RE: https://wikis.world/@legoktm/116557912530796630

🚨 we have a second job posting up at Freedom of the Press Foundation 🚨

We're looking for a security researcher to support the #SecureDrop team (up to 30hr/wk)

🔒 fully remote
🔒 work on security-focused project where it's not merely an afterthought
🔒 real security problems that affect real whistleblowers and journalists

This is a contractor position; you do not need to be US-based (unlike the other one). Happy to answer any questions!

https://freedomofthepress.na.teamtailor.com/jobs/611576-rfp-security-researcher

#GetFediHired

🚨 the @securedrop team at Freedom of Press Foundation is hiring 🚨

We're looking for a Cryptography Engineer to help us build out the new end-to-end encrypted version of #SecureDrop

✔️ fully remote (must be US based)
✔️ all FOSS
✔️ help secure whistleblowers and investigative journalists all around the world

More details in the job posting, happy to answer any questions

https://freedomofthepress.na.teamtailor.com/jobs/610227-cryptography-engineer

 

#GetFediHired #Rust #FormalMethods #Encryption #Cryptography #Whistleblowing #OpenSource

Cryptography Engineer - Freedom of the Press Foundation (FPF)

The Cryptography Engineer will design and specify extensions to the SecureDrop end-to-end encryption protocol for new security properties or features (e.g., implementing abuse-resistance features).

Freedom of the Press Foundation (FPF)

SecureDrop Workstation 1.5.2 has been released, as well as SecureDrop Client 0.17.4.

This update contains multiple security fixes, all of which are low or informational priority. We are not aware of any exploitation in the wild for any vulnerability.

https://securedrop.org/news/securedrop-workstation-1_5_2-released/

#OpenSource #Whistleblowing #SecureDrop

SecureDrop Workstation 1.5.2 released

This update contains multiple security fixes, all of which are low or informational priority. We are not aware of any exploitation in the wild for any vulnerability.

SecureDrop

Interesting new project from #Tor #SecureDrop - that’s essentially digitally signed web pages that are client-verified to prevent any server-side covert injection or backdooring. Sounds a bit like SRI (Subresource Integrity) but for the whole page and using digital signature not just server-delegated hash. Obviously, it won’t work for a typical ‘modern’ mash-up website that changes every minute, but sounds perfect for high-integrity and largely static pages such as SecureDrop.

WEBCAT helps protect users from malicious or unexpected changes to the client-side code of a web application. When a user visits a site that has enrolled in WEBCAT, the WEBCAT browser extension verifies the application’s served assets against a signed manifest before any content is executed. If verification fails, WEBCAT blocks the page from loading and shows a warning.

https://securedrop.org/news/webcat-alpha/

#infosec

Help us test WEBCAT alpha

Web applications are only as trustworthy as the servers that serve them, and servers can get hacked. So, last year, we introduced WEBCAT (Web-Based Code Assurance and Transparency), a project designed to enable verifiable in-browser code for web applications. We wrote extensively about WEBCAT’s requirements, constraints, and goals.Today, we’re excited to announce the alpha release of WEBCAT. In particular, we invite community participation in a new, decentralized enrollment infrastructure.

SecureDrop

SecureDrop 2.14.0 has been released. This release ensures KeePassXC remains installed on Tails. It also lays groundwork for the upcoming SecureDrop App.

https://securedrop.org/news/securedrop-2_14_0-released/

#OpenSource #Whistleblowing #SecureDrop

SecureDrop 2.14.0 Released

This release ensures KeePassXC remains installed on Tails. It also lays groundwork for the upcoming SecureDrop App.

SecureDrop

SecureDrop Client 0.17.2 has been released! This release addresses potential undefined behavior in a dependency.

https://securedrop.org/news/securedrop-client-0_17_2-released/

#OpenSource #Whistleblowing #SecureDrop

SecureDrop Client 0.17.2 released

This release addresses potential undefined behavior in a dependency

SecureDrop

Securedrop — Share and accept documents securely.

SecureDrop is an open source whistleblower submission system news organizations can install to safely and anonymously receive documents and tips from sources. It is used at over 60 news organizations worldwide.

📦 https://securedrop.org
 @securedrop

#securedrop #whisteleblower #hashline #security #free #report #e2ee #encryption #selfhosting #anonymous #journalism #lawers #employ #opensource #freedom

Share and accept documents securely

SecureDrop is an open-source whistleblower submission system that media organizations can install to securely accept documents from anonymous sources. It was originally coded by the late Aaron Swartz and is now managed by Freedom of the Press Foundation.

SecureDrop

Can hackers truly redeem themselves? Kevin Poulsen (aka Dark Dante) went from cracking systems to being a successful insider tech journalist for Wired, SecurityFocus, and The Daily Beast.

#hackers #darkDante #secureDrop #KIISFM #journalists #tech

https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/
https://negativepid.blog/kevin-poulsen-the-story-of-dark-dante/

Kevin Poulsen, the story of "Dark Dante" - Negative PID

In the 1980s, when payphones, modems, and bulletin board systems (BBSs) connected a secretive underground of digital explorers, one name began to echo across

Negative PID

What does it take to make web applications auditable?

Here's why reproducibility matters, and how WEBCAT—a framework for signing and verifying web applications—approaches the problem in practice.

https://securedrop.org/news/webcat-towards-auditable-web-application-runtimes/

#WebCrypto #OpenSource #Cryptography #SecureDrop #WEBCAT

WEBCAT: Towards auditable web application runtimes

In this blog post, we examine the technical requirements for web applications to be properly auditable, arguing that reproducibility is a necessary condition. Enforcing the constraints needed to achieve this on the web is non-trivial, and we present a technical deep dive into how we approach this problem in WEBCAT.

SecureDrop

Journalists are increasingly relying on insider sources, and protecting those sources is more important than ever.

Here's how SecureDrop is rising to the challenge, safeguarding whistleblowers’ anonymity against ever-evolving threats.

https://securedrop.org/news/looking-back-at-2025/

#OpenSource #Whistleblowing #SecureDrop

Looking back at 2025

Journalists are working harder than ever to protect their sources. SecureDrop has never been more important

SecureDrop