Skip to content

Recent Updates

Android 17 ships: the real GrapheneOS story is who decides what runs on your phone

Android 17 and GrapheneOS: who decides what runs on the phone you bought
Image: a smartphone wrapped in a chain and padlock, standing in for a device locked down by outside rules. Photo by Towfiqu barbhuiya, via Pexels (Pexels License).

You paid for the phone, but what it can run and what it can install is increasingly not yours to decide. That question stays invisible until an app refuses to open because it "detected a non-stock OS," or an open-source OS you rely on gets harder to maintain because the hardware data behind it stops being public. Android 17 landed on 2026-06-16, and it pushed that question one step further.

For privacy-minded users, the OS in the middle of this is GrapheneOS: a hardened, de-Googled Android built on AOSP. It runs almost exclusively on Google Pixel hardware, and Google has spent the past year adjusting how open Android and the Pixel actually are.

Why this matters (especially in APAC)

This reads like a US/EU story about Google and Brussels, but it is close to home for readers across East and Southeast Asia and the Chinese-speaking world. Android 17's new sideloading "developer verification" flow is rolling out first in Brazil, Indonesia, Singapore and Thailand in 2026, expanding from there. Banking, payment and government apps across the region increasingly check whether a device is in "stock" state, and in mainland China that posture — device attestation plus real-name requirements — is already the norm. The losers are the same everywhere: people who want a phone they actually control.

OONI is guarding its data against bad measurements — what that means if you build on it

We build on OONI's public dataset. Our own work tracks how well Taiwan and the wider APAC region are actually observed in that data, and our Run v2 census mapped how the whole Run v2 ecosystem gets used. So when OONI published a long engineering post on [how it detects and mitigates faulty measurements]1 — alongside a new anonymous-credential system now rolling into production — we read it not as OONI insiders but as people downstream who use this data to make claims about a thinly-observed part of the world.

Here is what stands out from that seat.

COSCUP 2026 Anonymity Networks Community track runs two days, Aug 8–9, free entry, just walk in

COSCUP 2026 Anonymity Networks Community track hero image

Journalists need to protect sources, civil-society groups need to keep member lists and donor records safe, developers want to know whether the tools in their hands actually hold up against surveillance, and ordinary people rattled by scam texts or ad tracking just want a little control back. Under spreading censorship and monitoring, these needs land on the same set of risks: traffic can be intercepted, identities can be traced, and the timing and amount of a single transfer can reconstruct an entire web of relationships.

The Anonymity Networks Community (anoni.net) brings a year of hands-on work with Tor, Tails, and OONI (open-source privacy and anti-censorship tools), plus personal privacy and anonymous payments, to the open-source floor of COSCUP 2026. Across two days at National Taiwan University of Science and Technology, we run a full community track, from how the internet and censorship work, through real-world open-source privacy tools, campus Tor nodes, browser tracking, and the national health-insurance database and data-privacy rights, to an anonymous-payments session co-organized with ETHTaipei (Taipei Ethereum Community). Whether you came looking for tools you can use right away or want to contribute to open-source projects, there is a session for you.

Event details

  • Dates: August 8 (Sat) and 9 (Sun), 2026
  • Venue: National Taiwan University of Science and Technology (NTUST), Taipei. The community track is in TR-510; the Aug 8 afternoon session co-organized with ETHTaipei is in TR-511.
  • Admission: COSCUP is free, and the community track needs no separate registration. Just show up.
  • Getting there: sessions are drop-in, so you can come and go and don't need to stay all day. For transport and room locations, follow the official COSCUP schedule and venue info, which are authoritative (times may still shift before the event).

See the full schedule and session summaries

Brief yourself before you travel — take the right questions to your own AI

Illustration: an AI assistant on the left gathers scattered data cards (Wi-Fi, location pin, lock, SIM, QR) and sorts them along dotted lines into a shield-framed pre-departure briefing panel on the right, with an airplane and a flight-path arc above

Before a trip you check visas, plug types, and currency. Few people check how the internet is controlled where they are going, whether their work is legal there, or who to call if something goes wrong. For journalists, human-rights defenders, NGO staff, and researchers, those are the questions that actually affect their safety, and the hard part is that you usually don't know what to ask before you leave.

OONI Run v2 usage census

Worldwide, OONI Run v2 has produced 14.17 million measurements, and just three lists account for 72% of them. The highest-volume lists all work the same way: each one targets a single censorship or blocking phenomenon, and a continuously-running measurement backend executes it on a schedule, accumulating data over time. We surveyed every Run v2 link to measure how concentrated this is, and to draw out what the pattern offers communities that want to run their own local connectivity observation.

OONI (the Open Observatory of Network Interference) is a global censorship-measurement project. Its mobile app, OONI Probe, runs through a list of websites and reports whether each one is reachable from where you are. OONI Run v2 lets anyone compose their own list of sites to watch, generate a link, and have others run that list with one tap in OONI Probe, with every result flowing into OONI's public dataset. You can define your own measurement targets without writing code, yet few people know the feature exists or have used it, which is exactly why we wanted to see how it is actually used.

How Unredacted Helps People in Censored Regions Reach the Open Internet

This post is based on a guest post on the Tor Blog by Unredacted, with an anoni.net community perspective added for Taiwan and the wider Sinophone region.

Keeping the doors open

Unredacted is a US-based 501(c)(3) non-profit that runs a network of 300+ servers to keep people in heavily censored places connected to the open internet. Their guest post is part of the Tor Blog's spotlight series on organizations defending the free internet, and it opens with a line from a user in China: "You have helped many many people to overcome the great firewall." That kind of message is rare, because people living under censorship usually have no safe channel to send one.

This post highlights what Unredacted builds, and what it looks like from where the anoni.net community sits, in Taiwan.

After Iran's 80-day blackout, traffic surged through our community's Tor WebTunnel bridge

For people in Iran, the outside internet barely existed for nearly three months. When connectivity started to come back a few days ago, the Tor WebTunnel bridge our community runs began taking on a wave of traffic. That was Iranians who had found a way around the censorship and reconnected to Tor, getting back onto the wider internet.

Wherever you are, you can help

If you have a VPS (a small cloud server) or a physical machine, plus a domain name, you can run a Tor WebTunnel bridge and give people cut off by censorship a way back onto the open internet. Can't run a server? Open a browser tab and run Snowflake instead, it contributes anonymous traffic just the same.

Server specs, legal considerations, and the full setup steps are written up in How to set up a Tor WebTunnel bridge.

CryptPad 2026.5.0: zh_Hant Lands as a Built-in Locale After Two and a Half Years Upstream

CryptPad Drive home in Traditional Chinese (zh_Hant). Left sidebar shows file categories; the +New button reveals Rich Text, Document, Sheet, Slides, Kanban, Whiteboard, Diagram, Forms, Calendar.
cryptpad.anoni.net Drive home after switching to 中文(正體). Every file category and app entry is localised.

For people who want a collaboration tool that does not silently keep a readable copy of their work on the server, the practical options are short. Google Docs, Notion, Microsoft 365 are excellent products, but every paragraph and every revision sits on those vendors’ servers in a form they can read. From there, algorithms, ads, training corpora, and government data requests each have their own path in.

That difference is exactly what matters when a journalist drafts a story that cannot leak, when a campaigner negotiates a strategy that cannot be wiretapped, when an NGO records distress reports from vulnerable users, or when a researcher works on a politically sensitive topic. Whether a first draft can be safely written at all often turns on that one architectural choice.

CryptPad is one of the few collaboration suites where the server genuinely cannot read what you wrote. Content is encrypted in your browser, the server only ever sees ciphertext, and yet a single interface covers most of what people normally reach for in Google Docs, Sheets, Slides, kanban boards, whiteboards, forms, and calendars.

Until recently the suite had one obvious gap for one large group of users: the UI shipped in English and Simplified Chinese only, with Traditional Chinese (zh_Hant) missing. From the first upstream PR opened at the end of 2023, through two and a half years of patient string-by-string work in Weblate, to the CryptPad 2026.5.0 “🌷 Spring release” on 2026/05/13, zh_Hant is now a built-in locale. The community-hosted cryptpad.anoni.net has been upgraded. Open cryptpad.anoni.net today and the Drive, the document editors, and the share-permission dialog are all in Traditional Chinese. Readers in Taiwan, Hong Kong, Macau, and across the Chinese-reading diaspora can use it without first learning an English menu.

MADLink report cover

A publicly listed Taipei-traded company shipped 1,708 CSA-7400 high-density network platforms to a Chinese customer between 2019 and 2020. Those appliances ended up in Kazakhstan running a national-grade internet censorship and surveillance system. The supplier was ADLINK Technologies (TWSE: 6166), the customer was Geedge Networks, and the system they ran was the flagship Tiangou Secure Gateway (TSG), an offering whose capabilities rival China's Great Firewall.

That is the central finding of MADLink: A Taiwanese Vestige in the Geedge Supply Chain, InterSecLab's April 2026 report and the first follow-up to their September 2025 The Internet Coup. The anoni.net community has completed the Mandarin (Taiwan terminology, zh-TW) translation. Unlike the previous Internet Coup release, this round also ships an editorial observation page mapping how Taiwan's media, government, and legislators have received the report — with an English summary written for international readers.

Campus Tor Relay templates: proposal, SOP, and FAQ now published

Campus Tor Relay template kit

In November 2025, the first campus Tor Relay in Taiwan went live at National Taiwan Normal University's CSIE department. Over the past six months, community member NZ (Su En-Li) — the student who pushed the proposal through — worked with the community to turn that experience into a reusable template kit. The three documents are now published under CC-BY 4.0, with a long-form interview as the entry point.

The templates are ready. The next step is for more universities to take them up.