Briar Project
briarproject.org
briarproject.org
They obviously sell user data in aggregate - not at a personal level, but which of the big tech companies sell personal data (maybe FB / Cambridge Analytica?)
Also, Apple has Google as the default search engine which Google pays billions for. Is that selling your personal data?
I can't see anything in that section that says that they sell information to third parties, personally identifiable or aggregate (I would consider the latter to be "personal" data as well fwiw). Is there a specific sentence you're thinking of?
It seems to be talking about the necessary sharing of data that happens when Apple contracts with third party services to run their own business. E.g. when they ship you a product they need to provide your address to the courier company. Or when they pay an advertising company to run ads for Apple products targeting certain markets/their own existing customers (not the same thing as selling personal data to an advertiser so that they can run ads for other products using said data - that would be selling personal data)
As far as I can tell you're either using a definition of "sell" that is different to mine, or you're claiming Apple is using weaselly language to make it sound like they don't when they do (which is not unheard of of course). But you haven't provided enough information for me to really know what you're talking about - which is it, and why?
Also no, making the default search engine google is not selling personal data.
"Ads that are delivered by Apple’s advertising platform may appear in Apple News and in the App Store. If you do not wish to receive ads targeted to your interests from Apple's advertising platform, you can choose to enable Limit Ad Tracking, which will opt your Apple ID out of receiving such ads regardless of what device you are using. If you enable Limit Ad Tracking on your mobile device, third-party apps cannot use the Advertising Identifier, a non-personal device identifier, to serve you targeted ads. You may still see ads in the App Store or News based on context like your search query or the channel you are reading. In third-party apps, you may see ads based on other information."
Third parties are buying ad listings, not user data. They have no way to extract user data from the ad platform, unless there's some kind of data leak.
If you think Apple is harvesting data off of bought back phones to improve their ad targeting that would also be a scandal (that I would expect some evidence of - otherwise it's just baseless speculation), but referring to it as "selling user data" is just obscuring what you're actually trying to communicate.
My impression was that Apple did trade ins to acquire stock to refurbish and resell in India, and to incentivize users to upgrade.
I would be pretty surprised to learn they were losing money on trade ins, and I've never heard of any kind of direct buy back.
Which ones?
When I can’t do what I want with my phone, I may as well be leasing it. Hmmm.
But I don’t believe Apple’s business model is to spy on me.
Apple business is not spying on you, but Apple business is much easier to do if they do spy on you. Meaning they do it anyway, don't worry.
It's impossible to use an iPhone with any popular apps and not be constantly spied on. Insofar as Apple's business model is to make the (full of spyware) App Store successful, it's Apple's business model to spy on you.
"Location-Based Apple Ads: Your iPhone will send your location to Apple in order to provide you with geographically relevant ads on Apple News and in the App Store."
More: https://support.apple.com/en-us/HT207056
So not exactly "business model", but does it matter?
Although it's annonymous, your connection to the network is detectable and would trigger redflags in government monitoring software...
Of course it doesn't even need to be real data, random gibberish would work too.
There is no need to imagine it.
In an alternative timeline where ISPs where more strictly regulated and trusted and everything was cleartext HTTP, I'm certain that HTTPS/TLS would face pushback from regulators. There's no way it can be banned today, though. Similarly, you won't be marked as suspicious just from opening an encrypted TLS connecting over port 443 to an arbitrary endpoint.
I don't think it's too late. There is a significant probability that today's centralized incumbents will Myspace at some point in the future. These federated, decentralized and secure solutions could be the next iteration after that.
https://www.zdnet.com/article/china-is-now-blocking-all-encr...
If you're getting mail from abroad you're already on a list. If you're getting encrypted mail - you'll probably disappear.
Targeting users who rely upon secure apps is becoming common in flawed democracies as well and more countries are eager to join that list. Several people, including minors were arrested in Kashmir when police found VPN app on their mobile during routine checks[0]. Government's logic being 'Why use VPN, if you are not a terrorist?'
At the same time journalists, activists are heavily dependent upon secure apps like this to make their voice heard outside, all the more reason for all of us who are lucky to not have gestapo knocking our doors because we used a VPN to watch PornHub to make usage of such secure apps (messaging, email, VPN etc.) very common.
[0]https://scroll.in/article/954711/in-kashmir-a-spree-of-arres...
In short, I just don't know what to use.
Edit: Session looks great but is not fully released yet: https://getsession.org/ This might be what I'm looking for in the future.
However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.
so is regardless of user count
Edit: Generally, Threema seems interesting feature-wise, but I think the price (4€) will prevent my contacts from using it...
I've also had terrible reliability issue with imessage in the past, messages not delivering, not showing up, errors sending, showing up on one device but not another, etc. Was a mess that caused a lot of confusion.
Which isn't end to end encrypted which defeats the whole point in terms of this conversation.
I would strongly advise against picking a tiny new-comer without some serious research beforehand... They're not battle-hardened, so will typically be less reliable than any of the existing larger players.
What if someone registers with my old number?
If someone were to register with your old number on a new phone, then they will have an empty message history. Your contacts will also be made aware of a safety number change if they start messaging with the old number.
https://support.signal.org/hc/en-us/articles/360007062012-Ne...The app is easy to use, but people are not using it. They use sms and FB etc. to message friends.
...Including the unstable frenemy-guy who was only in my contacts so I'd recognize the number if he called and I'd know not to answer...
....who immediately PM'd me on Signal to push his latest delusion and make sure I didn't disagree.
Great, just great. For a privacy-focused product, that's a pretty colossal fuckup.
Your local Signal installation regularly checks if any of your contacts (with the phone numbers you have of them) are registered at the Signal servers - and then lets you know it, such that you can text this contact securely.
Many people might have my phone number, possibly from a long ago. But the number itself is pretty safe -- there is no way to tell if this phone is in use or not.
Signal breaks that assumption -- it immediately tells every other user that this number is alive, valid, and can be contacted right now.
This is a terrible idea to do by default, especially if one cannot disable it.
This is all based on your address-book so it doesn't matter if the other party knows your number or not.
A check for "aliveness" of a number can be done without Signal. Just call and see if it is ringing. You get the same information. Your Signal profile name and picture, however, will only be shared when you accept it.
Anyone who says Signal has good privacy is just wrong. When Signal say they have good privacy, that's false advertising.
Of course, Telegram does the same thing. I have Telegram installed, and I use it, but it wasn't really a choice. I needed to access a forum which is only on Telegram :/ Unfortunately that meant I had no choice but to have people who know me notified that I installed it. Someone messaged me about 30 seconds after I installed it to say hi. I'm not comfortable about this, but as I say, I didn't really have a choice.
Then there's WhatsApp. I was surprised to read an article which recommended that, of the three, WhatsApp is probably the most privacy-respecting of the apps. I have WhatsApp installed after a long period of avoiding it, because of all people recruiters started expecting it. Hmph. I still refuse to grant it access to my contact list, because I'm not handing that over to Facebook. Which means every message is associated with a raw phone number only, and I have to guess who it is from the content :-)
You can tell WhatsApp doesn't reveal so much, by the people who have sent WhatsApp messages without being told that the recipient doesn't have WhatsApp installed and won't see the message. I've known a few people this happened to. One installed WhatsApp and found they'd been sent a message a year earlier, from someone they thought wasn't talking to them. They were talking, but the sender assumed of course the recipient would have WhatsApp.
All three of Signal, Telegram and WhatsApp make me a bit off about using them for various reasons. None of them are what you'd call "user's privacy first".
As it is, I'm currently having occasional confidential chats (at someone else's request) on Telegram secret chats, and at least that probably is what it says it is.
I don't think any of these three apps are awful.
They are pretty slick, and useful.
I don't feel too bad actually using them, any more then using say MSN, Yahoo or Freenode.
They just don't meet the advertised bar of respecting individual privacy first. And I find that really misleading in the case of Signal and Telegram in particular, which emphasise the privacy angle, and then without letting you know, sprays everyone you ever interacted with outside Signal with a notification, including professional contacts, customer service agents, people you don't like, spammers, etc.
Can someone elaborate?
The second one is more difficult to evaluate. If you use the above mentioned "secret chat" feature, Telegram employs their own closed-source encryption scheme. That's usually an indicator to be cautious from the get-go. Since it's closed source, it can't really be trusted.
See [Wikipedia](https://en.wikipedia.org/wiki/Telegram_(software)#Security) for a timeline in regards to the security.
https://telegram.org/apps#source-code
Encryption for secret chats doesn't involve server, so technically it can be analyzed.
It's a pity Telegram decided to roll their own encryption scheme. I use Telegram a lot for daily business because it's superior desktop messenger product. I would gladly participate if somebody started a crowd-funding for Telegram's security and encryption audit.
Except if you are on desktop, you have no secret chats at all. And "desktop" includes GNU/Linux phones.
Most importantly, you can host the server yourself without cutting off from the network.
OTF is being killed by the current US government and this will affect all projects!
https://en.wikipedia.org/wiki/Open_Technology_Fund
The common alternative to overcome this is to pass the messages through the server and encrypt/decrypt them on the device (aka e2e encryption). I acknowledge that might not be secure enough for certain use cases.
It seems the majority here seem to be expecting the former, although I think of IM as more like the latter: if the recipient is not available, then the message is simply dropped, much like I can't call someone who is not answering the phone.
a) Often the intended recipient isn't online when the message is sent, and it may happen that there is never a time when both sender and recipient are online simultaneously (e.g. sender's device only turns on to send the occasional message, receiver's device is usually off but turns on occasionally to check if there are messages)
b) Often one or both devices can only connect to, but can't be connected to (because behind a NAT, a mobile device, firewall, etc.)
c) Communication is often desired between accounts rather than devices -- I may want to send/receive on my work computer, home computer, phone, and watch
I think that’s basically the sort of system that most places employ. It’s nice because it’s easy to set up but you really need to trust Skype. Say they actually try to use end to end encryption. How does that work? Well, you could say “I am Alice and I want to establish a connection to Bob. Here is my public key he can use to send me messages and I’d like his public key so I can send him his.” That of course would need to happen in addition to establishing a network connection. So no if Skype is a good actor they will pass my public key to Bob, get his and send it to me as well as coordinate us establishing a direct connection.
But what if Skype is a bad actor? Well they could take my public key and send Bob one of their own. Then they could also send me their own. Now they can listen in on my conversation. They can also in a similar fashion make it seem like I’m connected directly to Bob’s networked device but really just relay the connection through their servers. Neither Bob nor I would have any way of knowing that without having exchanged public keys prior and having verified them. So this system is basically insecure against Skype wanting to listen to my conversations or being compelled to do so by a state actor.
My only big issue is that the iOS client doesn’t support multiple simultaneous identities.
What happens if someone with old Riot client creates a room and someone with e.g. RiotX joins it, will it force E2EE on? Or will it fall back to non-E2EE messaging?
IMO it should be the case that it's always E2EE, no other options. Until that's the case I think Matrix ecosystem isn't keeping up with centralized solutions like Signal.
If there are other applications that can run over the protocol, I'm interested in learning about them.
You could connect to a pub — an automatically-friendly bot account; see a list at https://github.com/ssbc/ssb-server/wiki/Pub-Servers — scuttle.space seems to be active right now.
If you're happy posting your SSB ID publicly, I'll follow you, and that may help. Or you can use the #new-people tag if you want to introduce/announce yourself :)
It's feasible once you reach the point where it's worth the effort of implementing.
Yes, but a sensible router will also firewall all incoming connections unless the port is explicitly opened.
(The current networks are often not set up to handle malicious incoming internet traffic, and new protocol is not going to change this)
Messaging apps are more like postal services — "please deliver this message to $person" — you're describing driving across town to drop something in a mailbox directly. A peer-to-peer messaging system wouldn't have many benefits over an E2E-encrypted one (in a centralized E2E-encrypted service you already enjoy technical guarantees that the courier can't peek inside the metaphorical envelope), but would have several usability drawbacks that would drive away casual users, which the sibling comments mention.
Driving away casual users has its own problems: you might drive them away to insecure services ("ah fuck it, this thing doesn't work, I'll just DM them on Twitter"), and the lack of casual users will make your remaining users stand out in traffic analysis (e.g. state agency says "hmm, askxnakjsn is using SuperEncryptoP2PMessenger, better go make sure they aren't a dissident").
How can a system be made decentralized, but able to self-police against legitimately, publicly agreed upon bad behavior? If the system is able agree upon and exclude legitimately bad behavior automatically, the governments would not have a claim upon needing to police it and regular users would probably find it beneficial as well.
How could the self policing possibly happen?
Maybe you have a blockchain of anonymized encrypted messages that is read by open source scanning bots - if enough independent bots flag a message, then a group of anonymous judges can adjudicate to ban those user accounts?
Encryption is one challenge, but if you want true ubiquitous privacy, you need to deliver internal safety to prevent the need for external policing of activity. Social creatures of any species from dolphins to macaques have evolved some kind of internal behavior policing mechanism or trust is lost, and as such the system of value exchange grinds to a halt.
Banning encryption because bad actors use it is not justifiable.
Throwing out the baby with the bathing water (does this proverb exist in English?) is not going to do society much good. Just because there some bad actors, one does not need to discard the whole idea of encryption.
Also the dehumanized way of checking for bad content will not help. Bad actors can pre-encrypt or disguise content, whatever you do. Furthermore when the bots have the key to decryption, then the backdoor is built into the system. Bad actors and politicians will try to make use of that.
Someone like Epstein could easily communicate with coded messages. Or send someone to convey messages in person.
Edit: seems there are some thoughts about this already https://code.briarproject.org/briar/briar/-/issues/511
- open source
- cross-platform (linux, mac, windows, ios, android)
- group chats
- end-to-end encryption
- well-understood crypto ciphers & protocols
- mature enough for a reasonable expectation of security & privacy
- easy enough for most computer users
- some way to protect metadata (e.g. self-hosting)
- signup without real-world ID
- offline message delivery
I ended up choosing the Matrix network. The reference client is called Element[1] (formerly Riot). There are things I dislike about the client, but they're pretty minor compared to the benefits of the underlying protocol, and lots of alternative clients are in development[2][3].
On top of meeting my requirements, all signs indicate that development is both active and moving in the right directions. Reading the team's weekly reports and issue tracker convinced me that they are making very sound decisions.
[1]: https://element.io/
[2]: https://matrix.org/clients-matrix/
[3]: https://matrix.org/clients/
Here's what I didn't like about the others:
Briar: Lacked cross-platform support and (iirc) offline messaging. Tor brings baggage that not everyone is ready to accept.
Cwtch: Not mature yet.
Jami: Very fragile code base in my experience, which was also true when was called Ring, and when it was called SFLphone. Only about 25% of the builds I've tried over the years actually worked. I was unable to determine whether it had offline messaging.
Keybase: Now owned by Zoom, which is a privacy nightmare.
Ricochet: Same problems as Briar.
RocketChat: Crypto is not mature yet.
Session: Not mature yet. Small limit on number of group chat participants.
Signal: Required phone number for signup. Required Google Play Services (aka spyware) for quite a long time. Weak cross-platform support. Some of that is finally changing, but Moxie will surely make more intolerable design decisions, and refuse to fix them for years, again.
Telegram: Homebrew crypto.
XMPP: Most clients are hard to use (or to teach others to use). Good servers are hard to find. Protocol standards are a mess. I couldn't find a real-world e2ee group chat implementation.
Everything else: Failed to meet my requirements even before I looked closely, mostly due to closed code and/or problematic corporate interests. (For example, I will not use an app from Facebook or any of its subsidiaries.)
https://matrix.org/blog/2018/01/29/status-partners-up-with-n...
> Bridging between Matrix and Whisper (Ethereum's own real-time communication protocol) - exposing all of the Matrix ecosystem into Ethereum and vice versa
But maybe this is just meaningless marketing fluff and something that's effectively left to "the community".
Every time any crypto-currency related messaging app is published, I think it should be mandatory to immediately explain what the currency and/or blockchain brings to the table. Is it a paid app? Does it store ciphertexts indenfinitely to the blockchain? Or public keys?
The main thing they have right now is an app acting as a wallet (ETH and Ethereum-based tokens) and IM app (Whisper protocol).
It's standard practice that what you request is answered in a whitepaper, which is also the case for Status: https://status.im/whitepaper.pdf
https://signal.org/docs/specifications/x3dh/x3dh.pdf
https://signal.org/docs/specifications/doubleratchet/doubler...
Status' whitepaper looks like marketing material for investors, not a technical description for infosec professionals. I find the content almost repulsive.
Waku is in R&D by Status.
TBF, that is the more commonly understood meaning of "white paper".
https://en.wikipedia.org/wiki/White_paper#In_business-to-bus...
In answer to your questions above:
What [do] the currency and/or blockchain brings to the table?
Decentralized messaging tech aims at making 1-1 and group messaging more secure. It is not inherently tied to blockchain / cryptocurrency, though for an economically incentivized network of mailserver nodes it could make sense to realize the incentivization mechanisms via cryptocurrency transfers.
See: https://vac.dev/vac-overview
The Waku protocol, currently used by the Status mobile and desktops apps, is being developed by the Vac team, which is part of Status.
The Status client includes an Ethereum wallet because many people interested in the messaging technology are also interested in cryptocurrency.
Is it a paid app?
No, it is free to download and free to use, and all the software developed by Status is open source: https://github.com/status-im/
Does it store ciphertexts indenfinitely to the blockchain? Or public keys?
Sending and receiving messages does not involve transactions on the blockchain; messages are not stored on the blockchain.
You may be interested to read more in the technical FAQ:
"The Status client includes an Ethereum wallet because many people interested in the messaging technology are also interested in cryptocurrency."
So it's an encrypted messenger with a wallet, OK.
"Decentralized messaging tech aims at making 1-1 and group messaging more secure."
So you should discuss the monetary incentives for people to host a decentralized server, and also discuss how malicious state entities running servers is not economically viable, if that's the case, or tell that it's not the case. You should also discuss how it makes it more secure.
So tl;dr create an article for cryptographers/infosec folks that need to understand how the security works (and please remember most people in those circles are really allergic to marketing language and buzzwords unless it's a technical property).
https://github.com/status-im/specs/tree/master/docs
https://github.com/vacp2p/specs/tree/master/specs
Monetary incentivization for running a mailserver is being researched and (afaik) is not yet implemented or specified. There is a relevant discussion forum:
Activity there is currently light because most core contributors' time, at present, is being spent on other pressing tasks.
See also: https://discuss.status.im/
It seems to be married to Ethereum. That's mildly interesting. It raises questions about its relationship to cryptocurrency and blockchain tech, but until it meets my requirements, I'm not inclined to spend time investigating the answers.
The wallet functionality is tied to Ethereum, but the chat functionality works separately.
Originally Status used the Whisper protocol, which used to ship with some Ethereum clients but never gained real traction. Status has switched to a protocol named Waku that's in development but progressing nicely.
If at some point you're interested and have questions, let us know! (I'm on the team developing the desktop client)
is incompatible with Wire. Let's not just scream product names without understanding if it's for their threat model. If you're here to promote Wire then I perfectly understand why you'd recommend it anyway.
There's the issue you mentioned, and there's also the issue of them violating their published policy (either by the letter or in spirit) when they accepted new owners/investors.[1] Even if it met my requirements, I would be leery, and reluctant to suggest that others invest their time and build their communications network on such a foundation.
Of course, things can change over time. Maybe Wire will do things differently in the future, and become more appealing. That doesn't solve a problem for me today, though.
For the record, there's some discussion of Wire and other apps scattered about the privacytools.io issue tracker[2]. The signal:noise ratio there isn't great, but some folks here might find it interesting. As long as I'm posting links, their main site is worth a look, and the section about instant messengers[3] relates directly to this thread.
[1] https://nitter.net/Snowden/status/1194396764293550080
[2] https://github.com/privacytools/privacytools.io/issues
[3] https://www.privacytools.io/software/real-time-communication...
IMHO we should be able to determine the amount of trust we can put on the app from the client alone. If FOSS client uses E2EE, no matter what the server starts doing when the service changes ownership will have an effect on it. Of course the new owner could e.g. start selling user metadata, but that's something you should kind of assume the service is doing anyway (just because they can), and if you can't take the risk, you should use something that prevents it by design (like Briar/Cwtch/Ricochet/TFC).
Until that day, a public host with the right incentives and track record remains valuable, even if only to include people who don't have tech-savvy friends to host for them.
Regardless of all that, given the choice between rewarding an organization with good behavior vs. one with bad behavior, I choose the former.
There's no overhead costs like static IP or hostname.
I can agree with the point of "average user lacks the skills" so that's something that needs good tutorials.
But then there's apps like Briar that just run on your phone, that bring the complexity down to these users.
From whom are you trying to protect metadata? Briar distinguishes itself as a platform that doesn't leak it to anyone. Matrix always has at least one central point for metadata eavesdropping, and that's the device the entities interested in your communication will hack first. Or maybe the threat of the group is in the inside -- John, the creepy IT-guy of the peer network who has a crush on Karen and is jealously eavesdropping on her every action, including content when E2EE is disabled for some chats.
Thanks but no thanks. I'd much rather just centralize the trust to a known crypto anarchist like Moxie who doesn't know me in person, and if I can't trust anyone I'll just use Briar despite lack of offline-messages. It's not like my phone isn't on 24/7 anyway.
Wrt. Session, it's not at all clear how anonymous their onion routing network is, if there's enough nodes etc.
I need a general-purpose chat tool for use with friends, family, and business contacts. Protection from targeted surveillance by a state actor (or someone with equivalent resources) is neither a priority nor realistic today in light of my other requirements. I'm okay with using a separate tool if I ever need that kind of special-purpose protection.
Roughly stated, the goal is to regain the convenience of older tools like talk, ytalk, irc, ICQ, AIM, Yahoo Messenger, Facebook Messenger, and Google Talk, without being inaccessible to swaths of the computer-using population, and without exposing us all to mass surveillance any more than necessary. Matrix succeeds at this admirably, and continues to get better at it over time. (You might want to look at their in-progress P2P work.)
Briar fails unless you only talk to people using smartphones.
MoxieTalk fails because it exposes people to mass surveillance. In multiple ways. Over and over again. (Also, I've never seen a good linux client for it.)
I acknowledge that both those tools look very useful for certain purposes, and I have a good deal of respect for Moxie because of his contributions to the crypto/comms community, but neither tool does what I need.
Targeted attacks against centralized points that enable wide-scale surveillance are mass surveillance. Imagine NSA would claim "A fiber optic splitter in the bottom of the ocean is a targeted attack against one device (repeater), or one inch segment of glass wire, it's not mass surveillance".
It's vital that we define targeted surveillance as something where the target is a single entity. Hacking Moxie's phone is targeted surveillance. Hacking Signal server is not. Hacking every visitor of a CP site is mass surveillance https://www.eff.org/deeplinks/2016/09/playpen-story-fbis-unp...
"You might want to look at their in-progress P2P work."
It will be a nice to have sure, but I think P2P should work exclusively via Tor if you want to hide metadata. wrt that, you might find my work interesting https://github.com/maqp/tfc
"Briar fails unless you only talk to people using smartphones."
A picture is worth a thousand words
https://twitter.com/Amlk_B/status/1286642831239647232/photo/...
"MoxieTalk fails because it exposes people to mass surveillance."
Jabs like these aren't really appreciated. Extraordinary claims require extraordinary evidence.
In our hypothetical dystopian future The Regime will probably jam 2Ghz to 5Ghz in public spaces. TEMPEST mode would also force them to install vibrators into all coffee shop tables.
In my dystopian future theory, the government that has no issue jamming 2 and 5 ghz channels to keep people from talking would probably notice two people on on a table continually picking up And dropping their phones. Why wouldn’t they simply whisper to each other in that scenario?
The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle changes in brightness reflected off the wall.
Is this feasible now?
Old BBC documentary on the topic
You are misusing the term. TEMPEST is an attack.
> Perhaps vibrate mode on one phone being picked up by the accelerometer of another?
At very close distance vibrating our vocal cords and eardrums would be much easier and works without battery.
Thats what encryption[1] is for.
then you have heavy stuff, people trafficking, bomb threats, suicide threats, organ trade, child abuse, and crypto seriously limits the options for a response. as long as we're talking about functioning democracies, it does more bad than good.
Edit: to clarify their marketing is transparently targeting organizers of street violence. I have no problem with encryption and don’t think government forbidding it is a good idea.
Also, please remember "Please don't comment about the voting on comments. It never does any good, and it makes boring reading"[1].
So, congratulations, I guess, on being privileged enough that your interests have always aligned with the interests of the state.
Also, privacy this app helps to protect is a fucking human right too. You're not welcome here, please leave.
The cops already have radios.