Skip to content

2026

Eight new tools on the docs site, all running in the reader's own browser

We are a group of volunteers working on anonymity networks and internet freedom, based in Taiwan. We maintain this documentation site, a practical guide to privacy and anonymity sorted by scenario for everyday life, sensitive work and high risk.

The articles on this site explain how to protect yourself. The tools section holds the things you can actually press. All eight compute in the reader's browser, send nothing anywhere, and keep working with the network off once stored on a device.

The tools index, eight cards each naming a tool and what it is for

The Anonymity Networks Community Is Going to Global Gathering 2026

Global Gathering 2026, hosted by Team CommUNITY, runs from 4 to 6 September in Estoril, Portugal. We applied for a booth and the slot is now confirmed.

  • Date and time: 6 September, 13:00 to 15:00 WEST (UTC+1, Portugal local time during the event)
  • Location: Booth 6 in the Regional Perspectives Village, 3 x 3 meters
  • Booth title: anoni.net Hub: Sinophone Asia-Pacific Networked Freedom

Event details are at Global Gathering 2026.

What the Global Gathering is

The Global Gathering is an annual event hosted by Team CommUNITY. It draws people from around the world whose work covers digital rights, internet freedom, and protecting civil society from digital attacks.

There is no main stage and no keynote, and the three days are built out of Circles, Meetups that bring together a region or a shared topic, and Booths open to anyone walking past. Villages then group those activities by theme, such as Circumvention Tech, Digital Security, and Regional Perspectives. Our booth sits in the Regional Perspectives Village.

Why we are taking part

This is our first time at the Global Gathering, and the main hope is to meet more people, both technologists developing anonymity networks and other circumvention tools, and others working across the Asia region.

We are a group of volunteers who care about anonymity networks and internet freedom, starting from Taiwan, and what we do covers keeping journalists' sources protected, letting activists organize without leaving traces, and helping people support sensitive causes without exposing who they are. All three rest on having an anonymity network that works. We run the Matrix home server im.anoni.net and this docs site, which keeps our observations and discussions somewhere they can be checked.

The community counts from the anonymity network workshop we ran in August 2025, where the first group of members came together. Three threads are open in 2026, with practical privacy guides sorted by scenario for everyday life, sensitive work, and high risk, campus Tor relays pushed forward together with EFF and the Tor Project and one already running at National Taiwan Normal University, and the anonymous payment work we are bringing to the booth.

Others across the Asia-Pacific work on the same problems, and so far each side has not known the other exists. Sinophone communities are spread across Taiwan, Hong Kong, China, Japan, and Southeast Asia, the situations they run into are connected, and opportunities to compare experiences are rare.

The other purpose is taking part in coordination across the region, since internet freedom work is rarely something a single community can finish, what any one of us can observe and maintain has limits, and most of these problems need more than one region to cover them properly. Establishing contact first is what makes working together possible later.

For the 30 minutes of mobile throttling in northern Taiwan on 13 August, we turned OONI's public data into a guided tour of what it recorded. Taiwan logged 238 connection speed tests from 47 devices that day, one of which saw its median download fall from 132,096 kbit/s to 1,223 kbit/s, and every query in the write-up runs without a key so anyone can recheck it. That record comes along to Estoril, and if anyone there is working on shutdowns or throttling, it is available for comparison.

We are bringing anonymous payment to the booth

The agenda went up in late August, and across the three days it covers shutdown response, circumvention tools, platform accountability, AI governance, and journalist safety. Having gone through the Circles, Villages, and Booths one by one, we found no session that takes financial privacy as its subject. Donor anonymity, cross-border disbursement, and what sanctions and currency controls do to civil society appear in no session title or description. A few sessions do take fundraising strategy and grant applications as their subject, where the focus is getting money in. How a payment reaches its recipient without exposing them goes unaddressed.

Sanctions lists, banks refusing to do business, donation records being subpoenaed: these are day-to-day realities for many organizations, with no matching discussion anywhere on the agenda.

We are making anonymous payment the main topic at our booth. As a community we are still at the research stage, gathering real situations, including who needs an anonymous money trail and under what circumstances, where current practice breaks down, and what limits regulation and compliance impose.

The people we would especially like to talk to:

  • Operators with cross-border disbursement experience: particularly where the recipient sits in a high-risk or sanctioned region.
  • Organisations that have dealt with donor anonymity: who know where the current tools fall short.
  • Projects blocked by financial controls: unable to receive support because a bank refused them or currency rules got in the way.
  • Anyone following the topic in research or advocacy: the regulatory side included.

Please just walk up during the booth slot, with no appointment and no prepared topic needed, and topics other than anonymous payment are just as welcome. The booth is meant to work as a regional meeting point, so that people in the room can find each other.

Another team from Taiwan is at the Gathering

Cofacts is here too, at Booth 10 on 6 September, 13:00 to 15:00 WEST, the same two hours as our own slot. They are showing Cofacts.ai, a multi-agent AI framework built on top of the crowdsourced fact-checking community and chatbot they have run for years.

The two subjects meet in the same place. A public sphere needs information that can be checked, and it needs a network that carries that information without exposing the people passing it along. Both booths are open the same afternoon, so please come to both.

Sessions on the agenda that overlap with our work

On anonymity and circumvention:

  • Technologist Meetup (4 September, 13:30 to 14:30) is where technologists working in digital rights and public interest technology get to know each other, hosted in the Circumvention Tech Village, and we are looking for people with experience maintaining measurement tools or self-hosted services.
  • Cross-Borders Storytelling: Device Searches, Metadata, and Collective Preparation compares experiences of device searches and metadata scrutiny across regions, and covers digital, legal, physical, and psychosocial preparation. Sinophone journalists cross jurisdictions often, and how others prepare is something we can put to use.
  • Can Signal Become Phishing-Resistant? addresses phishing aimed at journalists and activists, where the attacks abuse Signal's legitimate account recovery and device-linking workflows, with no software vulnerability required. How to write the risk in account recovery into a privacy guide is what we are after in this session.
  • Lights in the Tunnel: Co-Creating an Accountability Framework for VPN Transparency starts drafting a methodology for assessing VPN transparency and accountability, along with the providers to be evaluated. People keep asking us which VPN they can trust, so we want to know how that methodology turns into advice a user can act on.
  • Age Verification and Digital Identity Systems runs across two sessions, mapping how these systems are being rolled out and by whom, and discussing the harm-reduction pathways civil society can push for.

On measurement and regional coordination:

  • Strengthening Rapid Response Efforts to Censorship Events covers how groups around the world coordinate when censorship events emerge, including OONI's tools and methods for rapid response. We work with OONI's public data, and the August throttling write-up came out of the same methods.
  • Asia Meetup (4 September, 12:00 to 13:00) is a connection point for people working across the Asia region, and it is where we hope to meet others nearby working on adjacent problems.
  • Internet Shutdown Contingency Planning Help Desk builds a shutdown contingency plan around your own threat model, using the BRACE framework. Taiwan runs drills every year that give us something to compare against, and which parts of the framework connect is what we need to work out.
  • We See, We Archive, We Remember addresses how public-interest information can be preserved when it is being erased, drawing on archival work from Hong Kong, China, Iran, and Palestine.

Booths we plan to visit

  • The Onion Odyssey Cryptographic Universe is run by the Tor Project together with the Guardian Project (Orbot, Onion Browser), at Booth 22 in the Circumvention Tech Village, open all three days, and we want to hear about the friction Sinophone users hit with Orbot and Onion Browser.
  • Lockdown Systems brings OnionShare, which shares files, hosts websites, and runs chat anonymously over the Tor network, alongside Cyd for backing up and deleting social media history, and where a source gets stuck the first time they use it is exactly the kind of detail our privacy guides need.
  • Air Messenger is built on the MLS protocol, combining end-to-end encryption, low metadata, and a federated architecture, and since we run a Matrix home server ourselves, we want to know how far a federated setup can push metadata down.
  • Amnezia VPN shows their research on VPN blocking and DPI filtering, along with Amnezia Pulse for tracking shutdowns, and we want to compare our August throttling data against how they decide a shutdown is happening.
  • LEAP's MANTA measures tunnel health in censored environments, and we want to find out whether the same measurement approach fits the connectivity we see in Taiwan. Their booth (Booth 21) is open on 4 September only, 15:30 to 17:30, and a MANTA session runs in the Circumvention Tech Village earlier that day, 15:00 to 16:00.
  • po1ytech's polymorphic is an automated mirror system that keeps blocked independent media reachable, and we want to ask how much staffing it takes to keep running, because a volunteer community has limited capacity and sustainability comes first when choosing tools.

The full agenda is at Global Gathering 2026, and it runs far wider than what is listed here.

For those attending

Our booth is on the final day, which leaves no fixed spot for the first two days. Any of the following will reach us.

  • The Matrix room set up for the event is the most reliable, at #gg2026:im.anoni.net, where a message is enough to arrange a time and place, no phone numbers need to change hands, and we will reply as soon as we can during the event. Any Matrix account can join, so a free matrix.org account works and takes a couple of minutes to set up. Times in that room are in WEST unless someone says otherwise. Accounts on im.anoni.net are issued by a person and take a day or two, which is too slow for meeting someone at the venue, so do not wait on one.
  • Two sessions on 4 September are ones we will be attending, the Asia Meetup (12:00 to 13:00 WEST) and the Technologist Meetup (13:30 to 14:30 WEST), so meeting there works directly.
  • We will most likely be around for the Networking Hour, 12:00 to 13:00 WEST each day, though plans may still shift, so checking that room before you leave for Estoril helps. On 4 September that hour is where the Asia Meetup above sits, so it is one slot rather than two.
  • We will be at the venue for most of the three days, with anoni.net and a handle on our badges, so please do say hello.
  • The booth slot on 6 September, 13:00 to 15:00 WEST, is the easiest place to find us, and giving the name you go by is enough.

Taking part without travelling

Most people will not be travelling to Portugal, and there are still two things we can do together.

Please write down a coordination gap you have run into and send it to us, and we will take it along to compare against what other regions are seeing. Observations from Taiwan do not surface often at international events, and describing one concrete situation carries further than an abstract overview.

We would also like to hear real experiences of anonymous payment, so if you or an organization you know has dealt with small cross-border support, the trade-off between donation receipts and identity disclosure, or a recipient put at risk because a money trail identified them, that experience is what the booth needs. Anything you would rather not attach your name to can go to the anonymous mailbox below. We check it within a few hours across the three days of the Gathering, and reply within a day or two the rest of the time.

Beyond the event, all three threads for 2026 are short of hands. The privacy guides need people to sort scenarios and proofread, campus Tor relays need someone willing to ask about feasibility at their own institution, and the anonymous payment work needs more real cases. If you have compared the August throttling write-up against the raw OONI data and have something to add or correct, that is welcome too. Say which part interests you in the Matrix room.

Help pass this along

The booth runs for one slot only, and whether the right people walk past depends a great deal on how far word travels. If you know someone heading to Estoril, or there are journalists and open source community members around you working on these topics, please forward this to them, and there is no need to tell us first. If someone responds after you do, sharing that in the Matrix room helps us connect with them before we set off.

After the event

Whatever the booth collects will be written up and published in a later newsletter and on this docs site. We look at the situation a case arose in, and the people and the region involved stay out of anything published. Both the list of coordination gaps and the anonymous payment cases are de-identified first.

Channels

Brave flattens GPU fingerprints two opposite ways

Open a web page and the JavaScript on it can read your graphics card model, its driver details, and the hardware features it supports. Those answers barely change on a given machine, so a tracking company can combine them with other device traits into an identifier that needs no cookie, asks for no consent, and follows you between sites.

The graphics card is one source among many. Font lists, screen dimensions, time zone, and audio processing all feed the same identifier. A browser fingerprint cannot be cleared the way a cookie can covers how the whole mechanism works, why clearing cookies does nothing, and where each browser currently stands. This piece stays with the graphics card.

Brave has handled these signals since version 1.93, on by default on desktop and Android, rolling out in stages1. Three protections ship together: the WebGL vendor and renderer strings become one generic string shared by every Brave user, the WebGPU hardware description fields are cleared, and the list of supported WebGL extensions gets noise added to it.

The first two make every user look alike. The third makes one user look different on every site. Two opposite techniques arrived in the same release, each assigned to a different API, and where that line falls is also where Brave and Tor Browser part company on fingerprinting.

Two online sessions on digital security with Tian Jian, and the 26 August one is still open

Poster for the digital security and privacy series
Series poster by Tian Jian. Source: TJ Field School event page

Tian Jian's learning platform TJ Field School is running a two-session series on digital security and privacy. Toomore from our community gave the first session on 12 August, and Mashbean takes the second on 26 August. Registration is still open.

Both sessions are conducted in Mandarin Chinese.

Thirty Minutes of Mobile Throttling in Northern Taiwan, Read from OONI's Public Data

Measuring the mobile throttle of 13 August together

Taiwan has long gone without large-scale throttling or shutdowns. That is good for daily life, and for anyone trying to understand network anomalies it means there is no local sample to compare against. OONI is a long-running open source project measuring network interference and connection quality worldwide; anyone can install its app to contribute, and every result is published. Taiwan's record in that database has consistently shown a network working normally.

In the 30 days before 13 August, the three mobile carriers in Taiwan recorded 564 successful connection speed tests (the test is named ndt), with a median download of 12,425 kbit/s and only 4 measurements below 2,000 kbit/s, two of which were failures. kbit/s counts thousands of bits transferred per second — higher is faster, and 1,000 kbit/s is roughly 1 Mbps.

From 14:30 to 15:00 Taipei time on 13 August, mobile networks across seven northern counties were throttled for 30 minutes. Two days earlier the community put out a call asking people to run OONI Probe's performance tests during that window. Taiwan recorded 238 connection speed tests and 235 video streaming tests (named dash) that day, with 170 and 168 of them completed on mobile networks, coming from 47 devices. During the equivalent window at the central Taiwan drill on 10 August, the whole country produced zero mobile performance measurements.

The call started with community member mashbean, who proposed using the drill as a rare measurement opportunity. The two sides then prepared separately, one writing the call and the operating instructions, the other observing in the field on the day. He wrote his own record up as a separate post, which follows the network past the announced end of the drill and covers a period this dataset cannot see. Read together, the two posts span the full afternoon.

One Chunghwa Telecom Mobile handset measured 788 to 1,709 kbit/s during the throttle. Taiwan's public data had never shown figures of that order. It should be said up front that those figures come from 6 records left by a single device: enough to stand as one complete case, not enough to generalise to the country or to any carrier.

This post records network conditions. Whether carriers followed instructions precisely, and whether the officially published figure is accurate, are both outside its scope. Taiwan had no data on what throttling looks like, and preserving these 30 minutes is the point. Every query below works without authentication or an API key, so readers can run them again.

The most useful thing to come out of the analysis has nothing to do with throttling itself. It is a reading method: throttling and blocking produce completely different shapes in OONI data. Blocking sends anomaly rates up and leaves confirmed-blocking records behind, while throttling leaves the verdict fields untouched and shows up only in throughput and latency values. Taiwan's web connectivity anomaly rate that day was 1.0%, in the same band as the usual 0.6%, with confirmed blocking at 0 all day. Only speed went down. Describing a throttle through blocking anomaly rates returns a figure close to normal, and leads to the conclusion that nothing happened.

Recording 30 Minutes of Northern Taiwan's Mobile Networks During an Announced Throttle on 13 August

Measuring Taiwan's mobile network throttling drill

On Thursday 13 August, from 14:30 to 15:00 Taipei time (UTC+8), mobile networks in Keelung, Taipei, New Taipei, Taoyuan, Hsinchu City, Hsinchu County, and Yilan will be throttled for thirty minutes. The throttle is part of Taiwan's Urban Resilience Exercise, executed simultaneously by all three major carriers. Official announcements state that voice calls, SMS, and cell broadcast continue to work, and that high-bandwidth services degrade: video streaming, video calls, mobile payments, cloud sync.1 The advice for the window from the NCC (National Communications Commission, Taiwan's telecom regulator) is to prepare in advance for going offline.2

Officials have described the depth of the throttle twice. On 20 July, Defence Minister Wellington Koo told the Legislative Yuan (Taiwan's parliament) that speeds would drop to one percent of 4G and 5G capacity. After the central Taiwan drill on 10 August, the Executive Yuan (Taiwan's cabinet) described the method: carriers apply rate limiting in the core network, capping mobile download speeds at 256KB. The two statements are of the same order, and either one gives a figure to expect when the measurements come in.

The date, the window, the seven counties, the three carriers: every boundary of this throttle is public before it runs. Studies of network throttling rarely get that. In most cases users notice slowness first and researchers reconstruct the timeline afterwards, leaving the edges fuzzy. Pre-announced shutdowns are not new elsewhere, exam-period national shutdowns being the familiar example.6 On the publicly documented record, a pre-announced throttle is less common, particularly one with per-carrier granularity.

During the same window at the central Taiwan drill on 10 August, Taiwan's OONI observations contained no performance measurement from a mobile network at all. The northern drill is the last of this year's exercise, so after 13 August the opportunity does not come round again.

If you are in one of those seven counties, your phone is going to slow down for that half hour regardless. Rather than just waiting it out, you might as well leave a record behind.

Retracting what we published, and what changed on the docs site in the past two weeks

What changed on the docs site

Several pages changed over the past two weeks, and in most cases the change was to withdraw a passage rather than extend it. Hong Kong moved from medium to high risk for device inspection, the exemption for eSIMs bought outside Japan came out, a 2FA app we recommended turned out to have changed owners, and a blocking distribution drawn from 40 samples was recomputed over all 22,105. The site merged 50 pull requests between 27 July and 10 August, and a sizeable share of them went into corrections of this kind. What follows is page by page: what changed, what the evidence was, and a checklist in the middle for anyone who already prepared using the old guidance.

Snowflake gets a dedicated app, and the volunteer pool grew 29% in a month

Snowflake Volunteer promotional graphic showing several phone mockups of the app's enable toggle, settings screen, and statistics screen
Image source: Tor Project Blog.

We've written before that Snowflake is the lowest-barrier way to help people reach Tor: open a browser tab, leave it running, and you're relaying anonymous traffic. On 3 August, Tor Project lowered that barrier again with Snowflake Volunteer, a standalone Android app whose only job is being a Snowflake bridge.

Drawing an anonymity network onto a globe, the Interactive section and the open-data walls we hit

Tor Relay Globe

The docs site now has an Interactive section holding three pieces, all centred on Tor. The one carrying the most data is the Tor Relay Globe, which plots nearly ten thousand running relays onto a sphere. Over sixty percent of them sit in the United States, Germany and the Netherlands.

Building it meant checking more than twenty public datasets. Six made it in. Almost nothing failed for technical reasons: the APIs mostly worked and the formats were clean. What stopped us was terms that do not allow redistribution.

Defending the Public's Right to Know: A Sinophone Asia-Pacific Reading of OONI in Practice

This post sits alongside Tor Project's spotlight series article on OONI. The body below summarises what the original covers and then maps the same workflow onto Sinophone Asia-Pacific — the section the original does not cover, and the main contribution of this post.

For the full narrative on Kenya's High Court case, Tanzania's follow-up litigation, Meduza's public-education framing, and the supporting cases from Egypt, Jordan, and India, please read the original:

Visual header for the Tor Project 'Defending the free internet' spotlight series, featuring OONI
Image source: Tor Project Blog.