Current projects
Listed on this page are programs and projects which are - at this moment - working with NLnet funding.
project | description |
---|---|
SIPproxy64/6bed4 | 0cpm, SIPproxy64, 6bed4, applet, freeswitch RTT |
LibreCellular | Open hardware 4G Mobile Network |
AI-VPN | Local machine-based learned analysis of VPN trafffic |
Accessible security | Integration effort of independent security efforts like Qubes, Heads, coreboot, etc |
OCCRP Aleph disambiguation | OCCRP Aleph: disambiguating different people and companies |
Autocrypt for Thunderbird | Make email encryption extremely simple |
BBBsecureChat | Add E2EE instant messaging to Big Blue Button meetings |
Balthazar | One laptop for the new internet age. |
Balthazar - One laptop for the new internet age. | A secure fully open hardware laptop |
Betrusted OS | An embedded OS for cryptographic devices |
Betrusted software | A minimalist and secure OS for embedded communication devices |
Betrusted Storage | Plausably deniable encrypted storage |
Blink RELOAD | Secure P2P real-time communications with RELOAD |
Bonfire Search & Discovery | Improving search and discoverability in the Fediverse |
Briar | A secure messaging app with offline capabilities |
Castopod | Podcasting in the fediverse |
Castopod Mobile | Userfriendly mobile podcasting application |
Certbot ECDSA support | Certbot ECDSA support |
LibrEDA | An integrated development environment for chip design |
Zerocat Chipflasher Flashrom Interface | Hardware to flash alternative/libre firmware to BIOS chips |
Chips4Makers ASICs | Chips4Makers ASICs |
Supersizing the Gun | Chipwhisperer open hardware for side channel analysis |
Discover and move your coins by yourself | A safe way to explore and work with cryptocurrency forks |
Connect by Name | Library for easy connection setup |
Conversations | A secure mobile messaging client |
The Libre-RISCV SoC, Coriolis2 ASIC Layout Collaboration | Open tooling for ASIC Layout |
Record Federation for Corteza Clouds | Data federation over ActivityPub |
Corteza Discovery | (Geo)search and discovery within federated services |
Creative Passport | Allow creative artists to gain visibility and build reputation on the web |
CryptPad: Project Dialogue | Secure surveys and polls for Cryptpad |
CryptPad | Real-time collaboration with client-side encryption |
CryptPad for communities | Collaborative web editor with client-side encryption |
GNU Guix - Cuirass | Continuous integration system for GNU Guix/Linux + Hurd |
DCnets | Implementation of Dining Cryptographers Network |
Redash | Predictive text entry without a keyboard |
Dat Private Network | Private storage in DAT |
Structuring the System Layer with Dataspaces | Implementing a secure and scalable system layer on mobile |
DeltaBot | Social discovery over mail-based chat |
Dino | User-friendly and secure instant messaging |
Distributed Private Trust | Decentralised trust and reputation system |
How AdTech works | Improving public awareness of AdTech and privacy |
EEZ DIB | EEZ DIY Instrument Bus |
EGIL SCIM client | System for Cross-domain Identity Management |
ELF Linking | Analytic tools for UNIX' Executable and Linkable Format |
Edalize ASIC backend | Create open hardware silicon with a fully free software toolchain |
EDeA | A forge suitable for open hardware development |
AEAP | Automated e-mail address porting to a new provider |
Thunderbird - native EteSync integration using TbSync | Add encrypted sync to Thunderbird |
Etebase (EteSync) - protocol and encryption scheme enhancements | Redesign EteSync protocol and encryption scheme |
EteSync - iOS application | Encrypted synchronisation for calendars, addressbook, etc |
Explain | Deep search on open educational resources |
Tracking the Trackers | Automated scanning for spyware in mobile applications |
FairSync | Simplify aggregation and discovery of places and events |
searx | Federating self-hosted search hubs |
FemtoStar Project | Open Hardware Communications Satellite |
Folksonomy engine for the food ecosystem | Data modelling by the community |
ForgeFed | Federation for software collaboration tools |
Fractal | Native client for the Matrix protocol |
Fix the Pitch Black Attack in Freenet friend-to-friend routing | A decentralized distributed platform for private communication |
Funkwhale | ActivityPub-driven audio streaming and sharing |
GNU Name System | Authenticated naming system for the internet from GNU project |
GNU Mes | Help create an operating system we can trust |
GNU Mes on ARM | Trustworthy bootstrap for operating systems on ARM ISA |
GNU Mes: Full Source bootstrap | GNU Mes: Full Source bootstrap |
GNU social | Modernizing the original FOSS Social Network |
GNU Taler | Advanced electronic payment system for privacy-preserving payments |
GPG Mailgate project | Best effort encryption of mail flows with OpenPGP |
GNU Guix | Discovery of service configurations in a declarative setup |
Tooling to improve security and trust in GNU Guix | Contextual software vulnerability discovery |
Genodepkgs | When Genode and Nixpkgs meet |
GoatCounter | Privacy-friendly web analytics for small websites |
The Open Green Web | Ethical meta-search filter on green hosted websites |
Hubzilla | Federated social networking environment |
Implement sound support in the Hurd | Add audio capabilities to the multiserver microkernel from GNU |
A proof of concept of identity-based encryption | Make encryption simpler |
IMSI Pseudonymization | Better privacy protection for 2G-5G |
ipfs-search.com | Search engine for the Interplanetary File System |
IRMA made easy | Usability research into attribute based authentication |
IN COMMON | Public platform to map and act together for the Commons |
In-document search | Interoperable Rich Text Changes for Search |
Practical Tools to Build the Context Web | Declarative setup of P2P collaboration |
Indigenous | Indieweb mobile clients |
YunoHost and the Internet Cube | Solutions for DIY-ISP's and self-hosters |
Interpeer | Collaboration infrastructure with near real-time p2p data synchronization |
Inventaire | Wikidata-based social sharing of reading experiences |
JavaScript Restrictor | Increasing Security and Privacy of JavaScript APIs |
JavaScript Shield | Cross-browser extension to make javascript less exploitable |
End-To-End Encryption for Jitsi Meet | Proven strong encryption for open source video conferencing |
Verified Differential Privacy for Julia | Proving sound privacy guarantees through a type system |
Kaidan | Adding crypto to userfriendly Cross-platform XMPP client |
Kazarma | Bridge ActivityPub and Matrix realms |
Keyoxide | Self-hostable identity proofs with bidirectional linking verification |
Adopt improvements in Email Encryption in KMail | Adopt improvements in Email Encryption in KMail |
ARPA2 LDAP Middleware | Privacy enhancing middleware |
Langsec in Pectore | A secure pacemaker created from formal grammars |
Lemmy | ActivityPub for link aggregation |
Liberaforms | Open source form server |
XMPP-ActivityPub gateway | XMPP, ActivityPub and E2EE Pubsub |
The Libre-RISCV SoC | A fully open hardware System-on-a-Chip |
LibreOffice P2P | Encrypted collaborative editing in the browser |
LibreSilicon | Free/open source semiconductor manufacturing process |
Libre Silicon compiler | Synthesize, place and route hardware description to silicon |
Standard Cell Library | Open Standard Cell Library with automated dimensioning of transistors |
Port of AMDVLK/RADV 3D Driver to the Libre RISC-V SoC | Adapt Vulkan Drivers to the Libre RISC-V SoC |
The Libre RISC-V SoC, Formal Correctness Proofs | Mathematical unit tests for open hardware System-on-Chip |
The Libre RISC-V SoC, Formal Standards Development | Formal Standards for RISC-V extensions from Libre RISC-V SoC |
The Libre-RISCV SoC, Video Acceleration | Optimised video acceleration instructions for Libre RISC-V SoC |
Librecast Live | Live streaming with multicast |
Lightmeter | Email server configuration lifecycle management |
Improve usability of Linux firewall userspace tools | Userspace tooling for Linux kernel Netfilter |
LumoSQL | Create more reliable, distributed embedded databases |
Luna | A versatile and fast new open-source place and route tool |
Distributed Trust for Web Servers | Establishing a Distributed Trust Authority |
MNT Reform | A trustworthy open hardware laptop |
MPTCP | MultiPath TCP |
Maemo Leste | An independent mobile operating system focused on trustworthiness |
Mailpile Search Integration | Personal email search engine |
Mangaki | Advanced group recommendations |
Manyverse | An off-line capable privacy-centric social messaging app |
Improving Matrix E2E encryption UX | Better usability of Matrix.org E2E encryption |
MEGA65 Phone | A phone simple enough to understand in full |
MeiliSearch | Modern and responsive search |
Practical Decentralised Search and Discovery | Search and discovery inside mesh/adhoc networks |
Meta-Press.es | A press search engine in your browser |
MobileAtlas | A distributed open hardware test infrastructure to analyse mobile networks |
Mosaic | Trustworthy open hardware design tool for electrical engineers |
Movim | Add OMEMO encryption to Movim XMPP client |
Mynij | Portable indexing and search engine for mobile |
Namecoin: TLS | Various TLS integrations for Namecoin |
Namecoin: ZeroNet and Packaging | Make ZeroNet work with Namecoin |
Namecoin: Core Infrastructure | Alternative domain name system |
neuropil | Privacy by design P2P search including IoT |
Nextcloud | Unified and intelligent search within private cloud data |
Nitrokey | Open hardware for encryption and authentication |
NoScript Contextual Policies & LAN protection (ABE Quantum) | Application Boundaries Enforcer (ABE) for new generation of browsers |
Nominatim | Multi-lingual support in address search |
Nym Credentials | A decentralised solution for authentication |
Nyxt | A programmable browser with advanced search integration |
Off-the-Record messaging version 4 | Advanced protocol for secure messaging |
Offen | Privacy-respecting site analytics |
OnBaSca | Tor Bandwidth Scanner |
Opaque Sphinx | Secure password-based authentication with Opaque/Sphinx |
Opaque Sphinx Server and Clients | Server and tools for modern authentication |
Open Source DRTM implementation with TrenchBoot for AMD processors | Unified framework for dynamic RTM |
Personal Food Facts | Privacy protecting personalized information about food |
Openki.net | Make local events and meetups discoverable |
OpenPGP Certificate Authority | Managing OpenPGP keys for communities and organisation |
802.11n feature of openwifi | Open Hardware implementation of wifi |
P2Pcollab | Decentralised social search and discovery |
PGP4civiCRM | Add email encryption to CRM |
Securing PLCs via embedded Open-Source protocol adapters | Open hardware protocol adapters for industrial automation |
PeerTube | A decentralised streaming video platform |
Peertube-Desktop | Enjoy and share federated videos |
Extending PeerTube | Adding advanced search capabailities to PeerTube |
A Distributed Software Stack For Co-operation | Facilitating easy ad hoc cooperation |
PixelDroid | Share and browse photos in the fediverse with a mobile app |
Pixelfed Live | Live streaming and other Pixelfed enhancements |
Pixelfed | ActivityPub driven decentralised photo sharing platform |
Plaudit | Make good science discoverable through endorsements |
Poliscoops | Make political news and online debate accessible |
Privacy Enhancements for PowerDNS and DNSdist | Make it easier to deploy private DoT/DoH resolvers |
PrivateRecSys | Privacy-Friendly Recommendation System |
Private Searx | Add private resources to the open source Searx metasearch engine |
Qubes OS | Bring the security of Qubes OS to people with disabilities |
RISC-V Phone | Open hardware RISC-V Phone |
RNP Confium | Distributed trust store enabling threshold encryption |
Re-isearch | Vectorise text with a flexible unit of retrieval |
Redwax | Standardisation of client side PKI interfaces |
Reowolf | Rip and replace for BSD socket insecurity |
Replicant on Guix | Reproducible build infrastructure for Replicant |
Graphics acceleration on Replicant | Free software graphics drivers for mobile phones |
Finish porting Replicant to a newer Android version | Alternative, free software version of Android |
Ricochet Refreshed | Anonymous, meta-data free secure messaging |
Ripple | Safer and faster incremental software builds |
Robotnix | Reproducible Builds of Android with NIX |
Robur privacy-enhanced DNS resolver and DHCP server | Secure network configuration and DNS resolution |
Rust Threadpool | Improve privacy of Rust threading library |
SASL XMSS | Make SASL work with XMSS protocol |
SASL Works for the InternetWide Architecture | Integrate new authentication mechanisms into SASL |
SCION-Pathdiscovery | Secure and reliable decentralized storage platform |
Geographic tagging and discovery of Internet Routing and Forwarding | Geographic tagging and discovery of Internet Routing and Forwarding |
SOLID Data Workers | Toolkit to ingest data into SOLID |
SpinalHDL, VexRiscv, SaxonSoc | Open Hardware System-on-Chip design framework based on SpinalHDL |
SEARXR | Virtual reality for web search |
searx | A privacy-respecting, hackable metasearch engine |
SeedVault | Private backups of mobile applications |
Simmel | A wearable contact tracing beacon/scanner |
Software Heritage | Collect, preserve and share the source code of all software ever written |
Solid-NextCloud app | Bridge Nextcloud to Solid |
Solid-Search | Queries in a pod |
Solid Control | Access Control mechanism for data and services within Solid |
Sonar: a modular peer-to-peer search engine for the next-generation web | Modular peer-to-peer search engine |
Spectrum | A security through compartmentalization based operating system |
Secure User Interfaces (Spritely) | Usability of decentralised social media |
ARPA2 Steamworks | ARPA2 Steamworks |
StreetComplete | Fix open geodata with OpenStreetMap |
Suhosin-NG | Harness PHP 7 applications |
Sylk chat | Add instant messaging features to Sylk |
Sylk Client | Secure multiparty videoconferencing application |
Sylk Mobile | Secure real-time mobile communications |
Timing-Driven Place-and-Route (TDPR) | Open hardware tool to synthesize digital silicon circuits |
RETETRA | Security Analysis of Proprietary Cryptography in Terrestrial Trunked Radio |
TLS-KDH mbed | Implement TLS-KDH into mbed |
Tantum Search | Context-enhanced search driven by schema.org |
Padding Machines for Tor | Protect metadata in the Tor onion routing network |
Transparency Toolkit | A decentralized hosted archiving service with search |
Build Transparency (Trustix) | Towards a decentralized supply chain for software |
modular ULX3S | A modular open hardware FPGA platform |
URL Frontier | Develop a API between web crawler and frontier |
Universal DID Resolver and Registrar | Tooling for decentralized identifiers |
ValOS Cryptographic Content Security project | Cryptographic Content Security for ValOS |
variation graph (vgteam) | Privacy enhanced search within e.g. genome data sets |
Noise Explorer-VerifPal | Automated proofs and code generation for secure protocols |
Verifpal | Prove soundness of verification in Verifpal |
VFRAME: Visual Defense Tools | Use computer-vision to shield privacy in video |
video box | Affordable open hardware video-to-network |
Video chat privacy | Add privacy features to video chats |
Waasabi Framework | P2P Live Streaming for events |
Web Annotation | Building blocks for interoperable annotation systems |
WebXray Discovery | Expose tracking mechanism in search hubs |
Web Shell | Desktop and security environment for web apps |
XWiki | Bring wiki capabilities into the Fediverse |
WikiRate Insights | Transforming WikiRate ESG Platform User Experience to Maximise Reliable Data Insights |
WireGuard | Scale up WireGuard |
Wireguard Windows client | Native Wireguard protocol client for Windows |
Wireguard Rust Implementation | Implementation of WireGuard in a type safe language |
Wishbone Streaming | Add Streaming capabilities to Wishbone |
WordPress ActivityPub | Bring ActivityPub social networking to the widely used Wordpress |
XWiki ActivityPub | First class ActivityPub support in XWiki |
YaCy Grid SaaS | YaCy Grid SaaS |
ZSipOs | Open hardware for telephony encryption |
ARPA2 | Working towards a decentralised global internet that offers security and privacy by design. |
GnuTLS | Implement TLS-KDH in GnuTLS |
ARPA2 resource ACL and HTTP SASL modules for NGINX | Extend consistent access control to NGINX webserver |
betrusted | A protected hardware device for your private matters. |
Bitmask | User-friendly and secure VPN configuration |
Conferences | sponsoring of various conferences |
Democratic Sendcomm | An easy to use connected open hardware device with a flat learning curve |
dhcpcanon | Network configuration with better privacy |
DIME | A new encrypted, end-to-end email protocol |
Donations | smaller contributions to various activities |
eduVPN app | Add Wireguard protocol to federated VPN suite |
eduVPN on Apple | eduVPN for Apple devices |
eduVPN on Apple part II | Improved version of eduVPN for Apple devices |
eduVPN multi-protocol | Review of the eduVPN multi-protocol project. |
eduVPN | Making secure VPN network technology available to everyone |
elRepo.io - Resilient, human-centered, distributed content sharing and discovery. | Resilient, human-centered, distributed content sharing and discovery. |
Explain Direct | Providing effective and efficient access paradigms for open educational material |
Fashion Freedom | Supporting research, development, and education to bring the fashion industry into the 21st century |
fediverse.space | Find your way in the Fediverse |
FileSender | FileSender is a secure and private way to share large files with anyone. |
fwupd | Automatic Firmware updates for BSD operating systems |
GetDNS | Deliver DNSSEC as a building block in harsh environments |
Global Directories | Distributed contact information discovery mechanism |
Pretty Easy Privacy | At scale simulation over GNUnet with different realistic user behavior scenarios |
GUN P2P Encryption | A realtime, decentralized, offline-first, graph database engine |
Hackathons | contributions to various hackathons |
Internet of Coins | Create a decentralized, self-sustaining economy by implementing inter-blockchain connectivity |
Handling Data from IPv6 Scanning | Scanning tools for scaling up IPv6 scans |
iuh-openbsc | An open source implementation of 3G |
Katzenpost | Observation resistant secure messaging layer |
Key Management | Key Management |
DNSSEC Key Signing Suite | A best practise for DNSSEC Key Signing |
libspng | A fast and safe implementation of Portable Network Graphics |
Minedive | P2P search over webRTC |
mobile-nixos | NixOS for mobile phones and tablets |
Namecoin | Decentralized, censorship resist Internet infrastructure for e.g. DNS and identities |
Faster and configurable datapath/Linux xfrm | Rewriting nftables to optimise for xfrm |
Nixcloud Mail | Declarative mail server based on NixOS |
Nixcloud Webservices | Declarative web services based on NixOS |
Software vulnerability discovery | Automating discovery of software update and vulnerabilities |
node-Tor | Implementation of Tor protocols for inside webpages |
offen | Ethical site analytics, controlled by the user |
openEngiadina | Platform for creating, publishing and using open local knowledge |
pcb-rnd | Modular printed circuit board editor |
Pitchfork | Open hardware for compartmentalizing key material and cryptographic operations |
Pitchfork PKCS#11 | Contribute to OASIS standardisation PKCS#11 v3 |
PKCS#11 v3 | Contribute to standardisation of PKCS#11 for cryptographic tokens |
postmarketOS | An independent mobile operating system |
Privacy Preserving Disease Tracking | Research into contact tracing privacy |
RaptorJIT | RaptorJIT is a high-performance Lua virtual machine for network dataplanes. |
Modular CA | Modular infrastructure for building secure internet services |
Remote PKCS#11 | Remote usage of PKCS#11 |
SDR PHY | Create a GSM mobile phone consisting of completely open source software and SDR radio |
x86-64-bit Virtual Machine Monitor for seL4 verified microkernel | Very restricted virtualized environment for higher security |
Search and Displace | Find and redact privacy sensitive information |
SecuShare | A framework for sufficiently safe social interaction |
Secushare Box | Operating system extension of Secushare for hardware devices |
Serval-LR | SERVAL Long-range WiFi Add-on |
Magic Wormhole/SPAKE2 | Securely send files between two computers with minimum fuss |
Stubby | A local DNS Privacy stub resolver using DNS-over-TLS |
TLS-KDH | Combined Kerberos and Diffie-Hellman as an authentication mechanism for TLS |
TOS;DR | A user rights initiative to rate and label website terms & privacy policies |
Tracking Exposed | Increase transparency behind personalization algorithms |
Trusted Boot Module | An open hardware trusted boot manager |
Virtualizing device firmware | Creating digital twins for auditing and testing appliances |
Vita | A fast IPSEC-based VPN gateway |
Vita | A high performance IPSEC implementation |
Free Software Vulnerability Database | A resource to aggregate software updates |
Nixcloud | Declarative internet services based on NixOS |
WireGuard | A fast and modern VPN that utilizes state-of-the-art cryptography |
Wireguard | Take modern network tunnels to the next level |
WPIA CA Infrastructure | Deployment infrastructure for certificate authorities |
xqerl | Performant (Erlang) implementation of W3C XQuery and XML database |
NLnet Foundation currently supports the following projects with in-kind contributions: |
|
The Commons Conservancy | Legal infrastructure for public benefit efforts |
NLnet Labs | Independent lab for Internet infrastructure development |