SecureDrop 0.4.4 is released
Today we are announcing the release of SecureDrop 0.4.4. This is a hotfix release to fix a security vulnerability where during initial provisioning of the SecureDrop servers, three packages - tor, ntp, and the Tor keyring are installed without verifying cryptographic signatures. As these packages are fetched over HTTP, an attacker with network access could gain remote code execution on the SecureDrop servers if they are able to man-in-the-middle (MitM) the connection to the apt server. This vulnerability was found during internal code review and there are no signs of active exploitation. Read More
We found a vulnerability in the SecureDrop installation process. Here’s how we’re fixing it.
On the evening of Monday October 16th, just as the SecureDrop team was about to head home for the day, two of our engineers, while doing some testing for a new version of SecureDrop expected to be released the following week, discovered a serious vulnerability in the SecureDrop code. Read More
Ethical Security Research on SecureDrop
The SecureDrop engineering team welcomes the contributions of security researchers. SecureDrop is relied on by sources to talk with journalists at dozens of news organizations, many of whom are taking significant risks to bring information to the public eye. We want to do everything we can to make the whistleblowing process as safe for them as possible. Testing by external security researchers is an important part of that process. In order to minimize risk to SecureDrop users throughout the security research process, in this post we will describe how to ethically perform security research on SecureDrop and what constitutes acceptable and unacceptable behavior. Read More
SecureDrop 0.4.3 Released
Today we are announcing the release of SecureDrop 0.4.3. Read More
SecureDrop 0.4.3: Pre-Release Announcement
The release of the next version of SecureDrop, 0.4.3, is scheduled for September 12th, 2017. We will send out another notification through our blog on securedrop.org, Twitter, and the support portal when the release goes live. Read More
Security Advisory: Do not scan QR codes submitted through SecureDrop with connected devices
We have recently become aware of attacks attempting to exfiltrate data from the SecureDrop airgapped Secure Viewing Station. These attacks come in the form of QR codes that journalists must scan with an internet-connected device such as a phone. The QR code contains a link that sends exfiltrated data from the airgap environment to an attacker. Read More
SecureDrop 0.4.2 Released
Today we are announcing the release of SecureDrop 0.4.2. This is a bugfix release to fix an issue with the AppArmor profile for Apache, which caused the Source and Journalist Interface web applications to fail. The root of the problem was an implicit dependency on upstream AppArmor abstractions from the Tor package, which has been resolved. Read More
SecureDrop 0.4.1 Released
Today we are announcing the release of SecureDrop 0.4.1. This is a bugfix release to fix an issue with one of the scripts that configures the Tails workstation environment. If you encountered a permissions issue when running securedrop-admin tailsconfig, this release will fix that issue. Read More