5 ms·
So much more to opsec than using tor. I hope leakers are either ready to be unmasked, or have countermeasures against things like document fingerprinting.
by stuckagain 10y ago
So much more to opsec than using tor. I hope leakers are either ready to be unmasked, or have countermeasures against things like document fingerprinting.
- deleted 10y ago[deleted]
- Bamberg 10y agoyes, the steps detailed in the post are likely not enough to evade being caught if a large intel agency is looking for a leaker. it very probably will be enough to prevent detection before the materials are published, but not necessarily afterwards when authorities start looking for a leaker.
- alva 10y agoThis piece is so incredibly irresponsible. If someone uses this to leak truly important information, they should not be surprised to quickly receive knock on the door and a dark cell. There are many people in a position to leak things who are not involved in technology and may believe these steps as adequate for their protection.
- mcherm 10y ago> This piece is so incredibly irresponsible. Perhaps. Can you write a better one?
- alva 10y agoNo I can't. But if I had wrote this piece I would slap an absolutely massive disclaimer at the top warning leakers-to-be that these steps alone are very far from properly protecting yourself.
- verytrivial 10y agoI think that is overstating it. If you compare doing this to simply emailing en clair from a personal or work computer is it significantly more secure. If the leaker is already under close physical or technical surveillance there is very little they can do about it.
- mejari 10y agoThe additional risk is the assumption of protection. Someone who doesn't use this site and knows they are under watch may decide not to leak the information because they're aware of their risk. They could get a false sense of security from this site and leak information they otherwise wouldn't have, and are likely to be caught.
- aqme28 10y agoOut of curiosity: How do you counter document fingerprinting?
- _rolf 10y agoProbably best if you recreate the document from scratch and "in your own words".
- vog 10y agoThat's dangerous as well, because now your language can be analyzed and compared with other writings from you.
- tyrust 10y agoJust get hammered [0] before writing. [0] - or sober, whatever is the opposite of your typical working state
- Forbo 10y agoSoftware like Anonymouth [1] can be used to counter attempts to perform stylometric analysis. [1]: https://github.com/psal/anonymouth https://github.com/psal/anonymouth
- UnoriginalGuy 10y agoThen you're sending a fake to the media. The media will ask if the document is real and the organisation will correctly claim that the document is a fake (because you used your own words). A lot of these techniques actually make verifying leaked documents very difficult.
- techbio 10y agoIn fact some of the faithfully rewritten "facts" may be small fictions designed to identify, couched in the real text. Rewording them still confers the fingerprinted meaning.
- 10y ago
- verytrivial 10y agoLayers. It's all about layers. In this case, using Tails and Tor make it less likely, but not impossible, that the adversary will actually get their hands on the leaked document for analysis in the first place. (In this case I would be more concerned about the SecureDrop application and the specific instances becoming too juicy a target for the counter-intel people. Once they decide to infiltrate something, they generally do after a while.)
- deleted 10y ago[deleted]
- quickConclusion 10y agoAre there software vendors selling systems that make it easy to fingerprint documents? Are there any proven known cases of some administration branches using fingerprinting routinely?