How to Combat Online Surveillance + More.

Luminous▼SovereignAug 5, 2017, 11:37:24 AM

Governments have transformed the internet into a surveillance platform, but they are not omnipotent. They’re limited by material resources as much as the rest of us. We might not all be able to prevent the NSA and GCHQ from spying on us, but we can at least create more obstacles and make surveilling us more expensive. The more infrastructure you run, the safer the communication will be.



Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say. - Edward Snowden



The NSA has built an infrastructure that allows it to intercept almost everything. With this capability, the vast majority of human communications are automatically ingested without targeting. If I wanted to see your emails or your wife's phone, all I have to do is use intercepts. I can get your emails, passwords, phone records, credit cards. I don't want to live in a society that does these sort of things... I do not want to live in a world where everything I do and say is recorded. That is not something I am willing to support or live under. - Edward Snowden




We all need places where we can go to explore without the judgmental eyes of other people being cast upon us, only in a realm where we’re not being watched can we really test the limits of who we want to be. It’s really in the private realm where dissent, creativity and personal exploration lie. -Glenn Greenwald



📺 Browser Recommendation

Mozilla Firefox : https://www.firefox.com/

Tor Browser : https://www.torproject.org/

Brave : https://www.brave.com/


Onion Browser, Surf the web through the Tor network with this open source browser for iOS. - https://mike.tig.as/onionbrowser/
JonDoFox, Private browsing with IP anonymization service and JonDoFox profile for Firefox. - https://anonymous-proxy-servers.net/en/jondofox.html


📺 Some good Firefox Privacy Add-ons

Privacy Badger is a browser add-on that stops advertisers and other third-party trackers from secretly tracking where you go and what pages you look at on the web. Privacy Badger learns about trackers as you browse by inspecting external resources websites request. - https://www.eff.org/privacybadger


Disconnect, Visualize and block invisible tracking of your search and browsing history. - https://www.disconnect.me/disconnect


CryptoCat, Encrypted instant messaging within your web browser. - https://crypto.cat/An efficient
wide-spectrum-blocker that's easy on memory, and yet can load and enforce thousands more filters than other popular blockers out there. It has no monetization strategy and is completely open source. We recommend Firefox but uBlock Origin also works in other browsers such as Safari, Opera, and Chromium. Unlike AdBlock Plus, uBlock does not allow so-called "acceptable ads". - https://addons.mozilla.org/firefox/addon/ublock-origin/
A Firefox, Chrome, and Opera extension that encrypts your communications with many major websites, making your browsing more secure. A collaboration between The Tor Project and the Electronic Frontier Foundation. Encryption with HTTPS EVERYWHERE- https://www.eff.org/https-
Emulates Content Delivery Networks locally by intercepting requests, finding the required resource and injecting it into the environment. This all happens instantaneously, automatically, and no prior configuration is required. - https://addons.mozilla.org/firefox/addon/decentraleyes/- . The following add-ons require quite a lot of interaction from user to get things working. Some sites will not work properly until you have configured the add-ons.


Stop cross-site requests with "uMatrix" - Many websites integrate features which let other websites track you, such as Facebook Like Buttons or Google Analytics. uMatrix gives you control over the requests that websites make to other websites. This gives you greater and more fine grained control over the information that you leak online. - https://addons.mozilla.org/firefox/addon/umatrix/


Be in total control with "NoScript Security Suite" - Highly customizable plugin to selectively allow Javascript, Java, and Flash to run only on websites you trust. Not for casual users, it requires technical knowledge to configure. - https://addons.mozilla.org/firefox/addon/noscript/


📺 Search Engines

If you are currently using a search engines like Google, Bing or Yahoo you should pick an alternative here.


StartPage, Google search results, with complete privacy protection. Behind StartPage is an european company that has been obsessive about privacy since 2006. - https://www.startpage.com/


Qwant, Qwant's philosophy is based on two principles: no user tracking and no filter bubble. Qwant was launched in France in February 2013. Privacy Policy. - https://www.qwant.com/


searx, An open source metasearch engine, aggregating the results of other search engines while not storing information about its users. No logs, no ads and no tracking. - https://searx.me/ 



📺  File Encryption.

If you are currently not using encryption software for your hard disk, emails or file archives you should pick an encryption software here.


VeraCrypt - Disk Encryption, VeraCrypt is a source-available freeware utility used for on-the-fly encryption. It can create a virtual encrypted disk within a file or encrypt a partition or the entire storage device with pre-boot authentication. VeraCrypt is a fork of the discontinued TrueCrypt project. It was initially released on June 22, 2013. According to its developers, security improvements have been implemented and issues raised by the initial TrueCrypt code audit have been addressed. - https://veracrypt.fr/


GNU Privacy Guard - Email Encryption, GnuPG is a GPL Licensed alternative to the PGP suite of cryptographic software. GnuPG is compliant with RFC 4880, which is the current IETF standards track specification of OpenPGP. Current versions of PGP (and Veridis' Filecrypt) are interoperable with GnuPG and other OpenPGP-compliant systems. GnuPG is a part of the Free Software Foundation's GNU software project, and has received major funding from the German government. GPGTools for Mac OS X. - https://www.gnupg.org/



PeaZip - File Archive Encryption, PeaZip is a free and open-source file manager and file archiver made by Giorgio Tani. It supports its native PEA archive format (featuring compression, multi volume split and flexible authenticated encryption and integrity check schemes) and other mainstream formats, with special focus on handling open formats. It supports 181 file extensions (as of version 5.5.1). - http://www.peazip.org/

Worth Mentioning


  • Cryptomator - Free client-side AES encryption for your cloud files. Open source software: No backdoors, no registration.
  • miniLock - Browser plugin for Google Chrome / Chromium to encrypt files using a secret passphrase. Easy to use. From the developer of Cryptocat.
  • AES Crypt - Using a powerful 256-bit encryption algorithm, AES Crypt can safely secure your most sensitive files. For Windows, Mac, Linux and Android.
  • DiskCryptor - A full disk and partition encryption system for Windows including the ability to encrypt the partition and disk on which the OS is installed.



 📺 Encrypted Instant Messenger.

If you are currently using an Instant Messenger like WhatsApp, Viber, LINE, Telegram or Threema you should pick an alternative here.


Mobile: Signal, Signal is a mobile app developed by Open Whisper Systems. The app provides instant messaging, as well as voice and video calling. All communications are end-to-end encrypted. Signal is free and open source, enabling anyone to verify its security by auditing the code. The development team is supported by community donations and grants. There are no advertisements, and it doesn't cost anything to use. - https://signal.org/


Wire, Wire is an app developed by Wire Swiss GmbH. The Wire app allows users to exchange end-to-end encrypted instant messages, as well as make voice and video calls. Wire is free and open source, enabling anyone to verify its security by auditing the code. The development team is backed by Iconical and they will monetize in the future with premium features/services. Caution: The company keeps a list of all the users you contact until you delete your account. - https://get.wire.com/


Desktop: Ricochet, Ricochet uses the Tor network to reach your contacts without relying on messaging servers. It creates a hidden service, which is used to rendezvous with your contacts without revealing your location or IP address. Instead of a username, you get a unique address that looks like ricochet:rs7ce36jsj24ogfw. Other Ricochet users can use this address to send a contact request - asking to be added to your contacts list. - https://ricochet.im/

Worth Mentioning


  • ChatSecure - ChatSecure is a free and open source messaging app that features OTR encryption over XMPP.
  • Cryptocat - Encrypted open source messenger. Supports file sharing and multiple devices. Available for Windows, Linux and Mac.
  • Kontalk - A community-driven instant messaging network. Supports end-to-end encryption. Both client-to-server and server-to-server channels are fully encrypted.
  • Conversations - An open source Jabber/XMPP client for Android 4.0+ smart phones. Supports end-to-end encryption with either OMEMO, OTR or openPGP.
  • List of OTR Clients - Wikipedia



📺 Encrypted Video & Voice Messenger.If you are currently using an Video & Voice Messenger like Skype, Viber or Google Hangouts you should pick an alternative here.

Linphone, Linphone is an open source SIP Phone and a free voice over IP service, available on mobile and desktop environments and on web browsers. It supports ZRTP for end-to-end encrypted voice and video communication. - http://www.linphone.org/


Wire, Wire is an app developed by Wire Swiss GmbH. The Wire app allows users to exchange end-to-end encrypted instant messages, as well as make voice and video calls. Wire is free and open source, enabling anyone to verify its security by auditing the code. The development team is backed by Iconical and they will monetize in the future with premium features/services. Caution: The company keeps a list of all the users you contact until you delete your account. - https://get.wire.com/

Worth Mentioning


  • Jitsi - Jitsi is a free and open source multiplatform voice (VoIP), videoconferencing and instant messaging application.
  • Tox - A free and open-source, peer-to-peer, encrypted instant messaging and video calling software.
  • Ring (formerly SFLphone) - Gives you a full control over your communications and an unmatched level of privacy.



📺 Encrypted Cloud Storage Services.

If you are currently using a Cloud Storage Services like Dropbox, Google Drive, Microsoft OneDrive or Apple iCloud you should pick an alternative here.


Seafile - 100 GB Storage for $10/month, Seafile offers 100 GB Storage for $10/month but also gives you the opportunity to host on your own server. Your data is stored in Germany or with Amazon Web Service in the US for the cloud version. Encrypt files with your own password. - http://seafile.com/


Nextcloud - Choose your hoster, Similar functionally to the widely used Dropbox, with the difference being that Nextcloud is free and open-source, and thereby allowing anyone to install and operate it without charge on a private server, with no limits on storage space or the number of connected clients. - https://nextcloud.com/


Least Authority S4 - For Experts, S4 (Simple Secure Storage Service) is Least Authority's verifiably secure off-site backup system for individuals and businesses. 100% client-side encryption and open source transparency. $25/month for unlimited storage. Servers are hosted with Amazon S3 in the US. - https://leastauthority.com/

Related Information


  • Cryptomator - Free client-side AES encryption for your cloud files. Open source software: No backdoors, no registration.



 📺  Secure File Sync Software.

SparkleShare, SparkleShare creates a special folder on your computer. You can add remotely hosted folders (or "projects") to this folder. These projects will be automatically kept in sync with both the host and all of your peers when someone adds, removes or edits a file. - http://sparkleshare.org/


Syncany, Syncany allows users to backup and share certain folders of their workstations using any kind of storage. Syncany is open-source and provides data encryption and incredible flexibility in terms of storage type and provider. Files are encrypted before uploading. - https://www.syncany.org/


Syncthing, Syncthing replaces proprietary sync and cloud services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. - https://syncthing.net/

Worth Mentioning


  • git-annex - Allows managing files with git, without checking the file contents into git. While that may seem paradoxical, it is useful when dealing with files larger than git can currently easily handle, whether due to limitations in memory, time, or disk space.



📺  Self-contained Network

.If you are currently browsing the Clearnet and you want to access the Dark web this section is for you.

GNUnet, GNUnet is a fully free P2P network. - https://gnunet.org/Orbot, The features and functionality of Tor for Android. - https://guardianproject.info/apps/orbot/


Tor Project, The Tor network is a group of volunteer-operated servers that allows people to improve their privacy and security on the Internet. Tor's users employ this network by connecting through a series of virtual tunnels rather than making a direct connection, thus allowing both organizations and individuals to share information over public networks without compromising their privacy. Tor is an effective censorship circumvention tool. - https://www.torproject.org/


I2P Anonymous Network, The Invisible Internet Project (I2P) is a computer network layer that allows applications to send messages to each other pseudonymously and securely. Uses include anonymous Web surfing, chatting, blogging and file transfers. The software that implements this layer is called an I2P router and a computer running I2P is called an I2P node. The software is free and open source and is published under multiple licenses. - https://geti2p.net/


The Freenet Project, Freenet is a peer-to-peer platform for censorship-resistant communication. It uses a decentralized distributed data store to keep and deliver information, and has a suite of free software for publishing and communicating on the Web without fear of censorship. Both Freenet and some of its associated tools were originally designed by Ian Clarke, who defined Freenet's goal as providing freedom of speech on the Internet with strong anonymity protection. - https://freenetproject.org/

Worth Mentioning


  • RetroShare - Open Source cross-platform, Friend-2-Friend and secure decentralised communication platform.
  • GNUnet - GNUnet provides a strong foundation of free software for a global, distributed network that provides security and privacy.



📺  Productivity Tools. Cryptpad,

Self-hosted, zero-knowledge, real-time collaborative documents. - https://cryptpad.fr/

Etherpad, Etherpad is a highly customizable Open Source online editor providing collaborative editing in really real-time. Etherpad allows you to edit documents collaboratively in real-time, much like a live multi-player editor that runs in your browser. Write articles, press releases, to-do lists, etc. - http://etherpad.org/


EtherCalc, EtherCalc is a web spreadsheet. Data is saved on the web, and people can edit the same document at the same time. Changes are instantly reflected on all screens. Work together on inventories, survey forms, list management, brainstorming sessions.. - https://ethercalc.net/


ProtectedText, ProtectedText is an open source web application. It encrypts and decrypts text in the browser, and password (or its hash) is never sent to the server - so that text can't be decrypted even if requested by authorities. No cookies, no sessions, no registration, no users tracking - https://www.protectedtext.com/

Worth Mentioning


  • dudle - An online scheduling application, which is free and OpenSource. Schedule meetings or make small online polls. No email collection or the need of registration.



📺  PC Operating Sys.

If you are currently using a operating system like Microsoft Windows or Apple Mac OS X you should pick an alternative here.

Arch Linux, Elegant, minimal, and flexible GNU/Linux distribution - https://www.archlinux.org/
ArkOS, Lightweight self-hosting for websites, email, files, and more on Raspberry Pi - https://arkos.io/
AntiPrism, Live USB/memory card OpenELEC-based media server toolbox platform for securing the online presence, web browsing and communications. - https://www.antiprism.ca/
Whonix, VM-friendly OS based on Debian and Tor focused on anonymity, privacy and security. - https://www.whonix.org/

Qubes OS, Qubes is an open-source operating system designed to provide strong security for desktop computing. Qubes is based on Xen, the X Window System, and Linux, and can run most Linux applications and utilize most of the Linux drivers. - https://www.qubes-os.org/


Debian, Debian is a Unix-like computer operating system and a Linux distribution that is composed entirely of free and open-source software, most of which is under the GNU General Public License, and packaged by a group of individuals known as the Debian project. - https://www.debian.org/


Trisquel, Trisquel is a Linux-based operating system derived from Ubuntu. The project aims for a fully free software system without proprietary software or firmware and uses Linux-libre, a version of the Linux kernel with the non-free code (binary blobs) removed. - http://trisquel.info/




Worth Mentioning


  • OpenBSD - A project that produces a free, multi-platform 4.4BSD-based UNIX-like operating system. Emphasizes portability, standardization, correctness, proactive security and integrated cryptography.
  • Arch Linux - A simple, lightweight Linux distribution. It is composed predominantly of free and open-source software, and supports community involvement. Parabola is a completely open source version of Arch Linux.
  • Whonix - A Debian GNU/Linux based security-focused Linux distribution. It aims to provide privacy, security and anonymity on the internet. The operating system consists of two virtual machines, a "Workstation" and a Tor "Gateway". All communication are forced through the Tor network to accomplish this.
  • Subgraph OS - Another Debian based Linux distribution, it features security hardening which makes it more resistant to security vulnerabilities. Subgraph runs many desktop applications in a security sandbox to limit their risk in case of compromise. By default, it anonymizes Internet traffic by sending it through the Tor network. Note: It is still in alpha, and much testing and bug fixing still has to be done.



📺 Live CD Operating Sys.

JonDo Live, Live CD/USB based on Debian with pre-configured tools for anonymous surfing and more. - https://anonymous-proxy-servers.net/en/jondo-live-cd.html


Tails, Tails is a live operating system, that starts on almost any computer from a DVD, USB stick, or SD card. It aims at preserving privacy and anonymity, and helps to: Use the Internet anonymously and circumvent censorship; Internet connections go through the Tor network; leave no trace on the computer; use state-of-the-art cryptographic tools to encrypt files, emails and instant messaging. - https://tails.boum.org/


KNOPPIX, Knoppix is an operating system based on Debian designed to be run directly from a CD / DVD (Live CD) or a USB flash drive (Live USB), one of the first of its kind for any operating system. When starting a program, it is loaded from the removable medium and decompressed into a RAM drive. The decompression is transparent and on-the-fly. - http://www.knopper.net/knoppix/


Puppy Linux, Puppy Linux operating system is a lightweight Linux distribution that focuses on ease of use and minimal memory footprint. The entire system can be run from RAM with current versions generally taking up about 210 MB, allowing the boot medium to be removed after the operating system has started. - http://puppylinux.org/

Worth Mentioning


  • Tiny Core Linux - A minimal Linux operating system focusing on providing a base system using BusyBox and FLTK. The distribution is notable for its size (15 MB) and minimalism, with additional functionality provided by extensions.



📺  Mobile Operating Sys.

Cyanogen, Aftermarket firmware for Android devices - http://www.cyanogenmod.org/
Firefox OS, Open source operating system for Android-compatible devices. - https://www.mozilla.org/en-US/firefox/os/
Replicant , Fully free Android distribution based on CyanogenMod. - http://replicant.us/

LineageOS, LineageOS is a free and open-source operating system for smartphones and tablets, based on the official releases of Android by Google. It is the continuation of the CyanogenMod project. - https://www.lineageos.org/


CopperheadOS, CopperheadOS is a hardened mobile open-source operating system by Copperhead Security and based on Android. It aims to provide stronger security and privacy. It also contains a hardened kernel and sandbox features for app isolation. Available for select Pixel and Nexus devices. - https://copperhead.co/android/


Sailfish OS, Sailfish OS is a mobile operating system combining the Linux kernel for a particular hardware platform use, the open-source Mer core middleware, a proprietary UI contributed by Jolla, and other third-party components. - https://sailfishos.org/

Worth Mentioning


  • Replicant - An open-source operating system based on Android, aiming to replace all proprietary components with free software.
  • OmniROM - A free software operating system for smartphones and tablet computers, based on the Android mobile platform.



📺  Open Source Router Firmware.

OpenWrt, OpenWrt is an operating system (in particular, an embedded operating system) based on the Linux kernel, primarily used on embedded devices to route network traffic. The main components are the Linux kernel, util-linux, uClibc and BusyBox. All components have been optimized for size, to be small enough for fitting into the limited storage and memory available in home routers. - https://openwrt.org/


pfSense, pfSense is an open source firewall/router computer software distribution based on FreeBSD. It is installed on a computer to make a dedicated firewall/router for a network and is noted for its reliability and offering features often only found in expensive commercial firewalls. pfSense is commonly deployed as a perimeter firewall, router, wireless access point, DHCP server, DNS server, and as a VPN endpoint. - https://www.pfsense.org/



LibreWRT, LibreWRT is a GNU/Linux-libre distribution for computers with minimal resources, such as the Ben Nanonote, ath9k based wifi routers, and other hardware that respects your freedom with emphasis on free software. It is used by the Free Software Foundation on their access point and router which provides network connectivity to portable computers in their office. - http://librewrt.org/

Worth Mentioning


  • OpenBSD - A project that produces a free, multi-platform 4.4BSD-based UNIX-like operating system. Emphasizes portability, standardization, correctness, proactive security and integrated cryptography.

DD-WRT - A is Linux-based firmware for wireless routers and wireless access points. It is compatible with several models of routers and access points.



📺  Social Networks.

The most commonly used social networks like Facebook and Google plus are allegedly involved in the PRISM program. Here are some alternatives you can use to protect your data.Minds, Open Source, Encrypted, community-owned, privacy and Internet freedom. - http://minds.com


Buddycloud, Open source, federated social network. - http://buddycloud.com/


RetroShare, platform offering IM, forums, VoIP, file sharing,  - http://retroshare.org/


Syndie, Distributed, anonymous forum software. - http://syndie.i2p2.de/


📺  VPN Client.

Encrypted virtual private network (VPN) technology can be used by ordinary Internet users to connect to proxy servers for the purpose of protecting one’s identity and online footprint. It's a great way to tunnel your traffic through remote servers, allowing you to properly encrypt your data and remain anonymous online.

OpenVPN, Free software VPN client. - http://openvpn.net/index.php/open-source.html


TunnelBlick, Tunnelblick is a free, open source graphic user interface for OpenVPN on OS X.  -


📺 VPN Servers.
Libreswan, Free software VPN client (3rd generation) derived from Openswan. - https://libreswan.org/


Tinc, Free software daemon that uses tunnelling and encryption to create a secure private network - http://tinc-vpn.org/


Openswan, Free software VPN client derived from FreeS/WAN. - https://www.openswan.org/projects/openswan/
📺  Disk Encryption.
cryptsetup, A convenience and ease-of-use layer for use on top of dm-crypt. - https://gitlab.com
DiskCryptor, High performance partition encryption software for Windows. - https://diskcryptor.net/wiki/Main_Page
encfs, File based encryption tool with support for GNU/Linux, macOS and Windows. - https://vgough.github.io/encfs/




.DNSCrypt, Secure communications between a client and a DNS resolver. - http://dnscrypt.org/

OpenNIC, Open, democratic, and anti-censorship DNS provider. - https://www.opennic.org/

Unbound, Validating, recursive, and caching DNS server. - http://www.unbound.net/


📺 Mobile Messaging

  • ChatSecure is an encrypted chat client for Android and iPhone.
  • iPGMail (iOS): app to send and decrypt PGP-encoded messages.
  • K-9 Mail (Android): open source mail app for android that supports PGP.
  • Signal (Android): open source application for encrypted voice and text communications.
  • SilentCircle (iOS, Android): encrypted voice, video, text, and file communications
  • Telegram (iOS, Android, Windows Phone, PC, Mac, Linux): encrypted messaging
  • Wickr (iOS, Android): encrypted, self-destructing text, picture, audio and video messages.



📺 Mobile Web

  • DuckDuckGo Search and Stories (Android): Secure, anonymous searches with Tor/Orbot integration.
  • Orbweb is an exceptionally privacy-focused web browser for Android, based on Tor.

Other Mobile Resources

  • Encrypt your Android phone.
  • CyanogenMod open-source alternative: to avoid leaving your phone vulnerable to your carrier's customization of the Android OS, consider replacing the firmware (on select phone models) with CyanogenMod.
  • APG is an OpenPGP implementation for Android phones.



➠ Don't use Windows 10 - It's a privacy nightmare

- Microsoft introduced a lot of new features in Windows 10 such as Cortana. However, most of them are violating your privacy.http://www.winprivacy.de/english-home/ - This tool uses some known methods that attempt to disable major tracking features in Windows 10.


➠ Know the Enemy

What is PRISM?

PRISM is a clandestine surveillance program operated under the United States National Security Agency (NSA). The program collects internet communications from more than nine major US internet companies. ​


What is XKeyscore?​

XKeyscore is a formerly secret computer system used by the United States National Security Agency used for searching and analyzing global internet data collected on a daily basis. The program has been shared and is used by Australia, Canada, New Zealand, German, and other countries. This program was revealed in July 2013 by Edward Snowden. ​


What is Tempora?

Tempora is the codeword for the a formerly secret computer system used by the British Government Communications Headquarters. The system is used to buffer internet communications that are extracted from fibre-optic cables, so these can be processed and searched at a later time. The existence of Tempora was revealed by Edward Snowden. 



Recommended Privacy Resources:

📺 Guides


Privacy is the right to a free mind.



