Tim

"Codeberg e.V. is a German nonprofit organization specializing in open-source software development services." codeberg

For years, Codeberg has been known for its privacy-focused Git hosting, hosting modified versions of Forgejo and allowing registration. However, in some aspects, Codeberg is actually less privacy-conscious than GitHub or even SourceForge.

c

Codeberg Rejects Crypto Projects: Cryptocurrencies are known for their decentralization and privacy focus. As the largest Forgejo hosting provider, Codeberg completely bans any cryptocurrency-related libraries.

c

It's widely known that Stripe and PayPal are among the worst privacy providers of all payment platforms, while Wire Transfer, due to global AML policies, would absolutely leak anyone's name, email address, and bank account information. Interestingly, Codeberg, since its inception, has never offered any privacy-protecting donation methods (such as mailing cash or cryptocurrency), contradicting their claimed privacy practices.

Quoting the content from Issue #1832:

A:"Bitcoin alone is already the seventh largest asset in the world right now, and if you think that’s negative, silver and pretty much all stocks are negative too

Cryptocurrencies are almost legal currency in my country, crypto ATMs everywhere, and 90% of stores accept Binance payments

From another perspective, I believe that some people use Codeberg instead of Github because it is open source and privacy-focused, and Monero (XMR) is also privacy-focused, which can attract more donations from privacy-focused people

Other famous companies such as Mullvad, Proton, Tuta, IVPN, etc. all support cryptocurrency purchases or donations, and some even support cash by mail"

Q:"FWIW I personally think cryptocurrencies should not be accepted for Codeberg, nor promoted. It is a purely speculative currency with globally negative societal and environmental impact. I boycott all of them."

A:"Any asset is inherently a speculative currency, you can short the us dollar, long the gold, use leverage to buy treasuries or funds, why do you only think cryptocurrencies a negative impact? According to you, finance is essentially wrong, isn't it? Most people who hate cryptocurrency are old people who are unwilling to accept new things. They don't understand so they hate everything, including you. If you know more about the decentralization of cryptocurrency and the advantages of blockchain, you will find that this is the only way to replace traditional finance, and it is also the best way known to the world. The world is doing this, BlackRock holds 574000+ Bitcoins, and the United States has adopted cryptocurrency as a strategic reserve asset. This all proves the absolute legality and benefits of cryptocurrency. Codeberg is located in Germany, which is part of the European Union. I have been to Germany and there are many cryptocurrency ATMs there. It is enough to illustrate the cryptocurrency availability. Add cryptocurrency payment donate is the best way to let Codeberg better"

Q:"Here lies the most problematic societal aspect of cryptocurrencies. Since they are purely speculative, 100% of their value relies on how much people believe that it will not vanish overnight. But the reality is that they could and there has been recurring episodes similar to Mt Gox in the past decade. When some individual looses a unit of cryptocurrency because they were robbed of it or because it just cease to exist, they have no recourse.

No cryptocurrency is guaranteed by a nation state: some people would have you believe it is the case but none of them will show you proof, because there are none. The best they can provide are citations of other people voicing the same unfounded opinion.

If Codeberg was to accept cryptocurrencies, it would indirectly legitimize them and I think (again personal opinion) it would be harmful to society (in a minor way but still, why go there?)."

A:"As the most valuable asset in the world, gold has no value except as decoration, 100% of their value relies on how much people believe that it will not vanish overnight

Cryptocurrencies and gold, rely on consensus and we believe they have value so they will exist, cryptocurrency has been legalized as a universal currency. You can spend Bitcoin at will in El Salvador, and this will slowly cover the whole world

The disadvantages of any cryptocurrency are the same as in other assets, just a bit different. There is no denying that the overall market capitalization of cryptocurrencies in the world is huge. Seriously, people who are still against cryptocurrencies in 2025 are as stupid as being against the electric light in 1900

Some cryptocurrencies may disappear, some are scams, some have bugs, but most work fine, and when you think cryptocurrencies are speculative look at USDT and USDC, they are exactly USD, and EURC, etc., they are exactly equal to fiat currencies

Cryptocurrencies are no worse than traditional banks using a multi-signature wallet or stored on a large exchange comparession security. In fact, if cryptocurrencies are really unreliable, why does BlackRock own 574,000+ Bitcoins? If you live in the EU area, I'm sure your national government also owns cryptocurrencies, and if you think Codeberg's acceptance of cryptocurrencies is harmful to society, then you should first protest against the European Commission, why they have "socially harmful" currencies

As your personal opinion, of course I can't change your opinion, but I as the world's mainstream opinion to said these, I have no personal opinion, if Paypal can be an option, cryptocurrency also, according to market cap, cryptocurrency is much more reliable than this American company"

A:"What's wrong with cryptocurrencies? You're totally biased, YES, a US company with a market cap of 69.22 billion (Paypal) is MORE RELIABLE THAN A 1.71 Trillion cryptocurrency uh? Don't you find it ridiculous?

Look at Mullvad, they fully support cryptocurrencies, and as nonprofit companies, their finances are much better than Codeberg, which is based on having 10+ times the size of their employees."

Q:"I provided a link for fact checking with my statement (Mt Gox). The reasoning you wrote lacks references to be called objective. You are entitled to your opinion about cryptocurrencies and it is fine that it is not based on a rational reasoning. There really is no need to claim otherwise."

A:"Paypal very sucks, In any case, open source and decentralized cryptocurrencies are better than Paypal. Considering the liquidity of market cap, cryptocurrencies are also the best choice after fiat currency.

Any asset or even anything has the possibility of being stolen or lost, Mt Gox doesn't say much, the security of anything depends on how you use it, not expecting it to be perfect, and considering the market cap and liquidity of cryptocurrencies (this is available in any search engine), it is the second only to fiat currency at present and the future currency to replace fiat currency (predicted by market capital growth rate)

Opposing cryptocurrency is opposing money itself. I have listed many advantages and characteristics of cryptocurrencies above. You haven't listed them all to refute me. This means that you recognize some of them, right? The market cap can't be faked. You can find the myth of cryptocurrency on any famous websites. The numbers will tell you that you are wrong."

A:"The discussion is becoming moot, Codeberg owners needs to react as soon as possible, instead of me being here to teach people why electricity is better than oil. Even if I don't raise the issue, cryptocurrencies will be added to the payment methods for Codeberg donate at some point in the future (assuming Codeberg still exists by then) because cryptocurrencies are replacing any country's fiat currency

Hope everyone will stop questioning cryptocurrencies for very small and common problems. I'm not a teacher. The world will tell you whether cryptocurrencies are good enough, and the world is doing this. For conspiracy theorists and people who smear cryptocurrencies, you can leave the discussion. I believe Codeberg owners will make rational judgments. This is just a very small issue. I just hope that Codeberg will become better. For those who don't plan to donate, just ignore it as well "

Gusted:"This is an unproductive discussion, I ask everyone to refrain from commenting on this topic and also to refrain from opening new issues on this topic. If you want to say your piece on this matter, contact me.

I am quite confident that the official answer from 2 years ago is still effective and therefore this issue is resolved, #203 (comment)."

Subsequently, the issue was closed. This discussion also sheds light on Codeberg’s user base and stance; Codeberg is not a suitable choice for content related to cryptocurrency or other privacy-sensitive matters (see below).


Codeberg's Attack on Transparency and on Cloudflare Opposition Original:

Codeberg hosted the Cloudflare-Tor project. In 2021, Codeberg took down the project alleging libel.

what the deCloudflare project is

The Cloudflare-TOR project is a non-profit charitable effort to promote decentralization, network neutrality, and privacy with Cloudflare (a top adversary of that cause) as the core focus. The CFT project provides a variety of free software tools to help protect the general public from Cloudflare. An important component of protecting the community from Cloudflare is documenting websites that subject people to the harms of Cloudflare by maintaining a massive list of websites to avoid.

Unlike other tech giant adversaries to the CFT cause such as GAFAM (Google Amazon Facebook Apple Microsoft), Cloudflare operates surreptitiously and largely unknown to the general public, despite having access to ~20-30%+ of the world's web traffic and 80%+ of CDN market. Their existence is so much in the shadows that privacy orgs like EFF are largely oblivious to the threat of it. Mainstream privacy orgs not only neglect to protect web users from Cloudflare, but some of them actually naively use Cloudflare themselves and unwittingly work against their own interest and declared purpose. Some privacy and ethics advice sites like Switching Software actually recommend Cloudflare sites to those who entrust them to give advice pursuant to their own stated purpose.

The problem is so rampant that it became important for the CFT project's tracking of the Cloudflare problem to start keeping track of organizations and the pseudo-anonymous aliases of representatives who were spotted publicly promoting Cloudflare.

Codeberg-inflicted censorship

After someone on Codeberg's staff was added to the Cloudflare supporter list, Codeberg shut down the CFT project and issued this statement to contributors, and posted this blog announcement, allegedly in response to complaints.

Analysis of Codeberg's e-mail

"target lists", with personal data, lists of employment status, social media identities,

Calling it a "target list" entails a presumption of how the list is used. For example, if a threat actor wants to join the CFT project to gain access to our internal operations, it is not CFT targeting them but rather CFT avoiding being targeted by their adversary. CFT has been attacked several times and sometimes at the hands of insiders who gained trust by posing as those who support the CFT cause.

Transparency is essential in exposing the corporate bias behind the information and advice you are getting. For example, a forum for talk about bicycles might require Brompton representatives to be tagged as such so that other users are aware of the bias behind their posts. It would actually be reckless not to identify such conflicts of interest. This is particularly important when dealing with Cloudflare because they have proven to publish misinformation regularly. Codeberg's move to conceal who represents a company ultimately promotes corruption and deception.

Are forums hosted in Germany really forced to operate non-transparently and conceal such conflicts of interest from the public? Unlikely.

For Codeberg to allege CFT tracks "personal data" with social media identities is perversely deceptive. CFT did not track personal data or dox any social media identities. The social media identities were listed and only public data was shared -- data that is already public on platforms like Twitter. Personally identifiable information was not collected on social media aliases even if it was public.

Publication of such data, no matter if true or not, without the explicit consent of the person in question is illegal in EU.

When a user posts a tweet, they do so with consent to the publication of that tweet. If Codeberg's assertion above were true, then Nitter would be banned in Germany for republishing the tweets of Germans. We know this is not true because Germans have access to the Nitter network.

Codeberg's false accusation of illegal activity came with destructive removal of forked repositories without warning, without redress, and while refusing explanation to the users whose data they destroyed.

In response, Codeberg claims they had to act immediately to what they perceived as illegal activity. Even if we were to accept that the already public data somehow became sensitive merely by replication, the correct non-reckless action is to quarantine the data in a non-public state until court proceedings or settlement could commence. For Codeberg to destroy people's work, and also destroy what they believed was evidence of illegal activity was nothing short of reckless. Codeberg's haphazard response has actually created a legal liability for themselves, as they needlessly destroyed people's work without due diligence.

A take-down request implemented properly and fairly to all sides is temporary and non-destructive of the artifacts.

This is just a statement of Codeberg's interpretation of law. Note that Codeberg does not accuse CFT of this, as doing so would be libel against CFT. So it's unclear what purpose this statement serves other than to imply an accusation without stating it. Such weasel wording is designed to deceive the public while dodging legal accountability.

CFT has received only one complaint. It involved one social media alias that was listed and it turned out to be a misunderstanding surrounding the word "support". The listed party claimed to not personally condone Cloudflare and thus claimed to not be a Cloudflare "supporter" on that basis. But investigation of public statements by that individual revealed that the other party actually supported Cloudflare operationally. Note that Codeberg destroyed the investigation logs which led to the finding, so we can't cite them here.

The pure existence of lis ts "Enemies of X" is by all rational means unlikely to have any other purpose than public shaming, defamation, threatening and libel. These are generally considered illegal in German law and elsewhere.

The mere existence of a list of Cloudflare supporters certainly does not imply shaming. The list can potentially be used for shaming or praising, as well as in countless ways orthogonal to both praise and shame. Codeberg further produces no evidence that the list was used for shaming (which should be quite easy to do if they've had complaints on the scale that they allege).

It's important to establish bias so that readers can assess the accuracy of statements made by someone who is biased. This is why aliases of those entrusted with advice on matters of privacy were collected. It's important to track the underlying bias behind privacy advocacy sites to address the problem of detrimental advice.

Analysis of Codeberg's Blog Announcement

Codeberg said:

In the last couple of days, we have received multiple inquiries to remove sensitive information from the crimeflare/cloudflare-tor repository and all clones and forks of that repository hosted on Codeberg.org.

(emphasis added)

Data published by Twitter and public forums is not sensitive. Anyone who posts in a public space and later has regrets, they have only themselves to blame.

Privacy is like virginity: once you lose it, you can't have it back.

We have been made aware that this repository contains lists of usernames that are either linked with their Codeberg profile or their social media accounts and allegedly blamed as Cloudflare supporters without an evidence

CFT was never asked for evidence. Only one complaint was received. It was investigated and evidence was provided to the subject.

We started a discussion with the maintainers of this repository and asked to remove these sensitive information, that are apparently for shaming people (defamation),

CFT did not "shame" or "defame" anyone, and no evidence was given to that effect. Codeberg admitted earlier that their assumption is that a list of Cloudflare supporters inherently shames people. Yet the list is objective. It's for the reader to decide if the list is of shame or of pride. No value judgment was expressed by the CFT project.

According to GDPR, we are obligued to remove sensitive user information as soon as a concerned person demands us to do so.

The GDPR does not protect legal persons (i.e. organizations) and it does not protect anonymous information. Specifically:

"The principles of data protection should therefore not apply to
anonymous information, namely information which does not relate to an
identified or identifiable natural person or to personal data rendered
anonymous in such a manner that the data subject is not or no longer
identifiable. This Regulation does not therefore concern the
processing of such anonymous information, including for statistical or
research purposes."

CFT's Cloudflare supporter list did not contain real names; only pseudoanonymous aliases.

The listed alias of the subject who complained did not use an alias formed like "firstname_lastname", or any form that could reasonably identify a natural individual person.

The sole complaint CFT received lead to an investigation that found the data accurate. Even though the GDPR right to be forgotten does not have force in that case, it was removed anyway and therefore CFT was (and remains) in compliance with the GDPR right to be forgotten.

Yet Codeberg still removed the project despite immediate compliance.

as well as Cloudflare employee data, that are considered as private information

CloudFlare itself is listing their employees, so it's already public information.

People reaching out to us and to the maintainers of the repository itself tried to make clear that they do not consider themselves as Cloudflare-supporters, but critical opponents of this company, and thus could not even imagine a reason for being listed there.

CFT only received one complaint regarding one individual. CFT has continously been in GDPR compliance at all times. Codeberg destroyed the repository anyway.

"Support" comes in many forms. You can support Cloudflare by praising it, or you can support Cloudflare through actions (which may even be unwitting to the supporter). In the one case that CFT investigated, the subject's understanding narrowly assumed "support" was limited to philosophical praise.

We can not accept anyone attacking and threatening us and our users (or anyone for that matter), or inciting others to do so.

This is weasel wording, as directly accusing CFT of attacking or threatening Cloudflare supporters would constitute libel on the part of Codeberg. So they try to imply it. These claims can only be ignored in the absence of evidence.


Devs make foolish decisions (improving performance by breaking some browsers, when the performance improvement only affects those they broke.)


There are many similar incidents; here, I highlight only the key issues.

In summary: Codeberg—a Git hosting platform renowned for privacy and the largest provider of Forgejo—is not actually private and actively opposes other privacy-focused projects. Since privacy is a fundamental human right, put simply, Codeberg is undermining human rights, causing ongoing privacy disasters, and even engaging in acts amounting to crimes against humanity.