Skip to content

Recent Updates

CryptPad 2026.5.0: zh_Hant Lands as a Built-in Locale After Two and a Half Years Upstream

CryptPad Drive home in Traditional Chinese (zh_Hant). Left sidebar shows file categories; the +New button reveals Rich Text, Document, Sheet, Slides, Kanban, Whiteboard, Diagram, Forms, Calendar.
cryptpad.anoni.net Drive home after switching to 中文(正體). Every file category and app entry is localised.

For people who want a collaboration tool that does not silently keep a readable copy of their work on the server, the practical options are short. Google Docs, Notion, Microsoft 365 are excellent products, but every paragraph and every revision sits on those vendors’ servers in a form they can read. From there, algorithms, ads, training corpora, and government data requests each have their own path in.

That difference is exactly what matters when a journalist drafts a story that cannot leak, when a campaigner negotiates a strategy that cannot be wiretapped, when an NGO records distress reports from vulnerable users, or when a researcher works on a politically sensitive topic. Whether a first draft can be safely written at all often turns on that one architectural choice.

CryptPad is one of the few collaboration suites where the server genuinely cannot read what you wrote. Content is encrypted in your browser, the server only ever sees ciphertext, and yet a single interface covers most of what people normally reach for in Google Docs, Sheets, Slides, kanban boards, whiteboards, forms, and calendars.

Until recently the suite had one obvious gap for one large group of users: the UI shipped in English and Simplified Chinese only, with Traditional Chinese (zh_Hant) missing. From the first upstream PR opened at the end of 2023, through two and a half years of patient string-by-string work in Weblate, to the CryptPad 2026.5.0 “🌷 Spring release” on 2026/05/13, zh_Hant is now a built-in locale. The community-hosted cryptpad.anoni.net has been upgraded. Open cryptpad.anoni.net today and the Drive, the document editors, and the share-permission dialog are all in Traditional Chinese. Readers in Taiwan, Hong Kong, Macau, and across the Chinese-reading diaspora can use it without first learning an English menu.

MADLink report cover

A publicly listed Taipei-traded company shipped 1,708 CSA-7400 high-density network platforms to a Chinese customer between 2019 and 2020. Those appliances ended up in Kazakhstan running a national-grade internet censorship and surveillance system. The supplier was ADLINK Technologies (TWSE: 6166), the customer was Geedge Networks, and the system they ran was the flagship Tiangou Secure Gateway (TSG), an offering whose capabilities rival China's Great Firewall.

That is the central finding of MADLink: A Taiwanese Vestige in the Geedge Supply Chain, InterSecLab's April 2026 report and the first follow-up to their September 2025 The Internet Coup. The anoni.net community has completed the Mandarin (Taiwan terminology, zh-TW) translation. Unlike the previous Internet Coup release, this round also ships an editorial observation page mapping how Taiwan's media, government, and legislators have received the report — with an English summary written for international readers.

Campus Tor Relay templates: proposal, SOP, and FAQ now published

Campus Tor Relay template kit

In November 2025, the first campus Tor Relay in Taiwan went live at National Taiwan Normal University's CSIE department. Over the past six months, community member NZ (Su En-Li) — the student who pushed the proposal through — worked with the community to turn that experience into a reusable template kit. The three documents are now published under CC-BY 4.0, with a long-form interview as the entry point.

The templates are ready. The next step is for more universities to take them up.

Financial Companies as Censors: A Sinophone Asia-Pacific Reading of EFF's Transaction Denied

A piggy bank with its mouth taped shut, representing payment rails severed by financial intermediaries
Image from EFF Deeplinks article Former EFF Activism Director's New Book, Transaction Denied, Explores What Happens When Financial Companies Act like Censors (EFF Financial Censorship banner library), licensed under CC BY 4.0.

On 9 May 2017, the cross-border electronic payment service PayPal closed all domestic transaction functions in Taiwan. Two PayPal Taiwan accounts could no longer send money to each other. Cross-border transfers kept working. The streamer economy took the worst hit. Twitch Cheer, YouTube Super Chat, StreamLabs, and NightDev — tools that processed local audience tips through PayPal — went dark on the same day. Small organizations and independent media that relied on PayPal for domestic flows lost a payment rail overnight8.

The legal trigger was Article 3, Paragraph 1 of Taiwan's Electronic Payment Institution Management Act, passed in 2015. PayPal chose not to apply for a license and closed domestic functions instead9. Nearly nine years later, the U.S. online payment processor Stripe still does not allow individuals or companies in Taiwan to register. Stripe is the credit card collection layer behind Substack, many subscription SaaS products, and many open source sponsorship pages. Individual creators in Taiwan have to first register a U.S. LLC to use it10.

In Taiwan's payment conversation, these two facts have usually been filed under "compliance trade-offs" or "market size." EFF's former Activism Director Rainey Reitman, in her April 2026 book Transaction Denied12, compiles cases from 2012 onward across the U.S. and the Middle East. Stacked together, the cases reveal a cross-region, cross-issue pattern that's been running for more than a decade. Taiwan's two events belong in that record. So do parallel events from Hong Kong, mainland China, Macau, Singapore, and Malaysia, which Reitman's book — focused on U.S. and Middle Eastern material — does not yet cover.

onionoo MCP is now public: query the Tor relay network in plain language

onionoo MCP launch

The community-hosted onionoo-fastapi service is now public at https://onionoo.anoni.net, released as v1.0.0. It wraps the Tor Project's official Onionoo API in two interfaces: a semantic HTTP API with a full OpenAPI document, and a Model Context Protocol (MCP) server.

Connect it to Claude Desktop, Cursor, Claude Code, or any MCP-capable client and you can ask a single question like "how many running Tor relays does Taiwan have right now, what is the total bandwidth, and what are the top five ASNs?" The agent breaks the question down, picks tools, fetches the data, and returns a readable summary. You do not need to learn Onionoo's field schema before starting research.

What is Differential Privacy?

This article is based on the original explainer by fria at Privacy Guides:

Can you collect data from a large group of people while still protecting each individual's privacy? Differential privacy answers yes — with a mathematical proof to back it up. This article introduces the concept, traces its history from early anonymization failures to real-world deployments, and explores what it means for users and policymakers in Taiwan and the broader Chinese-speaking world.

What the Tor VPN security audit means for Taiwan's privacy community

This post is based on the Tor Project announcement:

TorVPN Cure53 Audit

In June 2025, Cure53 completed a penetration test and source code review of TorVPN for Android and its underlying Rust networking layer, Onionmasq. The Tor Project published the results in April 2026. The headline finding: Tor's core tunnel establishment and routing logic held up well. But there are specific technical issues worth understanding if you're recommending or deploying this tool in Taiwan's context.

Taiwan’s Virtual Asset Service Bill: What the Cabinet Approved (and What Happens Next)

Policy update

On 2 April 2026, Taiwan’s Executive Yuan (the cabinet) approved the Financial Supervisory Commission’s draft Virtual Asset Service Act and sent it to the Legislative Yuan for review. If you follow crypto policy or stablecoins, this matters because Taiwan is moving from an anti–money laundering registration regime toward a licensing regime for service providers. This post is a status briefing that gathers the April 2026 cabinet move in one place for readers who mostly skip the Mandarin policy wires. It stays at the policy level. For legal questions, talk to a qualified professional in Taiwan.

A Server That Forgets: why this relay design deserves attention

The Tor Project post, A Server That Forgets: Exploring Stateless Relays, is grounded in real operator experience from Osservatorio Nessuno in Italy. It is not just a technical tour. It asks a basic trust question: if a relay can be seized, searched, or physically cloned, what exactly can an adversary still learn?

Why this is worth translating

First, the article starts from actual seizure and raid precedents. That makes the threat model concrete. Relay operators are not debating abstract malware only; many are planning for legal process and physical hardware exposure.

Second, it gives a rare end-to-end map of the stack: TPM, measured boot, remote attestation, RAM-only runtime, VM images, and tooling paths such as Patela and stboot. Most discussions in our region cover one layer at a time. This one connects them.

Third, it keeps the hard parts visible. Re-sealing after updates, conflicts between stateless images and unattended upgrades, memory ceilings without swap, and the risk of losing a Stable flag due to restarts are all left as open engineering work, not hidden in marketing language.

A Server That Forgets

What "stateless relay" changes in practice

A stateless system reboots into a known image and does not keep writable disk state. In security terms, this shifts defaults:

  • physical seizure yields less forensic material;
  • configuration drift is constrained by declarative rebuilds;
  • persistence across reboots becomes harder for attackers;
  • reproducibility and auditability become more realistic goals.

For Tor relays, there is one unavoidable tension: identity must survive reboots. Relays build reputation over time through long-term keys. If keys disappear on every boot, the node loses its standing and utility.

That is where TPM-backed key handling matters. Keys can be bound to measured boot state and used without handing raw private key material to the operating system. Remote attestation can then let an external verifier check what software stack actually booted. But the limitations are real too, including key-type mismatches and operational complexity.

Three deployment paths, three trade-offs

The post compares three practical models:

  • minimal RAM-disk setups (simple, manual key operations);
  • VM-based RAM images (easier rollback and image lifecycle);
  • bare metal with TPM + verified boot (stronger trust chain, heavier operations).

No single model wins everywhere. The right choice depends on threat model, budget, hosting constraints, and team maturity.

Cross-Community Collaboration: Anonymity Networks Community × ETHTaipei

Cross-Community Collaboration: Anonymity Networks Community × ETHTaipei

This year we are excited to partner with ETHTaipei (Taipei Ethereum Community) on program coordination. Both communities approach anonymous payments from different angles. To ensure each submission reaches the most fitting audience, we will review proposals together:

  • Application-oriented and introductory talks: prioritized for the Anonymity Networks Community track
  • Technical and protocol-level talks: may be moved to the ETHTaipei blockchain track

You do not need to decide which track to submit to — we will discuss placement with speakers during the review process. Both communities will cross-promote their schedules, so attendees can move between tracks to follow related topics across the event.

On Day 2 (Aug 9), both communities plan to co-organize a dedicated session on Anonymous Payments. Speakers and attendees interested in this topic are especially encouraged to take note. If you have a relevant proposal, feel free to mention in your submission notes that you are interested in being included in the cross-community session.

How to Submit (Read First)

  • Read the full CFP information and submission link before submitting.
  • In your proposal, make sure to choose "匿名網路社群 anoni.net" as the track topic so your submission enters this track's review process.
  • Clearly include your topic direction, intended format, audience background, requested duration (30 or 50 minutes), and demo needs (if any).

Read the full CFP details and submission guide

Ethics and Open Licensing Reminder

  • This track is for lawful use and does not support money laundering, tax evasion, or other illegal activity.
  • For topics involving anonymity tools, crypto assets, or coin mixing, focus on education and risk understanding, and remind audiences about legal differences across jurisdictions.
  • Public teaching materials and demo assets should follow COSCUP requirements and use open licenses.

About COSCUP

COSCUP is Taiwan's annual open-source community conference, centered on open-source collaboration and free admission. This track aims to connect technology communities and civic groups, expand practical exchange and local collaboration around anonymity, privacy, and internet freedom, and make participation easier for people who prefer a lower-profile presence with less personal data exposure.