TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Introducing SafeSource, A New Way To Send Forbes Anonymous Tips And Documents

78 点作者 kevination超过 11 年前

13 条评论

jdmitch超过 11 年前
Its a shame that on the actual SafeSource site they don&#x27;t seem to give much assurance:<p><i>Forbes does not make any representations or warranties as to SafeSource, and your use of SafeSource is on an &quot;as is&quot; basis, at your own risk.</i><p>I suppose it is just to cover them legally, but they could be a bit more reassuring to whistleblowers and informants who might not understand the technology very well or the credentials of those who have vouched for it like Schneier and others.
评论 #6638405 未加载
kuny超过 11 年前
And of course the landing page <a href="https://safesource.forbes.com/" rel="nofollow">https:&#x2F;&#x2F;safesource.forbes.com&#x2F;</a> tracks any potential leakers left, right and center.<p>A quick glance at the source reveals immediately these externally hosted javascripts:<p>- contextual.media.net (unsecured http) - js.moatads.com (unsecured http) - tags.bluekai.com (unsecured http) - akamai.com - cdn.krxd.net - google-analytics.com - sb.scorecardresearch.com - i.forbesimg.com (unsecured http)<p>That&#x27;s right, the &quot;new way to send anonymous tips&quot; immediately tips off at least 7 external parties!
betterunix超过 11 年前
How about instead of each newspaper creating its own system, they all just run a Mixmaster&#x2F;Mixminion&#x2F;Sphinx node, so that there is no single point of failure? The problem of anonymous communication has been well-studied and we know how to make practical systems for it. I should not have to connect to a server run by Forbes in order to communicate anonymously with Forbes.
pasbesoin超过 11 年前
Buy an inexpensive b&#x2F;w laser printer, paying with cash. Maybe wear a baseball cap with a big front bill, for good measure. Or buy second hand. Preference to a model that at least ostensibly does not insert &quot;hidden&quot; identifiers into its printouts. Also buy a sealed ream of printer paper and envelopes that you can nest inside larger envelops, all in packaging. And a glue stick.<p>Buy stamps from an automated machine, paying with cash. Only handle them with gloves on, and be careful of body material adhering to the adhesive.<p>Put on your latex or similar gloves. Avoid touching yourself or breathing on them -- you might decide to wear a face mask and a hair net (before putting on the gloves).<p>Unpack the printer, and the paper. Load it up and print your documents. Print your mailing envelopes.<p>Find the mailing address in a non-obvious fashion. E.g. preferably from a paper copy of the newspaper. Don&#x27;t Google it. Also, address a reporter known to have a strong interest in the topic&#x2F;area you are addressing.<p>Put documents in mailing envelopes. Seal using glue stick. Apply postage carefully to avoid trapping identifiable material in the adhesive. If the adhesive requires activation (e.g. water), use the glue stick for this.<p>Nest the envelope in the larger envelope.<p>Find mailbox or mail drop that is, hopefully, unmonitored. DON&#x27;T take your cell phone with you when finding it nor when subsequently visiting it. Try to make it somewhere away from your normal patterns. Beware of your car being tracked; it may be better to visit it on foot or on a bicycle.<p>Slide the mailing envelope out of its nest in the larger envelope, into the mail receptacle. Try to be as discreet in this as possible.<p>I started writing this thinking that the suggested instructions would be relatively straight-forward. I&#x27;m realizing now just how much they are not so.<p>Now, a final step. Picture this scenario in a world where everyone&#x27;s DNA is profiled -- a proposal that keeps rising in many states and which is already increasingly applied to everone who is ever arrested -- <i>not convicted</i>, just arrested. Or has any &quot;secure&quot; role, which can include working in a hospital or other healthcare setting, working with children, working in law enforcement, working for any paranoid employer in a state not explicitly protective of personal privacy...<p>I am suddenly realizing just how important &quot;online&quot; &quot;black boxes&quot; may be, going forward.<p>P.S. Also, I simply ran out of steam -- motivation for what started as a minor thought exercise. Of course, the above doesn&#x27;t address the security, or lack thereof, of the system holding the documents and from which they are being printed. Nor many other aspects.<p>Already, it is seeming difficult enough.<p>I&#x27;m also thinking more about other, less desirable scenarios that seek to use anonymous postal mail. That was not my purpose. I was solely, hypothetically addressing sending whistle-blowing material to a journalist.<p>I am feeling more than a bit paranoid, right now...
评论 #6639721 未加载
ChikkaChiChi超过 11 年前
If I were a whistleblower, the only way I would feel safe would be through an Airgap using Shoe Leather Protocol.<p>If only the media could be trusted.
dmazin超过 11 年前
SecureDrop is going to end up being so important to journalism and overall freedom I just want to cry endlessly about Swartz&#x27;s fate, which came far before he (or we) knew about his potential effects on the world.
robertfw超过 11 年前
Where is the source code?
评论 #6638268 未加载
codeulike超过 11 年前
<i>An online submissions system of the kind pioneered by WikiLeaks ... </i><p>Nice that they give credit. These systems are going to be increasingly important.
pud超过 11 年前
Here&#x27;s a link for the lazy: <a href="https://safesource.forbes.com/" rel="nofollow">https:&#x2F;&#x2F;safesource.forbes.com&#x2F;</a>
评论 #6638449 未加载
jniles超过 11 年前
This is a great idea (even if not original). Every news agency should budget one of these as part of being in the business.
digitalengineer超过 11 年前
What about using a law firm as your front? Let them print and send the &#x27;sectrets&#x27;?
Sovietaced超过 11 年前
This is amazing.
benhebert超过 11 年前
Does not sound very safe.
评论 #6638596 未加载