FreedomBox Version 0.1 Released
freedomboxfoundation.org
freedomboxfoundation.org
Personally, I've set up a cheap router [1] with OpenWrt [2] with similar privoxy functionality, as well as a Wi-Fi hotspot and a webcam + motion(1) [3] for surveillance as an experiment. This might be an alternative if you want a small, low-power combination of hardware and software for privacy- or security-oriented applications right now. The hardware was sadly too slow to handle 2 FPS @ 720P video capture from a Microsoft LifeCam HD 3000 camera but it was usable with a 640x480 no-name cam from eBay.
I'm looking forward to mesh networking on OpenWrt.
[1] A TP-Link TL-MR3020; it's $35 where I'm at. I also had to use a powered USB hub and a USB flash drive for a pivot overlay file system.
[2] OpenWrt is quite possibly the most underrated Linux distribution from an administrative standpoint due to how it manages configuration and packages. See http://wiki.openwrt.org/toh/tp-link/tl-mr3020 for how it handles my particular router model.
I'm not sure it's a better solution for actual (black hat) hackers than paying for a VPS with a prepaid gift card or bitcoin (unless they need the webcam) but there's certainly some spy-movie appeal to it.
Last year I did a talk at BlackHat EU on abusing MiFi hotspots to do this, only using the hotspot to attack the wifi network and tunnelling back over 3G to an out of band C2. I've got a lot further since then and have working PoCs that can do this.
They're ugly, but they work and work well.
I would have certainly liked something less expensive to play with too, but this $160 thing has two USB ports and an eSATA port which will definitely make things somewhat more interesting -- my SheevaPlug has been struggling to keep up with the USB disk access... I also saw that there is Gig ethernet on this "devkit"-yellow-thing. I am almost convinced of getting one, but I will sleep on it just to make sure this is not just an empty geeko-consumerism moment.
Packaged up in an easy-to-use premade box, this could be killer. I've wanted something like it for some time.
Freedom-buddy uses the world class TOR network so that boxes can find each other regardless of location or restrictive firewall and then allows the boxes to negotiate secure direct connections to each other for actually sending large or time sensitive data. We believe this blended approach will be most effective at improving the security and usability of personal-server communications and all the services we plan to build into those servers. Web cleaning Our first service, a piece of software you can use today to start making your web browsing more secure and private, is called "privoxy-freedombox". This software combines the functionality of the Adblock Plus ad blocker, the Easy Privacy filtering list, and the (HTTPS Everywhere](https://www.eff.org/https-everywhere) website redirection plugin into a single piece of software to run on your FreedomBox. Combining these different plugins into software for your FreedomBox means that you can use them with almost any browser or mobile device using a standard web proxy connection.
Are they talking about Squid when they, "standard web proxy?" It seems quite a vague way to explain what's going on. Any insight here is appreciated.
Anyway, this seems like a more sophisticated approach since I last looked the freedomboax wiki. This looks promising.
Just to know...
Think of the FreedomBox as your personal cloud. Your box will be accessible from the Internet (via dynamic dns) and could handle your email and social shit, but all with the guarantee of not-being-the-product privacy.
I am really happy to see progress on this project. We (as a society) can finally start the //real// conversation about privacy in social media only once we have alternatives to fb and big G.
Until now, the "privacy in social media" debate has been phrased with this threat model in mind:
other user --> you.
F-that! The real threat model is: fb sysadmin --> you.
So yeah, this is what the FreedomBox is about... var getScript = function(url, success) {
var script = document.createElement('script');
script.src = url;
script.onload = success;
var head = document.getElementsByTagName('head')[0];
head.appendChild(script);
};
getScript("//ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js", function() {
var wrap = function(html, tag) {
var parts = html.split('\n')
var out = '<' + tag + '>' + parts[0] + '</' + tag + '>';
out += parts.slice(1).join(' ');
return out;
}
jQuery('#content li li').html(function(i, html) { return wrap(html, 'h4'); });
jQuery('#content ul > li').html(function(i, html) { return wrap(html, 'h2'); });
jQuery('li').css('margin-bottom', 3);
jQuery('body').css('line-height', 1.5);
});edit: http://www.kickstarter.com/projects/mbs348/diaspora-the-pers...
I know what you're saying though. I think this project was conceived long before the pi became a reality.
You're correct in that. Raspberry Pi was not around back then. Eben Moglen had a talk in the beginning of 2011, if I'm not mistaken that seems to have set this effort off.
Just saying.
I don't think this means one can create documents with a given md5 hash, but if you're concerned about people making software that impersonates your release, you definitely should start worrying about someone producing a compromised 'copy' of your software with the same md5 hash.