Hacker News new | ask | show | jobs
by antocv 4727 days ago
We need a guide and tutorial "How to leak safely, precautions and considerations"

Im writing it here because I dont want to register for another web site. I want to write a guide ,not deal with registrations usernames, validations, logins, ugh.

0. Find and use a safe computer to investigate about leaking and whistleblowing, or make your computer safer by using a Live operating system such as Linux - it basically runs your computer from a USB-stick and is safer than using your normal devices.

1. Get familiar with information security by using duckduckgo.com and wikipedia to search and find about following keywords, Tor bundle, I2P, https, PGP.

2. Find or probe a journalist at the guardian if you want to put your face behind the leak/whistleblowing, which ads more trust. Or if you choose leave it to wikileaks to protect your identity but they will manage the contacting with journalists for you, contact any journalists or wikileaks regarding mundane issues to setup trust, so that you are certain you're talking to the right person, and then begin talking using Tor bundle and PGP.

3. Dump your data on wikileaks or mail a USB-stick with it to several journalists, trusted friends. Learn how to make an encrypted file and put it on thepiratebay or any other torrent tracker. Email encrypted to two persons/journalists each half of the pasword to the file. This is your life insurance.

4. Run for it.

2 comments

With regard to the pain of creating yet another account, I really do believe Mozilla Persona is perfect for websites like this one. All they need is your email address, and Persona protects your privacy by only providing this information.

I honestly can't wait to see a future where almost all non-social websites use Persona as their login system. We'll be able to create accounts with only a single click.

I dont understand why they need my email address or "Persona"?

Wouldnt a captcha be good enough, prevent spam and user can choose to provide a nickname/handle. Just click and go.

What are you guarding by requiring a password/credential of the user? Is it really that important who wrote what for this kind of service? If its seriously important, such as to stop spam, use the IP or cookie to identify a user and keep spammers/saboteurs out, it would catch 99.9% of them while letting us normal users click and play around.

Ha!