5 ms·
If you ever need to whistle blow this is the list of organisations who have implemented securedrop https://securedrop.org/directory/ https://securedrop.org/dire
by ioseph 4y ago
If you ever need to whistle blow this is the list of organisations who have implemented securedrop https://securedrop.org/directory/ https://securedrop.org/directory/
But if you are going to my understanding is physical documents is still the safest option.
- masteranza 4y agoWhy would anyone trust it if most of the organisations listed have not called for the release of Julian Assange in years?
- alwayslikethis 4y agoPhysical documents requires you either to send it somehow with the hope that it doesn't get noticed, or personally deliver it assuming you are not getting tracked 24/7, which is a real possibility if you have anything of value for these news organizations. Guarantees provided by E2EE, among other things, do not exist in real life.
- eastbound 4y agoIf you deliver physical documents, don’t forget that printers have yellow dots to track the originating printer. Nowadays it’s certainly possible to track the credit card that purchased them.
- O__________O 4y ago> But if you are going to my understanding is physical documents is still the safest option. OpSec wise it’s unclear why physical delivery would be more secure. From mail carriers having non-public methods of identifying anonymous/fake senders, to printer & content steganography, device tracking, biological forensic identification, etc. Why to you is physical delivery a more secure option?
- vorpalhex 4y agoPrinter marks only apply to commercial laser printers, and only some brands. You are probably safe when printing at home. There are still plenty of mailboxes. No need to be anywhere near another human. Leave the phone at home. Walk to the mailbox at night. Drive closer to it but not up to it if need be it. You aren't going to get much except fingerprints from a document. Wear gloves when handling the document if that is a theat. Remember your adversary is probably not all powerful and knowing. They are willing to expend some cost to chase you, and you only need to be more expensive to unmask then that amount. We STILL live in the world where the most common security breach is having no password or a re-used password. Documents are leaky. Metadata kills.
- O__________O 4y agoYou’re assuming leaker is not actively being monitored, mail carriers’ non-public methods of identifying anonymous/fake senders do not overlap OpSec failure of sender, assuming printer & content steganography doesn’t apply, unusual device tracking counter surveillance techniques are not a red flag, leaker understands counter biological forensic identification measures, etc. Point is OpSec is HARD — and telling someone “just physically deliver it” is a recipe for failure.
- vorpalhex 4y agoThe theory that if you ever leak something that you are going to be positively identified by CSI style forensic science and it is basically impossible to leak something without spy agency level methods is, itself, a tool to stop leaks. We know your printer! We track you everywhere! We have your fingerprints! We can pull your DNA from a letter! It is beneficial to the powers that be that ordinary citizens believe they are good at their jobs and omniscient. They are not. Yes, to a great degree, this matters on your adversary. The truth is that most whistleblowers are not Edward Snowden. They are whistleblowing on their employer, who is probably a private company or small government org. The bar to exceed detection does not require you to be James Bond or to understand quantum cryptography. It requires gloves, a cheap printer, and maybe a trip to the thrift store and the post box. If your adversary is the NSA/FBI/KGB/Whoever, well, you know, plan accordingly. But that probably isn't your adversary. Your adversary is probably a mediocre IT security company that has trouble getting their techs to change their passwords and struggles to analyze whatever data they do collect from client endpoints. Don't under-estimate your adversary but also don't over-estimate them either.
- bflesch 4y agophysical stuff contains DNA and fingerpritns physical printouts are watermarked by the printer physical dvd copies sounds like safest option, but they might also have forensic watermarks by the disk drive firmware