SecureDrop is evolving: We want to hear from you
securedrop.org
securedrop.org
But if you are going to my understanding is physical documents is still the safest option.
OpSec wise it’s unclear why physical delivery would be more secure. From mail carriers having non-public methods of identifying anonymous/fake senders, to printer & content steganography, device tracking, biological forensic identification, etc.
Why to you is physical delivery a more secure option?
There are still plenty of mailboxes. No need to be anywhere near another human.
Leave the phone at home. Walk to the mailbox at night. Drive closer to it but not up to it if need be it.
You aren't going to get much except fingerprints from a document. Wear gloves when handling the document if that is a theat.
Remember your adversary is probably not all powerful and knowing. They are willing to expend some cost to chase you, and you only need to be more expensive to unmask then that amount.
We STILL live in the world where the most common security breach is having no password or a re-used password. Documents are leaky. Metadata kills.
Point is OpSec is HARD — and telling someone “just physically deliver it” is a recipe for failure.
We know your printer! We track you everywhere! We have your fingerprints! We can pull your DNA from a letter! It is beneficial to the powers that be that ordinary citizens believe they are good at their jobs and omniscient.
They are not.
Yes, to a great degree, this matters on your adversary. The truth is that most whistleblowers are not Edward Snowden. They are whistleblowing on their employer, who is probably a private company or small government org. The bar to exceed detection does not require you to be James Bond or to understand quantum cryptography. It requires gloves, a cheap printer, and maybe a trip to the thrift store and the post box.
If your adversary is the NSA/FBI/KGB/Whoever, well, you know, plan accordingly. But that probably isn't your adversary. Your adversary is probably a mediocre IT security company that has trouble getting their techs to change their passwords and struggles to analyze whatever data they do collect from client endpoints.
Don't under-estimate your adversary but also don't over-estimate them either.
We can bucket that risk in most cases. There are schelling points.
People, regular boring unsophisticated people, frequently successfully mail hardcore drugs through the postal system. This is with the postal system having an actual objective to stop them. Overwhelmingly the postal service fails at this, and even when it does interdict the drugs, it almost never identifies the sender. How much more quaint is it to send documents.
The goal of "OpSec" is to achieve the goal. If "OpSec" acts as a forever barrier because it can't successfully predict real life risk, you're doing it wrong.
Since you claim to know so much about what national mail systems know about a piece of mail, what specifically is your understanding of what they know?
These are batched, scanned (OCR applied), with method of entry tagged to the mail piece. Pieces are risk scored using an unknown to us algorithm. Pieces that trigger being suspicious can be x-ray'd, CT scanned or imaged (eg TSA style scanning) and may also be opened by the postmaster.
There's a whole long bit of what happens once a package is found to actually be contraband that I am going to skip because it's long.
Any piece of mail has attached to it the information on it, it's weight, dimensions and entry point into the system.
Your collection point will potentially capture more materials, depending. Mail offices are government offices and behave like it - security footage, ID checks when doing business, cameras typically behind the desk to capture faces. That footage is typically housed locally unless there is a reason to send it. There is a standard retention policy but variances exist per office.
Mail from other points is much, much less secured and may have no additional security. Mailboxes, in the US especially, do not get government operated video monitoring. Private parties such as HOAs or cities may add their own.
And if by "commercial" you mean "for the business market, not the consumer/home market", then that is also wrong. Plenty of consumer grade laser printers, including mine, print yellow tracking dots. If the EFF is correct, essentially all laser printers sold now put some sort of tracking info on the page.
[1] https://www.eff.org/pages/list-printers-which-do-or-do-not-d...
Generally speaking, one should assume if it’s possible to do something and economics make sense, it’s being done.
Printer identification has only been seen in color lasers (and some weird inkjets).
Lasers, especially cheaper ones, naturally DO have laser variances, etc. There isn't enough data in a b&w laser to leave a serial.
But let's say that you mess up and do leave a serial number... that's not useful. How many people register their printers? How many people buy printers from third parties or, gasp, second hand?
The printer serial code is useful only when you have the printer already and want to ask if it produced a given document. "This came from a Xerox printer with serial number xyz" isn't useful information for identifying a leaker from your corporate staff.
If you are worried about it, buy a crappy thrift store printer and donate it somewhere else.
Claim that data is able to be hidden in black & white laser prints is obviously false; for example, printer could intentionally embed information by make small algorithmic changes to the fonts that are unnoticeable to an untrained human eye.
Again, sure, possible this is over kill, but then so is SecureDrop. Anyone that’s worried about OpSec needs to understand their threats and related risks, then decide what to do, not just say do X just because Y said so. If mailing in documents was safer, why is that not presented as an alternative?
Your adversary doesn't need to be logical. You assume they need good evidence that is true - they don't. They can decide they don't like your face and that makes you guilty (and that has been the default for a lot of human history). They can also decide you are just nervous. Or that you seem like the leaking sort. They can jump to whatever conclusion they want, including the "let's hit them with a $2 wrench until they admit guilt".
If they are in your house and sampling your printer, they are also going to pull your electronic storage, physical storage, etc. SecureDrop doesn't help you here either - and a bunch of demag'd harddrives is pretty smoking gun.
> printer could intentionally embed information by make small algorithmic changes to the fonts that are unnoticeable to an untrained human eye.
The printer could have a secret implant, or broadcast a vhf beacon of what it prints, or have left an imprint on a second page of paper or....
But those things are unlikely. That you can theoretically think of some potential gotcha is not "opsec". That isn't risk analysis. That is you playing secret agent. That's fine - but don't confuse it with risk analysis.
> Anyone that’s worried about OpSec needs to understand their threats and related risks
Correct, the REAL actual threats, and the CHANCE of those threats happening.
You can not zero out a risk. Risk does not go to zero. You can only reduce a risk to a mission tolerable degree.
> possible this is over kill
The point is to achieve the goal. "OpSec" helps reduce risk. Let me repeat this.
There will always be risk. You can not remove the risk. The goal is not to remove the risk. The goal is to reduce the risk to a tolerable degree such that the goal can be achieved.
"But I can hallucinate a theoretical attack!" - Great, write a spy thriller. That has no bearing on "Opsec" or even risk analysis. At the very least you have to show the attack CAN happen, your threat actor CAN (theoretically) execute it, and ideally they are willing to (resourcing).
Give people practical advice. Prepare them for reasonable scenarios.
Who cares that "they" know you went to the mailbox? What does that tell them?
Realize you believe degree to which I look at risks is unnecessary, but to me, it’s irresponsible to neglect mentioning how complex good OpSec is — and how frequently minor mistakes, especially over extended duration add up.
physical printouts are watermarked by the printer
physical dvd copies sounds like safest option, but they might also have forensic watermarks by the disk drive firmware
Why would someone use SecureDrop instead of Signal?
Core point is that survey requests prior experience using SecureDrop, then uses Signal, email and/or https-form to communicate. Why? Feel like at very least SecureDrop should themselves be explicitly stating why they opted use alternatives instead of their own service.
Google Voice has always required a phone number for signup, since its legacy design was to forward calls. When creating the account you’re able to allow Google to generate a Google Voice number for the account, disconnect the setup number, and use Google without a phone number.
Why though go to all that trouble when Signal just needs a PIN one-time from a throw away number; at which point Signal allows user to lockout future registrations from that number as long as the Signal account is active per their definition.
Does the foundation claim their application is suitable for such use cases?
They have no choice but to assist the government with whatever info they may have.
https://tech.hindustantimes.com/mobile/news/recent-court-fil...
I agree SecureDrop is complex (in fact I mentioned that in another comment). It's way more complex than sending a file with Signal or other modern privacy apps, but at least all parts are private and secure (as far as we know) so it's up to the user to not make mistakes. With Signal we know that Signal itself may be compelled to provide information about its users and I think that's why they wouldn't recommend their application for such use cases.
For example, here’s one author’s list of related use cases and reasoning:
- https://www.linkedin.com/pulse/20-use-cases-homomorphic-encr...
Please respond to the question — and review HN’s guidelines, specifically:
> When disagreeing, please reply to the argument instead of calling names. Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith. Eschew flamebait. Avoid generic tangents. Omit internet tropes. Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something.
If you’re curious, found link via simple Google search, since I wanted to quickly check if there was an obvious relevant use case I was not aware of and after reviewing it thought it might be of use in you replying:
https://google.com/search?q=homomorphic+encryption+use+cases
Regarding your inquiry; because it allows for the original author to do mutations and calculations on (your) data carried or distributed by untrusted third parties. This way someone could for example provide updates while being at less risk. Various asymmetries between the amount of data dumped and the amount of resulted output could also be helpful in certain niche scenarios.
To me, while I agree such a use case might make sense in a very narrow context, homomorphic encryption currently supports a limited subset of resources normally available on a computer and even doing basic operations on a small amount of data takes a very long time, adds a lot of complexity, custom information formatting, etc.
As such, in my opinion, unless I am something, homomorphic encryption would be a poor fit for a use case similar to SecureDrop’s use case.
https://news.ycombinator.com/item?id=35027654
* To get a direct link to a HN comment, click timestamp for related comment; then click parent if additional context is needed.