Live data from Hacker News

How to Leak to the Press

wired.com

1–10 of 104 posts

Re: How to Leak to the Press

#3
This advice is dangerous, because the author fails to mention other precautions the user can and should take, such as:

* Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS

* Change the MAC address of the Wifi used to connect at the internet cafe

* Use Tor, most easily via the Vidalia browser bundle

The author also does not mention that leaking documents can expose the whistleblower via watermarking and user information embedded in the file (most infamously in MS Word documents with versioning).

Edit: update formatting

Re: How to Leak to the Press

#4

This advice is dangerous, because the author fails to mention other precautions the user can and should take, such as: * Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS * Change the MAC address of the Wifi used to connect at the internet cafe * Use Tor, most easily via the Vidalia browser bundle The author also does not mention that leaking documents can expose the whistleblower via wate…

> Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS

Tails is a Linux distribution aimed at privacy and anonymity.

(https://tails.boum.org/)

Re: How to Leak to the Press

#5
post #2

Out of curiosity, why not just send a letter in the post? Pretty hard to trace an anonymous letter. EDIT: Just spotted the update. Question answered.

Take in account they'll look at fingerprints, sweat, DNA, type of paper, ink and type of printer used. Spelling errors, how you wrote something, etc can also be used to identify you. (Every printer leaves it's own watermark). Perhaps best to print and use a old 2nd hand xerox machine to copy everything or fax it from a public faxservice.

Re: How to Leak to the Press

#6

This advice is dangerous, because the author fails to mention other precautions the user can and should take, such as: * Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS * Change the MAC address of the Wifi used to connect at the internet cafe * Use Tor, most easily via the Vidalia browser bundle The author also does not mention that leaking documents can expose the whistleblower via wate…

Buy a long-range WiFi antenna and connect from a distant location instead of going to an Internet cafe where you can be recorded by a lot of cameras in the way.

Re: How to Leak to the Press

#7
Or use a website that has an Anonymous Drop Box. Wikileaks did have one, but its no longer operational. I think a few mainstream media organisations copied the idea and claimed to have anonymous drop boxes?

e.g New Yorker has one, called Strongbox - http://www.newyorker.com/online/blogs/closeread/2013/05/intr... - powered by Tor, designed by Aaron Swartz and others, and open-sourced as DeadDrop http://deaddrop.github.io/

Re: How to Leak to the Press

#8

Or use a website that has an Anonymous Drop Box. Wikileaks did have one, but its no longer operational. I think a few mainstream media organisations copied the idea and claimed to have anonymous drop boxes? e.g New Yorker has one, called Strongbox - http://www.newyorker.com/online/blogs/closeread/2013/05/intr... - powered by Tor, designed by Aaron Swartz and others, and open-sourced as DeadDrop http://deaddrop.github…

Although, first comment on the new yorker post is a good explanation of why StrongBox might not be enough http://fyre.it/i3tCXN.4

Re: How to Leak to the Press

#9

This advice is dangerous, because the author fails to mention other precautions the user can and should take, such as: * Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS * Change the MAC address of the Wifi used to connect at the internet cafe * Use Tor, most easily via the Vidalia browser bundle The author also does not mention that leaking documents can expose the whistleblower via wate…

Fears of watermarking is probably why the leaked documents are what they are. A court order and a training slide deck are the kind of thing that people are authorized to distribute internally.

Re: How to Leak to the Press

#10
Feels a bit overkill and way too identifying - security cameras + internet records + GPS locations will all help track you down, even if they are intermittent.

Buy a stack of envelopes from a supermarket. Buy a stack of stamps. Buy a USB. Acquire all with cash. Transfer all files to the USB via live CD - make sure all meta-data is stripped and files are redacted to avoid fingering you. Handle the envelopes/stamps/USB with care - gloves + hairnets + have a shower before handling (skin cells). Print the addresses (be careful here - printers sometimes put identifying marks - get the most common inkjet that doesn't use dots). Print a message and stick it in the envelope - e.g. "USB contains leaked NSA documents on massive domestic spying. Copy files to your computer then destroy and dump USB then burn the envelope to ensure your own security." Put the stamp on. Drop the letter in the mailbox - try and get a journalist's home address, they'll read it.

Repeat for multi-journalist dump.

Make sure you don't lick the stamps and drop the letters off in physically separated postboxes without security cameras.

You do not want to be in constant communication with journalists/people whilst doing any of this, because the more you talk with them, the more you leak. You want to just strip all identifying data, dump your leak, and run. This tactic has been used for ages to transfer sensitive data, most notably by kidnappers (ransom notes), spies (easy data transfer), whistle blowers (documents) and serial killers (think Ted Kaczynski).

Post reply on HN