Bonum Certa Men Certa

How to Securely Provide Techrights With Information, Documents

The key is anonymity

A lock



Summary: Advice for potential whistleblowers, or sources with evidence of abuse that they wish to anonymously share with the world (via Techrights)

OVER the years Techrights has received critical information from dozens of sources, all of which remained safe (unexposed). But this does not mean that all of them did this safely. This article provides advice for those who wish to pass to us information in the safest of ways, without having to do a lot of complicated things.



Why Not Off-the-shelf, Self-contained Secure Software?



Over the past 6 months or so we have looked into various bits of Free/libre software, e.g. Briefkasten (no longer actively maintained, as of 2013) and SecureDrop, which is too big a project (massive also in the source code sense compared to Briefkasten, not to mention difficult to set up). After much effort we decided to settle for something which is simpler to use and is much faster to use. To facilitate leaking of sensitive documents (e.g. evidence of misconduct) we mostly require anonymity, as the content of the material does not -- in its own right -- do much (if anything) to expose the source.

Typically, whole frameworks are built for distributed and de-centralised leaking. This requires quite a bit of hardware, which in turn needs to be set up and properly configured. It's complicated for both sides (source and receiver) and it's usually developed for large teams of journalists, for constant interaction with sources, or a regular flow of material. We do not require something this advanced. In practice, a one-time document drop is usually enough.

Our Proposed Solution



We have decided that the following method would be good enough given the nature of leaks we normally receive. They are typically about technology, rather than some military or surveillance apparatus such as the CIA's assassination (by drones) programme or the NSA's mass surveillance programme.

For extra security, we kindly ask people to ensure anonymity/privacy tools are used, notably Tor. Without it, privacy/anonymity cannot be assured to a high degree. It's possible, but it would not be unbreakable (meaning too great an effort and a challenge for spies to take on).

Establishing a Secure (Anonymous) Session



Follow the following steps, with (1) for extra assurance of anonymity.

  1. Install Tails or prepare a Tails device (e.g. Live CD) to boot on a laptop, in order to simplify session creation with Tor (for those who insist on using Windows we have this guide [PDF]).
  2. Irrespective of (1), seek public wireless/wired access in something like a mall (preferably not a sit-down like a coffee shop, where cameras are operated and situated in a way that makes it easy to track individuals by faces, payment with debit/credit cards and so on). The idea is to seek a place -- any place -- where it is hard to know the identity of the connected party, even by association (e.g. friend or family). Do not use a portable telephone (these are notoriously not secure and regularly broadcast location).
  3. Refrain from doing any browsing that can help identify patterns or affiliations of the user (e.g. session cookies). In fact, unless Tails is used, it might be worth installing a new browser (Opera for instance) and doing nothing on it prior to the sending of material. This reduces the cookie trail/footprint.


Send the material



Once logged in anonymously, anonymously (do not log in) submit text through Pastebin and take the resultant URL for later pasting. Do not pass PDFs for non-textual material. Instead take shots of them, to reduce/eliminate metadata which is often being passed along with them. Then submit to Anonmgur and make a note of the resultant URL for later pasting.

This is typically a one-way communication channel, so add any context which is necessary, then link to the above material as follows:



Caveats



While not impenetrable, it would take an enormous amount of effort (and connections in several high places) to unmask a source who follows the steps above. Unless it's a high-profile political leak, such an unmasking effort would be well beyond what's worth pursuing (expensive and complicated). MAC address-level spying often assumes access to very high places (and deep into back rooms), so therein lies no significant danger, especially when the best anonymity tools are properly used and the incentive to unmask isn't great enough at high places (usually the political or military establishments).

Recent Techrights' Posts

The Slop Presumption Rule
Tainting oneself can take one day
August 2026 Microsoft Layoffs Are "Secret Layoffs" or "Silent Layoffs"
It's all about secrecy, isn't it?
Newer Not Better: Treadmill Updates Cause Problems
after 2 years the un-updated machines still fine
SLAPP Censorship - Part 136 Out of 200: Lawyers That Get Paid to Mess About
They were already outnumbered and understaffed
 
Why Techrights Will Still be Active a Decade From Now
Techrights will carry on for many years to come
We Are Witnessing the End of IBM
IBM cannot find growth by moving downwards, by lowering standards
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 01, 2026
IRC logs for Saturday, August 01, 2026
Gemini Links 02/08/2026: Older Books, Esperanto Music History, and Slop Making Things Worse
Links for the day
Sharing and Empathy
Be more like Stallman, not Linus
Fedora 'Community' Became 100% IBM Staff, Drawing Up Policies Like CoC and CoI (Where the IBM is Excepted From Conflict of Interest Policies)
IBM has in effect killed Fedora
Gemini Links 01/08/2026: Planner Season is Upon Us, Slop "Apocalypse", and USENET
Links for the day
Cuts at IBM, Allegedly More Shutdowns to Come, CEO Visits Complicit Media to Promote Lies and Products That Will Never Exist (Misleading Shareholders)
IBM is collapsing
Links 01/08/2026: GAFAM Falling Deep Into Trillion in (Secret) Debt to Keep the Slop Bubble From Popping Already, Anger Over "FIFA’s World Cup Privatisation Plan"
Links for the day
The Cyber Show on the Slop Bubble
new article about the implosion of the slop bubble
Links 01/08/2026: New York Times Trying to Inflate the Slop Pyramid Scheme (at Cost to Its Own Reputation) and "Iran Appears to Be Blasting Amazon Data Centers Off the Map"
Links for the day
Positive Political Momentum
Daniel Pocock is taken seriously by many people who contact us privately
Google "AI" is Plagiarism, the Case of Richard Stallman (RMS)
Why would anyone choose LLM slop over the originals, curated and fact-checked by domain experts?
Explaining That Software Patents Are Neither Legal Nor Desirable
Many of our readers work in the legal sector
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 31, 2026
IRC logs for Friday, July 31, 2026
Gemini Links 01/08/2026: Retirement, Bike Trips, Quake Stuff, Usenet Reborn
Links for the day
Links 31/07/2026: Microsoft Now Says Slop is Bad (LinkedIn Cracks Down on It), LinkedIn Narrows Down Size (No Expansion)
Links for the day
European Patent Office (EPO) Series: From Alicante to Munich: Another Smooth Ride
Campinos is intent on transforming what was originally envisaged as a temporary public office into his own permanent personal feather-bed
Daniel Pocock and the Important Observation About Threats of Cult-Like Behaviours (No Rationality, No Reason, Just "Mob Rule")
It's a threat to Europe's sovereignty
The "PIP Parade" of IBM's Lousy Management, Which Said "Blockchain" Was the Future
In a healthy company such a CEO would be punished for utterly wrong visions and predictions. Not at IBM...
SLAPP Censorship - Part 135 Out of 200: Limited Liability Partnership (LLP) That Does Not Disclose Financial Activities Before August
It certainly looks like they keep losing the remaining women that still exist in the firm
Links 31/07/2026: "Climate Cover-Up Continues" and Pesticides "Cook the Planet"
Links for the day
Datacentre 'Boom' Sceptics Aren't Luddites, They Recognise a Threat to Human Survival (Not Limited to Climate Change)
Archaeologists very well know that no species will survive forever
Microsoft's Claims Are Based on a Big Lie
the bubble is coming to its hard limits
Don't Lose Sight of the Impact of "End of 10" (Vista 10)
GNU/Linux has taken off fast
Microsoft's Debt Continues to Steadily Increase, Not Counting Hundreds of Billions in Secret/Hidden Debt
The mass layoffs will carry on, maybe labelled LITE
IBM is Circling Down the Drain, the 'Growth' Comes From Beancounting Tricks and Salary Cuts
IBM was down 2.17% yesterday
Microsoft's "Headcount" Distracts From How Big a Cull It Had This Month
It also speaks of numbers "[a]s of June 30" though the "buyouts" were effective July 1 and since then well over 10,000 workers have vanished
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 30, 2026
IRC logs for Thursday, July 30, 2026
Gemini Links 31/07/2026: Music, Journaling, and Longing
Links for the day