8 ms·
SecureDrop – An open-source whistleblower submission system
- amelius 10y agoIs this based on Tor? Or are whistleblowers expected to use Tor on top of this?
- tyingq 10y agoThey have an onion address at the bottom of the page. Then, the various guides, like for sources, suggest submissions are TOR only...
- agd 10y agoWhistleblowers are expected to use Tor to visit the specific secure drop address for the org in question.
- corobo 10y ago> Each Source Interface is only available as a Tor Hidden Service, which is a special type of website with an address ending in ”.onion” that is only accessible through Tor. Tor is an anonymizing network that makes it difficult for anybody observing the network to associate a user’s identity (e.g. their computer’s IP address) with their activity (e.g. uploading information to SecureDrop). From https://docs.securedrop.org/en/latest/source.html https://docs.securedrop.org/en/latest/source.html
- unicornporn 10y agoDo not forget https://onionshare.org/ https://onionshare.org/ An excellent alternative to SecureDrop. At least so it seems...
- hackuser 10y agoWhat is the basis for thinking it's secure? Anyone can write an app and then type the characters "s-e-c-u-r-i-t-y" in the description.
- greggh 10y agoCoded by Micah F. Lee of the free press foundation. Pretty well respected member of the community and all around great guy.
- hackuser 10y agoThanks. For my and others' reference, is Mr. Lee an IT security professional? I don't mean to disparage those who aren't (I'm not), but in the end security comes down to trusting the expertise, execution, and intentions of the developers - and he sounds good for the latter two, based on what you say.
- tptacek 10y agoThis is a trivial Flask file uploading application, with a "code name"-based feedback system, wrapping GnuPG's Python bindings, intended to be run on Tor. The security it provides is marginal, but it's so simple that it's not the part of anyone's stack that's most likely to be compromised. I think a significantly better version of this could be built. What makes doing that tricky is that you want to retain the almost hello-world simplicity of this app, because the big reason not to run something like this is the likelihood that the server itself will have flaws. On the other hand, it's 2017, and you can also accept files over secure messengers. Later Amusingly, people seem to think that these are bad things to say about an application like SecureDrop.
- agd 10y agoSecureDrop isn't just an application, it also encompasses the infrastructure setup and opsec procedures required for the submission system to function securely.
- aleksag 10y ago+1 It also teaches the receiving end how to receive, and work with sensitive materials in a more secure way. That has actually been the hardest part of the implementation we did; teaching the journalists how to treat the material received. We also tried to create a fairly informative page for the tipsters https://www.dn.no/staticprojects/2016/12/securedrop/ https://www.dn.no/staticprojects/2016/12/securedrop/ (in Norwegian)
- homakov 10y agoAgreed on unnecessary complexity, but it's not a trivial app. Quick scrolling through sources and we see dozens of endpoints and each is potentially vulnerable. Trusting the server, developers, Flask (which is by no means a good choice for secure app, my word) etc... messengers is a better option for sure.
- tptacek 10y agoThe endpoints don't do much, the app delegates most of its functionality to very well-known Python libraries, there's minimal backend, no account system... it's a pretty auditable piece of code. If you can't get a handle on the security of this thing, there's no web app you can get a handle on.
- eganist 10y agoFor those who don't know Garrett Robinson (who heads SecureDrop's development), he's been extremely dedicated to user privacy issues and first amendment concerns. I may occasionally differ from his views, but I admire the passion he's poured into both his work at Mozilla and into SecureDrop. https://freedom.press/people/garrett-robinson/ https://freedom.press/people/garrett-robinson/
- secfirstmd 10y agoAlso worth shouting out to Global Leaks, a similar sort of system with some interesting other features. https://www.globaleaks.org https://www.globaleaks.org
- hackuser 10y agoWhat is the basis for thinking it's secure?
- secfirstmd 10y agoExcellent team of people. Widely used. Code audits etc etc https://github.com/globaleaks/globaleaks/wiki https://github.com/globaleaks/globaleaks/wiki
- benwikler 10y agoRIP Aaron Swartz, who originally built this. He'd be 30 now.
- saycheese 10y agoHighly suggest anyone that has not watched "The Internet's Own Boy: The Story of Aaron Swartz" take the time to watch it: https://m.youtube.com/watch?v=gpvcc9C8SbM https://m.youtube.com/watch?v=gpvcc9C8SbM RIP Aaron
- jeron 10y agonon-mobile link: https://www.youtube.com/watch?v=gpvcc9C8SbM https://www.youtube.com/watch?v=gpvcc9C8SbM
- deleted 10y ago[deleted]
- eptcyka 10y agoIf a site like this doesn't yell at you for accessing over just https and not tor, you can only expect it to be run by three or four letter agencies.
- elcct 10y agoOne could use Bitmessage for leaks - just create a channel and let people publish data to it. https://bitmessage.org/wiki/Main_Page https://bitmessage.org/wiki/Main_Page
- dokument 10y agoCame here to say this. You could just publish to the general chan. However, bitmessage is no good for distributing data. It would be good for distributing how to get that data (torrent magnet, mega.nz link, encryption key, etc).
- benevol 10y agoI'm not sure the problem is a lack of leaking solutions that we can trust, especially as long as WikiLeaks is around. The problem I see is that there will be no more important leaks: a) Given how around 50% the US population was brainwashed by government and media into believing Snowden is a traitor, b) Given the fact that America has elected a president who wants Snowden executed, c) Given that the NSA has locked down their systems completely since Snowden's revelations. Who would want to take these risks to leak anything just to be put on "the list" by their own country and People? If Snowden's leaks were not enough to get people thinking then the only thing that will is serious pain and suffering. And that is what I personally expect to come (for the lower and middle class, at least).
- haikuginger 10y ago> I'm not sure the problem is a lack of leaking solutions that we can trust, especially as long as WikiLeaks is around. You still trust WikiLeaks?
- benevol 10y agoAs long as Assange is in control, absolutely. Currently, nobody beats the level of commitment that people like Assange and Snowden have proven.
- adultSwim 10y agoI still support Wikileaks.
- brokenmachine 10y agoWhat has WikiLeaks done to lose trust? Are you talking about the trumped-up completely bogus rape case?
- tuxxy 10y ago>Given that the NSA has locked down their systems completely since Snowden's revelations. Are you sure about that? NSA has been leaking far more recently than in the past. The Shadow Brokers are just one of many. Not to mention, the intercepted signals that are being talked about through the news with the Trump presidency.
- fptoperation 10y agoSecuredrop is used by NYT-level companies. I thought using it is a no-brainer for any news media. Now I am having doubts, especially after this [0] :(( [0] http://bit.do/meow-meow http://bit.do/meow-meow
- saycheese 10y agoRecently review the SecureDrop and was suprised how many main stream media companies to not provide a way for leakers to safely leak information to them.
- CM30 10y agoNo kidding. Seems like only a few of the largest media outlets provide SecureDrop or a similiar alternative, and that number quickly drops to zero when you move from general mainstream media to more specialised stuff (tech, sports, gaming, music, etc). Most don't even provide more than a simple contact form or email address...
- h4waii 10y agoSecureDrop is also in use by CBC, a publicly-funded National broadcaster in Canada, and is actually implemented and managed properly -- regardless of the quality of SecureDrop itself. https://securedrop.cbc.ca/ https://securedrop.cbc.ca/ The gateway site is only accessible over HTTPS, then it's to an .onion via a link to Torbrowser, and mentions of TAILS, all caveats with using the stated software applies though.
- kyboren 10y agoCBC should not host that site on such a distinctive subdomain, as the hostname "securedrop.cbc.ca" will leak in the clear during the TLS negotiation. It would be far better to host the same content at, say, https://cbc.ca/securedrop https://cbc.ca/securedrop.
- hackuser 10y agoSecureDrop uses Tor Browser, as do many other public interest security solutions. However, a respected security expert here on HN recently said of Tor Browser: the Tor Browser might be the least safe browser to use of all available browsers that can be installed on modern computers. It is a perfect storm of "inferior security design" and "maximized adversarial value per exploit dollar spent". / Don't use Tor Browser. He recommends Chrome (presumably over the Tor network). I tend to believe the expert, because IME real security expertise (as opposed to technically sophisticated people reading about security and trying to DIY) is rarely utilized and applied even by prominent organizations and projects. But I wish someone would reconcile all of this. EDIT: Some clarifying edits
- Kinnard 10y agoCould you cite with a link to the actual comment?
- riquito 10y agohttps://news.ycombinator.com/item?id=13623821 https://news.ycombinator.com/item?id=13623821
- nikcub 10y agoYou need to disable WebRTC, WebGL, Canvas and a bunch of other things if you're going to use Chrome/Chromium with Tor There is no good solution at the moment - one lacks security while the other lacks privacy.
- KirinDave 10y agoNone of this stops browser fingerprinting completely. Browser fingerprints can be extracted from just using canvas calls.
- hubert123 10y agoI dont really understand the issue with browser fingerprinting. Yes in theory it can uniquely identify you but only if your browser fingerprint never changes. Everytime I go to one of these "are you unique?" websites, I am a new guy to them.
- mindslight 10y agoTangential and more applicable to a different style of leak, but I'd be interested in seeing the development of some protocol ideas for authenticating leaks to gain confidence the leaker is actually within a given organization. Otherwise we're left not knowing if a casual leaker is for real or just entertainment twitting. One rough idea is that large organizations make specific press releases or announcements, that a precommitment could demonstrate privileged access to. Another idea would be inclusion of some internal communication, which other members of the organization could confirm. This would require those other members to be sympathetic to the leaking, and also not worried about reprisals for speaking publicly like so. This probably isn't useful on its own, but the basic mechanism could be combined with other means to derive utility without public attestation. The biggest issue is (of course) an adversarial organization subtly changing to-be-published information, to sniff out the actual leaker. Which is why I'm envisioning the need for some formality that could quantify and mitigate such leakage.