9 ms·
How to Leak to the Press
- Peroni 13y agoOut of curiosity, why not just send a letter in the post? Pretty hard to trace an anonymous letter. EDIT: Just spotted the update. Question answered.
- digitalengineer 13y agoTake in account they'll look at fingerprints, sweat, DNA, type of paper, ink and type of printer used. Spelling errors, how you wrote something, etc can also be used to identify you. (Every printer leaves it's own watermark). Perhaps best to print and use a old 2nd hand xerox machine to copy everything or fax it from a public faxservice.
- atirip 13y agoWrite in foreign language you do not master well. All your errors are then "childish" and untraceable.
- tehmaco 13y agoOr run it through Google translate (or equivilent) a few times and manually correct any critical words in the end result.
- raverbashing 13y agoHopefully it doesn't log the messages... or does it?
- skinnynerd 13y agoThere are plenty of old typewriters lying around. Although you would still have to take precautions like getting rid of it afterwards and make sure it does not make use of polymer tape ribbons (in which case you would have to destroy and discard that as well).
- smacktoward 13y agoTypewriters have signatures too: http://en.wikipedia.org/wiki/Typewriter#Forensic_examination http://en.wikipedia.org/wiki/Typewriter#Forensic_examination
- skinnynerd 13y agoGood link, thanks.
- tomjen3 13y agoSure, but the government wouldn't have a database of those anywhere and getting rid of a typewriter isn't likely to get anybody noticed (I cleaned up in the attick the other day, can you believe what I found?).
- rexreed 13y agoEven better, receipt / thermal printers. No ribbon and pretty much untraceable. Lots of them lying around second hand in flea markets and yard sales.
- jusben1369 13y agoThe bigger point is that journalists usually need to go back and forth with you.
- dsleno 13y agoTell the reporter to mail you at Mailinator or Lockbin.com and retrieve their messages by connecting with TOR.
- saalweachter 13y agoOr tell the reporter to take out a classified ad in a free, public paper distributed in the nearest large metropolitan area. The communications from the reporter don't need to be private or targeted. Everyone will know he's involved when he publishes, and he can reasonably encode questions by referring to the documents already sent. "MR X, CAN YOU PROVIDE FURTHER INFORMATION ON THE EVENTS DISCUSSED ON PAGE 13."
- brown9-2 13y agoThe communications from the journalist certainly do need to be private. Advertising that you are working on a story that will reveal big government secrets is a good way to be put under surveillance to find out who is doing the leaking to you. The journalist would not want to announce to the world that the process of receiving classified information is ongoing.
- smacktoward 13y agoThe ad can be written so as to look innocuous to anyone other than the journalist and the leaker, if those two can agree on a format for doing so.
- skinnynerd 13y agoHere is a good guide from Cryptome http://cryptome.org/cryptome-anon.htm http://cryptome.org/cryptome-anon.htm
- nkurz 13y agoOr maybe not that hard. "Feds: Postal Service photographs every piece of mail it processes" http://www.thesmokinggun.com/documents/woman-arrested-for-obama-bloomberg-ricin-letters-687435 http://www.thesmokinggun.com/documents/woman-arrested-for-ob...
- irrationalidiom 13y agoThis advice is dangerous, because the author fails to mention other precautions the user can and should take, such as: * Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS * Change the MAC address of the Wifi used to connect at the internet cafe * Use Tor, most easily via the Vidalia browser bundle The author also does not mention that leaking documents can expose the whistleblower via watermarking and user information embedded in the file (most infamously in MS Word documents with versioning). Edit: update formatting
- DanBC 13y ago> Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS Tails is a Linux distribution aimed at privacy and anonymity. (https://tails.boum.org/ https://tails.boum.org/)
- adlpz 13y agoI know I'm being paranoid, but I feel uneasy using a privacy-aimed distribution for privacy. The whole obvious target thing.
- steveklabnik 13y agoThis is where the 'many eyes' things comes into play; if the whole distro is OSS, then you can be pretty sure that it's good.
- anonyfuss 13y agoMost people never review source code, and they certainly don't disassemble and review all the binaries. 'Many eyes' is a security fallacy in cases like this.
- steveklabnik 13y agoTails is ridiculously well known; if something was bad in it, it would be big news.
- codeulike 13y agoOr use a website that has an Anonymous Drop Box. Wikileaks did have one, but its no longer operational. I think a few mainstream media organisations copied the idea and claimed to have anonymous drop boxes? e.g New Yorker has one, called Strongbox - http://www.newyorker.com/online/blogs/closeread/2013/05/introducing-strongbox-anonymous-document-sharing-tool.html http://www.newyorker.com/online/blogs/closeread/2013/05/intr... - powered by Tor, designed by Aaron Swartz and others, and open-sourced as DeadDrop http://deaddrop.github.io/ http://deaddrop.github.io/
- codeulike 13y agoAlthough, first comment on the new yorker post is a good explanation of why StrongBox might not be enough http://fyre.it/i3tCXN.4 http://fyre.it/i3tCXN.4
- dllthomas 13y agoIt sounds like we need to provide time delay for file transfer as a Tor hidden service.
- nosuchagency 13y agoMixmaster (and also Mixminion) is high latency anonymity network and is therefor nearly impossible to trace. You remember the University of Pittsburgh bomb threats. The FBI is still unable to track down who was sending the emails. A pretty strong endorsement in my mind
- digitalengineer 13y agoClicking on the comments link does not reveal any comments. I'm getting a "Subscribe now to get more of The New Yorker's signature mix of politics, culture, and the arts. "
- carlob 13y agoI get the same. Might be related to the fact that I use Ghostery to block absolutely everything. I was starting to feel too paranoid about that, but now I think it's totally justified.
- confluence 13y agoFeels a bit overkill and way too identifying - security cameras + internet records + GPS locations will all help track you down, even if they are intermittent. Buy a stack of envelopes from a supermarket. Buy a stack of stamps. Buy a USB. Acquire all with cash. Transfer all files to the USB via live CD - make sure all meta-data is stripped and files are redacted to avoid fingering you. Handle the envelopes/stamps/USB with care - gloves + hairnets + have a shower before handling (skin cells). Print the addresses (be careful here - printers sometimes put identifying marks - get the most common inkjet that doesn't use dots). Print a message and stick it in the envelope - e.g. "USB contains leaked NSA documents on massive domestic spying. Copy files to your computer then destroy and dump USB then burn the envelope to ensure your own security." Put the stamp on. Drop the letter in the mailbox - try and get a journalist's home address, they'll read it. Repeat for multi-journalist dump. Make sure you don't lick the stamps and drop the letters off in physically separated postboxes without security cameras. You do not want to be in constant communication with journalists/people whilst doing any of this, because the more you talk with them, the more you leak. You want to just strip all identifying data, dump your leak, and run. This tactic has been used for ages to transfer sensitive data, most notably by kidnappers (ransom notes), spies (easy data transfer), whistle blowers (documents) and serial killers (think Ted Kaczynski).
- eli 13y agoBeing completely anonymous with no method for followup questions makes it difficult for the journalist to publish your leak. I suggest you be very patient if you go this route as any reputable journalist will have to independently find another source or verify the documents.
- confluence 13y agoA multi-journalist dump + impressive documents + ambitious journalists + at their home addresses = highly likely publication without getting you sent to Gitmo. Make sure journalists are already on side with you though - aka people that have already argued against whatever cause you wish to damage. However, if the documents are uniquely identifying and of incredible importance then you will want to go public, and you will want to go loud; have your face plastered everywhere, documents in every conceivable location, send them to thousands of journalists via email, scream your identity to the roof tops, don't go to ground, go to press conferences, and leave the country if at all possible before you do go loud.
- smackfu 13y agoThe Boston bombing also shows that you should cloak your identity physically. Hat and sunglasses at least. The one who didn't hide his identity is the one who was easily identified.
- tomjen3 13y agoHat and sun glasses? No, get a burka (the muslim body clothing that hides the entire body) -- not only will people want to avoid you, but they wouldn't even be able to write in the description what sex you are (and with a little bonus they might assume it is not a disquise in which case they are truly looking in the wrong direction).
- rexreed 13y agoProbably one of the easiest ways to stand out in a typical US crowd. More noticable than hat and sunglasses. If the purpose it to make video surveillance not as notable but also not attract attention than a large hat and sunglasses in hot weather or a scarf and hat in cold weather (even better) will do the trick. Also, modifying hair color and facial hair features is a good trick.
- tomjen3 13y agoYou may stand out, but that isn't necessarily bad, so long as what they remember about you isn't enought to identify you and might even misdirect them into thinking muslim terrorist.
- lemming 13y ago...feeding the information to the phone company which retains this information for weeks, months, even years. Just a warrant-step away. The warrant comment suddenly sounds old-fashioned.
- sahirh 13y agoThe leaking via gmail has an issue: In many cases when creating a new gmail account, you have to provide a phone number for an automatic text verification code.
- _k 13y agoTrue. The article has so many mistakes in it, it's almost as if it's written by the government !! We need a new article.
- tripzilch 13y agoyeah, I was going to say this as well. sometimes they ask for a phone number, and sometimes they don't. I wonder what triggers it, maybe if a lot of different Google Accounts log in from that single IP, it assumes it's some open coffeeshop wifi or similar?
- ceautery 13y ago"When you are done you must [...] turn off the Wi-Fi before turning off the computer and removing the battery. The dedicated computer should never be used on the network except when..." This is silly on a "behind 7 proxies" level. Just go the library. If you're worried that investigators are going to swoop down CSI style to track you down because of your important secrets, maybe you should speak to a psychiatrist.
- jimworm 13y agoSecurity cameras are quite often placed at the entrance/exit. Having your device connect and making a DHCP request as you walk in seems like a legitimate concern.
- ceautery 13y agoYeah, I get it. I just don't feel this level of caution is productive. If you aren't being currently tracked, then your concern is about whether someone can backtrack forensically and find you. I think a simple trip to a public computer at a library, particularly at a busy time, affords as much pragmatic anonymity as jumping through all the hoops described in the article. On the flip side, if you are already are under suspicion, then all your efforts to anonymize a leak are in vain. You'll be the first person interrogated after a leak, and if your beliefs about the Orwellian nature of the government are true, the $10 hammer to the kneecaps (thanks XKCD) will undo any clever hiding you did. I just don't think it makes much sense to go to these lengths. It's already understood that governments are corrupt. Are the specifics of what secrets you want to publicize worth the personal risk? If no, then you're playing spy, which is fine. If yes, then they'll probably find you if they really put their heart into it.
- rexreed 13y agoConnect from the parking lot.
- randomchars 13y agoThe article basically for people who want to leak classified documents or state secrets. Whistleblowers are currently the target of witchhunts so I'm not sure what makes you feel think they should seek the help of a psychiatrist.
- perlpimp 13y agoIn Russia you have to provide passport in order to buy a sim card.
- steveklabnik 13y agoI'm not sure why you were downvoted; this is true in many places in the world.
- tomjen3 13y agoThat may be the law but in places like Russia you can also just hand them 20 USD to look the other way.
- mtgx 13y agoWhat about "simply" using DeadDrop? http://deaddrop.github.io http://deaddrop.github.io http://www.newyorker.com/online/blogs/closeread/2013/05/introducing-strongbox-anonymous-document-sharing-tool.html http://www.newyorker.com/online/blogs/closeread/2013/05/intr... Or Retroshare: http://retroshare.sourceforge.net http://retroshare.sourceforge.net https://retroshareteam.wordpress.com/2012/12/28/cryptography-and-security-in-retroshare https://retroshareteam.wordpress.com/2012/12/28/cryptography... https://retroshareteam.wordpress.com/2013/01/06/privacy-on-the-retroshare-network https://retroshareteam.wordpress.com/2013/01/06/privacy-on-t...
- mirkules 13y agoQuestion about cash: do banks keep track of the bills that are dispensed through ATMs? If so, it's probably safer to break your bills first. Also, be aware of cameras near the internet cafes or places you intend to use the burner phone.
- ajays 13y agoFTA: "There’s another option I didn’t originally mention here — leaking over mail. Investigative journalist Julia Angwin of the Wall Street Journal points out that physical mail, dropped in a random post-box with a bogus return address, is perhaps the best way for anonymous one-way communication." DO NOT DO THIS! Every printer leaves a microscopic fingerprint on every printout. The printouts can be traced back to your printer. If it's an office printer, that still narrows it down considerably. Even electronic documents can have watermarks, etc. For photographs, there's the EXIF information, for instance. If you want to share a photo, pipe it through "djpeg | pnmscale 0.99 | cjpeg -quality 90" first. It will get rid of EXIF, and also re-compress the image, changing its signature.
- rbonvall 13y agoInteresting, I didn't know about printer fingerprints. But I think there are still ways to workaround this. You could print the doc in an internet cafe, or buy a cheap printer and then destroy it, or print it and then take a low quality photocopy. You could even write it by hand or on a typewriter.
- jetti 13y ago"buy a cheap printer and then destroy it" Have somebody else buy it with cash only. Surveillance cameras catching you with a printer and then not able to explain where it went will not go well. I can't believe I actually am saying this. I truly can't believe that we are all having these kinds of conversations about something that should be as trivial as telling the truth. This is the kind of stuff I imagine the Russian mob would do, not employees of the US government who have a conscious. It is truly despicable and makes me a bit nauseated. The worse part is there doesn't seem like a fix and there doesn't seem like there is anywhere else to go to avoid this.
- ajays 13y agoA photocopier is a (scanner+printer), so the problem remains. Your best bet is large flea markets, where you can buy stuff like WiFi dongles, etc. with cash. Then wait a while before you use them. I can't believe I'm having to write this, either. This is like giving instructions to a Soviet activist in the Cold War days, but ironically it is in my own country. How did we fall so far?
- superuser2 13y agoLast time I purchased a prepaid cell phone, I had to show government photo ID. The RadioShack clerk entered my license number in a database. So the burner phone may not be the best route.
- tonyplee 13y agoLove the quote "Even the head of the CIA can’t email his mistress without being identified by the FBI." :-)
- 0xdeadbeefbabe 13y agoA test would at least increase my confidence. I guess step 1 is to find something worth reporting, and the article pretty well demonstrates how hard that is.
- Zarathust 13y agoThis discussion revolves a lot around printer watermarking documents. It seems that it mostly concern color printers. Here is an advisory by the EFF which tested quite a few of them https://www.eff.org/pages/list-printers-which-do-or-do-not-display-tracking-dots https://www.eff.org/pages/list-printers-which-do-or-do-not-d...
- VikingCoder 13y agoPull the sim card, and smash THAT with a hammer. Don't just smash the whole phone - you're unlikely to destroy the sim card, which is the most incriminating part of your phone.
- mischanix 13y agoOr toss the whole thing in a fire.
- beat 13y ago"I don't need to be fast. I just need to be faster than you!" Your trail-covering only needs to be better than the investigation capability of those who are investigating your leak.
- IgorPartola 13y agoHonest question: what prevents someone from feeding misinformation to the press if all IDE tidying info is stripped away? If the journalist has no way to contact you, why should they trust your leak? Could the FBI or NSA send out bogus leaks and the go after journalists that publish the fake info for revealing what they believed to be confidential information?