We no longer have any active servers in France and are continuing the process of leaving OVH. We'll be rotating our TLS keys and Let's Encrypt account keys pinned via accounturi. DNSSEC keys may also be rotated. Our backups are encrypted and can remain on OVH for now.
Our App Store verifies the app store metadata with a cryptographic signature and downgrade protection along with verification of the packages. Android's package manager also has another layer of signature verification and downgrade protection.
Our System Updater verifies updates with a cryptographic signature and downgrade protection along with another layer of both in update_engine and a third layer of both via verified boot. Signing channel release channel names is planned too.
Our update mirrors are currently hosted on sponsored servers from ReliableSite (Los Angeles, Miami) and Tempest (London). London is a temporary location due to an emergency move from a provider which left the dedicated server business and will move. More sponsored update mirrors are coming.
Our ns1 anycast network is on Vultr and our ns2 anycast network is on BuyVM since both support BGP for announcing our own IP space. We're moving our main website/network servers used for default OS connections to a mix of Vultr+BuyVM locations.
We have 5 servers in Canada with OVH with more than static content and basic network services: email, Matrix, discussion forum, Mastodon and attestation. Our plan is to move these to Netcup root servers or a similar provider short term and then colocated servers in Toronto long term.
France isn't a safe country for open source privacy projects. They expect backdoors in encryption and for device access too. Secure devices and services are not going to be allowed. We don't feel safe using OVH for even a static website with servers in Canada/US via their Canada/US subsidiaries.
We were likely going to be able to release experimental Pixel 10 support very soon and it's getting disrupted. The attacks on our team with ongoing libel and harassment have escalated, raids on our chat rooms have escalated and more. It's rough right now and support is appreciated.
Si vous ĂȘtes responsable de la fuite, rassurez-vous, vous ne risquez rien.
Vous pouvez cependant :
- nier ;
- invoquer le fameux serveur de test ;
- menacer de poursuites les gens qui en parlent trop fort.
La pvtain de ta mĂšre la p*te on nous retire 400⏠de salaire par mois pour le financer, si aprĂšs 10 ans de salariat jâai envie dâen profiter câest MON DROIT
đȘđș Telegram sent this message to all its users in France regarding Chat Control. People must know the names of those who try to steal their freedoms:
Today, the European Union nearly banned your right to privacy. It was set to vote on a law that would force apps to scan every private message, turning everyoneâs phone into a spying tool.
France led the push for this authoritarian law. Both former and current Interior Ministers, Bruno Retailleau and Laurent Nuñez, supported it. Last March, they declared that police should see French citizensâ private messages. The Republicans and Macronâs Renaissance group voted for it.
Such measures are supposed to âfight crimeâ, but their real target is regular people. It wouldnât stop criminals â they could just use VPNs or special websites to hide. Officialsâ and police messages wouldnât be scanned either, since the law conveniently exempts them from surveillance. Only YOU â ordinary citizens â would face the danger of your private messages and photos being compromised.
Today, we defended privacy: Germanyâs sudden stand saved our rights. But freedoms are still threatened. While French leaders push for total access to private messages, the basic rights of French people â and all Europeans â remain in danger.