Live data from Hacker News

How to Leak to the Press

wired.com

11–20 of 104 posts

Re: How to Leak to the Press

#11
The Boston bombing also shows that you should cloak your identity physically. Hat and sunglasses at least. The one who didn't hide his identity is the one who was easily identified.

Re: How to Leak to the Press

#12
...feeding the information to the phone company which retains this information for weeks, months, even years. Just a warrant-step away.

The warrant comment suddenly sounds old-fashioned.

Re: How to Leak to the Press

#13

Feels a bit overkill and way too identifying - security cameras + internet records + GPS locations will all help track you down, even if they are intermittent. Buy a stack of envelopes from a supermarket. Buy a stack of stamps. Buy a USB. Acquire all with cash. Transfer all files to the USB via live CD - make sure all meta-data is stripped and files are redacted to avoid fingering you. Handle the envelopes/stamps/USB…

Being completely anonymous with no method for followup questions makes it difficult for the journalist to publish your leak. I suggest you be very patient if you go this route as any reputable journalist will have to independently find another source or verify the documents.

Re: How to Leak to the Press

#14
post #13

Feels a bit overkill and way too identifying - security cameras + internet records + GPS locations will all help track you down, even if they are intermittent. Buy a stack of envelopes from a supermarket. Buy a stack of stamps. Buy a USB. Acquire all with cash. Transfer all files to the USB via live CD - make sure all meta-data is stripped and files are redacted to avoid fingering you. Handle the envelopes/stamps/USB…

Being completely anonymous with no method for followup questions makes it difficult for the journalist to publish your leak. I suggest you be very patient if you go this route as any reputable journalist will have to independently find another source or verify the documents.

A multi-journalist dump + impressive documents + ambitious journalists + at their home addresses = highly likely publication without getting you sent to Gitmo. Make sure journalists are already on side with you though - aka people that have already argued against whatever cause you wish to damage.

However, if the documents are uniquely identifying and of incredible importance then you will want to go public, and you will want to go loud; have your face plastered everywhere, documents in every conceivable location, send them to thousands of journalists via email, scream your identity to the roof tops, don't go to ground, go to press conferences, and leave the country if at all possible before you do go loud.

Re: How to Leak to the Press

#15

Or use a website that has an Anonymous Drop Box. Wikileaks did have one, but its no longer operational. I think a few mainstream media organisations copied the idea and claimed to have anonymous drop boxes? e.g New Yorker has one, called Strongbox - http://www.newyorker.com/online/blogs/closeread/2013/05/intr... - powered by Tor, designed by Aaron Swartz and others, and open-sourced as DeadDrop http://deaddrop.github…

Although, first comment on the new yorker post is a good explanation of why StrongBox might not be enough http://fyre.it/i3tCXN.4

Clicking on the comments link does not reveal any comments. I'm getting a "Subscribe now to get more of The New Yorker's signature mix of politics, culture, and the arts. "

Re: How to Leak to the Press

#17

Feels a bit overkill and way too identifying - security cameras + internet records + GPS locations will all help track you down, even if they are intermittent. Buy a stack of envelopes from a supermarket. Buy a stack of stamps. Buy a USB. Acquire all with cash. Transfer all files to the USB via live CD - make sure all meta-data is stripped and files are redacted to avoid fingering you. Handle the envelopes/stamps/USB…

>Print the addresses (be careful here - printers sometimes put identifying marks - get the most common one)

Printer steganography is usually limited to color laser printers and high-end inkjets. Buying a common one unfortunately won't help you. Included in the codes that have been cracked is the serial number of the printer as well as a date and time stamp of the printout.

Source: http://en.wikipedia.org/wiki/Printer_steganography

Re: How to Leak to the Press

#18

This advice is dangerous, because the author fails to mention other precautions the user can and should take, such as: * Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS * Change the MAC address of the Wifi used to connect at the internet cafe * Use Tor, most easily via the Vidalia browser bundle The author also does not mention that leaking documents can expose the whistleblower via wate…

you can get distros for the raspberry pi that hack wifi networks these days.

Re: How to Leak to the Press

#19
post #17

Feels a bit overkill and way too identifying - security cameras + internet records + GPS locations will all help track you down, even if they are intermittent. Buy a stack of envelopes from a supermarket. Buy a stack of stamps. Buy a USB. Acquire all with cash. Transfer all files to the USB via live CD - make sure all meta-data is stripped and files are redacted to avoid fingering you. Handle the envelopes/stamps/USB…

>Print the addresses (be careful here - printers sometimes put identifying marks - get the most common one) Printer steganography is usually limited to color laser printers and high-end inkjets. Buying a common one unfortunately won't help you. Included in the codes that have been cracked is the serial number of the printer as well as a date and time stamp of the printout. Source: http://en.wikipedia.org/wiki/Printer…

Cut the letters out of a common magazine or newspaper then.

Re: How to Leak to the Press

#20

Or use a website that has an Anonymous Drop Box. Wikileaks did have one, but its no longer operational. I think a few mainstream media organisations copied the idea and claimed to have anonymous drop boxes? e.g New Yorker has one, called Strongbox - http://www.newyorker.com/online/blogs/closeread/2013/05/intr... - powered by Tor, designed by Aaron Swartz and others, and open-sourced as DeadDrop http://deaddrop.github…

Although, first comment on the new yorker post is a good explanation of why StrongBox might not be enough http://fyre.it/i3tCXN.4

It sounds like we need to provide time delay for file transfer as a Tor hidden service.
Post reply on HN