CHEF-KOCH's Microblog ✨

Privacy Tools List by CHEF-KOCH

The list is currently shortened until the split-up process between Tools and Mobile Apps is finished.

Please consider to donate to the actual developers, I do not take any money from you nor is this project designed to make any donations out from other peoples projects. It is more helpful to all of us if the mentioned developers receiving funding to push their projects.

3D Simulation

Advertising

Do not use any advertising service that comes from big tech corporations like e.g. Google Ads, Facebook/Instagram Ads or Bing Ads. These services aggregate and exploit user data by micro-targeting specific individuals. Online Ads produce 60 Megatons of CO2 every year.

Advertising Identifier (IDFA)

See here what it is. Background on how to Ban Surveillance-Based Advertising (pdf).

Advertising Opt-Out

Alarm Clock

Mobile Alarm Clock

Amazon Shopping Alternatives

Not so good in terms of privacy:

Privacy oriented alternatives:

Amazon Book Store

Not so good in terms of privacy:

Privacy oriented alternatives:

Audible

Audio Platforms for Music Streaming

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Music Streaming Apps

Self-Hosted Mobile Music Streaming Apps

Amazon AWS

AirPod Apps

Android Apps on Linux

Android microphone checker and jamming

Android App Management

Android Keyboard Apps

Not so good in terms of privacy:

Privacy oriented alternatives:

Apple App Store

Android App Store

Not so good in terms of privacy:

Privacy oriented alternatives:

Alternative Google Play Store Clients

Android Auto

Not so good in terms of privacy:

Privacy oriented alternatives:

Android Home Screen Launcher

Not so good in terms of privacy:

Privacy oriented alternatives:

Artificial Intelligence Tools

ASN Blocking

Avatars

Anti-Facial Recognition

You find a summary of Concerns About Clearview AI's Facial Recognition Product here.

Alternative Networks

Most network systems are by default not designed to be fully anonymous.

Alternatives to Shopify

Analytics Web Software

Is Google Analytics illegal in your country? website can quickly give you an insight if and your website is affected by recent law changes.

Not so good in terms of privacy:

Privacy oriented alternatives:

Animated Charts

Apple Motion

Apple AirPlay

Anti-Reflective Glasses

There are some benefits in using anti-reflective glasses. Make sure if you pick some, that they come with a CE & FDA certification. Do not buy some blue light filter glasses since there is no evidence that they actually help.

AntiVirus

Anime & Manga

AI Assistants

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile AI Assistants

App Isolation

Anti-Theft Protection

Archiver Tools

Auto Airplane Mode

Audiobooks

Audiobook Player

Mobile AudioBook Player

Audio Editing

Audit Database

Audit Tools

Mobile Audit Tools

Audio Recording

Mobile Audio Recording

Audio Tools

AI music

Not so good in terms of privacy:

Privacy oriented alternatives:

Audio VST

There is a huge list for Audio VSTs for Linux over here. There is also another awesome open source audio tools list here.

Audio Programming

Bible study

Business Cards

Bypass GeForce RTX „LHR“ anti-mining protection

Bookmark Management

Book Management

Browsers - A general starter

Please check the Browser + WebView Comparison Table before you use something. In general I do not list any clown forks who offers no or less benefits because you can do it yourself without depending on a third-party project (in most cases) or in other words the community doesn't really need two practically identical packages that accomplish the same thing. iOS has limited Browser choice.

Not so good in terms of privacy:

Browser Profile Backup Solutions

You can manually backup your profile or use some tools. Keep in mind that script based solutions can quickly corrupt your profile because the Browser might not be fully closed when you run the script.

Desktop Browser

Please keep in mind that projects like Ungoogled Chromium are hobby projects and cannot nor will ever compete against professional projects such as Brave Browser, simply because more manpower is involved in Brave's development. The only reason Ungoogled Browser is listed here is because some people do not like Brave Browser because they eg. do not use any crypto Wallet features (among other reasons).

Browsers are typically used as gateways to a lot of things and not only Browsing, because you can hear audio, play videos, use PWAs, edit code, flash ROMs with it among other things, the term Browser is also heavily aged and outdated, since the program is so heavily altered these days that it more acts like all-in-one tool. It should be noted that using an questionable web browser that is not actively developed or maintained only by a single developer or a small group can be dangerous. Sticking with a mainstream browsers like Chrome/Chromium, Brave, Firefox is better for various reasons.

Android & iOS Browser

All browsers on iOS must use Apple's WebKit to be allowed on the App Store.

Flash Browser

Adobe Flash is dead and has several security implications however, some might want to quickly Browse oldschool websites and looking for a Browser based solution instead of blindly downloading and executing unknown code on their machine.

Peer-to-Peer Browser

IPFS Browsers

Text based Browser

Web Browser Tools

Browser Benchmark

Browser Syncing

Redirect News, Search, and Weather Results to Your Default Browser

Browser Referrer Hider Tools

WebView alternatives

Browser Fingerprinting

Canvas Fingerprinting

Fingerprinting measurement

Please keep in mind that no detection tool or website or app is absolute, they have a database and based on that they check known methods which returns your score. Unknown methods might exist already in the wild and maybe not all methods are integrated into the database. By no means are those tools an absolute instrument to measure - total - privacy, they only give you an indicator.

Passive Fingerprinting

TLS Fingerprinting

Remote Fingerprinting

Other Fingerprinting

Browser Extensions

The list is not a "best practice" recommendation list for extensions/add-ons you shall install. The list is random without any logic behind.

Before someone wrongly interpret this as "he uses those listed extensions himself", this is not the case. If you look for someone else suggestions, I suggest to take a look at privacy-fighter.

Every custom extension and configuration you change makes your browser unique in its own way. See e.g. amiunique.

You do not need them if you have above listed extensions/add-ons installed or in case you use an up-2-date hardened browser. Additional info/comments are labeled next to the extensions/add-on.

Book Resources

Dev Books

Other interesting guides and books

Brain Computer Interfaces

Brightness adjustment Tools

Bug Trackers

Bulk Renaming

Backup Solutions

Mobile Backup Apps

Background Remover

Barcode Scanner

Mobile Barcode Scanner Apps

Benchmark

OpenBenchmarking.org provides a nice database for benchmark results, sadly it cannot be self-hosted.

Birthday Notifications

Bluetooth Auto-Off

Blockchain

Blockchain based Games

Blockchains are distributed, not decentralized. There's one central ledger. They have almost all the downsides of fully-decentralized systems.

BitTorrent clients

Mobile BitTorrent Clients

Code and Text Editors

Mobile Code and Text Editors

APK Editors

Hex Editors

Programming IDE

GitHub Copilot alternatives

Live coding

Censor Bypassing Tools and Frameworks

Deep packet inspection is dead, and here's why.

Mobile Censor Bypassing Apps and Frameworks

Cloud Storage

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Cloud Storage

Cloudflare Workers Alternatives

Covid Notification Apps

Covid Certificate Apps

Call Blocker and Spam Filter Apps

Call Redirect

Calculator Apps

Mobile Calculator Apps

Camera Apps

Contacts & Calendars

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Contacts & Calendars

Crowdfunding, Community, & Self-Publishing Platforms

CAPTCHAs

Not so good in terms of privacy:

Privacy oriented alternatives:

Cloaking and Steganography Apps

Image Steganography

Clipboard Manager

Mobile Clipboard Manager

CCleaner alternatives

Multi functional app to find duplicates, empty folders, similar images etc.

Color Choices

CSS Frameworks

Collaboration Platforms

Chromebook hardware alternatives

How to enable Linux on your Chromebook (and why you should).

Chromecast alternatives

Configuration Software for Developers

CMS

Comment Systems

Cryptocurrencies

Not so good in terms of privacy:

Privacy oriented alternatives:

Computer Vision

Car Diagnostic

Computer-aided design short CAD

Cryptocurrencies Trading Bots

Crashlytics Logging

Not so good in terms of privacy:

Privacy oriented alternatives:

Data Deletion Services

Database protection

Dating Sites

Dialer Apps

Domain Hosting Providers

Domain Registrar

You can unblock domains from security filters.

Domain Backup Severs

Bulletproof Hosting Service Providers

Bulletproof Domain Hosting Providers

Local hosting

Diagramming Software

Not so good in terms of privacy:

Privacy oriented alternatives:

Developer Tools

Mobile Developer Tools

Deezer Alternative clients

Data Recovery

Data Collection and Telemetry Studies

Image credit: bc + tcddublin

Designing things

Disqus alternatives

Disk Benchmark Tools

Disk Erasure

Documentation Generators

Document Scanners

Download Managers

Mobile Download Mangers

Deep Fakes Software

Deep Fake Protection

DNS and filtering

NextDNS will not get listed, they make money by limiting the DNS queries, their filter-list are integrated from GitHub based on other people work (and they do not donate to such projects). I absolute have no respect for this. Making money on behalf of other peoples work will not be tolerated on my list, they designed it to make money out of it not to help the community, the argumentation that you can use it free without buying for it (unless you hit the limit) does not change the fact that they steal other people filter-list (without asking if they even wanted to be listed). It would be different if they would fully open it up and accept donations, but that is not the case. BlahDNS/youtube-dl (as example) also do not limit stuff and then forcing you to pay for it to "unlock" additional stuff, it would be unthinkable.

There is also another reason, you cannot self-host it.

Self-hosted DNS

Mobile Ad-blocking

DNS Servers

Do not blindly apply into any third-party DNS server, there are variables to consider like latency, privacy & security as well as the region you are from. Since I am from the EU/Swiss I only can list a handful providers. Listing 3 alternatives for every country would be too much for my list.

Key factors about DNS-over-HTTPS or short: DOH

Not so good in terms of privacy:

Privacy oriented alternatives:

DNS Latency Matters

Docker alternatives

You can find an open-source home cloud that allows you to run Docker applications without coding here, it is called CasaOS. A Docker GUI is here.

Detect Trackers in Apps

Debuggers designed for testing and trouble-shooting

eSports Tools

eCommerce platforms

Event Hosting

eMail Clients

Desktop eMail Clients

CLI based eMail Clients

Mobile eMail Clients

eMail Encryption

Disposable eMail Providers

None of them will actually work for Twitter, Gmail, etc. because they use a blacklist and basically blacklist all public providers. The moment I would post some Russian providers who currently work the moment they would add them to their blacklist. Self-host or search for some Russian providers yourself but do not leak them to the public.

Email Alias Services (Anonymous Forwarding)

With email aliases, you can finally create a different identity for each website. Defend against spams, phishing and data breach.

Services with self-hosting options:

Services without self-hosting:

eMail Services

Comparison of different eMail services, please check this. And regarding security and emails check this. Self-host your own Email server.

Not so good in terms of privacy:

I will split the list in free-mailer and paid providers. Free mailer tend to use ads based systems to survive and are controversial because that might come with privacy implications.

Privacy oriented alternatives:

Nadim Kobeissi released an Analysis of the ProtonMail Cryptographic Architecture paper, covering ProtonMail specifically. However, the same principles can be applied to other web applications and providers such as Tutanota, BitWarden, Threema, etc. which attempt to provide E2EE through web browsers. LiveOverflow explained Nadim's paper, and why the scope of the E2EE bypassing mechanism isn't arbitrarily chosen.

Onion eMail Services

Self-hosting eMail Services

Mail Server

Alternative eMail networks

Encryption (File/FDE)

The general rule is that encryption is meaningless unless proven, integrating just encryption into a random product means nothing because Security is only as strong as the weakest link.

A Comparison of Encrypted Raid on Debian GNU/Linux is available over here.

Mobile Encryption (File/FDE)

Encryption for Small Businesses

The businesses environment is a bit different from the normal Desktop environment. More people are affected at the same time and your assurance company will target you in case there was an breach and ask you if that could have been prevented and if security holes were known and how it could have been prevented. In such a case audits are important to ensure that you did all the best to your knowledge based on a third-party experts inspection on used program, libaries etc. This brings you in a way better position, jurisdiction wise.

This section is absolute unfinished.

Container Encryption

Mobile Encryption (File/FDE)

Git encryption

Web based encryption tools

Electronic Design Automation (EDA)

Electron Framework Alternatives

Electron Framework is in general more heavy on resources compared to other solutions.

Ebook readers

Employee Monitoring

Educational Suites

Educational materials and Books for Students and Researchers

e-mobility

Fact-Checking Sites to Fight Misinformation

Fairtrade Smartphones

Flashlight Apps

File Searching

Not so good in terms of privacy:

Privacy oriented alternatives:

File Systems

Fonts

Not so good in terms of privacy:

Privacy oriented alternatives:

Font Editors

Find My Device

This category needs some work because lots of known-apps are years old and outdated, which means they might not work as intended on newer Android versions.

How are iPhones still findable even when turned off in iOS 15 – Explainer on how Apple devices with iOS 15 can b found even when turned off.

File Management and Sharing

Not so good in terms of privacy:

Privacy oriented alternatives:

Fitness and Health

Your health is a very important piece of your private data and you should care a lot about it. Also, health related data is among the most coveted. Please don't use apps from Google, Fitbit, Huawei, Xiaomi or any company that seeks the gathering of your personal data and come potential with other security risks.

Privacy oriented alternatives:

Mobile Fitness Apps

Fitness and Health Resources

FTP Clients

For mobile apps please check the file manager section, most file manager include such a function.

File-Sharing

Keep in mind that most services are not fully open source or their back-end is closed.

Mobile File-Sharing

Send files between devices

Self-hosted File-Sharing

You find an entire self-hosted list with search capability here.

P2P based file-sharing

File Manager

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile File Manger

Funding

Firewalls

Apple’s Private Relay can cause the system to ignore firewall rules.

Firewall analysis and anti-censorship bypass

Router Firewalls

Hardware based Firewall solutions

Router Firmwares

Mobile Firewall Apps

Some of the listed apps are not traditional firewalls. I decided included them anyway because the category is not that long. Please keep in mind that Netguard among other Android firewalls may not be entirely helpful with Android 10+ due to per app internet permission toggles.

Windows Firewall GUIs

Linux Firewall GUIs

Web Application Firewall

Firmware Analysis

GDPR Tools

Gaming Preservation

Game Launchers

Game Emulation

Mobile Game Emulators

Games without DRM

Game Platforms

Gaming Security

Generate Fake Web Browsing and Mitigate Tracking

GPS, WiFi sensor and network status

Google Alerts

Google Doodle alternatives

Google Earth

Google Flutter

Google Forms

Google Music

Google Kepp

Google Classroom

Google Sheets

Google Sites

Not so good in terms of privacy:

Privacy oriented alternatives:

Google Safetynet

Faking, spoofing, manipulating category for SafetyNet Attestation and other Android limitations.

There are some open source API's available to Google trends.

Google Workspace

Most tools are normally paid or freemium only because you need to put lots of time, effort and maintenance in such G-Suite alternatives.

Graphic Novels & Comic Books

Groceries

Mobile Groceries Apps

Governmental Petition Portals

Some, or most listed alternatives are using Cloudflare or are in general CL hosted. See below why CL is general controversial even tho the EU fully trust Cloudflare

Some common sites that are FOSS:

Controversial:

Guides connected to privacy, security or anonymity

You find a basic info page about Open Source Guides here.

Please keep in mind that some guides might be a bit older, however some still have meaning and you possible can learn from them in an historic context to see how certain stuff evolved, or stay the same. In general guidance are only as good as the author did the research on the given topic, which means that some things can be universally applied to specific threads and other guidance are specific to one or a few given examples.

I only delist links that is entirely incorrect or even dangerous to follow because security practical constantly evolves in both ways, positive ways and negative ways, which means new attacks emerge and new counter measurements also getting released because of the new threats.

IoT Security

iOS Specific Privacy Guides

Privacy Guides

Hardening Guides

Anonymity Guides

"Best Practice" Guides

Anti-Censorship Guides and Tools

Opsec Guides

Self-Hosting Guides

Security Guides

Hardware Monitoring

Hardware Recycling

Heroku Alternatives

HTTPS

This section is not finished.

Hardware Teardown Websites

Huawei Smartwatches Firmware and Apps

Intel Management Engine & AMD Platform Security Processor

me_cleaner does not disable ME altogether, it just removes some "suspicious" parts. Majority of code still remains there. Same with AMD PSP. You can't remove all of it as your CPU will not even boot. PSP disable is supposed to disable some additional parts.

Icon Libraries

Mobile Icon Libraries

Icon and SVG Tools

Pictogram Libraries

IMSI

Imgur & Photobucket

Not so good in terms of privacy:

Privacy oriented alternatives:

Investment Trackers

Individual Authors and Books

Internet Speed Testing

IPFS

Check which public IPFS gateway are currently online.

Instant Messaging

Please check out this website for comparisons, there is also another one here. Threema provides their own chart. The most complete chart is this one.

FBI document shows what data can be obtained from encrypted messaging apps, this is controversial but gives an solid overview.

Not so good in terms of privacy:

P2P based Messaging

No servers involved. Everything goes directly from one peer to the other peer. No point of failure or control. The features are reduced because of the lack of server, messaging can be slower.

Peer-to-peer communications reveal one's IP address to each other, so using a reliable VPN, proxy, or TOR is advised. Briar is an exception to this rule, as it uses either Bluetooth range or the local network it's connected to; else all traffic goes through TOR. Ones without servers are ideal, such as: Jami, Tox, Ricochet, Status, Scuttlebot and PSYC-2. Some are still in development and may be prone to bugs.

Keep these options in mind when communicating with your clique. Many of us belong to private groups on Telegram which are presumably free from moderator surveillance (or at least interference), but ultimately we should transition to a more durable platform that will be unable to censor our messages. Try a few out and see what works for you and your crew.

Instant Messaging Decentralized

No single point of control or failure. A decentralized network operated by different servers from different volunteers around the globe. You choose where your data stays or you can self-host your own server. Somewhat more complex protocols (because of federation between servers) and some extra metadata is added to the messages (without compromising privacy).

Instant Messaging Centralized

Instant messaging guidance for beginners:

The service is in charge of running the servers that allow users to communicate. Single point of failure and control, but still 100% safe and trustworthy if the protocols and code are open and audited.

Leaked FBI Docs Suggest Telegram Safer than WhatsApp, Threema and others, see picture and source below.

Image credit: therollingstone

Source for this is claim is here. For people saying Telegram isn't mentioned in the source article, click on the source document. It does cover various apps including Telegram. The document as PDF is hosted here.

iOS Keyboard

iOS Shell replacement

Kahoot Alternatives

Keybase Alternatives

In May 2020 Keybase was acquired by Zoom.

Key Remapper

Mobile Key Remapper

Learn Coding

Life360 Alternatives

Limit maximum Battery charging percentage

There are some Windows apps but this is depending on BIOS/firmware because the batteries work independently from the OS and unless this is implemented in the firmware itself there is no way to control this behavior. The workaround is to use different energy profiles but this depends on the manufacturer.

Linktree Alternatives

Literary Archives & Libraries

DRM-Free Book Stores

DRM itself is highly controversial and there is large history abusing it. It is overall privacy invasive and the efforts to protect the content is known to be ineffective.

eBook Publishers

Login sharing platforms

Log4j Alternatives

Logos

Location tracking

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile location tracking

it out and the results can be viewed in a browser.

Local Public Transport

Mobile Network-wide Inspection Apps

Malware Analysis

macOS Malware Analysis

Tools and utilities mentioned in The Art of Mac Malware by Patrick Wardle.

MongoDB alternatives

Marine Autopilot

Monitor Website changes

Microblogging

Blogging and Microblogging Tools

Medium Blog Alternatives

Meditation

Mind Mapping

Mesh networking

Maps and Navigation

Not so good in terms of privacy:

Privacy oriented alternatives:

Microsoft Exchange

Metadata Removal

Mobile Metadata Removal Apps

Media Player

DLNA Media Player

IPTV Player and Services

Mobile IPTV Player

Music Player

Mobile Music Player Apps

Music Player Daemon

Guitar Tablature Editor

Create Music with your Browser

Markdown editors

Math Teaching

Mozilla Pocket alternatives

Note taking apps

MAC Address Changer

MAC Address Online Lookup Database

NSFW Detection

NFT

Law professor explains how blockchains and NFTs don’t protect virtual property

Notes and Tasks

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Note Taking Apps

News Pages

Mobile News

News Groups

Network-wide ad & tracker blocking DNS servers

We do not list the original Pi-Hole project in this section since AdGuard Home does overall a better job and includes more features with a better UI.

Oculus Quest

Office Apps

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Office Apps

Opt-Out of Mobile ISP location tracking

Open Knowledge Projects

Operating Systems

Android

Try to avoid using Google Android or any Android that has been modified and tuned by any manufacturer such as Xiaomi, Huawei, Samsung, etc. Android is an Open Source project – AOSP – Android Open Source Project – and it has many versions that will respect the user privacy and data and won't share it with private servers from manufacturers or service providers.

It is important to use always the latest OS - if possible - there are several reasons e.g. Android 10 disallows Apps in general from third-parties to access critical stuff like IMEI, SIM, Serial Number, MAC etc. There are some small exceptions but overall it means that Google adopts certain problems and tries to solve them in the next versions which makes the OS by default more secure compared to older and easier attackable Builds.

Android Stock OS aka AOSP alternatives

It should clearly noted that most if not all listed alternatives that are based on AOSP are typically done to cash-grab others via donations with marketing phrases and unproven promises and claims like, use our product it is more privacy friendly or security optimised. Everyone can harden an OS, this is not some secret magic.

AOSP is under heavy development by more developers and overall more people are involved and claiming that you as individual person or small group do it better without even trying to submit patches to the original AOSP in the first place is not only rude and disrespectful but also ethical questionable, assuming yo believe in ethics. Forks usually tend to add no actual benefit into something unless done by professionals as well as people with an actual reasonable business model and independence, however most of the listed project highly depend on AOSP.

People tend to smear AOSP based on what vendors afterwards integrating and doing with it, e.g. adding bloatware apps etc. however you can compile AOSP yourself without any bloatware nor depend on another third-party identity such as GrapheneOS, CalyxOS, etc.

Hardening the OS yourself would be less of an mainstream problem if those who claim, in the name or privacy and security would submit their patches in public trough and open database. This is usually not the case and such people tend to lure people instead of their own websites, pages to pretend they do the most work, which is not only incorrect but also ethical questionable because the AOSP cares a lot about privacy and security and are reasonable in merging possible pull requests, assuming the patch actually fixes some hole, leak etc.

The underlying point is that those providers usually feeding off others people work, modifying it and claim privacy and security that are hard to proof for average users because they are not skilled enough to audit it themselves and often those claims cannot be verified because it consumes lots of time, research and in the meantime AOSP could have already addressed it trough a new patch-level set or entirely new major OS build. The ethical dilemma in using alternatives is that you need trust another unknown identity with unproven claims, while they claim they need money in form of e.g. donation to pay professional people to do an audit, which is the perfect excuse to collect donations luring people into using your product(s). Or in other words, use our product and support us and we show you can trust us afterwards when we got enough money to pay someone for an audit.

For example the GrapheneOS developer needs money to pay professional people to do an audit, while he claims, unproven, that his OS is more secure than others based on applying only best practices, while you could do this for yourself, assuming the team would release all of the modified AOSP patches. In such cases you simply need to keep his word as truth, because most people have no time, skill or knowledge to inspect the source code. Just because there is source code available does not conduct security because we had examples like Heatbleed when the source was years available and no one actually inspected it, which ended up leading people for years vulnerable. Open source therefore is not a guarantee for trust and security. The security lies heavily on the fact that actual people need to inspect your code, code that is complicated and you need the skills, time and research to come to an conclusion if it can be exploited. Facts that the teams does not communicate in public, because open source is no wonder weapon regarding security and never will be.

In truth the developers want to make a living out of it to continuing his job which is the reason they depend on money trough e.g. donations. This is at no time nowhere directly communicated.

The logic falls apart the moment you put every aspect in consideration because AOSP is a larger target and used by much more people than GrapheneOS, so mathematically, without even real world examples the claim that is more secure and private cannot be correct. Applying best coding practices and hardening alone also do not necessarily mean that your OS is more secure, for example if you touch known cryptography the opposite can happen, you end up more vulnerable. I also doubt such individual people and small groups in general because if they would actually fight for the mass they would help the AOSP Team directly so that everyone can benefit and use their code which is inspected by a bigger audience and used by lots of more vendors and users and not trying to cash-grab others based on Googles security practices, which are not GrapheneOS research and experiences.

In other words, give me money in form of donations because I claim my products are more secure and privacy friendly because I applied best practices. I am not really a friend of such claims and this has a wide history of been abused, it usually takes a while until someone figures such things out because, as mentioned inspecting things + have the knowledge to come to the conclusion how hard or easily something can be exploited is a real job and requires various skills. Unpaid people usually do not do all of this or are not involved.

Another point is breakages, when you apply best practices you usually break the entire eco-system, apps will stop working, you can only install various apps because the author decided to only approve certain apps, see the practice applied by Pale Moon developers who only approve certain extensions, or other dependencies simply stop working and you need to entirely trust such developers with their workarounds, workarounds no one typically inspect, audit or use, which automatically limits the target factor. The less it is known and used the less, mathematically it is insecure, this is just statistics, other consideration that even if there are holes, that the not automatically easily be exploitable are not even mentioned in such scenarios.

The whole story reminds me on the Telegram Crypto-Gram challenge - Cripple the AOSP with best practices so that nothing works and then claim security to sell the product. Here use my product because it is secure, there is no audit, I cripple and break all apps or sandbox it to pretend I know what I am doing....

Android GSI Images

Android Generic System Images (GSIs) are for app developers to perform app validation and for development purposes, which means they are bare naked images without anything e.g. GAPPS preinstalled. Since version 401+ OTA is supported for devices with dynamic partition.

Google Play Services Framework

Mobile OS based on Linux

Some Distros, mobile as well as desktop using Google Fonts, however there is no evidence that this influence and security or privacy related things for you. There are no hidden connections or analytics.

WearOS

Open Source Hardware

Open Source Hardware Association – The Open Source Hardware Association or in short: OSHWA aims to foster technological knowledge and encourage research that is accessible, collaborative and respects user freedom. This is the starting point for your research and to check open source hardware news. Another good overview is a list of open-source computing hardware.

Free Hardware and Free Hardware Designs explained. You find an Certified Open Source Hardware Projects list here.

Online Leak and Leakproofing Tests

Only unique tests are getting listed here, it makes no sense to list 1000+ pages who do all the same or offering absolute nothing new regarding fingerprinting/leaking.

OSINT Tools

You find a bigger list here: Nixintel's OSINT Resource List - A startpage with online resources about OSINT.

OS and Data Monitoring

Open Source privacy-friendly firmware replacement for Robot Vacuums (ie Roombas)

Open Source Games

Open source game engines

PCB Design Software

Pixel Editors

PDF tools

PDF merging

PDF Reader

Mobile PDF Reader

PDF Editor

PDF Document Scanner

Poll Systems

Payment Systems

Most payment systems are closed source or contain tracking or contain Cloudflare and CDNs behind their systems.

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Payment

Payments and Personal Finances

Not so good in terms of privacy:

Privacy oriented alternatives:

Micropayment and funded software

Pin Brute-Force Protection

Photo Editing and Management

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Photo Editing and Management

Projects you can join to help the make the world more sustainable

Privacy organizations and Cyber-Pirates

Consider joining and donating to one, several or all of the listed organizations, they actually fight for your digital freedom.

Proxy Tools

Mobile Proxy Apps

Privacy Policies Analysis Tools

Privacy Analysis Tools

Privacy relevant books and papers

Package Managers

Package delivery

Same like eMail aliases proxies, this is controversial since you share your data with another third-party that you must fully trust.

Paywall Bypassing

Planning

Plagiarism Checker

None of below listed tools or websites are FOSS. I plan to change that, however I prefer showing the tools who actually work and doing their job. If I find more - reliable - FOSS tools I will add them instead. That said I only drop the links as is until I reconstructed this category.

Well worth searching your GitHub URL with Google Scholar, which is a great way to find out if your code has made it into any academic publications.

Password Managers

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Password Managers

Password auditing and recovery application

Per-app anonymization

Period Tracker

If you need an app for menstrual cycle tracking please don't use any apps like Clue, Period Tracker, etc. Those cute pink apps are greedy for your menstrual cycle and intimate life data and will sell it for sure, protect your private life. Check the list below and you will find nice alternatives.

Plastic Scanners and Spectrometer

Plastics: Material-Specific Data

Photo Storage

Not so good in terms of privacy:

Privacy oriented alternatives:

Self-hosted photo storage

Third-party photo storage cloud options

Mobile apps for photo storage

Podcast

Mobile Podcast-Player

Podcast search engine

QR-Code Creator

QR-Code Reader

Mobile QR-Code Reader

Robotics

Radio

Root

Software Energy Consumption Measurement

Social Networks and Platforms

Historically, amplified speech (think Newspapers/Radio/TV etc) has always been highly controlled, not in terms of content, but in terms of who could contribute. With social media, this is uncharted territory as not everyone's opinion is equally valueable yet the impact it. It could have is massive. So censorship as the social medias imagine it (misinformation) has never been historically tested. Imagine if anti-vaxxers were allowed public platforms when polio was a thing. Would have been devastating to society.

In general social networks are fedpots. It should be noted that alternative clients and font-ends will still share your IP among some other metadata with the service as they make direct requests too, this means the Instance owner still can gather several data from you.

Discord clients

Your IP address and messages will still be shared and belong to Discord, the worst part is that they are not encrypted. Keep in mind that Discord monitors your voice calls in real-time. Keep in mind that Discord itself is on our NOPE list for various reasons.

Discord alternative Clients

Your IP and messages will still be shared and belong to Discord and they are NOT encrypted. Some alternatives listed are highly controversial.

IRC

You can combine Matrix with IRC via bridges. Keep in mind that lots of IRC Servers might blocking Tor connections to prevent abuse. IRCv3 server software feature support table, common privacy and security issues with IRC are explained here.

The main reason IRC or XMPP is listed and Matrix is not

Privacy oriented alternatives:

Mobile IRC Apps

Instagram

Instagram is a very privacy-invasive app with biased results and feeds based on user profiles, it is also used as a manipulation tool and has a lot of censorship going against free speech. Lastly, it has an addictive and toxic UI design. You can request your entire data over here.

Privacy oriented alternatives:

Instagram Alternatives

Alternative Instagram clients

Keep in mind that there are some problems coming from Instagram’s end.

Instagram Tools

Mastodon

Some Info:

Some tools:

Onlyfans

Onlyfans has a controversial history with handling user data.

Metaverse Alternatives

Why Facebook’s Metaverse Is A Privacy Nightmare.

TikTok

TikTok privacy is similar like every popular platform really bad.

Twitter

Avoid using Twitter official app or the website. It tracks users and creates user profiles based on what they follow, retweet and like. You can request your Twitter data over here. Since 2022 Twitter offers an .onion address.

Twitter alternative font-ends

Alternatives to Twitter

Federated social networks: A federated social network isn't a single website like Twitter or Facebook, it's a network of thousands of communities operated by different organizations and individuals that provide a seamless social media experience.

If you insist on using Twitter then use Tweeten, which is based on TweetDeck, that contains no tracking code.

Alternatives that work similar:

Mobile Twitter

Privacy oriented alternatives:

Alternative Twitter front-ends

Alternative Front-end Bots

Facebook

A developer created a nice little tool which is called "Unfollow Everything". You can also self-host your Facebook data. Facebook itself has serious implications.

Facebook Mobile Clients

Alternatives to Facebook

I do not list Gab because it is somewhat connected and infiltrated by alt-right people. There is many proof to backup my statement. Alternatives like SlimSocial for Facebook only render the website in an app and ad-block or CSS block specific elements, Facebook still can be monitor everything e.g. see your IP which is the reason such apps are not listed here.

Mediathek

IMDb

Reuters

Quora

XMPP Jabber - Free Servers

XMPP Compliance Tester allows you to gather some background information about servers before you join them.

Jabber Clients

XMPP clients highly depending on specific XEPs, those are basically extensions. An example is that without XEP-0198 you will be losing offline messages if your connection is unreliable.

About OMEMO

Are we OMEMO yet? – This list displays the progress of OMEMO integration in various XMPP clients. Same like IRC, XMPP has his own issues.

OMEMO alias XEP-0384 relies on XMPP PEP for publishing key information, so it will require changes to run over other protocols.

However, same like any other piece of code it can be complex, OMEMO is pretty large and has some flaws and integration problems. Another problem with OMEMO is that it depends on libsignal-protocol.js that is developed by Open Whisper Systems and possible prevents you from using it due to the license it uses and compatibility issues to other projects. OMEMOs audit is basically devastating and allows MITM attacks.

So in a nutshell:

That said pretty much every listed client here is far from ideal and I list them for individual reasons. Please review them and check what you need, if Audio and Video is a factor than e.g. Conversations is not yours, in that case Dino might be a better choice.

XMPP Server Software

Capy.life

Clubhouse

Pinterest

Reddit

Try to avoid using Reddit or at least avoid their official clients because there are plenty of trackers and ad-systems integrated. Reddit itself shares a lot unnecessary user data with their servers and partners. If you want to use it anyway I highly recommend you to use old.reddit.com or i.reddit.com URLs instead because it renders faster and is more privacy respecting than the new design.

Taking over abandoned Subreddits:

You can Use r/redditrequest to take over subreddits, and/or make new subreddits.

Reddit Clients

Reddit Alternative front-ends

Unblock Reddit

YouTube

Don't use YouTube (or their official client). YouTube is very privacy invasive, it generates a very accurate profile based on your interests. Also it is a radicalization tool which shows biased content to users in order to get more engagement and to get them to watch more and more content creating an addiction. It never shows you alternative opinions to your ideology/bias. YouTube censors a lot. YouTube collects a lot of your data: interests, free time, ideology, likes, dislikes, music taste, etc.

Privacy oriented alternatives:

Keep in mind that lots of alternatives that are so-called privacy friendly are quickly abused to spread propaganda, disinformation and is deliberately abused to re-host stuff that is removed by other more sophisticated platforms. Extremists simply love to abuse platforms to spread their propaganda.

YouTube Music alternative front-ends

YouTube alternative clients and front-ends

Assuming you use any alternative Instance and Service make sure to read the Privacy Policy of that specific Instance/Service first, assuming they have one.

Self-hosted YouTube media servers

Social Media Wiping

Please consider NOT to wipe your posts on Reddit and other forum based platforms, the reason is simply, people search for answers and if you delete yours after you got a solution people might not be able to find useful stuff. Instead I suggest to use alternative accounts, one for questions, one for work etc.

The overall best strategy is that you post only useful or helpful stuff on platforms which does not expose or compromise you, this way you do not need to wipe something afterwards and you help others.

Social Media Identity Privacy

Streaming Tools

Mobile Streaming Apps

Streaming Platforms (e.g. Twitch)

Avoid using platforms such as Twitch, Patreon, YouTube because they are very privacy-invasive with viewers and you. Instead, you can try using some self-hosted platforms that do take care of everyone's privacy.

Privacy oriented alternatives:

Mobile Streaming Platform Apps

Songs regarding Open Source

Sound effects

Speech (synthesis and recognition)

Silverlight

Spotify Alternative Clients

These clients, although will have less tracking, still DO NOT protect your privacy at all as you will still be streaming from Spotify servers from you own premium (paid, identified) account. The only workaround is to use faked accounts in case you use some downloader tools.

Spotify Alternative Mobile Clients

Spotify Download Tools

Speedtest.net Alternative

Smart TV

Not so good in terms of privacy:

Privacy oriented alternatives:

Operating System Suggestions

These are only a handful suggested Distros. I do not intent do list all distros that I think are usable, the list mainly list them because they are well maintained, usable for beginners + experts and they have lots of background, which indicates that they are reliable, secure, private and accepted widely in the privacy and security scene. It is not a bias based list which means other distros that are not directly mentioned are maybe even better or similar like the ones I choose to list. Do not bash other Distros because of my findings, keep the piece, thanks.

Not so good in terms of privacy:

Privacy oriented alternatives:

MacOS OS alternatives

Linux Distros for beginners or ex-Windows users

Not so good in terms of privacy:

Testing and reviewing Linux Distros:

Privacy oriented alternatives:

Privacy and Security hardened Distros

Distros for NAS

Distros for Gaming only

Linux Alternatives

Calculator Operating Systems

Data Center Alternatives

Distro for Developers

There is no definition regarding the term - for developers - I only list Distros here that are official advertised as such and the ones which I approved. Of course you can use any other distro for something else that developers can use but some are optimized explicitly for developers or they come with pre-installed tools to make it easier to work with on a daily basis.

Linux Distros for Raspberry Pi Gamers

Chromebook OS alternatives

Fire OS alternatives

Remote Access and Control

Not so good in terms of privacy:

Privacy oriented alternatives:

Reverse Proxy

Reverse Engineering

RSS and ATOM Reader

You can obtain a comprehensive aggregator for news feeds here.

Mobile RSS and Atom Reader

RSS-Bridges

Recipes

Reverse tethering

Rescue Disks

Closed Source Rescue Disks

Screensavers

Screen Recording

Mobile Screen Recording

Self-Hosting Providers

Search Engines

List of GitHub repositories and articles with list of dorks for different search engines. I do not list App Stores under Search Engines because I do not want to confuse the average user and to avoid useless discussion about semantics and content discovery.

Not so good in terms of privacy:

Privacy oriented alternatives:

Metasearch engines

Metasearch engines use another search engine's data to produce its own results from the Internet. There's a widespread misconception that meta-search engines are somehow inferior or unworthy.

Be careful if you use public instances, this applies to every self-hosted public instance, and is not an exclusive search engine warning. Similar like with Tor nodes, anyone with bad intentions can set up a “rogue” instance and potentially log user activity.

Certificate Search Engines

Enterprise Search Engines

Torrent Search Engines

Developer oriented Search engines

Exploit and leaks search engines

Web3 search engines

SMS

SMS is in general not secure by nature.

SMS Apps

Secure Shell (SSH)

Major problems with SSH are explained over here.

Statistics

Scanning and Pentesting (Network Forensic)

Thesaurus Alternatives

TV Streaming

Tracking

Two Factor Authentication (2FA)

2FA Directory: List of websites and whether or not they support 2FA. 2FA QR code generator can be of assistance, it can be combined with e.g. Aegis Authenticator.

Not so good in terms of privacy:

Privacy oriented alternatives:

Two Factor MITM and auditing

Two Factor Hardware Keys

Text Steganography

File Steganography

Translation

Not so good in terms of privacy:

Privacy oriented alternatives:

Alternative Google Translate front-ends

Alternatives for Google Translate on Mobile

Transcription

Tax Software

Open source tax software is a difficult topic with a lots of issues and concerns.

Text to Speech

Temporary App Permissions

Threat Monitoring

Tor Network

This section is not finished.

Major problems while using Tor:

Tor Tools:

To-Do Manager

Mobile To-Do Manager

Teamwork Tools

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Team Working Apps

Text Sharing

Disposable Text Sharing

Terminal Emulators

TLS/SSL Ciphers

Trust in Computing

Use your phone as your PC

Use your phone as a webcam

Most if not all tools and apps are not free because they usually work with a driver that needs to be signed by Apple and other platforms which is not entirely free nor an open process. There exist some FOSS tools and apps but they usually work pretty badly in terms of performance and quality.

USB Protection

UnifiedNLP back-ends for MicroG

If location (NLP) is not working, download and install this and enable High Accuracy Location and open SatStat. Wait for it to get your location. Don't close SatStat app instead minimize it and open MicroG Settings > Self-Check. All boxes should be checked.

USB ISO tools

Userscripts

Unit Converter

URL Shorteners

List of URL shorteners.

URL Unshortener

URL changer for YouTube, Twitter...

URL Protection Tools

VirusTotal scanners

Keep in mind that VT is owned by Google.

Virus Scanners - Online

Virtualization Machines

Virtual Reality (VR)

Virtual Private Server (VPS)

VPN

PrivacyTools, now called PrivacyGuides spreads misinformation regarding Five Eyes, 9 Eyes, and 14 Eyes jurisdiction. Over the years PTIO/PGIO updated their original statement a lot and it looks better today but it is still overall wrong because people tend to believe that they are more secure and private if they use services, tools etc. that are not connected to such countries, programs or cooperation's - in the real world, this is not the case. There is no evidence to backup such claim, it is more likely the opposite, there is evidence that this does not change anything at all as I will explain below in detail with one specific example, there are others but it would be too complex here to go into every single detail because most people are already overwhelmed with this one given example.

Example that criminals in the real-world would use

Assuming you choose a provider outside any of those alliances and countries and their real servers are not located in such countries or have any other partnership, there is still no guarantee that the provider is not forced by other laws and cooperation to hand over your data anyway. There are alliances which are not directly bound by data protection laws only, lets say you plan to kill someone and you choose to use provider X as assurance that your secret is safe, you really think they not going down on you? With they I mean e.g. Interpol, if they not already obtained evidence that you used provider X to plan or spread your plans to kill someone, such thinking is more than naive. Interpol will rain down on you, you can count on that and every country that is not working with one of those alliances works together with eg. Europol, Interpol and others. There is no country that does not work together with some organization across borders to hunt down criminals. There is no actual evidence that someone got away while planing and executing murder on the internet, it often took long but at the end everyone made a mistake and the feds got them, see Silkroad, even with Tor and other protection mechanism there is always something, human error or other variables. Thinking you are 100% protected and get away with it is naive, it takes time to hunt criminals down, yes but there was no case ever that survived for long, the moment the feds are getting involved you can basically say goodbye, see cases like Cyberbunker, Silk etc.

People can also secretly do illegal surveillance and sell such data or give it away for free. Jurisdiction wise it does not hold but if illegal obtained contain hard evidence for e.g. murder, they will anyway start an investigation even if they cannot directly prosecute you based on the illegal obtained data. This happened several times, one of the most known example for this is the Panama Hack.


If you do illegal stuff. that is forbidden in every country alias transborder crimes the jurisdiction argument alone does not matter and even if, they will bypass it because if the judge gets evidence that there is something that you are involved in, they can rule and force everyone to hand over all data or shut it down. This is okay because the Internet shall no place to help, support or advertise criminal activities.


Some more details

Nutshell

VPN Comparison

About WireGuard

WireGuard. has many, many issues, as explained here and here. Because of several flaws WireGuard does not get my overall approval at this point, their design goals also do not match with what most people in the real-world really want.

Credit - ProtonVPN Team

Overall except the smaller codebase, less battery draining among the less CPU power you need there is absolute no benefit over OpenVPN.

The main reason why some VPN provider adding it is not security, or privacy, it is in most cases speed and efficiency compared to IPSec and OpenVPN.

Self-manageable VPNs

Mobile VPN apps

VPN Providers

SCM Tools (Source Code Management)

Remember that just because you self-host doesn't mean you can ignore DMCA take-down requests (DMCA itself is obviously an US law, but many Western countries have similar laws). You can choose to ignore such DMCA requests if they decide to send one to your self-hosted website, but not honoring it means you think you're not infringing on their copyright and are willing to go to court over it. If they don't want to go this far, or you try to not include contact info, they'll probably first send a DMCA to your web host/registrar who will suspend your hosting/website unless you counter-notice, which still means you've got to be ready to fight a lawsuit. Note that Cloudflare forwards DMCA requests to your web host company, so you can't hide behind CF.

Not so good in terms of privacy:

Privacy oriented alternatives:

Here is a list of all alternatives in a simply chart to compare features.

Mobile Version Control Platforms

Video Conferencing

Not so good in terms of privacy:

Privacy oriented alternatives:

Video Streaming Platforms

Not so good in terms of privacy:

Video and Audio Streaming

Mobile Streaming

Video encoders

Video editors

Video transcoders

Watermark Tools

Wayback Machine

WhatsApp Alternatives

WebDAV

Mobile WebDAV

Webgrabber

Webcam Apps

Web3

Some notes regarding Web3.

Wallpapers and Images

Not so good in terms of privacy:

Privacy oriented alternatives:

Mobile Wallpaper Apps

Wallet Apps

Mobile Wallet Apps

Wallets Hardware based

You find an introduction into the hardware wallet market here.

Whiteboard

Wikipedia

Read more about the issue with Wikipedia on the Wikiless manifesto. Keep in mind that Wikipedia is a social media site where users (and people paid to influence politics) write articles, which can shape public opinion and even undermine trust.

Wikipedia Mobile

Weather Tools

Mobile Weather Apps

Windows 11 Useful Tools and Scripts

Do not even think about wasting my time submitting nonsense tools like e.g. "O&O ClownUp", most of them are closed source anyway and the ones who are FOSS seems mostly copy and paste imitations.

Windows 11 Desktop Shell Replacement

Windows 11 Taskbar Tools

Windows 10/11 Download Utilities

Windows Forensic Tools

Window Manager

WLAN-SSID: Opt-Out

Why Privacy matters?

NOPE Software and Services

Image credit: devrant + RMS himself

I will not add the following projects/software and I will not debate this. Don't make him cry again 😢.

Please keep in mind that every software and service is at some point fixable and just because they are listed under this section does not mean they cannot be relisted once the mentioned product fixed provided criticism.

🔝 Back to top 🔝

#chef-koch #guides #list #privacy #privacy-tools #security #security-tools #tools