Working with exported files#
Risks from malware#
SecureDrop does not scan for or remove malware in files you receive. There are important steps you can take to protect yourself:
Keep your SecureDrop Workstation up-to-date.
Print documents from the SecureDrop Workstation instead of exporting them digitally, whenever possible.
Printing documents prevents the proliferation of malware to your everyday workstation, and eliminates most categories of embedded metadata. Note that printing a document may still preserve watermarks, printer codes, steganographically encoded data, or other information not visible to the naked eye.
Consult with your Administrator or your digital security staff before copying files digitally.
If you must copy a file in digital form (because of its format, the volume of information, or for other reasons), we recommend taking the time to consult with technical experts within the organization.
Tip
Converting files to simpler formats (e.g., PDF to PNG) can help reduce the risk of malware. Tails provides both graphical and command-line utilities that can be used for this purpose.
Never scan QR codes embedded in documents using a network-connected device.
QR codes can contain malicious links that your device will automatically visit. This can alert third-parties to your actions, reveal the identities of your Sources, and breach the isolation benefits of using Qubes.
In general, be careful when opening any links provided to you by a Source. If you are unsure if a link is safe to click, you should consult internally, or contact Freedom of the Press Foundation for assistance.
Don’t photograph your computer screen using your smartphone, and be careful with all digital photography.
Many smartphones are configured to back up photographs to cloud services, immediately or intermittently; newer digital cameras have similar functionality. Not all backup settings may be visible to you.
Any digital photograph will include certain metadata by default, which may reveal sensitive information about your SecureDrop usage patterns (potentially including GPS coordinates) to anyone who gains access to the file.
Fully mitigating the risks of malware received via SecureDrop is beyond the scope of this documentation. If you have questions, you can contact us. Please do NOT disclose details about the contents of any communication you have had with Sources.
Tip
This is only a very limited introduction. Freedom of the Press Foundation publishes and maintains digital security guides for journalists, many of which relate to these topics, and offers digital security training for news organization staff.