Skip to content

Privacy

Eight new tools on the docs site, all running in the reader's own browser

We are a group of volunteers working on anonymity networks and internet freedom, based in Taiwan. We maintain this documentation site, a practical guide to privacy and anonymity sorted by scenario for everyday life, sensitive work and high risk.

The articles on this site explain how to protect yourself. The tools section holds the things you can actually press. All eight compute in the reader's browser, send nothing anywhere, and keep working with the network off once stored on a device.

The tools index, eight cards each naming a tool and what it is for

Brave flattens GPU fingerprints two opposite ways

Open a web page and the JavaScript on it can read your graphics card model, its driver details, and the hardware features it supports. Those answers barely change on a given machine, so a tracking company can combine them with other device traits into an identifier that needs no cookie, asks for no consent, and follows you between sites.

The graphics card is one source among many. Font lists, screen dimensions, time zone, and audio processing all feed the same identifier. A browser fingerprint cannot be cleared the way a cookie can covers how the whole mechanism works, why clearing cookies does nothing, and where each browser currently stands. This piece stays with the graphics card.

Brave has handled these signals since version 1.93, on by default on desktop and Android, rolling out in stages1. Three protections ship together: the WebGL vendor and renderer strings become one generic string shared by every Brave user, the WebGPU hardware description fields are cleared, and the list of supported WebGL extensions gets noise added to it.

The first two make every user look alike. The third makes one user look different on every site. Two opposite techniques arrived in the same release, each assigned to a different API, and where that line falls is also where Brave and Tor Browser part company on fingerprinting.

Two online sessions on digital security with Tian Jian, and the 26 August one is still open

Poster for the digital security and privacy series
Series poster by Tian Jian. Source: TJ Field School event page

Tian Jian's learning platform TJ Field School is running a two-session series on digital security and privacy. Toomore from our community gave the first session on 12 August, and Mashbean takes the second on 26 August. Registration is still open.

Both sessions are conducted in Mandarin Chinese.

Section 702 Has Expired: A Sinophone Asia-Pacific Read on Warrantless US Surveillance

EFF's NSA eagle graphic, reworking the NSA seal into an eagle plugging its talons into telecom lines, representing warrantless mass surveillance
Image: EFF designer Hugh D'Andrade's "NSA eagle," which reworks the NSA seal into an eagle plugging its talons into the nation's telecom lines. From EFF's NSA spying work, licensed under CC BY 4.010.

This post is an anoni.net reading based on the EFF Deeplinks article:

At midnight on 12 June 2026, Section 702 of the Foreign Intelligence Surveillance Act lapsed1. EFF, which spent years arguing the program should require a warrant before the FBI reaches Americans' communications — or else expire — calls the lapse a victory1.

It is a real victory, and a narrow one. Section 702 was always built to collect the communications of non-US persons located abroad. That means everyone outside America — including readers in Taiwan, Hong Kong, mainland China, Macau, Singapore, and Malaysia — has always been a lawful target of this authority. The fight that just lapsed it was overwhelmingly a fight about protecting Americans. For the rest of us, the lapse changes much less than the headline suggests.

Android 17 ships: the real GrapheneOS story is who decides what runs on your phone

Android 17 and GrapheneOS: who decides what runs on the phone you bought
Image: a smartphone wrapped in a chain and padlock, standing in for a device locked down by outside rules. Photo by Towfiqu barbhuiya, via Pexels (Pexels License).

You paid for the phone, but what it can run and what it can install is increasingly not yours to decide. That question stays invisible until an app refuses to open because it "detected a non-stock OS," or an open-source OS you rely on gets harder to maintain because the hardware data behind it stops being public. Android 17 landed on 2026-06-16, and it pushed that question one step further.

For privacy-minded users, the OS in the middle of this is GrapheneOS: a hardened, de-Googled Android built on AOSP. It runs almost exclusively on Google Pixel hardware, and Google has spent the past year adjusting how open Android and the Pixel actually are.

Why this matters (especially in APAC)

This reads like a US/EU story about Google and Brussels, but it is close to home for readers across East and Southeast Asia and the Chinese-speaking world. Android 17's new sideloading "developer verification" flow is rolling out first in Brazil, Indonesia, Singapore and Thailand in 2026, expanding from there. Banking, payment and government apps across the region increasingly check whether a device is in "stock" state, and in mainland China that posture — device attestation plus real-name requirements — is already the norm. The losers are the same everywhere: people who want a phone they actually control.

OONI is guarding its data against bad measurements — what that means if you build on it

We build on OONI's public dataset. Our own work tracks how well Taiwan and the wider APAC region are actually observed in that data, and our Run v2 census mapped how the whole Run v2 ecosystem gets used. So when OONI published a long engineering post on [how it detects and mitigates faulty measurements]1 — alongside a new anonymous-credential system now rolling into production — we read it not as OONI insiders but as people downstream who use this data to make claims about a thinly-observed part of the world.

Here is what stands out from that seat.

Brief yourself before you travel — take the right questions to your own AI

Illustration: an AI assistant on the left gathers scattered data cards (Wi-Fi, location pin, lock, SIM, QR) and sorts them along dotted lines into a shield-framed pre-departure briefing panel on the right, with an airplane and a flight-path arc above

Before a trip you check visas, plug types, and currency. Few people check how the internet is controlled where they are going, whether their work is legal there, or who to call if something goes wrong. For journalists, human-rights defenders, NGO staff, and researchers, those are the questions that actually affect their safety, and the hard part is that you usually don't know what to ask before you leave.

Financial Companies as Censors: A Sinophone Asia-Pacific Reading of EFF's Transaction Denied

A piggy bank with its mouth taped shut, representing payment rails severed by financial intermediaries
Image from EFF Deeplinks article Former EFF Activism Director's New Book, Transaction Denied, Explores What Happens When Financial Companies Act like Censors (EFF Financial Censorship banner library), licensed under CC BY 4.0.

On 9 May 2017, the cross-border electronic payment service PayPal closed all domestic transaction functions in Taiwan. Two PayPal Taiwan accounts could no longer send money to each other. Cross-border transfers kept working. The streamer economy took the worst hit. Twitch Cheer, YouTube Super Chat, StreamLabs, and NightDev — tools that processed local audience tips through PayPal — went dark on the same day. Small organizations and independent media that relied on PayPal for domestic flows lost a payment rail overnight8.

The legal trigger was Article 3, Paragraph 1 of Taiwan's Electronic Payment Institution Management Act, passed in 2015. PayPal chose not to apply for a license and closed domestic functions instead9. Nearly nine years later, the U.S. online payment processor Stripe still does not allow individuals or companies in Taiwan to register. Stripe is the credit card collection layer behind Substack, many subscription SaaS products, and many open source sponsorship pages. Individual creators in Taiwan have to first register a U.S. LLC to use it10.

In Taiwan's payment conversation, these two facts have usually been filed under "compliance trade-offs" or "market size." EFF's former Activism Director Rainey Reitman, in her April 2026 book Transaction Denied12, compiles cases from 2012 onward across the U.S. and the Middle East. Stacked together, the cases reveal a cross-region, cross-issue pattern that's been running for more than a decade. Taiwan's two events belong in that record. So do parallel events from Hong Kong, mainland China, Macau, Singapore, and Malaysia, which Reitman's book — focused on U.S. and Middle Eastern material — does not yet cover.

What is Differential Privacy?

This article is based on the original explainer by fria at Privacy Guides:

Can you collect data from a large group of people while still protecting each individual's privacy? Differential privacy answers yes — with a mathematical proof to back it up. This article introduces the concept, traces its history from early anonymization failures to real-world deployments, and explores what it means for users and policymakers in Taiwan and the broader Chinese-speaking world.