安全与隐私

June 24, 2026 · View on GitHub

本文档整合了以下源文件:privacy.md, privacy2.md, survival.md, sentinel.md, security.md, firewall.md, vpn.md


来源:privacy.md

目录

  1. 理解 VPN 技术
  2. Mullvad VPN 概述
  3. 安装与设置
  4. 配置选项
  5. 高级功能
  6. 隐私最佳实践
  7. 故障排除
  8. 安全考虑

理解 VPN

虚拟专用网络(VPN)在你的设备和远程服务器之间创建加密隧道,隐藏你的 IP 地址并保护你的在线活动免受监控。

VPN 工作原理

组件功能隐私益处
加密混淆数据防止窃听
IP 隐藏隐藏真实 IP 地址匿名浏览
隧道安全数据通道在公共 WiFi 上保护数据
断路器VPN 断开时阻止流量防止数据泄露

VPN 协议对比

协议速度安全性用途
WireGuard现代默认选择
OpenVPN中等成熟传统支持
IKEv2移动设备

威胁模型

威胁保护级别VPN 有效性
ISP 监控向 ISP 隐藏浏览记录
公共 WiFi 攻击加密所有流量
政府监控中等隐藏 IP,不能隐藏使用模式
定向攻击VPN 只是一层保护

Mullvad VPN 概述

Mullvad 是一家总部位于瑞典的隐私优先 VPN 服务,以其对用户隐私的坚定承诺和最少数据收集而闻名。

Mullvad 核心功能

功能描述隐私益处
无日志策略不追踪活动无数据可分享
账号号码无需邮箱匿名注册
现金支付邮寄选项不可追踪的支付
开源可审计代码透明度
WireGuard现代协议速度与安全

Mullvad vs 其他 VPN

功能Mullvad典型 VPN
注册要求仅需账号号码邮箱、姓名
日志记录不定
支付方式现金、加密货币、银行卡仅银行卡
价格固定 5 欧元/月不定
审计定期罕见

服务器网络

地区服务器数量用途
欧洲300+主要覆盖
北美100+快速连接
亚太50+区域访问
南美20+本地连接

安装与设置

在所有主要平台上安装 Mullvad VPN 都很简单。

系统要求

平台最低版本内存磁盘空间
Windows10 或更高2GB100MB
macOS11 或更高2GB100MB
LinuxUbuntu 20.04+2GB100MB
Android8.0 或更高1GB50MB
iOS15.0 或更高1GB50MB

安装步骤

步骤操作命令/位置
1下载应用mullvad.net/download
2安装应用程序运行安装程序
3创建账号生成账号号码
4添加时长支付页面
5连接选择服务器,点击连接

账号设置

Account Number Format: XXXX XXXX XXXX XXXX

Payment Options:
- Credit Card
- Bitcoin
- Cash (mail to Sweden)
- Bank Wire
- Swish (Sweden only)

配置选项

正确的配置可以针对你的特定需求优化安全性和性能。

连接设置

设置选项推荐
协议WireGuard, OpenVPNWireGuard
端口自动、自定义自动
DNS默认、自定义Mullvad DNS
断路器开/关始终开启
自动连接开/关开启

DNS 配置

DNS 提供商隐私性速度内容过滤
Mullvad 默认
Mullvad 过滤广告/追踪器
自定义不定不定不定

分流隧道

应用使用 VPN原因
网页浏览器隐私关键
银行应用可能阻止 VPN
游戏可选对延迟敏感
流媒体可选内容访问

高级网络设置

设置描述何时使用
IPv6启用/禁用 IPv6兼容性
本地网络访问局域网设备家庭网络
混淆隐藏 VPN 流量受限网络
桥接模式双重 VPN最大隐私

高级功能

Mullvad 为需要增强隐私和控制的用户提供高级功能。

多跳(双重 VPN)

配置路径用途
入口 → 出口国家 A → 国家 B增强隐私
同一国家城市 A → 城市 B区域隐私
不同国家任意组合最大匿名性

Shadowsocks 混淆

功能描述好处
协议SOCKS5 代理绕过 VPN 封锁
加密额外层隐藏 VPN 使用
用途审查网络访问被封锁的内容

自定义 DNS 服务器

服务器IP 地址用途
Cloudflare1.1.1.1速度
Google8.8.8.8可靠性
Quad99.9.9.9安全性
AdGuard94.140.14.14广告拦截

CLI 命令

# Connect to specific country
mullvad relay set location se

# Enable kill switch
mullvad lockdown-mode set on

# Check connection status
mullvad status

# Set DNS
mullvad dns set default

隐私最佳实践

将 VPN 与其他隐私措施结合可以创建全面的安全防护。

隐私清单

实践优先级实施方式
断路器关键始终启用
DNS 泄露保护关键使用 Mullvad DNS
自动连接随系统启动
WebRTC 泄露防护浏览器设置
HTTPS Everywhere中等浏览器扩展

浏览器配置

设置推荐原因
WebRTC禁用防止 IP 泄露
DNS over HTTPS启用加密 DNS
Cookies阻止第三方减少追踪
扩展uBlock Origin拦截广告/追踪器

设备级隐私

层级工具用途
操作系统全盘加密数据保护
应用应用权限限制访问
网络防火墙控制流量
浏览器隐私优先减少指纹识别

支付隐私

方式匿名性便利性
现金最高最低
加密货币中等
信用卡最高
银行转账中等

故障排除

Mullvad VPN 常见问题及解决方案。

连接问题

问题可能原因解决方案
无法连接防火墙阻止允许 Mullvad 通过防火墙
速度慢服务器过载切换服务器
频繁断开网络不稳定更改协议
DNS 泄露配置问题重新安装应用

速度优化

因素影响解决方案
服务器距离选择更近的服务器
服务器负载中等选择较空闲的服务器
协议中等使用 WireGuard
加密级别默认设置

常见错误信息

错误含义修复
"Blocked"断路器已激活重新连接 VPN
"DNS error"DNS 解析失败更改 DNS 设置
"Auth failed"账号问题检查账号状态
"Timeout"连接太慢尝试其他服务器

诊断命令

# Check public IP
curl ifconfig.me

# Test DNS leak
nslookup example.com

# Check connection logs
mullvad relay get

# Reset settings
mullvad reset

安全考虑

了解 VPN 的局限性和补充安全措施。

VPN 安全模型

保护VPN 提供VPN 不提供
IP 隐藏-
加密-
匿名性部分完全匿名
恶意软件防护需要杀毒软件
钓鱼防护需要意识

威胁缓解矩阵

威胁VPN其他工具
ISP 窥探有效-
WiFi 窃听有效-
恶意软件杀毒软件
钓鱼邮件过滤器
浏览器追踪部分隐私浏览器
社会工程用户教育

审计历史

年份审计方范围结果
2020Assured AB基础设施通过
2021Cure53应用安全通过
2022Assured AB策略合规通过

总结

主题核心要点
协议WireGuard 提供最佳的速度-安全平衡
配置启用断路器和 DNS 泄露保护
隐私结合 VPN 与浏览器和设备隐私
支付现金或加密货币实现最大匿名性
维护保持应用更新并检查连接状态

来源:privacy2.md

简介

Awesome Privacy 是一个精心策划的尊重隐私的软件和服务列表。本指南涵盖了维护数字隐私的基本工具,涵盖从通信到浏览和文件存储的各个类别。

目录

  1. 隐私原则
  2. 通信工具
  3. Web 浏览器
  4. 电子邮件服务
  5. 云存储
  6. VPN 服务
  7. 操作系统
  8. 密码管理器
  9. 搜索引擎

隐私原则

原则说明
数据最小化仅收集必要数据
端到端加密仅发送方和接收方可读
开源可审计的代码
无遥测无使用跟踪
本地处理数据保留在设备上
零知识提供商无法访问您的数据

通信工具

即时通讯应用

应用平台E2E 加密开源可自托管
Signal全平台
Matrix/Element全平台
BriarAndroid
Session全平台
Wire全平台部分

对比详情

功能SignalMatrixBriarSession
需要手机号
群聊
语音通话
视频通话
文件共享
元数据保护良好中等优秀优秀

语音和视频

应用平台加密可自托管
Jitsi MeetWeb可选
BigBlueButtonWeb
Mumble桌面
Tox桌面

Web 浏览器

浏览器对比

浏览器引擎隐私重点扩展移动端
FirefoxGecko优秀
BraveChromium良好
Tor BrowserGecko最高有限
LibreWolfGecko最高良好
Mullvad BrowserGecko最高有限

Firefox 加固设置

设置影响
privacy.resistFingerprintingtrue减少指纹识别
network.http.referer.XOriginPolicy2限制来源数据
dom.event.clipboardevents.enabledfalse阻止剪贴板跟踪
media.navigator.enabledfalse阻止摄像头/麦克风访问

必备隐私扩展

扩展用途浏览器
uBlock Origin广告/跟踪器拦截全部
HTTPS Everywhere强制 HTTPS大多数
NoScriptJavaScript 控制Firefox
Privacy Badger跟踪器拦截大多数
Cookie AutoDeleteCookie 管理大多数

电子邮件服务

注重隐私的邮件提供商

提供商E2E 加密存储价格管辖权
ProtonMail1 GB 免费免费增值瑞士
Tutanota1 GB 免费免费增值德国
Mailbox.org2 GB1 欧元/月德国
Disroot1 GB免费荷兰
Posteo2 GB1 欧元/月德国

邮件安全功能

功能ProtonMailTutanotaMailbox.org
零访问加密
PGP 支持
日历
联系人
自定义域名付费付费
IMAP/SMTPBridge

邮件别名服务

服务免费额度域名用途
SimpleLogin10 个别名多个转发
AnonAddy20 个别名多个转发
Firefox Relay5 个别名1转发

云存储

注重隐私的存储

提供商E2E 加密开源存储价格
Nextcloud插件服务器 + 客户端自托管免费
Tresorit1 GB 免费高级
Cryptomator任意存储免费
MEGA部分20 GB 免费免费增值
Syncthing不适用P2P免费

Nextcloud 与替代方案

功能NextcloudTresoritMEGA
可自托管
文件同步
日历
联系人
办公套件
最大文件大小无限制5 GB不等

VPN 服务

可信 VPN 提供商

提供商日志管辖权协议价格
Mullvad瑞典WireGuard5 欧元/月
ProtonVPN瑞士WireGuard, OpenVPN免费增值
IVPN直布罗陀WireGuard, OpenVPN6 美元/月起
AirVPN意大利WireGuard, OpenVPN2 欧元/月起

VPN 协议对比

协议速度安全性已审计推荐
WireGuard
OpenVPN中等
IKEv2
L2TP/IPsec中等中等

VPN 选择标准

标准重要性关注点
无日志政策关键独立审计
管辖权14 眼联盟之外
开源可审计客户端
支付方式中等接受加密货币
服务器数量质量优于数量

操作系统

注重隐私的操作系统

操作系统平台基于隐私级别
Tails桌面Debian最高
Qubes OS桌面Fedora/Xen
GrapheneOS移动Android
CalyxOS移动Android
LineageOS移动Android中等

移动操作系统对比

功能GrapheneOSCalyxOSLineageOS
仅 Pixel
沙盒增强标准标准
MicroG可选
验证启动
默认应用最小标准不等

密码管理器

密码管理器对比

管理器开源E2E 加密平台价格
Bitwarden全平台免费增值
KeePassXC仅本地桌面免费
1Password全平台高级
Proton Pass全平台免费增值
KeePassDX仅本地Android免费

功能对比

功能BitwardenKeePassXCProton Pass
云同步
浏览器扩展
TOTP 支持
文件附件
紧急访问
可自托管不适用

搜索引擎

隐私搜索引擎

引擎结果来源广告跟踪即时答案
DuckDuckGoBing是(非跟踪)
StartpageGoogle是(非跟踪)
SearXNG多个
Brave Search自有索引
Mojeek自有索引有限

搜索引擎选择

使用场景推荐
通用隐私DuckDuckGo 或 Brave Search
Google 结果Startpage
可自托管SearXNG
无跟踪Mojeek
学术搜索SearXNG 配合学术引擎

其他工具

DNS 隐私

提供商DNS-over-HTTPSDNS-over-TLS日志
Cloudflare临时
Quad9临时
NextDNS可配置
Mullvad

元数据移除

工具平台支持格式
ExifTool全平台所有格式
mat2Linux图像、文档、媒体
ExifCleaner桌面图像、PDF
Scrambled ExifAndroid图像

总结

维护数字隐私需要为通信、浏览、存储和系统安全选择适当的工具。具有端到端加密的开源解决方案提供最强的隐私保障。本指南中列出的工具代表了每个类别的成熟选项,允许用户构建全面的隐私优先工作流。


来源:survival.md

The Rule of 3

Survival priorities are governed by a simple framework:

PriorityTime LimitAction
Air / severe bleeding3 minutesAddress immediately -- clear airways, stop hemorrhaging
Shelter / body temperature3 hoursProtect from exposure in extreme conditions
Water3 daysSecure a water source
Food3 weeksFind calories (lowest priority in short-term survival)

In most outdoor emergencies, exposure (hypothermia or hyperthermia) is the first lethal threat, not starvation or dehydration. Build or find shelter before searching for water.

Shelter Building

Site Selection

  • Avoid dry riverbeds (flash flood risk).
  • Avoid lone trees and hilltops (lightning risk).
  • Avoid avalanche paths, rockfall zones, and dead trees with hanging branches.
  • Look for natural windbreaks: rock faces, dense tree lines, ridges.
  • Stay slightly elevated to avoid cold air pooling in valleys.

Emergency Shelter Types

ShelterMaterialsTime to BuildBest For
Debris hutBranches, leaves, pine needles1-2 hoursCold weather, solo
Lean-toLong branches, tarp/poncho30-60 minModerate conditions
Snow caveCompact snow1-3 hoursDeep snow, extreme cold
A-frame tarpCordage, tarp/poncho15-30 minRain, mild cold
Natural shelterCaves, rock overhangsMinimalAny conditions (check for occupants)

Debris Hut Construction

  1. Find a ridgepole -- a sturdy branch about 9 feet long.
  2. Prop one end on a stump or rock at about 3 feet high, or wedge into a tree fork.
  3. Lean shorter branches along both sides to form an A-frame.
  4. Pile debris (leaves, pine needles, grass) thickly over the frame -- at least 2 feet deep.
  5. Line the inside with dry debris for insulation from the ground.
  6. Keep the entrance small and plug it with debris when inside.

The inside should be just large enough for your body. A smaller space retains heat better.

Water Purification

Dehydration kills within days. Never skip water purification in the backcountry.

Methods

MethodKills Bacteria?Kills Viruses?Removes Chemicals?Notes
Boiling (1 minute at rolling boil)YesYesNoMost reliable method
Chemical treatment (iodine/chlorine)YesYes (with wait time)NoTaste can be unpleasant; follow dosage carefully
UV light (SteriPEN)YesYesNoRequires batteries; clear water works best
Pump filter (0.2 micron)YesNo (most models)NoFast; backflush to maintain
Gravity filter (Sawyer, Platypus)YesNo (most models)NoGood for groups; slow
SODIS (sunlight in clear bottles)PartialPartialNoLast resort; requires 6+ hours of direct sun
Boiling + charcoal filterYesYesPartialImproves taste after boiling

Water Source Priority

  1. Spring water emerging from rock -- generally safest natural source.
  2. Fast-moving streams in forested, uninhabited areas.
  3. Lakes and ponds (requires thorough treatment).
  4. Puddles and standing water (last resort; heavy treatment needed).
  5. Snow -- melt before drinking. Eating snow lowers body temperature.

Fire Starting

Fire provides warmth, purifies water (via boiling), signals rescuers, and boosts morale.

Fire Triangle

You need three elements: heat (ignition), fuel (wood), and oxygen (airflow). Remove any one and the fire dies.

Ignition Methods

MethodReliabilitySkill RequiredNotes
Waterproof matchesHighMinimalCarry in sealed container
Butane lighterHighMinimalMay fail at altitude or extreme cold
Ferrocerium rodHighModerateWorks wet, lasts thousands of strikes
Magnifying lens / Fresnel lensModerateLowRequires direct sunlight
Bow drillLow (for beginners)HighFriction fire; requires practice
Flint and steelModerateModerateTraditional; requires char cloth or tinder

Fire Lay Structure

  1. Tinder: Fine, dry material that catches a spark. Examples: birch bark shavings, dryer lint, cotton balls with petroleum jelly, dry grass, cedar bark fibers, fatwood shavings.
  2. Kindling: Pencil-thin dry sticks and twigs.
  3. Fuel: Progressively larger wood, from finger-thick to wrist-thick.

Build in a teepee or log cabin structure. Light the tinder, add kindling as the flame grows, then add fuel gradually. Do not smother a young fire with too much wood too soon.

Map and Compass

The most reliable navigation method. Electronics fail; a compass does not.

Basic compass use:

  1. Hold the compass flat in front of you.
  2. Rotate the bezel until the red magnetic needle aligns with the orienting arrow (red in the shed).
  3. Read your bearing at the index line.
  4. To follow a bearing: rotate your body until the needle aligns, then walk toward a landmark in that direction.

Declination: Magnetic north and true north differ. Adjust your compass or account for the difference (shown on your topographic map).

Map Reading Essentials

SymbolMeaning
Contour lines close togetherSteep terrain
Contour lines far apartGentle terrain
V-shape pointing uphillValley or stream
V-shape pointing downhillRidge
Blue lines/shapesWater features
Brown linesElevation contours
Green shadingVegetation

Natural Navigation

When you lack a compass:

MethodTechnique
Sun positionSun rises in the east, sets in the west. At solar noon it is due south (northern hemisphere) or due north (southern hemisphere).
Shadow stickPlant a stick upright. Mark shadow tip. Wait 15 minutes. Mark again. The line from first to second mark runs roughly west-to-east.
North Star (Polaris)Locate the Big Dipper. The two stars forming the outer edge of the cup point toward Polaris. Polaris indicates true north.
Moss and vegetationUnreliable as a sole indicator. Moss often grows on the shaded side of trees in humid climates, but it grows on all sides too. Use only as a corroborating clue.
Prevailing windIf you know the prevailing wind direction for the area, you can orient from it.

Edible Plants

Critical warning: Misidentifying plants can be fatal. Do not eat any plant you cannot identify with certainty. When in doubt, do not eat it.

The Universal Edibility Test

If you must test an unknown plant and have no other food source:

  1. Test for contact reaction: Rub on inner wrist. Wait 15 minutes.
  2. Test for lip reaction: Touch to corner of mouth. Wait 15 minutes.
  3. Test for tongue reaction: Place on tongue. Wait 15 minutes.
  4. Test for mouth reaction: Chew and hold in mouth (do not swallow). Wait 15 minutes.
  5. Test for digestion: Swallow a small amount. Wait 8 hours.

If any reaction occurs at any stage, stop immediately.

Commonly Recognizable Edible Plants (Temperate Regions)

PlantParts EatenIdentification
CattailShoots, roots, pollenTall marsh plant with brown cigar-shaped heads
DandelionLeaves, flowers, rootsAll parts edible; unmistakable yellow flower
PineInner bark, needles (tea)Any pine species; needle tea provides vitamin C
Acorns (processed)NutsMust leach tannins by soaking in water
Wild garlic/rampsLeaves, bulbsOnion/garlic smell when crushed
BlackberriesFruitThorny brambles; berries in late summer

Plants to Avoid

  • Any plant with milky or discolored sap.
  • Any plant with a bitter or soapy taste.
  • Umbrella-shaped flower clusters (resemble poison hemlock).
  • Beans or seeds from pods you cannot identify.
  • Any plant with a strong almond scent in the leaves (cyanide compounds).

Signaling for Rescue

MethodVisibilityHow
Signal fire (3 in a triangle)10+ miles in daylight; farther at nightThree fires spaced 100 feet apart is an international distress signal
Whistle1 mileThree blasts = distress signal. Easier than shouting and carries farther
Mirror / reflective surface10+ miles in sunlightFlash toward aircraft or distant observers
Ground-to-air signalsAircraft altitudeLarge letters made with rocks, logs, or stomped in snow. X = need help, V = need assistance, arrow = direction of travel
Bright clothing / gearVisual rangeSpread out on open ground for contrast
GPS messenger (PLB / inReach)SatelliteActivates search and rescue directly

First Aid Basics

SituationAction
Severe bleedingApply direct pressure with clean cloth. If bleeding cannot be controlled, apply a tourniquet 2-3 inches above the wound and note the time.
FractureSplint in the position found. Use sticks, trekking poles, or rolled clothing. Immobilize the joints above and below.
HypothermiaRemove wet clothing. Insulate from the ground. Provide warm drinks (not alcohol). Skin-to-skin contact if severe.
Heat exhaustion / heat strokeMove to shade. Remove excess clothing. Cool with water on neck, armpits, groin. Heat stroke (confusion, no sweating) is a medical emergency.
SnakebiteKeep calm and still. Remove jewelry near the bite. Do not cut, suck, or tourniquet. Evacuate.
Allergic reaction (anaphylaxis)Use epinephrine auto-injector if available. Elevate legs. Evacuate.

Weather Reading

SignLikely Weather
Rapidly falling barometric pressureStorm approaching
High, thin cirrus clouds thickeningRain or snow within 24-48 hours
Towering cumulus cloudsThunderstorms possible
Red sky at night (clear western horizon)Fair weather (mid-latitude)
Sudden temperature drop with windCold front passing; precipitation likely
Increasing wind speed with falling pressureDeteriorating conditions
Ring around the moonMoisture in upper atmosphere; rain likely within 1-2 days

Gear Checklist

The Ten Essentials

ItemPurpose
Navigation (map, compass, GPS)Know where you are and where to go
Sun protection (sunscreen, sunglasses, hat)Prevent sunburn, snow blindness
Insulation (extra layers)Prepare for unexpected weather
Illumination (headlamp, spare batteries)See and be seen after dark
First aid kitTreat injuries
Fire starter (matches, lighter, ferro rod)Warmth, water purification, signaling
Repair tools (knife, duct tape, cordage)Fix gear, build shelter
Nutrition (extra food)Energy for unexpected delays
Hydration (extra water, purification)Prevent dehydration
Emergency shelter (tarp, bivvy, space blanket)Protection from exposure

Additional Recommendations

  • Tell someone your plan: where you are going, your route, and when you expect to return.
  • Carry a whistle on your person, not in your pack.
  • A knife with a fixed blade is more reliable than a folding knife in survival situations.
  • Duct tape wrapped around a water bottle or trekking pole saves pack weight and is endlessly useful.

来源:sentinel.md

Source: https://github.com/kr-stn/awesome-sentinel

Overview

This tutorial covers the key resources and tools from the kr-stn/awesome-sentinel project.

Awesome Sentinel

A curated list of awesome tools, tutorials and APIs related to data from the Copernicus Sentinel Satellites.

Data Hubs and National Mirrors

Official datahubs and mirrors by the Copernicus partners and Collaborative Ground Segment members.

Partial Mirrors

Initiatives to integrate specific Sentinel data into existing search and discovery platforms.

Cloud Providers

Providers that host Copernicus Sentinel data and allow you to bring your own code to process it without the need to download the data.

DIAS

Data and Information Access Services (DIAS), funded by the European Commission "providing centralised access to Copernicus data and information, as well as to processing tools"

  • CREODIAS
  • MUNDI
  • ONDA DIAS
    • VM Infrastructure as a Service, with an API for access to hosted Copernicus data
  • sobloo
    • on-demand processing of thematic products with link to other data-sets (i.e. geo-marketing)
  • WEkEO
    • harmonised data access with a REST API, hosted VM options

Tools

Specific to Copernicus Sentinel data discovery, download and processing.

Search & Download

Viewers & Portals

Processing

  • SNAP (Sentinel Application Plattform)
    • (pre-)process any Sentinel data
    • also available as docker
  • ARCSI (Atmospheric and Radiometric Correction of Satellite Imagery)
    • atmospheric correction of Sentinel-2 data
  • Google Earth Engine
    • process the global Sentinel archives directly on Google's servers
  • EOS Processing
    • workflow library for thematic processing of (Sentinel-2) satellite data
  • iCOR
    • atmospheric correction of Sentinel-2 data
    • available as SNAP plugin
  • MAJA (MACCS ATCOR Joint Algorithm)
    • atmospheric correction of Sentinel-2 data using time series
    • used for Theia and Sen2-Agri
  • Sen2-Agri
    • toolbox for processing images for agricultural purposes
    • includes modules for atmospheric correction, monthly syntheses, biophysical variables, crop mask, crop-type classification and an orchestrator
  • s2cloudless
  • Sen2Cor
    • atmospheric correction of Sentinel-2 data
    • basis for L2A data published on Copernicus Open Access Hub
  • sen2r
    • R toolbox to search, download and pre-process Sentinel-2 data
  • ACOLITE
    • atmospheric correction algorithms for aquatic applications of Landsat and Sentinel-2
  • C2RCC
    • atmospheric correction of Sentinel-3 and -2 for coast colour applications
    • included in the SNAP toolbox for Sentinel-3
  • i.sentinel.mask
    • GRASS GIS addon for atmospheric correction of Sentinel-2 including cloud and shadow detection
  • sat-stac-sentinel
    • convert original Sentinel-1 and -2 metadata into STAC items
  • EOReader
    • Opensource Python library reading Sentinel-1, 2, 3, and other optical and SAR sensors - loading and stacking bands in a sensor-agnostic way
  • xsar
    • read Sentinel-1 data into xarray for further processing
  • FORCE Processing Framework
    • Generate analysis ready data for Sentinel-2 and Landsat-4/5/7/8/9 (including atmospheric correction and homogenization of Sentinel-2 and Landsat data)

Key Resources

ResourceLink
Copernicus Sentinel Satelliteshttp://www.copernicus.eu/main/sentinels
Collaborative Ground Segment membershttps://sentinels.copernicus.eu/web/sentinel/missions/collaborative/national-points-of-contact
Copernicus Data Spaces Ecosystem (CDSE)https://dataspace.copernicus.eu/
Australia National Mirrorhttps://copernicus.nci.org.au/
Austria National Mirrorhttps://data.sentinel.zamg.ac.at/
Czech Rebublic National Mirrorhttps://dhr1.cesnet.cz/#/home
Estonia National Mirrorhttps://geoportaal.maaamet.ee/eng/Spatial-Data/National-Satellite-Data-Centre-ESTHub-p654.html
Finland National Mirrorhttps://finhub.nsdc.fmi.fi/
France National Mirror (PEPS)https://peps.cnes.fr/rocket/
Germany National Mirror (CODE-DE)https://code-de.org/
Greece National Mirrorhttps://sentinels.space.noa.gr/
Luxembourg National Mirrorhttps://www.collgs.lu/
Norway National Mirrorhttps://colhub.met.no/#/home
Portugal National Mirrorhttps://ipsentinel.ipma.pt/dhus/#/home
United Kingdom National Mirror (SEDAS)http://sedas.satapps.org/
Alaska Satellite Facility (Sentinel-1)https://www.asf.alaska.edu/sentinel/
Centre for Environmental Data Analysis - CEDA (Sentinel-1, -2)http://catalogue.ceda.ac.uk/search/?search_term=sentinel&return_obj=ob&search_obj=ob
Theia (Sentinel-2)https://theia.cnes.fr/atdistrib/rocket/#/search?collection=SENTINEL2
areas proposed by scientistshttp://www.cesbio.ups-tlse.fr/multitemp/?page_id=7501
USGS EarthExplorer (Sentinel-2)https://earthexplorer.usgs.gov/
EUMETSAT CODA (Sentinel-3 Marine Products)https://coda.eumetsat.int/#/home
DLR Geoservice (Sentinel-2)https://geoservice.dlr.de/web/
Downloadhttps://download.geoservice.dlr.de/S2_L2A_MAJA/files/
NOAA CoastWatchhttps://coastwatch.noaa.gov/
NASA Earthdatahttps://search.earthdata.nasa.gov/
Open data on AWShttps://registry.opendata.aws/tag/satellite-imagery/
Sentinel-2 L1C and L2Ahttps://registry.opendata.aws/sentinel-2/
Sentinel-2 L2A Cloud-Optimized GeoTIFFshttps://registry.opendata.aws/sentinel-2-l2a-cogs/
STAC Browserhttps://sentinel.stac.cloud/?t=catalogs
Sentinel-1 GRDhttps://registry.opendata.aws/sentinel-1/

来源:security.md

简介

本指南提供了一份全面的安全清单,用于保护个人数字资产。基于 Personal Security Checklist 项目,涵盖了个人必备的安全实践。

为什么安全很重要

威胁影响预防措施
身份盗窃经济损失强身份验证
数据泄露隐私暴露加密
恶意软件系统被入侵软件更新
钓鱼攻击凭据被盗安全意识培训

安全层级

层级保护
物理层设备安全
网络层连接安全
应用层软件安全
数据层信息安全

身份验证

密码安全

实践描述
使用唯一密码每个账户使用不同密码
长密码至少 12 个字符
密码管理器安全存储密码
避免个人信息不使用姓名、生日等

密码管理器推荐

管理器平台特性
Bitwarden跨平台开源,免费层级
1Password跨平台家庭共享
KeePass本地离线,开源
LastPass跨平台浏览器集成

双因素认证

方法安全级别便捷性
短信验证码
认证器应用
硬件密钥
Passkeys

2FA 应用推荐

应用平台特性
AegisAndroid开源,加密
Raivo OTPiOSiCloud 同步
Authy跨平台多设备
EntAuth跨平台硬件令牌支持

设备安全

操作系统

设置WindowsmacOSLinux
全盘加密BitLockerFileVaultLUKS
防火墙内置内置ufw/iptables
自动更新启用启用配置
杀毒软件DefenderXProtectClamAV

移动设备

设置iOSAndroid
锁屏强密码PIN + 生物识别
加密自动非默认时手动启用
应用权限定期审查定期审查
远程擦除查找我的查找我的设备

物理安全

实践描述
锁定设备使用屏幕锁
安全存放离开时锁定设备
USB 谨慎避免未知 USB 设备
摄像头遮挡不使用时遮挡摄像头

网络安全

家庭网络

设置建议
路由器密码更改默认密码
WiFi 密码使用强 WPA3/WPA2
网络名称避免个人信息
固件定期更新
访客网络隔离访客设备

公共 WiFi

风险缓解措施
中间人攻击使用 VPN
数据包嗅探仅使用 HTTPS
邪恶双子验证网络名称
会话劫持避免敏感操作

VPN 选择

标准注意事项
无日志策略经过审计验证
协议WireGuard、OpenVPN
管辖权隐私友好国家
速度影响最小
断路器防止数据泄露

邮件安全

邮件最佳实践

实践描述
分离账户个人、工作、临时
别名服务隐藏真实邮箱
钓鱼意识验证发件人和链接
加密敏感邮件使用 PGP

邮件别名服务

服务特性
SimpleLogin开源,无限别名
AnonAddy可自托管
Firefox RelayMozilla 集成
Apple Hide My EmailiCloud+ 功能

钓鱼特征

特征示例
紧急语言"账户立即暂停"
URL 不匹配显示与实际 URL 不同
通用称呼"亲爱的客户"
可疑附件意外的文件
语法错误拼写和语法差

浏览器安全

浏览器设置

设置建议
拦截跟踪器启用跟踪保护
HTTPS 模式强制 HTTPS 连接
Cookie 管理拦截第三方 Cookie
密码管理器使用浏览器内置或外部
扩展程序最少,仅信任的

推荐扩展

扩展用途
uBlock Origin广告和跟踪器拦截
HTTPS Everywhere强制 HTTPS
Privacy Badger跟踪器拦截
NoScriptJavaScript 控制

安全浏览器

浏览器专注
Firefox隐私,开源
Brave内置广告拦截
Tor Browser最大匿名性
Mullvad Browser隐私优先

数据保护

加密

工具用例
VeraCrypt磁盘加密
GPG文件和邮件加密
Signal消息加密
Cryptomator云存储加密

备份策略

组件建议
频率定期自动备份
位置多个位置
加密加密备份
测试验证备份完整性

3-2-1 备份规则

规则含义
3 份备份总数
2 种介质不同存储类型
1 份异地远程备份位置

隐私

社交媒体

设置建议
资料可见性仅好友
位置共享关闭
标签审查需要批准
应用权限最小化访问

数据最小化

实践描述
限制分享仅必要信息
阅读政策了解数据用途
选择退出行使隐私权利
删除账户移除未使用的账户

隐私工具

工具用途
DuckDuckGo私密搜索
Signal私密通讯
ProtonMail加密邮件
Tor Browser匿名浏览

软件安全

更新实践

软件更新频率
操作系统自动
浏览器自动
杀毒软件每日定义更新
应用程序可用时更新

下载安全

来源信任级别
官方网站
应用商店中高
第三方网站
未知来源非常低

软件推荐

类别推荐
杀毒软件Windows Defender、ClamAV
防火墙系统内置防火墙
密码管理器Bitwarden、KeePass
VPNMullvad、ProtonVPN

事件响应

如果被入侵

步骤操作
1立即更改密码
2在所有账户启用 2FA
3检查未授权访问
4监控财务账户
5向相关机构报告

账户恢复

账户类型恢复方式
邮箱恢复邮箱、手机
银行携带证件到网点
社交媒体账户恢复流程
云存储恢复密钥

安全审计清单

月度审查

任务状态
审查账户活动
检查数据泄露
按需更新密码
审查应用权限
备份重要数据

年度审查

任务状态
全面安全审计
更新恢复信息
审查隐私设置
测试备份恢复
更新紧急联系人

总结

类别关键操作
身份验证强密码、2FA
设备加密、更新
网络VPN、安全 WiFi
邮件别名、钓鱼意识
隐私最小化数据分享

来源:firewall.md

简介

Firezone 是一个基于 WireGuard 构建的开源 VPN 网关和防火墙。它提供安全的远程访问,支持基于身份的策略、分流隧道以及与流行身份提供商的集成,实现零信任网络访问。

架构

组件用途
Gateway(网关)处理 WireGuard 隧道的 VPN 服务器
Control Plane(控制平面)API 和 Web 管理界面
Relay(中继)用于 NAT 穿越的 STUN/TURN 服务器
客户端应用所有平台的原生应用
数据库用于配置存储的 PostgreSQL

系统要求

组件最低配置推荐配置
CPU2 核4 核
内存2 GB4 GB
操作系统Linux x86_64Ubuntu 22.04 或更新
端口UDP 51820UDP 51820, TCP 443
网络公网 IP 地址带 DNS 的公网 IP

安装

Docker Compose

version: '3.8'
services:
  firezone:
    image: firezone/firezone:latest
    ports:
      - "443:443"
      - "51820:51820/udp"
    env_file:
      - .env
    volumes:
      - ./firezone-data:/var/firezone
    cap_add:
      - NET_ADMIN
      - SYS_MODULE
    sysctls:
      - net.ipv4.ip_forward=1
      - net.ipv6.conf.all.forwarding=1
    depends_on:
      - db
    restart: unless-stopped

  db:
    image: postgres:15
    volumes:
      - pg-data:/var/lib/postgresql/data
    environment:
      POSTGRES_DB: firezone
      POSTGRES_USER: firezone
      POSTGRES_PASSWORD: changeme
    restart: unless-stopped

volumes:
  pg-data:

环境配置

# .env
EXTERNAL_URL=https://vpn.example.com
DEFAULT_ADMIN_EMAIL=admin@example.com
DEFAULT_ADMIN_PASSWORD=securepassword
DATABASE_URL=postgres://firezone:changeme@db/firezone
SECRET_KEY_BASE=generate-a-long-random-string-here
WIREGUARD_PORT=51820
WIREGUARD_IPV4_ADDRESS=10.3.2.1
WIREGUARD_IPV6_ADDRESS=fd00::3:2:1

核心概念

概念说明
Site(站点)包含网关的网络位置
Resource(资源)受保护的端点(CIDR、DNS 名称或 IP)
Policy(策略)将组链接到资源的访问规则
Group(组)具有共享访问权限的用户集合
Gateway(网关)站点内的 VPN 服务器实例
Client(客户端)通过 VPN 连接的用户设备

网关管理

网关部署类型

类型部署方式用途
Docker服务器上的容器Linux 服务器环境
Systemd原生二进制服务裸机 Linux 安装
Gateway Group(网关组)多个网关高可用配置

网关配置设置

设置说明默认值
Listen PortWireGuard UDP 端口51820
DNS Servers推送到客户端的 DNSCloudflare 1.1.1.1
MTU最大传输单元1280
Persistent KeepaliveNAT 保活间隔25 秒

资源配置

资源类型

类型示例用途
CIDR10.0.0.0/24子网访问
IP 地址192.168.1.100单主机访问
DNS 名称internal.example.com基于域名的访问

创建资源

字段说明示例
名称资源显示名称"Internal Network"
地址CIDR、IP 或 DNS10.0.0.0/24
站点关联站点"Main Office"
流量过滤器允许的端口和协议TCP 80, 443

策略管理

策略结构

组件说明
Group(组)谁获得访问权限
Resource(资源)他们可以访问什么
Action(操作)允许或拒绝

策略示例

资源操作用途
EngineersDev Servers允许开发访问
All StaffIntranet允许内部 Wiki 访问
ContractorsProduction DB拒绝限制敏感访问
AdminsAll Resources允许完全管理访问

身份提供商集成

支持的提供商

提供商协议功能
Google WorkspaceOIDC组同步
Microsoft EntraOIDC / SAML条件访问策略
OktaOIDC / SAMLMFA 支持
KeycloakOIDC / SAML自托管 IdP
Auth0OIDC自定义认证规则
JumpCloudOIDC / SAML目录同步
Local邮箱和密码无需外部 IdP

OIDC 配置字段

字段说明示例
Client IDOAuth 客户端标识firezone-client
Client SecretOAuth 客户端密钥secret-value
Discovery URLOIDC well-known URLhttps://accounts.google.com/.well-known/openid-configuration
Redirect URI回调 URLhttps://vpn.example.com/auth/oidc/callback

客户端应用

支持的平台

平台分发方式主要功能
macOSApp Store原生应用,自动连接
WindowsMicrosoft Store系统托盘集成
Linux包管理器CLI 和 GUI 可用
iOSApp Store始终在线 VPN 模式
AndroidPlay Store / F-Droid按应用 VPN 路由
HeadlessCLI 二进制服务器和脚本使用

客户端配置选项

设置说明默认值
自动连接应用启动时连接
按需连接自动重连
DNS 覆盖自定义 DNS 服务器使用网关 DNS
分流隧道仅路由资源流量启用

分流隧道(Split Tunneling)

模式说明用途
全隧道所有流量通过 VPN最大安全性
分流隧道仅资源流量通过 VPN家庭和办公使用
排除应用按应用选择隧道移动设备

分流隧道优势

优势说明
节省带宽仅 VPN 相关流量使用隧道
速度保留直接互联网访问
兼容性保持本地网络访问
隐私资源访问已加密和安全

高可用

多网关架构

组件用途
主网关处理活跃流量
备用网关故障转移备用
负载均衡器分配连接
健康检查监控网关可用性

故障转移指标

指标阈值操作
健康检查失败连续 3 次标记网关不健康
故障转移时间30 秒以内切换到备用网关
客户端重连自动客户端自动重连

网络配置

防火墙规则

规则来源目标端口操作
允许 VPN任意网关51820/UDP接受
允许 HTTPS任意网关443/TCP接受
转发 VPNVPN CIDR资源任意接受
丢弃其他任意任意任意丢弃

NAT 穿越场景

场景解决方案
客户端在 NAT 后WireGuard 自动处理 NAT
网关在 NAT 后需要在路由器上设置端口转发
对称 NAT需要中继服务器穿越

监控

仪表板指标

指标说明
活跃连接当前连接的 VPN 用户数
数据传输传入和传出的字节数
网关健康每个网关的在线/离线状态
用户活动连接历史和持续时间

查看日志

# 网关日志
docker logs firezone-gateway -f

# 控制平面日志
docker logs firezone -f

# 最近的连接流
docker exec firezone-db psql -U firezone \
  -c "SELECT * FROM flows ORDER BY created_at DESC LIMIT 10;"

API 访问

REST API 端点

端点方法用途
/api/v1/usersGET / POST用户管理
/api/v1/groupsGET / POST组管理
/api/v1/resourcesGET / POST资源管理
/api/v1/policiesGET / POST策略管理
/api/v1/gatewaysGET / POST网关管理
/api/v1/sitesGET / POST站点管理

API 认证

curl -H "Authorization: Bearer YOUR_TOKEN" \
  https://vpn.example.com/api/v1/users

安全功能

功能说明
WireGuard 协议现代高性能 VPN
零信任模型基于身份的访问控制
MFA 支持多因素认证
加密ChaCha20-Poly1305 密码
密钥轮换自动 WireGuard 密钥刷新
审计日志完整的访问审计追踪

备份

组件方法频率
数据库pg_dump每日
配置.env 文件备份更改时
WireGuard 密钥安全存储生成时
SSL 证书证书备份续期时

故障排除

问题原因解决方案
无法连接防火墙阻止 UDP在防火墙中打开端口 51820
VPN 无互联网DNS 配置问题检查网关中的 DNS 设置
VPN 速度慢MTU 不匹配将 MTU 降低到 1280
认证失败IdP 配置错误验证 OIDC 设置
网关离线服务未运行重启网关容器

总结

Firezone 提供了一个基于 WireGuard 构建的现代 VPN 解决方案,具有基于身份的访问控制。其与身份提供商的集成、分流隧道能力以及多平台客户端支持,使其适合寻求零信任网络访问的各种规模组织。


来源:vpn.md

简介

SoftEther VPN 是由筑波大学开发的开源、跨平台 VPN 服务器和客户端软件。它支持多种 VPN 协议,提供高性能、灵活性和强大的安全功能。

特性描述
多协议支持 SSL-VPN、L2TP、OpenVPN 和 WireGuard
跨平台支持 Windows、Linux、macOS 和 FreeBSD
高性能针对速度优化,支持 NAT 穿透
防火墙友好可在防火墙和 NAT 设备后工作
免费开源Apache License 2.0

架构

支持的 VPN 协议

协议端口加密备注
SSL-VPN (HTTPS)443AES-256、RSA内置协议,防火墙友好
L2TP/IPsec500、4500IPsec ESP兼容原生操作系统客户端
OpenVPN1194OpenSSL广泛使用的开源协议
SSTP443TLSWindows 原生支持
WireGuard51820ChaCha20现代轻量级协议

服务器模式

模式描述使用场景
VPN Server接受来自 VPN 客户端的连接主要服务器部署
VPN Bridge通过 VPN 隧道连接网络站点间组网
VPN Client连接到 VPN 服务器终端用户访问

安装

Linux 安装

# 下载 SoftEther VPN Server
wget https://github.com/SoftEtherVPN/SoftEtherVPN_Stable/releases/download/v4.41-9787-beta/softether-vpnserver-v4.41-9787-beta-2022.04.26-linux-x64-64bit.tar.gz

# 解压
tar -xzf softether-vpnserver-*.tar.gz
cd vpnserver

# 编译(Linux 上需要)
make

# 启动服务器
./vpnserver start

Docker 部署

docker run -d \
  --name=softether-vpn \
  --cap-add=NET_ADMIN \
  -p 443:443 \
  -p 992:992 \
  -p 5555:5555 \
  -p 500:500/udp \
  -p 4500:4500/udp \
  -p 1194:1194/udp \
  -v ./vpn_server.config:/usr/local/vpnserver/vpn_server.config \
  --restart unless-stopped \
  siomiz/softethervpn

系统要求

组件最低要求推荐配置
CPU1 核2+ 核
内存256 MB1 GB+
网络100 Mbps1 Gbps+
操作系统Linux、Windows、macOSUbuntu 20.04+ 或 Windows Server 2019+

初始配置

服务器管理器设置

步骤操作
1启动 SoftEther VPN Server Manager(GUI 或 CLI)
2连接到 localhost:443 或使用 ServerAdminPassword
3设置管理员密码
4配置虚拟 Hub(默认:DEFAULT)
5启用所需的 VPN 协议

虚拟 Hub 配置

设置描述
Hub 名称虚拟网络的标识符
密码Hub 管理密码
最大会话数最大并发连接数
在线/离线启用或禁用 Hub

网络设置

设置描述
本地网桥将 Hub 连接到物理网络适配器
SecureNAT虚拟 NAT 和 DHCP 服务器
级联连接连接到另一个 VPN 服务器

用户管理

用户类型

类型描述
个人用户具有凭证的特定用户账户
用户组具有共享设置的用户集合
匿名未认证的访问(有限使用)

认证方式

方式描述
密码用户名和密码认证
证书基于 X.509 证书的认证
RADIUS外部 RADIUS 服务器认证
NT DomainWindows 域认证
LDAP目录服务认证

创建用户

# 使用 vpncmd
./vpncmd localhost /SERVER /CMD UserCreate username /GROUP:none /REALNAME:"User Name" /NOTE:""
./vpncmd localhost /SERVER /CMD UserPasswordSet username /PASSWORD:strongpassword

用户权限

权限描述
无限制带宽不限制流量
最大带宽限制上传/下载速度
最大会话数限制并发连接
时间限制指定时长后断开连接
IP 限制仅允许来自特定 IP 的连接

VPN 协议配置

SSL-VPN 设置

设置
端口443 (HTTPS)
证书服务器 SSL 证书
加密AES-256-GCM
客户端SoftEther VPN Client 或 SSTP

L2TP/IPsec 设置

设置
端口500 (IKE)、4500 (NAT-T)
预共享密钥IPsec 预共享密钥
加密AES-256 配合 SHA-256
客户端原生操作系统 VPN 客户端

OpenVPN 兼容性

设置
端口1194 (UDP)
协议UDP 或 TCP
加密AES-256-CBC
客户端使用导出配置的 OpenVPN 客户端

SecureNAT

SecureNAT 功能

功能描述
虚拟 NATVPN 客户端的 NAT 转换
虚拟 DHCP自动 IP 地址分配
DNS 中继VPN 客户端的 DNS 解析
无需驱动无需管理员权限即可工作

SecureNAT 配置

设置描述
虚拟 IP 范围分配给客户端的 IP 地址(如 192.168.30.0/24)
NAT 网关NAT 的网关 IP(如 192.168.30.1)
DHCP 范围DHCP 地址池的起始和结束地址
DNS 服务器VPN 客户端的 DNS 服务器
租约时间DHCP 租约时长

级联 VPN 连接

站点间 VPN

组件位置 A位置 B
服务器带 Hub 的 VPN Server带 Hub 的 VPN Server
网桥到局域网的本地网桥到局域网的本地网桥
级联连接到远程 Hub接受级联连接

配置步骤

步骤操作
1在两台服务器上创建匹配的用户账户
2在服务器 A 上创建到服务器 B 的级联连接
3在两台服务器上配置本地网桥
4如需要则启用 IP 路由
5测试局域网之间的连通性

安全

加密选项

算法密钥长度使用场景
AES128、192、256 位主要加密标准
Camellia128、192、256 位AES 的替代方案
RSA2048、4096 位密钥交换和证书
SHA256、384、512 位哈希和完整性

安全最佳实践

实践描述
强密码为管理员和用户账户使用复杂密码
证书认证尽可能使用证书替代密码
禁用未使用协议仅启用需要的协议
IP 限制将管理员访问限制在特定 IP 地址
日志记录启用全面的日志记录
更新保持服务器软件更新

监控和日志

日志类型

日志内容
安全日志认证事件、访问尝试
服务器日志服务器启动/停止、配置更改
连接日志VPN 会话的建立和终止
数据包日志网络流量捕获

监控指标

指标描述
活跃会话当前连接的客户端数量
吞吐量每秒的网络流量(字节)
总流量累计传输数据量
会话时长每个客户端的连接时间

客户端配置

原生客户端设置

设置L2TP/IPsecOpenVPN
服务器地址VPN 服务器 IP 或主机名VPN 服务器 IP 或主机名
端口默认(自动)1194
认证预共享密钥 + 用户凭证证书 + 用户凭证
协议UDPUDP 或 TCP

故障排除

常见问题

问题原因解决方案
连接被拒绝服务器未运行或端口被阻止启动服务器并检查防火墙
认证失败凭证错误验证用户名和密码
VPN 无法上网NAT/路由配置错误启用 SecureNAT 或配置路由
性能缓慢加密开销或带宽限制检查服务器资源和网络
L2TP 无法连接IPsec 端口被阻止打开 UDP 端口 500 和 4500

总结

主题核心要点
协议支持 SSL-VPN、L2TP、OpenVPN、SSTP 和 WireGuard
部署在 Linux、Windows、macOS 上运行,支持 Docker
用户灵活的密码、证书和 LDAP 认证
网络SecureNAT 便于设置,本地网桥用于高级配置
安全AES-256 加密配合基于证书的认证
使用场景远程访问、站点间和桥接组网