#securedrop — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securedrop, aggregated by home.social.
-
TODAY! Lockdown Systems is at @hopeconf 🌐🐢
Come watch our collective member @redshiftzero 's talk with Harlo Holmes from @freedomofpress about the psychological toll of whistleblowing and the empathetic dimensions of the journalist-source relationship.
From Source to Story: Cryptography and Psychosocial Care Protects Public Interest Journalism
When: Friday, August 14th at 1pm
Where: New York City (USA), New Yorker Hotel, Grand Ballroomhttps://schedule.hope.net/hope26/talk/38QUVU/
#HOPE26 #HOPEconf #LockdownSystems #FPF #Journalism #SecureDrop #DangerZone
-
THIS FRIDAY! Lockdown Systems will be at HOPE 26! 🌐🐢
If you're at the Hackers On Planet Earth conference this week, come watch our collective member @redshiftzero 's talk with Harlo Holmes from @freedomofpress about the psychological toll of whistleblowing and the empathetic dimensions of the journalist-source relationship.
From Source to Story: Cryptography and Psychosocial Care Protects Public Interest Journalism
When: Friday, August 14th at 1pm
Where: New York City (USA), New Yorker Hotel, Grand Ballroomhttps://schedule.hope.net/hope26/talk/38QUVU/
#HOPE26 #LockdownSystems #FPF #Journalism #SecureDrop #DangerZone
-
TODAY! Lockdown Systems is at DEF CON! ☠️🐢
Come watch our collective member @redshiftzero 's talk with Trevor Timm of @freedomofpress about @securedrop and the technical challenges in running an anonymous whistleblower platform!
Lessons from a decade of building whistleblower tech
When: Friday, August 7th at 2:00pm
Where: LVCC - L1 - Exhibit Hall West 3 - 906 (Main Track 3)https://defcon.org/html/defcon-34/dc-34-speakers.html#content_66593
#DEFCON #DEFCON34 #DEFCON2026 #LockdownSystems #Security #SecureDrop #FPF
-
Come watch our collective member @redshiftzero 's talk with Trevor Timm of the Freedom of the Press Foundation about SecureDrop and the technical challenges in running an anonymous whistleblower platform!
Lessons from a decade of building whistleblower tech
When: Friday, August 7th at 2:00pm
Where: LVCC - L1 - Exhibit Hall West 3 - 906 (Main Track 3)https://defcon.org/html/defcon-34/dc-34-speakers.html#content_66593
#DEFCON #DEFCON34 #DEFCON2026 #LockdownSystems #Security #SecureDrop #FPF
2/4
-
RE: https://wikis.world/@legoktm/116557912530796630
🚨 we have a second job posting up at Freedom of the Press Foundation 🚨
We're looking for a security researcher to support the #SecureDrop team (up to 30hr/wk)
🔒 fully remote
🔒 work on security-focused project where it's not merely an afterthought
🔒 real security problems that affect real whistleblowers and journalistsThis is a contractor position; you do not need to be US-based (unlike the other one). Happy to answer any questions!
:boost_ok:
https://freedomofthepress.na.teamtailor.com/jobs/611576-rfp-security-researcher
-
🚨 the @securedrop team at Freedom of Press Foundation is hiring 🚨
We're looking for a Cryptography Engineer to help us build out the new end-to-end encrypted version of #SecureDrop
✔️ fully remote (must be US based)
✔️ all FOSS
✔️ help secure whistleblowers and investigative journalists all around the worldMore details in the job posting, happy to answer any questions
https://freedomofthepress.na.teamtailor.com/jobs/610227-cryptography-engineer
:boost_ok:
#GetFediHired #Rust #FormalMethods #Encryption #Cryptography #Whistleblowing #OpenSource
-
SecureDrop Workstation 1.5.2 has been released, as well as SecureDrop Client 0.17.4.
This update contains multiple security fixes, all of which are low or informational priority. We are not aware of any exploitation in the wild for any vulnerability.
https://securedrop.org/news/securedrop-workstation-1_5_2-released/
-
Interesting new project from #Tor #SecureDrop - that’s essentially digitally signed web pages that are client-verified to prevent any server-side covert injection or backdooring. Sounds a bit like SRI (Subresource Integrity) but for the whole page and using digital signature not just server-delegated hash. Obviously, it won’t work for a typical ‘modern’ mash-up website that changes every minute, but sounds perfect for high-integrity and largely static pages such as SecureDrop.
WEBCAT helps protect users from malicious or unexpected changes to the client-side code of a web application. When a user visits a site that has enrolled in WEBCAT, the WEBCAT browser extension verifies the application’s served assets against a signed manifest before any content is executed. If verification fails, WEBCAT blocks the page from loading and shows a warning.
-
SecureDrop 2.14.0 has been released. This release ensures KeePassXC remains installed on Tails. It also lays groundwork for the upcoming SecureDrop App.
-
SecureDrop Client 0.17.2 has been released! This release addresses potential undefined behavior in a dependency.
https://securedrop.org/news/securedrop-client-0_17_2-released/
-
Securedrop — Share and accept documents securely.
SecureDrop is an open source whistleblower submission system news organizations can install to safely and anonymously receive documents and tips from sources. It is used at over 60 news organizations worldwide.
📦 https://securedrop.org
:mastodon: @securedrop#securedrop #whisteleblower #hashline #security #free #report #e2ee #encryption #selfhosting #anonymous #journalism #lawers #employ #opensource #freedom
-
Can hackers truly redeem themselves? Kevin Poulsen (aka Dark Dante) went from cracking systems to being a successful insider tech journalist for Wired, SecurityFocus, and The Daily Beast.
#hackers #darkDante #secureDrop #KIISFM #journalists #tech
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/ -
What does it take to make web applications auditable?
Here's why reproducibility matters, and how WEBCAT—a framework for signing and verifying web applications—approaches the problem in practice.
https://securedrop.org/news/webcat-towards-auditable-web-application-runtimes/
-
Journalists are increasingly relying on insider sources, and protecting those sources is more important than ever.
Here's how SecureDrop is rising to the challenge, safeguarding whistleblowers’ anonymity against ever-evolving threats.
-
Can hackers truly redeem themselves? Kevin Poulsen (aka Dark Dante) went from cracking systems to being a successful insider tech journalist for Wired, SecurityFocus, and The Daily Beast.
#hackers #darkDante #secureDrop #KIISFM #journalists #tech
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/ -
SecureDrop Workstation 1.5.1 has been released! This minor fix addresses a Tails config location change found in version 2.13.0 of the SecureDrop server.
https://securedrop.org/news/securedrop-workstation-1_5_1-released/
-
SecureDrop 2.13.0 is now available. This release primarily provides the securedrop-admin tool as a Debian package within Tails, and prepares for future availability of the securedrop-admin utility on Qubes OS.
-
SecureDrop Client 0.17.1 has been released! This release addresses a low-impact, high-complexity denial-of-service issue:
https://securedrop.org/news/securedrop-client-0_17_1-released/
-
Can hackers truly redeem themselves? Kevin Poulsen (aka Dark Dante) went from cracking systems to being a successful insider tech journalist for Wired, SecurityFocus, and The Daily Beast.
#hackers #darkDante #secureDrop #KIISFM #journalists #tech
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/ -
#TIL that #securedrop (originally called DeadDrop) was coded and architected by Aaron Swartz!
-
SecureDrop is building the next generation of anonymity tools for whistleblowers. SecureDrop software engineer Cory Myers and ETH Zurich researcher Felix Linker gave a talk in Montreal earlier this month about our new, custom messaging protocol:
-
Can hackers truly redeem themselves? Kevin Poulsen (aka Dark Dante) went from cracking systems to being a successful insider tech journalist for Wired, SecurityFocus, and The Daily Beast.
#hackers #darkDante #secureDrop #KIISFM #journalists #tech
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/ -
SecureDrop Workstation 1.5.0 has been released! This version simplifies the installation process by allowing you to install a bootstrap package from the Qubes-Contrib repo, and removes the remaining dependencies on Whonix.
https://securedrop.org/news/securedrop-workstation-1_5_0-released/
-
SecureDrop 2.12.10 has been released. This is a Journalist and Admin Workstation-only release, which adds support for the recent Tails 7 version.
-
SecureDrop Workstation 1.4.0 has been released! This version integrates Tor directly in the sd-proxy VM instead of using Whonix, and fixes an issue that prevented USB devices from automatically attaching.
https://securedrop.org/news/securedrop-workstation-1_4_0-released
-
SecureDrop users, we have heard your requests for an updated support experience! We are now providing support directly via Signal, and will be completing a migration away from Redmine on Nov. 3, 2025
https://securedrop.org/news/changing-how-we-deliver-support/
-
New-ish blog post: Adventures of a YAML engineer
https://blog.legoktm.com/2025/08/28/adventures-of-a-yaml-engineer.html
(I actually wrote this back in May and never published it...)
I mostly wanted to brag about a bit of YAML code I wrote back in March for #SecureDrop's completed migration to Ubuntu Noble that I neglected to mention in the blog post explaining the technical details. Yes, #YAML, is a programming language.
-
#SecureDrop è uno strumento di anonimato per giornalisti e informatori sviluppato da @noybeu
📬 Invia documenti in modo anonimo e comunica con i nostri avvocati. 💬
Per saperne di più, visita 👉 https://noyb.eu/it/securedrop
-
🔐 #SecureDrop is an anonymity tool for journalists and whistleblowers. 📬 Anonymously submit documents and communicate with our lawyers. 💬
To find out more, visit 👉 https://noyb.eu/en/securedrop
-
SecureDrop Workstation 1.3.0 has been released! This version allows users to import credentials during setup, and updates the Fedora base template to version 42, which re-enables SELinux.
https://securedrop.org/news/securedrop-workstation-1_3_0-released