Quantcast
Channel: CodeSection,代码区,网络安全 - CodeSec
Viewing all articles
Browse latest Browse all 12749

Riseup’s Canary Has Died

$
0
0

Popular provider of web tools for activists and anarchists and backbone of much infrastructure for internet freedom,Riseup.net has almost certainlybeen issued a gag order by the US government.

Riseup regularly updates a canary located here certifying that they haven’t received a gag order, court orders or the like. That canaryhas gone dead (ie has notbeen updated). In addition just before it expired Riseup posted a tweet with Cohen lyrics “ listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don’t listen to me ” and a tweet saying “ we have no plans on pulling the plug ” with a screencap of the segment of their FAQ that says they’d rather pull the plug on services than comply with surveillance. Of course this entry in their FAQalso says you should back up email in preparation for such a shutdown.

My read is that Riseup is complying with the gag order while fighting the surveillance demanded in court. Riseup is made up of long-time anarchist activists who would feel obliged to go to prison rather than collaborate in snitching out others. However there is a small chance someone could crack from threats of decades in prison. Additionally there’s a much more substantive chance that regardless of their optimism Riseup may soon be forced to close everything down.

This is an incredibly unfortunate development given the Riseup collective’s longstandingrole for many activists and radicals in providing email , listservs , VPNs , and assorted tools like Etherpad . However this should serve as a stark wakeup call about the dangers of relying on centralized services. The last decade has seen a collapse of the once varied and widely networked internet into a number of centralized services (like Facebook and Gmail, but also Riseup and Signal).

If you currently use Riseup you shouldn’t panic, but there are a number of productive steps you can take:

1) Backup all your emails on your Riseup account locally. This may require you to (install and) connect Thunderbird to your email account rather than just using the webmail through your browser. See this array of options for backing up while using IMAP. (Additionally it’s a good ideato enablefull disk encryption or separately encrypt your email back up. The EFF has guidesfor full disk encryption for windows . For Macs see this . Ubuntu, linux Mint and several other Linux variants provide full disk encryption as an option when first installing the operating system.)

2) Get another email address that you can use as a fallback. Resist.ca is based out of Canada (which doesn’t do you much good but at least some). Protonmail is based in Switzerland, although be a bit suspicious about the “encryption” claims they make, there are problems. There are many other email providers. Gandi is popular. Time to shop around or ― if you’re a confident sysadmin ― roll up your sleeves and run your own email server.

3) Set up another listserv with another provider if your group currently uses riseup for listservs. Resist.ca runslistservs .

4) You can set up email forwarding with Riseup. Either to pipe emails to your Riseup account to your new account or pipe emails to your new account to Riseup (if say you want to start popularizing a new email address but continue primarily answering through Riseup for the time being).

5) Remember that while some providers may encrypt emails once received on their server, all email is basically sent unencrypted between servers. Every email is a postcard, readable by nearly everyone. Unless you and the person you’re corresponding with use PGP. So use PGP. It can be daunting to set up and to get a handle on using (the user interface is infamously non intuitive), however PGPis very useful and provides a good baseline. Email is a federated (moderately decentralized) protocol in wide use that will thus be one of the last services shut down by authoritarians (unlike encryption services that use centralized servers like Signal). The EFF has good guides to setting up PGP for Linux , Windows , and Mac . And Micah Lee has a good overview of it .


Viewing all articles
Browse latest Browse all 12749

Trending Articles