Riseup

Last updated
Riseup Networks
Company type Private
Headquarters
Seattle, Washington
,
USA
Area served
Worldwide
ProductsRiseupVPN, Riseup Red
Services
ASN 16652 OOjs UI icon edit-ltr-progressive.svg
Website riseup.net

Riseup is a volunteer-run collective providing secure email, email lists, a VPN service, online chat, and other online services. This organization was launched by activists in Seattle with borrowed equipment and a few users in 1999 or 2000, and quickly grew to millions of accounts. [1] [2]

Contents

As of 2013, Riseup features 6 million subscribers spread across 14,000 lists. [1] Their projects have included the Stop Watching Us campaign against global surveillance disclosures revealed by Edward Snowden. [1]

Products

Riseup provides products to facilitate secure communications, including use of strong encryption, anonymizing services, and minimal data retention, which aimed at individuals and non-profit and activist groups. [3] Riseup's two most popular features are secure, privacy-focused email [4] [5] [6] [7] and mailing list management services. [8] [9] [10]

The email service is available through IMAP, POP3, and a web interface. [11] The web interface is a variant of Roundcube or SquirrelMail. [12]

According to Kate Krauss at Technical.ly in April 2017, "riseup is a famously ethical nonprofit organization", and "the riseup VPN does not log your IP address, unlike most other VPNs." [13] In 2012, discussing an attack against a Microsoft-developed authentication scheme that makes it trivial to break the encryption used by hundreds of anonymity and security services, Moxie Marlinspike, who unveiled the attack, said VPN services offered by riseup.net, for example, selected a 21-character password on behalf of the user that used a combination of 96 different numbers, symbols, and upper- and lower-case letters to withstand such attacks. [14]

In 2011 Riseup was said to be the only one of several subpoenaed groups to resist subpoenas related to 2008 Bash Back protests. [15]

In 2014, Riseup Network was one of several claimants against GCHQ in international court. Devin Theriot-Orr of Riseup.net said, "People have a fundamental right to communicate with each other free from pervasive government surveillance. The right to communicate, and the ability to choose to do so secretly, is essential to the open exchange of ideas which is a cornerstone of a free society." [16]

In December 2014, a judge in Spain partially justified prolonging the detention of seven alleged anarchist activists by citing their use of "extreme security measures" such as the Riseup email service. The judge's act has been criticized by the Electronic Frontier Foundation (EFF). [17] [18]

In 2014 the Google I/O conference was disrupted by protests. The protest outside was led by Fletes and Erin McElroy from Riseup.net and the Anti-Eviction Mapping Project. [19]

Warrant canary

In mid-November 2016, an unexplained stealth error appeared in Riseup's warrant canary page, and they did not respond to requests to update the canary, leading some to believe the collective was the target of a gag order. [20] On February 16, 2017, the Riseup collective revealed their failure to update the canary was due to two sealed warrants from the FBI, which made it impossible to legally update their canary. The two sealed warrants concerned a public contact of an international distributed denial-of-service attack extortion ring and an account using ransomware to extort people financially. The decision to release user information has been criticized in the hacker community. [21] The canary has since been updated, but no longer states the absence of gag orders. [22]

Related Research Articles

<span class="mw-page-title-main">Mass surveillance</span> Intricate surveillance of an entire or a substantial fraction of a population

Mass surveillance is the intricate surveillance of an entire or a substantial fraction of a population in order to monitor that group of citizens. The surveillance is often carried out by local and federal governments or governmental organizations, such as organizations like the NSA, but it may also be carried out by corporations. Depending on each nation's laws and judicial systems, the legality of and the permission required to engage in mass surveillance varies. It is the single most indicative distinguishing trait of totalitarian regimes. It is also often distinguished from targeted surveillance.

The Invisible Internet Project (I2P) is an anonymous network layer that allows for censorship-resistant, peer-to-peer communication. Anonymous connections are achieved by encrypting the user's traffic, and sending it through a volunteer-run network of roughly 55,000 computers distributed around the world. Given the high number of possible paths the traffic can transit, a third party watching a full connection is unlikely. The software that implements this layer is called an "I2P router", and a computer running I2P is called an "I2P node". I2P is free and open sourced, and is published under multiple licenses.

<span class="mw-page-title-main">Privacy International</span>

Privacy International (PI) is a UK-based registered charity that defends and promotes the right to privacy across the world. First formed in 1990, registered as a non-profit company in 2002 and as a charity in 2012, PI is based in London. Its current executive director, since 2012, is Dr Gus Hosein.

Internet privacy involves the right or mandate of personal privacy concerning the storage, re-purposing, provision to third parties, and display of information pertaining to oneself via the Internet. Internet privacy is a subset of data privacy. Privacy concerns have been articulated from the beginnings of large-scale computer sharing and especially relate to mass surveillance.

GreenNet is a not-for-profit Internet service provider based in London, England. It was established in 1985 "as an effective and cheap way for environmental activists to communicate". In 1987 the Joseph Rowntree Charitable Trust gave GreenNet a grant to enable it to bring a large number of peace groups online, and "After a few years they became one of the first internet service providers in Britain". GreenNet formed an international link with IGC and was a founder member of the Association for Progressive Communications, established in 1990. The registered charity GreenNet Charitable Trust was established in 1994 and owns GreenNet.

Anonymizer, Inc. is an Internet privacy company, founded in 1995 by Lance Cottrell, author of the Mixmaster anonymous remailer. Anonymizer was originally named Infonex Internet. The name was changed to Anonymizer in 1997 when the company acquired a web based privacy proxy of the same name developed by Justin Boyan at Carnegie Mellon University School of Computer Science. Boyan licensed the software to C2Net for public beta testing before selling it to Infonex. One of the first web privacy companies founded, Anonymizer creates a VPN link between its servers and its users computer, creating a random IP address, rather than the one actually being used. This can be used to anonymously report a crime, avoid spam, avoid Internet censorship, keep the users identity safe and track competitors, among other uses.

<span class="mw-page-title-main">Warrant canary</span> Method of indirect notification of a subpoena

A warrant canary is a method by which a communications service provider aims to implicitly inform its users that the provider has been served with a government subpoena despite legal prohibitions on revealing the existence of the subpoena. The warrant canary typically informs users that there has not been a court-issued subpoena as of a particular date. If the canary is not updated for the period specified by the host or if the warning is removed, users might assume the host has been served with such a subpoena. The intention is for a provider passively to warn users of the existence of a subpoena, albeit violating the spirit of a court order not to do so, while not violating the letter of the order.

<span class="mw-page-title-main">Tor (network)</span> Free and open-source anonymity network based on onion routing

Tor, short for The Onion Router, is free and open-source software for enabling anonymous communication. It directs Internet traffic via a free, worldwide volunteer overlay network that consists of more than seven thousand relays.

The WikiLeaks-related Twitter court orders were United States Department of Justice 2703(d) orders accompanied by gag orders issued to Twitter in relation to ongoing investigations of WikiLeaks issued on 14 December 2010. The U.S. government sent Twitter a subpoena for information about Julian Assange and several other WikiLeaks-related persons, including Chelsea Manning. Twitter appealed against the accompanying gag order in order to be able to disclose its existence to its users, and was ultimately successful in its appeal.

<span class="mw-page-title-main">PRISM</span> Mass surveillance program run by the NSA

PRISM is a code name for a program under which the United States National Security Agency (NSA) collects internet communications from various U.S. internet companies. The program is also known by the SIGAD US-984XN. PRISM collects stored internet communications based on demands made to internet companies such as Google LLC and Apple under Section 702 of the FISA Amendments Act of 2008 to turn over any data that match court-approved search terms. Among other things, the NSA can use these PRISM requests to target communications that were encrypted when they traveled across the internet backbone, to focus on stored data that telecommunication filtering systems discarded earlier, and to get data that is easier to handle.

Lavabit is an open-source encrypted webmail service, founded in 2004. The service suspended its operations on August 8, 2013 after the U.S. Federal Government ordered it to turn over its Secure Sockets Layer (SSL) private keys, in order to allow the government to spy on Edward Snowden's email.

<span class="mw-page-title-main">2010s global surveillance disclosures</span> Disclosures of NSA and related global espionage

During the 2010s, international media news reports revealed new operational details about the Anglophone cryptographic agencies' global surveillance of both foreign and domestic nationals. The reports mostly relate to top secret documents leaked by ex-NSA contractor Edward Snowden. The documents consist of intelligence files relating to the U.S. and other Five Eyes countries. In June 2013, the first of Snowden's documents were published, with further selected documents released to various news outlets through the year.

The Calyx Institute is a New York-based 501(c)(3) research and education nonprofit organization formed to make privacy and digital security more accessible. It was founded in 2010 by Nicholas Merrill, Micah Anderson, and Kobi Snitz.

<span class="mw-page-title-main">Proton Mail</span> End-to-end encrypted email service

Proton Mail is a Swiss end-to-end encrypted email service founded in 2013 headquartered in Plan-les-Ouates, Switzerland. It uses client-side encryption to protect email content and user data before they are sent to Proton Mail servers, unlike other common email providers such as Gmail and Outlook.com. The service can be accessed through a webmail client, the Tor network, or dedicated iOS and Android apps.

The Email Privacy Act is a bill introduced in the United States Congress. The bipartisan proposed federal law was sponsored by Representative Kevin Yoder, a Republican from Kansas, and then-Representative Jared Polis, a Democrat of Colorado. The law is designed to update and reform existing online communications law, specifically the Electronic Communications Privacy Act (ECPA) of 1986.

Google's changes to its privacy policy on March 16, 2012, enabled the company to share data across a wide variety of services. These embedded services include millions of third-party websites that use AdSense and Analytics. The policy was widely criticized for creating an environment that discourages Internet innovation by making Internet users more fearful and wary of what they do online.

<span class="mw-page-title-main">Mullvad</span> VPN service based in Sweden

Mullvad is a commercial VPN service based in Sweden. Launched in March 2009, Mullvad operates using the WireGuard and OpenVPN protocols. It also supports Shadowsocks as a bridge protocol for censorship circumvention. Mullvad's VPN client software is released under the GPLv3, a free and open-source software license.

<span class="mw-page-title-main">HMA (VPN)</span> Virtual private network service founded in 2005

HMA is a VPN service founded in 2005 in the United Kingdom. It has been a subsidiary of the Czech cybersecurity company Avast since 2016.

Proton AG is a Swiss technology company offering privacy-focused online services. It was founded in 2014 by a group of scientists who met at CERN and created Proton Mail. Proton is headquartered in Plan-les-Ouates, Switzerland. It is supported by FONGIT and the European Commission.

A virtual private network (VPN) service provides a proxy server to help users bypass Internet censorship such as geoblocking and users who want to protect their communications against data profiling or MitM attacks on hostile networks.

References

  1. 1 2 3 Pangburn, DJ (11 September 2013). "Inside the Effort to Crowdfund NSA-Proof Email and Chat Services". Archived from the original on 25 October 2017. Retrieved 8 August 2015.
  2. Cohen, Noam (2010-08-15). "In Google-Verizon Deal, Fears for Privacy". The New York Times. ISSN   0362-4331. Archived from the original on 2019-11-10. Retrieved 2019-11-11.
  3. "Cheap hosting and free speech". CNET. July 25, 2007. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  4. Greenberg, Andy (2014-06-17). "How to Anonymize Everything You Do Online". Wired. ISSN   1059-1028. Archived from the original on 2014-10-18. Retrieved 2019-11-10.
  5. "Encrypt your emails, evade the NSA". Salon. 2013-06-11. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  6. Norton, Quinn (2013-06-11). "Worried about the Mass Surveillance? How to Practice Safer Communication". ProPublica. Archived from the original on 2019-11-09. Retrieved 2019-11-10.
  7. Adee, Sally (17 January 2017). "How to protest against Trump in his expanded surveillance state". NewScientist. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  8. Wendorf, Daniel; Plass-Fleßenkämper, Benedikt (August 2018). "Redeeming the darknet in five examples". Goethe-Institut. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  9. Willis, Nathan (June 24, 2015). "The security benefits of using Gmail [LWN.net]". lwn.net. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  10. COHEN, NOAM (August 15, 2010). "Internet Proposal From Google and Verizon Raises Fears for Privacy". The New York Times. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  11. Farivar, Cyrus (2013-10-13). "Europe won't save you: Why e-mail is probably safer in the US". Ars Technica. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  12. "Webmail - riseup.net". riseup.net. Archived from the original on 2019-11-11. Retrieved 2019-11-11.
  13. Krauss, Kate (2017-04-04). "Trump just signed a bill that lets ISPs sell your browsing data. Here's what to do now". Technical.ly Philly. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  14. Goodin, Dan (2012-07-31). "Attack against Microsoft scheme puts hundreds of crypto apps at risk". Ars Technica. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  15. Mirk, Sarah (March 22, 2011). "Hack Back: Right-Wing Group Subpoenas Queer Activists' Info from Google". Portland Mercury. Archived from the original on 2015-09-10. Retrieved 2019-11-11.
  16. Bowcott, Owen (2014-07-02). "ISPs take GCHQ to court in UK over mass surveillance". The Guardian. ISSN   0261-3077. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  17. Kayyali, Nadia (16 January 2015). "Security is Not a Crime—Unless You're an Anarchist". Archived from the original on 27 July 2015. Retrieved 8 August 2015.
  18. Baker, Jennifer (14 Jan 2015). "Warning: Using encrypted email in Spain? Do not pass go, go directly to jail". Archived from the original on 24 October 2017. Retrieved 8 August 2015.
  19. Buhr, Sarah (25 June 2014). "Google I/O Protester Stopped The Conference Claiming To Be Jack Halprin Eviction Victim". TechCrunch. Archived from the original on 2019-11-10. Retrieved 2019-11-10.
  20. "Disparity in the RiseUp Canary - GPG RSA Key Was Changed By ONE Character At The Last Update". Reddit. 2016-11-18. Archived from the original on 2021-03-21. Retrieved 2016-11-18.
  21. "Episode 1: Riseup, Technological Centralization & Snitching". Archived from the original on 2017-03-04. Retrieved 2017-12-21.
  22. Whittaker, Zack. "Encrypted email service Riseup sparks worry after warrant canary appears to expire". ZDNet. Archived from the original on 2020-01-19. Retrieved 2019-11-10.