+ All Categories
Home > Technology > Globaleaks pp-int-2014

Globaleaks pp-int-2014

Date post: 07-May-2015
Category:
Upload: globaleaks
View: 124 times
Download: 2 times
Share this document with a friend
Description:
This presentation shows why GlobaLeaks exists and why it can be used to bring social change in different environments. GlobaLeaks is currently used by different kind of organizations (anti corruption political group, independent media) as listed in: https://en.wikipedia.org/wiki/GlobaLeaks#GlobaLeaks_uses This presentation has provided a brainstorming session for selection and analysis of future whistleblowing initiatives.
35
GlobaLeaks: anonymous whistleblowing framework Claudio Agosti [email protected] Frankfurt ThinkTwice PP-INT 23/02/2014
Transcript
Page 1: Globaleaks pp-int-2014

GlobaLeaks: anonymous whistleblowing framework

Claudio Agosti [email protected]

ThinkTwice PP-INT 23/02/2014

Page 2: Globaleaks pp-int-2014

Who we are ?• Hermes Center, for transparency and

digital human rightshttp://logioshermes.org

• Advocate in digital human rights• Developers (tor2web software)

Page 3: Globaleaks pp-int-2014
Page 4: Globaleaks pp-int-2014
Page 5: Globaleaks pp-int-2014

https://globaleaks.org

Page 6: Globaleaks pp-int-2014

GlobaLeaksWhat we don't

• After WikiLeaks cablegate:

• No more a central entity would face a danger so extreme

• General-purpose whistleblowing may be unable to understand details and environment

Page 7: Globaleaks pp-int-2014

Who want whistleblowing ?

Page 8: Globaleaks pp-int-2014

Who want whistleblowing ?

Page 9: Globaleaks pp-int-2014

Whistleblowing + Technology = Citizens Power

Page 10: Globaleaks pp-int-2014

Digital Whistleblowing

Page 11: Globaleaks pp-int-2014

How connect them ?• Whistleblowers are someone with

“something to tell”.– a WB may not know that someone is

interested

• Journalist can trasform the right information in an action, in a change.– a WB may not know the right journalist.

“if you know something, you can do something about it”

Page 12: Globaleaks pp-int-2014

Is internet safe for whistleblowers ?

• Online/LAN data control is a business itself• Offices control is commonly present• Whistleblowers

protection law• Freedom of speech

threatened in somecountries

• Reprisal/revenge

Page 13: Globaleaks pp-int-2014

Our project• Free software

– We do not run services• Every topic may have an appropriate

whistleblowing site– We call them contexts

• Roles separation– Whistleblower– Node Administrator– Receivers (Journalists, experts, public

official)

Page 14: Globaleaks pp-int-2014

Paradigm change

Page 15: Globaleaks pp-int-2014

When “online” psychological barrier reduce

Page 16: Globaleaks pp-int-2014

Digital Whistleblowing works only with strong privacy

Page 17: Globaleaks pp-int-2014

But online reporting actions could leave online

Page 18: Globaleaks pp-int-2014

Especially due to massive government surveillance

Page 19: Globaleaks pp-int-2014

Not every node has NSA as primary concern...

• But you can't go back from not being anonymous

• GlobaLeaks is a framework, can adapt shape in different environments

• Note: 10 languages supported, and growing with Transifex!

Page 20: Globaleaks pp-int-2014

EmailWeb BrowsingPhone callsLocation trackingMetadataData retention

Page 21: Globaleaks pp-int-2014

Connection Protection• Guarantee whistleblower anonymity

(of whistleblower connection, almost)– No one can materially have information about the

whistleblower (admin, server, others)• Protection from censorship attempt• Do not disclose service

physical location

Page 22: Globaleaks pp-int-2014

Security• Anonymity or Confidentiality (Tor, Tor2web, configurable)• Encryption

● Files encrypted with PGP● Realtime AES encryption from XHR to the disk

● 3 professional security review (iSec, cure53, leastauthority)● Data Retention

● Submissions are deleted every 2 weeks (configurable), keep server clean

● Whistleblower Awareness● PrivacyBadge, Forced disclaimers, Awareness messages

Page 23: Globaleaks pp-int-2014

Running a GlobaLeaks node...

Page 24: Globaleaks pp-int-2014

The troubles of the “node administrator”

● Social Activism by soliciting whistleblower isn’t just “running a whistleblowing platform & a twitter account”

● Different social goals, methods, threat model for various actors

● Different way to “transform information into action”● Activists often lacks all the skills required to startup

a whistleblowing initiative in an “effective” way

Page 25: Globaleaks pp-int-2014

The rensponsibility of the “node administrator”

● Once a while / at the setup● Infrastructure, Security, Software and

procedures, Legal

● Always● Editorial, ADS/promotion, Fundraising,

Organization

Page 26: Globaleaks pp-int-2014

The rensponsability of the “receivers”

• Trust only data– They are much more checkable than

gossip

• They need to be knowledgable about the subject, but not eventually related– They may be selected by the available

receivers, so have to declare their

Page 27: Globaleaks pp-int-2014
Page 28: Globaleaks pp-int-2014

https://irpi.eu/irpileaks/

http://atlatszo.hu/magyarleaks/ http://www.perun.rs/

Investigative Journalist Digital Dropbox• Investigative Journalist Groups acting on Topics of Public Interests• Journalistic investigation and fact-checking done in-house• Publishing of scoops and articles

Select Category

Send Tip

Fact Checking

Investigative Journalism

MediaMedia PublishingPublishing

Coordinate release across multiple media

Coordinate release across multiple media

Page 29: Globaleaks pp-int-2014

Initiative supported by:http://pistaljka.rs/

Pistaljka: Anti Corruption Activism

Send Tip Issue FOIA SerbianGov

SerbianGov

AuthoritiesAuthorities

MediaMedia

Structured workflow of operation for Serbian wholesale anticorruption initiative

Page 30: Globaleaks pp-int-2014

Recent Achievements:• 30/12/2013: Release of Iceland Banking Collapse raw data• 31/12/2013: Ministry of Finance found to be key stakeholder in saved banks

LJOST: Government Transparency Activism

Send Tip Validation Raw Data PublishingRaw Data Publishing

Crowdsourcing

Factchecking

May lead to Publishi

ng

May lead to Publishi

ng

http://www.ljost.is Iceland Government Transparency Activism

Page 31: Globaleaks pp-int-2014

42 media partners• National Media• Printed Journal• Online Media• TV• Local Media

https://publeaks.nl

PubLeaks Foundation• Consortium by all media partners• Manage the IT infrastructure• Can’t access to Leaks• Provide technical support• Provide “Secure” Laptop

Achieved amazing result in few months• Abuse of power by politicians• Abuse of public funds• Already got attempt of Takedown

https://secure.publeaks.nl

Multi Stakeholders Digital Whistleblowing

Page 32: Globaleaks pp-int-2014

Key Points:• Stimulate cooperation• Stimulate competition• Whistleblower choose reputation based

Select Media

Send Tip

Fact Checking

Fact Checking

Max 3 in parallel

out of 42

Max 3 in parallel

out of 42

IF only 1 media

IF multiple mediareceive the leaks

ExclusivityExclusivity

• Embargo Period• Cooperation Rules

• Embargo Period• Cooperation Rules

Publishingon mediaPlatform (web,

printed, tv)

Publishingon mediaPlatform (web,

printed, tv)

MUST write that source come from publeaks

MUST write that source come from publeaks

Page 33: Globaleaks pp-int-2014

MafiaLeaks: Activism against Organized Crime

Mafia Whistleblowers

MAFIA LEAKSMAFIA LEAKS

AuthoritiesAuthorities

AntiaMafia ONGAntiaMafia ONG

Antimafia JournosAntimafia Journos

Victim of Mafia

“I know something”

http://www.mafialeaks.org

Page 34: Globaleaks pp-int-2014

What’s your social activism schema and ideas?

Page 35: Globaleaks pp-int-2014

Questions ?• Technical Documentation

http://github.com/globaleaks/GlobaLeaks/wiki• Project Plan (outdated! But...)

http://globaleaks.org/ProjectPlan.pdf

• Contacts

http://logioshermes.org

WE – Whistleblowe Everywhere @globaleaks


Recommended