Live data from Hacker News

How to Leak to the Press

wired.com

61–70 of 104 posts

Re: How to Leak to the Press

#61
post #17

Earlier quoted context omitted.

>Print the addresses (be careful here - printers sometimes put identifying marks - get the most common one) Printer steganography is usually limited to color laser printers and high-end inkjets. Buying a common one unfortunately won't help you. Included in the codes that have been cracked is the serial number of the printer as well as a date and time stamp of the printout. Source: http://en.wikipedia.org/wiki/Printer…

Cut the letters out of a common magazine or newspaper then.

Cut the common letters out of a newspaper or magazine.

Re: How to Leak to the Press

#62
post #13

Earlier quoted context omitted.

Being completely anonymous with no method for followup questions makes it difficult for the journalist to publish your leak. I suggest you be very patient if you go this route as any reputable journalist will have to independently find another source or verify the documents.

A multi-journalist dump + impressive documents + ambitious journalists + at their home addresses = highly likely publication without getting you sent to Gitmo. Make sure journalists are already on side with you though - aka people that have already argued against whatever cause you wish to damage. However, if the documents are uniquely identifying and of incredible importance then you will want to go public, and you…

Too much work. Watch homeland and drink amazing wine on your 100K+ salary. Tearfully wish the country wasn't descending into the cauldron ...

Re: How to Leak to the Press

#63

Earlier quoted context omitted.

Tails is ridiculously well known; if something was bad in it, it would be big news.

If it was found. Which is the point. Debian, which is much better known and in much wider circulation than Tails generated weak SSH keys for two years . Yes, it was indeed very big news . When it was found. After two years . Oh, and tin-foil-hat on: Do we know (actually know-know, not just assume, think, trust) that the weakness wasn't planted there?

[deleted]

Re: How to Leak to the Press

#64
post #43

What about "simply" using DeadDrop? http://deaddrop.github.io http://www.newyorker.com/online/blogs/closeread/2013/05/intr... Or Retroshare: http://retroshare.sourceforge.net https://retroshareteam.wordpress.com/2012/12/28/cryptography... https://retroshareteam.wordpress.com/2013/01/06/privacy-on-t...

You would still want to use a tablet/laptop as they described to connect to TOR and DeadDrop.

Re: How to Leak to the Press

#65
post #9

This advice is dangerous, because the author fails to mention other precautions the user can and should take, such as: * Use a Linux live CD on the "burner laptop" -- don't trust the preinstalled OS * Change the MAC address of the Wifi used to connect at the internet cafe * Use Tor, most easily via the Vidalia browser bundle The author also does not mention that leaking documents can expose the whistleblower via wate…

Fears of watermarking is probably why the leaked documents are what they are. A court order and a training slide deck are the kind of thing that people are authorized to distribute internally.

Which is why you need a co-leaker. Dangerous yes, but you can at least compare documents between each other. Extract the text, strip the UTF down to ascii and fix the whitespace...

Hell, even have it transcribed by a typist. Full air-gap. This whole leaking business needs to be turned into an SEO optimized translated wiki page.

Re: How to Leak to the Press

#67

Last time I purchased a prepaid cell phone, I had to show government photo ID. The RadioShack clerk entered my license number in a database. So the burner phone may not be the best route.

This is why you go to a package store, or some other non-tech establishment. Probably in a shadier part of town.

Re: How to Leak to the Press

#68
post #28

Earlier quoted context omitted.

I get the same. Might be related to the fact that I use Ghostery to block absolutely everything. I was starting to feel too paranoid about that, but now I think it's totally justified.

Oh, correct! Must be Ghostry as I use it as well.

It is Ghostery. Pause it and the comments will appear.

Re: How to Leak to the Press

#70
post #55

FTA: "There’s another option I didn’t originally mention here — leaking over mail. Investigative journalist Julia Angwin of the Wall Street Journal points out that physical mail, dropped in a random post-box with a bogus return address, is perhaps the best way for anonymous one-way communication." DO NOT DO THIS! Every printer leaves a microscopic fingerprint on every printout. The printouts can be traced back to you…

Interesting, I didn't know about printer fingerprints. But I think there are still ways to workaround this. You could print the doc in an internet cafe, or buy a cheap printer and then destroy it, or print it and then take a low quality photocopy. You could even write it by hand or on a typewriter.

"buy a cheap printer and then destroy it"

Have somebody else buy it with cash only. Surveillance cameras catching you with a printer and then not able to explain where it went will not go well.

I can't believe I actually am saying this. I truly can't believe that we are all having these kinds of conversations about something that should be as trivial as telling the truth. This is the kind of stuff I imagine the Russian mob would do, not employees of the US government who have a conscious. It is truly despicable and makes me a bit nauseated. The worse part is there doesn't seem like a fix and there doesn't seem like there is anywhere else to go to avoid this.

Post reply on HN