Unofficial machine translation of the Italian original, produced for this restore — not by AvANa. For anything safety-critical, refer to the Italian version. Italian original.

Crypt'r'die

Restored from the project wiki (we.riseup.net), which is no longer online.


Crypt’я’Die

download the version in PDF

Repression and technology: an overview

That repression makes use of technology is nothing new. What we try to do in this chapter, then, is give an overview of the problem, trying to quantify it and to understand its risks and the room for action.

Who has something to hide?

Everyone.

A sea of sensitive information passes through your computer: the sites you visit, the people you talk to, the messages you exchange are monitored systematically, the better to “classify” you. The same goes for smartphones and tablets. With a little analysis it is possible to know who you are, where you live, who you spend time with, your routine, your “character”. This data can reveal your taste in music just as much as your political leanings: commercial profiling goes hand in hand with mass record-keeping.

It is not only a matter of protecting your identity, however, or specific facts connected to offences: by monitoring the network, the police are above all trying to work out who the most active people within a group are, in order to make countering them easier.

Is my data safe?

Computer security is a complex subject, so let us try to untangle it.

Your computer contains data. Whoever controls your computer has full access to your data. It is not so unlikely that someone will do so: physical access (computers left unattended) or software access (over the internet) happens every day.

Your computer communicates. Every time you chat, make a video call, write email, connect to social networks, send photos or listen to music, your computer exchanges messages with other computers and servers. Someone could listen to these communications.

Many of the services you use on the internet control your data. The companies (google, facebook, microsoft, yahoo…) keep track of every possible piece of information about you, and you can be sure they will forward it to the authorities as soon as it is requested. You are therefore delegating your data to their management. Do you trust them?

Finally, remember that managing your security is mainly a mental approach. Often you need to pay particular attention: for example when using a friend’s computer or those of an internet point you could leave your passwords there, allowing later visitors to see your data.

Keeping our feet on the ground

It is natural to wonder how realistic these problems are and who is actually in a position to carry out computer attacks in order to get hold of your data. Some attacks are within reach of many people, others require less common resources and skills.

For example, an intrusive colleague could read your email while you step away from the computer for a break. The police, on the other hand, prefer to seize your computer in order to carry out in-depth analysis: it is up to you to make sure that this analysis leads nowhere!

Different situations and different solutions, therefore, depending on the type of attack you become the target of.

Malware

We all know what a virus is. Malware is a program similar to a virus whose purpose is to gain control of your computer, turning it into a kind of highly technological bug.
This technique is used more and more by police forces all over the world, and it is decidedly the most powerful. There is some evidence of its use by the Italian police as well.

You can protect yourself first of all by no longer using proprietary operating systems (Microsoft Windows and Mac OSX) since they are decidedly more controllable than, for example, GNU/Linux (although careless use of Linux can carry risks too).

Similar problems are found in applications too; a significant example is Skype: it is in fact known that this program is not only monitored by police forces, but is actually used to monitor all of the computer’s activity. We can therefore say that Skype is malware.

Thanks to Wikileaks’ publications on the Spy Files page it is possible to get a picture of how widespread the global surveillance industry is.
On this page, on the other hand, we have begun to collect the investigations in which malware has been used as an instrument of interception.

Seizure

With a warrant, the police can seize computer equipment for the purposes of an investigation. When in doubt, the police seize everything they can (computers, USB sticks, cameras, recorders…).

After the seizure, the police take possession of everything they find on computers and hard disks. If the computer’s data is not encrypted, the police can easily get at the passwords you have saved on your computer, at your documents, at your history (browser, chats etc.) and, if you use a mail client, at your e-mails.

The best solution against this attack is to encrypt your disk.

Requesting data from the service provider

Most of the services you use are online: email, social networks and others.
The police can ask the companies that run these services for everything it is possible to know about a particular email address or a specific account: usually the contents of communications and the IP addresses the user connected from are requested. Even without a warrant.

Deleting data from our online accounts gives us no guarantee at all. For example, Facebook and perhaps other companies too keep on their servers a copy of the data the user has deleted from their account, for a certain period of time.
Other companies encourage the persistence of data on their servers. For example, GMail “discourages” the deletion of email by making a very large amount of storage space available to everyone and proposing the “archiving” of old communications instead of deleting them.

Interception

The communications you make over the Internet pass through your provider’s infrastructure (fastweb, alice, tiscali, …).
Some of these communications are “encrypted”, and it is therefore very complicated to read their content, but many others are not: these are described as “in the clear”.
In essence, a good part of your communications is perfectly readable by the administrator of your network as well as by the company that provides your connectivity.

Your ADSL or mobile telephony provider could also collaborate with the police, allowing them to monitor what you do. This monitoring technique is technologically less powerful than malware, given that the use of cryptography can block it.

From a legal point of view, this procedure is entirely equivalent to a “telephone tap”.

Legal

The search of computer equipment

How it works

If you are in a public place the police can ask to inspect your computer (or smartphone) without needing a warrant or a justification.

How to behave

As far as a laptop is concerned, a simple solution is to close the lid: most systems ask for a password to unlock the screen. At that point, if the password is not too easy (for example the same as the username) it will hardly be possible to get into the system through a simple search.

Remember that you are not required to give the password, quite apart from the fact that the possibility of not remembering it is always available.

For smartphones similar methods for locking the screen are available, often very simply.

The seizure

The case of a seizure is different: it is typically an organised event in which the police enter a home in order to seize objects useful to an investigation. A search of a home normally requires a warrant. It is however possible to be subjected to a house search without a warrant if it is aimed at looking for weapons or drugs; in that case the police cannot seize anything other than weapons or drugs.

Here are some recommendations:

  • Switch the computers off or “lock” them (for example by activating the laptop’s screensaver): this serves, more than for the seizure itself, to avoid a search being carried out as well.
  • Check that seals are placed on all the seized material, including computers, hard disks,…; if this does not happen, ask for it to be recorded in the report.
  • Ask for a party-appointed expert to be present during the seizure. Anyone can act as one (obviously a person with computing skills comes across as more credible).
  • Ask for a lawyer to be present.
  • If you are asked for your passwords you are not obliged to give them. Not remembering is better than refusing and taking a hostile stance. Bear in mind, however, that if the computer is not encrypted, all the passwords stored on it will be broken extremely easily – for example the Windows login one, or the password of your favourite online service.
  • If your computer is already switched on and is used by the police or by experts during the seizure, ask for it to be recorded in the report. All the more so if it was switched off and is then switched on.

After the release of the material (that is, when the equipment is handed back) do not switch the devices on under any circumstances, so as not to rule out the possibility of a counter-examination. Instead, notify a computer expert you trust.

Continues online

Recipes for your security

A secure computer

Using secure programs on an insecure computer is of little use; in the same way, no cryptographic technique will protect us from a trivial password. An armoured door is useless if you leave the key under the doormat.
What follows are recipes that always hold, whatever you want to do with your computer.

Leaving Windows and Mac behind

Configuration difficulty: medium (if you want to install GNU/Linux alongside another operating system), easy (if you want to install only GNU/Linux), very easy indeed (if you use freepto)
Day-to-day difficulty: medium
Useful against: malware

Malware is a program that performs arbitrary operations on a computer without our being able to notice.
Although it is not yet very widespread it is the most dangerous of the attacks we can be subjected to, because it allows complete access to our computer and, consequently, to all our data as well.
For example, the police use it to monitor suspects through the webcam and microphone of their computer.

The use of malware as an instrument of interception is spreading, and the target most vulnerable to this kind of attack is the Microsoft Windows operating system. Mac OS X is not exempt from attacks either. No serious attacks against GNU/Linux.
The best remedy for protecting yourself from this kind of attack is to abandon Windows in favour of an open source operating system such as GNU/Linux and to acquire a bit of skill in using it.

For example you can use freepto. See the last chapter for more information.

Encrypting your data

Preparation difficulty: very easy with Freepto, easy if you have a Mac, easy if you install GNU/Linux from scratch, medium/hard in all other cases
Day-to-day difficulty: minimal
Useful against: seizure

To protect data from seizure, the simplest and most effective solution is disk encryption. In practice, this requires entering a password when the computer starts. If the password is sufficiently complex and is kept secret, the contents of the disk will be undecipherable.
Encrypting the system disk does not protect data placed on usb sticks or external disks.

A further reason to choose to encrypt the disk is the possibility of downloading your email with Thunderbird, deleting it from the mail servers and keeping it safe on your encrypted disk.

This does not protect you from malware, however: to avoid that, the best advice we can give you is Leave Windows and Mac behind.

Continues online

Passwords

Day-to-day difficulty: easy
Useful against: unauthorised access

A “secure” password helps prevent unwanted access to your account. Often, out of laziness, the same password gets used for several online services. Moreover, simple passwords can be guessed by purpose-built programs.

It is worth sharing a few considerations for managing a password:

  • You should not use important passwords in insecure contexts (internet points, computers of people you do not trust or of people you trust “personally” but not technically); it will happen sometimes anyway. In that case, change the password (from a trusted computer) as soon as you can.
  • Do not use easy passwords: your name, your date of birth or other known details. Do not use simple words; use combinations of upper and lower case letters, combine numbers and symbols. Recommended minimum length: 8 characters.
  • Do not share passwords unless it is really absolutely necessary.
  • Vary your passwords as much as possible and in any case always use different passwords for different contexts (for example use different passwords for work mail, for mail on commercial servers and for mail on self-managed servers such as Autistici/Inventati or Riseup).
  • If your computer is not encrypted, the passwords you store in your browser will be recorded in the clear; consider therefore not saving the particularly sensitive ones at all (or better still, encrypt your disk!).

Secure deletion of files

Configuration difficulty: medium; on freepto: already configured
Day-to-day difficulty: very easy
Useful against: seizure of the computer

When you delete data on your PC, traces remain on the disk anyway and it is possible for a forensic technician to recover them completely or in part through the use of suitable software.
Some programs, however, allow the secure deletion of your files, so that it is impossible to recover them afterwards.

Continues online

Communicating

Personal, everyday communications are the most sensitive operations you carry out on the network and, in all likelihood, they have already been observed by your adsl or email provider.
So, either you find yourself a less nosy provider or you make sure the provider cannot read your communications. We recommend you follow both pieces of advice.

Using self-managed services

Configuration difficulty: easy
Day-to-day difficulty: very easy
Useful against: identification, data requests to the service provider, profiling

Self-managed services are little islands on the network, open spaces where individuals and collectives provide free communication tools and services. These services are free of charge for everyone, but they have a cost for those who make them available: support them with benefits and donations!

Self-managed services (riseup.net, autistici.org, indivia.net, tracciabi.li) take countermeasures to avoid providing information about you to the authorities.

In addition these services put the user, rather than profit, at the centre of their priorities. This leads them to make much better choices where you are concerned. For example, Gmail “advises against” deleting email, while other commercial services encourage you to attach a mobile number to your account. No self-managed server will ever ask you to do things like that.

Using self-managed services is really simple: to request an email account on autistici.org go to services.autistici.org and fill in the form. After a few days your email account will be activated.

Continues online

Secure chat

Installation difficulty: medium, already installed on freepto
Day-to-day difficulty: easy
Useful against: interception

The most widespread tools for Instant Messaging (Skype, GTalk, Facebook Chat, Yahoo! Messenger, etc) “protect” your communications through the use of SSL (or TLS) encryption. This makes it harder for an over-curious flatmate or colleague to read your conversations easily.
In these cases, your privacy is entirely managed by the companies you rely on to communicate; there is no good reason to believe that, faced with a request from the judiciary, these companies will take any action to protect your privacy.

There are solutions, however:

The self-managed servers A/I and Riseup offer their users Jabber (XMPP), a very widespread Instant Messaging tool.
Moreover, the service is automatically activated for anyone who has an email account with one of these self-managed servers.
In addition, to increase your privacy you can use OTR (Off-the-Record), a technology that makes it simple to encrypt all your conversations. When you use OTR not even A/I or Riseup are able to read your conversations and you can be sure that nobody is intercepting you.

Configuration difficulty of OTR: medium

continues online

Use GPG with Thunderbird + Enigmail

Configuration difficulty: medium
Day-to-day difficulty: medium; if you have one group you mostly talk to, easy
Useful against: Interception

It is by now well known that using commercial services strips your communications of all confidentiality. For example, nothing prevents Google from reading all your conversations, handing them over to law enforcement or analysing them in order to offer you targeted advertising. On the contrary.

Even if you use more trustworthy services, such as Autistici/Inventati, Riseup, Indivia or Ortiche, a good security practice is to send email messages that are not readable by whoever runs your mailbox.

To protect the confidentiality of your communications you can use GnuPG, a cryptographic piece of software that integrates very well with Thunderbird.

Continues online

Audio/Video chat

For making audio calls (or video calls) there are various solutions. Unfortunately none of them is perfect.

Two-way audio/video chat

Installation difficulty: medium, already installed on Freepto.
Difficulty of use: easy
Useful against: interception, skype!

We have already talked about Jabber and Pidgin. These support audio/video chat between two people without problems: the degree of confidentiality is not very high, but it is certainly far better than using skype! The main advantage is that if you use Pidgin for chat with OTR, no additional configuration is needed to use it for video calls as well.

Continues online

Group audio chat

Installation difficulty: medium
Difficulty of use: very easy
Useful against: interception, skype!

Mumble is a very convenient piece of software for handling group chats simply and practically: the only slight difficulty in installation is configuring the microphone. Compared with other commercial software (skype, for example) you also get better sound and conversation quality, especially in very large groups. Obviously nothing stops you using it for calls between just two people as well. The confidentiality of conversations is not particularly robust: comparable to exchanging email without using cryptography.

Continues online

Encrypted audio/video chat

Installation difficulty: medium-hard
Difficulty of use: easy
Useful against: interception, skype!

Jitsi lets you make audio/video calls using ZRTP encryption, which can be considered “analogous” to OTR. The encryption is therefore complete, and the verification mechanism extremely simple. Jitsi is good software and is simple to use: the main defect is that the default configuration leaves a lot of traces on the computer, so some options have to be changed in order to use it securely.

Continues online

Browsing the network

All of your activity on the network can be tracked easily.
Most websites keep a record of their visitors’ IP addresses. This data can be used afterwards to identify the author of content published on the Internet. For this reason using a pseudonym is not enough to protect our real identity.
There is software that gives us the possibility of remaining anonymous while browsing the internet with a browser:

Use Firefox + HTTPS Everywhere

Configuration difficulty: easy, on freepto: already configured
Day-to-day difficulty: none
Useful against: interception

Communications on the internet can be in the clear (that is, readable by anyone) or encrypted (that is, readable only by the sender and the recipient).
Many online services offer the possibility of communicating both in the clear and in encrypted form, but our browser (Firefox) does not automatically choose the encrypted mode.
HTTPS everywhere is an extension available for Firefox and Chrome/Chromium that solves this problem.

One click is enough to install it and you gain a great deal in terms of security: intercepting encrypted communications is in fact very difficult, and can only be carried out by highly motivated attackers.

Continues online

TorBrowser

Configuration difficulty: easy, on freepto: very easy
Day-to-day difficulty: easy, but browsing is much slower
Useful against: identification; interception of communications

It is a modified version of Firefox already configured to use the Tor network.
TorProject.org is a network of servers, developed and run through the work of digital rights organisations and of individuals all over the world. Tor bounces your internet traffic from one country to another before it reaches its destination. This process makes it impossible, as of now, to identify who is using it through their IP address.

Continues online

VPN autistici/riseup

Configuration difficulty: medium/hard
Day-to-day difficulty: easy
Useful against: identification; interception of communications

A VPN lets you protect the flow of data produced by your browsing by putting it inside a kind of encrypted virtual channel (technically called a tunnel). This lets you protect your anonymity rather effectively and protects you from the risk of interception on your home ADSL line.

Unlike TorBrowser (which tends to be more secure), which anonymises the traffic generated by your browser, the VPN encrypts and anonymises all the internet traffic generated by your computer (mail client, instant messaging client, ftp client, etc.)

The self-managed servers Autistici/Inventati and Riseup provide a VPN service for their users; however, it is important to understand that they do not provide anonymity, only “confidentiality”: that is, they are useful for securely “getting past” disadvantageous network conditions such as corporate networks, public hotspots or even your own home line, if you suspect it may be monitored.

Continues online

The security of your phone

The mobile phone is by far the most widespread technological instrument, which is why it is worth asking how to use it in the best way. The first problem to tackle concerns the use of the GSM network; a more complex situation arises with the use of smartphones: their advanced functions offer additional opportunities and introduce new problems.

Voice calls

All mobile phones rely on the GSM network. This already has security implications.

When you use your mobile, your position is continuously communicated to your operator with an accuracy of about 50 metres. There are also “preventive” monitoring systems, capable of detecting a device’s movements in real time by interpreting habitual and “anomalous” behaviour and alerting the authorities in the event of gatherings of people of interest.

The phone records and text messages of every citizen are stored for at least 2 years (often longer) and are accessible at any moment by the police. This data, apparently harmless, is in reality extremely useful even simply for identifying new people to place under surveillance.

All the calls you make can be intercepted by the operators and consequently by the police and the judiciary. In reality this possibility is widely exploited: although only a small part of interceptions can be used as evidence in court proceedings, interception is particularly widespread for investigative purposes, including against people who are not under investigation. To conclude, although phone calls are heavily monitored, they are slightly preferable to text messages.

Smartphones

Not all mobile phones are the same; some are more advanced than others. We are talking about smartphones. These devices, which are genuine light and extremely portable computers, can generate traffic and communicate over the network (wifi/3G) and can be “extended” by installing new applications. There are then other kinds of mobile phone, which we will call featurephones, which offer the same possibilities as smartphones even though they come across as less usable and less appealing.

Smartphones and featurephones offer additional modes of communication compared with old mobile phones, such as e-mail, chat and social networks.

These possibilities can turn into threats.

For example, the applications we install so easily could turn out to be malware and transform our smartphone into an ultra-portable bug: this eventuality has already become reality on many occasions. Caution is therefore needed in choosing which applications to install, avoiding compulsive installation.

It is not only apps that can have ulterior motives: the “market” itself is in reality a system capable of installing whatever it likes on our device on its own initiative. This gives enormous power to the companies that control it, and it cannot reassure us.

The location of smartphones is even more precise (reaching an accuracy of a few metres) than with GSM: thanks to the use of GPS and WiFi networks, any application can obtain very detailed information about your movements.

A smartphone is to all intents and purposes a pocket computer, and if used appropriately it can have several advantages over a traditional mobile phone: the ability to take photos and put them online quickly, for example, is of great use to an activist; the availability of encrypted chat is also certainly more attractive than SMS, but we have to remember that smartphones cannot be considered a 100% secure instrument.

In particular, we feel we should strongly advise against BlackBerry and Apple (iPhone and iPad) smartphones. Android smartphones are not free of problems either, but they leave open the possibility of reasonably secure use by an aware user. A complete guide to the security of your smartphone would be too long for this booklet: what we provide here are recipes for using smartphones for media activism, or for reaching a level of security such that it can only be broken with a considerable investment of time and money.

ObscuraCam: anonymising images

Installation difficulty: easy
Difficulty of use: easy
Useful against: identification

If you take photos with your smartphone during a demonstration you would do well to edit them so as to make people’s faces unrecognisable, if you intend to keep them or to share them on a social network. In trials against activists, identifications through photos are often decisive evidence. Also remember that it is often not enough to cover only the face: badges, clothing and all the other accessories that can be used for identification need anonymising too.
Moreover both Facebook and Google use software capable of automatically recognising the faces of photographed people and associating a real identity with them.
You cannot always predict how a demonstration will turn out, which is why, if you publish your photos “live” on social networks, always remember that they can put the people involved in danger even if you are photographing a situation that is calm at the time; for example you might photograph someone who has taken time off work in order to be at the demonstration, and the circulation of that photo could cause them a lot of problems.
Also remember that during a demonstration your photographic material can be seized if you are stopped by the police, so if your photos could put people in danger, avoid taking them.

Obscuracam is an Android app that makes blurring faces extremely simple and semi-automatic, and lets you quickly edit photos before publishing them online.

Continues online

Xabber: Secure chat

Installation difficulty: easy
Day-to-day difficulty: easy, with OTR: medium
Useful against: interception

Xabber is an android instant messaging app that natively supports TOR and OTR, so it lets you be confidential and anonymous.
Like Pidgin, Xabber uses the Jabber protocol (see the chapter Recipes→Communicating→Secure chat) and therefore lets you have two-way or group chats.
With Xabber you can communicate both with other Xabber users and with Pidgin, but remember that on a smartphone you are not as safe as on a computer running GNU/Linux.

Continues online

TextSecure

Configuration difficulty: easy
Day-to-day difficulty: medium
Useful against: interception, searches

TextSecure is an android app that lets you send messages confidentially both by SMS and over the internet. It also supports group chats.

TextSecure allows you to send SMS in the clear to people who do not have this application too. These communications are not encrypted and so care must be taken over how this app is used.

Compared with Xabber, TextSecure has these differences:

  • there is no need to configure an account;
  • it works even without an internet connection, using SMS;
  • it cannot communicate with iPhone users or with computers;
  • the interface is a bit confusing and it is easy to send unencrypted messages believing that they are encrypted (check for the padlock before sending!).

Continues online

Prepaid phone cards

Difficulty: easy
Useful against: interception

In many countries it is possible to buy prepaid SIM cards without providing identity documents at the time of purchase.

All phones, however, have an identifier called an IMEI which is transmitted during every call. Swapping the phone card you use every day for one bought anonymously might not guarantee your complete anonymity, since it could still be possible to identify your phone. You therefore need to pair an anonymous card with a phone that is not associated with your identity.

Using public computers

Sometimes it is not possible to use your own computer. To check mail or browse the internet, “public” computers get used, for example in an internet point. On these occasions it is important to remember to:

  • use “private browsing” (also called Incognito Mode in google chrome), a mode in which history and passwords are not saved. Details online
  • log out of your accounts, otherwise the next person to use the computer will have access to your data!
  • remember that a public computer is untrustworthy by definition: better not to let passwords or sensitive data pass through it. A good practice remains that of separating spheres, keeping separate accounts for different topics (and different legal exposure).

Another thing to watch out for is cameras: these are used to read what you are writing, by observing the screen or even the fingers typing on the keyboard. This danger obviously also applies to using your own computer in public places (libraries, bars,…). It is very hard to protect yourself from this type of attack, but some suggestions are:

  • cover one hand with the other when typing passwords; if you decide to save passwords in the browser this only has to be done once, so it is not particularly tedious.
  • avoid accessing sensitive content

Freepto

Freepto is an operating system installed on a usb stick.
This means you can carry the stick with you at all times and use any computer just as if it were your own laptop.
In addition the data you save inside this stick will be automatically encrypted (that is, it cannot be read by anyone else).

You can download Freepto and find further information starting from this page

What are Freepto’s main features?

Designed for activists

There are many GNU/Linux distributions oriented towards security and privacy; Tails is perhaps the most famous of this kind of distribution.
These distributions are called “live”, that is they offer a “clean” operating system every time we use them, because on shutdown they remove all the data the user has produced. They are also designed to deal with really very high levels of repression, where attention has to be paid to every single action, and this makes them distributions that are hard to use for everyday activity.

The idea underlying the development of Freepto is to offer a simple operating system that allows the secure management of the tools most frequently used by activists, without however giving up the convenience of a traditional operating system.

Given that abandoning the use of proprietary operating systems (Windows and Mac OSX) is the first necessary step towards increasing our security, there are a great many cases in which completely abandoning the use of these proprietary systems becomes difficult (perhaps because of work requirements), and it is for this reason that it becomes important to find a practical, quick way to separate the account used at work from the account used for activism.

In this sense Freepto lets us protect our data through cryptography and carry it with us at all times.

WARNING: Freepto can raise your level of security considerably, but if you think you are in a situation that deserves extra paranoia, we recommend that you use TAILS and deepen your knowledge of the tools that serve to protect your anonymity and your privacy, so as to be quite clear about the limits and the risks that arise from the use of these technologies.

Always with you

Freepto is a complete operating system inside a usb stick. You can use it from any computer and you will have everything you need.

Encrypted

The data contained in the usb stick is encrypted, so only you can read it.

All included

Freepto contains many of the useful programs: browser, mail reader, image editor… and if something is missing, it can always be installed thanks to synaptic, the package manager also found in debian and ubuntu.

Preconfigured for security

We have tried to make freepto as secure as possible without this worsening the user experience in any way:

  • the chat programs and filezilla are configured to use tor, so as to have anonymous and secure connections.
  • firefox includes extensions to encrypt communication with servers as much as possible
  • with firefox you can browse to .onion sites (sites inside the tor network whose location is hidden)

Optional extra paranoia

We have included inside freepto a series of tools for those who want to increase their level of security still further:

  • secure deletion of files
  • removal of metadata containing sensitive information from images, audio files, pdfs and much more
  • truecrypt, for managing encrypted archives
  • torbrowser-launcher, so as always to have the latest version of torbrowser and to browse anonymously
  • gpg, for exchanging encrypted mail
  • pidgin-otr, for having secure chats very simply
  • tortp, to force the use of TOR on all applications that use the network
  • florence, for having a virtual keyboard on which to enter your passwords
  • tomb, for advanced management of encrypted archives

Customisable

The development of freepto is based on Debian Live Build, a set of tools that make it possible to generate customised live distributions based on Debian (GNU/Linux).

This means that you can help improve freepto and change its configuration to customise it to suit your needs.
If you are a developer and are interested in contributing to freepto you can do so by modifying our repository on GitHub

How is it used?

On this page we have collected the documentation and a few small tutorials on how to configure freepto: freepto-docs

It is important that you read the documentation carefully, and if something is not clear to you you can always use the comments to let us know.