Interesting new project from #Tor #SecureDrop - that’s essentially digitally signed web pages that are client-verified to prevent any server-side covert injection or backdooring. Sounds a bit like SRI (Subresource Integrity) but for the whole page and using digital signature not just server-delegated hash. Obviously, it won’t work for a typical ‘modern’ mash-up website that changes every minute, but sounds perfect for high-integrity and largely static pages such as SecureDrop.

WEBCAT helps protect users from malicious or unexpected changes to the client-side code of a web application. When a user visits a site that has enrolled in WEBCAT, the WEBCAT browser extension verifies the application’s served assets against a signed manifest before any content is executed. If verification fails, WEBCAT blocks the page from loading and shows a warning.

https://securedrop.org/news/webcat-alpha/

#infosec

Help us test WEBCAT alpha

Web applications are only as trustworthy as the servers that serve them, and servers can get hacked. So, last year, we introduced WEBCAT (Web-Based Code Assurance and Transparency), a project designed to enable verifiable in-browser code for web applications. We wrote extensively about WEBCAT’s requirements, constraints, and goals.Today, we’re excited to announce the alpha release of WEBCAT. In particular, we invite community participation in a new, decentralized enrollment infrastructure.

SecureDrop

SecureDrop 2.14.0 has been released. This release ensures KeePassXC remains installed on Tails. It also lays groundwork for the upcoming SecureDrop App.

https://securedrop.org/news/securedrop-2_14_0-released/

#OpenSource #Whistleblowing #SecureDrop

SecureDrop 2.14.0 Released

This release ensures KeePassXC remains installed on Tails. It also lays groundwork for the upcoming SecureDrop App.

SecureDrop

SecureDrop Client 0.17.2 has been released! This release addresses potential undefined behavior in a dependency.

https://securedrop.org/news/securedrop-client-0_17_2-released/

#OpenSource #Whistleblowing #SecureDrop

SecureDrop Client 0.17.2 released

This release addresses potential undefined behavior in a dependency

SecureDrop

Securedrop — Share and accept documents securely.

SecureDrop is an open source whistleblower submission system news organizations can install to safely and anonymously receive documents and tips from sources. It is used at over 60 news organizations worldwide.

📦 https://securedrop.org
 @securedrop

#securedrop #whisteleblower #hashline #security #free #report #e2ee #encryption #selfhosting #anonymous #journalism #lawers #employ #opensource #freedom

Share and accept documents securely

SecureDrop is an open-source whistleblower submission system that media organizations can install to securely accept documents from anonymous sources. It was originally coded by the late Aaron Swartz and is now managed by Freedom of the Press Foundation.

SecureDrop

Can hackers truly redeem themselves? Kevin Poulsen (aka Dark Dante) went from cracking systems to being a successful insider tech journalist for Wired, SecurityFocus, and The Daily Beast.

#hackers #darkDante #secureDrop #KIISFM #journalists #tech

https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/

Kevin Poulsen, the story of “Dark Dante” - PID Perspectives

In the 1980s, when payphones, modems, and BBSs connected digital explorers, one name emerged in hacker channels: Dark Dante. Behind the alias was Kevin Poulsen.

PID Perspectives

What does it take to make web applications auditable?

Here's why reproducibility matters, and how WEBCAT—a framework for signing and verifying web applications—approaches the problem in practice.

https://securedrop.org/news/webcat-towards-auditable-web-application-runtimes/

#WebCrypto #OpenSource #Cryptography #SecureDrop #WEBCAT

WEBCAT: Towards auditable web application runtimes

In this blog post, we examine the technical requirements for web applications to be properly auditable, arguing that reproducibility is a necessary condition. Enforcing the constraints needed to achieve this on the web is non-trivial, and we present a technical deep dive into how we approach this problem in WEBCAT.

SecureDrop

Journalists are increasingly relying on insider sources, and protecting those sources is more important than ever.

Here's how SecureDrop is rising to the challenge, safeguarding whistleblowers’ anonymity against ever-evolving threats.

https://securedrop.org/news/looking-back-at-2025/

#OpenSource #Whistleblowing #SecureDrop

Looking back at 2025

Journalists are working harder than ever to protect their sources. SecureDrop has never been more important

SecureDrop

Can hackers truly redeem themselves? Kevin Poulsen (aka Dark Dante) went from cracking systems to being a successful insider tech journalist for Wired, SecurityFocus, and The Daily Beast.

#hackers #darkDante #secureDrop #KIISFM #journalists #tech

https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/

Kevin Poulsen, the story of “Dark Dante” - PID Perspectives

In the 1980s, when payphones, modems, and BBSs connected digital explorers, one name emerged in hacker channels: Dark Dante. Behind the alias was Kevin Poulsen.

PID Perspectives

SecureDrop Workstation 1.5.1 has been released! This minor fix addresses a Tails config location change found in version 2.13.0 of the SecureDrop server.

https://securedrop.org/news/securedrop-workstation-1_5_1-released/

#securedrop #whistleblowing #opensource #qubes

SecureDrop Workstation 1.5.1 Released

This minor fix allows configuration from Tails USB sticks for those running version 2.13.0 or greater of SecureDrop

SecureDrop

SecureDrop 2.13.0 is now available. This release primarily provides the securedrop-admin tool as a Debian package within Tails, and prepares for future availability of the securedrop-admin utility on Qubes OS.

https://securedrop.org/news/securedrop-2_13_0-released/

#securedrop #whistleblowing #opensource

SecureDrop 2.13.0 Released

This release provides the securedrop-admin tool as a Debian package within Tails, and prepares for future availability of the securedrop-admin utility on Qubes OS

SecureDrop