"Decentralized Whistleblowing" by Dr. Jennifer Helsby // ECC#2 - Buenos Aires 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Freedom of the Press Foundation CTO Dr. Jennifer Helsby talks about their decentralization whistleblowing system. Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/
Transcript
[applause] Hey everyone. So, I'm Jen. I go by Red Shift Zero on the internet and I work at Freedom of the Press Foundation. We are a US-based nonprofit organization and we work with news organizations, whistleblowers, and journalists. And one of the things that we do is build privacy technology.
So today I want to talk about technology enabled whistleblowing. But first I want to start with a story. So back in 2012, Glenn Greenwald was a well-known journalist who worked on national security and civil liberties. And he received a cryptic email from an unnamed person who wanted Glenn to set up PGP so that he could send him something. Glenn admitted he didn't know what PGP was, didn't know how to install it, and so he ignored this person.
However, the emailer was persistent. He then sent Glenn a homemade video walking him through how to set up PGP. But after a month of no response from Glenn, the source gave up, or at least gave up that route. He knew that Glenn Greenwald had recently co-founded a small nonprofit with filmmaker Laura Pitus, and this nonprofit's website listed the PGP keys of Laura and others. And so this source was able to connect with Laura via PGP and she was one of the few journalists at that time that was using privacy tools.
She was then able to contact Glenn and the resulting collaboration would lead to some of the most impactful journalism of the 21st century. This is the first of many stories that they published uh demonstrating that the US National Security Agency was spying on people all over the world and virtually every American in secret against the law and the constitution. That source of course was Edward Snowden and the website he used to first get in contact with the journalists was ours at Freedom of the Press Foundation. So this story shows how hard it can be to get in contact with journalists in a secure way. And this story is also unusual because Snowden is an incredibly technically sophisticated person.
At the time he was at NSA, he understood the capabilities in terms of surveillance of the government and he could create an anonymous email account and set up PGP. Ever since this moment at Freedom of the Press Foundation, we've been working with news organizations all over the world to deploy systems that sources not as technically sophisticated as Snowden can use to get documents to journalists safely and securely. It should go without saying that investigative journalism could not exist without brave whistleblowers who put their livelihoods or even their lives on the line to get stories to the public. From the Pentagon Papers to Watergate to the Snowden revelations and countless stories in between, whistleblowers need a way to get information to journalists when in many cases it will be illegal for them to talk. And it used to be that there was a powerful tool that journalists had to protect their sources.
And that was when the government came uh knocking demanding to know who they talked to, reporters could refuse to comply. So there are many cases in the 20th century where reporters got a subpoena, defied them, and even went to jail in order to protect the identity of their sources. Given their importance to society and democracy, many states passed laws protecting the rights of journalists not to testify. But something changed around the turn of the century, and that is what we all know well here, which is the explosion of internet communications. the fact that almost all communications are intermediated by a third-party service, Facebook, Google and so on, or a telecommunications provider.
So, governments now know that it's a lot easier to go to a tech company or a telecom company to vacuum up all of the data that they need on journalists. And worse, they can do all of this in secret such that the journalist doesn't find out until it's way too late to challenge in court. So in the United States, starting at the end of the Bush administration and the beginning of the Obama administration, the US Justice Department seized on this ability and brought more charges against sources of journalists than all other administrations combined. In almost all these cases, they go to tech companies in secret and find out who journalists are talking to, how often, and when. This was most starkly illustrated in the case of Pulitzer Prizewinning journalist James Ryzen.
Then at the New York Times, he fought a subpoena for years. Uh he had a subpoena to testify against one of his sources. The Obama administration eventually dropped it, not because they relented, but because they acquired his email, phone, financial, and travel records, which was more than enough to convict that source who went to prison. A national security official later said that the Ryzen subpoena would be the last one we'd see in the national security context. quote, "We don't need to ask who you're talking to.
We know." So clearly, there was a great urgency for journalists to figure out how technology can be used to protect them rather than against them. Around this same time, Wikileaks uh was making headline news, making waves with their anonymous uh submission system. And the last project that the internet pioneer Aaron Schwarz worked on before passing away in 2013 was an anonymous Wikileak style submission system. So after his death, we took over that project, renaming it Secure Drop.
So it's now our biggest and longest running project and it's used by some of the biggest news organization in the world to receive tips and documents from whistleblowers in an increasingly dangerous environment for journalism. It's led to countless front page stories, many we can't discuss or don't know about, but just as one example of one we do know. In the leadup to the 2016 election, the Washington Post published an explosive scoop with a video, the Access Hollywood video, showing then presidential candidate Donald Trump seemingly admitting to sexual assault on camera. It was the Washington Post's most read story in history at that time. The author of the piece, David Farenhole, tweeted the next day about secured drop, calling it secure dropbox, saying, "It works."
I know. Now, news organizations are understandably tight- lipped about where they get their specific stories from, but here's the investigation's editor of the Guardian saying that Secured Up has become an integral part of the way we work on a daily and sometimes hourly basis. So, in many ways, this has been a big success. It's certainly the most impactful thing that our organization has done in the past decade. But this type of technology involves many complicated tradeoffs given the unique set of threats that whistleblowers face.
So I want to talk a little bit about some of the unique technical challenges that exist and perhaps this group can come up with creative solutions. So the first problem that secured tries to solve is we just discuss the issues with having third parties. So we get rid of third parties holding your data by building the software. So the security up developers write the software and then news organizations install it on prem on premises. So there's no cloud providers.
That means that the power is back in the hands of the journalists and the news organization. We can't prevent the government from serving subpoenas to someone. But now they have to go to the news organization who can challenge it in court or refuse to comply. Another big threat that journalists face is malware. So, as we've seen recently with Pegasus and other forms of spyware, journalists are often the target.
So, as a person who's worked on privacy tech for a long time, journalists are a interesting group to work with because they usually don't need to be convinced of the importance of security and privacy tools. They know. And this malware threat is particularly relevant for submission systems, public submission systems, because regular security advice says, "Be very wary of opening attachments from strangers, but anyone who's running a public submission system is saying, "Please, strangers, send us attachments and we'll open them immediately." So, there has to be a way of handling this technically. And for the first several years of this system, we solved for malware by having journalists use an airgapped computer, a computer that's never been connected to the internet.
So they would download encrypted files on an online machine, take them over to an air gap computer via USB or CDs in some cases, manually decrypt that file, and then walk back over to the online machine to send a reply. So as you can imagine, this is a very cumbersome process. If you've ever used an air gap, you understand uh some news organizations would hire a full-time person who would only do this all day, shuffle messages back and forth to their sources. So, what we do today is use virtualization. So, hopefully there are some cubes fans out there.
So, taking a step back, the key property that we want from an air gap is isolation. So we want the environment that's opening potentially malicious documents to be isolated from the network or any other secrets on the machine and we get that with an air gap across separate physical machines but we can get that across multiple virtual machines. So cubes for those that don't know is effectively a desktop distribution of the Zen hypervisor. This is a picture from their documentation describing how cubes might work for an example user. So what we did is take cubes and take all that complexity and put it behind the scenes.
So this is a screenshot from the interface that journalists use in cubes. So from the journalist's perspective, it's just a regular chat application and journalists can check secure drop 90% plus faster using this method than an air gap. So this is one of the rare cases where usability and security are aligned. the journalist doesn't need to worry about doing the right thing because the right thing is the default behavior of the system. So in this case they just click on a document and it will open in a non-wetorked VM that is destroyed once it's closed.
So in the case that uh there is a uh exploit of some type then it's going to be sandbox and not affect any other VMs on the machine. So that's another threat that needs to be handled. There's also anonymous sources need to be anonymous. So how do we do that? So in this context, we can't have sources download any type of specialurpose application.
So we can't create a secure drop app or a leak to the press app because how would they get that in a way that doesn't identify them. We need them to use tooling on the source side at least that is as general purpose as possible such that they have plausible deniability. So we use tour and tour browser because it is widely used by journalists, human rights defenders and even government employees. So the way that it works is we run a web application for sources as a tour on service. Not because we're hiding the location of the servers necessarily, but we still want to use tornian services to enforce that potential sources must connect through tour.
They can't accidentally connect directly and deonymize themselves. Another challenge is we just said we're using a web browser on the source side. So how can we do endto-end encryption? So unlike native applications that are protected by you know a signature that comes with the application when you download it from the uh app store, web applications lack these strong integrity checks. So if the hosting server is compromised, the browser is going to blindly execute whatever code it's served.
And that leads to a unique threat that's especially relevant for anonymous services. And those are watering hole attacks. So attacks where an adversary compromises the server and uses the server to attack all of the visitors. So in the adversary would eject JavaScript into pages served from the server to exploit the users's browser and deanonymize them. And this is not a theoretical attack.
We've seen this in the wild many times and it's been done by the US government multiple times. So here's one early example from back in 2013. Freedom Hosting was a provider of turnkey tour onion services. Uh the FBI compromised them and did a watering hole attack in which visitors of the onion service were served an exploit that deanonymized the visitors. So obviously some of the content on these services was I'm sure terrible.
But these attacks are important to keep in mind because these same methods, especially in an environment where governments are increasingly hostile to journalism, these methods can be used against news organizations to attempt to deanonymize sources. So for whistleblowing, this lack of integrity mechanism means that a compromised server could serve whatever it wants. It could silently remove end to end encryption code. It could tell a client to send its keys to the server. Or it could serve an exploit.
So we need to consider this in the threat model. So what can we do? So one of our recent projects to try to tackle this is called webcat web-based code assurance and transparency. Um created by one of our security researchers Julio as part of his master's work. You can read the paper on the archive here.
The basic idea is a developer who creates a web application also creates a manifest which is just a description of the resources on the site. So JavaScript, web assembly. The manifest then gets signed by the developer such that we can have the browser check the signature is valid prior to page load and check that the assets served from the site match what's specified in the manifest else the page is not loaded to protect the user. So what the user sees is this. So this is a demo of Jity meet with a browser extension doing the uh validation.
So if the server is hacked and a script is modified the content won't uh verify and the page load is aborted. So the cool thing about this is it's a generalpurpose tool. It's something of interest really to any security focused project. So any project that's doing end to-end encryption in the browser, uh password managers that are in browser only, voting in the browser. Um you might also think about attacks where cryptocurrency frontends were compromised.
Code integrity guarantees could prevent these types of attacks. So eventually it would be great for this type of integrity guarantee to be built in on the browser layer. And there is an ongoing cross browser effort uh by Mozilla, Cloudflare and others that you can read more about on the Cloudflare blog which also talks a bit about how webcat fits in. But until we have a deeper browser integration, we're going to work on Webcat so that we can protect anonymous sources since for our use case the only browser we care about is to tour browser. So just a note on the future of whistleblowing tech.
So we hope that the future of whistleblowing technology is that it's not needed. Not because we'll live in some sort of utopian society, but if this community is successful, then special purpose tools like secure drop should be obsolete. So what we would need is an anonymous private communications tool that resists traffic analysis so that governments can't reconstruct who is talking to who. It would also need to be ubiquitous, used by hundreds of millions around the world. and it would need to handle large files which is a current pain point for a lot of the end to end encrypted chat apps and the endpoints would need to provide strong protections against malware.
Hopefully one day that exists until then we will keep building. So I want to end with a note on our organization Freedom of the Press Foundation. We're a nonprofit. We survive on funding from the public. So uh please go to our website at freedom.
pressdonate press/donate to donate or just learn more about what else we do including training advocacy. And we also have a team of journalists that investigate and report on press freedom incidents, arrest, subpoenas, and so on of journalists. Uh, and we were originally founded in response to government-driven financial censorship of organizations doing journalism. So, the rise of usable decentralized private money directly rates relates to that challenge. I'm happy to talk with any of you and thank you [applause]
Automatic transcript — names and jargon may be misspelled.