Privacy Tools: Encryption against global mass surveillance
privacytools.io
privacytools.io
But the logic this post uses to make the case against US privacy tools is specious.
The United States Government didn't ruin Lavabit. Lavabit did that to itself. Lavabit was a "secure" email system whose servers kept the keys to your email. There is no safe way to design such a system, and Lavabit didn't even approximate safety.
Lavabit didn't make this terrible decision to help the DOJ (although they did help the DOJ, multiple times, before the Snowden case). Rather, they did it because they wanted users. Building a better security system would mean prospective users would need to download and install software on their computer, and nobody wants to do that anymore. Lavabit chose user adoption over security. We all see what that cost, not just them, but all their users.
So I'd submit that while making it's legit to make political statements by carefully choosing the country of origin of your privacy tools, your first priority is to select tools that are actually secure. It does you no good to adopt a crypto tool from Iceland if it's using unauthenticated AES-CBC, unpadded RSA, or bad elliptic curves --- and there are tools, probably some of them quite popular, that make these kinds of mistakes.
If you're talking about how a chat tool comes from Switzerland before you're talking in detail about how its security works, your priorities are out of whack.
As for the value of encryption to keep governments from snooping -- no way, that's not going to work ever. Endpoint security is a joke, PC and mobile phone are insecure on all levels, from applications over OS to firmware and microcode. And if Snowden's educational slide show leaks have shown anything, then certainly that the guys at NSA know what they are doing in terms of side-channel attacks.
Government snooping and privacy decay is a social and political problem and should primarily be addressed at that level.
Please don't attempt to bolster support for one approach by discouraging another. There is no "primarily". None of the approaches have worked so far, so it's premature to say that fewer approaches are necessary.
Personally, I don't see how the NSA (never mind Google) would ever be politically prevented from most mechanisms of surveillance. To the extent that political power could be used to categorically end surveillance, it can just be used to constrain the application of surveillance. We can encourage people to value privacy, but it's another thing to convince them to completely dismantle the capabilities against everyone, including say child pornographers.
But I'll still applaud you for trying.
For example, NSA surveillance has no direct effects on the average US citizen. It is a setup for bad things to happen, has possible political meta-effects, and is a worrying trend. But if the process is successfully constrained by law, then to your average person it represents a capability rather than a vulnerability. This has little to do with your average person not understanding technology, but instead with their feeling safe as part of a majority.
Though when checking a few i found,
"Statement VPNSecure has not been silenced by legal and or anti-democratic law. Last updated Thur Jul 30 00:57:30 EDT 2016
If there is no statement, please proceed with caution"
It doesn't state how often/recent it should be updated, its august 2nd now, did this canary choke in the mine?
Archive of the page your looking at maybe found here: https://web.archive.org/web/*/https://www.vpnsecure.me/files...
(Given the pull date noted by the archive and the date listed in the related cache of the canary are off in some cases by months, may guess is it is meaningless that the current canary is off by a few days.)
I'd also suggest striking anyone from the 14 eyes off the list too.
6 lines of Bash