SecureDrop Inbox 1.6.0 is now available, and will automatically be installed as part of your regular preflight updates; no further action is needed.
This release adds support for “double-encrypted” submissions, where sources manually encrypt messages and files against a SecureDrop server’s public key prior to submitting them to gain the protection of end-to-end encryption. This brings SecureDrop Inbox further in line with feature parity of the prior Tails-based workflow.
Other features added in this release include:
- Faster message and file downloads by separating the download and decryption queues.
- Refinements to the source menu, including a new option to delete the source within the menu itself.
- A number of improvements to the sync process.
For a full list of changes, please refer to the changelog for this release.
Missing logout
Edu0x01 reported via the SecureDrop Bug Bounty program that the SecureDrop Inbox was missing an explicit logout to invalidate the session token when the journalist closes the application. This issue has been fixed in this release. It has minimal to no security impact, as an attacker would need to be able to steal a valid session token in the first place; nevertheless, we’ve awarded them $500 for the discovery.
Acknowledgments
We’d like to thank Julius Alexandre from Trail of Bits for working with us to identify a number of correctness issues in SecureDrop Inbox as part of their Patch the Planet project.
This release incorporates Freedom of the Press Foundation (FPF) contributions by Giulio B; Martin C; Nathan Dyer, communications manager; Micah Lee; Kunal Mehta, release manager; Cory Francis Myers, deputy release manager; Vicki Niu; Kevin O’Gorman; Francisco Rocha; John Skinner; and Rowen S.
Questions and comments
If you have questions or comments regarding this release, please contact us:
- Via Signal, either in your dedicated SecureDrop Support group, or by contacting the support account listed at securedrop.org/help/.
- Via securedrop@freedom.press (PGP encrypted) for sensitive security issues (please use judiciously), or submit a report via Bugcrowd.
We also encourage you to file nonsensitive issues via our GitHub repository.
Thank you for using SecureDrop!