Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Making leaking safe(er).

After the twitter account of DDOSecrets got shut down (due Blueleaks), this got me thinking: How would you leak / provide data but are not directly attributable. (At least like a retweet - not your tweet, just amplified.).

And how to add some resilience and protection to the distribution, since there were indicators that the torrent and download of leaked data was being attacked.

So far, I have come up with an encryption matryoshka: you distribute leaks without telling whats in and enable gradually a few to look inside until they are public.

All thats missing is a better document describing it and a command line tool to help to walk through the multi level encryption ... so there is 90% still to do ¯\_(ツ)_/¯.



Not really sure what this is trying to solve. If it's some legitimate leak of public interest then the organizations active in this space often have a tip line / encrypted drop where you can put it.

If it's something that's not of interest to many but you want to put out there for some reason then what's stopping you from uploading it to some random one click hoster and posting the link in random places on the internet?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: