Live data from Hacker News

How to Leak to the Press

wired.com

71–80 of 104 posts

Re: How to Leak to the Press

#71
post #55

FTA: "There’s another option I didn’t originally mention here — leaking over mail. Investigative journalist Julia Angwin of the Wall Street Journal points out that physical mail, dropped in a random post-box with a bogus return address, is perhaps the best way for anonymous one-way communication." DO NOT DO THIS! Every printer leaves a microscopic fingerprint on every printout. The printouts can be traced back to you…

Interesting, I didn't know about printer fingerprints. But I think there are still ways to workaround this. You could print the doc in an internet cafe, or buy a cheap printer and then destroy it, or print it and then take a low quality photocopy. You could even write it by hand or on a typewriter.

A photocopier is a (scanner+printer), so the problem remains.

Your best bet is large flea markets, where you can buy stuff like WiFi dongles, etc. with cash. Then wait a while before you use them.

I can't believe I'm having to write this, either. This is like giving instructions to a Soviet activist in the Cold War days, but ironically it is in my own country. How did we fall so far?

Re: How to Leak to the Press

#72
post #62

Earlier quoted context omitted.

A multi-journalist dump + impressive documents + ambitious journalists + at their home addresses = highly likely publication without getting you sent to Gitmo. Make sure journalists are already on side with you though - aka people that have already argued against whatever cause you wish to damage. However, if the documents are uniquely identifying and of incredible importance then you will want to go public, and you…

Too much work. Watch homeland and drink amazing wine on your 100K+ salary. Tearfully wish the country wasn't descending into the cauldron ...

I think that's both unfair and inaccurate. You don't want someone to publish a story based a single anonymous source and unverified documents. That's how bogus stories about Benghazi emails or George W Bush's military record get made.

Re: How to Leak to the Press

#74
post #71

Earlier quoted context omitted.

Interesting, I didn't know about printer fingerprints. But I think there are still ways to workaround this. You could print the doc in an internet cafe, or buy a cheap printer and then destroy it, or print it and then take a low quality photocopy. You could even write it by hand or on a typewriter.

A photocopier is a (scanner+printer), so the problem remains. Your best bet is large flea markets, where you can buy stuff like WiFi dongles, etc. with cash. Then wait a while before you use them. I can't believe I'm having to write this, either. This is like giving instructions to a Soviet activist in the Cold War days, but ironically it is in my own country. How did we fall so far?

> How did we fall so far?

Fall? You'd have to give the same instructions to a Soviet activist in the Cold War days here.

Re: How to Leak to the Press

#76
post #21

The leaking via gmail has an issue: In many cases when creating a new gmail account, you have to provide a phone number for an automatic text verification code.

yeah, I was going to say this as well. sometimes they ask for a phone number, and sometimes they don't.

I wonder what triggers it, maybe if a lot of different Google Accounts log in from that single IP, it assumes it's some open coffeeshop wifi or similar?

Re: How to Leak to the Press

#77
post #11

The Boston bombing also shows that you should cloak your identity physically. Hat and sunglasses at least. The one who didn't hide his identity is the one who was easily identified.

Hat and sun glasses?

No, get a burka (the muslim body clothing that hides the entire body) -- not only will people want to avoid you, but they wouldn't even be able to write in the description what sex you are (and with a little bonus they might assume it is not a disquise in which case they are truly looking in the wrong direction).

Re: How to Leak to the Press

#79

Earlier quoted context omitted.

Tails is ridiculously well known; if something was bad in it, it would be big news.

If it was found. Which is the point. Debian, which is much better known and in much wider circulation than Tails generated weak SSH keys for two years . Yes, it was indeed very big news . When it was found. After two years . Oh, and tin-foil-hat on: Do we know (actually know-know, not just assume, think, trust) that the weakness wasn't planted there?

TAILS is actually now done by the Tor Project, so I think they have a vested interest in vetting it before it is released.

https://www.torproject.org/projects/projects/

Re: How to Leak to the Press

#80

Earlier quoted context omitted.

There are plenty of old typewriters lying around. Although you would still have to take precautions like getting rid of it afterwards and make sure it does not make use of polymer tape ribbons (in which case you would have to destroy and discard that as well).

Typewriters have signatures too: http://en.wikipedia.org/wiki/Typewriter#Forensic_examination

Sure, but the government wouldn't have a database of those anywhere and getting rid of a typewriter isn't likely to get anybody noticed (I cleaned up in the attick the other day, can you believe what I found?).
Post reply on HN