Knowledge

SecureDrop

Source 📝

36: 231: 162: 117: 692: 27: 372:
Freedom of the Press Foundation has stated it will have the SecureDrop code and security environment audited by an independent third party before every major version release and then publish the results. The first audit was conducted by security researchers at the
346:
in the Tor network. After a user visits a SecureDrop website, they are given a randomly generated code name. This code name is used to send information to a particular author or editor via uploading.
369:
code. The first and second flash drives are inserted into the second personal computer, and the material becomes available to the journalist. The personal computer is shut down after each use.
787: 361:
and two personal computers to access SecureDrop data. The first personal computer accesses SecureDrop via the Tor network, and the journalist uses the first flash drive to download
1318: 1154: 400:
The Freedom of the Press Foundation now maintains an official directory of SecureDrop instances. This is a partial list of instances at prominent news organizations.
365:
data from the SecureDrop server. The second personal computer does not connect to the Internet, and is wiped during each reboot. The second flash drive contains a
797: 1131: 951: 872: 1393: 1413: 841: 1522: 929:
Biryukov, Alex; Pustogarov, Ivan; Thill, Fabrice; Weinmann, Ralf-Philipp (2013). "Content and popularity analysis of Tor hidden services".
755: 1502: 1497: 1432: 350:
can contact the whistleblower via SecureDrop messaging. Therefore, the whistleblower must take note of their random code name.
275: 54: 1298: 1226: 1002:
Czeskis, Alexei; Mah, David; Sandoval, Omar; Smith, Ian; Koscher, Karl; Appelbaum, Jacob; Kohno, Tadayoshi; Schneier, Bruce.
980: 655: 899: 544: 211: 556: 194: 1477: 846: 297: 79: 343: 1180: 1492: 175: 1338: 1203: 141: 1517: 108: 1352: 1276: 479: 820: 116: 1440: 729: 676: 374: 347: 1512: 631: 335: 1507: 842:"A tribute to James Dolan, co-creator of SecureDrop, who has tragically passed away at age 36" 868: 1414:"ABC launches SecureDrop for whistleblowers to securely and anonymously contact journalists" 1372:"Nice. The @NYTimes launched @SecureDrop today, along with a really useful secure tips page" 1375: 1046: 1003: 286:
After Aaron Swartz's death, the first instance of the platform was launched under the name
247: 199: 161: 8: 1303: 1108: 493: 342:, journalists, and news organizations. SecureDrop sites are therefore only accessible as 322: 255: 230: 35: 304:, and has since assisted with its installation at several news organizations, including 1323: 930: 581: 521: 354: 1271: 1371: 697: 1027: 722: 1041: 568: 206: 182: 1473: 1248: 358: 1464: 1155:"Introducing SafeSource, A New Way To Send Forbes Anonymous Tips And Documents" 877: 825: 620: 415: 378: 339: 292: 150: 1486: 594: 466: 316: 267: 259: 243: 59: 1319:"The Globe adopts encrypted technology in effort to protect whistle-blowers" 907: 792: 760: 507: 310: 263: 64: 1009:. University of Washington Department of Computer Science and Engineering 643: 357:
that are in the possession of the news organization. Journalists use two
788:"Aaron Swartz legacy lives on with New Yorker's Strongbox: How it works" 1132:"Forbes Launches First Updated Version of SecureDrop Called SafeSource" 756:"Guardian launches SecureDrop system for whistleblowers to share files" 705: 454: 389: 366: 305: 251: 74: 46: 1433:"SecureDrop and Alexandre Oliva are 2016 Free Software Awards winners" 1398: 710: 607: 362: 1085: 442: 935: 812: 26: 1379: 1468: 928: 429: 382: 833: 187: 1183:. The International Consortium of Investigative Journalists 679:, Free Software Award, Award for Projects of Social Benefit 395: 1458: 1424: 749: 747: 223: 1080: 1078: 1076: 1074: 1072: 1070: 1068: 1066: 1064: 1062: 1060: 1058: 1033: 744: 1339:"CBC adopts SecureDrop to allow for anonymous leaks" 1055: 687: 1001: 1181:"Initiatives seek to protect anonymity of leakers" 1299:"Q&A about SecureDrop on The Washington Post" 300:took over development of DeadDrop under the name 1484: 40:Screenshot from the SecureDrop Source interface. 1394:"USA TODAY launches secure whistle-blower site" 1227:"ProPublica Launches New Version of SecureDrop" 974: 972: 262:). It was originally designed and developed by 1353:"How SecureDrop helps CPJ protect journalists" 863: 861: 859: 857: 949: 781: 779: 777: 775: 773: 771: 1369: 981:"SecureDrop Undergoes Second Security Audit" 969: 854: 768: 229: 160: 115: 34: 934: 922: 1430: 1004:"DeadDrop/StrongBox Security Assessment" 892: 867: 396:Prominent organizations using SecureDrop 353:The system utilizes private, segregated 1249:"How to Securely Contact The Intercept" 1178: 1039: 943: 818: 785: 1485: 388:SecureDrop suggests sources disabling 334:SecureDrop uses the anonymity network 1229:. The Freedom of the Press Foundation 1201: 1152: 1269: 1224: 1204:"How to Send Us Files More Securely" 1129: 1106: 978: 839: 753: 381:. The second audit was conducted by 338:to facilitate communication between 1523:Software using the GNU AGPL license 1086:"The Official SecureDrop Directory" 656:Australian Broadcasting Corporation 13: 1503:Free software programmed in Python 1370:Timm, Trevor (15 December 2016). 1270:Bowe, Rebecca (18 February 2014). 1179:Chavkin, Sasha (21 October 2013). 14: 1534: 1451: 1134:. Freedom of the Press Foundation 1088:. Freedom of the Press Foundation 983:. Freedom of the Press Foundation 545:Canadian Broadcasting Corporation 212:GNU Affero General Public License 1431:Sullivan, John (25 March 2017). 1357:Committee to Protect Journalists 1225:Timm, Trevor (27 January 2014). 1130:Timm, Trevor (29 October 2013). 979:Timm, Trevor (20 January 2014). 786:Kassner, Michael (20 May 2013). 690: 557:Committee to Protect Journalists 25: 1498:Free content management systems 1478:Freedom of the Press Foundation 1406: 1386: 1363: 1345: 1331: 1311: 1291: 1263: 1241: 1218: 1202:Tigas, Mike (27 January 2014). 1195: 1172: 1146: 1123: 1109:"When sources remain anonymous" 1100: 1021: 995: 847:Freedom of the Press Foundation 840:Timm, Trevor (9 January 2018). 298:Freedom of the Press Foundation 80:Freedom of the Press Foundation 1042:"Tor at the Heart: SecureDrop" 819:Poulsen, Kevin (14 May 2013). 278:also co-created the software. 1: 950:Davidson, Amy (15 May 2013). 716: 1111:. Columbia Journalism Review 821:"Strongbox and Aaron Swartz" 7: 1040:ssteele (6 December 2016). 683: 329: 10: 1539: 1277:San Francisco Bay Guardian 754:Ball, James (5 Jun 2014). 480:San Francisco Bay Guardian 385:, a German security firm. 281: 669: 348:Investigative journalists 218: 205: 193: 181: 171: 140: 136: 107: 103: 85: 73: 45: 33: 24: 1441:Free Software Foundation 677:Free Software Foundation 375:University of Washington 952:"Introducing Strongbox" 873:"Introducing Strongbox" 632:The Wall Street Journal 1272:"Introducing BayLeaks" 392:to protect anonymity. 91:; 10 years ago 16:Free software platform 1493:Sources (journalism) 409:Implementation date 406:Name of organization 296:on 15 May 2013. The 248:secure communication 200:Secure communication 122:; 9 days ago 89:15 October 2013 1420:. 28 November 2019. 1402:. 22 February 2017. 1304:The Washington Post 732:. 18 September 2024 494:The Washington Post 323:The Washington Post 21: 1518:Tor onion services 1359:. 12 January 2016. 1341:. 29 January 2016. 1324:The Globe and Mail 1107:Kirchner, Lauren. 582:The New York Times 522:The Globe and Mail 120:(18 September 2024 47:Original author(s) 19: 1153:Greenberg, Andy. 698:Journalism portal 667: 666: 237: 236: 127:18 September 2024 1530: 1461: 1446: 1445: 1437: 1428: 1422: 1421: 1410: 1404: 1403: 1390: 1384: 1383: 1367: 1361: 1360: 1349: 1343: 1342: 1335: 1329: 1328: 1315: 1309: 1308: 1295: 1289: 1288: 1286: 1284: 1267: 1261: 1260: 1258: 1256: 1245: 1239: 1238: 1236: 1234: 1222: 1216: 1215: 1213: 1211: 1199: 1193: 1192: 1190: 1188: 1176: 1170: 1169: 1167: 1165: 1150: 1144: 1143: 1141: 1139: 1127: 1121: 1120: 1118: 1116: 1104: 1098: 1097: 1095: 1093: 1082: 1053: 1052: 1037: 1031: 1025: 1019: 1018: 1016: 1014: 1008: 999: 993: 992: 990: 988: 976: 967: 966: 964: 962: 947: 941: 940: 938: 926: 920: 919: 917: 915: 910:on 13 April 2017 906:. Archived from 896: 890: 889: 887: 885: 865: 852: 851: 837: 831: 830: 816: 810: 809: 807: 805: 796:. Archived from 783: 766: 765: 751: 742: 741: 739: 737: 730:"Release 2.10.0" 726: 700: 695: 694: 693: 663: 615: 601: 589: 575: 569:Associated Press 563: 551: 539: 529: 515: 501: 487: 473: 461: 449: 437: 423: 403: 402: 359:USB flash drives 233: 228: 225: 183:Operating system 164: 159: 156: 154: 152: 130: 128: 123: 119: 99: 97: 92: 38: 29: 22: 18: 1538: 1537: 1533: 1532: 1531: 1529: 1528: 1527: 1483: 1482: 1457: 1454: 1449: 1436:(Press Release) 1435: 1429: 1425: 1412: 1411: 1407: 1392: 1391: 1387: 1368: 1364: 1351: 1350: 1346: 1337: 1336: 1332: 1327:. 4 March 2015. 1317: 1316: 1312: 1297: 1296: 1292: 1282: 1280: 1268: 1264: 1254: 1252: 1251:. The Intercept 1247: 1246: 1242: 1232: 1230: 1223: 1219: 1209: 1207: 1200: 1196: 1186: 1184: 1177: 1173: 1163: 1161: 1151: 1147: 1137: 1135: 1128: 1124: 1114: 1112: 1105: 1101: 1091: 1089: 1084: 1083: 1056: 1038: 1034: 1026: 1022: 1012: 1010: 1006: 1000: 996: 986: 984: 977: 970: 960: 958: 948: 944: 927: 923: 913: 911: 898: 897: 893: 883: 881: 871:(15 May 2013). 866: 855: 838: 834: 817: 813: 803: 801: 800:on 29 July 2013 784: 769: 752: 745: 735: 733: 728: 727: 723: 719: 696: 691: 689: 686: 672: 661: 613: 599: 587: 573: 561: 549: 537: 527: 513: 499: 485: 471: 459: 447: 435: 421: 398: 332: 284: 270:under the name 222: 167: 155:/freedomofpress 149: 132: 126: 124: 121: 95: 93: 90: 86:Initial release 69: 41: 17: 12: 11: 5: 1536: 1526: 1525: 1520: 1515: 1513:Whistleblowing 1510: 1505: 1500: 1495: 1481: 1480: 1471: 1462: 1459:SecureDrop.org 1453: 1452:External links 1450: 1448: 1447: 1423: 1405: 1385: 1378:) – via 1362: 1344: 1330: 1310: 1307:. 5 June 2014. 1290: 1262: 1240: 1217: 1194: 1171: 1145: 1122: 1099: 1054: 1032: 1020: 994: 968: 956:The New Yorker 942: 921: 904:The New Yorker 891: 878:The New Yorker 853: 832: 826:The New Yorker 811: 767: 743: 720: 718: 715: 714: 713: 708: 702: 701: 685: 682: 681: 680: 671: 668: 665: 664: 659: 651: 650: 647: 639: 638: 635: 627: 626: 623: 621:Bloomberg News 617: 616: 611: 603: 602: 597: 591: 590: 585: 577: 576: 571: 565: 564: 559: 553: 552: 547: 541: 540: 535: 531: 530: 525: 517: 516: 511: 503: 502: 497: 489: 488: 483: 475: 474: 469: 463: 462: 457: 451: 450: 445: 439: 438: 433: 425: 424: 419: 416:The New Yorker 411: 410: 407: 397: 394: 379:Bruce Schneier 344:onion services 340:whistleblowers 331: 328: 293:The New Yorker 283: 280: 260:whistleblowers 235: 234: 220: 216: 215: 209: 203: 202: 197: 191: 190: 185: 179: 178: 173: 169: 168: 166: 165: 146: 144: 138: 137: 134: 133: 113: 111: 109:Stable release 105: 104: 101: 100: 87: 83: 82: 77: 71: 70: 68: 67: 62: 57: 51: 49: 43: 42: 39: 31: 30: 15: 9: 6: 4: 3: 2: 1535: 1524: 1521: 1519: 1516: 1514: 1511: 1509: 1508:2013 software 1506: 1504: 1501: 1499: 1496: 1494: 1491: 1490: 1488: 1479: 1475: 1472: 1470: 1466: 1463: 1460: 1456: 1455: 1443: 1442: 1434: 1427: 1419: 1415: 1409: 1401: 1400: 1395: 1389: 1381: 1377: 1373: 1366: 1358: 1354: 1348: 1340: 1334: 1326: 1325: 1320: 1314: 1306: 1305: 1300: 1294: 1279: 1278: 1273: 1266: 1250: 1244: 1228: 1221: 1205: 1198: 1182: 1175: 1160: 1156: 1149: 1133: 1126: 1110: 1103: 1087: 1081: 1079: 1077: 1075: 1073: 1071: 1069: 1067: 1065: 1063: 1061: 1059: 1050: 1048: 1043: 1036: 1029: 1024: 1005: 998: 982: 975: 973: 957: 953: 946: 937: 932: 925: 909: 905: 901: 895: 880: 879: 874: 870: 869:Davidson, Amy 864: 862: 860: 858: 849: 848: 843: 836: 828: 827: 822: 815: 799: 795: 794: 789: 782: 780: 778: 776: 774: 772: 763: 762: 757: 750: 748: 731: 725: 721: 712: 709: 707: 704: 703: 699: 688: 678: 674: 673: 660: 658: 657: 653: 652: 648: 646: 645: 641: 640: 636: 634: 633: 629: 628: 624: 622: 619: 618: 612: 610: 609: 605: 604: 598: 596: 595:BuzzFeed News 593: 592: 586: 584: 583: 579: 578: 572: 570: 567: 566: 560: 558: 555: 554: 548: 546: 543: 542: 536: 534:Radio-Canada 533: 532: 526: 524: 523: 519: 518: 512: 510: 509: 505: 504: 498: 496: 495: 491: 490: 484: 482: 481: 477: 476: 470: 468: 467:The Intercept 465: 464: 458: 456: 453: 452: 446: 444: 441: 440: 434: 432: 431: 427: 426: 420: 418: 417: 413: 412: 408: 405: 404: 401: 393: 391: 386: 384: 380: 376: 370: 368: 364: 360: 356: 351: 349: 345: 341: 337: 327: 325: 324: 319: 318: 317:The Intercept 313: 312: 307: 303: 299: 295: 294: 289: 279: 277: 273: 269: 268:Kevin Poulsen 265: 261: 257: 253: 249: 246:platform for 245: 244:free software 241: 232: 227: 221: 217: 213: 210: 208: 204: 201: 198: 196: 192: 189: 186: 184: 180: 177: 174: 170: 163: 158: 148: 147: 145: 143: 139: 135: 118: 112: 110: 106: 102: 88: 84: 81: 78: 76: 72: 66: 63: 61: 60:Kevin Poulsen 58: 56: 53: 52: 50: 48: 44: 37: 32: 28: 23: 1439: 1426: 1417: 1408: 1397: 1388: 1365: 1356: 1347: 1333: 1322: 1313: 1302: 1293: 1281:. Retrieved 1275: 1265: 1253:. Retrieved 1243: 1231:. Retrieved 1220: 1208:. Retrieved 1206:. ProPublica 1197: 1185:. Retrieved 1174: 1162:. Retrieved 1158: 1148: 1136:. Retrieved 1125: 1113:. Retrieved 1102: 1090:. Retrieved 1045: 1035: 1028:Source Guide 1023: 1011:. Retrieved 997: 985:. Retrieved 959:. Retrieved 955: 945: 924: 912:. Retrieved 908:the original 903: 894: 882:. Retrieved 876: 845: 835: 824: 814: 802:. Retrieved 798:the original 793:TechRepublic 791: 761:The Guardian 759: 736:26 September 734:. Retrieved 724: 654: 642: 630: 606: 580: 520: 508:The Guardian 506: 492: 478: 428: 414: 399: 387: 371: 352: 333: 321: 315: 311:The Guardian 309: 301: 291: 290:by staff at 287: 285: 271: 264:Aaron Swartz 239: 238: 114:2.10.0  75:Developer(s) 65:Aaron Swartz 1283:20 February 1092:January 29, 961:26 December 914:15 November 900:"Strongbox" 662:28 Nov 2019 644:Aftenposten 614:22 Feb 2017 600:21 Dec 2016 588:15 Dec 2016 574:18 Oct 2016 562:12 May 2016 550:29 Jan 2016 538:20 Jan 2016 486:18 Feb 2014 472:10 Feb 2014 460:27 Jan 2014 448:30 Oct 2013 436:29 Oct 2013 422:15 May 2013 276:James Dolan 252:journalists 214:, version 3 157:/securedrop 55:James Dolan 1487:Categories 1474:SecureDrop 1465:SecureDrop 1255:9 February 1233:28 January 1210:28 January 1187:28 January 1164:28 January 1138:28 January 1115:28 January 1030:SecureDrop 717:References 706:GlobaLeaks 528:4 Mar 2015 514:6 Jun 2014 500:5 Jun 2014 455:ProPublica 390:JavaScript 367:decryption 306:ProPublica 302:SecureDrop 240:SecureDrop 224:securedrop 172:Written in 142:Repository 96:2013-10-15 20:SecureDrop 1399:USA Today 936:1308.6768 711:WikiLeaks 608:USA Today 363:encrypted 288:Strongbox 1418:ABC News 684:See also 649:Unknown 637:Unknown 625:Unknown 330:Security 272:DeadDrop 250:between 1380:Twitter 1013:13 July 987:13 July 355:servers 282:History 256:sources 219:Website 207:License 125: ( 94: ( 1469:GitHub 1159:Forbes 884:20 May 804:20 May 675:2016: 670:Awards 430:Forbes 383:Cure53 320:, and 176:Python 151:github 1376:Tweet 1007:(PDF) 931:arXiv 443:Bivol 242:is a 188:Linux 131:) 1285:2014 1257:2014 1235:2014 1212:2014 1189:2014 1166:2014 1140:2014 1117:2014 1094:2017 1049:Blog 1015:2014 989:2014 963:2013 916:2013 886:2013 806:2013 738:2024 377:and 266:and 254:and 226:.org 195:Type 153:.com 1476:at 1467:on 1047:Tor 336:Tor 1489:: 1438:. 1416:. 1396:. 1355:. 1321:. 1301:. 1274:. 1157:. 1057:^ 1044:. 971:^ 954:. 902:. 875:. 856:^ 844:. 823:. 790:. 770:^ 758:. 746:^ 326:. 314:, 308:, 274:. 1444:. 1382:. 1374:( 1287:. 1259:. 1237:. 1214:. 1191:. 1168:. 1142:. 1119:. 1096:. 1051:. 1017:. 991:. 965:. 939:. 933:: 918:. 888:. 850:. 829:. 808:. 764:. 740:. 258:( 129:) 98:)

Index



Original author(s)
James Dolan
Kevin Poulsen
Aaron Swartz
Developer(s)
Freedom of the Press Foundation
Stable release
Edit this on Wikidata
Repository
github.com/freedomofpress/securedrop
Edit this at Wikidata
Python
Operating system
Linux
Type
Secure communication
License
GNU Affero General Public License
securedrop.org
Edit this at Wikidata
free software
secure communication
journalists
sources
whistleblowers
Aaron Swartz
Kevin Poulsen
James Dolan

Text is available under the Creative Commons Attribution-ShareAlike License. Additional terms may apply.