Live data from Hacker News

How to Leak to the Press

wired.com

31–40 of 104 posts

Re: How to Leak to the Press

#31
post #28

Earlier quoted context omitted.

Clicking on the comments link does not reveal any comments. I'm getting a "Subscribe now to get more of The New Yorker's signature mix of politics, culture, and the arts. "

I get the same. Might be related to the fact that I use Ghostery to block absolutely everything. I was starting to feel too paranoid about that, but now I think it's totally justified.

Oh, correct! Must be Ghostry as I use it as well.

Re: How to Leak to the Press

#32

"When you are done you must [...] turn off the Wi-Fi before turning off the computer and removing the battery. The dedicated computer should never be used on the network except when..." This is silly on a "behind 7 proxies" level. Just go the library. If you're worried that investigators are going to swoop down CSI style to track you down because of your important secrets, maybe you should speak to a psychiatrist.

Security cameras are quite often placed at the entrance/exit. Having your device connect and making a DHCP request as you walk in seems like a legitimate concern.

Re: How to Leak to the Press

#33
post #26

Earlier quoted context omitted.

Use a letter stencil? One of those plastic stencils.

That should do it too, you can even make it yourself with a piece of cardboard and a sharp knife.

Probably take fingerprints of someone on the envelope too? Randomize it and complicate it so much that the idea of finding you dies the most desperate death.

Ha ha, the situation feels 'arrived' at fictional level already!

Re: How to Leak to the Press

#34

Earlier quoted context omitted.

Although, first comment on the new yorker post is a good explanation of why StrongBox might not be enough http://fyre.it/i3tCXN.4

It sounds like we need to provide time delay for file transfer as a Tor hidden service.

Mixmaster (and also Mixminion) is high latency anonymity network and is therefor nearly impossible to trace. You remember the University of Pittsburgh bomb threats. The FBI is still unable to track down who was sending the emails. A pretty strong endorsement in my mind

Re: How to Leak to the Press

#35
post #27

Earlier quoted context omitted.

Take in account they'll look at fingerprints, sweat, DNA, type of paper, ink and type of printer used. Spelling errors, how you wrote something, etc can also be used to identify you. (Every printer leaves it's own watermark). Perhaps best to print and use a old 2nd hand xerox machine to copy everything or fax it from a public faxservice.

Write in foreign language you do not master well. All your errors are then "childish" and untraceable.

Or run it through Google translate (or equivilent) a few times and manually correct any critical words in the end result.

Re: How to Leak to the Press

#36

"When you are done you must [...] turn off the Wi-Fi before turning off the computer and removing the battery. The dedicated computer should never be used on the network except when..." This is silly on a "behind 7 proxies" level. Just go the library. If you're worried that investigators are going to swoop down CSI style to track you down because of your important secrets, maybe you should speak to a psychiatrist.

The article basically for people who want to leak classified documents or state secrets. Whistleblowers are currently the target of witchhunts so I'm not sure what makes you feel think they should seek the help of a psychiatrist.

Re: How to Leak to the Press

#37
post #25
post #4

Earlier quoted context omitted.

> Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS Tails is a Linux distribution aimed at privacy and anonymity. ( https://tails.boum.org/ )

I know I'm being paranoid, but I feel uneasy using a privacy-aimed distribution for privacy. The whole obvious target thing.

This is where the 'many eyes' things comes into play; if the whole distro is OSS, then you can be pretty sure that it's good.

Re: How to Leak to the Press

#39
post #17

Feels a bit overkill and way too identifying - security cameras + internet records + GPS locations will all help track you down, even if they are intermittent. Buy a stack of envelopes from a supermarket. Buy a stack of stamps. Buy a USB. Acquire all with cash. Transfer all files to the USB via live CD - make sure all meta-data is stripped and files are redacted to avoid fingering you. Handle the envelopes/stamps/USB…

>Print the addresses (be careful here - printers sometimes put identifying marks - get the most common one) Printer steganography is usually limited to color laser printers and high-end inkjets. Buying a common one unfortunately won't help you. Included in the codes that have been cracked is the serial number of the printer as well as a date and time stamp of the printout. Source: http://en.wikipedia.org/wiki/Printer…

Couldn't you just buy a cheap printer with cash, use it, and then dump it as well, perhaps leave it in a charity bin somewhere.

Printers are pretty cheap these days, and it seems that in order for any of the markings to be useful they would have to find the printer in question in your possession/prove it was your printer.

Re: How to Leak to the Press

#40
post #25

Earlier quoted context omitted.

I know I'm being paranoid, but I feel uneasy using a privacy-aimed distribution for privacy. The whole obvious target thing.

This is where the 'many eyes' things comes into play; if the whole distro is OSS, then you can be pretty sure that it's good.

Most people never review source code, and they certainly don't disassemble and review all the binaries. 'Many eyes' is a security fallacy in cases like this.
Post reply on HN