GlobaLeaks: Open-Source Whistleblowing Software
github.com
github.com
These have actual, proven expertise in publishing leaks.
All those new "leak sites" have a trust problem. Although it's likely that most of them have noble intentions, it's equally likely that some of them have been funded by or have been undermined by intelligence services. I wouldn't even trust any open source software that is specifically developed for leaking sensitive information - it's simply too easy to slip an obfuscated security hole in it, and it's not as if the developers could afford regular professional audits.
I suspect some people will downvote me for this, but in highly sensitive matters I'd rather stick to those with a proven track record and evidence of having been persecuted by governments in the past.
To the people who think this is paranoid: It's not. Getting informants or people working on their behalf in crypto projects is the bread & butter of what intelligence agencies do, and it's much easier for them than their usual targets such as foreign military and agencies of state adversaries.
Im not that expert to evaluate them but the reviews seems good and performed by relevant auditors to the community.
Depending on the nature of the leak, perhaps it'd be best to get it into a safe public store that won't be disappeared (e.g. the blockchain) in an encrypted fashion, and then release the key to select parties.
* Scandal and investigation when they do, potentially leading to removal of trust from an associated CA.
* Easier and easier to detect (recently mandatory disclosure of all publicly-trusted certs https://groups.google.com/a/chromium.org/forum/#!topic/ct-po... and you can sign up to get alerts when a certificate is logged for a particular domain name).
* Onion sites also derive cryptographic security from the onion name itself. (I'm working on getting them to be allowed to have DV certs, but even without certs, the onion rendezvous protocol confirms that you've reached a party that controls a key specified in the name itself.)
(Someone else mentioned HPKP, which I've also touted in the past as improving HTTPS security, but it seems HPKP enforcement is going away, so we can't necessarily tout it for this purpose anymore...)
Is it possible to derive a fully secure HTTPS-or-equivalent connection purely from the site's curve25519 key? It seems like that would make DV (and CAs in general) completely redundant. (And if not, is there a explanation of why not?)
https://cabforum.org/pipermail/public/2017-November/012451.h...
See the section "Why do people want certificates for onion names?".
It's correct that both v2 and v3 onions provide end-to-end encryption based on the onion service key. In v3 onions that encryption uses more modern cryptographic primitives than in v2 onions, so the incremental cryptographic benefit would be much larger in v2, where unfortunately for historical reasons the CA industry is reluctant to allow DV certs.
Just put it up as a torrent and share the magnet link.
What would get the most buzz? FreedomChain?
Don't do this; it has all the same problems of just giving the data to select parties directly.
Instead use http://www.gwern.net/Self-decrypting-files and post that to the blockchain. This ensures that anyone can access the data without depending on a trusted third party, but the data will already be irrevocably committed by the time anyone realizes that they want to censor it. Then publish the decryption key for convenience; if that get censored, it's merely mildly annoying.
I don't know whether Chrome provides appropriate extension APIs to allow an extension to do this, but I have a number of colleagues who work on browser extension development whom I could ask.
Just curious, why is that even in the process? If you want to spread information, would you not distribute it to as many people as possible? Why do you have to trust the recipient?
one of the reasons snowden sent his information to journalists was to remove his own biases from the process -- he wanted journalists to help go through it all, determine what was in the public interest, what could be unnecessarily damaging, etc. he wouldn't have had time to do that himself before being caught.
this is in stark contrast to documents found on wikileaks for example that contain social security numbers and other sensitive information completely unrelated to the thing the whistle is being blown on.
Now, you introduced biases from the journalists, which is arguably not better. Journalists could be influenced or controled by states or other parties, and then surely control a part of public opinion. (See the scandal with the Tesla employee who sent data to a reporter from Business Insider, and that reporter is then accused of being systematically biased against Tesla)
> this is in stark contrast to documents found on wikileaks for example that contain social security numbers and other sensitive information completely unrelated to the thing the whistle is being blown on.
That's a better argument to me.
sure, but he significantly reduced that risk by going to a number of journalists working for different organizations in different countries, creating a disincentive for any single publisher to become known as the one that publishes misinformation.
I agree there's a stronger argument against radical transparency than there is in favor of intermediaries, but whistleblowing is realistically never going to be a scenario in which the circumstance or timing is perfect... going to journalists is a good solution, not a magic one.
attacks on tor are, increasingly, attacks on tor browser[1], so I'm not sure I understand your logic there. ricochet has nothing to do with the web, it is not a browser, it just uses a tor process for routing -- tor browser presents a gigantic attack surface that the tor process itself does not.
FWIW, there was an issue or PR on github at some point after the ricochet audit about removing the "experimental" warning, I could be misremembering a different conversation but I think the author just wasn't comfortable telling people that using software for this sort of thing isn't inherently high-risk.
If you're only connecting to a newspaper's secure drop instance on a .onion the risk of running into malicious code seems low but I do agree that leakers need more than just Tor browser, so let's add whonix to that.
Richochet does sound good and I'll try it at some point.
"GlobaLeaks is open-source / free software intended to enable secure and anonymous whistleblowing initiatives..."
JS is not the only surface attack. Also what's the point of targeting anyone who goes into *.onion if it risks burning up your high-price exploit?
Maybe the two softwares serve different use cases?
https://blog.torproject.org/italian-anti-corruption-authorit...
But a few years ago, GlobaLeaks was a lot simpler to install and administer than SecureDrop. Which ment smaller organisations could afford to have an instance.
First, it's ridiculously easy for powerful and dubious players (example here Russian intelligence, not Trump) to twist this well-meaning idea into a horrible parody of itself.
Second, the most vulnerable to manipulation from this technique are democracies (and to a much lesser extent) public corporations, who I would argue, are less of a problem than either autocracies or super-rich individuals. You can't embarrass Putin out of office no matter what gets leaked. Anyone who tries to use it against him will fall out of a window and it will be forgotten. Nor can you easily make the Koch brothers behave, even if an award winning journalist writes a best-selling and award winning book about their shenanigans https://www.amazon.com/Dark-Money-History-Billionaires-Radic...). You'd pretty much have to leak photos of them holding severed heads to get the US government to move against them effectively.
Third. Often, it's politically dangerous for a leader to do the 'right thing'. This technique is just as useful to prevent someone from doing the right thing as it is to prevent them from doing the wrong thing. The difference is how controversial the action is, not whether it is right or wrong.
So, regardless of whether this can be done securely, it's really important to ask yourself how it is likely to be used, by whom, and to what end. People tend to forget that stuff when they have a cool new technology.
Information manipulation is one of the core functions of the CIA, Russian Intelligence, etc. Whistleblowing agencies do not seek to solve CIA information manipulation - only provide an outlet for the publication of contradictory material. In other words: these systems publish information - they are not golden bullets. They do not protect you entirely from the CIA. They aren't intended to. Don't let perfect the enemy of good.
Regarding the third point: it's often very easy for a leader to do the easy thing instead of the right thing.
Agree wholeheartedly that a person needs to be careful about how information is used, by whom, and to what end. I think that more than equally applies to Western intelligence and national security agencies.
Maybe somebody can show me why I'm wrong in stating that democracies are asymmetrically more vulnerable, or that this can be used as readily by bad actors for bad ends as it can by well-intentioned people for good ends.
If we can create some technology, then dismissing it because it can be used to do bad things seems futile. Bad actors will create and use it anyway[1]. If you want to protect some secrets then have a decent security protocols in place, network of trusted people, slightly different data encrypted with different public keys and so on.
I don't think government intelligence needs projects like this to do what they want to do.
I doubt you are trying to argue not to have knifes because they kill people. You work at Google so I think your context may come from the fact that you can easily put things that make a lot of sense after considering them carefully in a bad light when presenting them to public without enough context. But you can do that based on any information, not necessarily private.
In general, in politics, data doesn't seem to matter all that much, unfortunately. We don't have democracy. We have some media-cracy. Majority of voters opinions are heavily influenced by the media. So it's them who actually make decisions (or whoever controls them).
That's why Snowden for example, probably had much more influence on people who already thought about those things, than it had on general public.
1. bioweapons come to mind and those are indeed scary as our current defense is pretty much what I'm considering to be futile
Sure Russia could be behind the DNC leak, but so could a 14 year old who guessed that podesta's password was password (if you believe Julian Assange's claims which haven't been denied by the DNC). It could also be a disgruntled Democratic party staffer who saw what Hillary and Podesta were like behind the scenes and said "fuck these people, the public needs to know what they're really like"
Second, why is it a bad thing that Hillary's email was leaked? It gave an insight into how corrupt the Democratic party is and how corrupt our politicians are and how the democratic process is being rigged. This is a lady who ran a private email server as secretary of state. I'm happy that we were able to find out how the Democratic party rigged the campaign against Sanders and worked a little too closely with the media to ensure a Hillary victory. I'm also glad we found out the real reason for the attacks on Libya (gold reserves not protection of people).
Sure it had a bad result for Trump opponents who didn't want Trump to win. But imagine it was not Trump but Obama running against Hillary and the emails had been leaked. I'm sure you and everyone else would be saying that it was a great moment for democracy instead of regarding it as a terrible mockery.
This is an iterative process. Yes, GlobaLeaks could be used to spread fake leaks, but then it will force all democratic processes to be more transparent, in order to efficiently prove or disprove leak L or new N.
How fast we can prove a piece of fact is the next step, but to get there, you have to give people the tools to spread information (true and fake) as much as possible, imho
Edit : Also, this initiative is European. If you don't trust your own intelligence services, stop whining about it and come live in Europe?
Someone else gave the Pentagon papers as an example of a "good leak" and it was. But I think good leaks tend to be those, like the pentagon papers that are handled by responsible organizations (NY Times and Wash. Post in that case). The people who created this code may be just such people, but there's no reason to think someone who does git-clone on this repo is.
By the way, both the Post and the Times openly solicit leaks.
The method of leaking has little to do with the value of the leak, someone will print almost anything. The Times and the Post regularly print items intentionally leaked for propaganda purposes, the classic example is the buildup to the Iraq War.
Maybe this post is not seen as relevant starting point of the discussion you wanted to have.