Aaron Swartz’s last gift to journalism and online privacy finds a new home
washingtonpost.com
washingtonpost.com
"The conclusion of our analysis is that many of the technical properties of DeadDrop are decent; however, we do not believe that DeadDrop is yet ready for deployment in an ecosystem with nation-state capable adversaries and non-expert users. The lack of software versioning, reliance on VPN, the errors in the installation and deployment documentation, leaking of document metadata, and lack of anonymity best practices all contribute to our reluctance for suggesting that DeadDrop is ready for mass deployment.
Additionally, the usability of the system is sometimes lacking, potentially leading to insecure use. For example, DeadDrop requires a fair amount of technical sophistication on behalf of journalists (such as being able to use the GPG encryption software)6 and sources (such as being able to sanitize the metadata in the submitted documents). We believe that this lack of usability may lead to failures in anonymization. We enumerate the usability pitfalls we found, as well as suggested remediation approaches in our report."
One interesting question is: can we have the same level of security if we use one server instead of three? https://github.com/freedomofpress/securedrop/issues/85
[1] http://homes.cs.washington.edu/~aczeskis/research/pubs/UW-CS...
[1] http://homes.cs.washington.edu/~aczeskis/research/pubs/DeadD... [2] https://pressfreedomfoundation.org/blog/2013/10/how-we-plan-...
I bet this is like that time Jake was in the room when a bunch of Europeans cracked the PKI and he made sure to get his name on the list.
Seeing him listed next to people who actually know what they're doing is a sad testament to his ability to play the media.
The event kicks off at Internet Archive on Friday night, and will be at Noisebridge all weekend after that.
Once a reporter has taken possession/responsibility for your communication, do your future communications still end up in the general bucket, or can they be restricted only to that reporter?
At the moment, the design is such that there is a single "master" public key for each Securedrop installation that all submissions are encrypted with. The journalists are advised to download the encrypted submissions, transfer them to the airgapped Viewing Station, decrypt them with the "master" private key (which is only stored there), and then optionally re-encrypt them to their personal public key if they want to transfer them to their personal workstations.
It would certainly be possible for this process to be automated with some additions to the journalist backend, and in that case once a journalist had taken responsibility for a particular source's communications, further communications could be restricted for their eyes only.
Whatever, you'll know when it hits you...
http://homes.cs.washington.edu/~aczeskis/research/pubs/UW-CS...
I believe the developers answered and made changes, but he blog post detailing the response is down at the moment: