Skip to content

Utilities

The articles on this site explain how to protect yourself. This section holds the tools you can use directly. Four rules apply to all of them:

  • Everything is computed in your browser, and nothing is sent anywhere
  • Once stored on your device they work with the network off, and working offline is itself the proof that nothing is being sent
  • The source is in anoni-net/docs, so anyone who can read code can verify it
  • All of them need JavaScript enabled, because the computation happens on your device

One conflict to know about if you use Tor Browser

Setting Tor Browser's security level to Safest disables JavaScript entirely, and the tools in this section stop responding.

The conflict is that the same page's guidance is to raise the level for "unfamiliar onion sites, links of unknown origin, unfamiliar domains", and receiving a suspicious link is exactly when you would want the invisible character detector or the QR code reader.

Handle the two separately. Open the suspicious site at the higher level, copy out the text or image you want to check, switch back to Standard to examine it, then raise the level again. The tools here make no outbound connections, so opening them at Standard does not add to your exposure on that site.

Available now

What to protect

  • Threat model checklist

    Turn your answers to the three questions (what you are protecting, who from, what you will spend) into a copyable checklist, with the mismatches flagged. Nothing is saved unless you choose to keep it, encrypted with a passkey on your device.

  • My preparation checklist

    The site's action items gathered into one list you can tick off. Progress is encrypted with your passkey and stays on your device; one fingerprint next time and it is back. No account, no server, nothing stored here.

Passwords, encryption

  • Passphrase and password generator

    Draw a passphrase from the 7776-word asian-diceware list, or a random password from the character sets you pick. Randomness comes from the browser's crypto.getRandomValues, and the entropy you got is shown alongside.

  • Local file encryption

    Pick a file or paste some text and encrypt it to the age format in your browser with a passphrase, a passkey or recipients' age public keys, or open an age file. The ciphertext can come out as text, so it goes into your password manager next to the passphrase and follows you across devices. The output is decrypted again and checked before the download is offered. It is a public format: any computer with the age command-line tool opens it, without this site.

  • Passkey as your key

    Create a passkey for this site and store it in your password manager or keychain. For the checklist alone, one press of "Create passkey" is enough; only file encryption also needs a test unlock and a backup key. Local file encryption can then use it as the key, with no passphrase to remember, and the checklist, saved threat model answers and the address book are encrypted with it on your device. No account, no server, nothing stored here.

Handing things over

  • QR code generator

    Turn onion addresses, Tor bridges and other long, easily mistyped strings into a QR code the person in front of you can read with a camera, without anything passing through a server. Downloadable as SVG for printing.

  • QR code reader

    Read what is inside a QR code image without the image leaving your device. URLs get their hostname shown separately, and there is no open button.

  • QR code frame stream

    Something on your phone needs to reach the laptop beside you and the Wi-Fi in the room is not yours. The file becomes a run of QR codes played in a loop, read back by the other device's camera. No pairing, no shared network, no server.

  • File hash comparison

    Compute a file's SHA-256 and check it against the string you were given. A USB stick carried by hand, a file sent with someone else, an installer you downloaded: this is the step that confirms what arrived matches the original. Multi-gigabyte files work, with progress shown.

Before you send

  • PDF page tidy-up

    Merge several PDFs, pull out or drop pages, reorder them, fix their orientation. The result is a newly built file, so the source's title, author, producer and creation date do not come along, and it is read back once before you get it.

  • File metadata remover

    Strip EXIF, GPS, device model, authoring software, author and comment fields from photos, videos, recordings, Office documents and PDFs without the file leaving your device. For photos, videos and recordings not one byte of compressed data is touched, and every segment kept or removed is listed for you.

  • Screenshot redaction

    Draw boxes over names, avatars and messages that must not leave a screenshot or photo and fill them with solid black, entirely on your device. The output is re-encoded so no metadata or filename carries over, and every box is checked pixel by pixel before you download.

After you receive

  • URL cleaner

    Pick out and remove the tracking parameters in a URL, each annotated with who is doing the tracking. Unwraps Google and Facebook redirect wrappers, and shows the real registered domain on its own, explaining brands in subdomains, extra words around a brand, and look-alike letters.

  • Invisible character detector

    Find zero-width characters, bidirectional controls and homoglyphs hiding in text, with positions marked and each class explained. Both document leak tracking and phishing URLs rely on these.

  • What your browser gives away

    Lists what any site can read without asking, annotated with how Tor Browser normalises each one. Open it in a second browser to see what those defences actually do.

How the tools connect

Each tool above covers one action, and one thing on your plate usually runs through two or three of them. These are the paths people walk most often.

What you have to do The order
Sitting down for the first time to work out what to do Threat model checklist for the three questions and the mismatches, My preparation checklist to pick what comes next, Passkey as your key to keep the progress encrypted on your device
Wanting to know what a website receives without asking What your browser gives away once, then again in a different browser for comparison, and the URL cleaner for whose identifier rides on the end of a link
Photos or screenshots going to someone else If something in the picture needs covering, use Screenshot redaction, whose output already carries no metadata from the original. If the picture is clean and you only want the capture data gone, use the File metadata remover
A PDF going out PDF page tidy-up to arrange the pages, then the same page's "see what is inside" to search for text that should not still be there
A link or QR code of unclear provenance QR code reader to decode it, URL cleaner for the registered domain, Invisible character detector for homoglyphs in the text
A file from someone else, to confirm and to inspect File hash comparison to confirm it matches their copy, the File metadata remover or "see what is inside" on PDF page tidy-up to list what it carries, Invisible character detector for embedded characters
Something going to the person or device in front of you Long strings go through the QR code generator for the other side to read with a camera. Files of a few kilobytes go through the QR code frame stream, which compares SHA-256 itself once the pieces arrive
A file travelling by courier or on a USB stick Passphrase and password generator for a passphrase, Local file encryption to seal it, File hash comparison so the recipient can verify
A password you need now and again later Passphrase and password generator to draw one, Passkey as your key to hold it, My preparation checklist to record where you got to

Nine concrete situations, each written up as a full walk through one of these paths. The everyday group assumes no particular role or threat. The group at work is written against the kinds of work this site serves.

Everyday cases

  • The ads seem to know what you are thinking

    Something you looked at elsewhere turns up in your feed shortly afterwards. What any website receives without asking, why those values together identify a person, and whose identifier rides on the end of a link.

  • Sending out a job application

    One evening before the deadline, a CV edited from an old version, a portfolio in three files, and one page showing work a previous employer has not published. Why an exported PDF carries the account name from your computer, and why text under a black box is still in the file.

  • Selling things on a secondhand marketplace

    Fourteen photos taken before a move, with a house number, the sign on the building opposite, and a utility bill in the backgrounds. When to reach for screenshot redaction and when for the metadata remover, and what to say when a buyer asks you for ID.

  • A link forwarded into a group chat

    A neighbourhood group chat forwards a limited-time registration, with a URL that looks official and a QR code image. Why the registered domain is the only part worth reading, and what invisible characters can and cannot tell you.

Cases at work

  • Walking a new colleague through a device review

    Someone starts next week with access provisioned and nobody has talked to them about their devices. Why the three questions need a second person asking, why the mismatch list beats the answers, and why the progress stays on their device.

  • Handing a list to an outside partner

    The annual filing means sending a donor list to your accountant, which used to travel as an email attachment. Why the passphrase takes a different route, and why an encrypted file still gets a hash.

  • Handing things out at a workshop

    The venue Wi-Fi belongs to the host and twenty people brought twenty different devices. What belongs on a printed QR code, what travels by screen and camera, and what still needs a USB stick.

  • A file from a source

    A source sends an internal deck, you need to verify it and quote from it, and nobody should be able to work out who handed it over. How document leak tracking works, and why quoting means retyping and redacting.

  • Turning conversation screenshots into a submission

    Forty-odd conversation screenshots have to become one attachment, with third parties' names and avatars in frame. The order of redacting, merging and confirming, and what the last check before sending looks for.

Taking them offline

The code and data behind these tools are stored along with the page. The QR code generator, reader, frame stream and passphrase generator are stored on the device automatically along with the core chapters, because those four get used during an outage; see Preparing for and handling a network outage. For the rest, tick them in the offline reading list and they will open without a network afterwards.

Whose code this uses

Most of the code in this section is our own, under anoni-net/docs. A few things come from elsewhere, included unmodified:

Component Used by Licence Where the licence text is
qrcode-generator 1.4.4 QR code generator, frame stream MIT the header at the top of the file
jsQR 1.4.0 QR code reader, frame stream Apache-2.0 jsQR-LICENSE.txt
pdf-lib 1.17.1 The PDF part of the file metadata remover MIT pdf-lib-LICENSE.txt
typage (age-encryption on npm) 0.3.1 Local file encryption BSD-3-Clause LICENSE
typage's dependencies noble-ciphers 2.1.1, noble-curves 2.0.1, noble-hashes 2.0.1, noble-post-quantum 0.5.3, scure-base 2.0.0 Local file encryption MIT noble-ciphers, noble-curves, noble-hashes, noble-post-quantum, scure-base
The 7776-word list from asian-diceware Passphrase and password generator Word data CC-BY-4.0, code MIT the upstream repository

The pdf-lib.min.js build also bundles Microsoft's tslib (Apache-2.0), whose copyright header survives in the file rather than being stripped by the minifier.

typage and its dependencies are ES modules with no single-file distribution, so they sit under vendor/age/ unmodified together with their package.json and licences, wired up by an import map on the page. Every file can be compared byte for byte with the same version's npm tarball, whose hashes are recorded in vendor/README.md.

Leaving these unmodified is deliberate. Editing them would forfeit their upstream provenance, leaving readers who want to check with nothing but our word for it. The files sit under utils/vendor/ and can be diffed against upstream.

Why each of these is not written from scratch is explained at the bottom of the relevant page. The shared reason is that getting them wrong does not crash anything. It produces output that looks right and is not, which is harder to notice than a failure, and the QR code generator page records one such case we hit ourselves.

What is not here

Anything that needs an external service to work stays out, because the connection itself breaks both the offline rule and the no-data rule. For network measurement use OONI Probe, which is built for network measurement and documents what happens to the data.

There will be no share links either. Saving a result so someone else can look at it sounds like a convenience, but it sends the content to a server while the tool itself still runs in your browser, and nothing on screen tells the two apart. JSONFormatter and CodeBeautify, two paste-and-go tool sites, work exactly like that: their policies say that 99% of their tools process data in the browser, which is true, and they also have a save button whose output is public by default and indexed by search engines. In 2025 the security team at watchTowr Labs pulled more than 80,000 submissions and over 5 GB out of it, spanning five years, including database passwords, cloud keys and corporate account credentials. Both policies do warn against saving confidential data there. Not many people read them.

So there is no side door here for the sake of convenience. To hand a result to someone, save it yourself and send it over a channel you trust.