EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

10.25.15

How to Securely Provide Techrights With Information, Documents

Posted in Site News at 6:35 am by Dr. Roy Schestowitz

The key is anonymity

A lock

Summary: Advice for potential whistleblowers, or sources with evidence of abuse that they wish to anonymously share with the world (via Techrights)

OVER the years Techrights has received critical information from dozens of sources, all of which remained safe (unexposed). But this does not mean that all of them did this safely. This article provides advice for those who wish to pass to us information in the safest of ways, without having to do a lot of complicated things.

Why Not Off-the-shelf, Self-contained Secure Software?

Over the past 6 months or so we have looked into various bits of Free/libre software, e.g. Briefkasten (no longer actively maintained, as of 2013) and SecureDrop, which is too big a project (massive also in the source code sense compared to Briefkasten, not to mention difficult to set up). After much effort we decided to settle for something which is simpler to use and is much faster to use. To facilitate leaking of sensitive documents (e.g. evidence of misconduct) we mostly require anonymity, as the content of the material does not — in its own right — do much (if anything) to expose the source.

Typically, whole frameworks are built for distributed and de-centralised leaking. This requires quite a bit of hardware, which in turn needs to be set up and properly configured. It’s complicated for both sides (source and receiver) and it’s usually developed for large teams of journalists, for constant interaction with sources, or a regular flow of material. We do not require something this advanced. In practice, a one-time document drop is usually enough.

Our Proposed Solution

We have decided that the following method would be good enough given the nature of leaks we normally receive. They are typically about technology, rather than some military or surveillance apparatus such as the CIA’s assassination (by drones) programme or the NSA’s mass surveillance programme.

For extra security, we kindly ask people to ensure anonymity/privacy tools are used, notably Tor. Without it, privacy/anonymity cannot be assured to a high degree. It’s possible, but it would not be unbreakable (meaning too great an effort and a challenge for spies to take on).

Establishing a Secure (Anonymous) Session

Follow the following steps, with (1) for extra assurance of anonymity.

  1. Install Tails or prepare a Tails device (e.g. Live CD) to boot on a laptop, in order to simplify session creation with Tor (for those who insist on using Windows we have this guide [PDF]).
  2. Irrespective of (1), seek public wireless/wired access in something like a mall (preferably not a sit-down like a coffee shop, where cameras are operated and situated in a way that makes it easy to track individuals by faces, payment with debit/credit cards and so on). The idea is to seek a place — any place — where it is hard to know the identity of the connected party, even by association (e.g. friend or family). Do not use a portable telephone (these are notoriously not secure and regularly broadcast location).
  3. Refrain from doing any browsing that can help identify patterns or affiliations of the user (e.g. session cookies). In fact, unless Tails is used, it might be worth installing a new browser (Opera for instance) and doing nothing on it prior to the sending of material. This reduces the cookie trail/footprint.

Send the material

Once logged in anonymously, anonymously (do not log in) submit text through Pastebin and take the resultant URL for later pasting. Do not pass PDFs for non-textual material. Instead take shots of them, to reduce/eliminate metadata which is often being passed along with them. Then submit to Anonmgur and make a note of the resultant URL for later pasting.

This is typically a one-way communication channel, so add any context which is necessary, then link to the above material as follows:

  • Log in to the #techrights IRC Channel via the Web browser.
  • Choose a pseudonym and sooner or later we will get around to seeing the new arrival and checking what there is to be said (there are dozens of us there).
  • Drop the link/s in the channel. If someone is on the keyboard at the time, there might even be time for interaction. Do not say anything that can help reveal identity (sometimes the language itself is revealing).

Caveats

While not impenetrable, it would take an enormous amount of effort (and connections in several high places) to unmask a source who follows the steps above. Unless it’s a high-profile political leak, such an unmasking effort would be well beyond what’s worth pursuing (expensive and complicated). MAC address-level spying often assumes access to very high places (and deep into back rooms), so therein lies no significant danger, especially when the best anonymity tools are properly used and the incentive to unmask isn’t great enough at high places (usually the political or military establishments).

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email
  • Slashdot

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Guest Post: The Worrying State of Political Judgement in Free Software Communities

    A look at what Mozilla has become and what that teaches us about the Web and about software



  2. Links 21/9/2020: KTechLab 0.50.0, Linux 5.9 RC6

    Links for the day



  3. Git is Free Software, GitHub is Proprietary Trap

    More and more people all around the world understand that putting their fruit of labour in Microsoft's proprietary (but 'free') prison is misguided; the only vault they have is for human beings, not code



  4. Daniel Pocock on Codes of Conduct and Their Potential Dangers in Practice

    In Debian we’ve already witnessed several examples where Codes of Conduct, if put in the wrong hands (in the Linux Foundation it’s corporate hands), can achieve the very opposite of their intended goal and its a true shame as well as a travesty for legitimate victims of real abuse



  5. Links 20/9/2020: Flameshot Screenshot Tool 0.8, Okular Improvements and More

    Links for the day



  6. Reminder: Vice Chair of the Linux Foundation's Board is an Oracle Executive Who Used to Work for Microsoft

    The Linux Foundation issued statements to the effect of opposing Donald Trump, but its current leadership (people from companies like Oracle, Microsoft and IBM) is a strong proponent of doing as much business as possible with Trump (even in violation of international law)



  7. [Meme] How to Hijack Linux and Free Software to Make Them Proprietary and Microsoft-Controlled

    Intel keeps outsourcing almost everything (that's not proprietary with back doors, e.g. ME) to Microsoft's proprietary software prison, known as GitHub; to make matters worse, Intel now uses the Microsoft-hosted Rust to develop in Microsoft servers, along with Microsoft, code that promotes Microsoft proprietary software (e.g. Hyper-V) and non-standard 'extensions'.



  8. DDOS Attacks Against Us Lately

    (Distributed) Denial-of-service attacks or DDOS attacks have slowed down the site, but we treat that as evidence of suppression and fear (of what's to come and what was recently published), or accuracy (in reporting) rather than inaccuracy



  9. [Meme] Windows as Dead Man Walking (Patches Accelerate the Death)

    Microsoft is squeezing whatever life is left in its “burning platform” (which is already exceeded in terms of market share by Android) that has a "burning" (bricked) WSL with barely any users and plenty of critical problems



  10. We Let Them Get Away With Murder, But They Make up for It by Banning Words

    The Microsoft propaganda machines (notably ZDNet this weekend) are busy portraying Microsoft as a “good company” for censoring words, never mind the actual, meaningful, substantial actions of Microsoft, which is boosting authoritarian people who imprison even babies (for the ‘crime’ of being on the ‘wrong’ side of the border)



  11. High-Profile and Invalid (Invalidated) European Patents Harm the Presumption of Validity of European Patents

    The EPO's 'printing machine' (over-producing patent monopolies) is harming the legal certainty associated with such patents, helping nobody but deep-pocketed monopolists and law firms



  12. Epitaph for (Death of) Patent-Centric Media: Litigation Giant Bird & Bird Nowadays Doing Ads as 'Podcasts' in Think Tank Site 'Managing IP'

    Publishers don't hesitate and openly revel in taking bribes as if it's a badge of honour or importance, allowing themselves to be profoundly corrupted in pursuit of quick cash; we discuss what's happening in sites that pretend to cover patent news (but actually drive agenda of litigation giants, to the detriment of actual innovators)



  13. IRC Proceedings: Saturday, September 19, 2020

    IRC logs for Saturday, September 19, 2020



  14. Links 20/9/2020: 4MLinux 34.0 Released, September Release and EndeavourOS for ARM

    Links for the day



  15. Video: Free Communication With Free Software - Daniel Pocock - FOSSASIA Summit 2016

    The 2016 FOSSASIA talk from Daniel Pocock (Debian) about Free software alternatives to Google, Microsoft Skype and so on (Microsoft started paying Debian in 2016)



  16. [Meme] Microsoft Downtime... Now in 'Linux' (Wait a Month for Microsoft to Restore Uptime)

    Microsoft’s utter failure that is "WSL2" is bringing the failures Windows is so notorious for (loss of work, lack of security, fatal patches) to so-called ‘Linux’; the timeframe for a fix says a lot about just how much Microsoft “loves” Linux…



  17. Coming Soon: Microsoft Leaks (Which Microsoft Pressured Medium to Suppress and Promptly Unpublish)

    Microsoft is no ordinary company; exposing it is like dealing with the Mafia or some drug cartel in Mexico, but we're able to publish truths about Microsoft nonetheless (their notorious intimidation and silencing attempts have always failed against us)



  18. Dishonest Corporations -- Like Smug Politicians -- Pretend to be Something They're Not

    Corporate lies dominate the media, having been crafted by unethical marketing departments with their photo ops and hashtags



  19. GNU is Also a Brand, But It Boils Down to Philosophy and Principles, Not Greed or Corporate Identity

    Why the goal of GNU should be freedom rather than so-called 'world domination' (the objective of large firms with shareholders)



  20. IRC Proceedings: Friday, September 18, 2020

    IRC logs for Friday, September 18, 2020



  21. Links 19/9/2020: Taiwins 0.2 and a Call for Ubuntu Community Council Nominations

    Links for the day



  22. One Year Later Richard Stallman Needs to be Un-cancelled and Attention Turned to the Real Perpetrator of MIT Scandals

    The sheer hypocrisy, treating Stallman as the real nuisance to MIT when it was in fact Bill Gates who trafficked money through convicted sex criminals (to MIT); justice needs to be belatedly restored



  23. ZDNet's 'Linux' Section Isn't About Linux But About Microsoft

    ZDNet's so-called 'Linux' section isn't really about GNU/Linux; it's just the site's usual Microsoft propaganda, bought and paid for by Microsoft



  24. Debian's Network of Gossip and Gossipmongering in Debian-Private

    Reprinted with permission from Debian Community News



  25. More EPO Disclosures: An Explanation of How an EPO Survey Plots to Dismantle the EPO's Staff

    Dismantling the Office for the benefit of a bunch of private companies (taking over various duties of EPO staff) seems like the management's goal; included in image form (and text) below is today's publication. There's a PDF with text (not OCR) but it contains metadata.



  26. Forced Confessions and Thought Control in Debian

    Reprinted with permission from Debian Community News



  27. [Meme] You Cannot Elect/Vote Corporations Out of Power (Eternal Vigilance is Required)

    Based on early polls, Biden will be president-elect in about a month and a half; but it’s important to remember that the election (if honoured by the current tenant of the White House) won’t be the end of corporate abuse of power in the same sense that driving Microsoft out of business won’t miraculously mean that Free software ‘won’ (we have a lot more to confront still)



  28. Debian Volunteers Disallowed and Forbidden From Talking About Politics (Unlike Debian's Aristocracy That Handles All the Money From Sponsors)

    Reprinted with permission from Debian Community News



  29. Political Compass for Free Software (and Those Who Attack Software Freedom)

    With RMS (the father of the movement) betrayed from multiple angles (OSI, Linux Foundation etc.) it’s probably important to depict what’s going on, quasi-politically speaking



  30. Richard Stallman Has Not Changed His Tune at All

    Richard Stallman's (RMS) principled views regarding software go back to the days of zeroes and ones; his position 35 years ago was almost indistinguishable from today's position


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts