Privacy and Terms of Service #40
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Opened 7 years ago
Last modified 2 years ago
#1120assignedtask
Privacy and Terms of Service
Reported by:zzzOwned by:sadie
Priority:
minor
Milestone:
eventually
Component:
www/i2p
Version:
Keywords:
Cc:
Parent Tickets:
#1632
Sensitive:
no
Description
Needs significant documentation and process improvement. Should cover server logs on all project websites and services, including reseed hosts if possible. Make clear what sites are and are not covered, both clearnet and in-network.
Not only a "good thing", but on the Open ITP checklist, i.e. a potential factor in funding / auditing decisions.
refs:
http://trac.i2p2.i2p/wiki/OpenITPReview/Criteria
Subtickets
Create inclusion policy for all third party services.
Third party service providers / functions should require assurances of proper security, data handling, monitoring, and their own ToS, transparency and contact information.
This should be listed within the router console and where I2P core software is distributed.
We do not assume privacy, we assure it.
Blind faith is not compatible with FOSS standards.
Policy for third party services included in I2P software should be included on the site.
Jump Services
Reseed
Outproxy
comment:6 Changed 2 years ago by zzz
pinned post in mm has list of who runs what, so you can turn that into the list of who has what logs.
comment:5 Changed 2 years ago by sadie
need to know who has what in terms of logs and create or discuss retention / security policy of data
outproxy ToS for operators and users needed
Best practices / considerations for users
comment:4 Changed 3 years ago by Eche|on
terms of service are harder.
On general:
be excellent to each other
do no harm, do not (D)DOS
do not do harrassment, lie, tell others bad stuff. no illegal stuff (based on EU laws)
admin has last word
reseed hosts: no more than getting seed files
geti2p: get information, not much more
forum: do discuss, help, create content based on on-topic content. No right to publish any content a user likes to, admin has admin rights
comment:3 Changed 3 years ago by Eche|on
Ok
reseed is a topic on its own, as those are not controlled by I2P itself.
Those do get the IP of the requester and may save them.
geti2p.net gets IP addresses of the requests and do drop those each day.
i2pforum.net gets IP addresses of the requests and drop those each day.
mtn.i2p2.de gets IP addresses of the requests and drop those each day.
Those .i2p hidden services get the requests b64 address, drop them each day.
i2pforum has username, password (encrypted with hash) and the user based content in a DB and keep them.
echelon
comment:2 Changed 3 years ago by zzz
Owner:
set to _sadie_Status:open →
assigned
comment:1 Changed 6 years ago by str4d
Milestone:
→ eventuallyParent Tickets:
→ 1632Status:new →
open