Reset the Net Privacy Pack
pack.resetthenet.org
pack.resetthenet.org
Instead of having a local javascript, they want you to make sure all your visitors load it from members.internetdefenseleague.org or fightforthefuture.github.io
The main site is not privacy protecting either. Leaking to Optimizely, Amazon, YouTube, Heroku, Cloudflare, taskforce.is, Typekit.
Optimizely helps the team at FFTF A/B test wording. I was asking to remove that sooner too, but it adds a lot of value for them, so that stayed. I'm with you there.
Amazon Web Services power a lot of the internet.
YouTube only gets loaded if a user clicks "Watch Video".
Heroku only gets loaded if you submit your email in the top form.
Cloudflare helps power a lot of the internet. (HN, for example)
Taskforce.is a trusted partner, who offered to lend us Piwik hosting for this project. FFTF is hoping to set up their own server in the future.
TypeKit... that's where "Proxima Nova" is served from. The main designer at FFTF, Vasjen, made this awesome design using Proxima Nova and... we just all got attached to that font. I agree though, hosting all of the custom fonts would have rocked.
---
The point of the site, isn't to coddle people, and tell them that this little corner of the internet is safe, but not to go anywhere else. Sorry, but the reality is, to attain privacy, users need to take action. Installing the Tor bundle, for instance, which includes NoScript. Ghostery is another good one.
Also, when you criticized the usage of AWS, Clouflare, and Heroku... were you making the point that high visibility sites should be self-hosted?
Sadly that is true and sadly that site is part of that problem.
I think Sprint's main point was the "please embed our javascript" part though. For what reason is that not meant to be self-hosted?
Reset the Net is a step forward. A step, on a journey towards a society which stands up for itself, by taking action.
The purpose is to showcase all of the awesome companies who really care about privacy, and showing users methods by which they can increase the privacy in their electronic communications.
There's really no pressure for you to embed any JavaScript.
Yes but they don't exist.
TextSecure looks perfect but has been "coming soon to iPhone" for a year. It seems to be a long way off if I look at the GitHub activity (https://github.com/WhisperSystems/TextSecure-iOS)
I'm not sure why this is, exactly. Maybe there aren't enough iOS developers willing to donate their time to open source projects?
A real pity. The only way we have a chance is if the basic tools we use are cross-platform, open-source, and verifiably end-to-end.
Text Secure for Android uses Google's Push Messaging Service which queues messages when devices are offline for transport.
Apple's push messaging service can't be used in an analogous way because it only delivers the most recent message when a device comes online.
You certainly could help with the server side work. Otherwise, the UI, crypto etc... of the iOS app is all done.
This should not actually be a complicated inquiry.
http://www.theguardian.com/technology/2014/may/27/-sp-privac...
“You can't solve social problems with software.” – Marcus Ranum
ps: actually, it is worse: https://www.defcon.org/html/links/dc-archives/dc-18-archive....
http://benjamin.sonntag.fr/Moglen-at-Re-Publica-Freedom-of-t...
The page linked for "our criteria" doesn't mention any criteria other than:
We need tools that a broad community of experts can get behind.
I don't know of a single expert that would recommend Pidgin. I strongly recommend against it, whether you believe you are a "specific target of surveillance" or not.
What is the value of encrypted communications when your system is closed and presumably compromised (Windows, iOS, OSX)?
Also, why are they suggesting that you write down passwords? For that matter, why passwords at all? Passphrases are easier for people to remember for the same amount of entropy.
That is true if you compare them directly, but if you have a different pass(word|phrase) for each service it doesn't matter anymore, you can't remember more than a limited number of passphrases (unless you use common and predictable phrases I suppose, but then they're easier to crack).
Crypto is worthless if intelligence agencies of serious/powerful nations (guess: ~20 around the world), top blackhat groups or a small number of people working at the respective software companies are interested in your data.
Stealing data from your box through a backdoor might be relatively simple and automated, but it's still an order of magnitude or two harder than just analyzing the plaintext sent to someone's server.
Specifically, telling to enable the two-factor authentication to protect against government snooping makes no sense whatsoever. So this is either just an amateur "OMG, they are spying on us, let's do something secure!!" campaign or it has secondary objectives. My bet is on latter.