Privacy & Security Resources | ricalNet Recommendations

Access ricalNet's curated collection of privacy and security tools, software recommendations, and digital protection guides. All resources adhere to strict evaluation criteria for effectiveness and trustworthiness.

Ultra Password

Generate & Protect Your Digital Identity

Generate password

Prabu Incognito

Transparent, open source tools for your privacy & security

Install

ricalDev

No Tracking, No Logging.

Check the tools

ricalNet Guides #

  • Video thumbnail - The ULTIMATE Windows Privacy & Security Guide!

    Pelacakan digital adalah praktik sistematis dalam mengumpulkan, memproses, dan menganalisis data aktivitas pengguna melalui infrastruktur teknologi, algoritma, dan protokol khusus. Artikel ini menggabungkan tinjauan umum dan analisis teknis mendalam tentang metode, arsitektur, implikasi keamanan, serta regulasi yang terkait dengan pelacakan oleh entitas seperti Big Tech dan pemerintah.

  • Video thumbnail - The ULTIMATE Windows Privacy & Security Guide!

    Kebutuhan untuk melindungi informasi pribadi sering kali dipandang sebagai sesuatu yang terlalu rumit atau bahkan mencurigakan. Padahal, menjaga privasi adalah hak kita sebagai pengguna teknologi.

Software, hardware and applications

Affiliate Link: Some services link to their official site, with a separate affiliate link if you choose to support ricalNet. View our strict requirements here. To view all affiliates, visit here.

marks a favorite. They don't represent every threat model and shouldn't be over-analyzed.

Web Browsers #

Tor Browser #

Open SourceGecko

The Tor Browser is one of the safest browsing experiences by prioritizing anonymity & freedom of information above all else. It's one of the most effective and accessible anonymity tools.

Mullvad Browser #

Open SourceGecko

Mullvad Browser offers a fantastic middle-ground between the strong protections of a hardened Firefox, and the advantages of Tor Browser for desktop. It's co-developed by Mullvad & the official Tor Project.

Brave #

Open SourceChromiumWebkit - iOS

Brave attempts to offer a familiar browser experience with privacy & security by default. Brave does many neat things for users out-of-the-box, but a possible annoyance is the cryptocurrency features. (Can be disabled)

Firefox/Focus #

Open SourceGeckoWebkit - iOS

Firefox is a fantastic alternative to the Chromium monopoly. Mozilla is a non-profit which aims to provide digital rights to everybody. We have a Firefox hardening guide below.

Onion Browser#

Open SourceWebkit

Onion Browser is an unofficial Tor Browser application for iOS. Due to iOS limitations, it should not be considered as safe as the official Tor Browser, though it still offers users a layer of anonymity.

LibreWolf#

Open SourceGecko

LibreWolf tackles most Firefox hardening out-of-the-box & does a decent job of maintaining security updates.

Cromite#

Open SourceChromium

Cromite is a Chromium fork based on Bromite with built-in support for ad blocking and an eye for privacy. It is currently supported on Android, Windows, & Linux.

Safari#

ProprietaryWebkit

Apple's Safari offers users in the Apple ecosystem a moderately safe default browser with basic privacy & security precautions out-of-the-box. Consider using AdGuard for further protections. We strongly recommend Safari specifically to users using 'Lockdown Mode' on iOS, as it's the way only to exclude trusted websites.

uBlock Origin #

Open SourceExtensionFree

The king of browser extensions. Just installing it will make any browser far more private & secure, and you can customize it to your heart's content. Install UBO in any browser for yourself or a loved one to make an immediate impact on their safety (and sanity!) online.

AdGuard#

Open SourceExtensionFree Tier

For those using Safari, AdGuard is a great option to block ads, trackers, phishing, use custom DNS, and more.

Password Managers #

KeePass #

Open SourceFree

KeePass is a secure & customizable password manager, but it requires work to function as conveniently as some users may expect. We have recommended clients below to make the experience as smooth as possible.

KeePassXC (client) #

Open SourceFreeWindowsmacOSLinux

KeePassXC is a modern, secure, & customizable KeePass client available on all major desktop operating systems with active development.

KeePassDX (client) #

Open SourceFreeAndroid

KeePassDX is a KeePass client for Android available on F-Droid and the Google Play Store with a modern interface, active development, and strong trust in the community.

Strongbox (client)#

Open SourceFree TieriOSmacOS

Strongbox is a beautiful KeePass client that integrates well with iOS & MacOS devices, even offering the option for E2EE syncing via iCloud. They also now use a local network sync to avoid the cloud altogether. Warning: They were recently acquired by Applause and we have yet to see the impact on Strongbox.

KeePassium (client)#

Open SourceFree TieriOSmacOS

KeePassium combines the security of KeePass with a clean intuitive design for iOS & MacOS. Since Strongbox's acquisition, many are migrating to KeePassium.

Proton Pass #

Open SourceFree Tier

Proton Pass is a secure password manager integrated with the Proton ecosystem with an emphasis on a simple user experience. Its built-in email aliasing is an attractive feature, along with its UI/UX.

Bitwarden #

Open SourceFree Tier

Bitwarden is a trusted, cloud-based option with zero-knowledge encryption to keep you safe. They offer an attractive experience for password management, with the option for self-hosting.

1Password#

ProprietaryPaid

1Password is an option for users who aren't happy with other offerings. It is similar to most 'mainstream' cloud-based managers, while having an excellent privacy & security record.

2FA #

Ente Auth #

Open SourceFreeiOSAndroidDesktopWeb

Ente's E2EE 2FA app. A cross platform TOTP app with secure online backups on all major operating systems.

Aegis#

Open SourceFree

Aegis is one of the most polished & simple TOTP services for Android.

Yubikey #

Proprietary

Yubikey is one of the most polished and trusted U2F solutions.

SoloKeys#

Open Source

SoloKeys provide affordable, open source U2F hardware.

Nitrokey#

Open Source

Nitrokey provides affordable, open source U2F hardware and more private payment methods.

Encryption #

Veracrypt #

Open Source

Veracrypt offers users encrypted volumes, and on some operating systems full disk encryption. It is a great option for those needing maximum security.

GNU Privacy Guard#

Open Source

GnuPG offers flexible encryption options across different mediums for users needing a more versatile option, at the cost of generally being more advanced.

7-zip#

Open Source

7-Zip is an archiving tool with basic file encryption options. It is not as robust as the other options and should be used with caution for sensitive tasks.

Firewalls #

Portmaster #

Open SourceWindowsLinux

Powerful (& beautiful) firewall program for Windows & Linux to give you finer control over what your device connects to.

Lulu #

Open SourcemacOS

Firewall program for MacOS to give you finer control over what your device connects to.

rethinkDNS #

Open SourceAndroid

Block malware, spyware, ads, and trackers across all apps with Rethink DNS. Servers in 300+ locations: Experience Blazing fast speeds.

NetGuard#

Open SourceAndroid

Firewall program for Android (no root required) to give you finer control over what your device connects to. Warning: NetGuard by default takes the place of a VPN on Android.

Applications #

F-Droid #

Open SourceAndroid

F-Droid is the go-to FOSS app store for all Android devices.

Aurora Store #

Open SourceAndroid

Aurora Store allows users to download apps directly from the Google Play Store without a Google Account safely.

Obtainium#

Open SourceAndroid

Obtainium enables you to install & update apps directly from developers, no app stores necessary.

Exodus Privacy #

Open SourceAndroidWeb

Analyzes privacy concerns in Android applications. Many iOS applications will use similar trackers, so this is a useful tool to check trackers for applications before downloading.

AltStore#

Open SourceiOS

AltStore allows iOS users to install IPA files (apps) to their device without the App Store. Apple's restrictions, however, make this a generally limited experience. Europeans can install AltStore PAL for an improved sideloading experience.

Operating systems

Affiliate Link: Some services link to their official site, with a separate affiliate link if you choose to support ricalNet. View our strict requirements here. To view all affiliates, visit here.

marks a favorite. They don't represent every threat model and shouldn't be over-analyzed.

Desktop Operating Systems #

Fedora #

Open SourceLinuxModerate

Fedora has strong out-of-the-box privacy & security practices, all backed by a trustworthy and commited team. Use Fedora Silverblue for an even more secure, atomic experience.

QubesOS #

Open SourceXenAdvanced

Qubes separates programs & operating systems into secure environments for maximum safety. It can be slower and may have compatibility issues with certain hardware.

Whonix#

Open SourceVirtual MachineLive OS

Whonix offers both a virtual and live environment with a goal of anonymity. All activities are routed through Tor with strong privacy & security precautions.

TailsOS#

Open SourceLive OS

TailsOS offers a Tor-routed live environment for privacy & anonymity.

Arch#

Open SourceLinuxAdvanced

Arch offers bleeding-edge updates with a more configurable option for users. Many looking to harden Linux themselves enjoy the flexibility offered by Arch.

Linux#

Open SourceLinuxVariable

Not every Linux distro is created equal. But almost all guarantee better privacy, digital control, and open source values. Click to use Distrochooser to help you find which distro makes sense for you.

MacOS #

ProprietaryAppleSimple

For users unable to use Linux for one reason or another: MacOS can be a reasonably private & secure option for many threat models. Despite being proprietary, it offers decent protection and is a great alternative to Windows. Please refer to the guide below for our MacOS hardening guide.

Android #

GrapheneOS #

Open SourceOnly Pixels

A private and secure mobile operating system with Android app compatibility via Sandboxed Google Play Services. Developed as a non-profit open source project.

CalyxOS #

Open SourceSome devices

CalyxOS maintains quality protection for most users, while offering many usability features via MicroG for app compatibility. Developed by a non-profit Calyx Institute with moderate device compatability.

LineageOS#

Open SourceMany devices

LineageOS is an option for those chasing a de-Googled device, with large device compatibility. Less security than GrapheneOS & CalyxOS, but also introduces OS security updates to EOL devices.

MicroG#

Open Source

MicroG is an open source replacement to proprietary Google Play Services. It allows apps & services to work as intended in a more privacy-respecting & transparent fashion on most custom ROMs.

Other services

Affiliate Link: Some services link to their official site, with a separate affiliate link if you choose to support ricalNet. View our strict requirements here. To view all affiliates, visit here.

marks a favorite. They don't represent every threat model and shouldn't be over-analyzed.

Search engines #

SearXNG #

Open SourceMetasearchFree

SearXNG is an open source, configurable, self-hostable, metasearch engine that compiles results from countless search engines in the same place.

Mullvad Leta#

ProprietaryMetasearchFree

Mullvad's Leta uses the Google Search API as a proxy to deliver Google results privately. It also proxies Brave Search results.

DuckDuckGo#

ProprietaryMetasearchFree

DuckDuckGo is a metasearch engine with mainly Bing results and an emphasis on user privacy.

Startpage#

ProprietaryMetasearchFree

Startpage is a metasearch engine with privately proxied Google and Bing results.

Kagi#

ProprietaryCrawlerPaid

Kagi is a paid search engine that promises privacy with a sustainable business model. No ads, no tracking.

VPNs #

Mullvad VPN #

Open SourcePaid

Mullvad is one of the most transparent providers with some of the most robust measures to keep users safe. Use the VPN Toolkit below to compare VPNs more thoroughly.

IVPN #

Open SourcePaid

IVPN, similar to Mullvad is one of the most transparent providers with some of the most robust measures to keep users safe. Use the VPN Toolkit below to compare VPNs more thoroughly.

Proton VPN#

Open SourceFree tier

Proton VPN is included in the Proton ecosystem and offers a very safe experience. Use the VPN Toolkit below to compare VPNs more thoroughly.

Windscribe#

Open SourceFree tier

Windscribe is a great VPN provider for an excellent value. Use the VPN Toolkit below to compare VPNs more thoroughly.

Orbot#

Open SourceAndroidiOS

While not a traditional VPN, Orbot allows users to connect to the Tor network on mobile devices via a system VPN connection. It does not offer the same anonymity the Tor Network provides in other contexts, but it's a free and easy way to protect your traffic and connect to onion sites on mobile.

DNS #

NextDNS #

Free tier

NextDNS offers a highly customizable DNS solution for the upmost control across your devices in a simple interface.

Mullvad DNS #

Free

Mullvad offers a free private & secure DNS service with several blocklist options for limited customization.

Quad 9#

Free

Quad9 offers a private & secure DNS service.

CONTROL D#

Paid

CONTROL D offers a highly customizable DNS solution for the upmost control across your devices. There's a discount available for Windscribe customers as they are from the same company.

Messengers #

Briar #

Open SourceAndroidDesktopFree

Briar is a Tor-routed, E2EE, P2P, anonymity-oriented messenger with some of the most robust protections. It can even be used without internet access.

Signal #

Open SourceAndroidiOSDesktopFree

Signal is the gold standard for private & secure messaging, all with a simple interface. Threat modeling is necessary though, as Signal requires a phone number to register which may be problematic for some. We recommend using Signal with usernames for improved privacy. Use our hardening guide below for max safety.

Molly#

Open SourceAndroidFree

Molly is an independent Signal fork for Android. You can use it alongside your regular Signal account for extra features & security perks. Keep in mind it's not officially endorsed by Signal and introduces a new party to trust.

SimpleX#

Open SourceAndroidiOSDesktopFree

SimpleX prides itself on requiring no identifiers, is decentralized, and is audited with fairly competitive features. Your data is your own with no central servers.

Session#

Open SourceAndroidiOSDesktopFree

Session strives for a balance between privacy, security, anonymity, & usability.

Matrix#

Open SourceAndroidiOSDesktopFree

Matrix is a federated protocol with the option for E2EE. There is a degree of trust with each homeserver, especially regarding metadata. Its federation is both a pro & a con that users should be aware of before using.

Threema#

Open SourceAndroidiOSDesktopPaid

Pay once, chat forever. E2EE messenger with solid practices. Open Source.

Email #

Proton Mail #

Open SourceFree tier

Proton Mail checks all the right boxes when it comes to adding privacy & security protections over the inherently broken email system, all while seeking a simple experience in a larger suite.

Tuta #

Open SourceFree tier

Tuta offers a transparent service with trust, security, and privacy as its focus. They are open source and implement fantastic protections for their users.

StartMail#

ProprietaryPaid

StartMail offers a polished web client with a feature-rich experience.

Mailbox.org#

ProprietaryPaid

Mailbox.org offers privacy & security with an incredibly feature-rich experience. It may be overwhelming and cluttered to some, or a power user's dream.

Fastmail#

ProprietaryPaid

User-friendly email with better privacy than Gmail. It lacks E2EE and advanced privacy features, but it's generally considered the most feature-rich option on this list.

Self-Host#

AdvancedVarying prices

Self-hosting is commonly touted as the safest email approach, but this isn't always the case. Self-hosting comes with risks you should read in the referenced link. Generally speaking, we do not recommend self hosting to many people.

Aliasing #

Proton Pass #

Open SourceFree Tier

Proton Pass is a password manager with built-in support for email aliasing via SimpleLogin.

SimpleLogin #

Open SourceFree tier

SimpleLogin makes email aliasing easier than ever, all built with privacy & security from the ground up. SimpleLogin can also be self-hosted or utilized via Proton Pass.

addy.io#

Open SourceFree tier

addy.io (previously AnonAddy) is a private & secure email aliasing service with a very generous free option. It's the main alternative to SimpleLogin/Proton Pass.

MySudo #

ProprietaryPaid

MySudo is predominantly a phone number aliasing solution. Like most aliasing solutions, it's a transfer of trust from countless services to one.

Privacy.com#

ProprietaryFree tierUS only

Privacy.com is a card aliasing solution for shopping online. Like most aliasing solutions, it's a transfer of trust from countless services to one.

Guerrilla Mail#

ProprietaryFree

Guerrilla Mail is a disposable email service, allowing users to generate ephemeral emails conveniently.

Cloud #

NextCloud #

Open SourceVarying prices

Nextcloud is a self-hostable suite for photos, documents, files, contacts, and more. It's a robust service, with the main drawback being an unpolished E2EE offering. You can either use a trusted organization to host your data, or ideally you host your own data.

Filen #

Open SourceFree tier

Open source, E2EE cloud storage with many advanced features in a fresh UI. Beyond documents, they also support photos, chats, and more!

Proton Drive#

Open SourceFree tier

Proton's drive offering within the Proton ecosystem with security in mind. It's still not a complete suite for every operating system, but it has basic functionality for many use-cases.

MEGA#

Source-availableFree tier

MEGA is a more traditional cloud provider with E2EE and usable, source-available clients.

Cryptomator #

Open SourceFree

Cryptomator allows users to encrypt their files before uploading them to another mainstream cloud provider (Google Drive, Dropbox, iCloud etc.) - it's a great way to still use the cloud provider of your choice with improved security.

OnionShare #

Open SourceDesktop

OnionShare allows users to share files, websites, chats, and more over the Tor network directly from their system with no central parties for absolute safety.

Syncthing #

Open SourceAll devices

Syncthing allows users to easily sync files between devices without needing to upload them to the internet.

Notes, docs & photos #

Cryptee #

Open SourceFree tier

Cryptee offers E2EE notes, documents, & photos with a modern theme as a PWA. It is not collaborative nor designed for external sharing.

Notesnook #

Open SourceFree tier

Notesnook offers E2EE notes & documents for people looking for a feature-filled experience in their workflow.

Standard Notes#

Open SourceFree tier

Standard Notes is a secure note-taking app with end-to-end encryption, privacy features, and cross-platform syncing on unlimited devices.

CryptPad#

Open SourceFree tier

CryptPad is an E2EE, document collaboration platform.

Ente #

Open SourceFree tier

Safe Home for your photos and videos. Store, share, and discover your memories with absolute privacy.

Cryptocurrencies #

Monero #

Open Source

Monero is one of the strongest, private-by-default cryptocurrencies to ensure the safety of transactions. Its wide adoption & community-first approach to privacy makes it the gold standard for private digital transactions with FCMP++ coming soon.

Zcash#

Open Source

Encrypted electronic cash. The first cryptocurrency to develop zero-knowledge encryption for private peer-to-peer payments.

Haveno#

Open Source

Haveno is a non-custodial, decentralized exchange platform for crypto and fiat currencies built on Tor and Monero.

Bisq Network#

Open Source

Bisq is a P2P, KYC-free, decentralized Bitcoin exchange.

Cake Wallet #

Open Source

Cake Wallet is a wallet to store your Bitcoin, Monero, & Litecoin in a trusted place.

Coincards#

Proprietary

Coincards has a vast selection of Gift Cards from America's top merchants. They allow you to buy these gift cards with numerous cryptocurrencies—including Bitcoin and Monero.

Other tools #

EasyOptOuts #

PaidProprietaryWebUS-Only

Easy & affordable data removal service. Nothing currently matches its value and transparency. Demonstrated to be effective through independent Consumer Reports research. Refer to BADBOOL below for manual instructions!

Optery#

Free-tierProprietaryWebUS-Only

Optery's paid plan is also effective, but far pricier than EasyOptOuts. We enjoy Optery's free plan to scan sites for your information to assist in manual opt-outs, or to double-check your data is removed from another automated service. Demonstrated to be effective through independent Consumer Reports research. Refer to BADBOOL below for manual instructions!

BleachBit #

Open SourceDesktop

BleachBit is a file shredding and data removal tool.

Dangerzone #

Open SourceDesktop

Dangerzone is a program to safely open potentially suspicious attachments.

AlternativeTo #

ProprietaryWeb

AlternativeTo allows users to find more privacy-respecting alternatives to the software they use.

Objective-See #

Open SourcemacOS

Objective-See offers a suite of open source security & privacy tools for MacOS.

External resources

Explore our curated list of organizations and tools that offer valuable insights, advocacy, and support for protecting your online freedoms. We don't have all the answers and encourage everyone to get information from multiple places!