Transparency
How to check what app.perch.ws runs · Privacy policy
Perch's privacy promises are meant to be checked, not taken on trust. There are two levels
to that, and it's worth being clear about which is which.
1. What the design guarantees
The strongest guarantee doesn't depend on our server at all. Sync chains are encrypted on
your devices with a key that never leaves them, and app.perch.ws keeps no libraries. Even a
server changed to misbehave couldn't read your feeds, what you read or your private notes.
You can check this in the open-source code of the apps, which is where the encryption
happens.
2. Which code the server runs
For the rest (accounts, shared notes, what the server logs) you need to know which code it
runs. Every server image is built by the project's public CI from a commit on GitHub,
published to GitHub's registry, and given a signed attestation saying exactly which commit
and workflow produced it. app.perch.ws runs those images and reports its commit:
curl -s https://app.perch.ws/api/v1/server
The build.commit it returns is a commit you can read on GitHub. To check that
the image for it was built there, from that code:
gh attestation verify \
oci://ghcr.io/arifcinartekin/perch-server:<commit> \
--repo arifcinartekin/perch
The reported commit is the newest one that changes what goes into the server; commits that
only touch the apps, the docs or this site build no new image, so it can be older than the
repository's latest.
This proves the image is genuine. It can't prove, from the outside, that the machine
answering at app.perch.ws is running it: no ordinary server can prove that about itself.
That's why the design in point 1 matters more, and why we keep as little as possible on the
server in the first place.
Other servers
Anyone can run Perch, and change it. A server you don't run yourself may run different code.
The apps show which server you're connected to; trust it as much as you trust whoever runs
it.
Şeffaflık
app.perch.ws'in ne çalıştırdığını nasıl kontrol edersin ·
Gizlilik politikası
Perch'ün gizlilik sözleri güvenle kabul edilmek için değil, kontrol edilmek için. Bunun iki
düzeyi var ve hangisinin ne sağladığını açıkça söylemek gerekiyor.
1. Tasarımın garanti ettiği
En güçlü garanti sunucumuza hiç bağlı değil. Senkron zincirleri, cihazlarından hiç çıkmayan
bir anahtarla cihazlarında şifrelenir ve app.perch.ws kitaplık tutmaz. Kötü davranacak
şekilde değiştirilmiş bir sunucu bile akışlarını, ne okuduğunu ya da özel notlarını
okuyamaz. Bunu, şifrelemenin yapıldığı yer olan uygulamaların açık kaynak kodunda kontrol
edebilirsin.
2. Sunucunun hangi kodu çalıştırdığı
Geri kalanı için (hesaplar, paylaşılan notlar, sunucunun neyi kaydettiği) sunucunun hangi
kodu çalıştırdığını bilmen gerekir. Her sunucu imajı, projenin herkese açık CI'ı tarafından
GitHub'daki bir commit'ten derlenir, GitHub'ın kayıt deposunda yayınlanır ve onu tam olarak
hangi commit'in ve iş akışının ürettiğini söyleyen imzalı bir belge (attestation) alır.
app.perch.ws bu imajları çalıştırır ve commit'ini bildirir:
curl -s https://app.perch.ws/api/v1/server
Dönen build.commit, GitHub'da okuyabileceğin bir commit'tir. O commit'in
imajının orada, o koddan derlendiğini kontrol etmek için:
gh attestation verify \
oci://ghcr.io/arifcinartekin/perch-server:<commit> \
--repo arifcinartekin/perch
Bildirilen commit, sunucunun içeriğini değiştiren en son commit'tir; yalnızca uygulamalara,
dokümanlara ya da bu siteye dokunan commit'ler yeni imaj üretmez, bu yüzden deponun en son
commit'inden eski olabilir.
Bu, imajın gerçek olduğunu kanıtlar. app.perch.ws'te cevap veren makinenin onu
çalıştırdığını ise dışarıdan kanıtlayamaz; hiçbir sıradan sunucu bunu kendisi için
kanıtlayamaz. 1. maddedeki tasarımın daha önemli olmasının ve sunucuda en baştan
olabildiğince az şey tutmamızın nedeni bu.
Diğer sunucular
Perch'ü herkes çalıştırabilir ve değiştirebilir. Kendi çalıştırmadığın bir sunucu farklı bir
kod çalıştırıyor olabilir. Uygulamalar hangi sunucuya bağlı olduğunu gösterir; ona, onu
işleten kişiye güvendiğin kadar güven.