Aaron Swartz's Final Project: Secure Whistleblower Submission Platform Gets New Support

from the and-a-detailed-security-audit dept

Back in May, we wrote about Aaron Swartz’s final project, done in collaboration with Wired’s Kevin Poulsen, to create a very secure platform to allow whistleblowers to anonymously submit documents to the press. At the time it was called DeadDrop, and the initial media partner was The New Yorker, which set up its version as Strongbox. It’s unclear if anyone’s actually used Strongbox, but obviously since that launch there’s been renewed attention concerning leakers and whistleblowers, and ways to leak information safely.

Today it was announced that the Freedom of the Press Foundation, an offshoot of the EFF which we’ve covered before, has taken over the project, now dubbed SecureDrop. Besides having the support of the Foundation to help with development and deployment of the platform, they’ve also announced that the system has gone through a significant security audit by some of the most respected names in the business, leading to a few additional improvements:

SecureDrop’s code has gone through a detailed security audit by a team of University of Washington researchers, led by Alexei Czeckis. Other authors of the audit include renowned security expert Bruce Schneier and Tor developer Jacob Appelbaum. Freedom of the Press Foundation has made a number of updates to SecureDrop based on these findings and will be making a significant investment in continually improving the system.  

On top of that the Foundation has hired computer security expert James Dolan to maintain the code and to help install the system for media organizations. He helped do the original installation of StrongBox for the New Yorker. Hopefully a bunch of media organizations look into using this system, as it will help provide better ways to protect whistleblowers, especially in an age where they’re under such constant attack from the government.

Filed Under: , , , , ,
Companies: freedom of the press foundation

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Aaron Swartz's Final Project: Secure Whistleblower Submission Platform Gets New Support”

Subscribe: RSS Leave a comment
Anonymous Coward says:

let’s face it, every government etc relies on and encourages whistleblowers until they release something about them, then it’s a totally different matter! if being embarrassed is too much attention for those concerned, they should have thicker skins. if doing something illegal is exposed, those concerned need prosecuting and not be able to hide behind their positions. governments, however, are in the public eye more than any other and need to be squeaky clean. if they are not, they deserve the wrath of the public. what they should not do is persecute and prosecute those that expose the wrong doing. that is destroying the public trust and replacing democracy with Fascism or something similar!

horse with no name says:

whistleblowing or data dump?

I think that the real risk these days is that there is little difference between whistleblowers and data dumpers. A true whistleblower would spot a more specific instance of something, and perhaps leak data related to that particular event or situation.

The Manning situation is a perfect example of a data dump. He dumped tons of data that had nothing to do with whistleblowing any particular situation, rather it was done to put as much stuff out there so many someone else might find something that was perhaps unseemly. That isn’t whistleblowing at all.

I am sure that almost any business or company could be a victim of this sort of thing. If you look at the lunch or travel expenses for every person every time, you are very likely to find someone who fudged a few dollars along the way, reported an extra meal, or something similar. A datadump from almost any company could turn up something, without any particular whistleblowing.

Tools that encourage mindless and vengeful data dumping does not really help us in the long run. It only encourages governments, companies, and individuals to hide and restrict stuff more, and to find better ways to disguise their misdeeds. That isn’t going to benefit anyone.

John Fenderson (profile) says:

Re: whistleblowing or data dump?

If you look at the lunch or travel expenses for every person every time, you are very likely to find someone who fudged a few dollars along the way

True, but irrelevant. The wrongdoing that’s been exposed by Manning, Snowden, etc., has hardly been of that sort. And, really, nobody would care at all if the only wrongdoing was trivial fudging of expense reports.

It only encourages governments, companies, and individuals to hide and restrict stuff more

Meh. They’ve been in maximum coverup mode for years. We’re well above the threshold where further encouragement has any effect.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...