buds, this is the wrong article to put under an email gate.
Here's the info from that article (with a lot of heavy editorializing from me):
Don't call or text; you want to leave as minimal a traceable digital footprint as possible and cellphones are extremely traceable. The Trump admin is committed to collecting metadata from journalists who receive leaks and that includes call history and who sent text messages; even if the message gets deleted there is a record of it with the carrier that can be subpoenaed.
If you are going to email, do so from a burner account created for the purpose of leaking/whistleblowing. (my advice: use a service like protonmail that allows you to encrypt messages and doesn't collect any data beyond what is absolutely necessary for an email system to function; email is inherently insecure you have to treat it as insecure, but a burner account at a privacy-focused company like proton that facilitates sending encrypted messages is the best option for email; here's some information about how to use protonmail as privately as possible) When setting up your burner email, do not use your phone number for 2FA or include any accurate biographical information during the account setup. Set up the account while using a traffic anonymizer like Tor. Here's a PDF about what Tor is and how it works and here's the Tor project's manual explaining how to install and configure the browser for privacy. (The article advises to use Tor or a VPN but that raises the question of whether you trust your VPN provider; if you are going to use a VPN use one of the ones recommended by privacyguides; I know fuck all about VPNs but I know I wouldn't trust most VPN providers in this context).
Don't reach out to the person you're leaking to on social media. I feel like this should be obvious, but it may not be - don't reach out through meta or X or tumblr, these are not anonymous platforms and they can and will be compelled to share messages sent to journalists or data sent from your account. Don't follow the people you're leaking to (unless you already happened to be following them), don't interact with their posts. Do not make any kind of visible connection between you and the person you are leaking to.
Be careful about using encrypted messaging platforms. I personally wouldn't trust telegram or whatsapp, and I haven't heard of Session until now, but generally speaking Signal is one of your safest bets for sending messages. Signal collects the smallest amount of user data it can, and while it does require a phone number to sign up, the phone number doesn't have to stay connected to your username. If you don't already have a signal account, create one NOW because one of the things that they do track and can be compelled to disclose is when an account was created. If an account is linked to you and it was created shortly before a leak, that's suspicious. Create an account now and have it handy for when you need it. IF you are using signal, be aware that people can still screencap your messages; don't share personally identifying data via signal chats.
Have good opsec about how you collect the data that you're going to leak. For example, don't email yourself a copy of the data from your work email account, take photos of the data on a non-work phone and then strip the metadata. If you require login access to get the info you're looking to leak, figure out if there's a way that you can make the leak more ambiguous about the access by making sure there's time between your access and the leak, or that the time of your access isn't included in the information that is leaked. Take a lot of time to think about how someone might track a leak back to you and take steps to mitigate that.
Don't save copies of the data that you've leaked; once you've passed the message on to people who can get it out there, destroy any copies that you had.
GlobaLeaks and SecureDrop are tools to securely share leaks with organizations that will publicize the information you're sharing while protecting you to the best of their ability. Do not access those sites through your normal browser when you are preparing to leak data, only access them through Tor.
Be cautious about who you leak to. (Look I love the team at It Could Happen Here but you don't share a leak with a podcaster you share a leak with a group like Distributed Denial of Secrets). Focus on groups that have a history of securely sharing leaked info and on outlets that might have some legal protection from sharing information about you. The Intercept and DDoSecrets are the two that spring to mind immediately for me. (In fact I got the screenshot at the top of this thread because I went searching for this intercept article to paste on to a reply to another post but then this happened so here we are). Both of those links have their tips for leakers, btw.
It isn't stated elsewhere here so I'll add it at the end: if you are using Tor, don't log in to personal accounts that are associated with your real name or your private data. If you create burner accounts, don't use them to communicate with accounts associated with your real name or private data.
Also don't tell people - partners, parents, friends, etc. - that you're going to leak something.
And, I cannot emphasize this enough, do not tell me or any other tumblr user if you have data you are thinking about leaking or a hack you think you've pulled off. Don't talk about doing crime on the internet and definitely don't talk to me about it. Don't send an anonymous ask, don't send a private message. "The hacker or hacker-adjacent person I parasocially know from tumblr" is not a safe recipient for your leak and tumblr is not a secure or anonymous platform EVER.















