If your home network has 192.168.1.0/24 assigned for all of the computers in your house, then any computer in your network can only ever be 192.168.1.2 - 192.168.1.254. I don&#39;t want to get into the details of IP subnetting, I just want to be clear about how there are only 253 usable IP addresses in that IP subnet, .2 - .254. All VPN providers on Earth have limited IP networks.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The one-hop proxy circuit design is purposeful in order to maintain minimal latency (the time it takes for your traffic to reach the VPN provider), and to maximize bandwidth (how much you can download or upload per second).
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;the-onion-router-a-3-hop-proxy&quot;&gt;The onion router: a 3-hop proxy&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-11.jpg&quot; alt=&quot;Alt Text: Slide 11&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Tor is more complex and can generally be described as a three-hop proxy when someone is using Tor Browser to connect to a normal website. It would be like purchasing PO BOX services from three different, globally diverse mail proxy service providers, and each of those providers automatically works with each other to relay your mail to maximally protect your home address and maybe even your identity.&lt;/p&gt;
&lt;p&gt;When sending mail communications:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;the first mail proxy knows who you are and also knows who the second mail proxy is.&lt;/li&gt;
&lt;li&gt;The second mail proxy only knows who the first and third mail proxies are.&lt;/li&gt;
&lt;li&gt;By the time your mail gets to the third and final mail proxy, your home address is not in any of the metadata that is destined for the recipient.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Unless you disclosed your identity in the content of your communications, the recipient cannot know your identity, either.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;tor-postcard&quot;&gt;Tor / postcard&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-12.jpg&quot; alt=&quot;Alt Text: Slide 12&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Now let&#39;s look at an example of talking to (2016) &lt;strong&gt;http://ebay.com&lt;/strong&gt; with Tor Browser.&lt;/p&gt;
&lt;p&gt;Tor encrypts your Ebay-destined traffic in three layers before leaving your computer.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Green circle: the Tor encrypted traffic from your computer to the Tor guard relay. The guard relay removes this first layer of encryption.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Yellow circle: the Tor encrypted traffic from the guard relay to the middle relay. The middle relay removes the second layer of encryption.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Orange circle: the Tor encrypted traffic from the middle relay to the exit relay. The exit relay removes the last layer of encryption and sends your traffic on to Ebay. Naked.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Connecting to &lt;strong&gt;http://ebay.com&lt;/strong&gt; over Tor and searching Ebay does not disclose your IP address or your identity unless you log in to Ebay. Logging in to Ebay would disclose your identity to Ebay and thus may disclose the probability of your physical location if you gave Ebay or PayPal your home address as a shipping destination. If you browse Ebay without logging in but search for things that could allow an adversary to identify who is doing the searches, then you may disclose your identity that way, too.&lt;/p&gt;
&lt;p&gt;If network adversaries observing the Ebay searches somewhere between the Tor exit relay and Ebay may also be able to determine who is doing the searches based on the content of the Internet traffic, because these Ebay searches are just like sending postcards in the mail. Said adversaries can view, record, and change any of the metadata or content.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;tor-letter&quot;&gt;Tor / letter&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-13.jpg&quot; alt=&quot;Alt Text: Slide 13&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Now let&#39;s look at an example of talking to (2016) &lt;strong&gt;https://twitter.com&lt;/strong&gt; with Tor Browser.&lt;/p&gt;
&lt;p&gt;Tor encrypts your Twitter-destined traffic in three layers before leaving your computer. Then, because Twitter requires that you use HTTPS to connect to Twitter, the first connection to Twitter establishes TLS (red), and then all of your Twitter-bound traffic will be encrypted in four layers of encryption.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Green circle: the Tor encrypted traffic from your computer to the Tor guard relay. The guard relay removes this first layer of encryption.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Yellow circle: the Tor encrypted traffic from the guard relay to the middle relay. The middle relay removes the second layer of encryption.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Orange circle: the Tor encrypted traffic from the middle relay to the exit relay. The exit relay removes the last layer of encryption and sends your traffic on to Twitter. Because of HTTPS, the content of your Twitter-bound traffic is still protected.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Connecting to &lt;strong&gt;https://twitter.com&lt;/strong&gt; over Tor and searching Twitter does not disclose your IP address or your identity unless you log in to Twitter. Logging in to Twitter would disclose your identity to Twitter. If you browse Twitter without logging in but search for things that could allow an adversary to identify who is doing the searches, then you may disclose your identity that way, too.&lt;/p&gt;
&lt;p&gt;Network adversaries observing Twitter searches somewhere between the Tor exit relay and Twitter can not determine who is doing the searches, because these searches are like letters in the mail. Said adversaries can still view and record any of the metadata but not the content.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;tor-circuits&quot;&gt;Tor circuits&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-14.jpg&quot; alt=&quot;Alt Text: Slide 14&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Unlike VPN circuits, Tor circuits are generated randomly by your local Tor client. In addition to Tor circuit randomness when starting Tor Browser, circuits are automatically and randomly changed every 10 minutes. Another feature of Tor Browser is that opening a new tab will generate a new circuit for that tab.&lt;/p&gt;
&lt;p&gt;The downsides of using Tor is that, due to the required use of three (probably) geographically diverse hops, each of which likely has limited bandwidth, a high-latency and low-bandwidth experience is possible.&lt;/p&gt;
&lt;p&gt;This is more of a positive than a negative, especially versus a typical VPN, but a Tor user must trust a random selection of roughly 2,000 guard relay operators and roughly 1,000 exit relay operators per circuit. Further, the Tor specification requires that relays belonging to the same operator cannot be used within the same circuit, presuming any given volunteer operator is not using significantly different (/16) IP subnets.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-15.jpg&quot; alt=&quot;Alt Text: Slide 15&quot; /&gt;&lt;/p&gt;
&lt;p&gt;By now, it should be clear that the number of relay operators is critical to the success of Tor and its users. Similarly, because all Tor traffic generally looks the same, it is similarly critical for the success of the Tor network for there to be a high number of users and services, including Onion services.&lt;/p&gt;
&lt;p&gt;Most purchasable Internet security services are built using a controlled set of infrastructure. This is a form of centralization. Tor is powerful exclusively because of the decentralized nature of the Tor network and the requirements of the Tor protocol. No other centralized security service can come close to having all of the security and privacy properties as Tor.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;ads-vs-nsa&quot;&gt;Ads vs. NSA&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-16.jpg&quot; alt=&quot;Alt Text: Slide 16&quot; /&gt;&lt;/p&gt;
&lt;p&gt;We know that there are two active and constant threats to the internet and thus to its users: governments with intelligence agencies that are bent on the presumption that mass surveillance is valuable, and advertising agencies that are bent on collecting as much information about people as possible in order to control them and sell them products. It just so happens that intelligence agencies are leveraging the work of advertising agencies because of their already deep integration into the large majority of the public internet. Thus, the biggest threat to any internet user is being attacked by advertising agencies.&lt;/p&gt;
&lt;p&gt;However, we know that the NSA and FVEY (Five Eyes) focuses on traffic analysis leaving the Tor network, so it is highly probable that the same focus occurs for IP subnets associated with VPN service providers.&lt;/p&gt;
&lt;p&gt;Sources:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://medium.com/message/the-hypocrisy-of-the-internet-journalist-587d33f6279e&quot;&gt;The Hypocrisy of the Internet Journalist&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.eff.org/deeplinks/2013/12/nsa-turns-cookies-and-more-surveillance-beacons&quot;&gt;NSA Turns Cookies (And More) Into Surveillance Beacons
&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;vpn-behavior&quot;&gt;VPN behavior&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-17.jpg&quot; alt=&quot;Alt Text: Slide 17&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-18.jpg&quot; alt=&quot;Alt Text: Slide 18&quot; /&gt;&lt;/p&gt;
&lt;p&gt;These are examples of two connections to two random Internet services via a one-hop proxy in Sweden. It should be obvious how simple this is and how trivial it would be for a &lt;a rel=&quot;external&quot; href=&quot;https://www.mdpi.com/2076-3417/12/1/137&quot;&gt;global passive adversary&lt;/a&gt; (GPA) to track low-latency, one-hop proxy connections.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-19.jpg&quot; alt=&quot;Alt Text: Slide 19&quot; /&gt;&lt;/p&gt;
&lt;p&gt;VPN services might feel safe. Especially when you pull out your credit card, you expect to get what you think you’re buying. But its largely false if your goal is to defend personal privacy. VPNs can still be really powerful for getting around censorship, sometimes. VPNs are also still really powerful for file sharing. But both advertising agencies and intelligence agencies are not slowed by technologies that are trivial to undermine with automatic network and data analysis.&lt;/p&gt;
&lt;p&gt;Also important to understand is that when you hire one corporate entity to safeguard your privacy, you create one target for an adversary to legally or technically attack. Nobody can assure that VPN services do not maintain connection logs; we know that they are required to maintain payment logs, and we know that some service providers have handed over connection information while also advertising that they do not store connection information.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;tor-behavior&quot;&gt;Tor behavior&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-20.jpg&quot; alt=&quot;Alt Text: Slide 20&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-21.jpg&quot; alt=&quot;Alt Text: Slide 21&quot; /&gt;&lt;/p&gt;
&lt;p&gt;These examples of two Tor circuits demonstrates why adding complexity to network connections is valuable, especially compared to standard options (HTTP, HTTP+TLS, or VPN).&lt;/p&gt;
&lt;p&gt;These examples above are also extremely simplified. Because all Tor traffic, no matter if its first-hop, second-hop, third-hop, or onion services traffic, all of those parts of a circuit look identical to a GPA. All Tor relays, especially really big relays, are handling thousands to hundreds of thousands of Tor circuits every second, and the Tor protocol keeps them all looking identical.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-22.jpg&quot; alt=&quot;Alt Text: Slide 22&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I included this slide again to further stress the importance of diversity of the Tor network.&lt;/p&gt;
&lt;p&gt;The more Tor users, the more Tor relays, the more Tor services there are, the more any one person blends into all of those things.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;onion-services&quot;&gt;Onion services&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-23.jpg&quot; alt=&quot;Alt Text: Slide 23&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Common client-server connections means that you are making a network request to a server, to see if that server is available, and to request digital resources if the server is available. This is done by communicating directly with the server. Onion services work differently.&lt;/p&gt;
&lt;p&gt;Onion services, like the (2016) ProPublica Onion site, is like a permanent Tor user that is constantly connected to the Tor network. You, the client, and ProPublica, the server, both inform the Tor network of your hidden identities. The only difference is that you, the client, makes an anonymous request to the Tor network to ask if the ProPublica server is available. The Tor network, automatically and anonymously, connects the two of you through a random &lt;strong&gt;rendezvous point&lt;/strong&gt; inside the Tor network, in the middle of you and the server. You never actually talk directly to the ProPublica Onion site, and you both have your own three-hops to protect your IP address. Since none of this traffic ever leaves the Tor network, Onion services are not vulnerable to standard forms of passive internet surveillance.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-24.jpg&quot; alt=&quot;Alt Text: Slide 24&quot; /&gt;&lt;/p&gt;
&lt;p&gt;In addition to being free of passive internet surveillance of normal HTTP or HTTPS traffic, Onion services have meaningful security properties that are built into the Tor protocol.&lt;/p&gt;
&lt;p&gt;It is important for security to be the default in systems that should be secure. It is also important to empower users by offering a diversity of security properties, automatically and transparently, so that users cannot mess anything up. It is impossible for any one organization to fully grasp each threat model for every one of their users; therefore, security and privacy should be built into the protocol, not options to be enabled if understood.&lt;/p&gt;
&lt;p&gt;Aside from the obvious security benefits of Onion services for users, there are obvious security benefits for large organizations. For example, many companies commonly have website or other services outages because of problems with DNS (domain name system), BGP (border gateway protocol), or their CA (certificate authority). Providing Onion services, even as a backup access solution, helps mitigate losing access to Web resources because of these failure points.&lt;/p&gt;
&lt;p&gt;The quote on slide 24 is from &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Roger_Dingledine&quot;&gt;Roger Dingledine&lt;/a&gt; as stated in his 32C3 talk, “&lt;a rel=&quot;external&quot; href=&quot;https://media.ccc.de/v/32c3-7322-tor_onion_services_more_useful_than_you_think&quot;&gt;Tor Onion Services: More Useful Than You Think&lt;/a&gt;”. It is a very informative talk and covers deeper issues, problems, and opportunities for the future of Onion services.&lt;/p&gt;
&lt;p&gt;Every “&lt;a rel=&quot;external&quot; href=&quot;https://media.ccc.de/v/32c3-7307-state_of_the_onion&quot;&gt;State of the Onion&lt;/a&gt;” presentation is worth watching and would be an excellent primer into understanding the nature of Tor and the quality of the people behind it.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;onion-services-behavior&quot;&gt;Onion services behavior&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-26.jpg&quot; alt=&quot;Alt Text: Slide 26&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This simplified example of a client accessing an Onion service demonstrates the complexity and importance of Onion services. Because both the client and the server makes independent Tor circuits, both maintain anonymity while also providing end-to-end encryption.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;tor-browser&quot;&gt;Tor browser&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-29.jpg&quot; alt=&quot;Alt Text: Slide 29&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Tor Browser, when juxtaposed to normal Web browsers, has significant advantages when the goal is to minimize identity exposure and the effects of Web tracking. Browser plug-ins cannot accomplish these privacy-focused goals, and many of these problems are identity-divulging browser features that advertising agencies always exploit.&lt;/p&gt;
&lt;p&gt;If you are brand new to Tor, or generally need assistance with using a personal computer, these step-by-step guides are perfect for Tor Browser installation and basic use.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;EFF SSD: &lt;a rel=&quot;external&quot; href=&quot;https://ssd.eff.org/en/module/how-use-tor-windows&quot;&gt;How to: Use Tor for Windows&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;EFF SSD: &lt;a rel=&quot;external&quot; href=&quot;https://ssd.eff.org/module/how-use-tor-macos&quot;&gt;How to: Use Tor for macOS&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;onion-services-hosting&quot;&gt;Onion services hosting&lt;/h1&gt;
&lt;p&gt;If you are interested in learning about or advocating for the use of Onion services, these are some useful resources.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Tor Project: &lt;a rel=&quot;external&quot; href=&quot;https://community.torproject.org/onion-services/&quot;&gt;Onion Services&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Riseup: &lt;a rel=&quot;external&quot; href=&quot;https://help.riseup.net/en/security/network-security/tor/onionservices-best-practices&quot;&gt;Best Practices for Hosting Onion Services&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;tor-applications&quot;&gt;Tor applications&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-30.jpg&quot; alt=&quot;Alt Text: Slide 30&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This is a list of Tor related software applications for different platforms. It is not an exhaustive list, and in my talk I briefly described the purpose of each one.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
&lt;h1 id=&quot;questions-and-feedback&quot;&gt;Questions and feedback&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/images/ta3m-slide-31.jpg&quot; alt=&quot;Alt Text: Slide 31&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Please email me with any questions or constructive feedback at yawnbox@disobey.net.
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat modeling YubiKeys and passkeys</title>
        <published>2024-11-02T00:00:00+00:00</published>
        <updated>2024-11-02T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/threat-modeling-yubikeys-and-passkeys/"/>
        <id>https://yawnbox.eu/blog/threat-modeling-yubikeys-and-passkeys/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/threat-modeling-yubikeys-and-passkeys/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;This blog post attempts to document certain risks when implementing FIDO2/WebAuthn-based YubiKeys and passkeys in enterprise environments and can be applied to high-risk individuals. This content took months of learning, thinking, and discussing with other security engineers due to the nature of these highly nuanced technologies in real-world situations.&lt;/p&gt;
&lt;p&gt;Please email me (yawnbox@disobey.net) or Signal me (yawnbox.01) if you have constructive feedback. I&#39;m a security engineer who&#39;s professionally worked with these technologies for only 6 months and am still a student who&#39;s writing this to continue my journey as an educator. I would have written about this sooner, but it&#39;s a very daunting topic to get right, and there&#39;s been a number of significant changes in the passkey landscape in the past few months.&lt;/p&gt;
&lt;p&gt;If you&#39;re interested in hiring me for information security consulting, please email me at c@stellarwind.net. In fact, I&#39;m currently unemployed and would love a full-time job!&lt;/p&gt;
&lt;p&gt;Like my other blog posts, this article is licensed as &lt;a rel=&quot;external&quot; href=&quot;https://creativecommons.org/public-domain/cc0/&quot;&gt;Creative Commons Zero&lt;/a&gt; (CC0), and I will do my best to keep this article up to date with relevant changes as the technologies or threat landscape change. I am also writing an expansion the Risk Analysis section to include threat scenarios with &lt;a rel=&quot;external&quot; href=&quot;https://attack.mitre.org/&quot;&gt;Mitre ATT&amp;amp;CK&lt;/a&gt; structure and references.&lt;/p&gt;
&lt;p&gt;Word count: 9,000+&lt;/p&gt;
&lt;h1 id=&quot;tl-dr&quot;&gt;TL;DR&lt;/h1&gt;
&lt;p&gt;Aim to maximize user adoption of phishing-resistant auth factors while helping IT reduce password attack vectors, policy maintenance, and support processes.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Maximize YubiKeys with user-validating fingerprints (YubiKey Bio) or PINs (YubiKey + PIN) to maximize defenses from phishing threats and to minimize theft attacks. For customers too, not just employees.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Remove server-validating second-factors (MFA, 2FA) when using the above auth factors if not limited by rules set by standards bodies. For customers too, not just employees.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Support passkeys carefully. Clearly understand the different types of passkeys and their security trade-offs when used in high security environments. For customers too, not just employees.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Eliminate weak auth factors and analyze and enhance auth factor reset processes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If the budget allows, gift YubiKeys to employees and their families and offer hands-on user training. When people appreciate the importance of FIDO2, they will naturally adopt YubiKeys in their daily lives, building a culture of security that extends beyond work. If a company plans on taking YubiKeys back after resignations and terminations, they&#39;ll be less likely to practice secure authentication in their personal lives.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;scope&quot;&gt;Scope&lt;/h1&gt;
&lt;p&gt;Threat modeling for FIDO2/WebAuthn Yubikeys and passkeys for passwordless authentication (secure signle-factor authentication) or in conjunction with multiple factors (multi-factor authentication such as with passwords).&lt;/p&gt;
&lt;p&gt;Integration of FIDO2/WebAuthn for Okta IdP from ChromeOS, Linux (w/ Chrome), macOS (w/ Chrome), and Windows (w/ Chrome) workstations. As of writing, Chrome has the best support for FIDO2/WebAuthn, can be centrally managed in an enterprise environment, and works on all workstation types.&lt;/p&gt;
&lt;p&gt;Please note, while there are other hardware FIDO2 devices available on the market, this risk analysis dives into the details of YubiKeys. Other devices may not operate in the exact same way, so please be careful not to misunderstand my use of &quot;hardware FIDO2&quot;. If I were asked to compare other hardware devices to the YubiKey, I would have to rethink all aspects of this document and potentially rewrite certain sections to be clear about any differences.&lt;/p&gt;
&lt;h2 id=&quot;positive-use-cases&quot;&gt;Positive Use Cases&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;100% employee, contractor, and business parter coverage for passwordless authentication via Okta from all platforms (ChromeOS, Linux, MacOS, Windows) and interfaces (browser, application, CLI) using FIDO2/WebAuthn hardware-based (YubiKey) and software-based (passkey) authentication methods.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;100% administrator coverage for passwordless authentication via Okta from Chromebooks (a pre-selected &lt;a rel=&quot;external&quot; href=&quot;https://www.beyondtrust.com/blog/entry/using-privileged-access-workstations-to-protect-the-cloud&quot;&gt;Priviledged Access Workstation&lt;/a&gt; (PAW)) with YubiKeys for accessing high-risk environments.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Zero-trust access control policies using the IdP (Okta Verify, Okta API) with supporting/layered Mobile Device Management (MDM) controls for device posture checks aligned to corporate security policies and standards.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;negative-use-cases&quot;&gt;Negative Use Cases&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;A successful phishing attack compromising a user account.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Administrative accounts being accessed without the dual security of a PAW and YubiKey.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;An individual, including employees, using a personal, unmanaged laptop or desktop gaining access to the company network.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;A device lacking necessary hardware security modules or non-compliant biometrics being able to authenticate without a YubiKey or passkey.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Any bypass of the IdP or supporting/layered MDM controls.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;biometric-security-analysis&quot;&gt;Biometric Security Analysis&lt;/h1&gt;
&lt;p&gt;Biometrics, including fingerprints and faceprints, are often touted for their uniqueness and are considered more convenient and relatively more secure than traditional passwords or passcodes. However, the reality is more nuanced. As highlighted by &lt;a rel=&quot;external&quot; href=&quot;https://arstechnica.com/information-technology/2020/04/attackers-can-bypass-fingerprint-authentication-with-an-80-success-rate/&quot;&gt;Ars Technica&lt;/a&gt;, attackers have been able to bypass fingerprint authentication with an approximate 80% success rate in tests conducted on devices from major manufacturers like Apple, Microsoft, Samsung, and Huawei. This success rate illustrates that biometric data can indeed be manipulated or mimicked by determined attackers with access to relatively simple technology and a modest budget.&lt;/p&gt;
&lt;p&gt;Unlike passwords or PINs, biometric data is immutable. Once compromised, it cannot be changed or revoked. This immutability poses a significant security risk for some, as exemplified by the &lt;a rel=&quot;external&quot; href=&quot;https://www.wired.com/2015/09/opm-now-admits-5-6m-feds-fingerprints-stolen-hackers/&quot;&gt;breach&lt;/a&gt; of the Office of Personnel Management (OPM) in which 5.6 million fingerprints of federal employees were copied. The compromise of such irreplaceable identifiers not only exposes individuals to lifelong vulnerabilities but also raises national security concerns, given the potential misuse of this data by adversarial entities.&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://blog.kraken.com/product/security/your-fingerprint-can-be-hacked-for-5-heres-how&quot;&gt;Kraken Security Labs&lt;/a&gt; demonstrated that with just $5 worth of materials, a fingerprint can be lifted off touched objects, creating a synthetic fingerprint capable of bypassing scanners on devices like a MacBook Pro. “[U]nlike a regular password, you leave your fingerprint on taxi doors, iPhone screens, and glasses of wine at your local restaurant.” This security research underscores the vulnerability of biometric systems to relatively low-tech attacks, highlighting the risk of over-reliance on these systems for securing sensitive information and access controls.&lt;/p&gt;
&lt;p&gt;The nuanced security architecture of biometric authentication involves a sophisticated interplay between biometric inputs and cryptographic hardware (ie Apple&#39;s Secure Enclave). In these systems, biometric data does not directly grant access to the device or platform. Instead, it serves as a key to authenticate the user against the on-device cryptographic module. This module then generates, manages, and/or proves a valid encryption key to macOS or to Okta. This ensures that even if biometric data is compromised, unauthorized access requires stealing the targeted device for either breaking into the device or breaking into Okta. This layered approach to security significantly enhances protection but also underscores the complexity of fully understanding and securing systems against determined attackers.&lt;/p&gt;
&lt;p&gt;To deepen the understanding of this nuanced security architecture, it&#39;s critical to recognize the distinctions in how biometric systems are integrated, particularly when planning for risk mitigation. For instance, Apple and Microsoft adopt notably different strategies in designing biometric authentication systems for laptops. Microsoft (Windows Hello), constrained by its dependence on a wide array of hardware manufacturers, firmware and driver developers, faces challenges in enforcing stringent requirements, as highlighted by &lt;a rel=&quot;external&quot; href=&quot;https://arstechnica.com/gadgets/2023/11/researchers-beat-windows-hello-fingerprint-sensors-with-raspberry-pi-and-linux/&quot;&gt;Ars Technica&lt;/a&gt; in November 2023. Understanding the details of cryptographic mechanisms is important, particularly when there is an absence of cryptographic mechanisms when transporting biometric authentication data between system components. In contrast, Apple&#39;s controlled ecosystem allows for more rigorous standards in its biometric authentication implementation. This disparity underscores the importance of considering the specific architecture and integration approach of biometric systems when assessing security risks and protections.&lt;/p&gt;
&lt;p&gt;Lastly, devices are not equally vulnerable. On the other hand, it’s impossible to predict when and where new vulnerabilities will be found, or what arsenal well funded adversaries possess. This security analysis aims to highlight known vulnerabilities in MFA components while being weighed against broad risk for biometric authentication technology.&lt;/p&gt;
&lt;h1 id=&quot;pins-passwordless&quot;&gt;PINs = Passwordless?&lt;/h1&gt;
&lt;blockquote&gt;
&lt;p&gt;A YubiKey &quot;PIN&quot;, as written in this article, includes passcodes and passphrases, given that setting a &quot;PIN&quot; allows for alphanumeric passphrases. YubiKeys are not limited to only 0-9 when setting a PIN.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The concept of &quot;passwordless&quot; authentication, particularly in the context of using a YubiKey coupled with a PIN, represents a significant shift in how we think about securing access to systems and services like Okta. This approach is considered passwordless not because it eliminates all forms of user input that a user must remember, but because it fundamentally changes the nature of secure authentication information being presented to Okta.&lt;/p&gt;
&lt;p&gt;To understand why a combination of YubiKey and PIN is classified under passwordless authentication, it&#39;s essential to delve into the mechanics of how the YubiKey functions and how the PIN fits into this authentication model. The YubiKey is a hardware device that supports various forms of cryptographic proofs, such as Universal 2nd Factor (U2F), FIDO2, and smart card capabilities. These cryptographic proofs are used to authenticate the user to a service like Okta, without transmitting a traditional password.&lt;/p&gt;
&lt;p&gt;The role of the PIN in this setup is to authenticate the user to the YubiKey itself, not to Okta. The PIN is a safeguard that ensures only the authorized user of the YubiKey can activate the YubiKey&#39;s cryptographic functions. When the user inserts their YubiKey into a device and is prompted for a PIN, the correct entry of this PIN activates the YubiKey. Subsequently, the YubiKey performs cryptographic operations that prove the user&#39;s identity to Okta or another service. This process involves the YubiKey creating a digital signature or other cryptographic response that only it can generate, thanks to its secure, embedded cryptographic keys.&lt;/p&gt;
&lt;p&gt;It&#39;s important to emphasize that Okta, in this scenario, does not receive or process the PIN. Instead, Okta interacts with the cryptographic proof provided by the YubiKey. This is a critical distinction that makes the system &quot;passwordless.&quot; Okta verifies the authenticity of the cryptographic proof against the registered details of the YubiKey, thus authenticating the user. This method is inherently more secure than traditional passwords, which can be intercepted, stolen, or guessed. FIDO2 cryptographic proofs, on the other hand, are unique to each authentication session, time dependent, and cannot be reused by an attacker.&lt;/p&gt;
&lt;p&gt;Lastly, this approach aligns with the principles of multi-factor authentication (MFA), requiring something the user has (the YubiKey) and something the user knows (the PIN). However, unlike traditional MFA that might use a password as one of the factors, this method relies on cryptographic authentication, which is significantly more resilient against phishing, man-in-the-middle attacks, and other common security threats. In essence, considering YubiKey plus PIN as passwordless stems from the fact that the authentication process with Okta and similar platforms does not involve a shared secret like a password being sent over the network. Instead, it leverages the robust security of hardware-based cryptography to verify identity locally. This shift not only enhances security but also simplifies the user experience, as users no longer need to remember complex passwords or change them regularly.&lt;/p&gt;
&lt;h1 id=&quot;software-passkeys-vs-hardware-yubikeys&quot;&gt;Software passkeys vs hardware YubiKeys&lt;/h1&gt;
&lt;p&gt;Passkeys, credentials used in FIDO2 authentication, can be supported by software-based systems or secured by hardware authenticators like YubiKeys. While both approaches implement strong, phishing-resistant authentication standards, they differ in how securely credentials are protected and verified.&lt;/p&gt;
&lt;p&gt;Software-based passkeys offer user-friendly, seamless biometric or PIN-based authentication without requiring additional devices. While convenient, these passkeys rely on the security posture of the underlying system and can be vulnerable to sophisticated malware if the device is compromised. Additionally, cloud-synced passkeys depend on the security of cloud infrastructure and the personal settings of user&#39;s accounts.&lt;/p&gt;
&lt;p&gt;Hardware-based YubiKeys securely store private keys within a tamper-resistant physical token that isolates cryptographic operations from potentially compromised host systems. This makes hardware tokens more resilient against remote attacks and phishing, as the private key never leaves the device. User interaction, such as a touch to confirm or, in the case of the YubiKey Bio, PIN entry or a fingerprint swipe, adds an extra layer of verification.&lt;/p&gt;
&lt;p&gt;Both software and hardware methods use public key cryptography, providing robust security properties, but each comes with unique trade-offs which this articles aims to help document.&lt;/p&gt;
&lt;h1 id=&quot;types-of-passkeys&quot;&gt;Types of Passkeys&lt;/h1&gt;
&lt;p&gt;Generally speaking there are two types of passkeys that each carries unique risks. I&#39;m also breaking down each of these two types into two sub-types for further security engineering clarity. Each type and sub-type has categorical risks. Additionally, operating system or web browser implementation can significantly change the nature of risks associated with using any one type of passkey.&lt;/p&gt;
&lt;h2 id=&quot;synced-passkeys&quot;&gt;Synced Passkeys&lt;/h2&gt;
&lt;h3 id=&quot;cloud-synced-passkey&quot;&gt;Cloud-synced Passkey&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There is no guarantee that a synced passkey without “passkey attestation” cannot be used somewhere else. That is an intentional, user-focused portability feature that was not intended for enterprise use.&lt;/p&gt;
&lt;p&gt;Using Apple as an example, use of passkeys on Apple devices automatically sync to a user&#39;s iCloud account via what is now called Apple Passwords. If a threat actor is able to compromise a targeted user&#39;s iCloud account and is able to add an Apple device owned by the malicious user as an authenticated device, the malicious user would have access to the targeted user&#39;s passkeys. This is by design for passkey portability and ease-of-use.&lt;/p&gt;
&lt;h3 id=&quot;cloud-synced-passkey-w-attestation&quot;&gt;Cloud-synced Passkey w/ Attestation&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The addition of Passkey Attestation is supposed to make a passkey device-bound even if it syncs to the cloud.&lt;/p&gt;
&lt;p&gt;Apple, for example, allows enterprises utilizing MDM to enable &lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-is/guide/deployment/depd218e61b5/web&quot;&gt;Apple Passkey Attestation&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;device-bound-passkeys&quot;&gt;Device Bound Passkeys&lt;/h2&gt;
&lt;h3 id=&quot;local-passkeys&quot;&gt;Local passkeys&lt;/h3&gt;
&lt;p&gt;Auth Method Characteristics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For the common enterprise operating systems used today – iOS, macOS, Windows, ChromeOS – local passkeys are created by and authenticated by a private key made and stored in a hardware security module such as the laptop&#39;s TPM or Apple&#39;s Secure Enclave.&lt;/p&gt;
&lt;p&gt;Since the passkey exists on-disk as software, usually in an encrypted state, managed by the OS or by a web browser, the passkey will not work on any other device because of the requirement of the local hardware security module that generated the passkey.&lt;/p&gt;
&lt;p&gt;In other words, the private key in the hardware security module that generates the private key for a passkey is hardware protected. But the passkey private key is not.&lt;/p&gt;
&lt;p&gt;However, if the outer layer of encryption can be defeated, and the private key material of the passkey can be exported, it is no longer protected by, nor requires, the local hardware security module to be used.&lt;/p&gt;
&lt;p&gt;Using a local passkey means:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The hardware security module is present&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The passkey private key is present and managed by the private key in the hardware security module&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The passkey is validated by something user-verifying, typically a PIN or biometric, which the user has to input, which is also validated by the local hardware security module&#39;s private key&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The timing of the use of the passkey and the user verification has to be accurate. WebAuthn requires time intervals of each step has not timed out, and that time measurement is cryptographically secure.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id=&quot;local-passkey-w-attestation&quot;&gt;Local passkey w/ attestation&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Passkey Attestation is an additional cryptographic proof that ties a passkey to a specific hardware security module. If the private key material of a passkey with attestation is exported, no other hardware security module can authenticate its use.&lt;/p&gt;
&lt;p&gt;The addition of passkey attestation greatly improves the security of a local passkey due to layered security, but it is most important when the passkey can or will be synced to the cloud and kept on numerous devices.&lt;/p&gt;
&lt;h1 id=&quot;fido2-1fa-better-than-classic-2fa-mfa&quot;&gt;FIDO2 1FA: better than classic 2FA/MFA?&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;The below table and terms are adapted from Okta&#39;s &lt;a rel=&quot;external&quot; href=&quot;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/about-authenticators.htm&quot;&gt;multifactor authentication&lt;/a&gt; documentation.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/fido2-auth-characteristics.png&quot; alt=&quot;alt text&quot; /&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;User presence&lt;/strong&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;These authenticators require human interaction.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Phishing-resistant&lt;/strong&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;These authenticators don&#39;t provide any authentication data that a user can share with others. Users therefore can&#39;t be tricked into sharing their credentials in phishing campaigns. See Phishing-resistant authentication and Okta solutions for phishing resistance.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Device-bound&lt;/strong&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;These authenticators are associated with a specific device.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Hardware-protected&lt;/strong&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;These authenticators require a physical device to authenticate.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;User verifying&lt;/strong&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;These authenticators prove that a specific user is the one who is authenticating.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;p&gt;These five &quot;authentication method characteristics&quot;, defined by Okta, each mitigates entire classes of attacks. If I had to write an SSO security standard for a company, I would use this table for categorical clarification about which methods are permitted. I would require &lt;strong&gt;User Presence&lt;/strong&gt;, &lt;strong&gt;Phishing Resistance&lt;/strong&gt;, &lt;strong&gt;Device Bound&lt;/strong&gt;, and &lt;strong&gt;User Verifying&lt;/strong&gt; authentication characteristics. &lt;strong&gt;Hardware Protected&lt;/strong&gt; is ideal, but would rule out passkeys. My personal preferences would rule out PIN-less YubiKeys and passkeys that sync to the cloud without proven passkey attestation controls.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Device Bound&lt;/strong&gt; characteristic is messy when looking at passkeys. In short, without robust MDM and/or cloud security controls, social engineering threats that target less secure cloud accounts where passkeys sync is a real threat. Like Apple iCloud.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Hardware Protected&lt;/strong&gt; characteristic is also messy. It&#39;s commonly presumed that Apple-generated passkeys are stored in Apple device&#39;s Secure Enclave, for example, which is not true. Apple-generated passkeys use Secure Enclave to generate and validate passkeys, but these passkeys are stored in the iCloud Keychain -- in software. Similarly, Chrome-generated passkeys, while they will use a system&#39;s TPM or Secure Enclave, are stored in a Google-managed encrypted database -- in software.&lt;/p&gt;
&lt;p&gt;While there are always edge cases, a single, modern, properly managed (&lt;strong&gt;User Verifying&lt;/strong&gt;) FIDO2 authenticator such as a YubiKey or credential like a passkey does not require a server-validated second-factor for authentication because the first auth factor is robust: it will adequately mitigate most risks in most situations. FIDO2/WebAuthn, when configured correctly, offers client-validated two-factor authentication, which becomes clear in the following section. Classic, password-based MFA is an approach to authenticate where two or more auth factors have significant weaknesses, so as a matter of layered security, multiple auth types are necessary to secure access to a remote system.&lt;/p&gt;
&lt;p&gt;YubiKeys are hardware devices that cannot be easily copied -- &lt;a rel=&quot;external&quot; href=&quot;https://arstechnica.com/security/2024/09/yubikeys-are-vulnerable-to-cloning-attacks-thanks-to-newly-discovered-side-channel/&quot;&gt;but beware older keys&lt;/a&gt; -- and passkeys are software cryptographic keys that are not easily exportable to arbitrary people. Both maintain strong risk mitigations of their own, however passkey implementations vary widely. Passwordless auth factors are not immune from phishing attacks. It is possible for social engineers to pretend to be the helpdesk of the company of the targeted employee and in effect steal a YubiKey along with an associated PIN. Passkeys, on the other hand, are exportable in many situations and therefore may be transferable. Without passkey attestation or certain controls to make passkeys device-bound, it&#39;s possible for social engineers to copy, steal, or hijack cloud accounts with synced private keys. More on these risks later.&lt;/p&gt;
&lt;h1 id=&quot;risk-analysis&quot;&gt;Risk Analysis&lt;/h1&gt;
&lt;p&gt;The following risk analysis is scoped to common workstation types and common authentication types. There are more of each; for example, I did not dive into mobile phones or tablets. I also did not work with third-party password managers that can manage passkeys. This analysis aims to provide a basic template for adding more device types or authentication types.&lt;/p&gt;
&lt;p&gt;This risk analysis is also focused on Okta&#39;s capabilities as of early 2024. It may be possible now or in the future that Okta allows additional server-validated 2FA auth factor combinations, including an ideal possibility of allowing the first server-validated auth factor to be a passkey instead of a password with a second server-validated auth factor be a YubiKey. In my testing, I was not able to configure Okta to allow a passkey + YubiKey combination, for example. I hope that server-side authentication systems develop to the point of offering support for multiple forms of FIDO2 auth factors.&lt;/p&gt;
&lt;h2 id=&quot;authentication-and-workstation-types-matrix&quot;&gt;Authentication and Workstation Types Matrix&lt;/h2&gt;
&lt;p&gt;Below you will see several tables with specific color-coding to differentiate aspects of these authentication methods and the workstations from which they can be used. These tables offer quick-glance, high-level risk indicators. The low-level risk analysis for each authentication type follows this section.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Green: Advised&lt;/li&gt;
&lt;li&gt;Yellow: Not Advised&lt;/li&gt;
&lt;li&gt;Red: Dangerous&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As you will see below, two-factor authentication (2FA) requires two of: something you have, something you know, or something you are. It becomes clear why a single FIDO2/WebAuthn method is 2FA when there is user-validating cryptographic authentication baked into the protocol, when configured correctly. This nuanced distinction, when juxtaposed to classic 2FA/MFA, is that the validation of the user is occurring locally instead of by the server/IdP -- the former being more secure in some meaningful contexts, but not all.&lt;/p&gt;
&lt;p&gt;&quot;Server-validated&quot; (2FA) can mean:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;an IdP, like Okta&lt;/li&gt;
&lt;li&gt;IdP-less situations&lt;br&gt;
2a. super admins or break-glass accounts&lt;br&gt;
2b. online services without SSO integration capabilities&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&quot;Client-validated&quot; (2FA) can mean:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;a workstation, like with Apple&#39;s macOS Touch ID, providing local cryptographic validation of a passkey&lt;/li&gt;
&lt;li&gt;a fully-integrated hardware token, like a YubiKey, including a web browser or CLI terminal that performs PIN validation&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id=&quot;high-level-risk-analysis-for-passwordless-server-validated-1fa-client-validated-2fa&quot;&gt;High-Level Risk Analysis for Passwordless, server-validated 1FA, client-validated 2FA&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;/images/fido2-1fa-1-high.png&quot; alt=&quot;alt text&quot; /&gt;&lt;/p&gt;
&lt;p&gt;These five authentication types are usable options if the company decides to adopt single-factor, passwordless authentication for Okta SSO.&lt;/p&gt;
&lt;p&gt;The first two types are hardware based, and last three (in light blue) utilize software-based storage of passkeys with hardware-backed (TPM, Secure Enclave) creation and validation. As you can see, the passkey methods are system specific. Windows Hello (option 5) caries notable risk compared to the alternative passwordless options, which this article will dive into in the next section.&lt;/p&gt;
&lt;p&gt;To my knowledge, there is no known, production-ready, centrally-managed passkey option for Linux workstations. Theoretically, Chrome (browser) will generate passkeys with a workstation&#39;s TPM, validated by a fingerprint reader, and Chrome will store and sync a passkey with Google Password Manager. This may have the ability to be &quot;centrally managed&quot; to a degree if a company is using Google Workspace for company email and MDM. It will not affect or help passkeys needed for CLI work. Additionally, third-party password managers that have built in passkey management options could be used, but that is true for any operating system, and password-manager-managed passkeys have distinct security tradeoffs. I have not tested either of these scenarios. YubiKeys are ideal when supporting Linux workstations in addition to offering the most robust security.&lt;/p&gt;
&lt;h3 id=&quot;high-level-risk-analysis-for-server-validated-2fa&quot;&gt;High-Level Risk Analysis for Server-validated 2FA&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;/images/fido2-2fa-high.png&quot; alt=&quot;alt text&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Auth methods 6 through 15 include options that are not FIDO2. Further, Push, TOTP, YubiKey (PIN-less), SMS, and &quot;Security&quot; Questions are here to show juxtaposition. These auth methods are common in enterprise environments. Your company may have others, and they should be documented in a similar way.&lt;/p&gt;
&lt;h3 id=&quot;high-level-risk-analysis-for-passwordless-server-validated-1fa-client-validated-1fa&quot;&gt;High-Level Risk Analysis for Passwordless, server-validated 1FA, client-validated 1FA&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;/images/fido2-1fa-2-high.png&quot; alt=&quot;alt text&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Last but not least, auth method 16 is simply a YubiKey without a second-factor of any kind, server-validated or client-validated. It should be clear that there is no native or supplemental second-factor that meets the &quot;something you have, know, or are&quot; criteria. Those facts aside, a PIN-less YubiKey, by itself, is still strong when it comes to phishing resistance. Low-level analysis below.&lt;/p&gt;
&lt;h2 id=&quot;risk-discussion&quot;&gt;Risk Discussion&lt;/h2&gt;
&lt;p&gt;My methodology for defining a high-level “risk” for each of the risk categories is “averaged” based on overall mitigated risk factors when using the above authentication methods, either single-factor or multi-factor.&lt;/p&gt;
&lt;h3 id=&quot;advising&quot;&gt;Advising&lt;/h3&gt;
&lt;p&gt;My “advised” recommendations stem from one simple criteria: No &lt;strong&gt;High&lt;/strong&gt; or &lt;strong&gt;Critical&lt;/strong&gt; risks.&lt;/p&gt;
&lt;p&gt;Any amount of &lt;strong&gt;Medium&lt;/strong&gt; risks can often be minimized with layered security controls. However, pay attention to my notes. Some &lt;strong&gt;Medium&lt;/strong&gt; risks should be elevated to &lt;strong&gt;High&lt;/strong&gt; risks if a company or user&#39;s threat model includes moderate to high likelihood of targeted attacks. In these situations, my advisement shifts to &lt;strong&gt;Not Advised&lt;/strong&gt;, and it is up to the company to accept certain medium to high risks.&lt;/p&gt;
&lt;h3 id=&quot;risks-definitions&quot;&gt;Risks Definitions&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Spoofing Risk&lt;/strong&gt;: The likelihood that an attacker could replicate or spoof the authentication method.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Theft/Loss Risk&lt;/strong&gt;: The risk of the authentication method being lost, stolen, or guessed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Phishing Risk&lt;/strong&gt;: The susceptibility of the authentication method to phishing attacks.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Technical Vulnerabilities&lt;/strong&gt;: The risk of publicly known technical flaws or vulnerabilities anywhere in the authentication method compute stack.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;low-level-risk-analysis-for-passwordless-server-validated-1fa-client-validated-2fa&quot;&gt;Low-Level Risk Analysis for Passwordless, server-validated 1FA, client-validated 2FA&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;/images/fido2-1fa-1-low.png&quot; alt=&quot;alt text&quot; /&gt;&lt;/p&gt;
&lt;h3 id=&quot;1-yubikey-pin-advised&quot;&gt;1. YubiKey + PIN (Advised)&lt;/h3&gt;
&lt;p&gt;1a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;1b. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;YubiKeys are easy to lose, easier to have stolen, and impossible to track since they operate without connectivity. There are at least three increased risks with regard to a stolen YubiKey that has a PIN configured:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Guessing: It should be assumed that most people will choose a PIN that they will not easily forget. Therefore, it is common for employees to choose PINs that they use in their personal lives. For example, for their ATM debit card. A determined threat actor may have access to privileged data or hacked datasets that would allow the attacker to presume a targeted user&#39;s PIN with high probability.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Copying: Technical vulnerabilities, known or future, may allow an attacker to copy the YubiKey, and possibly return the stolen YubiKey to its owner without the owner knowing it went missing. Having a duplicated YubiKey may be combined with other risks.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Social engineering: A determined threat actor may be able to phish or social engineer an employee into disclosing their PIN, even if the YubiKey has already been taken from their possession.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;1c. Note&lt;/p&gt;
&lt;p&gt;YubiKeys have built-in defense mechanisms protecting against repeated PIN guessing, and so does Okta. Further, companies could purchase the FIPS-certified YubiKeys that require a user set a 6-digit PIN instead of a default 4-digit PIN, or they could educate employees about the risks and ask them to use a unique PIN.&lt;/p&gt;
&lt;p&gt;1d. Note&lt;/p&gt;
&lt;p&gt;With this method of client-validated 2FA, as discussed earlier, the PIN certifies the user to the security key. Neither the YubiKey nor the PIN can be used independently of each other for any authentication factor. Therefore the use of a PIN is not the same as using a password as an individual factor for authentication into a remote system.&lt;/p&gt;
&lt;h3 id=&quot;2-yubikey-bio-advised&quot;&gt;2. YubiKey Bio (Advised)&lt;/h3&gt;
&lt;p&gt;2a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;2b. Spoofing Risk and Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;It is a fact that bioreaders are susceptible to artificially constructed fingers and faces. Such authentication methods are immutable. Given a determined attacker&#39;s ability to easily steal a YubiKey Bio, the attacker would be in possession of half of the authentication system.&lt;/p&gt;
&lt;p&gt;With no other authentication factor to mitigate the risk of a stolen YubiKey Bio being misused, this overall risk is &lt;strong&gt;Medium&lt;/strong&gt; when considering low-skilled attackers due to the fact that YubiKeys have a native anti-brute-forcing feature.&lt;/p&gt;
&lt;p&gt;However, if a specific user&#39;s threat model includes determined or well-funded threat actors, this Spoofing risk should be increased to &lt;strong&gt;High&lt;/strong&gt; and automatically the overall recommendation would be changed to Not Advised.&lt;/p&gt;
&lt;p&gt;2c. Note&lt;/p&gt;
&lt;p&gt;To activate a YubiKey Bio, a user first must add a PIN, just like if a user had a YubiKey non-Bio and was enabling a PIN. The PIN is used as a backup method of authentication after a small number of fingerprint swipe attemps.&lt;/p&gt;
&lt;p&gt;YubiKey Bio devices ensure a limited amount of failed authentication attempts overall. A YubiKey will cease functioning after a certain amount of retries. This security control is in addition to Okta’s limit of failed authentication attempts.&lt;/p&gt;
&lt;p&gt;2d. Note&lt;/p&gt;
&lt;p&gt;YubiKey Bios, while more expensive, are ideal for most end-users. Users do need to set (and remember) a PIN, but the PIN does not need to be used in most situations. The ease-of-use will increase adoption while also lowering PIN- (YubiKey-) resets.&lt;/p&gt;
&lt;p&gt;It&#39;s recommended that companies teach users of YubiKeys Bios to set unique PINs and to store those PINs in their company-approved password managers.&lt;/p&gt;
&lt;h3 id=&quot;3-macos-touch-id-advised&quot;&gt;3. macOS Touch ID (Advised)&lt;/h3&gt;
&lt;p&gt;3a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;3b. Spoofing Risk, Medium&lt;/p&gt;
&lt;p&gt;Bioreaders are susceptible to artificially constructed fingers or faces. The risk is increased to Medium since a threat actor is likely in possession of the first client-validated auth factor (Secure Enclave) when a laptop is also lost or stolen.&lt;/p&gt;
&lt;p&gt;Since Macbooks are usually left turned-on, an since macOS Touch ID is also used to gain access to the system, when lost or stolen, any compromise of Touch ID would not only allow access to the system but also to Okta. However, Macbooks will revert back to requiring the user&#39;s password to enter the system if enough time as passed.&lt;/p&gt;
&lt;p&gt;Like YubiKey Bio risks, if a specific user&#39;s threat model includes determined or well-funded threat actors, this Spoofing risk rating should be increased to High and automatically the overall risk rating should be changed to Not Advised.&lt;/p&gt;
&lt;p&gt;3c. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;Since one’s fingerprint is validating the user to Secure Enclave, and since both Secure Enclave and the bioreader is lost when a Macbook is lost or stolen, it carries similar risks when a YubiKey Bio is lost or stolen. Please read that section as it is highly similar.&lt;/p&gt;
&lt;p&gt;3d. Phishing Risk, Medium&lt;/p&gt;
&lt;p&gt;While the auth method characteristic &lt;strong&gt;Phishing Resistant&lt;/strong&gt; is true, in a broader sense, due to the nature of cloud-synced passkeys, there is meaningful, extrinsic phishing risk that a company should consider. Due to how Apple employs passkeys, requiring a reliance on iCloud Keychain, Apple passkeys are not Device Bound. If an attacker is able to social engineer a user to gain access to a user&#39;s Apple account, the attacker may be able to gain access to passkey private key material. If a user is signed into their personal Apple account, companies will have little to no control or visibility into personal accounts.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I go into greater detail looking at Apple iCloud Keychain risks later in this article (WIP).&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;3d. Note&lt;/p&gt;
&lt;p&gt;This method of authentication employs software FIDO2: passkeys. It is not a 1:1 replacement for a YubiKey. Secure Enclave generates a private key and stores the private key in iCloud Keychain, in software, because, in order to use passkeys on Apple systems, iCloud and iCloud Keychain must be enabled. However there still are strong security guarantees. It is not trivial to export a passkey arbitrarily, and it is not easily phishable. Secure Enclave + the user&#39;s unique fingerprint are both required to activate the passkey.&lt;/p&gt;
&lt;p&gt;3e. Note&lt;/p&gt;
&lt;p&gt;Exported passkey private keys from Apple Passwords (formerly iCloud Keychain) can be used by malicious attackers if successfully copied or stolen if a company is not using MDM that also enables passkey attestation.&lt;/p&gt;
&lt;p&gt;3f. Note&lt;/p&gt;
&lt;p&gt;Neither Secure Enclave nor one’s fingerprint can be used independently. Secure Enclave is designed to securely store cryptographic keys and perform cryptographic operations, while Touch ID is used to authorize the use of these keys.&lt;/p&gt;
&lt;p&gt;3g. Note&lt;/p&gt;
&lt;p&gt;Like YubiKey Bio devices and YubiKey + PIN, macOS Touch ID ensures a limited amount of failed authentication attempts. Touch ID will cease functioning after a certain amount of retries. This security control is in addition to Okta’s limit of failed authentication attempts.&lt;/p&gt;
&lt;h3 id=&quot;4-chromebook-tpm-fingerprint-advised&quot;&gt;4. Chromebook TPM + fingerprint (Advised)&lt;/h3&gt;
&lt;p&gt;4a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;4b. Spoofing Risk, Medium&lt;/p&gt;
&lt;p&gt;Bioreaders are susceptible to artificially constructed fingers or faces. The risk is increased to Medium since a threat actor is likely in possession of the first client-validated auth factor (TPM) when a laptop is also lost or stolen.&lt;/p&gt;
&lt;p&gt;Like YubiKey Bio risks, if a specific user&#39;s threat model includes determined or well-funded threat actors, this Spoofing risk rating should be increased to High and automatically the overall risk rating should be changed to Not Advised.&lt;/p&gt;
&lt;p&gt;4b. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;Since one’s fingerprint is validating the user to TPM, and since both TPM and the bioreader is lost when a Chromebook is lost or stolen, it carries similar risks when a YubiKey Bio is lost or stolen. Please read that section as it is highly similar.&lt;/p&gt;
&lt;p&gt;4c. Phishing Risk, Medium&lt;/p&gt;
&lt;p&gt;While the auth method characteristic &lt;strong&gt;Phishing Resistant&lt;/strong&gt; is true, in a broader sense, due to the nature of cloud-synced passkeys, there is meaningful phishing risk that a company should consider. Ever since Google changed how passkeys are managed in Chrome, passkeys are no longer Device Bound. If an attacker is able to social engineer a user to gain access to a user&#39;s Google account, the attacker may be able to gain access to passkey private key material. If a user is signed into their personal Google account, companies will have little to no control or visibility into personal accounts.&lt;/p&gt;
&lt;p&gt;4d. Note&lt;/p&gt;
&lt;p&gt;If used as a PAW, I would strongly advise Okta admins to employ a ChromeOS-specific policy to require server-validated 2FA and not solely relay on ChromeOS&#39;s fingerprint security. Or, to simply require the use of a YubiKey + PIN. Even a YubiKey Bio, i believe, would be a more trustworthy client-validated 2FA method to avoid the risks of random OEM manufacturing. Employing YubiKeys with Chromebooks as PAWs is ideal because it&#39;s likely that an admin uses a Windows laptop or Macbook as their main workstation.&lt;/p&gt;
&lt;p&gt;4e. Note&lt;/p&gt;
&lt;p&gt;I&#39;m not aware of any specific, known exploits of Chromebook bioreader attacks. Unlike Macbooks, and more like Windows laptops, Chromebooks are manufacturered by many different OEMs. While a TPM + fingerprint combination sounds similiar to a Macbook, I would not give it the same level of trust. I think of it as somewhere in between a Macbook and a Windows laptop in terms of physical security risk.&lt;/p&gt;
&lt;p&gt;If know&lt;/p&gt;
&lt;h3 id=&quot;5-windows-hello-not-advised&quot;&gt;5. Windows Hello (Not Advised)&lt;/h3&gt;
&lt;p&gt;5a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;5b. Spoofing Risk, High&lt;/p&gt;
&lt;p&gt;Bioreaders are susceptible to artificially constructed fingers/faces, especially on Windows laptops. The risk of Windows Hello spoofing is high due to Microsoft’s and OEM’s track record of inferior technology compared to Apple. The risk here is elevated due to a lack of a second auth factor which raises the overall spoofing risk.&lt;/p&gt;
&lt;p&gt;5c. Accidental Loss and Theft for Resale, Medium&lt;/p&gt;
&lt;p&gt;Laptops are not easily lost of stolen unless the owner travels a lot for work. However due to the ease in which a laptop can be misplaced or stolen, this is not an insignificant risk, especially coupled with the scenario where there is no second-factor for authentication. If the laptop owner travels for work, this risk score would raise to High.&lt;/p&gt;
&lt;p&gt;5d. Targeted Theft Risk, High&lt;/p&gt;
&lt;p&gt;Laptops do not require a great deal of effort or cost to steal for a determined threat actor. Combined with the Critical Risks associated with default BitLocker configurations and with Windows Hello, and the overall risk (platform insecurity) with Windows laptops in general (see below), this has an increased risk.&lt;/p&gt;
&lt;p&gt;5e. Phishing Risk, Medium&lt;/p&gt;
&lt;p&gt;As of October 2024, Microsoft has &lt;a rel=&quot;external&quot; href=&quot;https://blogs.windows.com/windowsdeveloper/2024/10/08/passkeys-on-windows-authenticate-seamlessly-with-passkey-providers/&quot;&gt;announced&lt;/a&gt; that passkeys on Windows systems will become trivial to sync to either a user&#39;s signed-in Microsoft account or to a third party service like BitWarden or 1Password.&lt;/p&gt;
&lt;p&gt;While the auth method characteristic of &lt;em&gt;Phishing Resistant&lt;/em&gt; is true, in a broader sense, due to the nature of cloud-synced passkeys, there is meaningful, extrinsic phishing risk that a company should consider. Via default Windows Hello workflows, users are asked to sync their passkeys to the cloud. While this is opt-in, most users are likely to enable this convenience feature. If an attacker is able to social engineer a user to gain access to a user&#39;s cloud account, the attacker may be able to gain access to passkey private key material. If a user signs into their personal cloud account, companies will have little to no control or visibility into personal accounts.&lt;/p&gt;
&lt;p&gt;5f. Technical Vulnerabilities, Critical&lt;/p&gt;
&lt;p&gt;There are active, cheap exploits against &lt;a rel=&quot;external&quot; href=&quot;https://github.com/Wack0/bitlocker-attacks&quot;&gt;Windows BitLocker&lt;/a&gt;. Given:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How easy it is to steal a laptop&lt;/li&gt;
&lt;li&gt;A default BitLocker configuration is known-vulnerable to a myriad of physical-access attacks&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The only potential method to reduce risk to gain access to a shut down (turned off) Windows workstation is for the company to enable a BIOS password on all Windows laptops and enable BitLocker hardening through Group Policy on all Windows laptops. Specifically, forcing users to set a pre-boot PIN. However, having a pre-boot PIN enabled may not help in some scenarios where a Windows laptop is stollen in a turned-on, suspended, or hibernation state.&lt;/p&gt;
&lt;p&gt;Given the IT department impact, and the user impact of requiring pre-boot PINs to boot into Windows, it is not common for companies to add these technical inconveniences. For example, Windows patching is made significantly harder when there is a pre-boot PIN for IT and for the end-user.&lt;/p&gt;
&lt;p&gt;There are active, cheap exploits against &lt;a rel=&quot;external&quot; href=&quot;https://arstechnica.com/gadgets/2023/11/researchers-beat-windows-hello-fingerprint-sensors-with-raspberry-pi-and-linux/#gsc.tab=0&quot;&gt;Windows Hello&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In short, a threat actor is able to enroll a fingerprint into a company-owned laptop fingerprint sensor and use that arbitrary fingerprint to authenticate via Windows Hello. This attack would allow a threat actor to log into Windows and authenticate into Okta. Based on the public information about these exploits, they do not appear to be patchable. Most companies do not have any firmware patching or firmware hardening controls in place, potentially allowing an attacker to boot into Linux on a stolen Windows laptop in order to perform this arbitrary-fingerprint-enrollment attack.&lt;/p&gt;
&lt;p&gt;The linked Ars Technica article discussing this attack, and the public, associated research, calls our many popular laptop OEMs. Given the scale of vulnerable systems, I would operate on the assumption that all Windows laptop OEMs are vulnerable until proven otherwise.&lt;/p&gt;
&lt;p&gt;5g. Note&lt;/p&gt;
&lt;p&gt;Unlike the server-validated 2FA Password + Windows Hello, due to the known exploits against Windows Hello, this is not an acceptable risk for a company to use. Not only is it likely that an attacker could use a related exploit to gain access into the system from a shutdown state, they then would be able to easily gain access into Okta from the same system, and likely do so without triggering any system health checks.&lt;/p&gt;
&lt;h2 id=&quot;low-level-risk-analysis-for-server-validated-2fa&quot;&gt;Low-Level Risk Analysis for Server-validated 2FA&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;/images/fido2-2fa-low.png&quot; alt=&quot;alt text&quot; /&gt;&lt;/p&gt;
&lt;h3 id=&quot;6-password-yubikey-pin-advised&quot;&gt;6. Password + YubiKey + PIN (Advised)&lt;/h3&gt;
&lt;p&gt;6a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;6b. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;YubiKeys are easily lost or stolen. However, the use of a PIN to authenticate the user to the YubiKey significantly mitigates this risk.&lt;/p&gt;
&lt;p&gt;6c. Note&lt;/p&gt;
&lt;p&gt;One issue that may arise with this method is that users may reuse a passcode that they use somewhere else in their life, like an ATM card passcode. It’s advised that users use 6 digit passcodes (or more) instead of 4. The FIPS-series of YubiKeys require 6 digits minimally.&lt;/p&gt;
&lt;p&gt;6d. Note&lt;/p&gt;
&lt;p&gt;This combined MFA method has strong security properties: something you know, something you have, and something else that you know.&lt;/p&gt;
&lt;p&gt;6e. Note&lt;/p&gt;
&lt;p&gt;Like YubiKey Bio devices, YubiKey + PIN ensures a limited amount of failed authentication attempts. A YubiKey will cease functioning after a certain amount of retries. This security control is in addition to Okta’s limit of failed authentication attempts.&lt;/p&gt;
&lt;h3 id=&quot;7-password-yubikey-bio-advised&quot;&gt;7. Password + YubiKey Bio (Advised)&lt;/h3&gt;
&lt;p&gt;7a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;7b. Spoofing Risk, Medium&lt;/p&gt;
&lt;p&gt;Bioreaders are susceptible to artificially constructed fingers/faces. The risk of Windows Hello spoofing is high due to Microsoft’s and OEM’s track record of inferior technology compared to Apple. However, the risk is lowered due to the moderate second factor provided by a password.&lt;/p&gt;
&lt;p&gt;7c. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;YubiKeys are easily lost or stolen. However, the use of a bioprint to authenticate the user to the YubiKey significantly mitigates this risk.&lt;/p&gt;
&lt;p&gt;7d. Note&lt;/p&gt;
&lt;p&gt;Bioprint validation of a YubiKey mitigates a great deal of risk associated with loss/theft risks of a YubiKey, and when combined with a password, this has strong security properties: something you know, something you have, and something you are.&lt;/p&gt;
&lt;h3 id=&quot;8-password-macos-secure-enclave-touch-id-advised&quot;&gt;8. Password + macOS Secure Enclave + Touch ID (Advised)&lt;/h3&gt;
&lt;p&gt;8a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;8b. Spoofing Risk, Medium&lt;/p&gt;
&lt;p&gt;Touch ID, like any bioreader, is susceptible to artificially constructed fingers/faces. Like YubiKey Bio devices and YubiKey + PIN, Touch ID ensures a limited amount of failed authentication attempts. Touch ID will cease functioning after a certain amount of retries. This security control is in addition to Okta’s limit of failed authentication attempts.&lt;/p&gt;
&lt;p&gt;8c. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;Laptops are fairly trivial to steal. When stealing a Macbook, the Secure Enclave + bioreader that allows Touch ID to function is lost too. During a targeted attack, Touch ID compromise risk would be considered a High Risk if it were not for the mitigating factor of MFA.&lt;/p&gt;
&lt;p&gt;8d. Phishing Risk, Medium&lt;/p&gt;
&lt;p&gt;While the auth method characteristic Phishing Resistant is true, in a broader sense, due to the nature of cloud-synced passkeys, there is meaningful, extrinsic phishing risk that a company should consider. Due to how Apple employs passkeys, requiring a reliance on Apple Passwords (formerly iCloud Keychain), Apple passkeys are not Device Bound. If an attacker is able to social engineer a user to gain access to a user&#39;s Apple account, the attacker may be able to gain access to passkey private key material. If a user is signed into their personal Apple account, companies will have little to no control or visibility into personal accounts.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I go into greater detail looking at Apple iCloud Keychain risks later in this article (WIP).&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;8e. Note&lt;/p&gt;
&lt;p&gt;Even though there are two Medium risks identified, the combination of a Password + Touch ID adequately mitigates the Medium risks. While passwords alone are vulnerable to phishing attacks, the second factor mitigates the overall risk considerably. Touch ID consists of two strong factors due to Apple’s strong, integrated design: Secure Enclave is something you have, and Touch ID (the biometric reader component) attests something you are. There are no known vulnerabilities between Secure Enclave and the fingerprint reader, unlike TPM + Windows Hello.&lt;/p&gt;
&lt;h3 id=&quot;9-password-chromebook-tpm-fingerprint-advised&quot;&gt;9. Password + Chromebook TPM + fingerprint (Advised)&lt;/h3&gt;
&lt;p&gt;9a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;9b. Spoofing Risk, Medium&lt;/p&gt;
&lt;p&gt;Bioreaders are susceptible to artificially constructed fingers or faces. The risk is increased to Medium since a threat actor is likely in possession of the first client-validated auth factor (TPM) when a laptop is also lost or stolen.&lt;/p&gt;
&lt;p&gt;Like YubiKey Bio risks, if a specific user&#39;s threat model includes determined or well-funded threat actors, this Spoofing risk rating should be increased to High and automatically the overall risk rating should be changed to Not Advised.&lt;/p&gt;
&lt;p&gt;9c. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;Since one’s fingerprint is validating the user to TPM, and since both TPM and the bioreader is lost when a Chromebook is lost or stolen, it carries similar risks when a YubiKey Bio is lost or stolen.&lt;/p&gt;
&lt;p&gt;9d. Phishing Risk, Medium&lt;/p&gt;
&lt;p&gt;While the auth method characteristic &lt;strong&gt;Phishing Resistant&lt;/strong&gt; is true, in a broader sense, due to the nature of cloud-synced passkeys, there is meaningful phishing risk that a company should consider. Ever since Google changed how passkeys are managed in Chrome, passkeys are no longer Device Bound. If an attacker is able to social engineer a user to gain access to a user&#39;s Google account, the attacker may be able to gain access to passkey private key material. If a user is signed into their personal Google account, companies will have little to no control or visibility into personal accounts.&lt;/p&gt;
&lt;p&gt;9e. Note&lt;/p&gt;
&lt;p&gt;Adding a second server-validated auth factor does reduce risk. However, due to the nature of passwords, the risk is not significantly reduced. It&#39;s important to call out the increased risks even if they are marginal in a server-validated 2FA situation.&lt;/p&gt;
&lt;h3 id=&quot;10-password-push-not-advised&quot;&gt;10. Password + Push (Not Advised)&lt;/h3&gt;
&lt;p&gt;10a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;10b. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;Personal cell phones are fairly trivial to steal. During a targeted attack, passcode (public shoulder surfing, etc) compromise risk would be considered a High Risk if it were not for the mitigating factor of MFA.&lt;/p&gt;
&lt;p&gt;10c. Phishing Risk, High&lt;/p&gt;
&lt;p&gt;Since users might receive frequent push notifications, they could inadvertently approve a fraudulent request, especially if the attacker times it with a legitimate login attempt. Further, push-based authentication is particularly vulnerable to what&#39;s known as an &#39;exhaustion attack&#39;. Threat actors may repeatedly send fraudulent push authentication requests to the user&#39;s device. Over time, the user, overwhelmed or desensitized by the constant stream of requests, may inadvertently approve a malicious request.&lt;/p&gt;
&lt;p&gt;10d. Note&lt;/p&gt;
&lt;p&gt;Both methods here individually carry high risks for phishing, so one method does not significantly mitigate the risks with the other.&lt;/p&gt;
&lt;h3 id=&quot;11-password-totp-not-advised&quot;&gt;11. Password + TOTP (Not Advised)&lt;/h3&gt;
&lt;p&gt;11a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;11b. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;Personal cell phones are fairly trivial to steal. During a targeted attack, passcode (public shoulder surfing, etc) compromise risk would be considered a High Risk if it were not for the mitigating factor of MFA. Further, Google account takeover during targeted attack carries risk given Google Authenticator’s recent change to sync TOTP private tokens to Google Cloud for ease of use.&lt;/p&gt;
&lt;p&gt;11c. Phishing Risk, High&lt;/p&gt;
&lt;p&gt;Threat actors can create fake login pages that prompt users to enter their TOTP . Once the user inputs the TOTP into the phishing site, the attacker can quickly use it to gain unauthorized access to the user&#39;s account, as these passwords are typically valid for a short period (usually 30 seconds to a minute). This type of attack requires speed but is entirely feasible, given the automated nature of many phishing tools. Further, TOTP passcodes in apps like Google Authenticator are more susceptible than passwords when it comes to spear phishing.&lt;/p&gt;
&lt;p&gt;11d. Note&lt;/p&gt;
&lt;p&gt;Both methods here individually carry high risks for phishing, so one method does not significantly mitigate the risks with the other.&lt;/p&gt;
&lt;h3 id=&quot;12-password-yubikey-advised&quot;&gt;12. Password + YubiKey (Advised)&lt;/h3&gt;
&lt;p&gt;12a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;strong&gt;User Verifying&lt;/strong&gt; characteristic is added back because of the use of a password.&lt;/p&gt;
&lt;p&gt;12b. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;YubiKeys are fairly trivial to steal. A YubiKey with no PIN to validate the user is a High risk. The overall risk is reduced since of the layered security of a password. Strictly speaking, it meets all of the Auth Method Characteristics defined earlier.&lt;/p&gt;
&lt;p&gt;12c. Phishing Risk, Medium&lt;/p&gt;
&lt;p&gt;Passwords are generally susceptible to phishing and other attacks. The reason why Phishing risk is not High is because of the layered security of the YubiKey.&lt;/p&gt;
&lt;p&gt;12d. Note&lt;/p&gt;
&lt;p&gt;The combination of Password + YubiKey does not adequately mitigate overall risk for a determined attacker. Password reuse is highly likely, in part because of commonly forced password changes at a company, and due to the fact that individual’s passwords are harvested via database hacks almost everywhere on the internet. The two factors are both weak, even when combined, if a company or user&#39;s threat model includes medium to high risk of targeted attack.&lt;/p&gt;
&lt;h3 id=&quot;13-password-windows-hello-not-advised&quot;&gt;13. Password + Windows Hello (Not Advised)&lt;/h3&gt;
&lt;p&gt;13a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;13b. Spoofing Risk, Medium&lt;/p&gt;
&lt;p&gt;Bioreaders are susceptible to artificially constructed fingers/faces, especially on Windows laptops. The risk of Windows Hello spoofing is high due to Microsoft’s and OEM’s track record of inferior technology compared to Apple, but the moderate security provided by the second factor of a password lowers the overall spoofing risk.&lt;/p&gt;
&lt;p&gt;13c. Targeted Theft Risk, Medium&lt;/p&gt;
&lt;p&gt;Laptops do not require a great deal of effort to steal for a determined threat actor. Combined with the Critical Risk associated with Windows Hello, and the overall risk (platform insecurity) with Windows laptops in general, this has an increased risk.&lt;/p&gt;
&lt;p&gt;13d. Technical Vulnerabilities, Critical&lt;/p&gt;
&lt;p&gt;There are active, cheap, unpatched exploits against Windows Hello; specifically, on WebAuthn-compliant Dell laptops. In short, a threat actor is able to enroll a fingerprint into the company-owned Dell fingerprint sensor and use that arbitrary fingerprint to authenticate via Windows Hello. This attack would allow a threat actor to log into Windows without a password (if configured) and authenticate into Okta if the threat actor also had the user’s password. Based on the public information about these exploits, they do not appear to be patchable. company does not have adequate firmware patching controls in place, potentially allowing an attacker to boot into Linux on a stolen Windows laptop in order to perform this specific arbitrary-fingerprint-enrollment attack.&lt;/p&gt;
&lt;p&gt;13e. Note&lt;/p&gt;
&lt;p&gt;Windows Hello has a long history of insecurity. Due to the fact that Microsoft has to develop OS/kernel support for third-party hardware, third-party firmware, and third-party drivers (which are notoriously bad) for the underpinning of Windows Hello to work on millions of laptop SKUs, Windows Hello will likely never be as secure compared to a fully integrated, locked down Apple Macbook.&lt;/p&gt;
&lt;h3 id=&quot;14-password-sms-dangerous&quot;&gt;14. Password + SMS (Dangerous)&lt;/h3&gt;
&lt;p&gt;14a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;14b. Spoofing Risk, High&lt;/p&gt;
&lt;p&gt;The risk associated with SIM card spoofing (aka duplicating or cloning, with the help of a social engineered or coerced telecommunications company) is significant, particularly when facing a determined adversary. This attack allows unauthorized access to copies of an individual&#39;s SMS messages, including those containing one-time passcodes.&lt;/p&gt;
&lt;p&gt;14c. Targeted Theft Risk, High&lt;/p&gt;
&lt;p&gt;The risk associated with SIM card hijacking is significant, particularly when facing a determined adversary. This attack allows unauthorized access to an individual&#39;s SMS messages, including those containing one-time passcodes.&lt;/p&gt;
&lt;p&gt;14d. Phishing Risk, High&lt;/p&gt;
&lt;p&gt;SMS-based passcodes, although typically time-sensitive, are highly susceptible to phishing attacks. It&#39;s common for attackers to impersonate corporate IT or security personnel, using intimidation tactics to extract these passcodes from unwary employees.&lt;/p&gt;
&lt;p&gt;14e. Technical Vulnerabilities, Critical&lt;/p&gt;
&lt;p&gt;The underlying technology of telecommunication networks, particularly SS7 (Signaling System No. 7), presents a critical vulnerability for SMS passcodes. This legacy technology means SMS messages are essentially unencrypted during transmission, allowing determined attackers to intercept or even reroute these messages. This inherent vulnerability in SS7 is fundamental and unlikely to be rectified in the future.&lt;/p&gt;
&lt;h3 id=&quot;15-password-questions-dangerous&quot;&gt;15. Password + Questions (Dangerous)&lt;/h3&gt;
&lt;p&gt;15a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;15b. Targeted Theft Risk, Critical&lt;/p&gt;
&lt;p&gt;The often easily discoverable nature of answers to “security questions” cannot be understated. These questions are often easily obtainable by a determined social engineer. Personal information used as answers may be accessible through social media or other public records. Further, the sheer amount of hacked information from other companies makes information disclosure a pervasive and escalating concern. The frequent occurrence of data breaches means that personal information often used in security questions may already be exposed and accessible to threat actors of all kinds.&lt;/p&gt;
&lt;p&gt;If a user is targeted for obtaining answers to basic questions, it is equally trivial to target them for passwords. The overall risk here is not reduced for targeted attacks in part because both vulnerabilities are remotely exploitable.&lt;/p&gt;
&lt;p&gt;15c. Phishing Risk, High&lt;/p&gt;
&lt;p&gt;“Security questions” are highly vulnerable to phishing attacks, even more so than passwords. Attackers can trick users into revealing their answers through deceptive emails, social media messages, or fake security prompts. This is an even higher risk if the server-validated challenges are static questions. The overall risk is reduced to High because of the layered security offered by the server-validated 2FA password.&lt;/p&gt;
&lt;h2 id=&quot;low-level-risk-analysis-for-passwordless-server-validated-1fa-client-validated-1fa&quot;&gt;Low-Level Risk Analysis for Passwordless, server-validated 1FA, client-validated 1FA&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;/images/fido2-1fa-2-low.png&quot; alt=&quot;alt text&quot; /&gt;&lt;/p&gt;
&lt;h3 id=&quot;16-yubikey-not-advised&quot;&gt;16. YubiKey (Not Advised)&lt;/h3&gt;
&lt;p&gt;16a. Combined Auth Method Characteristics&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Presence&lt;/li&gt;
&lt;li&gt;Phishing Resistant&lt;/li&gt;
&lt;li&gt;Device Bound&lt;/li&gt;
&lt;li&gt;Hardware Protected&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Verifying&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;16b. Targeted Theft Risk, Critical&lt;/p&gt;
&lt;p&gt;A YubiKey with no PIN to validate the user is a significant risk, even if it is not remotely exploitable.&lt;/p&gt;
&lt;p&gt;A significant risk of using a YubiKey only, with no PIN and no other auth factor, is from coworkers or even family members. People close to the employee likely knows exactly how to use a stolen YubiKey, knows who it&#39;s for, and likely understands what access it grants them. The only way to lessen the risk is to layer on Okta or MDM managed system health checks so that a YubiKey cannot be used from a system that does not belong to the company. If a device is not managed properly and does not quickly enable a system lock screen due to inactivity, using a stolen YubiKey from the targeted user&#39;s own computer is a significant risk and would cause inaccurate audit logs, further protecting the attacker.&lt;/p&gt;
&lt;p&gt;Then there is also coworker sharing. This is different from a coworker stealing a fellow employee&#39;s YubiKey. This is intentional sharing of access. Further, if a coworker has temporary access to a peer&#39;s Okta account, they would be able to add their own YubiKey, allowing them to have permanent, long-term access to their coworker&#39;s SSO.&lt;/p&gt;
&lt;p&gt;16c. Note&lt;/p&gt;
&lt;p&gt;Accidental Loss is a Low risk because someone who finds an arbitrary YubiKey is not likely to know who it belongs to or what accounts it is used for. This information is not discoverable from posession of a YubiKey.&lt;/p&gt;
&lt;p&gt;Theft for Resale is Low because YubiKeys are not particularly valuable to the general public.&lt;/p&gt;
&lt;p&gt;When an employee notices that they are missing their YubiKey, they must report it to the company, and IT must simply unenroll the YubiKey from Okta to mitigate all risk.&lt;/p&gt;
&lt;h1 id=&quot;adoption-challenges&quot;&gt;Adoption Challenges&lt;/h1&gt;
&lt;h2 id=&quot;weak-defaults&quot;&gt;Weak Defaults&lt;/h2&gt;
&lt;p&gt;First and foremost, SSO accounts cannot have weak fallback authentication options. A company can&#39;t allow users (or attackers) to downgrade authentication with the IdP by way of supporting weak (phishing-vulnerable) reset mechanisms such as TOTP, &quot;security questions&quot;, static &quot;backup codes&quot;, or SMS. If a user has a YubiKey enrolled in their SSO account but the company allows a user to get back into their account via email OTP alone, then an attacker can simply ignore the YubiKey and attack the phishing-vulnerable OTP code. Whatever strategy the company comes up with has to balance ease of use and security.&lt;/p&gt;
&lt;p&gt;Apple has an advanced security feature called &quot;&lt;a rel=&quot;external&quot; href=&quot;https://support.apple.com/en-us/102637&quot;&gt;Security Keys&lt;/a&gt;&quot; that users can enroll into. In order to activate this Apple iCloud security feature, a user has to enroll two YubiKeys. Enrolling two keys allows a user to keep a secondary YubiKey in a secured, static location, like in a fireproof box. Or better, in an off-site fireproof box. If the first key is lost, there&#39;s a second, pre-enrolled key to fall back on. Companies can do something similar: make users enroll at least two WebAuthn factors, like:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;two or more passkeys&lt;/li&gt;
&lt;li&gt;one passkey and one YubiKey, or&lt;/li&gt;
&lt;li&gt;two or more YubiKeys&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Users would be able to sign in with any one of those factors, and users should be forced to remove all weak factors from their SSO account.&lt;/p&gt;
&lt;h2 id=&quot;weak-authenticator-reset-strategies&quot;&gt;Weak Authenticator Reset Strategies&lt;/h2&gt;
&lt;p&gt;Even with multiple WebAuthn factors enrolled, some users will still lose all their auth factors. This fact requires a thoughtful set of user support and verification policies, standards, and processes. Further in this article, I will go into more detail offering some robust authenticator reset strategies.&lt;/p&gt;
&lt;h1 id=&quot;work-in-progress&quot;&gt;Work in Progress&lt;/h1&gt;
&lt;p&gt;I have more content to add to this article, but it needs to be matured before I publish it.&lt;/p&gt;
&lt;p&gt;Thank you for reading!&lt;/p&gt;
&lt;br&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>HSTS-preload Mastodon</title>
        <published>2024-10-30T00:00:00+00:00</published>
        <updated>2024-10-30T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/hsts-preload-mastodon/"/>
        <id>https://yawnbox.eu/blog/hsts-preload-mastodon/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/hsts-preload-mastodon/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;I run the &lt;a rel=&quot;external&quot; href=&quot;https://disobey.net/&quot;&gt;disobey.net&lt;/a&gt; Mastodon instance. I self-host these as standalone servers built from source, not Docker.&lt;/p&gt;
&lt;h2 id=&quot;why-hsts-preload&quot;&gt;Why HSTS-preload?&lt;/h2&gt;
&lt;p&gt;Mastodon admins should care about their domain being HSTS-preloaded to enhance user security and protect against targeted network attacks, but also enhances defences for users from sweeping network surveillance in the future leading to internet censorship.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Yes, your nginx config should automatically upgrade any HTTP requets to HTTPS during any visit. That&#39;s after a potential HTTP handshake is sent.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Yes, the default HSTS (non-preload) header set by Mastodon/Rails, and by Let&#39;s Encrypt Certbot in nginx (non-preload), will make it so any second visit to the domain from a user&#39;s browser will only ever send TLS handshakes before sending clear-text HTTP handshakes. Again, that&#39;s after an HTTP handshake is sent during a first visit.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;And, yes, modern browsers should all default to trying HTTPS first even if a user only enters &quot;disobey.net&quot; into their address bar. But what if a browser or Mastodon app fails the user?&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By being HSTS-preloaded, your Mastodon domain will be on a list of HSTS domains built into their web browser. This means even first-time visitors are protected from MitM attacks because clear-text HTTP headers will never be sent to the web server.&lt;/p&gt;
&lt;p&gt;This has even more value once &lt;a rel=&quot;external&quot; href=&quot;https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-22&quot;&gt;TLS Encrypted Client Hello (ECH)&lt;/a&gt; becomes mainstream, particularly for people living behind government surveillance and censorship. If a user is observed going to a censored Mastodon domain the first time, there might not be a first visit, let alone a second or third visit.&lt;/p&gt;
&lt;h1 id=&quot;pre-config-validation&quot;&gt;Pre-config validation&lt;/h1&gt;
&lt;p&gt;In a terminal window, I can see that my strict-transport-security header does not have the preload option:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;curl -I https://disobey.net |grep strict&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The last line shows:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;strict-transport-security: max-age=63072000; includeSubDomains&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We can see that there is no &quot;preload&quot; flag at the end, and this is with an nginx config that explicitly, presumably adds HSTS-preload:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;add_header Strict-Transport-Security &amp;quot;max-age=63072000; includeSubDomains; preload&amp;quot;;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Obviosuly setting this in nginx is not enough. The problem is Rails.&lt;/p&gt;
&lt;h1 id=&quot;mastodon-changes&quot;&gt;Mastodon changes&lt;/h1&gt;
&lt;p&gt;All file editing below is from my Mastodon root directory, &quot;&lt;strong&gt;~/live&lt;/strong&gt;&quot;.&lt;/p&gt;
&lt;p&gt;You will only need to edit this one file:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim config/environments/production.rb&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Find the &quot;config.ssl_options&quot; line. Immediately under it, add:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;hsts: { preload: true },&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It should be indented the same as the line below it:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/hsts-preload-mastodon.jpg&quot; alt=&quot;added hsts preload line&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Save and quit, if you&#39;re using vim:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;:wq&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;As the &lt;strong&gt;mastodon&lt;/strong&gt; user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;RAILS_ENV=production bundle exec rails assets:precompile&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;As &lt;strong&gt;root&lt;/strong&gt; user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemctl restart mastodon-web mastodon-sidekiq mastodon-streaming&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;post-config-validation&quot;&gt;Post-config validation&lt;/h1&gt;
&lt;p&gt;In a terminal window, I can see that my strict-transport-security header is now set correctly:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;curl -I https://disobey.net |grep strict&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The last line shows:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;strict-transport-security: max-age=63072000; includeSubDomains; preload&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&quot;add-your-domain-to-the-hsts-preload-list&quot;&gt;Add your domain to the HSTS-preload list&lt;/h1&gt;
&lt;p&gt;Now you can add your domain to Google&#39;s HSTS-preload list: &lt;a rel=&quot;external&quot; href=&quot;https://hstspreload.org&quot;&gt;https://hstspreload.org&lt;/a&gt;
&lt;br&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Create Curseforge Modded Minecraft Server Files for Linux</title>
        <published>2024-10-11T00:00:00+00:00</published>
        <updated>2024-10-11T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/curseforge-modded-minecraft-server-files-for-linux/"/>
        <id>https://yawnbox.eu/blog/curseforge-modded-minecraft-server-files-for-linux/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/curseforge-modded-minecraft-server-files-for-linux/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;&lt;strong&gt;This guide aims to document how to create a modded Minecraft linux server from a Curseforge modpack that does not have server files.&lt;/strong&gt; My example uses a linux server on the internet with public IPs. If you&#39;re a modpack dev trying to make server files for your Curseforge page, you may be able to adapt this guide, but this guide is not written for you.&lt;/p&gt;
&lt;p&gt;In my example for the purposes of writing this, I&#39;m testing &lt;a rel=&quot;external&quot; href=&quot;https://www.curseforge.com/minecraft/modpacks/inconvenient&quot;&gt;An Inconvenient Modpack&lt;/a&gt; which uses Forge 1.18.2.&lt;/p&gt;
&lt;p&gt;I&#39;m using Ubuntu Server 22.04 LTS. You need to have root/sudo privileges and local or ssh access to your server.&lt;/p&gt;
&lt;h1 id=&quot;install-dependencies&quot;&gt;Install dependencies&lt;/h1&gt;
&lt;p&gt;In my work below, I depend on unzip and jq. As a privileged (sudo) user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt install unzip jq -V&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;install-java&quot;&gt;Install Java&lt;/h1&gt;
&lt;p&gt;I believe you can use any version of Java that you like, but I recommend using the latest Adoptium&#39;s Eclipse Temurin v21. However I use the bleeding edge v23 and it works great too.&lt;/p&gt;
&lt;p&gt;Installation documentation: &lt;a rel=&quot;external&quot; href=&quot;https://adoptium.net/installation/&quot;&gt;https://adoptium.net/installation/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;v21, as a privileged (sudo) user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt install temurin-21-jdk&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;v23 (see &lt;a rel=&quot;external&quot; href=&quot;https://adoptium.net/temurin/releases/?version=23&quot;&gt;https://adoptium.net/temurin/releases/?version=23&lt;/a&gt;), as a privileged (sudo) user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo mkdir -p /etc/apt/keyrings&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo wget -O - https://packages.adoptium.net/artifactory/api/gpg/key/public | tee /etc/apt/keyrings/adoptium.asc&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo echo &quot;deb [signed-by=/etc/apt/keyrings/adoptium.asc] https://packages.adoptium.net/artifactory/deb $(awk -F= &#39;/^VERSION_CODENAME/{print$2}&#39; /etc/os-release) main&quot; | tee /etc/apt/sources.list.d/adoptium.list&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt update &amp;amp;&amp;amp; apt install temurin-23-jdk zip -V&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Validate the Java version:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;/usr/bin/java --version&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The output should look like:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;openjdk 23 2024-09-17&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;OpenJDK Runtime Environment Temurin-23+37 (build 23+37)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;OpenJDK 64-Bit Server VM Temurin-23+37 (build 23+37, mixed mode, sharing)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&quot;create-an-isolated-linux-user-for-security&quot;&gt;Create an isolated Linux user for security&lt;/h1&gt;
&lt;p&gt;As a privileged (sudo) user, create a limited non-privileged user called &quot;minecraft&quot; that will be running the Minecraft server:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo adduser --system --home /home/minecraft --group --shell /usr/sbin/nologin minecraft&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Create a new folder for the server, i refer to this folder as my &quot;working folder&quot; for the majority of this guide:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo mkdir /home/minecraft/inconvenient&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Now change to your new minecraft user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo su minecraft&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Go to the working directory:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;cd /home/minecraft/inconvenient&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;download-the-curseforge-modpack&quot;&gt;Download the Curseforge Modpack&lt;/h1&gt;
&lt;p&gt;As of writing, &lt;a rel=&quot;external&quot; href=&quot;https://www.curseforge.com/minecraft/modpacks/inconvenient&quot;&gt;An Inconvenient Modpack&lt;/a&gt; (my example) is at version 0.6.10. Find the download link from your modpack&#39;s Curseforge page.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;wget https://mediafilez.forgecdn.net/files/5802/672/An%20Inconvenient%20Modpack%200.6.10.zip&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;unzip An\ Inconvenient\ Modpack\ 0.6.10.zip&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;download-forge&quot;&gt;Download Forge&lt;/h1&gt;
&lt;p&gt;An Inconvenient Modpack (my example) depends on Forge 1.18.2. Determine which Forge version you need. In a web browser, go to: &lt;a rel=&quot;external&quot; href=&quot;https://files.minecraftforge.net/net/minecraftforge/forge/index_1.18.2.html&quot;&gt;https://files.minecraftforge.net/net/minecraftforge/forge/index_1.18.2.html&lt;/a&gt;. Note: I have not tested this with NeoForge.&lt;/p&gt;
&lt;p&gt;You will see an &quot;Installer&quot; link under &quot;Download Latest&quot;. Right-click that &quot;Installer&quot; link and click &quot;Copy Link&quot;.&lt;/p&gt;
&lt;p&gt;The link you copy will look like:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https://adfoc.us/serve/sitelinks/?id=271228&amp;amp;url=https://maven.minecraftforge.net/net/minecraftforge/forge/1.18.2-40.2.21/forge-1.18.2-40.2.21-installer.jar&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Delete the first part of that link. They add it for link tracking and it breaks a simple wget download on linux:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https://adfoc.us/serve/sitelinks/?id=271228&amp;amp;url=&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The second part of the original link is what you need:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https://maven.minecraftforge.net/net/minecraftforge/forge/1.18.2-40.2.21/forge-1.18.2-40.2.21-installer.jar&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Download the jar file:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;wget https://maven.minecraftforge.net/net/minecraftforge/forge/1.18.2-40.2.21/forge-1.18.2-40.2.21-installer.jar&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Make the jar file executable:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;chmod +x forge-1.18.2-40.2.21-installer.jar&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;download-the-modpack-s-mods&quot;&gt;Download the modpack&#39;s mods&lt;/h1&gt;
&lt;p&gt;The Curseforge modpack zip file doesn&#39;t come with the mods, it comes with a &quot;manifest.json&quot; file with a list of mods that need to be downloaded. I made a shell script to parse the &quot;manifest.json&quot; file from any modpack to automatically create the mods folder then download all (200+ in my case) mods for the modpack.&lt;/p&gt;
&lt;p&gt;Create the shell script file. I use vim, you can use nano, etc:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim download-mods.sh&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Paste in this shell script:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#!/bin/bash&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Ensure jq is installed&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;if ! command -v jq &amp;amp;&amp;gt; /dev/null; then&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    echo &amp;quot;jq could not be found. Please install it using your package manager.&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    exit 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;fi&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Create mods directory if it doesn&amp;#39;t exist&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mkdir -p mods&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Loop through each mod in manifest.json&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;jq -r &amp;#39;.files[] | .downloadUrl&amp;#39; manifest.json | while read -r url; do&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    if [ -n &amp;quot;$url&amp;quot; ]; then&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        # Extract filename from the URL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        filename=$(basename &amp;quot;$url&amp;quot;)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        # Show download progress&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        echo -e &amp;quot;\nDownloading: $filename&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        # Download the file with minimal curl output&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        curl -L -o &amp;quot;mods/$filename&amp;quot; &amp;quot;$url&amp;quot; --silent --show-error&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        # Check if the download succeeded&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        if [ $? -eq 0 ]; then&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;            echo &amp;quot;✓ Downloaded $filename successfully&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        else&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;            echo &amp;quot;✗ Failed to download $filename&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        fi&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    else&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        echo &amp;quot;No download URL found for a mod entry.&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    fi&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;done&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo -e &amp;quot;\nAll downloads completed.&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Save and quit vim:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;:wq&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Make the script executable:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;chmod +x download-mods.sh&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Run the script to download the mods:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;./download-mods.sh&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Once the download is complete, you can see all of the mods with:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ls -alh mods/&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;If you need to update one or more mods, it&#39;s easiest to just delete the whole mods folder then redownload everything with the same manifest download script.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;rm -rf mods/&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;./download-mods.sh&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Be sure to delete the client-side mods!&lt;/p&gt;
&lt;h1 id=&quot;deleting-client-side-mods&quot;&gt;Deleting client-side mods&lt;/h1&gt;
&lt;p&gt;Deleting client-side mods is critical for server files. If there are client-only mods in a server, the server probably won&#39;t launch. There&#39;s lots of ways to do this, but there&#39;s not one great answer. Not all mods clearly indicate on the Curseforge page that they are or are not client-side or server-side mods. I&#39;ve had to resolve this with trial and error. Later on in this guide, once the server is in a startable/stoppable state, you can read the error logs to see which mods are client-side only then delete them from the mods folder.&lt;/p&gt;
&lt;p&gt;For example, Oculus is a client side mod in An Inconvenient Modpack that needs to be deleted. The server won&#39;t start with it:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;rm /home/minecraft/inconvenient/mods/oculus-*.jar&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;copy-over-the-modpack-configs&quot;&gt;Copy over the modpack configs&lt;/h1&gt;
&lt;p&gt;After the earlier step where we unzipped the modpack, an &quot;overrides&quot; folder was created in our working directory. Copy its contents into our working directory:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;cp -r overrides/* .&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;install-and-test-the-server&quot;&gt;Install and test the server&lt;/h1&gt;
&lt;p&gt;Install the base server files:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;java -jar forge-1.18.2-40.2.21-installer.jar --installServer&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Edit the server properties file that gets created:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim server.properties&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;In server.properties, the &quot;level-name=world&quot; line tells the server where the world folder/files are. For example, in An Inconvenient Modpack that has a pre-built world, that world folder is &quot;template&quot;. So for me, I changed the level-name to &quot;level-name=template&quot;.&lt;/p&gt;
&lt;p&gt;Other things I typically change in server.properties:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;motd=your.domain.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;difficulty=hard&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;max-players=9000&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;allow-flight=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;view-distance=20&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;server-ip=1.2.3.4&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;server-name=your.domain.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;level-type=AMPLIFIED&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Accept the EULA:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;rm -f eula.txt &amp;amp;&amp;amp; touch eula.txt &amp;amp;&amp;amp; echo &#39;eula=true&#39; &amp;gt;&amp;gt; eula.txt &amp;amp;&amp;amp; cat eula.txt&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Run the server for the first time:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;./run.sh&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Presuming the server runs without errors, once it launches fully, type stop to stop the server&lt;/p&gt;
&lt;p&gt;&lt;code&gt;stop&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;If the server has errors and it hasn&#39;t full started, you&#39;ll need to stop the process with ctrl + c keys on your keyboard, then figure out what went wrong.&lt;/p&gt;
&lt;p&gt;If you have errors, I can&#39;t help you, so please don&#39;t ask for help. They are either client-side mod errors, or you need to report the errors either to the owner of the modpack or to the owner of the respective mod. Java errors are frustratingly unhelpful so I am very sorry if you have to deal with them.&lt;/p&gt;
&lt;h1 id=&quot;create-a-systemd-service-for-security-and-ease-of-use&quot;&gt;Create a systemd service for security and ease of use&lt;/h1&gt;
&lt;p&gt;Note: I would have used a Java Security Manager policy to harden Java, but that&#39;s being depreciated in newer versions of Java. Since we want to always use the most recent version of Java possible for security and performance reassons, I use a hardened systemd service to manage Java Minecraft.&lt;/p&gt;
&lt;p&gt;As a privileged (sudo) user, create a new Minecraft systemd service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/systemd/system/minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Copy and paste all of these lines into the minecraft.service file:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Unit]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Description=Modded Minecraft Server&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;After=network.target&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Service]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;User=minecraft&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Group=minecraft&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Restrict local network access to local IPs&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;IPAddressAllow=103.232.207.250&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;IPAddressAllow=2620:18c:0:192::250&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Security Enhancements&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;AmbientCapabilities=CAP_NET_BIND_SERVICE&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;CapabilityBoundingSet=CAP_NET_BIND_SERVICE&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;LockPersonality=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NoNewPrivileges=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectSystem=full&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectClock=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateDevices=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelLogs=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateTmp=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateUsers=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProcSubset=pid&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectControlGroups=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelModules=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelTunables=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectProc=invisible&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectSystem=strict&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RemoveIPC=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictAddressFamilies=AF_INET AF_INET6&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictNamespaces=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictRealtime=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictSUIDSGID=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SystemCallFilter=@system-service&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SystemCallArchitectures=native&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Paths related to the Minecraft server&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadOnlyPaths=/usr/bin/java&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadOnlyPaths=/usr/lib/jvm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadWritePaths=/home/minecraft/inconvenient&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;WorkingDirectory=/home/minecraft/inconvenient&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# JVM flags for performance optimization&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExecStart=/home/minecraft/inconvenient/run.sh --nogui&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Install]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;WantedBy=multi-user.target&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&quot;important-minecraft-service-file-notes&quot;&gt;Important minecraft.service file notes:&lt;/h2&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;IPAddressAllow=103.232.207.250&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;IPAddressAllow=2620:18c:0:192::250&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ These two lines limit which IPv4 and IPv6 addresses can be used. Be sure to change these to your server&#39;s IPs. If you don&#39;t have an IPv6 address, remove the line.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadOnlyPaths=/usr/bin/java&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadOnlyPaths=/usr/lib/jvm&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ These two paths are to make sure Java can be called. The JVM folder is where Temurin is installed. These lines shouldn&#39;t need to change.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadWritePaths=/home/minecraft/inconvenient&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;WorkingDirectory=/home/minecraft/inconvenient&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ These two paths are the same, as they are where the modpack is downloaded to.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExecStart=/home/minecraft/inconvenient/run.sh --nogui&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ This line clearly shows the run.sh file in our working directory. This is how the modpack will launch. If you want to tune the JVM arguments, I share how to do that later in this guide.&lt;/p&gt;
&lt;h2 id=&quot;continue-systemd-setup&quot;&gt;Continue systemd setup&lt;/h2&gt;
&lt;p&gt;Save the minecraft.service file (via vim):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;:wq&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Reload systemd:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl daemon-reload&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Note: everytime the minecraft.service file is updated, this daemon-reload must be re-run.&lt;/p&gt;
&lt;p&gt;Enable the new service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl enable minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Start Minecraft for the first time to setup the files:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl start minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;You can see the service status with:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl status minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;You can see the logging output with:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo journalctl -u minecraft.service -f&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;firewalling-minecraft&quot;&gt;Firewalling Minecraft&lt;/h1&gt;
&lt;p&gt;Be sure that you understand Ubuntu&#39;s firewall, ufw, and if its already enabled on your server before you make any changes. You don&#39;t want to lock yourself out of your server, like if you&#39;re not already allowing 22/tcp for ssh.&lt;/p&gt;
&lt;p&gt;View existing rules, as a privileged (sudo) user:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw status verbose numbered&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;If it&#39;s not active, then you don&#39;t need to open up the port. But i&#39;d urge you to learn about ufw and start using it if you&#39;re not.&lt;/p&gt;
&lt;p&gt;Presuming you have already enabled the firewall for server security, open up the default Minecraft port. I use &quot;limit&quot; instead of &quot;allow&quot; to prevent DoS attacks:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw limit 25565/tcp&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To apply the firewall change:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw reload&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;tuning-the-jvm-arguments&quot;&gt;Tuning the JVM arguments&lt;/h1&gt;
&lt;p&gt;While still in /home/minecraft/inconvenient:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim user_jvm_args.txt&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;In order to maximize Java performance, i set these arguments. I&#39;ve used these from Java versions 17 - 23. Add these to the bottom of this file:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xms16G&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xmx16G&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UnlockExperimentalVMOptions&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+DisableExplicitGC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+AlwaysPreTouch&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+PerfDisableSharedMem&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UseG1GC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+ParallelRefProcEnabled&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:MaxGCPauseMillis=200&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1NewSizePercent=40&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MaxNewSizePercent=50&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1HeapRegionSize=16M&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1ReservePercent=15&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1HeapWastePercent=5&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MixedGCCountTarget=4&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:InitiatingHeapOccupancyPercent=20&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MixedGCLiveThresholdPercent=90&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1RSetUpdatingPauseTimePercent=5&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:SurvivorRatio=32&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:MaxTenuringThreshold=1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The -Xms16G and -Xmx16G lines combined tell the server to use a static 16GB of RAM. I prefer this since my server has 64GB of RAM. Change these flags based on how much starting RAM and how much max RAM you want to give the Minecraft server. The other arguments are mostly for Java garbage collection. For descriptions of these java arguments, see the bottom of this article.&lt;/p&gt;
&lt;p&gt;I haven&#39;t tried this, but you may be able to log G1GC output with:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xlog:gc*,gc+heap,gc+region,gc+pause=debug:file=/home/minecraft/inconvenient/logs/gc_full.log:time&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you&#39;re using Java version 22 or 23 like me, you can take advantage of &lt;a rel=&quot;external&quot; href=&quot;https://openjdk.org/jeps/474&quot;&gt;newer garbage collection&lt;/a&gt; arguments called Generational ZGC. Use these arguments instead:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xms16G&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xmx16G&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UnlockExperimentalVMOptions&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+DisableExplicitGC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+AlwaysPreTouch&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+PerfDisableSharedMem&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UseZGC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xlog:gc*:file=/home/minecraft/inconvenient/logs/zgc.log&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Now you can also see Java garbage colelction logs!&lt;/p&gt;
&lt;p&gt;&lt;code&gt;tail -f /home/minecraft/inconvenient/logs/zgc.log&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;troubleshooting&quot;&gt;Troubleshooting&lt;/h1&gt;
&lt;p&gt;Avoid doing things with sudo in your Minecraft working directory. If you need to fix permissions:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo chown minecraft:minecraft -R /home/minecraft/&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;maintenance&quot;&gt;Maintenance&lt;/h1&gt;
&lt;p&gt;To start:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl start inconvenient-modpack.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To stop:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl stop inconvenient-modpack.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To restart:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl restart inconvenient-modpack.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To see the status:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl status inconvenient-modpack.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To view logs:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo journalctl -u inconvenient-modpack.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;or&lt;/p&gt;
&lt;p&gt;&lt;code&gt;cat /home/minecraft/inconvenient/logs/latest.log&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;or&lt;/p&gt;
&lt;p&gt;&lt;code&gt;tail -f /home/minecraft/inconvenient/logs/latest.log&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To backup a world folder manually:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;zip -r /home/minecraft/inconvenient/world.zip /home/minecraft/inconvenient/world/&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To delete a world and start over (while the server is stopped):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;rm -r /home/minecraft/inconvenient/world/&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Be sure to keep Adoptium&#39;s Java up to date, and of course all other system packages:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt update &amp;amp;&amp;amp; sudo apt dist-upgrade -V &amp;amp;&amp;amp; sudo apt autoremove -y &amp;amp;&amp;amp; sudo apt autoclean&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;If you want to tune the security of your new systemd service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemd-analyze security minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;custom-jvm-arguments-explained&quot;&gt;Custom JVM arguments explained&lt;/h1&gt;
&lt;p&gt;RAM management flags&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xmx16G:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;This sets the maximum heap size for the JVM to 16GB. This limits how much memory the Minecraft server can use.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xms16G:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;This sets the initial heap size to 16GB. This allocates 16GB of RAM from the start, ensuring the server has that memory available right away.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Garbage Collection (GC) Optimization Flags&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UseG1GC:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Enables the G1 garbage collector. G1 is optimized for low-latency garbage collection and is recommended for applications that need to handle large heaps like Minecraft.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+ParallelRefProcEnabled:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Enables parallel reference processing during garbage collection, improving GC performance by handling reference objects in parallel.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:MaxGCPauseMillis=200:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets a target for the maximum pause time for garbage collection to 200 milliseconds. This means the JVM will try to keep GC pauses under 200ms to avoid impacting performance.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UnlockExperimentalVMOptions:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Unlocks experimental JVM options. This allows the JVM to use advanced and less commonly used optimizations.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+DisableExplicitGC:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Disables calls to System.gc() from the code, preventing explicit garbage collection that might affect performance.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+AlwaysPreTouch:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Pre-touch memory pages during JVM startup, ensuring all memory is allocated and locked upfront, which can reduce pauses during runtime.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;G1 Garbage Collection Tuning Flags&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1NewSizePercent=40:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the minimum size of the new (young) generation to 40% of the total heap.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MaxNewSizePercent=50:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the maximum size of the new (young) generation to 50% of the total heap.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1HeapRegionSize=16M:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the size of each heap region in G1 garbage collection to 16MB. Larger region sizes are better for large heaps.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1ReservePercent=15:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Reserves 15% of the heap as free space to reduce the chance of full garbage collection cycles (which are more expensive).&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1HeapWastePercent=5:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the tolerated heap waste percentage. G1 will aim to reclaim regions if more than 5% of the heap is considered &amp;quot;waste.&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MixedGCCountTarget=4:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the target number of mixed garbage collections (which reclaim both old and young regions) to 4.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:InitiatingHeapOccupancyPercent=20:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the threshold for starting concurrent garbage collection at 20% heap occupancy. This allows GC to start early enough to avoid larger full GC cycles.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MixedGCLiveThresholdPercent=90:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;G1 will not reclaim any old regions where more than 90% of the region contains live objects.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1RSetUpdatingPauseTimePercent=5:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Limits the pause time for updating the remembered set (RSet) to 5% of the GC pause time.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:SurvivorRatio=32:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the ratio of Eden to Survivor spaces in the young generation to 32:1. Larger ratios mean more space in Eden, reducing promotion to the old generation.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+PerfDisableSharedMem:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Disables the use of shared memory for performance monitoring, which can prevent unnecessary memory overhead.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:MaxTenuringThreshold=1:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the maximum tenuring threshold to 1. This determines how many garbage collection cycles an object will go through before being promoted to the old generation.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Other Flags&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;--add-modules=jdk.incubator.vector:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Adds support for incubator modules in Java, such as the vector API. Incubator modules are experimental features.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-jar /home/minecraft/server.jar:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Specifies the path to the Minecraft server JAR file to be executed, if used.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;--nogui:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Disables the Minecraft server&amp;#39;s GUI for performance reasons since the server is run headless.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Have fun!
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>BitTorrent with Dignity</title>
        <published>2024-10-09T00:00:00+00:00</published>
        <updated>2024-10-09T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/bittorrent-with-dignity/"/>
        <id>https://yawnbox.eu/blog/bittorrent-with-dignity/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/bittorrent-with-dignity/">&lt;h1 id=&quot;introduction-to-library-zero&quot;&gt;Introduction to Library Zero&lt;/h1&gt;
&lt;p&gt;This document is a work-in-progress design document for Library Zero, a human-rights focused Rust-based BitTorrent application designed to operate exclusively over Tor onion services. Library Zero will be developed as a stand-alone application that interacts only with itself, enhancing the Tor network while allowing anonymous access and contribution to a distributed library of data.&lt;/p&gt;
&lt;p&gt;Unlike legacy BitTorrent applications that depend on centralized search and tracking functionality, Library Zero aims to base discovery on a Web of Trust model for peer connections while refactoring search and tracking into new distributed models. Every Library Zero node can become a Library, with its own Reference, and References are automatically shared based on trust. Searching for files is performed locally, because trusted Libraries auto share their complete References. Further, Library Zero libraries not only have copies of their own references, but they make copies of other Refernces of Libraries that they connect to. This is how Libraries can become known, trusted, and shared.&lt;/p&gt;
&lt;p&gt;Library Zero is not intended to be used by anyone. Because of the requirement to run as a Tor middle relay, Library Zero users must understand and use technical concepts and requirements.&lt;/p&gt;
&lt;h1 id=&quot;requirements&quot;&gt;Requirements&lt;/h1&gt;
&lt;p&gt;Every Library Zero node must be:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;a Tor middle relay that operates in parallel to BitTorrent operations.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;a BitTorrrent client that accesses libraries via Tor onion services.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;a BitTorrent server that hosts a library on Tor onion services.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;desired-user-experieince&quot;&gt;Desired User Experieince&lt;/h1&gt;
&lt;h2 id=&quot;leaching&quot;&gt;Leaching&lt;/h2&gt;
&lt;p&gt;A user wants to download a file from a Library.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The user downloads then installs Library Zero for BSD, Linux, macOS, or Windows.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The user sees a Get Started UI (tab 1) educating the user how to use Library Zero.&lt;/p&gt;
&lt;p&gt;2a. The Get Started tab first informs the user that to be able to use Library Zero, they must first contribute to the Tor network as a Tor middle relay. The user is provided clear education about what this means, and then the user must accept, then configure, and then start a Tor middle relay. Once they click Accept, a new tab will appear, a Public Tor Relay tab (tab 2). Now on the Public Tor Relay tab, the user is further educated on how to setup their Tor middle relay. It asks for basic information and provides facts about what the user must do, like enabling port forwarding on their home firewall. Once started, and the UI shows it is successfully connected to the Tor network as a relay, the Tor Relay tab will show the status and basic metrics of their Tor middle relay. (In the background, a new Search tab (tab 3) and My Public Library tab (tab 4) are also made avaialble.) The user is then prompted to return to the Get Started tab.&lt;/p&gt;
&lt;p&gt;2b. Library Zero then educates the user about searching other libraries and instructs the user wishing to download something to click on the Search tab (tab 3). In the Search tab, Library Zero asks the user to enter in one or more Tor onion addresses. The user, knowing a Tor onion address &lt;em&gt;of their local library&lt;/em&gt;, pastes the onion address in and clicks Connect.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Once connected, the user is prompted to pin the Tor onion address as a trusted Library. Pinned, trusted libraries are kept in a sub-tab of the Search tab (tab 3). The user may pin the onion address so that when Library Zero is opened, the app will always connect to this Library. (In the background, metadata for the Library is downloaded, and if the Library has opted into naming itself, the name will automatically populate in Library Zero. Additionally, the entire Library Reference data is downloaded to the user&#39;s Library Zero application.) The user is shown a simple search field. The user can search for anything, and all metadata fields will be searched for in the Reference of the Library they are connected to, but the search being performed is local. (In the background, Zero Library finds all of the onion addreses for the Library they are connected to, and those other onion addresses can be viewed by the user in the advanced view of a pinned Library. By default, a connection with a Library uses 3 Tor onion addresses, but a Library my opt into having more onion addresses.)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The user finds one item of the two items that they are looking for in the connected Library&#39;s Reference. The user clicks download. The item is immediately queued for download in the Download tab. (In the background, Library Zero already has all of the data about a file, and how to begin downloading the data, beacuse of the auto-downloaded Refernce data. The Reference data does not contain a list of other seeders and leachers (other onion addresses). As soon as the user clicks Download, the list of other onion addresses (other leachers and seeders of the file) is provided by the connected Library. Zero Library multiplexes a download over the available onion addresses. If authentication is successful with other leachers and seeders, multiplexing with those Libraries also begins.) Once a download is 100% complete, a user may use their file.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Since the user was only able to find one of two items, the user is able to opt into searching the References of extended lirbaries.&lt;/p&gt;
&lt;p&gt;5a. (Extended Trusted) Also on the Search tab (tab 3), the user is prompted to select how many degrees of separation they want to search when it comes to the trusted libraries of the library that they trust. Education is provided about what this means. (With one onion address beloning to one Library, a user is able to connect to and search the Reference of said Library. The Library being connected to, being an independent oeprator, opts into pinning their own trusted Libraries, which, to the user we&#39;re talking about, is two-degrees of separation from the user. If the user opts into searching two degree of separation, they then download the References of those trusted Libraries, and the user may opt into pinning those libraries as trusted Libraries.) The user selects two degrees of separation, then performs the same search but against five References, all local searches, because the Library they trust trusts four Libraries. The original Library that the user pinned as trusted trusts a different library that has the second file they are looking for. The user clicks Download.&lt;/p&gt;
&lt;p&gt;5b. (Extended Untrusted) Also on the Search tab (tab 3), the user is prompted to select how many degrees of separation they want to search when it comes to untrusted Libraries. An untrusted library is a Library seen simply by being a peer, either seeding or leaching. Those peers, who are also Library Zero users, will automaitcally share their References with the user. The user is able to opt into searching (downloading the entire Reference first) References they come into contact with. If users decide that the untrusted Libraries contain high quality files, they can pin that library as trusted, like in step 3.&lt;/p&gt;
&lt;p&gt;5c. Extended Trusted and Extended Untrusted libraries have simple check boxes in the Search Tab for enabling or disabling them when performing Reference searches.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;seeding&quot;&gt;Seeding&lt;/h2&gt;
&lt;p&gt;A user wants to share a file with the world.&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;See 1a.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The user sees a Get Started UI (the first tab) educating the user how to use Library Zero.&lt;/p&gt;
&lt;p&gt;7a. See 2a.&lt;/p&gt;
&lt;p&gt;7b. Library Zero instructs the user wishing to share something to click on the My Public Library tab (tab 4). In the My Public Library tab, the user is asked to select a file or folder to share. The user selects a folder of MP4 video files. Zero Library cleanly presents the user with the file and folder structure along with file and folder names. Below each file and folder name is its associated metadata. Library Zero offers a one-click button to anonymize the metadata of all files and folders selected to a standard configuration that all Library Zero application will do, which the user clicks. Optionally, Zero Library also provides one-click options to anonymize select metadata, categorically, like any &quot;author&quot; fields or &quot;time and date&quot; data. The file and folder names are left intact, and the user does not change them. The user clicks a Next button. Zero Libary prompts the user with one last screen informing them how to safeguard their anonymity, and to acknowledge that what they choose to share must be done carefully while aiming to not break any of their laws. The user clicks the a Share button. (In the background, Zero Library zips the folder into one file, generates a Reference dataset, and creates a set of Library onion addresses to share with anyone.)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The user is now able to share their onion address with anyone. Go to 2b.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Now that a user&#39;s Library Zero application has generated its own Reference, there is a new My Public Reference tab under the Share tab (tab 3). There a user can review the entire Refernce data that anyone with their onion address can see and download. Until a user shares something, there is no Reference file, so nothing is shared with other Library Zero users.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;threats&quot;&gt;Threats&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Governments who don&#39;t want their residents to read freely or become exposed to cultures other than their own.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Capitalists who want capitalism to be more important than human rights.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Politicians and Advertisers who want to control what users are exposed to and when.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Malicious users who want to trash the funtionality or user experieince of Library Zero.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;goals-of-library-zero&quot;&gt;Goals of Library Zero&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Allow users to access and contribute to a distributed library of data, anonymously, over the internet. Tor onion services can meaningfully protect the physical location of all libraries, and from there, aspects of Tor and other software design choices will protect the identity of any library user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The &lt;a rel=&quot;external&quot; href=&quot;https://www.un.org/en/about-us/universal-declaration-of-human-rights&quot;&gt;Universal Declration of Human Rights&lt;/a&gt; must dictate design and architecture choices for Library Zero, weighed against known threats. Distributed systems, layered cryptography, and layered networking empowers users to retain their human rights.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Users should be able to access and contribute to a global library from anywhere with minimal effort. Tor onion services excels at achieving this goal as a reverse proxy.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The protection of a user&#39;s identity is more important than performance. As such, a successful and complete download or upload in a privacy-preserving manner takes priority over speed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Today, the Tor network is limited in its capacity so BitTorrent is discouraged. Library Zero must contribute back to the Tor network and Library Zero will do this by becoming a Tor middle relay. How much anyone is able to download with Library Zero will be limited by how much they give back to the Tor network. The more people that use Library Zero, the faster and more robust the Tor network will be. Secondarily, being that Library Zero is a Tor middle relay, users have plausible deniability when it comes to contributing to other&#39;s Libraries.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Tor network is limited to TCP traffic. UDP traffic generated by some BitTorrent clients today may also undermine a user&#39;s expectations of privacy. Zero must utilize TCP protocols to be properly routable over Tor.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Tor network, made up of random volunteers all around the world, run Tor relays that are limited in various network and compute capacities. Tor onion services are made up of a 6-hop circuit, of which the slowest of the 6 will limit the maxiumum throughput of a download or upload. Library Zero must multiplex onion services, which BitTorrent makes easy since all files being shared are broken down into small chucks, and it doesn&#39;t matter which chunk arrives first or last since a successful download will require 100% of all chunks.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Library Zero must be modular to support other transport types, such as mixnets, but initially will be designed to leverage well known anonymity protols and networks such as Tor. Specifically, Library Zero will exclusively use &lt;a rel=&quot;external&quot; href=&quot;https://community.torproject.org/onion-services/&quot;&gt;Tor onion services&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Library Zero must not to be interoperable with legacy BitTorrent over the clear-web. Those platforms, when used in the public domain, are negligent in protecting users and should be abandoned.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;software-knowns&quot;&gt;Software knowns&lt;/h1&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://tpo.pages.torproject.net/core/arti/&quot;&gt;Arti&lt;/a&gt; is Tor Project&#39;s Tor daemon written in Rust. Arti will be used to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;interface with the Tor network&lt;/li&gt;
&lt;li&gt;operate a Tor middle relay&lt;/li&gt;
&lt;li&gt;access remote onion services&lt;/li&gt;
&lt;li&gt;generate local onion services&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;software-unknowns&quot;&gt;Software unknowns&lt;/h1&gt;
&lt;p&gt;Since Tor provides automatic end-to-end encryption, does Library Zero need to be responsible for any additional transport cryptography? For example, Tor does not yet implement any quantum safe algorithms.&lt;/p&gt;
&lt;p&gt;Tor has claimed within recent years that it is aiming to support UDP. When will that be?&lt;/p&gt;
&lt;p&gt;Rust BitTorrent applications like &lt;a rel=&quot;external&quot; href=&quot;https://github.com/ikatson/rqbit&quot;&gt;rqbit&lt;/a&gt; exist, but how much can be forked, and how much will have to be rewritten?&lt;/p&gt;
&lt;p&gt;How much of the &lt;a rel=&quot;external&quot; href=&quot;https://www.bittorrent.org/beps/bep_0005.html&quot;&gt;DHT protocol&lt;/a&gt; can safely be ported? Or, because of its intended design, is it too anti-privacy, inefficient, or insecure to be used?&lt;/p&gt;
&lt;p&gt;What should the TCP-based transport protocol be inside of the Tor onion circuits since Tor does not yet support UDP-based protocols? &lt;a rel=&quot;external&quot; href=&quot;https://docs.rs/hyper/latest/hyper/&quot;&gt;Hyper&lt;/a&gt; could be used for UDP to HTTP/2 conversion. Or, again, should a BitTorrent client be written from scratch to never use UDP in the first place?&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://github.com/sn0b4ll/aria2-onion-downloader/tree/main&quot;&gt;aria2-onion-downloader&lt;/a&gt; exists for multiplexing onion/HTTP downloads, but how well is it designed?&lt;/p&gt;
&lt;p&gt;&quot;&lt;a rel=&quot;external&quot; href=&quot;https://docs.rs/serde/latest/serde/&quot;&gt;Serde&lt;/a&gt; is a framework for serializing and deserializing Rust data structures efficiently and generically.&quot;&lt;/p&gt;
&lt;h1 id=&quot;thoughts&quot;&gt;Thoughts&lt;/h1&gt;
&lt;h2 id=&quot;multiplexing-onions&quot;&gt;Multiplexing onions&lt;/h2&gt;
&lt;p&gt;Due to the network performance limitations of data passing through 6 different, globally distributed ISPs (a standard tor onion onion circuit), multiplexing download/upload streams is prudent. This has additional benefits of distributing data via increasingly greater data paths around the world, making it significantly harder to perform network analysis to de-anonymize users. Onion services can be created dynamically and automatically depending on a number of factors, including network performance and file size. By default, the number of streams should be nine. To generate multiple Tor onion services and multiplex network streams, custom code would need to be created.&lt;/p&gt;
&lt;h2 id=&quot;tracking&quot;&gt;Tracking&lt;/h2&gt;
&lt;p&gt;To make the tracker functionality of BitTorrent distributed (not centralized in any way), a new tracker application, written in rust, would need to be created to run as a distributed, federating system. In this model, the tracker must exist on all nodes in the network automatically. This approach has several advantages over traditional centralized tracker systems, including increased resilience, scalability, privacy, and plausible deniability. Making every node a tracker also makes it easy to self-host files without needing someone else&#39;s tracker. The reverse-proxy aspect of tor onion services makes this trivial from any network.&lt;/p&gt;
&lt;p&gt;Every node on the network is a tracker. In addition, every tracker can choose to become a mirror for any other tracker (which doesn&#39;t mean it copies all the data, just the metadata). Becoming a tracker mirror should be as simple as copying and pasting the tor onion address of the tracker, which is the only identifier of a node. Therefore, every node operator can run multiple instances and trivially copy over tracker data. This way, when an operator needs to restart hardware or software, they can leave one instance online so that related tracker data is still accessible to the rest of the network. If the original tracker does not ever come back online, that is not a problem. Copying tracker data is a one-time event (full backup), and an operator can choose to automatically keep the tracker data up to date, or to do it manually. But each copy of a tracker becomes its own net-new onion service. Even though becoming a tracker mirror is a one-time event, that does not apply to keeping track of the peers that have copies of the file data related to the tracker data. Address data must be shared synchronously in near real-time between all peers that share tracker data and file data.&lt;/p&gt;
&lt;h2 id=&quot;tor-middle-relay&quot;&gt;Tor middle Relay&lt;/h2&gt;
&lt;p&gt;Classically, with BitTorrrent, the share ratio is what determines how much someone can download. In this torified version of a BitTorrrent application, the share ratio needs to be pre-determined by how much tor middle relay traffic they provided to the network. The Tor network has limited bandwidth and resources, and using it for high-volume file sharing could negatively impact the network&#39;s performance. By using middle relays as a measure of contribution, users would be incentivized to provide resources to the network without overburdening it. Determining a fair and effective share ratio based on Tor middle relay traffic could be challenging and would require careful consideration and testing. Remember that tor onion services only utilize middle relays, not exit relays. So substantially increasing the side of the network with thousands of new middle relays of this type would not affect, and would not contribute to, exit relaying.&lt;/p&gt;
&lt;h2 id=&quot;web-of-trust&quot;&gt;Web of trust&lt;/h2&gt;
&lt;p&gt;Connecting to a trusted node (one-degree of separation) can provide further access to the trusted nodes of the trusted node that the user connected to (two-degrees of separation). However, trust only works for one-degree of separation by default in order to minimize local performance issues. After adding a first node to trust (1deg), the user adding the node to trust can opt-in to adding up to N-degrees of separation for node trust. In other words: if a trusted node (1deg) trusts two nodes (2deg), the app user will in effect trust three total nodes. If the user allows up to three-degrees of separation for trust and the two (2deg) trusted nodes all trust two nodes (3deg), the user will in effect trust seven nodes (1 + 2 + 4). If any of those degrees-of-separation trusts 10,000 nodes, you can see how that might quickly overwhelm the user&#39;s local app, and is why they need to be careful about adding nodes to trust based on their hardware, software, and network limitations. Limiting searchable and shareable access to nodes via delegated trust also helps keep the network somewhat flat (prevents extreme bloating), while still allowing users to easily access and share.&lt;/p&gt;
&lt;h2 id=&quot;leaching-1&quot;&gt;Leaching&lt;/h2&gt;
&lt;p&gt;A user wishing to download file data first requires mirroring the tracker data of the file a user wishes to download, further enhancing the distribution of tracker data. Once the tracker data is 100% mirrored, the source node then adds the onion service of user to their tracker table, and all nodes that trust and mirror that node then become aware of this new node and what files it is offering, but it is not trusted by any node.&lt;/p&gt;
&lt;h2 id=&quot;ux&quot;&gt;UX&lt;/h2&gt;
&lt;p&gt;From the UI:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Users (node operators) can point the app to any local file or folder that they wish to share.&lt;/li&gt;
&lt;li&gt;The application will automatically generate a tracker file for the user that gets self-hosted.&lt;/li&gt;
&lt;li&gt;The user will be required to input information about the file(s) they are about to share. Here is where there should be additional user education about not de-anonymizing one&#39;s self, if applicable.&lt;/li&gt;
&lt;li&gt;After confirming the files to be shared, the app will automatically make the tracker data and file data ready to be shared (as a private tracker by default).&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;private-trackers&quot;&gt;Private trackers&lt;/h2&gt;
&lt;p&gt;Being able to keep shared data limited (not publicly shared) is an important feature. By default, data that is ready to be shared will only be privately available. Meaning:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;the tracker for this data will effectively be a private tracker and a random onion URI (http://v3onion.onion:port/private/token) will be generated exclusively for this tracker and file.&lt;/li&gt;
&lt;li&gt;in order to share access to this file in its default state, a user must share the onion URI out-of-band from the application.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;public-trackers&quot;&gt;Public trackers&lt;/h2&gt;
&lt;p&gt;Being able to trivially share data with the whole world is also an important feature. Once data has been made available for private sharing, a user can opt-in to making it publicly available.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;With a single click, a user can convert something from a dedicated private tracker into a public share via a new onion URI (http://v3onion.onion:port/public/token).&lt;/li&gt;
&lt;li&gt;Sharing this onion URI with anyone, or with the general public, will allow any app user to access this user&#39;s public trackers and any publicly shared data.&lt;/li&gt;
&lt;/ol&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>My Star Citizen Fleet</title>
        <published>2024-10-04T00:00:00+00:00</published>
        <updated>2024-10-04T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/starcitizen/"/>
        <id>https://yawnbox.eu/blog/starcitizen/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/starcitizen/">&lt;p&gt;&lt;em&gt;This post is regularly updated.&lt;/em&gt;&lt;/p&gt;
&lt;h1 id=&quot;my-history-with-star-citizen&quot;&gt;My History with Star Citizen&lt;/h1&gt;
&lt;p&gt;I haven&#39;t found a game worth my time since &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/Star_Wars_Galaxies&quot;&gt;Star Wars Galaxies&lt;/a&gt; and I deeply wish Star Citizen to fill that void. Over the years, ship sales have allowed me to invest a lot into this game&#39;s development. I consider these investments as meaningful investments as a gamer and as someone who wants to contribute to the idea of what this game aims to become for the entire gaming industry.&lt;/p&gt;
&lt;p&gt;I had a super fun time at CitizenCon 2954 in Manchester, UK, my first in-person event!&lt;/p&gt;
&lt;p&gt;Here&#39;s my current fleet as of March 2026.&lt;/p&gt;
&lt;h1 id=&quot;referral&quot;&gt;Referral&lt;/h1&gt;
&lt;p&gt;If you&#39;re interested in getting into Star Citizen, please use my &lt;a rel=&quot;external&quot; href=&quot;https://robertsspaceindustries.com/enlist?referral=STAR-FZPR-XF2M&quot;&gt;referral&lt;/a&gt;!&lt;/p&gt;
&lt;p&gt;&lt;code&gt;STAR-FZPR-XF2M&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;my-professions-fleet&quot;&gt;My Professions &amp;amp; Fleet&lt;/h1&gt;
&lt;p&gt;My primary profession will be as an Explorer: deep space exploration, information broker, and covert intelligence gatherer. My secondary profession will be Medical: fleet medic and deep space rescue operations.&lt;/p&gt;
&lt;p&gt;I have invested in two copies of certain ships that I think i&#39;ll really enjoy and depend on. The main reason for this is because the Persistent Universe will be massive, and I plan on having multiple homes at different &quot;ends&quot; of the galaxy. It&#39;s not feasible for me to have easy access to my favorite ships. And, um, yeah, I have five 600i&#39;s so far.&lt;/p&gt;
&lt;p&gt;Lastly, I am not cognitively limited by popular expectations of how to use certain ships. For example, I&#39;ve listed the Nautilus, Mustang Delta, Persius, and Polaris as exploration ships, and I explain why below.&lt;/p&gt;
&lt;h2 id=&quot;exploration&quot;&gt;Exploration&lt;/h2&gt;
&lt;h3 id=&quot;aegis-nautilus&quot;&gt;Aegis &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Nautilus&quot;&gt;Nautilus&lt;/a&gt;&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/nautilus.jpg&quot; alt=&quot;Nautilus&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;The main reason I am curious about the Naut is because of its defensive capabilities combined with its exploration-capable components. I think of it as an exploration ship with heavy armor. For example, exploration near Stars, radioactive nebulae, or in asteroid belts. Think, like, a bigger Terrapin.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Exploration-related components for comparison with the Carrack, Odyssey, Perseus, and Polaris:&lt;/em&gt;&lt;/p&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Quantity&lt;/th&gt;
      &lt;th&gt;Size&lt;/th&gt;
      &lt;th&gt;Component&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Radar&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;Scanner&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S2 (M)&lt;/td&gt;
      &lt;td&gt;Computer&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Jump Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;Med Bed&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;I should note that the RSI page for the Naut contains different informatoin from the original concept brochure, like with the number of fuel tanks being 1x on the page but 2x in the brochure.&lt;/p&gt;
&lt;h3 id=&quot;anvil-carrack-expedition-w-c8x-pisces-expedition-x2&quot;&gt;Anvil &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Carrack&quot;&gt;Carrack Expedition&lt;/a&gt; w/ &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/C8X_Pisces_Expedition&quot;&gt;C8X Pisces&lt;/a&gt; Expedition (x2)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/carrack.jpg&quot; alt=&quot;Carrack Expedition&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I&#39;m hoping for big things with the Carrack, but I know that I won&#39;t be able to fully appreciate its potential until there are multiple star systems to fly through. And, of course, after it gets all of its promised features.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Exploration-related components for comparison with the Nautilus, Odyssey, Perseus, and Polaris:&lt;/em&gt;&lt;/p&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Quantity&lt;/th&gt;
      &lt;th&gt;Size&lt;/th&gt;
      &lt;th&gt;Component&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Radar&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;Scanner&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;3&lt;/td&gt;
      &lt;td&gt;S2 (M)&lt;/td&gt;
      &lt;td&gt;Computer&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Jump Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;T2&lt;/td&gt;
      &lt;td&gt;Med Bed&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&quot;consolidated-outland-mustang-delta&quot;&gt;Consolidated Outland &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Mustang_Delta&quot;&gt;Mustang Delta&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;While the Delta is intended for light combat, I plan on using it exclusively as a small, stealth information gatherer. The Delta has excellent cockpit views!&lt;/p&gt;
&lt;h3 id=&quot;consolidated-outland-pioneer&quot;&gt;Consolidated Outland &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Pioneer&quot;&gt;Pioneer&lt;/a&gt;&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/pioneer.jpg&quot; alt=&quot;Pioneer&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;One of my most favorite parts about Star Wars Galaxies was decorating my home with all of the rare loot I found or rare armor and weapons I had made, and base/outpost/city building with my guild. I invested in a Pioneer within the first minute of it launching and was so excited to do so (the purchase date on my pack is later becasue I melted it at one point then repurcahsed it). While the Pioneer is not made to explore, building bases in parts of the universe will be a critial aspect of security and sustainability in a region.&lt;/p&gt;
&lt;h3 id=&quot;misc-endeavor-x2&quot;&gt;MISC &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Endeavor&quot;&gt;Endeavor&lt;/a&gt; (x2)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/endeavor.jpg&quot; alt=&quot;Endeavor Master Set&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I have one Endeavor Master Set and another Endeavor with what is effecively its own Master Set of LTI pods. I list one under Exploration and one under Medical. With an exploration variant I&#39;ll be very keen on understanding and using the Telescope pod. So much about this ship is currently unknown, I expect it will be one of the very last early ships to be made.&lt;/p&gt;
&lt;h3 id=&quot;misc-odyssey-x2&quot;&gt;MISC &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Odyssey&quot;&gt;Odyssey&lt;/a&gt; (x2)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/odyssey.jpg&quot; alt=&quot;Odyssey&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I think, currently, the Odyssey is my most favorite ship. I think it will beat out the Carrack because of its ability to be self-sustainable in terms of fuel. However, the Carrack is due for major updates and the Odyssey isn&#39;t even out. One big reason why the Odyssey and the Carrack are exciting is because of their ability to be a remote base of operation.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Exploration-related components for comparison with the Nautilus Carrack, Perseus, and Polaris:&lt;/em&gt;&lt;/p&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Quantity&lt;/th&gt;
      &lt;th&gt;Size&lt;/th&gt;
      &lt;th&gt;Component&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Radar&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;Scanner&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;4&lt;/td&gt;
      &lt;td&gt;S2 (M)&lt;/td&gt;
      &lt;td&gt;Computer&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Jump Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;T2&lt;/td&gt;
      &lt;td&gt;Med Bed&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&quot;origin-600i-exploration-module-x4&quot;&gt;Origin &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/600i_Explorer&quot;&gt;600i Exploration&lt;/a&gt; Module (x4)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/600i.jpg&quot; alt=&quot;600i Explorer&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I was so incredibly hyped for the 600i when it launched. I posted the most popular Reddit thread about it right before it launched, tracking all of the information that was out about it. I plan on using the 600i as my daily driver. I hope. I know that its a rather large ship, and I won&#39;t be able to park it in an Odyssey or Carrack. So plans could change. How I ended up with 4x of them was more or less an accident, I plan on CCU&#39;ing two of the four to something else, and I hope it will be new variats of the 600i.&lt;/p&gt;
&lt;h3 id=&quot;rsi-perseus&quot;&gt;RSI &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Perseus&quot;&gt;Perseus&lt;/a&gt;&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/perseus.jpg&quot; alt=&quot;Perseus&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;Again, I&#39;m not cognitively limited in expected use cases. I invested in a Perseus because its a large warship centered on patrol. As a patrol ship it is expected to come with a good radar, fuel tanks and drives. A smaller Polaris. I am curious about how it can and will be used for exploration in more hostile regions.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Exploration-related components for comparison with the Nautilus, Carrack, Odyssey, and Polaris:&lt;/em&gt;&lt;/p&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Quantity&lt;/th&gt;
      &lt;th&gt;Size&lt;/th&gt;
      &lt;th&gt;Component&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S2 (M)&lt;/td&gt;
      &lt;td&gt;Radar&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;Scanner&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S2 (M)&lt;/td&gt;
      &lt;td&gt;Computer&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Jump Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;Med Bed&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&quot;rsi-polaris&quot;&gt;RSI &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Polaris&quot;&gt;Polaris&lt;/a&gt;&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/polaris.jpg&quot; alt=&quot;Polaris&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;Like the Nautilus, the Polaris is a patrol ship, meaning it&#39;s intended to scan for stuff and travel longer distances. Again, I am curious about how it can and will be used for exploration in more hostile regions. I don&#39;t care at all about its torpedos, unless I can launch probes into deep space.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Exploration-related components for comparison with the Nautilus, Carrack, Odyssey, and Perseus:&lt;/em&gt;&lt;/p&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Quantity&lt;/th&gt;
      &lt;th&gt;Size&lt;/th&gt;
      &lt;th&gt;Component&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S4 (C)&lt;/td&gt;
      &lt;td&gt;Radar&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;Scanner&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S2 (M)&lt;/td&gt;
      &lt;td&gt;Computer&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Quantum Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;1&lt;/td&gt;
      &lt;td&gt;S3 (L)&lt;/td&gt;
      &lt;td&gt;Jump Drive&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2&lt;/td&gt;
      &lt;td&gt;S2 (M)&lt;/td&gt;
      &lt;td&gt;Fuel Tank&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;4&lt;/td&gt;
      &lt;td&gt;Tier-2&lt;/td&gt;
      &lt;td&gt;Med Bed&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id=&quot;large-exploration-ships-comparison&quot;&gt;Large &quot;exploration&quot; ships comparison&lt;/h2&gt;
&lt;p&gt;Is there a clear winner? Absolutely not. Although, the Carrack, Odyssey, and Polaris will have med beds, and I&#39;ll be very pissed off if large military ships like the Nautilus and Perseus don&#39;t have med beds of any kind. But look at the capitol class radar on the Polaris! And not all regions are safe for solo ship exploration. The type and quality of a component should significantly change how well a traditional combat ship performs in exploration, simply shifting drive and tank classes from miliitary to industrial should help. Since I have all of these ships, and even some doubles, borrowing components from exploration ships and putting them in traditionally combat ships will work. Then keep the military components on board as backups!&lt;/p&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Component&lt;/th&gt;
      &lt;th&gt;Anvil Carrack&lt;/th&gt;
      &lt;th&gt;MISC Odyssey&lt;/th&gt;
      &lt;th&gt;Aegis Nautilus&lt;/th&gt;
      &lt;th&gt;RSI Perseus&lt;/th&gt;
      &lt;th&gt;RSI Polaris&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;Radar&lt;/td&gt;
      &lt;td&gt;2x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Medium&lt;/td&gt;
      &lt;td&gt;1x Capitol&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Scanner&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
      &lt;td&gt;?&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Computer&lt;/td&gt;
      &lt;td&gt;3x Medium&lt;/td&gt;
      &lt;td&gt;4x Medium&lt;/td&gt;
      &lt;td&gt;2x Medium&lt;/td&gt;
      &lt;td&gt;2x Medium&lt;/td&gt;
      &lt;td&gt;2x Medium&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Quantum Drive&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Quantum Fuel Tank&lt;/td&gt;
      &lt;td&gt;2x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;2x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Jump Drive&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
      &lt;td&gt;1x Large&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Fuel Tank&lt;/td&gt;
      &lt;td&gt;2x Large&lt;/td&gt;
      &lt;td&gt;2x Large&lt;/td&gt;
      &lt;td&gt;2x Large&lt;/td&gt;
      &lt;td&gt;2x Large&lt;/td&gt;
      &lt;td&gt;2x Medium&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Med Bed&lt;/td&gt;
      &lt;td&gt;1x Tier-2&lt;/td&gt;
      &lt;td&gt;1x Tier-2&lt;/td&gt;
      &lt;td&gt;Unknown&lt;/td&gt;
      &lt;td&gt;Unknown&lt;/td&gt;
      &lt;td&gt;Yes&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id=&quot;medical&quot;&gt;Medical&lt;/h2&gt;
&lt;h3 id=&quot;anvil-c8r-pisces-rescue-x2&quot;&gt;Anvil &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/C8R_Pisces_Rescue&quot;&gt;C8R Pisces&lt;/a&gt; Rescue (x2)&lt;/h3&gt;
&lt;p&gt;The Pisces Rescue is just going to be a heavily used ship in all kinds of gameplay. I expect them to be valuable ships in and around my Endeavors.&lt;/p&gt;
&lt;h3 id=&quot;misc-endeavor-x2-1&quot;&gt;MISC &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Endeavor&quot;&gt;Endeavor&lt;/a&gt; (x2)&lt;/h3&gt;
&lt;p&gt;While I will aim to avoid direct conflict in Star Citizen, I do plan on being critical support for battles. This includes being a respawn point in regions of conflict, especially for those that my guild(s) and org(s) are involved with.&lt;/p&gt;
&lt;h3 id=&quot;rsi-ursa-medivac-x2&quot;&gt;RSI &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Ursa_Medivac&quot;&gt;URSA Medivac&lt;/a&gt; (x2)&lt;/h3&gt;
&lt;p&gt;Like the Pisces Rescue, the &quot;Nursa&quot; is going to be an indespesible vehicle for all types of gameplay.&lt;/p&gt;
&lt;h2 id=&quot;general&quot;&gt;General&lt;/h2&gt;
&lt;h3 id=&quot;star-kitten-dragonfly&quot;&gt;Star Kitten Dragonfly&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/star-kitten-dragonfly.jpg&quot; alt=&quot;Star Kitten Dragonfly&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I only got this the second time CIG offered it, for the referral reward, but I am so excited I could get one. The first time it was offered was so long ago, I forget how and why it was offered. A friend had been interested in checking out Star Citizen so I lucked out they needed a referral code c:&lt;/p&gt;
&lt;h3 id=&quot;aopoa-nox-kue-x5&quot;&gt;Aopoa &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Nox&quot;&gt;Nox&lt;/a&gt; Kue (x5)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/nox-kue.jpg&quot; alt=&quot;Nox Kue&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I just think this bike is the sexiest bike. Xi&#39;An tech ftw. I got the original concept 5-pack and I had Conceirge Support make the four normal Nox&#39;s into Nox Kues. I&#39;ve also been collecting all of the Nox paints, there are a total of 10!&lt;/p&gt;
&lt;h3 id=&quot;crusader-mercury-star-runner-x2&quot;&gt;Crusader &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Mercury_Star_Runner&quot;&gt;Mercury Star Runner&lt;/a&gt; (x2)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/msr.jpg&quot; alt=&quot;Mercury Star Runner&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;The MSRs are really exciting ships. They seem to be the Millenium Falcon of Star Citizen, and they seem great for information brokering gameplay.&lt;/p&gt;
&lt;h3 id=&quot;origin-600i-touring-module-x1&quot;&gt;Origin &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/600i_Touring&quot;&gt;600i Touring&lt;/a&gt; Module (x1)&lt;/h3&gt;
&lt;p&gt;The 600i Explorer is way more valuable to me since it has cargo space and a med bed. Because I love the 600i platform so much, I&#39;m keeping one Touring just because. However I do have one extra Touring to Explorer CCU just in case, after the 600i rework, it just makes more sense to have yet another 600i Explorer.&lt;/p&gt;
&lt;h3 id=&quot;origin-890-jump&quot;&gt;Origin &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/890_Jump&quot;&gt;890 JUMP&lt;/a&gt;&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/890j.jpg&quot; alt=&quot;890 Jump&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I wasn&#39;t as excited for the 890J as I was the 600i, but I did have to invest in an 890J because of my appreciation for Origin. Since the Origin brand is more on the defensive and survivability side, I see the 890J as being another option for a base of operations. I just hope it won&#39;t suck as a deep space explorer.&lt;/p&gt;
&lt;h3 id=&quot;l-22-alpha-wolf-x2&quot;&gt;L-22 Alpha Wolf (x2)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/L22-alpha-wolf.jpg&quot; alt=&quot;L22 Alpha Wolf&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I absolutely hated the L-21 and mostly love the L-22. The kneel seriously killed it. I&#39;m happy they fixed their mistake with the L22. I did also got the weapons packs and the paint pack!&lt;/p&gt;
&lt;h2 id=&quot;defensive&quot;&gt;Defensive&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;The best defense is a good offense.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;anvil-f8c-lightning-x2&quot;&gt;Anvil &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/F8C_Lightning&quot;&gt;F8C Lightning&lt;/a&gt; (x2)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/f8c-shockwave.jpg&quot; alt=&quot;VIP Wing Commander&quot; width=&quot;500&quot;&gt;&lt;br&gt;
      Shockwave paint
    &lt;/td&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/f8c-stormfire.jpg&quot; alt=&quot;Standalone Ship - F8C Lightning&quot; width=&quot;500&quot;&gt;&lt;br&gt;
      Stormfire paint
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;The hype and rarity for the F8C Lightning got to me and I relished in it. Sadly it&#39;s not rare anymore. When the Golden Tickets were first lootable around the PU, I was only a couple hundred dollars away from becoming a &lt;a rel=&quot;external&quot; href=&quot;https://support.robertsspaceindustries.com/hc/en-us/articles/360002542733-Concierge-Levels-and-Rewards&quot;&gt;Wing Commander&lt;/a&gt;. So, I ended up investing in both the same week. While I don&#39;t plan on dog fighting, like, ever, I do enjoy flying around with strong defensive capabilities. I plan on getting the third one (via &lt;a rel=&quot;external&quot; href=&quot;https://support.robertsspaceindustries.com/hc/en-us/articles/360002542733-Concierge-Levels-and-Rewards&quot;&gt;Praetorian&lt;/a&gt;) with more Star Citizen backing, but I will likely melt the Golden Ticket F8C once I get the Praetorian F8C.&lt;/p&gt;
&lt;h3 id=&quot;crusader-ares-inferno-and-an-ares-ion&quot;&gt;Crusader &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Ares_Star_Fighter_Inferno&quot;&gt;Ares Inferno&lt;/a&gt; and an &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Ares_Star_Fighter_Ion&quot;&gt;Ares Ion&lt;/a&gt;&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/ares.jpg&quot; alt=&quot;Ares Inferno and Ion&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;These are just so cool and fun, I needed to have one of each. The Golden Blossom skin is also gorgeous, so I got two for both. I&#39;m looking forward to the gold standard pass and I deeply hope they put the components inside... the ship is big enough.&lt;/p&gt;
&lt;h3 id=&quot;f7a-hornet-mk-ii&quot;&gt;F7A Hornet MK II&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/f7a-hornet-mk-II.jpg&quot; alt=&quot;F7A MK II&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I don&#39;t really need or want this, but since I had the CCU, I put it on an LTI package. I hope I can upgrade this to the F7A Ghost MK II someday, then I&#39;d love it a lot.&lt;/p&gt;
&lt;h2 id=&quot;industrial&quot;&gt;Industrial&lt;/h2&gt;
&lt;h3 id=&quot;crusader-genesis-starliner&quot;&gt;Crusader &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Genesis_Starliner&quot;&gt;Genesis Starliner&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;I&#39;m undecided if I want to have this gameplay. Perhaps I&#39;ll loan it to my guild(s) and org(s).&lt;/p&gt;
&lt;h3 id=&quot;misc-hull-d-and-a-hull-e&quot;&gt;MISC &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Hull_D&quot;&gt;Hull D&lt;/a&gt; and a &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Hull_E&quot;&gt;Hull E&lt;/a&gt;&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/hull-e.jpg&quot; alt=&quot;Hull E&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I&#39;m very excited about the modular gameplay the Hull series will offer. Meaning, I&#39;m not as excited about cargo hauling by itself. I&#39;m also curious about how these ships might be used without being expanded for cargo given how defensive they will be.&lt;/p&gt;
&lt;h3 id=&quot;rsi-arrastra&quot;&gt;RSI &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Arrastra&quot;&gt;Arrastra&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;I&#39;m undecided if I want to have this gameplay. Perhaps I&#39;ll loan it to my guild(s) and org(s).&lt;/p&gt;
&lt;h3 id=&quot;rsi-orion&quot;&gt;RSI &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Orion&quot;&gt;Orion&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;I&#39;m undecided if I want to have this gameplay. Perhaps I&#39;ll loan it to my guild(s) and org(s).&lt;/p&gt;
&lt;h2 id=&quot;collection-items&quot;&gt;Collection Items&lt;/h2&gt;
&lt;h3 id=&quot;consolidated-outland-mustang-omega-amd-edition-x2&quot;&gt;Consolidated Outland &lt;a rel=&quot;external&quot; href=&quot;https://starcitizen.tools/Mustang_Omega&quot;&gt;Mustang Omega&lt;/a&gt;: AMD Edition (x2)&lt;/h3&gt;
&lt;table border=&quot;1&quot;&gt;
  &lt;tr&gt;
    &lt;td&gt;
      &lt;img src=&quot;/images/omega-never-settle.jpg&quot; alt=&quot;AMD Never Settle Space Edition&quot; width=&quot;800&quot;&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;I don&#39;t plan on racing much in Star Citizen, and I certainly don&#39;t plan on racing with these. I just want to put them on display in a hangar because they are beautiful and rare ships.&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Debian 12 + tor onions guide</title>
        <published>2024-10-02T00:00:00+00:00</published>
        <updated>2024-10-02T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/debian-tor-onions/"/>
        <id>https://yawnbox.eu/blog/debian-tor-onions/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/debian-tor-onions/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;This guide ignores the default torrc and sets up two new onions dedicated to their purpose. Do this so you&#39;re not exposing the SSH daemon or your public SSH key via your public onion address. Duplicate web* instance steps if you&#39;re going to use Onionbalance, and duplicate ssh* instance steps if you want backup circuits to get back into your Pi.&lt;/p&gt;
&lt;p&gt;This guide also presumes certain things. This server is behind NAT and does not have a public IP. While you could use this guide to setup a remote virtual machine (I would never advise this unless you own the harware), I set up this server with a USB keyboard that I have direct access to.&lt;/p&gt;
&lt;p&gt;The first step is to block everything inbound. Be careful with this if you are setting up a remote system. If and when I have a public IP, I like to deny everything inbound first so that bots run by Eve cannot grab my public SSH key as soon as I make a cleartext request to install Tor.&lt;/p&gt;
&lt;p&gt;Imagine a passive or active adversary with network visibility. This includes your ISP, maybe your government, or maybe well-funded global passive adversaries. They might create an automatic system to track the activity and behavior of any IP that initiates a clear-text (plaintext or tls-encrypted cleartext (metadata)) install of tor. Imagine that system adding your IP to a surveillance list that then automates monitoring the uptime of your system and juxtaposes that behavior to a seprate system that tracks the bahavior of known onion sites in attempts to identify the physical location of onion sites and services. Metadata privacy matters. Do not expose port 22 to the internet.&lt;/p&gt;
&lt;p&gt;Another presumption is that you do not need php, sql, or other heavy and vulnerable code, and is why I use nginx-light. Further, I do not bother with TLS and adding another potentially-vulernable dependency like openssl. Tor onion access is end-to-end encrypted by default.&lt;/p&gt;
&lt;h1 id=&quot;installation&quot;&gt;Installation&lt;/h1&gt;
&lt;p&gt;Testing has been updated to Debian 12.&lt;/p&gt;
&lt;h2 id=&quot;block-everything-inbound&quot;&gt;block everything inbound&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;su root&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;apt update &amp;amp;&amp;amp; apt install ufw gpg vim -y&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ufw enable&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;install-tor&quot;&gt;install tor&lt;/h2&gt;
&lt;p&gt;Use this script: &lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/tor-install-script/&quot;&gt;https://yawnbox.eu/blog/tor-install-script/&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;create-onion-site&quot;&gt;create onion site&lt;/h2&gt;
&lt;p&gt;By default, sbin directories aren&#39;t accessible in our path:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;echo &#39;export PATH=$PATH:/sbin:/usr/sbin:/usr/local/sbin&#39; &amp;gt;&amp;gt; ~/.bashrc&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;source ~/.bashrc&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Create a new, isolated tor instance named web1:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;tor-instance-create web1&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim /etc/tor/instances/web1/torrc&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Delete everything in this torrc file and and use:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;HiddenServiceDir /var/lib/tor-instances/web1/hidden_service/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;HiddenServicePort 80 127.0.0.1:80&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Restart the new web onion service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemctl restart tor@web1.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;View the new port 80 (web) onion address:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;cat /var/lib/tor-instances/web1/hidden_service/hostname&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The output will look like:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;abcdefghijklmnopqrstuvwxyz.onion&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;create-ssh-onion&quot;&gt;create ssh onion&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;tor-instance-create ssh1&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim /etc/tor/instances/ssh1/torrc&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Delete everything and use:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;HiddenServiceDir /var/lib/tor-instances/ssh1/hidden_service/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;HiddenServicePort 22 127.0.0.1:22&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Restart the new ssh onion service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemctl restart tor@ssh1.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;View the new port 22 (ssh) onion address:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;cat /var/lib/tor-instances/ssh1/hidden_service/hostname&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The output will look like:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;zyxwvutsrqponmlkjihgfedcba.onion&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;install-web-server&quot;&gt;install web server&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;apt install nginx-light&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Edit the default nginx site file:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim /etc/nginx/sites-available/default&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Change the default server to:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;listen 127.0.0.1:80 default_server;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Restart nginx:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemctl restart nginx&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;ssh-and-scp-from-macos-client-via-tor&quot;&gt;ssh and scp from macOS client via tor&lt;/h1&gt;
&lt;p&gt;Install tor and torsocks&lt;/p&gt;
&lt;p&gt;&lt;code&gt;brew install tor torsocks&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Edit ssh (client) config:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/ssh/ssh_config&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Add:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;UseRoaming no&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;proxyCommand nc -x 127.0.0.1:9050 %h %p&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Copy your ssh pub key to the server via tor onion:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ssh-copy-id user@zyxwvutsrqponmlkjihgfedcba.onion&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;ssh to the onion server:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ssh user@zyxwvutsrqponmlkjihgfedcba.onion&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;scp site data to the onion&#39;s web server folder:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;scp -r ./_site/* user@zyxwvutsrqponmlkjihgfedcba.onion:/var/www/html/.&lt;/code&gt;&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Ubuntu Server OS Updates with Security and Privacy</title>
        <published>2024-09-29T00:00:00+00:00</published>
        <updated>2024-09-29T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/ubuntu-os-updates-with-security-and-privacy/"/>
        <id>https://yawnbox.eu/blog/ubuntu-os-updates-with-security-and-privacy/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/ubuntu-os-updates-with-security-and-privacy/">&lt;h1 id=&quot;never-forget&quot;&gt;Never Forget&lt;/h1&gt;
&lt;p&gt;Never Forget &lt;a rel=&quot;external&quot; href=&quot;https://www.debian.org/security/2016/dsa-3733&quot;&gt;DSA-3733&lt;/a&gt;: Validating Signatures &amp;gt; MitM &amp;gt; RCE.&lt;/p&gt;
&lt;p&gt;The Debian developer community refused to implement transport cryptography for updates because “signing packages is secure enough”. Incompetence. This post is about &quot;the how&quot;. If you want to read about &quot;the why&quot;, please read my earlier post: &lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/privacy-proposal-for-debian/&quot;&gt;https://yawnbox.eu/blog/privacy-proposal-for-debian/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This guide will help significantly improve the privacy and security of your Ubuntu server. It requires the installation of apt-transport-tor, an application that will allow apt transfers to occur over Tor. There is also an application called apt-transport-https that is already installed in all modern versions of Ubuntu.&lt;/p&gt;
&lt;p&gt;The Wikimedia Ubuntu repo has a good TLS configuration, IPv6 and IPv4 support, and they don&#39;t block Tor. See their Qualys SSL Labs grade: &lt;a rel=&quot;external&quot; href=&quot;https://www.ssllabs.com/ssltest/analyze.html?d=mirrors.wikimedia.org&amp;amp;latest&quot;&gt;https://www.ssllabs.com/ssltest/analyze.html?d=mirrors.wikimedia.org&amp;amp;latest&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;First, secure the transport of the DNS request. The following guide enables DNS over TLS (DoT) for outbound DNS queries with built-in functions.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Note: If you are reading this and know of a way to push DoT or DoH traffic out Tor (like with a SOCKS5 proxy pointing to 127.0.0.1:9050 or something), please send me a message!&lt;/em&gt;&lt;/p&gt;
&lt;h1 id=&quot;dns-transport-security&quot;&gt;DNS transport security&lt;/h1&gt;
&lt;p&gt;Works on Ubuntu 22.04 - 24.04.&lt;/p&gt;
&lt;p&gt;Edit resolved.conf by&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;enabling enabling Quad9&#39;s IPs with coresponding DoT FQDNs&lt;/li&gt;
&lt;li&gt;enabling Cloudflare&#39;s IPs with coresponding DoT FQDNs as fallback&lt;/li&gt;
&lt;li&gt;enabling strict DNSSEC validation&lt;/li&gt;
&lt;li&gt;enabling strict DoT&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/systemd/resolved.conf&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Resolve]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DNS=9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net 2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;FallbackDNS=1.1.1.1#cloudflare-dns.com 1.0.0.1#cloudflare-dns.com 2606:4700:4700::1111#cloudflare-dns.com 2606:4700:4700::1001#cloudflare-dns.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DNSSEC=yes&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DNSOverTLS=yes&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If these hardening changes for DNSSEC or DNSoverTLS don&#39;t work for you, these are optional, weaker replacements:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DNSSEC=allow-downgrade&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DNSOverTLS=opportunistic&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I also enable these settings:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;MulticastDNS=no&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;LLMNR=no&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Cache=no-negative&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DNSStubListener=yes&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Restart systemd-resolved:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl restart systemd-resolved&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Edit Netplan (depending on your system, there should be one *.yaml file in /etc/netplan by default. Edit that one.):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/netplan/01-netcfg.yaml &lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Under nameservers, add the local DNS stub listener only:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      nameservers:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;              addresses:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;                      - 127.0.0.53&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Apply the netplan changes:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo netplan apply&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;dot-validation&quot;&gt;DoT Validation&lt;/h2&gt;
&lt;p&gt;You can validate the exclusive use of DoT by using ufw. If, like me, you are denying all outbound (&lt;em&gt;ufw default deny outgoing&lt;/em&gt;), all you have to do is delete the &lt;em&gt;allow out 53/udp&lt;/em&gt; rule, and add an &lt;em&gt;allow out 853/tcp&lt;/em&gt; rule. Otherwise, add a &lt;em&gt;deny out 53/udp&lt;/em&gt; rule and test.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo ufw delete 53/udp&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo ufw allow out 853/tcp&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo ufw reload&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;or&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo ufw deny out 53/udp&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo ufw allow out 853/tcp&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sudo ufw reload&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You can also check the status of resolvectl:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;resolvectl status&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;This should say something like:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Global&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        Protocols: -LLMNR -mDNS +DNSOverTLS DNSSEC=yes/supported&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        resolv.conf mode: stub&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        Current DNS Server: 2620:fe::9#dns.quad9.net&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        DNS Servers: 9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;                      2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net 127.0.0.53&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        Fallback DNS Servers: 1.1.1.1#cloudflare-dns.com 1.0.0.1#cloudflare-dns.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;                      2606:4700:4700::1111#cloudflare-dns.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;                      2606:4700:4700::1001#cloudflare-dns.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Link 2 (eth0)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        Current Scopes: DNS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;                 Protocols: +DefaultRoute -LLMNR -mDNS +DNSOverTLS DNSSEC=yes/supported&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        Current DNS Server: 127.0.0.53&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;                DNS Servers: 127.0.0.53&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Watch local legacy DNS queries, if any:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo tcpdump -i any -n port 53&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Watch local DoT queries, if any:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo tcpdump -i any -n port 853&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Try an outbound web request, like with &lt;em&gt;sudo apt update&lt;/em&gt;! If it works, then your DNS queries are TLS encrypted to Quad9! Pinging domains is also a sound check:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ping4 google.com&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;If you have IPv6 configured on your system:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;ping6 google.com&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;apt-transport-security&quot;&gt;apt transport security&lt;/h1&gt;
&lt;p&gt;If you only want increased apt transport security, this is what your apt sources should look like.&lt;/p&gt;
&lt;h2 id=&quot;ubuntu-22-04-jammy&quot;&gt;Ubuntu 22.04 Jammy&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/apt/sources.list&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;deb https://mirrors.wikimedia.org/ubuntu/ jammy main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;deb https://mirrors.wikimedia.org/ubuntu/ jammy-updates main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;deb https://mirrors.wikimedia.org/ubuntu/ jammy-backports main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;deb https://mirrors.wikimedia.org/ubuntu/ jammy-security main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&quot;ubuntu-24-04-noble&quot;&gt;Ubuntu 24.04 Noble&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/apt/sources.list.d/ubuntu.sources&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Types: deb&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;URIs: https://mirrors.wikimedia.org/ubuntu/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Suites: noble noble-updates noble-security noble-backports&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Components: main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&quot;apt-transport-privacy&quot;&gt;apt transport privacy&lt;/h1&gt;
&lt;p&gt;If you want security and privacy, use tor, via apt-transport-tor.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt install tor apt-transport-tor&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;ubuntu-22-04-jammy-1&quot;&gt;Ubuntu 22.04 Jammy&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/apt/sources.list&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;deb tor+https://mirrors.wikimedia.org/ubuntu/ jammy main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;deb tor+https://mirrors.wikimedia.org/ubuntu/ jammy-updates main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;deb tor+https://mirrors.wikimedia.org/ubuntu/ jammy-backports main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;deb tor+https://mirrors.wikimedia.org/ubuntu/ jammy-security main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&quot;ubuntu-24-04-noble-1&quot;&gt;Ubuntu 24.04 Noble&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/apt/sources.list.d/ubuntu.sources&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Types: deb&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;URIs: tor+https://mirrors.wikimedia.org/ubuntu/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Suites: noble noble-updates noble-security noble-backports&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Components: main restricted universe multiverse&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Validate with:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt update&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;apt-transport-privacy-scripted&quot;&gt;apt transport privacy - scripted&lt;/h1&gt;
&lt;p&gt;This is a shell script I made for Jammy that will also install the Tor Project&#39;s PGP key and install the most recent version of Tor from Tor Project.&lt;/p&gt;
&lt;h2 id=&quot;ubuntu-22-04-jammy-2&quot;&gt;Ubuntu 22.04 Jammy&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;sudo vim jammy_apt_upgrade.sh&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Cut and paste this in there:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#!/bin/bash&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mv /etc/apt/sources.list /etc/apt.sources.backup1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;touch /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb https://mirrors.wikimedia.org/ubuntu/ jammy main restricted universe multiverse&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb https://mirrors.wikimedia.org/ubuntu/ jammy-updates main restricted universe multiverse&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb https://mirrors.wikimedia.org/ubuntu/ jammy-backports main restricted universe multiverse&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb https://mirrors.wikimedia.org/ubuntu/ jammy-security main restricted universe multiverse&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb [arch=amd64] https://deb.torproject.org/torproject.org jammy main&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;wget -qO- https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --import&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;gpg --export A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89 | apt-key add -&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;apt update&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;apt install tor deb.torproject.org-keyring apt-transport-tor -y&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mv /etc/apt/sources.list /etc/apt.sources.backup2&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;touch /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb tor+https://mirrors.wikimedia.org/ubuntu/ jammy main restricted universe multiverse&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb tor+https://mirrors.wikimedia.org/ubuntu/ jammy-updates main restricted universe multiverse&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb tor+https://mirrors.wikimedia.org/ubuntu/ jammy-backports main restricted universe multiverse&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb tor+https://mirrors.wikimedia.org/ubuntu/ jammy-security main restricted universe multiverse&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;#39;deb [arch=amd64] tor+https://deb.torproject.org/torproject.org jammy main&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;apt update &amp;amp;&amp;amp; apt dist-upgrade -V&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;code&gt;sudo chmod +x jammy_apt_upgrade.sh&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Run:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo sh ./jammy_apt_upgrade.sh&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Or, if you trust me, run this script (for Jammy):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;curl -s https://yawnbox.eu/scripts/jammy_apt_upgrade.sh | sudo sh&lt;/code&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Ubuntu Server + Minecraft vanilla server with Purpur</title>
        <published>2024-09-08T00:00:00+00:00</published>
        <updated>2024-09-08T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/ubuntu-minecraft-server/"/>
        <id>https://yawnbox.eu/blog/ubuntu-minecraft-server/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/ubuntu-minecraft-server/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;I started using Purpur in order to support vanilla Minecraft plugins and for server performance enhancements. I am also using Adoptium Java for the stability, performance, and security benefits rather than using OpenJDK. I like running Purpur becuase its vanilla minecraft but then allows the use of more advanced plugins. The plugins are all server-side, so the clients get them automatically, unlick modded Minecraft.&lt;/p&gt;
&lt;h1 id=&quot;setup-and-install-purpur&quot;&gt;Setup and Install Purpur&lt;/h1&gt;
&lt;p&gt;I&#39;m using Ubuntu Server 22.04 LTS at the time of writing.&lt;/p&gt;
&lt;h2 id=&quot;install-java&quot;&gt;Install Java&lt;/h2&gt;
&lt;p&gt;Install Adoptium&#39;s Temurin 22 for Java: https://adoptium.net/installation.html&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo mkdir -p /etc/apt/keyrings&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo wget -O - https://packages.adoptium.net/artifactory/api/gpg/key/public | tee /etc/apt/keyrings/adoptium.asc&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo echo &quot;deb [signed-by=/etc/apt/keyrings/adoptium.asc] https://packages.adoptium.net/artifactory/deb $(awk -F= &#39;/^VERSION_CODENAME/{print$2}&#39; /etc/os-release) main&quot; | tee /etc/apt/sources.list.d/adoptium.list&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt update &amp;amp;&amp;amp; apt install temurin-22-jdk zip -V&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Validate the Java version:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;/usr/bin/java --version&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The output should look like:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;openjdk 22.0.2 2024-07-16&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;OpenJDK Runtime Environment Temurin-22.0.2+9 (build 22.0.2+9)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;OpenJDK 64-Bit Server VM Temurin-22.0.2+9 (build 22.0.2+9, mixed mode, sharing)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&quot;create-an-isolated-linux-user-for-security&quot;&gt;Create an isolated Linux user, for security&lt;/h2&gt;
&lt;p&gt;Create a limited user that will be running the Minecraft server:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo adduser --system --home /home/minecraft --group --shell /usr/sbin/nologin minecraft&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Create a new folder for the server and enter that folder:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo mkdir /home/minecraft/purpur &amp;amp;&amp;amp; cd /home/minecraft/purpur&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;download-purpur&quot;&gt;Download Purpur&lt;/h2&gt;
&lt;p&gt;You can download the latest Purpur by going here in a web browser:&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://purpurmc.org&quot;&gt;https://purpurmc.org&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Copy the link to download it to your server folder (ie: /home/minecraft/purpur):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo wget https://api.purpurmc.org/v2/purpur/1.21.1/latest/download --content-disposition&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Make the jar file is executable:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo chmod +x purpur-1.21.1-2303.jar&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;create-s-systemd-service-for-security-and-ease-of-use&quot;&gt;Create s systemd service, for security, and ease of use&lt;/h2&gt;
&lt;p&gt;Note: I would have used a Java Security Manager policy to harden Java, but that&#39;s being depreciated in newer versions of Java. Since we want to always use the most recent version possible for security and performance reassons, I use a hardened systemd service to manage Java, Purpur, and Minecraft.&lt;/p&gt;
&lt;p&gt;Create a new Minecraft systemd service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/systemd/system/minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Copy and paste all of these lines into the minecraft.service file:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Unit]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Description=Minecraft Server&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;After=network.target&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Service]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Run as the &amp;#39;minecraft&amp;#39; user and group&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;User=minecraft&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Group=minecraft&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Restrict network access to specified IPs&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;IPAddressAllow=103.232.207.250&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;IPAddressAllow=2620:18c:0:192::250&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Security Enhancements&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;AmbientCapabilities=CAP_NET_BIND_SERVICE&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;CapabilityBoundingSet=CAP_NET_BIND_SERVICE&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;LockPersonality=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#MemoryDenyWriteExecute=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NoNewPrivileges=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectSystem=full&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#ProtectHome=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectClock=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateDevices=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelLogs=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#PrivateNetwork=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateTmp=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateUsers=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProcSubset=pid&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectControlGroups=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelModules=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectKernelTunables=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectProc=invisible&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ProtectSystem=strict&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RemoveIPC=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictAddressFamilies=AF_INET AF_INET6&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictNamespaces=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictRealtime=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RestrictSUIDSGID=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SystemCallFilter=@system-service&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SystemCallArchitectures=native&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Paths related to the Minecraft server&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadOnlyPaths=/usr/bin/java&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadOnlyPaths=/usr/lib/jvm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadWritePaths=/home/minecraft/purpur&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;WorkingDirectory=/home/minecraft/purpur&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# JVM flags for performance optimization&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExecStart=/usr/bin/java -Xmx16G -Xms16G -XX:+UseG1GC -XX:+ParallelRefProcEnabled -XX:MaxGCPauseMillis=200 \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UnlockExperimentalVMOptions -XX:+DisableExplicitGC -XX:+AlwaysPreTouch -XX:G1NewSizePercent=40 \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MaxNewSizePercent=50 -XX:G1HeapRegionSize=16M -XX:G1ReservePercent=15 -XX:G1HeapWastePercent=5 \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MixedGCCountTarget=4 -XX:InitiatingHeapOccupancyPercent=20 -XX:G1MixedGCLiveThresholdPercent=90 \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1RSetUpdatingPauseTimePercent=5 -XX:SurvivorRatio=32 -XX:+PerfDisableSharedMem -XX:MaxTenuringThreshold=1 \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;--add-modules=jdk.incubator.vector -jar /home/minecraft/purpur/purpur-1.21.1-2303.jar --nogui&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Install]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;WantedBy=multi-user.target&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h3 id=&quot;important-minecraft-service-file-notes&quot;&gt;Important minecraft.service file notes:&lt;/h3&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;IPAddressAllow=103.232.207.250&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;IPAddressAllow=2620:18c:0:192::250&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ These two lines limit which IPv4 and IPv6 addresses can be used. Be sure to change these to your IPs. If you don&#39;t have an IPv6 address, remove the line.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadOnlyPaths=/usr/bin/java&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadOnlyPaths=/usr/lib/jvm&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ These two paths are to make sure Java can be called. The JVM folder is where Temurin is installed. These lines shouldn&#39;t need to change.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ReadWritePaths=/home/minecraft/purpur&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;WorkingDirectory=/home/minecraft/purpur&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ These two paths are the same, as they are where Purpur is downloaded to. If you want to install purpur into /opt instead, then these lines should change.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xmx16G -Xms16G&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ This flag must change based on how much static RAM you want to give the Minecraft server.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-jar /home/minecraft/purpur/purpur-1.21.1-2303.jar&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;^ This jar flag indicates the specified purpur file with its explicit version that must be launched. This needs to be manually updated every time purpur is updated.&lt;/p&gt;
&lt;p&gt;For descriptions of all of the java arguments used, see the bottom of this article.&lt;/p&gt;
&lt;h3 id=&quot;continue-systemd-setup&quot;&gt;Continue systemd setup&lt;/h3&gt;
&lt;p&gt;Save the minecraft.service file (via vim):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;:wq&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Reload systemd:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl daemon-reload&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Note: everytime the minecraft.service file is updated, this daemon-reload must be re-run.&lt;/p&gt;
&lt;p&gt;Enable the new service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl enable minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Accept the EULA in advance of running the first time (from within /home/minecraft/purpur):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo rm -f eula.txt &amp;amp;&amp;amp; sudo touch eula.txt &amp;amp;&amp;amp; sudo echo &#39;eula=true&#39; &amp;gt;&amp;gt; eula.txt &amp;amp;&amp;amp; sudo cat eula.txt&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Presuming you have already enabled the inbound firewall for server security, open up the Minecraft port. I use &quot;limit&quot; instead of &quot;allow&quot; to prevent DoS attacks:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo ufw limit 25565/tcp &amp;amp;&amp;amp; sudo ufw reload&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Start Minecraft for the first time to setup the files:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl start minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;You can see the service status with:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl status minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;You can see the logging output with:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo journalctl -u minecraft.service -f&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;note-about-the-first-run&quot;&gt;Note about the first run&lt;/h2&gt;
&lt;p&gt;When I ran the start script the first time, I saw &quot;Downloading mojang_1.20.1.jar&quot; for a long time and nothing seemed to be happening. To test, I downloaded it &lt;a rel=&quot;external&quot; href=&quot;https://www.minecraft.net/en-us/article/minecraft--java-edition-1-20-1&quot;&gt;manually&lt;/a&gt; to my minecraft server just to see if there was a connection issue, but it seems it&#39;s just a very slow download. Less than 100 KB/s yet only a 46 MB file. Could take as long as 20 minutes, so just be patient. Manually downloading the server.jar file does not speed up the script.&lt;/p&gt;
&lt;p&gt;After the download completes, the script will start Minecraft for the first time.&lt;/p&gt;
&lt;h2 id=&quot;configure-purpur-for-the-first-time&quot;&gt;Configure Purpur for the first time&lt;/h2&gt;
&lt;p&gt;Stop the service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl stop minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;There are now many other files and folders in the /home/minecraft/purpur directory.&lt;/p&gt;
&lt;p&gt;Edit the server.properties file:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo vim server.properties&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Things I typically change:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;motd=your.domain.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;difficulty=hard&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;max-players=9000&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;allow-flight=true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;view-distance=32&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;server-ip=1.2.3.4&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;server-name=your.domain.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;level-type=AMPLIFIED&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then start the server back up!&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl start minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Have fun!&lt;/p&gt;
&lt;h2 id=&quot;plugins&quot;&gt;Plugins&lt;/h2&gt;
&lt;p&gt;If and when you want to install any plugins, first download the plugin jar files then restart the server service. I&#39;d watch YouTube about the most popular plugins for ideas.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;cd /home/minecraft/purpur/plugins/&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;MineTinker&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo wget https://github.com/Flo56958/MineTinker/releases/download/v1.9/MineTinker.jar&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;WorldEdit&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo wget https://cdn.modrinth.com/data/1u6JkXh5/versions/yAujLUIK/worldedit-bukkit-7.3.6.jar&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;WorldGuard&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo wget https://dev.bukkit.org/projects/worldguard/files/latest --content-disposition&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;VeinMiner&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo wget https://cdn.modrinth.com/data/OhduvhIc/versions/Sogh3qHz/Veinminer-2.1.3.jar&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;DeadChest&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo wget https://dev.bukkit.org/projects/dead-chest/files/latest --content-disposition&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Restart the systemd service:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo systemctl restart minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;h2 id=&quot;maintenance&quot;&gt;Maintenance&lt;/h2&gt;
&lt;p&gt;To backup a world manually:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo zip -r /home/minecraft/purpur/world.zip /home/minecraft/purpur/world/&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To delete a world and start over (while the server is stopped):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo rm -r /home/minecraft/purpur/world/&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Be sure to keep Adoptium&#39;s Java up to date, and of course all other system packages:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt update &amp;amp;&amp;amp; sudo apt dist-upgrade -V &amp;amp;&amp;amp; sudo apt autoremove -y &amp;amp;&amp;amp; sudo apt autoclean&lt;/code&gt;&lt;/p&gt;
&lt;h1 id=&quot;java-arguments-explained&quot;&gt;Java arguments explained&lt;/h1&gt;
&lt;p&gt;RAM management flags&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xmx16G:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;This sets the maximum heap size for the JVM to 16GB. This limits how much memory the Minecraft server can use.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-Xms16G:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;This sets the initial heap size to 16GB. This allocates 16GB of RAM from the start, ensuring the server has that memory available right away.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Garbage Collection (GC) Optimization Flags&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UseG1GC:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Enables the G1 garbage collector. G1 is optimized for low-latency garbage collection and is recommended for applications that need to handle large heaps like Minecraft.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+ParallelRefProcEnabled:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Enables parallel reference processing during garbage collection, improving GC performance by handling reference objects in parallel.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:MaxGCPauseMillis=200:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets a target for the maximum pause time for garbage collection to 200 milliseconds. This means the JVM will try to keep GC pauses under 200ms to avoid impacting performance.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+UnlockExperimentalVMOptions:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Unlocks experimental JVM options. This allows the JVM to use advanced and less commonly used optimizations.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+DisableExplicitGC:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Disables calls to System.gc() from the code, preventing explicit garbage collection that might affect performance.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+AlwaysPreTouch:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Pre-touch memory pages during JVM startup, ensuring all memory is allocated and locked upfront, which can reduce pauses during runtime.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;G1 Garbage Collection Tuning Flags&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1NewSizePercent=40:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the minimum size of the new (young) generation to 40% of the total heap.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MaxNewSizePercent=50:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the maximum size of the new (young) generation to 50% of the total heap.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1HeapRegionSize=16M:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the size of each heap region in G1 garbage collection to 16MB. Larger region sizes are better for large heaps.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1ReservePercent=15:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Reserves 15% of the heap as free space to reduce the chance of full garbage collection cycles (which are more expensive).&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1HeapWastePercent=5:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the tolerated heap waste percentage. G1 will aim to reclaim regions if more than 5% of the heap is considered &amp;quot;waste.&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MixedGCCountTarget=4:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the target number of mixed garbage collections (which reclaim both old and young regions) to 4.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:InitiatingHeapOccupancyPercent=20:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the threshold for starting concurrent garbage collection at 20% heap occupancy. This allows GC to start early enough to avoid larger full GC cycles.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1MixedGCLiveThresholdPercent=90:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;G1 will not reclaim any old regions where more than 90% of the region contains live objects.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:G1RSetUpdatingPauseTimePercent=5:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Limits the pause time for updating the remembered set (RSet) to 5% of the GC pause time.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:SurvivorRatio=32:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the ratio of Eden to Survivor spaces in the young generation to 32:1. Larger ratios mean more space in Eden, reducing promotion to the old generation.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:+PerfDisableSharedMem:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Disables the use of shared memory for performance monitoring, which can prevent unnecessary memory overhead.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-XX:MaxTenuringThreshold=1:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sets the maximum tenuring threshold to 1. This determines how many garbage collection cycles an object will go through before being promoted to the old generation.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Other Flags&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;--add-modules=jdk.incubator.vector:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Adds support for incubator modules in Java, such as the vector API. Incubator modules are experimental features.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-jar /home/minecraft/purpur/purpur-1.21.1-2303.jar:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Specifies the path to the Minecraft server JAR file to be executed.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;--nogui:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Disables the Minecraft server&amp;#39;s GUI for performance reasons since the server is run headless.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&quot;old-legacy-notes&quot;&gt;Old / Legacy Notes&lt;/h1&gt;
&lt;p&gt;I used to not use systemd and run Purpur with a shell script. here&#39;s what that old file would look like:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#!/bin/bash&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;JAVA=&amp;quot;java&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;JAR=&amp;quot;purpur-1.21.1-2303.jar&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RAM=&amp;quot;16000M&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;FLAGS=&amp;quot;-XX:+UseG1GC -XX:+ParallelRefProcEnabled -XX:MaxGCPauseMillis=200 -XX:+UnlockExperimentalVMOptions -XX:+DisableExplicitGC -XX:+AlwaysPreTouch -XX:G1NewSizePercent=40 -XX:G1MaxNewSizePercent=50 -XX:G1HeapRegionSize=16M -XX:G1ReservePercent=15 -XX:G1HeapWastePercent=5 -XX:G1MixedGCCountTarget=4 -XX:InitiatingHeapOccupancyPercent=20 -XX:G1MixedGCLiveThresholdPercent=90 -XX:G1RSetUpdatingPauseTimePercent=5 -XX:SurvivorRatio=32 -XX:+PerfDisableSharedMem -XX:MaxTenuringThreshold=1&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;quot;Starting the Minecraft server...&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;${JAVA} -Xmx${RAM} -Xms${RAM} ${FLAGS} --add-modules=jdk.incubator.vector -jar ${JAR} --nogui&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&quot;troubleshooting&quot;&gt;Troubleshooting&lt;/h1&gt;
&lt;p&gt;If you run into file or folder permissions issues, do this to correct them:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo find /home/minecraft/purpur/ -type d -exec chmod 755 {} \;&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo find /home/minecraft/purpur/ -type f -exec chmod 644 {} \;&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;But remember the .jar purpur file must always be executible&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo chmod +x purpur-1.21.1-2303.jar&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Audit your systemd service security with:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemd-analyze security minecraft.service&lt;/code&gt;&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Changing your Mastodon joined date with PostgreSQL</title>
        <published>2024-05-16T00:00:00+00:00</published>
        <updated>2024-05-16T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/changing-mastodon-joined-date/"/>
        <id>https://yawnbox.eu/blog/changing-mastodon-joined-date/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/changing-mastodon-joined-date/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;Thanks to &lt;a rel=&quot;external&quot; href=&quot;https://infosec.exchange/@micahflee&quot;&gt;Micah F Lee&lt;/a&gt; for the tip!&lt;/p&gt;
&lt;h1 id=&quot;steps&quot;&gt;Steps&lt;/h1&gt;
&lt;p&gt;I revalidated this recently on Mastodon v4.2.8.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;su mastodon&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;psql -d mastodon_production&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;mastodon_production=&amp;gt; &lt;code&gt;UPDATE accounts SET created_at=&#39;2017-04-06 00:00:00&#39; WHERE username=&#39;yawnbox&#39;;&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;exit&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The change is immediate, no need to restart postgresql or Mastodon.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>How to Use a Pixel Tablet as a Secure Calling and Messaging Device</title>
        <published>2024-02-19T00:00:00+00:00</published>
        <updated>2024-02-19T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/how-to-use-an-pixel-tablet-as-a-secure-calling-and-messaging-device/"/>
        <id>https://yawnbox.eu/blog/how-to-use-an-pixel-tablet-as-a-secure-calling-and-messaging-device/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/how-to-use-an-pixel-tablet-as-a-secure-calling-and-messaging-device/">&lt;p&gt;&lt;img src=&quot;/images/signal-message.png&quot; alt=&quot;Alt Text: A Pixel Tablet with CalyxOS showing a new Signal message&quot; /&gt;&lt;/p&gt;
&lt;h1 id=&quot;related-work&quot;&gt;Related Work&lt;/h1&gt;
&lt;p&gt;You may like my highly related article, &quot;&lt;a rel=&quot;external&quot; href=&quot;https://yawnbox.eu/blog/how-to-use-an-ipad-as-a-secure-calling-and-messaging-device/&quot;&gt;How to Use an iPad as a Secure Calling and Messaging Device&lt;/a&gt;&quot;.&lt;/p&gt;
&lt;h1 id=&quot;intro&quot;&gt;Intro&lt;/h1&gt;
&lt;p&gt;This guide is aimed at providing a detailed method for maximizing security and privacy on a Google Pixel Tablet (2023). This guide should be adapted to fit your threat model. While this guide aims to provide a high level of operational security, I am not &lt;em&gt;your&lt;/em&gt; security engineer. If you&#39;d like to hire me to talk about your threat model, please email c@stellarwind.net.&lt;/p&gt;
&lt;p&gt;Legacy phone calling and texting (SMS, MMS) are inherently insecure. Communications content and metadata is collected and stored by various organizations and for many years. All people, but especially those in at-risk professions, have a responsibility to safeguard their communications with strong encryption technologies. Only then will your coworkers, friends, and family be able to collectively defend your rights. In professions where privacy is expected between you and clients like law and journalism, policy should dictate to either communicate securely or not at all.&lt;/p&gt;
&lt;p&gt;Encryption technology is not new but default strong encryption in mass-market devices is. The political cost of default privacy and security is at an all-time low while the social expectations of strong encryption are at an all-time high. Modern telecommunications largely depend on legacy and vulnerable communications infrastructure, which is by design:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All cell phones (baseband processor) transmit insecure content and metadata because cell networks were designed for connectivity and surveillance of said connectivity.&lt;/li&gt;
&lt;li&gt;All cell phones (baseband processor) not broken, off, or in Airplane Mode can be easily tracked.&lt;/li&gt;
&lt;li&gt;The majority of SIM cards require registration using government-issued ID.&lt;/li&gt;
&lt;li&gt;Most Androids get slowly patched, if at all.&lt;/li&gt;
&lt;li&gt;Carrier modified versions of Android are poorly developed and maintained.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;“Nobody is listening to your telephone calls”&lt;/strong&gt; –President Obama, 2013&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;President Obama is not &lt;em&gt;lying&lt;/em&gt;. It is not possible for the US government to &quot;listen&quot; to every phone call. However, the technical requirements for recording phone calls (&lt;a rel=&quot;external&quot; href=&quot;https://www.washingtonpost.com/world/national-security/nsa-surveillance-program-reaches-into-the-past-to-retrieve-replay-phone-calls/2014/03/18/226d2646-ade9-11e3-a49e-76adc9210f19_story.html&quot;&gt;MYSTIC&lt;/a&gt;, &lt;a rel=&quot;external&quot; href=&quot;https://theintercept.com/2015/02/19/great-sim-heist/&quot;&gt;DAPINO GAMMA&lt;/a&gt;) and text messages (&lt;a rel=&quot;external&quot; href=&quot;https://www.theguardian.com/world/2014/jan/16/nsa-collects-millions-text-messages-daily-untargeted-global-sweep&quot;&gt;DISHFIRE&lt;/a&gt;) is more than feasible. It is cheaper and more effective to transcribe voice data to text, transcriptions that can be stored forever. The solution is easy: don’t give it to them.&lt;/p&gt;
&lt;p&gt;What is bad for U.S. Intelligence is also bad for all other malicious actors. It is up to us to cause the social change that in turn lowers the personal costs of default privacy and security and the financial risk of businesses to support what we need.&lt;/p&gt;
&lt;p&gt;The financial cost of surveillance equipment is also at an all-time low. Mobile IMSI catchers can be built and deployed by anyone technically savvy enough to learn how to build one, and law enforcement has large budgets for more feature rich devices. The most effective way to assure that you are not a victim of cell tracking or attack is to not use those systems.&lt;/p&gt;
&lt;h1 id=&quot;the-goal&quot;&gt;The Goal&lt;/h1&gt;
&lt;p&gt;The goal of this guide is to install CalyxOS (or GrapheneOS if you choose) onto a &lt;a rel=&quot;external&quot; href=&quot;https://store.google.com/us/product/pixel_tablet&quot;&gt;Google Pixel Tablet&lt;/a&gt;, which is not a cellular device (no baseband processor). Using CalyxOS streamlines the install and use of Orbot (Tor) and Signal while also not using Google services of any kind. At the end of this guide is an optional DEFCON ONE configuration that may further mitigate certain kinds of attackers.&lt;/p&gt;
&lt;h1 id=&quot;the-google-pixel-tablet-from-a-hardware-point-of-view&quot;&gt;The Google Pixel Tablet, from a hardware point of view&lt;/h1&gt;
&lt;p&gt;The Pixel Tablet fills a much needed space:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Supports Wi-Fi only&lt;/li&gt;
&lt;li&gt;Supports &lt;a rel=&quot;external&quot; href=&quot;https://security.googleblog.com/2021/10/pixel-6-setting-new-standard-for-mobile.html&quot;&gt;Tensor SoC &amp;amp; Titan M2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Supports &lt;a rel=&quot;external&quot; href=&quot;https://calyxos.org&quot;&gt;CalyxOS&lt;/a&gt; or &lt;a rel=&quot;external&quot; href=&quot;https://grapheneos.org&quot;&gt;GrapheneOS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Supports &lt;a rel=&quot;external&quot; href=&quot;https://signal.org&quot;&gt;Signal&lt;/a&gt; via &lt;a rel=&quot;external&quot; href=&quot;https://f-droid.org&quot;&gt;F-Droid&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Supports &lt;a rel=&quot;external&quot; href=&quot;https://support.torproject.org/glossary/orbot/&quot;&gt;Orbot&lt;/a&gt; also via F-Droid&lt;/li&gt;
&lt;li&gt;Supports wired headsets for audio and video calls via USB-C&lt;/li&gt;
&lt;li&gt;Supports wired ethernet adapters via USB-C&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;blending-in&quot;&gt;Blending In&lt;/h2&gt;
&lt;p&gt;One reason why Tor is so valuable compared to any for-profit VPN provider is that you blend in with everyone else using Tor. Don&#39;t stick out. Using &quot;un-hackable phones&quot; or hardware-modded devices sticks out. Using commodity hardware like a Google Pixel device does not. This has important value for both physical surveillance and network surveillance.&lt;/p&gt;
&lt;h2 id=&quot;why-not-use-a-phone-in-airplane-mode-why-does-it-need-to-be-a-wi-fi-only-device&quot;&gt;Why not use a phone in Airplane Mode? Why does it need to be a Wi-Fi-only device?&lt;/h2&gt;
&lt;p&gt;In cell phones (devices with cellular baseband processors), the baseband is an isolated computer within the phone, with its own power controller, CPU, memory, firmware, and operating system. When a phone boots up, the initialization sequence of the phone includes the boot up of the baseband. This means that the baseband is initialized, before and in parallel to, the phone&#39;s main SoC and operating system. This is done for power-saving and security reasons. It means that when you put a phone into Airplane Mode, all you&#39;re doing is turning your phone&#39;s operating system&#39;s access to the baseband off. Airplane Mode does not guarantee that the baseband hardware, firmware, or software stack is turned off. Airplane Mode effectively preventing baseband from I/O&#39;ing may be dependent on the hardware, firmware, and OS of the deivce, and it should be presumed that no baseband is trustworthy unless proven otherwise.&lt;/p&gt;
&lt;p&gt;Another issue is that Airplane Mode is an OS feature. If the OS hasn&#39;t even booted, a user has extremely limited control over baseband. Recently confirming this issue is a security researcher &lt;a rel=&quot;external&quot; href=&quot;https://discuss.grapheneos.org/d/10710-rf-reader-spike-cell-tower-bands-when-powering-up&quot;&gt;observing an RF spike&lt;/a&gt; during cellular Pixel devices (phones, with basebands) during boot. Wether it&#39;s a hardware or firmware design decision, or accident, different operating systems cannot guarantee that lower levels of a phone will not behave in unexpected ways, particularly during the phone&#39;s boot process before the OS even initializes. It should be assumed that every kernel patch and every firmware patch may change the behavior of baseband. Testing all patch levels with RF meters would be necessary to guarantee expected outcomes. Or, don&#39;t use devices with basebands.&lt;/p&gt;
&lt;p&gt;Even without a SIM card, with Airplane Mode not enabled, a baseband processor can and does connect to cell towers, including the disclosure of the device&#39;s IMEI along with &quot;when&quot; and &quot;where&quot; metadata (&lt;a rel=&quot;external&quot; href=&quot;https://www.fcc.gov/document/rosenworcel-shares-mobile-carrier-responses-data-privacy-probe&quot;&gt;read more here&lt;/a&gt;). This is how a SIM-less phone can call 911. It&#39;s impossible to mitigate cellular communications without resorting to Faraday cages.&lt;/p&gt;
&lt;h1 id=&quot;google-the-national-security-agency-and-data-link-ability&quot;&gt;Google, the National Security Agency, and Data Link-Ability&lt;/h1&gt;
&lt;p&gt;Google is an American company that works with the NSA and is part of the &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/PRISM_(surveillance_program)&quot;&gt;PRISM program&lt;/a&gt;. If you are, or ever could be a target of U.S. intelligence or U.S. military organizations, you are already playing difficult game by choosing a Google product. However, you probably aren&#39;t defending against the NSA. Not all adversaries are the NSA, nor do they have the budgets and reach as the NSA. Risk minimization should not always be compared to NSA-style actors. Care about your threat model, not someone else&#39;s.&lt;/p&gt;
&lt;p&gt;Just turning on a Google product with stock Android, the device is working against you by collecting WiFi and Bluetooth network information in order to attempt to &quot;streamline&quot; a user&#39;s setup experience. Some of that data is uploaded to Google&#39;s servers as soon as the device is connected to the internet. Every Google device, especially new ones, upload its unique hardware identifiers to Google, along with network metadata that can disclose physical location information to Google.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Your mobile device&#39;s hardware identifiers, like a MAC address.&lt;/li&gt;
&lt;li&gt;Your wireless access point (WAP) MAC address and SSID.&lt;/li&gt;
&lt;li&gt;All of your neighbor&#39;s WAP&#39;s MACs and SSIDs.&lt;/li&gt;
&lt;li&gt;Your public IP address used to connect to *.google.com services.&lt;/li&gt;
&lt;li&gt;If your WAP, or any of your neighbor&#39;s WAPs observe your real MAC address, and those WAPs are cloud connected, it should be presumed that those WAPs will report the metadata associated with seeing your MAC at that location to a cloud database.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Note: CalyxOS, by default, uses MAC address randomization.&lt;/p&gt;
&lt;p&gt;If Google, or any of the U.S. intelligence or military organizations, have any other data that links anything about you to the this Google device, your identity can be tracked by these organizations via data link-ability. Other secondary data points about this device can and will be linked to you if targeted:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Your bank card used to make the purchase.&lt;/li&gt;
&lt;li&gt;Your physical address for device delivery, if bought online.&lt;/li&gt;
&lt;li&gt;Your car license plate seen by Automatic License Plate Readers (ALPR) going to pick up the device.&lt;/li&gt;
&lt;li&gt;Face survaillance systems as you travel to and from a physical store to buy the device.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;google-firebase-cloud-messaging-fcm&quot;&gt;Google Firebase Cloud Messaging (FCM)&lt;/h2&gt;
&lt;p&gt;When using Signal on a device running Android, such as a Google Pixel Tablet, it requires the use of Firebase Cloud Messaging (FCM). This indicates that Google has access to metadata records of when, where, and what service you&#39;re using. NSA/FVEY &lt;a rel=&quot;external&quot; href=&quot;https://techcrunch.com/2023/12/06/us-senator-warns-governments-spying-apple-google-smartphone-users-via-push-notifications/&quot;&gt;is spying on and storing this data&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://mastodon.world/@Mer__edith/111563866152334347&quot;&gt;Per&lt;/a&gt; Meredith Whittaker, Signal&#39;s President, &quot;In Signal, push notifications simply act as a ping that tells the app to wake up. They don&#39;t reveal who sent the message or who is calling (not to Apple, Google, or anyone). Notifications are processed entirely on your device.&quot;&lt;/p&gt;
&lt;p&gt;That &quot;ping&quot; is more than just a ping, and requires Google to have a lot of data about the target service and the target device. Google is able to see, and thus FVEY is able to make a permanent record of:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;FCM identifiers, such as hardware identifiers, of who is receiving a message.&lt;/li&gt;
&lt;li&gt;The messaging application; in this case, Signal.&lt;/li&gt;
&lt;li&gt;The date and time associated with received messages.&lt;/li&gt;
&lt;li&gt;Any network metadata, such as IP, associated with receiving messages.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;All of this can and will be used with FVEY&#39;s other records, such as internet backbone or ISP metadata, and will be used to confirm assumptions made when identifying who is talking to whom.&lt;/p&gt;
&lt;p&gt;To further break this down:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A Signal user sends a message to an Android user via Signal (the receiver).&lt;/li&gt;
&lt;li&gt;Signal&#39;s servers notify FCM that there is a message or call waiting for a specific user.&lt;/li&gt;
&lt;li&gt;FCM &quot;pings&quot; the specific user&#39;s Android device.&lt;/li&gt;
&lt;li&gt;The receiver&#39;s Android device receives the &quot;ping&quot; and notifies the end user that there are new Signal messages, or a call.&lt;/li&gt;
&lt;li&gt;The receiver&#39;s Signal application then activates and requests any new messages (or calls) from Signal&#39;s servers.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;After wiping stock Android off the Pixel Tablet, which the CalyxOS setup process does, a user is able to opt-in to installing Google services. This is how to evade FCM: by not installing Google services. CalyxOS is Android without any Google services by default, and Signal can be installed trivially and operate without FCM. Further, CalyxOS makes it trivial to install and use Orbot (Tor), system wide. Orbot significantly enhances network metadata surveillance resistance to a global passive adversary (GPA; in other words, someone who is able to surveil tremendous amounts of the internet).&lt;/p&gt;
&lt;h1 id=&quot;critical-notes&quot;&gt;Critical Notes&lt;/h1&gt;
&lt;h2 id=&quot;wi-fi-tablet-signal-advantages&quot;&gt;Wi-Fi tablet + Signal advantages&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;The Pixel Tablet does not have a baseband processor, SIM card, or SIM card port insecurities.&lt;/li&gt;
&lt;li&gt;You can control which Wi-Fi networks to expose your device to, if you choose to use Wi-Fi.&lt;/li&gt;
&lt;li&gt;The Pixel Tablet employs default Full Disk Encryption that is dependent on hardware and firmware cryptographic integrity controls.&lt;/li&gt;
&lt;li&gt;CalyxOS publishes security patches quickly and are not dependent on carrier restrictions.&lt;/li&gt;
&lt;li&gt;Signal uses only modern, always-on, end-to-end cryptography. As of September 2023, Signal now has &lt;a rel=&quot;external&quot; href=&quot;https://signal.org/blog/pqxdh/&quot;&gt;quantum resistance&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Signal allows users to verify encryption key fingerprints.&lt;/li&gt;
&lt;li&gt;Signal is free, open source, and has public security audits.&lt;/li&gt;
&lt;li&gt;Signal supports interoperability, meaning that other people can use Signal on iOS or Android devices.&lt;/li&gt;
&lt;li&gt;CalyxOS employes good security and privacy protections by default. For example, a cloud account is not necessary to download, install, or update apps such as Signal (via F-Droid).&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;wi-fi-tablet-signal-disadvantages&quot;&gt;Wi-Fi tablet + Signal disadvantages&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Wired or Wi-Fi internet access is not as abundant as cellular internet access. These days, people depend heavily on having an always-connected device to function.&lt;/li&gt;
&lt;li&gt;Setting up CalyxOS on an Android device, while straight forward, will feel very daunting to a non-technical individual. Calyx Institute made its own installer to automate the process as much as possible, and it&#39;s a huge help.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;notes-on-device-charging&quot;&gt;Notes on Device Charging&lt;/h2&gt;
&lt;p&gt;Only use genuine Google chargers and charging cables that you have purchased yourself, ideally in-person with cash. Do not use friend&#39;s, family&#39;s, or borrow stranger&#39;s chargers or charging cables. Do not use third-party chargers or charging cables. Do not let anyone else use your chargers or charging cables. &lt;a rel=&quot;external&quot; href=&quot;https://www.bitdefender.com/blog/hotforsecurity/youtuber-demonstrates-fake-charging-cable-that-can-hack-your-computer/&quot;&gt;Read more here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Please note that the Pixel Tablet &lt;em&gt;does not&lt;/em&gt; come with a USB-C charger in the box. Because Google wants people to use this as a &quot;connected home&quot; device, there&#39;s a speaker stand that comes included with the tablet, and the charging cable is a proprietary barrel plug that is only for the speaker/charging stand.&lt;/p&gt;
&lt;h1 id=&quot;device-purchase-strategies&quot;&gt;Device Purchase Strategies&lt;/h1&gt;
&lt;p&gt;Again, this largely depends on your threat model.&lt;/p&gt;
&lt;p&gt;In my case, for fun, I asked a friend to drive me to the store in their car. The benefits of this is that automatic license plate readers (ALPRs) will not observe me moving through public streets. I asked them to drive me to a different city, one that I&#39;ve never spent any time in before, but one that has a Best Buy. I brought $550 USD to a Best Buy.&lt;/p&gt;
&lt;p&gt;After the purchase, since we were already in a city that I&#39;d spent no time in before, we went to a small cafe with free internet. Not a Starbucks. Starbucks has a huge global surveillance network of wireless access points that all centrally log devices and user activity. I unboxed the Pixel Tablet in my friend&#39;s car then used the cafe&#39;s wifi to connect to the internet for the setup process.&lt;/p&gt;
&lt;h1 id=&quot;device-setup-directions&quot;&gt;Device Setup Directions&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;Powered on, clicked Get Started&lt;/li&gt;
&lt;li&gt;Set up offline then continue&lt;/li&gt;
&lt;li&gt;Set the time&lt;/li&gt;
&lt;li&gt;Disable location&lt;/li&gt;
&lt;li&gt;Disable diagnostic data&lt;/li&gt;
&lt;li&gt;Set a simple PIN&lt;/li&gt;
&lt;li&gt;Opt-out of setting up biometric authentication&lt;/li&gt;
&lt;li&gt;Settings &amp;gt; System &amp;gt; System Update&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This is a necessary step in order to install the most up to date device firmware. My device had a March 2023 patch level (11 months old). The update on my Pixel Tablet took roughly 30 to 45 minutes.&lt;/p&gt;
&lt;ol start=&quot;9&quot;&gt;
&lt;li&gt;Reboot&lt;/li&gt;
&lt;li&gt;Settings &amp;gt; About Tablet &amp;gt; Tap “Build Number” 9 times to unlock Developer Mode&lt;/li&gt;
&lt;li&gt;Settings &amp;gt; System &amp;gt; Developer Options &amp;gt; Enable USB Debugging&lt;/li&gt;
&lt;li&gt;Settings &amp;gt; System &amp;gt; Developer Options &amp;gt; Enable OEM Unlocking&lt;/li&gt;
&lt;li&gt;Enable the tablet’s Airplane Mode&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I then had my friend drive me home.&lt;/p&gt;
&lt;p&gt;From a personal laptop, Go home, follow setup directions from &lt;a rel=&quot;external&quot; href=&quot;https://calyxos.org/&quot;&gt;calyxos.org&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/welcome-to-calyxos.jpeg&quot; alt=&quot;Alt Text: the CalyxOS setup screen&quot; /&gt;&lt;/p&gt;
&lt;p&gt;After CalyxOS is installed:&lt;/p&gt;
&lt;ol start=&quot;13&quot;&gt;
&lt;li&gt;Connect to WiFi (unless you have stalkers, read DEFCON ONE at the bottom of the guide first!)&lt;/li&gt;
&lt;li&gt;Disable Google Services Compatibility&lt;/li&gt;
&lt;li&gt;Uncheck all of the optional apps except for: OnionShare, Orbot, Signal, and Tor Browser for Android&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;/images/setup-app-installer.jpeg&quot; alt=&quot;Alt Text: the CalyxOS setup app installer screen&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Click Install. All done!&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/homescreen.png&quot; alt=&quot;Alt Text: the CalyxOS home screen&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I added a couple of shortcuts to the homescreen and changed the wallapaper to a different one preinstalled on the device, just for fun.&lt;/p&gt;
&lt;h2 id=&quot;setting-up-orbot&quot;&gt;Setting up Orbot&lt;/h2&gt;
&lt;p&gt;First, to protect network metadata:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Open up Orbot&lt;/li&gt;
&lt;li&gt;Click Connect&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;/images/orbot.png&quot; alt=&quot;Alt Text: Orbot&quot; /&gt;&lt;/p&gt;
&lt;ol start=&quot;3&quot;&gt;
&lt;li&gt;Go to Settings &amp;gt; Network &amp;amp; Settings &amp;gt; VPN &amp;gt; Orbot (settings, on the right) &amp;gt; Enable Always-on VPN and Enable Block connections without VPN&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;/images/vpn-settings.png&quot; alt=&quot;Alt Text: Android VPN settings&quot; /&gt;&lt;/p&gt;
&lt;p&gt;As a precaution, I used the pre-installed Chromium browser (not Tor Browser, intentionally) to check to see if Android (CalyxOS) is being torified by Orbot. I simply go to &lt;a rel=&quot;external&quot; href=&quot;https://check.torproject.org/&quot;&gt;check.torproject.org&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Note, this tablet should not be used for any other web browsing unless Javascript is competely disabled.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/check-tor.png&quot; alt=&quot;Alt Text: Checking if Tor routing is working in Chrmium&quot; /&gt;&lt;/p&gt;
&lt;h2 id=&quot;setting-up-signal&quot;&gt;Setting up Signal&lt;/h2&gt;
&lt;p&gt;There are lots of choicees to be made here. What&#39;s most important when choosing a Signal number is that you have long-term, secure control of the phone number, or trust the person or organization managing the phone number. Choosing the right method really depends on your threat model and your goals for your publicity or anonymity.&lt;/p&gt;
&lt;p&gt;Journalists, lawyers, and other professionals might have an already-public phone number given to them from their employer. You can use that phone number in Signal on this device, and on this device only.&lt;/p&gt;
&lt;p&gt;Americans can leverage Google Voice. Digital phone number serices might be a good solution for a Signal phone number, but only if access and control of that phone number is legitimately secure. Google Voice, for example, leverages the same nation-state defences that Gmail accounts use. Two-factor authentication must be used to access these services. Americans with access to Google Voice can also pay Google $20 to transfer in a phone number to Google Voice, and doing so will make it a permanent number on your Google account and will not get purged due to lack of activity.&lt;/p&gt;
&lt;p&gt;You can request that a friend or family member add a new phone number to their cellular provider&#39;s plan. Activate the phone number on an old cell phone and get the Signal registration SMS, then destroy that phone and SIM card, and remember &lt;a rel=&quot;external&quot; href=&quot;https://www.schneier.com/blog/archives/2015/04/cell_phone_opse.html&quot;&gt;anchor points&lt;/a&gt; (dont activate the phone number and use cellular services in places where you regularly go).&lt;/p&gt;
&lt;h2 id=&quot;notes-on-the-use-of-the-contacts-calendars-and-notes-apps&quot;&gt;Notes on the use of the Contacts, Calendars, and Notes apps&lt;/h2&gt;
&lt;p&gt;You have two choices when it comes to managing your contacts list, calendars, and notes data. There are many pros and cons with these two options and will depend on your threat model, so please think very carefully about your operational security practices.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Offline data: Since you can&#39;t sign into a Google account on this CalyxOS device, you cannot risk disclosing your contacts, calendars, and notes data to Google or your local government willingly (if your government has forced Google to host your data in your country instead of, or in addition to, the USA). This means it is relatively safe to use the on-device Contacts, Calendar, and Notes apps, depending on your threat model. Using CalyxOS&#39;s Contacts app is seamless since you can safely grant Signal access to contacts, if it asks.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;You have to trust Signal to continue to implement trustworthy cryptographic security mechanisms that continue to prevent themselves from ever having cleartext access to your contacts. This risk is low, since you are already trusting Signal with the confidentiality and integrity of the content of your communications and whom you communicate with via Signal. This risk is also low because Signal does not have any financial motivation to collect your contacts in any way. In fact, data storage is expensive, and responding to government requests for users data is expensive, so it is cheaper for Signal to never have this data.&lt;/li&gt;
&lt;li&gt;WIP &lt;del&gt;Android-native apps are the default places to look for this data if you ever are stopped and searched by government or private security agents. If this risk applies to you, store your data in a trustworthy offline password manager that supports a &quot;key file&quot; like &lt;a rel=&quot;external&quot; href=&quot;https://apps.apple.com/us/app/strongbox-keepass-pwsafe/id897283731&quot;&gt;Strongbox&lt;/a&gt;. Strongbox is like KeypassXC but for iOS, where the database is encrypted in addition to iOS disk encryption, but you can use a key file to make bruteforcing of this database impossible. Keep your key file online somewhere so you can remotely download it when you need access to your Strongbox database contents. Like your passphrase to the database, the key file should never be shared.&lt;/del&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Online data: If you are technically savvy, or have access to trustworthy technical friends or coworkers, you can self host your contacts, calendars, and notes. I use Mail-in-a-Box to self host these things, but there are many open source, self-host solutions out there.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Since data is remotely available, you can easily wipe your phone when crossing security check points, including regional borders like at airports, and re-setup your device and re-download your data from anywhere in the world after you have safely cross these types of high-risk areas.&lt;/li&gt;
&lt;li&gt;Since data is remotely available, it may be possible for your adversaries to know of the existence of where your data is stored online. In my example of using Mail-in-a-Box, this setup requires a public domain name that is registered to my name. Government and private entities can buy full access to domain registry data. Online storage is a risk for remote exploitation by way of illegal or legal (government warrant) means.&lt;/li&gt;
&lt;li&gt;Running your own Tor hidden service, like from a Raspberry Pi hosted in a secure location, means that you can use Tor Browser to safely and privately access or download remote data.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h1 id=&quot;defcon-one-configuration&quot;&gt;DEFCON ONE configuration&lt;/h1&gt;
&lt;h2 id=&quot;why-defcon-one-might-be-critical-for-you&quot;&gt;Why DEFCON ONE might be critical for you&lt;/h2&gt;
&lt;p&gt;Are you worried about, or have you ever experienced, attackers physically stalking, harassing, or assaulting you? If the answer is yes, then you have a high risk of those same abusers conducting wireless attacks against your wireless devices.&lt;/p&gt;
&lt;p&gt;Wireless (Wi-Fi or Bluetooth) attacks are &quot;physical&quot; attacks since they have to physically capture the electromagnetic waves passing though the air near you. They may aim to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Capture your wireless packets in order to conduct surveillance. Your abusers might be trying to determine:
&lt;ul&gt;
&lt;li&gt;Are you nearby?&lt;/li&gt;
&lt;li&gt;When are you online and active?&lt;/li&gt;
&lt;li&gt;How long are your conversations?&lt;/li&gt;
&lt;li&gt;How often do you have conversations?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Capture your wireless packets in order to attempt to hack the security vulnerabilities in wireless protocols. Your abusers might be trying to determine:
&lt;ul&gt;
&lt;li&gt;What type of device are you using?&lt;/li&gt;
&lt;li&gt;What methods are you using in order to communicate with others?&lt;/li&gt;
&lt;li&gt;Are there any vulnerabilities that could be taken advantage of?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;DoS (Denial of Service) your device to prevent you from being able to communicate.&lt;/li&gt;
&lt;li&gt;Hack the wireless protocols allowing active surveillance of wireless transmissions or to hack the device through protocol, driver, or operating system vulnerabilities. Your abusers might be trying to determine:
&lt;ul&gt;
&lt;li&gt;What apps are you using?&lt;/li&gt;
&lt;li&gt;Do those apps have any vulnerabilities?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Hack the wireless device directly through unknown or unpatched vulnerabilities in the wireless service, driver, and/or operating system. Your abusers might be trying to:
&lt;ul&gt;
&lt;li&gt;Have complete access to your device, including apps like Signal.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;defcon-one-setup-directions&quot;&gt;DEFCON ONE setup directions&lt;/h2&gt;
&lt;p&gt;Perform these steps after installing CalyxOS, but booting CalysOS, and especially before enabling internet connectivity in CalyxOS.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Use a network router at your home or office that allows the use of wired ethernet.&lt;/li&gt;
&lt;li&gt;Use a USB-C to gigabit ethernet adapter to connect the Pixel Tablet to the router via wired eithernet cable.&lt;/li&gt;
&lt;li&gt;Before booting CalyxOS (when you have not configured any wireless network) connect the ethernet adapter to the CalysOX-installed tablet.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;CalyxOS should automatically default to the wired connection. However, wired success may depend on the ethernet adapter. When I tried this on my tablet, my Belkin adapter, which was made for Apple devices, did not work. I&#39;ll order one for Android and verify this works soon(TM).&lt;/p&gt;
&lt;h2 id=&quot;notes-on-defcon-one-configuration&quot;&gt;Notes on DEFCON ONE configuration&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;An ethernet adapter does not support USB-C charging. You will not be able to leave the tablet with an always-on internet connection, but that is not necessarily a bad thing. You might, instead, purchase an adapter that supports both wired ethernet and a USB-C power cable port.&lt;/li&gt;
&lt;li&gt;Assure that Airplane Mode is enabled immediately after setting up the tablet for the first time. Assure that Airplane Mode is always enabled, presuming wired ethernet will work in this configuration. Assure that you never connect to any Wi-Fi access point, ever, so that if Airplane Mode ever becomes disabled accidentally, it will not broadcast any Wi-Fi connect packets with a real MAC address.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;yawnbox&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Sailing Zapdos</title>
        <published>2023-07-31T00:00:00+00:00</published>
        <updated>2023-07-31T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/sailing-zapdos/"/>
        <id>https://yawnbox.eu/blog/sailing-zapdos/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/sailing-zapdos/">&lt;p&gt;I’m a novice sailor. I took my first sailing class with the Seattle Mountaineers in April 2023. Zapdos is my sailboat. I bought Zapdos in May 2023 near Vancouver Island, British Columbia (BC), Canada and started refitting it in July 2023. Zapdos is a 1985(?) Bruce Robert’s design steel-hull sailboat. No one knows exactly when or where it was made or what model it is. Zapdos didn’t even have an HIN! I named it Zapdos because I am converting it from diesel to electric; since its primary propulsion is wind and its secondary propulsion is electricity, I felt I must use a childhood icon to name it.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/zapdos_hull.jpeg&quot; alt=&quot;Zapdos&quot; /&gt;&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Defending the (Mastodon) User</title>
        <published>2023-02-07T00:00:00+00:00</published>
        <updated>2023-02-07T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/defending-the-mastodon-user/"/>
        <id>https://yawnbox.eu/blog/defending-the-mastodon-user/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/defending-the-mastodon-user/">&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;In this article, I’m going to discuss some ways in which users can potentially take back some power when using (self-hosting) federated social networks such as Mastodon. These ideas might best help activists, journalists, or hackers publishing stuff.&lt;/p&gt;
&lt;p&gt;I am not a lawyer. I’ve talked to a lot of them, but these ideas should be thought about carefully with your lawyer. All of this is based on my first-hand experiences operating Emerald Onion (in the United States), but most ideas are adaptable, so keep an open mind.&lt;/p&gt;
&lt;h1 id=&quot;control-systems&quot;&gt;Control Systems&lt;/h1&gt;
&lt;p&gt;I can&#39;t be as specific as I’d like to in this first section because I’m being censored from my own government not to. On a date after May 2019 (after Emerald Onion published its first update to its &lt;a rel=&quot;external&quot; href=&quot;https://emeraldonion.org/transparency/&quot;&gt;Transparency Report&lt;/a&gt;), but before November 2022 (before Emerald Onion published its most recent report), Emerald Onion was served a grand jury subpoena for user data along with our first gag order.&lt;/p&gt;
&lt;p&gt;It doesn’t matter that Emerald Onion publishes [censored]. It doesn’t matter that well-informed government agencies should know that Tor [censored]. I am being prevented from using my First Amendment rights simply because a law enforcement agency has a process, and I am now part of it.&lt;/p&gt;
&lt;p&gt;One of the issues defending anonymity on the internet is that it is built upon surveillance systems and control systems. The fediverse, be it ActivityPub-based like Mastodon, allows users to have more control, but it doesn&#39;t mean they have total control. If it hasn&#39;t happened already, a Mastodon admin is going to be served a subpoena or warrant of some kind and they are required to respond. So how do you prepare for that next act?&lt;/p&gt;
&lt;p&gt;You must use public control systems for your defensive advantage. For years leading up to Emerald Onion’s founding, and to this day, I think about ways in which Emerald Onion could be structured to best defend the user. It’s one reason why we’re a public charity, why we have our own IP addresses that aren’t leased from an ISP, and why we have a Transparency Report.&lt;/p&gt;
&lt;p&gt;Operating a social network is not a trival task. Adversaries come in all shapes and sizes, it&#39;s not all going to come from the government. Private entities have lawyers. Please understand &lt;a rel=&quot;external&quot; href=&quot;https://www.eff.org/deeplinks/2022/12/user-generated-content-and-fediverse-legal-primer&quot;&gt;User Generated Content and the Fediverse: A Legal Primer&lt;/a&gt;.&lt;/p&gt;
&lt;h1 id=&quot;defend-the-user&quot;&gt;Defend the User&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Form a corporation. Does it need to be a federally-recognized 501(c)(3)? No, but there are benefits to that. You need liability mitigations. You need business insurances. You need legal and operational structure within the State in which you operate. You must be transparent and honest within your own government systems for what you’re doing (supporting public-benefit social networks). You need a business bank account and a budget.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Your organizational and legal structure needs to be preemptively made in a way that decision makers must all be informed of legitimate legal demands.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;For example: Emerald Onion is a Washington state nonprofit corporation. Washington requires at least three directors. We made those same directors the Board of Directors to stay lean. We’re a “flat” organization where one person gets one vote on major decisions. The Board of Directors must be all informed, along with our legal counsel, about legal demands. That’s written into the Articles of Incorporation with the State. That’s what a small corporation that doesn’t have its own legal department must do. So, use it against the system. As painful as it might become, every user of your small Mastodon instance needs to be a legal decision maker for the corporation because then it’s required (by law) that they are informed of all legal demands that are mailed or emailed to the organization. This way, no one user of your Mastodon instance can be subject to secret data sharing or surveillance.&lt;/p&gt;
&lt;p&gt;Does that mean, when this organization receives a legal demand, that a user should delete user data? Absolutely not, that would be illegal. You need to do exactly what the legitimate legal demand is. This preemptive structuring is important because it empowers the user, as part of the organization, to respond with the help of a lawyer. It will help the targeted user be supported in meaningful ways, especially emotional.&lt;/p&gt;
&lt;p&gt;yawnbox&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Buying a Home with Physical Location Privacy</title>
        <published>2022-09-10T00:00:00+00:00</published>
        <updated>2022-09-10T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/buying-a-home-with-physical-location-privacy/"/>
        <id>https://yawnbox.eu/blog/buying-a-home-with-physical-location-privacy/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/buying-a-home-with-physical-location-privacy/">&lt;p&gt;Buying a home in the United States, by default, means that your name and the address of your home will become public information. Data brokers unethically scrape this information and combine it with digital data harvesting. Law Enforcement organizations use it. Stalkers use it.&lt;/p&gt;
&lt;p&gt;This is considerably problematic for people in witness protection programs, or domestic violence survivors. In Washington state, these people can be a part of the &lt;a rel=&quot;external&quot; href=&quot;https://www.sos.wa.gov/acp/&quot;&gt;Washington State Address Confidentiality Program&lt;/a&gt;. The ACP program does nothing for people who are or want to become home owners.&lt;/p&gt;
&lt;p&gt;After speaking to a Washington state attorney about this problem, this is a plan that might work for you. One big problem is that not all home loan lenders will support it, so it might be important for you to find one that does.&lt;/p&gt;
&lt;p&gt;The ultimate goal here is to &quot;close&quot; on the purchase of a property in a fashion where your name would not appear on any recorded documents.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Law office prepare a revocable living trust consistent with Bank/Credit Union/Lender requirements;&lt;/li&gt;
&lt;li&gt;The trustee of the trust is a LLC to avoid your being named on the deed;&lt;/li&gt;
&lt;li&gt;The borrowers on the note are the trust and you individually; and&lt;/li&gt;
&lt;li&gt;The grantor of the deed of trust would be the trust.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Under this approach, you would remain personally liable for the monies and the trust would be the title holder.&lt;/p&gt;
&lt;p&gt;This approach is contrary to the requirement that the trustee of the trust be the borrower. However, you would remain personally liable for the amount owed under the note. The sole purpose of the LLC would be to sign for the trust in order to avoid your name appearing on recorded documents.&lt;/p&gt;
&lt;p&gt;One benefit of being in the Washington State ACP is that you can file an LLC using your Secretary of State provided PO BOX. It&#39;s not a perfect solution since one could simply look up the LLC and see who the owners are. One solution to this problem might be working with your attorney for their law office to be the legal owner of the LLC on your behalf.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Operational Security (opsec) Anchor Points</title>
        <published>2022-09-10T00:00:00+00:00</published>
        <updated>2022-09-10T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/opsec-anchor-points/"/>
        <id>https://yawnbox.eu/blog/opsec-anchor-points/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/opsec-anchor-points/">&lt;p&gt;I first learned about &quot;anchor points&quot; from Bruce Schneier. In this article I am going to establish some different types of anchor points since not all anchor points are the same when thinking about security or privacy risks.&lt;/p&gt;
&lt;h2 id=&quot;anchor-point-operational-security&quot;&gt;Anchor Point (operational security)&lt;/h2&gt;
&lt;p&gt;A basis for operation.&lt;/p&gt;
&lt;h3 id=&quot;anchor-point-type-1-static-locations&quot;&gt;Anchor Point, Type 1: Static Locations&lt;/h3&gt;
&lt;p&gt;Any physical or digital space that you regularly frequent, wether or not you are using digital communications. Your home, office, vehicle, coffee shops, grocery stores, retail malls, and restaurants are all examples of static location anchor points.&lt;/p&gt;
&lt;h3 id=&quot;anchor-point-type-2-static-paths&quot;&gt;Anchor Point, Type 2: Static Paths&lt;/h3&gt;
&lt;p&gt;A route or path that you commonly use to travel. Examples include a road to your home or office. Static paths also include mobility services that you commonly use for transportation. Examples include airports, specific airlines that you repeatedly use, or car-sharing services.&lt;/p&gt;
&lt;h3 id=&quot;anchor-point-type-3-static-relationships&quot;&gt;Anchor Point, Type 3: Static Relationships&lt;/h3&gt;
&lt;p&gt;A person or group of people whom you regularly visit, no matter where you are. Consider the NSA&#39;s &lt;a rel=&quot;external&quot; href=&quot;https://archive.org/details/nsa-cotraveler/mode/2up&quot;&gt;Co-Traveler Analytics program&lt;/a&gt;, or any technologically sophisticated government program that uses cell phone location data to unethically track relationships. A group of people does not necessarily need to be static, it could be different people from the same organization.&lt;/p&gt;
&lt;h2 id=&quot;anchor-point-type-combinations&quot;&gt;Anchor Point Type Combinations&lt;/h2&gt;
&lt;p&gt;Anchor Point types can be combined and carry compounding risks. Sitting in your car is a Type 1 Anchor Point. Driving your car between home and work is both Type 1 and 2. If you are driving your parent, sibling, or friend to a place where you regularly spend time together, this combines all three types of anchor points.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>IRCspy.com</title>
        <published>2018-11-10T00:00:00+00:00</published>
        <updated>2018-11-10T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/ircspy-com/"/>
        <id>https://yawnbox.eu/blog/ircspy-com/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/ircspy-com/">&lt;p&gt;IRCspy.com launched in February 2003.&lt;/p&gt;
&lt;center&gt;
    &lt;img src=&quot;/images/ircspy-welcome.png&quot; alt=&quot;launch by xanthus&quot;&gt;
&lt;/center&gt;
&lt;p&gt;The IRCspy forums (forums.ircspy.com) launched around November 2003, but it&#39;s not clear based on Wayback Machine snapshots.&lt;/p&gt;
&lt;center&gt;
    &lt;img src=&quot;/images/ircspy-forum-start.png&quot; alt=&quot;ircspy.com forum beginnings&quot;&gt;
&lt;/center&gt;
&lt;p&gt;It was this forum that I spent a lot of time in as a kid, passionately debating with folks in the &quot;serious debate&quot; general chat.&lt;/p&gt;
&lt;center&gt;
    &lt;img src=&quot;/images/ircspy-yawnbox.png&quot; alt=&quot;ircspy forums yawnbox activity&quot;&gt;
&lt;/center&gt;
&lt;p&gt;When IRCspy.com got shut down in November 2005, I was devestated that I would be losing access to my online community.&lt;/p&gt;
&lt;center&gt;
    &lt;img src=&quot;/images/goodbye-ircspy.png&quot; alt=&quot;goodbye from forcefire&quot;&gt;
&lt;/center&gt;
&lt;p&gt;The IRCspy forums eventually rebranded as the TorrentSpy Forums and stayed online until at least June 2007.&lt;/p&gt;
&lt;center&gt;
    &lt;img src=&quot;/images/ircspy-torrentspy-logo.gif&quot; alt=&quot;ircspy and torrentspy forums rebrand&quot;&gt;
&lt;/center&gt;
&lt;p&gt;For years I tracked the WHOIS data of IRCspy.com to see if the new owner would either not renew the domain, or auction it off. It finally went to auction in November 2018; I was determined to win, to keep this small piece of internet history from being abused further.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/winning-ircspy.png&quot; alt=&quot;winning ircspy.com from godaddy auctions&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I haven&#39;t decided if I am going to create a simple HTML/CSS memorial, or, use the domain for something else. I&#39;ve been thinking about making it a Mastodon server. I wish I had friends from the original forum to reach an agreement on how to use it.&lt;/p&gt;
&lt;p&gt;More to come!
&lt;br&gt;
&lt;br&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Emerald Onion has Launched</title>
        <published>2017-09-07T00:00:00+00:00</published>
        <updated>2017-09-07T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/emerald-onion-has-launched/"/>
        <id>https://yawnbox.eu/blog/emerald-onion-has-launched/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/emerald-onion-has-launched/">&lt;p&gt;The Tor network and the dot-Onion infrastructure was built for security and privacy in mind. This is unlike legacy clear-net infrastructure, which over the years needs routine and dramatic security changes just to solve evolving security chalenges. Even worse, modern security for legacy clear-net infrastructure does very little for privacy.&lt;/p&gt;
&lt;p&gt;Vulnerable populations were the first to recognize the importance of a technology like “the onion router”. The United States Navy was among the first. The United States Navy, realizing very quickly that an anonymity network that only the Navy would use, means that any of its users is from the United States Navy. To this day, the United States Navy researches and develops Tor.&lt;/p&gt;
&lt;p&gt;Once Tor became a public, free, and open source project, journalists and other vulnerable populations with life-and-death threat models started using Tor. These survivors and human-rights defenders were a red flag. By the time Tor became a public project, other departments from the United States Government, such as the United States National Security Agency, had already started conducting global mass surveillance.&lt;/p&gt;
&lt;p&gt;The United States Navy knew and continues to know that Tor is a necessity in a world dominated by global mass surveillance and by governments that strive for power and control.&lt;/p&gt;
&lt;p&gt;Emerald Onion envisions a world where access and privacy are the defaults. This is necessary to ensure human rights including access to information and freedom of speech. If we do not have human rights online, we will not have them offline, either. We launched, officially, on July 2nd. We are looking at 10 year+ development and sustainability. Please reach out to me if you can think of ways to support our work.&lt;/p&gt;
&lt;p&gt;yawnbox&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>House Bill 1909, Automatic License Plate Reader Systems</title>
        <published>2017-02-20T00:00:00+00:00</published>
        <updated>2017-02-20T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/house-bill-1909-automatic-license-plate-reader-systems/"/>
        <id>https://yawnbox.eu/blog/house-bill-1909-automatic-license-plate-reader-systems/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/house-bill-1909-automatic-license-plate-reader-systems/">&lt;p&gt;My testimony to the State of Washington House Transportation Committee:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Chair Clibborn and members of the committee, my name is Christopher Sheats, Chair of the Privacy Committee for Seattle’s Community Technology Advisory Board, and Chair of the Seattle Privacy Coalition. I want to make clear that any form of Automatic License Plate Reader (ALPR), regardless of its security or policy controls, is fundamentally a mass-surveillance system for the simple fact that it indiscriminately collects data about everyone.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;ALPR mass-surveillance systems collect an incredible amount of personal information.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Where are you and where are you not?&lt;/em&gt;
&lt;em&gt;Where are you heading?&lt;/em&gt;
&lt;em&gt;What time were you there and not anywhere else?&lt;/em&gt;
&lt;em&gt;Who else was traveling or not traveling around that time?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;All of these personal facts can facilitate identifying our interests, affiliations, activities, and beliefs. Data collection, and any amount of data retention, allows for the copying and sharing of said data. According to the U.S. Department of Transportation Bureau of Transportation Statistics, an “overwhelming majority of person trips—for all purposes—are taken in personal vehicles.” When mass-surveillance data of our vehicles is collected, granularly surveilling a state, a city, a community, or an individual becomes trivial.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Where do they live?&lt;/em&gt;
&lt;em&gt;Who lives around them?&lt;/em&gt;
&lt;em&gt;Where do they go to church?&lt;/em&gt;
&lt;em&gt;Who else goes to their church?&lt;/em&gt;
&lt;em&gt;Where do they work?&lt;/em&gt;
&lt;em&gt;When do they visit their friends and family?&lt;/em&gt;
&lt;em&gt;When do they drop their children off at school or childcare?&lt;/em&gt;
&lt;em&gt;When do they leave the house to go grocery shopping?&lt;/em&gt;
&lt;em&gt;When do they visit their doctor and how often?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Answering these questions go above and beyond “personal information,” yet these questions become answerable when data collected by an ALRP mass-surveillance system is gathered by an abusive government or hacker, domestic or foreign.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;If the State is to condone APRL mass-surveillance systems, whereby we have precluded we will not protect human rights by not collecting personal data in the first place, the only other rational alternative is to not retain collected data for any period longer than absolutely needed.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Thank you for your time.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Concerns of mine that I did not include in my testimony because of the delicate nature of politics:&lt;/p&gt;
&lt;p&gt;Regarding House Bill 1909, I have several concerns:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;How is House Bill 1909 going to impact RCW 40.24 — Address Confidentiality for Victims of Domestic Violence, Sexual Assault, and Stalking? Particularly, how is House Bill 1909 going to protect vulnerable people from law enforcement abuses?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Is any part of the ALPR mass-surveillance system, including data retention, managed or operated by unregulated third party providers?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Why are third parties not explicitly barred from owning and operating ALRP mass-surveillance systems?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;What specific controls and audit safeguards will be put in place to prevent system operators from performing unapproved searches of people or vehicles?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Once data is collected by mass-surveillance systems, it can be copied, used, copied again, and re-used for unimaginable purposes. What specific controls and audit safeguards will be put in place to prevent data copying by federal agency data systems such as regional Fusion Centers?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The “Second War Powers Act of 1942” removed Census privacy protections of Japanese-Americans, allowing federal agents to know exactly where go and whom to arrest. How is Washington State going to defend us from unconstitutional policy changes brought on by an illegitimate U.S. President?&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Privacy Proposal for Debian</title>
        <published>2016-05-03T00:00:00+00:00</published>
        <updated>2016-05-03T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/privacy-proposal-for-debian/"/>
        <id>https://yawnbox.eu/blog/privacy-proposal-for-debian/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/privacy-proposal-for-debian/">&lt;h2 id=&quot;objectives&quot;&gt;Objectives:&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The Debian community must immediately deploy Onion Service repositories for Debian downloads and Debian updates.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Debian community must immediately deploy TLS-only repositories for Debian downloads and Debian updates as a backup to Onion Services.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Debian community must assure anonymity-by-default with the employment of apt-transport-tor by changing existing update mechanics.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Debian community must deploy a critical security update to patch existing update mechanics to use Onion Services.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;summary&quot;&gt;Summary:&lt;/h2&gt;
&lt;p&gt;Current and future network adversaries can view and retain which repositories Debian servers connect to (metadata), when (metadata), the updates schedule (information), which updates are being applied (information), and into which operating system (information). This is incredibly valuable information for any adversary wanting to perform minimal attacks against Debian servers. Further, with cheapening data retention, mass-hacking and nation-state dominance is supported by the Debian community’s short-sighted update mechanics.&lt;/p&gt;
&lt;p&gt;Edward Snowden has given the world factual evidence describing the capabilities and objectives of global powers and the Debian community has willfully neglected these problems.&lt;/p&gt;
&lt;h2 id=&quot;arguments&quot;&gt;Arguments:&lt;/h2&gt;
&lt;p&gt;Report of the Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression, David Kaye — Presented to the Human Rights Council in May 2015:&lt;/p&gt;
&lt;p&gt;(2)(A)(9) “Notably, encryption protects the content of communications but not identifying factors such as the Internet Protocol (IP) address, known as metadata. Third parties may gather significant information concerning an individual’s identity through metadata analysis if the user does not employ anonymity tools. Anonymity is the condition of avoiding identification. A common human desire to protect one’s identity from the crowd, anonymity may liberate a user to explore and impart ideas and opinions more than she would using her actual identity. […] Users seeking to ensure full anonymity or mask their identity (such as hiding the original IP address) against State or criminal intrusion may use tools such as virtual private networks (VPNs), proxy services, anonymizing networks and software, and peer-to-peer networks.1 One well-known anonymity tool, the Tor network, deploys more than 6,000 decentralized computer servers around the world to receive and relay data multiple times so as to hide identifying information about the end points, creating strong anonymity for its users.”&lt;/p&gt;
&lt;p&gt;Debian powers more than one-third of the Internet. The default behavior of Debian is to obtain updates via clear-text HTTP which discloses the following to any network adversary:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Server location via IP address&lt;/li&gt;
&lt;li&gt;Update server via IP address and DNS resolution&lt;/li&gt;
&lt;li&gt;Server update schedule&lt;/li&gt;
&lt;li&gt;Server version&lt;/li&gt;
&lt;li&gt;Application version&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This information, via network analysis, would allow any passive or active adversary to plan effective attacks against any Debian server.&lt;/p&gt;
&lt;p&gt;Not all adversaries are the same because not all servers have the same risk. Like people, data mining and data retention capabilities pose grave risks for infrastructure. HTTPS may resolve some of the above information leakage depending on an adversary’s capabilities, but Tor resolves them to a greater degree. Anonymity provides the strongest security and is the only acceptably secure option given the facts.&lt;/p&gt;
&lt;p&gt;XKEYSCORE, a FVEY technology, is one example of a modern threat to Internet infrastructure. Via Wikipedia:&lt;/p&gt;
&lt;p&gt;On January 26, 2014, the German broadcaster Norddeutscher Rundfunk asked Edward Snowden in its TV interview: “What could you do if you would [sic] use XKeyscore?” and he answered:&lt;/p&gt;
&lt;p&gt;“You could read anyone’s email in the world, anybody you’ve got an email address for. Any website: You can watch traffic to and from it. Any computer that an individual sits at: You can watch it. Any laptop that you’re tracking: you can follow it as it moves from place to place throughout the world. It’s a one-stop-shop for access to the NSA’s information.&lt;/p&gt;
&lt;p&gt;You can tag individuals… Let’s say you work at a major German corporation and I want access to that network, I can track your username on a website on a form somewhere, I can track your real name, I can track associations with your friends and I can build what’s called a fingerprint, which is network activity unique to you, which means anywhere you go in the world, anywhere you try to sort of hide your online presence, your identity.”&lt;/p&gt;
&lt;p&gt;The question posed to Edward Snowden was rightly focused on people. However, an XKEYSCORE-like system can trivially threaten any node on the Internet. If XKEYSCORE-like systems can be programmed to track nations, servers, or application installations, the Debian community must act.&lt;/p&gt;
&lt;h2 id=&quot;scenarios&quot;&gt;Scenarios:&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Debian server &amp;gt; https://update-server.onion&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In scenario 1, operating system and application updates are obtained exclusively within the Tor network with an added layer of Certificate Authority validation ability. HTTP-based Certificate Authority, Domain Name System, and Border Gateway Protocol vulnerabilities do not exist.&lt;/p&gt;
&lt;ol start=&quot;2&quot;&gt;
&lt;li&gt;Debian server &amp;gt; http://update-server.onion&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In scenario 2, operating system and application updates are obtained exclusively within the Tor network. HTTP-based Certificate Authority, Domain Name System, and Border Gateway Protocol vulnerabilities do not exist.&lt;/p&gt;
&lt;ol start=&quot;3&quot;&gt;
&lt;li&gt;Debian server &amp;gt; tor+https://update-server.org&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In scenario 3, operating system and application updates are obtained via Tor but must leave the Tor network to reach its HTTPS destination. All HTTP-based Certificate Authority, Domain Name System, Border Gateway Protocol, and Man-in-the-Middle vulnerabilities exist once the traffic traverses Tor exit relays onto the normal Internet. Debian servers retain anonymity but security risk is increased.&lt;/p&gt;
&lt;ol start=&quot;4&quot;&gt;
&lt;li&gt;Debian server &amp;gt; tor+http://update-server.org&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In scenario 4, operating system and application updates are obtained via Tor but must leave the Tor network to reach its HTTP destination. All HTTP-based Domain Name System, Border Gateway Protocol, and Man-in-the-Middle vulnerabilities exist once the traffic traverses Tor exit relays onto the normal Internet. Debian server retain anonymity but security risk is increased.&lt;/p&gt;
&lt;ol start=&quot;5&quot;&gt;
&lt;li&gt;Debian server &amp;gt; https://update-server.org&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In scenario 5, operating system and application updates are obtained via normal Internet with minimal transport security. Server location information, update server information, and server update schedule information easily obtainable, and sophisticated attackers can obtain server version information and package version information. All HTTP-based Certificate Authority, Domain Name System, Border Gateway Protocol, and Man-in-the-Middle vulnerabilities exist.&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;Debian server &amp;gt; http://update-server.org&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In scenario 6, the current Debian default, operating system and application updates are obtained via normal Internet with zero transport security. Server location information, update server information, server update schedule information, server version information, and package version information are trivially obtainable. All HTTP-based Domain Name System, Border Gateway Protocol, and Man-in-the-Middle vulnerabilities exist.&lt;/p&gt;
&lt;p&gt;yawnbox&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>ACLU of Washington Encryption Evangelism Intern</title>
        <published>2015-09-28T00:00:00+00:00</published>
        <updated>2015-09-28T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/aclu-of-washington-intern/"/>
        <id>https://yawnbox.eu/blog/aclu-of-washington-intern/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/aclu-of-washington-intern/">&lt;p&gt;Day one :)&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/aclu-1.jpeg&quot; alt=&quot;1&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/aclu-2.jpeg&quot; alt=&quot;2&quot; /&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>ACLU-WA Encryption Evangelism Internship Proposal</title>
        <published>2015-09-01T00:00:00+00:00</published>
        <updated>2015-09-01T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/aclu-wa-internship-proposal/"/>
        <id>https://yawnbox.eu/blog/aclu-wa-internship-proposal/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/aclu-wa-internship-proposal/">&lt;h2 id=&quot;goal&quot;&gt;Goal&lt;/h2&gt;
&lt;p&gt;Further the use of FOSS encryption technologies within Washington legal and journalism circles.&lt;/p&gt;
&lt;h2 id=&quot;tor&quot;&gt;Tor&lt;/h2&gt;
&lt;p&gt;Tor relay and Tor exit relay adoption by organizations because of resources and stability. EFF “Tor Challenge” is unsuccessful at gaining long-term relays because they are focused on individuals that are largely not focused or lack stable resources. ACLU-WA support could happen in three ways: write to local organizations who are likely to
deploy a Tor relay, provide written education or in-person training, and create public reports on successes and failures. Supporting Tor supports human rights work 24/7/365, globally.&lt;/p&gt;
&lt;h2 id=&quot;https-and-starttls&quot;&gt;HTTPS and StartTLS&lt;/h2&gt;
&lt;p&gt;Many organizations who require privacy lack website/service transport security. Focusing on specific types of organizations, such as law firms and news agencies, would benefit the public and overall Internet health. HTTPS is critical for keeping private specific pages and forms visited in addition to any transmitted information. StartTLS is critical for keeping entire emails confidential. In light of recent developments in Texas [1], it would be timely to push Washington state legal policy organizations to adopt similar rules. The “Let’s Encrypt” project has been pushed out to November 16th, 2015 [2] — it would be great to have 2 months to start an ACLU-WA parallel initiative (focused on law firms and news agencies, for example) when it launches in order to benefit and enhance the initial press.&lt;/p&gt;
&lt;h2 id=&quot;textsecure-redphone-signal&quot;&gt;TextSecure, RedPhone, &amp;amp; Signal&lt;/h2&gt;
&lt;p&gt;While HTTPS and StartTLS are important for public and private communication, mobile apps can greatly strengthen inter-org privacy. Classic telephony and SMS communications are insecure. The Open Whisper Systems ecosystem uses state of the art encryption, is scalable, and is free and open source software. Purchasing 5th gen iPod Touch devices is a small cost for law firms and allows lawyers to register their work phone number with Signal. Doing so would let anyone with their regular work phone number to leverage end-to-end encryption instead. No wiretaps, no SS7 tracking, no IMSI catcher tracking, and no baseband or SIM card vulnerabilities that are inherent with any cellular device.&lt;/p&gt;
&lt;h2 id=&quot;securedrop&quot;&gt;SecureDrop&lt;/h2&gt;
&lt;p&gt;Whistleblowing is a critical part in a democracy by keeping the public informed and organizations accountable. SecureDrop, by Freedom Press Foundation, is a powerful tool that allows anyone to leak information to targeted organizations. SecureDrop has been around for 2 years and is largely used by news agencies. That being said, a very small fraction of news agencies support SecureDrop which creates two problems: overall diversity and market diversity. Overall, there are too few options in terms of trusted organizations for whistleblowers to choose from. If a specific person who has access to specific information is only comfortable providing information to a specific organization or person, but secure a whistleblowing platform does not exist, nothing will get leaked. Similarity, if only news agencies support secure
whistleblowing platforms, other NGOs who might be better equipped to handle response will not get leaks. ACLU-WA could work with Freedom Press Foundation to focus on evangelizing SecureDrop to NGOs.&lt;/p&gt;
&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;It is ethics and education apathy that is preventing people from adopting FOSS security systems that provide privacy. It is one thing to be apathetic in our personal lives, but it is not acceptable in professions that demand privacy in order to keep people safe.&lt;/p&gt;
&lt;p&gt;1 &lt;a rel=&quot;external&quot; href=&quot;http://ridethelightning.senseient.com/2015/07/when-must-lawyers-ethically-encrypt-data-texas-answers.html&quot;&gt;http://ridethelightning.senseient.com/2015/07/when-must-lawyers-ethically-encrypt-data-texas-answers.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2 &lt;a rel=&quot;external&quot; href=&quot;https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html&quot;&gt;https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html&lt;/a&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>On the nature of surveillance, self defense, and activism</title>
        <published>2015-01-19T00:00:00+00:00</published>
        <updated>2015-01-19T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/on-the-nature-of-surveillance/"/>
        <id>https://yawnbox.eu/blog/on-the-nature-of-surveillance/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/on-the-nature-of-surveillance/">&lt;p&gt;&lt;em&gt;Originally posted on &lt;a rel=&quot;external&quot; href=&quot;https://web.archive.org/web/20150122035519/https://www.seattleprivacy.org/on-the-nature-of-surveillance-self-defense-and-activism/&quot;&gt;SeattlePrivacy.org&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The Seattle Privacy Coalition instructed our first anonymous group of Seattleites who are victims of abusive surveillance or at risk of becoming a victim. Overwhelmingly, the students of our first workshop were women, even though everyone that attended ranged in age, background, race, nationality, ethnicity, and sexual-orientation. Despite their differences, their commonality was their genuine care for people — society — to such a degree that their non-violent actions are considered a threat to corporate and government power.&lt;/p&gt;
&lt;h2 id=&quot;the-concern&quot;&gt;The concern&lt;/h2&gt;
&lt;p&gt;Almost 226 years ago, our fundamental rights as Americans were ratified. Broad protections were guaranteed to us against search and seizure, something that we, as a society, now sometimes call privacy due to the large amount of our lives willingly and unwillingly propelled into digital spaces. Objection to intrusive search and seizure of physical objects has evolved into our ability to control personal information made harder by advancing and cheapening technology.&lt;/p&gt;
&lt;p&gt;Corporations, governments, and law enforcement agencies do not have a right to abuse people by way of deploying advanced technology. They may have the ability and privilege to do so, but that ability and privilege cannot and should not become a slippery slope to control people who are exercising their government-sponsored and government-protected right to protest perceived abuses of power. What is the significance of our constitutional protections unless we act, so that our rights become right and our values proven?&lt;/p&gt;
&lt;p&gt;Despite the stark ethical differences between rights and privileges, activists are readily harassed, stalked, physically abused, or murdered. Anyone guided by justifiability and morality can understand why we need to support this vulnerable population of people.&lt;/p&gt;
&lt;h2 id=&quot;the-workshop&quot;&gt;The workshop&lt;/h2&gt;
&lt;p&gt;In large part, surveillance self-defense is about technology and education. Similar to the practice of martial arts, self-defense is learned by empowering one’s self with knowledge and control over mind, body, and environment. Understanding technological threats and assets will help non-violent activists achieve their goals. To best achieve our objectives, we approached this training with the wisdom of a teacher and also the curiosity of a student. Everyone there had something to share and learn.&lt;/p&gt;
&lt;p&gt;Our students were not tech-savvy. Many of them had cell phones that were merely recommended to them by family members or casual friends. One of them had a Windows phone, something even our technologists didn’t know if it employs storage encryption. Even though only one person was the facilitator over the course of almost five hours of training, various Seattle Privacy Coalition co-educators were participants of the training and regularly contributed facts, metaphors, and applied real-time research.&lt;/p&gt;
&lt;p&gt;We started off by introducing the Seattle Privacy Coalition and notable facts about the organizers, like not being associated with law enforcement or intelligence services. A story was told to create some initial privacy empowerment and a statement about everyone’s right to identity-self-determination while  participating in the workshop.&lt;/p&gt;
&lt;p&gt;We started our curriculum by highlighting the cause of risk, which can be characterized by a balance between threat and vulnerability. Throughout the workshop, distinctions were made by attributing the specifics of scenarios to either a threat or a vulnerability to best appreciate any given risk.&lt;/p&gt;
&lt;p&gt;The first tool provided to our students was not software; it was an information resource, one regularly brought back into the dialogue. The Electronic Frontier Foundation‘s (EFF) online guide titled “Surveillance Self Defense” (SSD) was chosen to be our primary reference material. Their amazing and much needed work is where we got the name of our new program. We think that the EFF’s SSD should discuss the notion of a vulnerability, not just the notion of a threat when assessing risk regarding “An Introduction to Threat Modeling“.&lt;/p&gt;
&lt;p&gt;Another SSD concern was the need for a preemptive list of jargon in each article. As you might notice, one of the Seattle Privacy Coalition’s goals is to provide constructive feedback to the EFF from our experiences with our activist and journalist students.&lt;/p&gt;
&lt;p&gt;Graciously, one of our students enjoyed sharing the words of every acronym that we used to instruct with. It was a healthy reminder that our students need a lot of breakdown, which in effect, leads to a lot of segues. Seattle Privacy Coalition needs to include more subtle structure into our curriculum plans so not to spend as much time on segues. Segues created a condition where it became too easy for non-technologists to get lost. We regularly asked if everyone were comfortable with the previously discussed topic so people could easily ask questions.&lt;/p&gt;
&lt;p&gt;Other over-arching concepts included the differences between active and passive surveillance, and also the differences between transport encryption and encrypted storage. The Seattle Privacy Coalition needs to add a section disusing a basic concept of encryption in our upcoming workshops.&lt;/p&gt;
&lt;p&gt;The majority of our students were iOS and OS X users, which was slightly unfortunate since we don’t have any Apple users among the active Seattle Privacy Coalition volunteers. Creating power users out of Apple users was a clear challenge in our workshop, but we were able to educate on a few important self-defense tactics and operations.&lt;/p&gt;
&lt;p&gt;Regardless of the lack of Apple iOS and OS X experience, we were able to cover many outstanding encryption tools. We only instructed on the use of open source tools made by The Guardian Project, Open Whisper Systems, and The Tor Project . We limited our tools training to these developers because of their commitment to human rights, attention to usability, and their verifiable skills at employing strong encryption through careful software development.&lt;/p&gt;
&lt;p&gt;We covered topics like “data linkability” and applied its concept throughout the workshop. We covered notions of “metadata” and applied its concept throughout the workshop. We covered search and seizure laws and rights. We covered Washington state audio and video recording laws and responsibilities. We made sure every Android and iOS user had storage encryption enabled. We also discussed OTR advantages in light of the above chosen software tools.&lt;/p&gt;
&lt;p&gt;We spent a lot of time talking about cell phone communication encryption as a matter of risk deterrence. We did this by covering basic cellular network infrastructure and various vulnerabilities. Discussing SS7 vulnerabilities, baseband processor vulnerabilities, and IMSI-catcher threat detection was a primary knowledge area that we think is critically important for activists.&lt;/p&gt;
&lt;p&gt;With only five hours before everyone was completely wiped, we barely had enough time to cover the proper use of Tor. Regrettably, Tor was talked about only as a solution. We did not comprehensively discuss threats and vulnerabilities. We did not have enough time to include any hands-on exercises which we think is ideal for showing activists how easy it is to install and use the above mentioned software tools. We also were not able to talk about HTTPS or PKI, which would have been useful after a basic intro to encryption.&lt;/p&gt;
&lt;p&gt;Lastly, while we were able to discuss contact management for cell phones, we did not discuss contact management for personal computers. In fact, while 5 hours is a lot of time, we had no time for talking about personal computer hardening aside from a few brief mentions of Tails Linux. The only attendees to raise their hands as being Linux users were those from the Seattle Privacy Coalition.&lt;/p&gt;
&lt;h2 id=&quot;in-retrospect&quot;&gt;In Retrospect&lt;/h2&gt;
&lt;p&gt;Everyone walked away having learned many important things, and with a some healthy paranoia. Seattle Privacy Coalition volunteers learned a lot too, particularly about the nature of this specific underrepresented community in Seattle. The Seattle City Council is advised by the Citizens Technology and telecommunications Advisory Board (CTTAB), and in a couple months, CTTAB will be hosting a privacy symposium specifically looking at underrepresented communities that are often hurt by data mismanagement or surveillance. Activists are not only underrepresented, they’re often abused and misunderstood by capitalists, politicians, and journalists. We hope that these surveillance self-defense workshops will help our fellow residents, our city, and our perception of privacy moving forward.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Configuring my Tor exit router with IPv6</title>
        <published>2013-05-09T00:00:00+00:00</published>
        <updated>2013-05-09T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/configuring-my-tor-exit-router-with-ipv6/"/>
        <id>https://yawnbox.eu/blog/configuring-my-tor-exit-router-with-ipv6/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/configuring-my-tor-exit-router-with-ipv6/">&lt;blockquote&gt;
&lt;p&gt;Please be warned this is from 2013 and is kept for historical value.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Recently I upgraded my home internet to 1 Gbps and also requested a static block of IPv6 addresses. It’s hard to believe how many hosts I could support with a /64 block–18,446,744,073,709,551,616 (18 quintillion) unique IPs.&lt;/p&gt;
&lt;p&gt;Special shout-out to &lt;a rel=&quot;external&quot; href=&quot;http://www.condointernet.net/&quot;&gt;CondoInternet.net&lt;/a&gt; for being such an awesome ISP. With my former 100 Mbps internet line, I transfered over 20 Terabytes a month with this Exit Router and they don’t care. I had emailed them over a year ago asking for their policy or opinion about Tor and they don’t have either, though I did pique the interest of my support representative who kindly responded to my emails.&lt;/p&gt;
&lt;p&gt;The following was performed on my recently deployed Ubuntu 13.04 server x64 host.&lt;/p&gt;
&lt;p&gt;First I added the following 5 lines to the bottom of my network interfaces config.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/network/interfaces&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;auto eth0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;iface eth0 inet static&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;address 216.243.58.198&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;netmask 255.255.###.###&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;gateway 216.243.###.###&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;broadcast 216.243.###.###&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;dns-nameservers 8.8.8.8 8.8.4.4&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;iface eth0 inet6 static&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;pre-up modprobe ipv6&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;address 2604:4080:110f:201::9001&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;netmask 64&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;gateway 2604:4080:####:###::####&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I turned off the &lt;a rel=&quot;external&quot; href=&quot;https://en.wikipedia.org/wiki/IPv6#Privacy&quot;&gt;IPv6 Privacy Extension&lt;/a&gt;, which is on by default in recent versions of Ubuntu, since I’m not worried about my privacy for this static address being compromised by advertisers. However, I’m not sure if this is a necessary step for Tor routing.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo vim /etc/sysctl.d/10-ipv6-privacy.conf&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;net.ipv6.conf.all.use_tempaddr = 0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;net.ipv6.conf.default.use_tempaddr = 0&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I had to update my /etc/tor/torrc file by adding three lines. As the Tor Project guides mention, at this time Tor can only support IPv6 incoming traffic, so I added an ORPort with a static address. Since the Tor Project recommends that Exit Routers that aren’t hosting encrypted web content via port 443 use this port for their ORPort, I changed my IPv4 ORPort to 443 to better support Tor users behind restrictive firewalls. In the future I will likely change my IPv6 ORPort to a similar, more accessible port.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https://people.torproject.org/~linus/ipv6-relay-howto.html&quot;&gt;https://people.torproject.org/~linus/ipv6-relay-howto.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.torproject.org/docs/tor-manual-dev.html.en&quot;&gt;https://www.torproject.org/docs/tor-manual-dev.html.en&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, I up’d my Relay Bandwidth Rate and Burst caps.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;## Configuration file for a typical Tor user&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;## Last updated 12 September 2012 for Tor 0.2.4.3-alpha.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;## (may or may not work for much older or much newer versions of Tor.)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SocksPort 0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Log notice file /var/log/tor/notices.log&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RunAsDaemon 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DataDirectory /var/lib/tor&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;################ This section is just for relays #####################&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ORPort 443&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ORPort [2604:4080:110f:201::9001]:9001&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ClientUseIPv6 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ClientPreferIPv6ORPort 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;OutboundBindAddress 216.243.58.198&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Nickname YawnboxSeattle&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RelayBandwidthRate 16000 KB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RelayBandwidthBurst 20000 KB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ContactInfo Chris Sheats &amp;lt;yawnbox@gmail.com&amp;gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DirPort 9030&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DirPortFrontPage /var/www/index.html&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:20-23 # FTP, SSH, telnet&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:43 # WHOIS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:53 # DNS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:79-81 # finger, HTTP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:88 # kerberos&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:110 # POP3&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:119 # accept nntp as well as default exit policy&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:143 # IMAP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:194 # IRC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:220 # IMAP3&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:389 # LDAP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:443 # HTTPS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:464 # kpasswd&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:465 # smtps (SMTP over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:531 # IRC/AIM&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:543-544 # Kerberos&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:554 # RTSP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:563 # NNTP over SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:636 # LDAP over SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:706 # SILC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:749 # kerberos&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:873 # rsync&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:902-904 # VMware&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:981 # Remote HTTPS management for firewall&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:989-995 # FTP over SSL, Netnews Administration System, telnets, IMAP over SSL, ircs, POP3 over SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1194 # OpenVPN&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1220 # QT Server Admin&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1293 # PKT-KRB-IPSec&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1500 # VLSI License Manager&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1533 # Sametime&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1677 # GroupWise&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1723 # PPTP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1755 # RTSP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1863 # MSNP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2082 # Infowave Mobility Server&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2083 # Secure Radius Service (radsec)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2086-2087 # GNUnet, ELI&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2095-2096 # NBX&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2102-2104 # Zephyr&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:3128 # SQUID&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:3389 # MS WBT&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:3690 # SVN&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:4321 # RWHOIS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:4643 # Virtuozzo&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5050 # MMCC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5190 # ICQ&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5222-5223 # XMPP, XMPP over SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5228 # Android Market&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5900 # VNC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:6660-6669 # IRC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:6679 # IRC SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:6697 # IRC SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8000 # iRDMI&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8008 # HTTP alternate&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8074 # Gadu-Gadu&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8080 # HTTP Proxies&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8087-8088 # Simplify Media SPP Protocol, Radan HTTP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8332-8333 # BitCoin&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8443 # PCsync HTTPS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8888 # HTTP Proxies, NewsEDGE&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:9418 # git&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:9999 # distinct&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:10000 # Network Data Management Protocol&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:11371 # OpenPGP hkp (http keyserver protocol)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:19294 # Google Voice TCP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:19638 # Ensim control panel&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy reject *:*&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;After updating my UFW (iptables) rules, I rebooted my host and everything works great!&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Updated my Tor exit router policy</title>
        <published>2012-08-13T00:00:00+00:00</published>
        <updated>2012-08-13T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/updated-my-tor-exit-router-policy/"/>
        <id>https://yawnbox.eu/blog/updated-my-tor-exit-router-policy/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/updated-my-tor-exit-router-policy/">&lt;blockquote&gt;
&lt;p&gt;Please be warned this is from 2012 and is kept for historical value.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Revised: &lt;a rel=&quot;external&quot; href=&quot;https://atlas.torproject.org/#details/6B53D408A434C2410FADA8224097CC60A441F7C5&quot;&gt;https://atlas.torproject.org/#details/6B53D408A434C2410FADA8224097CC60A441F7C5&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;From: &lt;a rel=&quot;external&quot; href=&quot;https://trac.torproject.org/projects/tor/wiki/doc/ReducedExitPolicy&quot;&gt;https://trac.torproject.org/projects/tor/wiki/doc/ReducedExitPolicy&lt;/a&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:20-23     # FTP, SSH, telnet&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:43        # WHOIS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:53        # DNS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:79-81     # finger, HTTP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:88        # kerberos&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:110       # POP3&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:119       # accept nntp as well as default exit policy&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:143       # IMAP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:194       # IRC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:220       # IMAP3&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:389       # LDAP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:443       # HTTPS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:464       # kpasswd&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:465       # smtps (SMTP over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:531       # IRC/AIM&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:543-544   # Kerberos&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:554       # RTSP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:563       # NNTP over SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:636       # LDAP over SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:706       # SILC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:749       # kerberos &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:873       # rsync&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:902-904   # VMware&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:981       # Remote HTTPS management for firewall&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:989-995   # FTP over SSL, Netnews Administration System, telnets, IMAP over SSL, ircs, POP3 over SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1194      # OpenVPN&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1220      # QT Server Admin&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1293      # PKT-KRB-IPSec&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1500      # VLSI License Manager&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1533      # Sametime&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1677      # GroupWise&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1723      # PPTP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1755      # RTSP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:1863      # MSNP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2082      # Infowave Mobility Server&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2083      # Secure Radius Service (radsec)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2086-2087 # GNUnet, ELI&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2095-2096 # NBX&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:2102-2104 # Zephyr&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:3128      # SQUID&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:3389      # MS WBT&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:3690      # SVN&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:4321      # RWHOIS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:4643      # Virtuozzo&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5050      # MMCC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5190      # ICQ&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5222-5223 # XMPP, XMPP over SSL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5228      # Android Market&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:5900      # VNC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:6660-6669 # IRC&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:6679      # IRC SSL  &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:6697      # IRC SSL  &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8000      # iRDMI&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8008      # HTTP alternate&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8074      # Gadu-Gadu&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8080      # HTTP Proxies&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8087-8088 # Simplify Media SPP Protocol, Radan HTTP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8332-8333 # BitCoin&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8443      # PCsync HTTPS&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:8888      # HTTP Proxies, NewsEDGE&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:9418      # git&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:9999      # distinct&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:10000     # Network Data Management Protocol&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:11371     # OpenPGP hkp (http keyserver protocol)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:19294     # Google Voice TCP&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:19638     # Ensim control panel&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy reject *:*&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Updated Tor exit config</title>
        <published>2012-07-24T00:00:00+00:00</published>
        <updated>2012-07-24T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/updated-tor-exit-config/"/>
        <id>https://yawnbox.eu/blog/updated-tor-exit-config/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/updated-tor-exit-config/">&lt;blockquote&gt;
&lt;p&gt;Please be warned this is from 2012 and is kept for historical value.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Below are some small developments with respect to my Tor exit routing operations. I updated my torrc file by removing the configuration lines that I don’t use and the comment verbiage. I also added a new low-bandwidth exit router on a VPS in Iceland, &lt;a rel=&quot;external&quot; href=&quot;http://tor.pirate.is/&quot;&gt;tor.pirate.is&lt;/a&gt;, and made sure to update my MyFamily fingerprint line.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;UPDATED: 2012-JUL-24&lt;/strong&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NumCPUs 2&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SocksPort 0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Log notice file /var/log/tor/notices.log&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RunAsDaemon 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DataDirectory /var/lib/tor&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ORPort 9001&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Nickname yawnbox&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Address tor.anon.is&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RelayBandwidthRate 5500 KB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RelayBandwidthBurst 7000 KB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ContactInfo Chris Sheats&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DirPort 9030&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;MyFamily $6B53D408A434C2410FADA8224097CC60A441F7C5,$0F8D514E77A8E375105F506C549B87D080F736BB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:119 # accept nntp as well as default exit policy&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:22 # ssh&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:443 # https (HTTP via TLS)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:465 # smtps (SMTP over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:993 # imaps (IMAP over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:994 # ircs (IRC over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:995 # pop3s (POP3 over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:6660-6667 # allow irc ports&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:6697 # irc (using SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy reject *:* # no exits allowed&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I also updated both to &lt;a rel=&quot;external&quot; href=&quot;https://lists.torproject.org/pipermail/tor-talk/2012-July/024713.html&quot;&gt;Tor 0.2.3.19-rc&lt;/a&gt;. Since I run these as a hobby, I don’t mind running bleeding-edge exit routers.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Wikipedia continues to violate my privacy</title>
        <published>2012-07-03T00:00:00+00:00</published>
        <updated>2012-07-03T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/wikipedia-continues-to-violate-my-privacy/"/>
        <id>https://yawnbox.eu/blog/wikipedia-continues-to-violate-my-privacy/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/wikipedia-continues-to-violate-my-privacy/">&lt;p&gt;I’ve been a small part of Wikipedia’s community since 2006. In July of 2012, I wrote to Wikipedia requesting that my username be grated permission to edit Wikipedia via the Tor network, in order to further protect my physical location. I kindly explained that I was a participant of the Washington State Address Confidentiality Program, citing Washington State RCW 40.24 and offering a photocopy of my A.C.P. identification card. I even went into detail, which I didn’t feel I legally needed to do, about me and my family being victims of extreme domestic violence. Here’s their response:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Tue, Jul 3, 2012 at 11:17 AM PT&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Hello Yawnbox,&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Our privacy policy is very strict. When you edit Wikipedia when logged in to your account, nobody will generally be able to get any information from your IP address. The only few people have access to this information are only allowed to access this information under very specific situations. These people are personally identified to the Wikimedia Foundation, and their work is checked for violations of the stict access rules. For the policy pertaining to these people, see https://en.wikipedia.org/wiki/Wikipedia:CheckU ser Also consider that it is possible to connect to Wikipedia through https, securing communications even further.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;This means that as long as you are logged in to your account, no information is ever public. Our policy on IP Block exempts shows that there needs to be (quoting our policy) “highly exceptional circumstances”. I do realize that your circumstances are indeed exceptional, and that it is a bit of a hassle to turn off your VPN/TOR to edit wikipedia, but seeing that we have strong means in place to protect your privacy, I can’t say that your need to reach Wikipedia specifically through an anonymizing proxy or TOR is exceptional.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;In other words, your clearly exceptional need for privacy doesn’t demonstrate an exceptional need to edit Wikipedia through VPN or TOR. Therefor, I am currently denying your request for an IP Block exempt to be used for anonymous proxy editing.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Kind regards,&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;M. H.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;English Wikipedia Administrator&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>25 days of Tor exit routing</title>
        <published>2012-03-13T00:00:00+00:00</published>
        <updated>2012-03-13T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/25-days-of-tor-exit-routing/"/>
        <id>https://yawnbox.eu/blog/25-days-of-tor-exit-routing/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/25-days-of-tor-exit-routing/">&lt;blockquote&gt;
&lt;p&gt;Please be warned this is from 2012 and is kept for historical value.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;11 terabytes of traffic with my current torrc configuration.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/bmon_tor_mar13_Original.PNG&quot; alt=&quot;bmon_tor_mar13&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Related to an earlier blog post, I changed my domain from torexit.yawnbox.com to &lt;a rel=&quot;external&quot; href=&quot;http://tor.anon.is/&quot;&gt;tor.anon.is&lt;/a&gt;. I also contacted my ISP to add the reverse DNS, so now I’m “&lt;a rel=&quot;external&quot; href=&quot;http://torstatus.blutmagie.de/router_detail.php?FP=6b53d408a434c2410fada8224097cc60a441f7c5&quot;&gt;named&lt;/a&gt;“.&lt;/p&gt;
&lt;p&gt;Following clarification on the &lt;a rel=&quot;external&quot; href=&quot;https://www.torproject.org/about/contact.html.en&quot;&gt;Tor IRC channel&lt;/a&gt;, I closed up some open inbound ports via iptables that didn’t need to be open:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“inbound you only have to open your dirport and orport for tor to function”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“outbound you shouldn’t disallow anything”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So, using &lt;a rel=&quot;external&quot; href=&quot;https://help.ubuntu.com/community/UFW&quot;&gt;UFW&lt;/a&gt;, I adjusted my iptables rules as such:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;$ sudo ufw status verbose&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; Status: active&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; Logging: on (low)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; Default: deny (incoming), allow (outgoing)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; New profiles: skip&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;To                         Action      From&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; --                         ------      ----&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; 22                         LIMIT       Anywhere&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; 9030                       ALLOW       Anywhere&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; 9001                       ALLOW       Anywhere&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; 80/tcp                     ALLOW       Anywhere&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Running a Tor exit, one week in</title>
        <published>2012-02-26T00:00:00+00:00</published>
        <updated>2012-02-26T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/running-a-tor-exit-one-week-in/"/>
        <id>https://yawnbox.eu/blog/running-a-tor-exit-one-week-in/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/running-a-tor-exit-one-week-in/">&lt;blockquote&gt;
&lt;p&gt;Please be warned this is from 2012 and is kept for historical value.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;To update on my short experience as a Tor node operator, It’s been over a week now and in that week I made some changes.&lt;/p&gt;
&lt;p&gt;First and foremost, since I’ve been online for a few days straight, &lt;a rel=&quot;external&quot; href=&quot;http://torstatus.blutmagie.de/router_detail.php?FP=6b53d408a434c2410fada8224097cc60a441f7c5&quot;&gt;I’ve been flagged&lt;/a&gt; by the Tor network as a “Stable” node. So now I’m processing traffic rather consistently. I’ve also been flagged as a “&lt;a rel=&quot;external&quot; href=&quot;https://www.torproject.org/docs/faq#EntryGuards&quot;&gt;Guard&lt;/a&gt;“, meaning,”…each Tor client selects a few relays at random to use as entry points, and uses only those relays for her first hop”. More can be read about Guards &lt;a rel=&quot;external&quot; href=&quot;https://blog.torproject.org/blog/research-problem-better-guard-rotation-parameters&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Secondly, I adjusted (increasing) how much of my bandwidth I’m willing to let Tor use.&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RelayBandwidthRate 6000 KB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RelayBandwidthBurst 7500 KB&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I’ve observed traffic peaks of 5 Megabytes a second, sending and receiving. This last Friday I noticed that I was passing a lot of traffic. It made me wonder if people are using Tor a lot more on Fridays.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/bmon_tor_feb26_Original.PNG&quot; alt=&quot;bmon_tor_feb26&quot; /&gt;&lt;/p&gt;
&lt;p&gt;As you can see, 8 Day(s), 19 Hour(s) in I’ve already relayed 1142.4 GiB.&lt;/p&gt;
&lt;p&gt;Thirdly, I put up the standard “This is a Tor Exit Router” page on &lt;a rel=&quot;external&quot; href=&quot;http://torexit.yawnbox.com/&quot;&gt;torexit.yawnbox.com&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Lastly, I am now allowing port 443 to pass HTTPS traffic. So here’s my updated &lt;a rel=&quot;external&quot; href=&quot;https://trac.torproject.org/projects/tor/wiki/doc/ReducedExitPolicy&quot;&gt;Reduced Exit Policy&lt;/a&gt;:&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:119 # accept nntp as well as default exit policy&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:22  # ssh&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:443 # https (HTTP via TLS)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:465 # smtps (SMTP over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:993 # imaps (IMAP over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:994 # ircs (IRC over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:995 # pop3s (POP3 over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy reject *:* # no exits allowed&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It turns out that in order to be flagged as an exit, the node needs to either be exiting ports 443 and 80 or 443 and 6667. And I’m being stubborn about only passing, ideally, encrypted traffic. However, not having the check-mark next to “Exit” on my Network Status &lt;a rel=&quot;external&quot; href=&quot;http://torstatus.blutmagie.de/router_detail.php?FP=6b53d408a434c2410fada8224097cc60a441f7c5&quot;&gt;page&lt;/a&gt; doesn’t mean that I’m not an exit– the Tor network certainly knows I’m exiting.&lt;/p&gt;
&lt;p&gt;Props to everyone at the &lt;a rel=&quot;external&quot; href=&quot;https://blog.torproject.org/blog/university-washington-open-hackfest&quot;&gt;UW/Tor hack-fest&lt;/a&gt;. Absolutely brilliant people having the most interesting of conversations. I really enjoyed the two days I spent around them, soaking in as much as I could. It made me think critically about a number of problems that I hope to blog about soon.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Node Operator Notes&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reloading Tor instead of restarting it (the service) allows me to update my torrc file without disrupting traffic.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo /etc/init.d/tor reload&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Also, I added two security features to help block annoying attacks. Make sure you’re familiar with how to use them.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt-get install -y fail2ban denyhosts&lt;/code&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>My first 24 hours as a Tor exit node</title>
        <published>2012-02-18T00:00:00+00:00</published>
        <updated>2012-02-18T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/my-first-24-hours-tor-exit-node/"/>
        <id>https://yawnbox.eu/blog/my-first-24-hours-tor-exit-node/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/my-first-24-hours-tor-exit-node/">&lt;blockquote&gt;
&lt;p&gt;Please be warned this is from 2012 and is kept for historical value.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;I setup a limited Tor exit node in my home yesterday by following &lt;a rel=&quot;external&quot; href=&quot;https://twitter.com/#!/grahamking&quot;&gt;@grahamking&lt;/a&gt;‘s &lt;a rel=&quot;external&quot; href=&quot;http://www.darkcoding.net/society/running-a-tor-relay-node-server-on-ubuntu/&quot;&gt;guide for Ubuntu&lt;/a&gt;. Presently I’m using Ubuntu 11.10 x64 on a spare laptop. The laptop is HP/Compaq &lt;a rel=&quot;external&quot; href=&quot;http://www.notebookreview.com/default.asp?newsID=3763&amp;amp;review=HP+6510b&quot;&gt;6510b&lt;/a&gt;; not very powerful, but I wanted a low-power solution since it is running 24/7 in my home.&lt;/p&gt;
&lt;h1 id=&quot;the-basic-steps&quot;&gt;The basic steps&lt;/h1&gt;
&lt;p&gt;First I configured my A record for torexit.yawnbox.com. Then my static IP/hostname for the laptop (step 7 from &lt;a rel=&quot;external&quot; href=&quot;http://www.howtoforge.com/perfect-server-ubuntu-11.10-ispconfig-3-p3&quot;&gt;this guide&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;If I open my torrc file, these are the settings I uncommented or added:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;vim /etc/tor/torrc&lt;/code&gt;&lt;/p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #BFBDB6; background-color: #0D1017;&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;SocksPort 0 # what port to open for local application connections&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Log notice file /var/log/tor/notices.log&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RunAsDaemon 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DataDirectory /var/lib/tor&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ORPort 9001&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Nickname yawnbox&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Address torexit.yawnbox.com&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RelayBandwidthRate 2500 KB # Throttle traffic to 2500KB/s&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;RelayBandwidthBurst 5000 KB # But allow bursts up to 5000KB/s&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ContactInfo Christopher Sheats&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DirPort 9030 # what port to advertise for directory connections&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DirPortFrontPage /etc/tor/tor-exit-notice.html&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:119 # accept nntp as well as default exit policy&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:22 # ssh&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:465 # smtps (SMTP over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:993 # imaps (IMAP over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:994 # ircs (IRC over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy accept *:995 # pop3s (POP3 over SSL)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ExitPolicy reject *:* # no exits allowed&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I am only allowing ports that are intended for encrypted traffic. I am not yet allowing the standard IRC ports. Also, since this Tor exit node is in my home, I’m not comfortable with running a completely open node. After I figured out what ports I would be allowing, I configured the iptables firewall accordingly using &lt;a rel=&quot;external&quot; href=&quot;https://help.ubuntu.com/community/UFW&quot;&gt;UFW&lt;/a&gt;.&lt;/p&gt;
&lt;h1 id=&quot;bandwidth-usage&quot;&gt;Bandwidth usage&lt;/h1&gt;
&lt;p&gt;I set the bandwidth at 2,500KB/s with 5,000KB/s burst. By browsing the &lt;a rel=&quot;external&quot; href=&quot;http://www.ubuntu.com/ubuntu/features/ubuntu-software-centre&quot;&gt;Ubuntu Sofware Center&lt;/a&gt; I managed to find two easy to use bandwidth monitors. One for watching locally and one for watching remotely. &lt;strong&gt;In just over 24 hours, I have already sent/received 27 GB of traffic!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/2012-02-18-knemo.png&quot; alt=&quot;A GUI bandwidth monitor, KNemo&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/images/2012-02-18-bmon.png&quot; alt=&quot;A command-line bandwidth monitor, BMon&quot; /&gt;&lt;/p&gt;
&lt;h1 id=&quot;why-am-i-running-a-tor-exit-node-from-my-home&quot;&gt;Why am I running a Tor exit node from my home?&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;I strongly support the notion of our &lt;a rel=&quot;external&quot; href=&quot;https://www.gnu.org/philosophy/right-to-read.html&quot;&gt;right to read&lt;/a&gt;, no matter who is trying to stop us.&lt;/li&gt;
&lt;li&gt;I am paying for a fast Internet service that I don’t fully utilize 24/7&lt;/li&gt;
&lt;li&gt;I want to contribute to the Tor Project, especially after watching Roger Dingledine and Jacob Appelbaum (two “&lt;a rel=&quot;external&quot; href=&quot;https://www.torproject.org/about/corepeople.html.en&quot;&gt;core people&lt;/a&gt;“) talk at &lt;a rel=&quot;external&quot; href=&quot;https://events.ccc.de/congress/2011/wiki/Welcome&quot;&gt;28C3&lt;/a&gt; (YouTube video below)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https://www.youtube.com/watch?v=DX46Qv_b7F4&quot;&gt;https://www.youtube.com/watch?v=DX46Qv_b7F4&lt;/a&gt;&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Lawnridge</title>
        <published>2005-03-28T00:00:00+00:00</published>
        <updated>2005-03-28T00:00:00+00:00</updated>
        
        <author>
          <name>Unknown</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yawnbox.eu/blog/lawnridge/"/>
        <id>https://yawnbox.eu/blog/lawnridge/</id>
        
        <content type="html" xml:base="https://yawnbox.eu/blog/lawnridge/">&lt;p&gt;Under the warm blanket of the sun,&lt;br&gt;
Completely passive,&lt;br&gt;
I lay on my stomach atop freshly cut grass.&lt;br&gt;
A warm summer breeze blows over my back that carries a captivating scent;&lt;br&gt;
A scent of the rose garden that lies near, and of raspberry shrubbery.&lt;br&gt;
Content with myself, I breathe deeply.&lt;br&gt;
The flawless taste of sweet honey suckle fills my lungs,&lt;br&gt;
Soothing my already relaxed body.&lt;br&gt;
Serenely, I compel myself into turning over;&lt;br&gt;
My head tilted to a slant, like the hill that I rest on.&lt;br&gt;
The lingering shadows from the orchard swing among the scented breeze.&lt;br&gt;
A drifting leaf from the Aspen lands on my abdomen,&lt;br&gt;
Tickling my skin with purity.&lt;br&gt;
As my front side warms,&lt;br&gt;
My eyelids fill with an alternating balmy glow and a lightly tinted shadow.&lt;/p&gt;
&lt;br&gt;
&lt;br&gt;</content>
        
    </entry>
</feed>
