Privacy & Security

How to Protect Sources as a Journalist

How to protect sources as a journalist — a practical guide covering the technical, operational, and legal practices that protect confidential sources from identification, covering secure communication channels, research privacy, and document handling.

Back to blogAugust 18, 202611 min read
aeprotect-sources-as-a-journalist-guidesecure-protect-sources-as-a-journalistprivate-protect-sources-as-a-journalistprotect-sources-as-a-journalist-tools

The Stakes of Source Protection

A confidential source is a person who provides information to a journalist on the condition that their identity will not be revealed. The range of people who serve as confidential sources is wide: a government employee who reveals wrongdoing knowing their career depends on confidentiality, a corporate insider who documents fraud, a witness to events that powerful parties want suppressed, a person with information that could end their employment, their safety, or their freedom if revealed.

The commitment to protect a source's identity is not merely an ethical convention — it is the condition that makes sources willing to come forward. A press that cannot protect its sources cannot report on the things that powerful institutions want hidden.

Source protection fails through multiple pathways:

The journalist's communications: If the journalist communicates with the source through channels that are logged or monitored (email, phone calls, standard SMS), those communication records can reveal the source's identity. Metadata — who communicated with whom and when — can identify a source even when the content of the communication is not disclosed.

The journalist's research trail: The digital record of a journalist's research (search queries, visited websites, documents accessed) can, in some cases, indicate who a source is or what materials the source provided.

The source's communications: The source's digital footprint — documents printed, systems accessed, emails sent — is often more dangerous to them than the journalist's footprint. The source operates inside the organization and leaves a trail there.

Legal process: Journalists and their employers can be served with subpoenas seeking source-identifying information: communications, notes, call logs, email headers. Shield laws in some jurisdictions protect journalists from being compelled to reveal sources; in others, the protection is limited or nonexistent.

Physical surveillance: Sources can be identified through physical surveillance of their contact with journalists, through license plate readers, through cell phone location data, and through witness accounts.

This guide focuses primarily on the technical and operational practices the journalist controls. Source-side operational security is equally important but depends on the source's understanding and willingness to implement it.


Secure Communication Channels

The foundation of source protection is communicating through channels that produce minimal or no metadata linking the journalist to the source.

Signal (end-to-end encrypted messaging)

Signal is the standard recommendation for secure journalist-source communication. It provides end-to-end encrypted voice calls and text messages. By default, Signal messages are not stored in the cloud. The content of communications is encrypted; Signal itself cannot read them.

Metadata limitation: Signal requires a phone number for account registration. The phone number creates a linkage between the account and a real-world identity. Sources who register Signal with their primary phone number are linkable to that number.

Mitigations: Sources can register Signal with a number not linked to their identity (a prepaid SIM purchased with cash; a Google Voice number). Journalists who receive regular sensitive communications may have a Signal account registered to a work device with a separate number.

Enable "disappearing messages" in Signal conversations — messages automatically delete after a set time, reducing the retained record on both sides.

SecureDrop

SecureDrop is a purpose-built open-source whistleblower submission system developed by the Freedom of the Press Foundation. It is deployed by major news organizations (The Washington Post, The New York Times, The Intercept, and many others) and is designed specifically for source protection.

How it works: the news organization installs SecureDrop on a server they control (often air-gapped or Tor-isolated). Sources submit documents and communicate with journalists through Tor Browser. Sources are given a random codename — not their name, not their email, not their phone number — that is the only identifier for the communication. The source and journalist can communicate through the system without either knowing the other's identifying information unless the source chooses to reveal it.

SecureDrop is the gold standard for receiving documents from sources who need maximum anonymity. It requires the news organization to deploy and maintain the system.

ProtonMail (end-to-end encrypted email)

ProtonMail provides end-to-end encrypted email between ProtonMail accounts. Email between a ProtonMail account and a standard email account (Gmail, Outlook) is not E2EE — it's sent as standard email on the recipient's side.

For source communication, ProtonMail provides meaningful protection when both the journalist and source use ProtonMail accounts that aren't associated with their primary identities. ProtonMail accounts can be created without a phone number or recovery email, reducing the identity linkage.

Limitation: email metadata (who sent to whom, when) is not encrypted even in ProtonMail communications. The fact that a communication occurred can be revealed even if the content cannot.

Encrypted voice calls

Standard phone calls are unencrypted and produce call log metadata retained by carriers. Signal's voice call function provides end-to-end encrypted audio that doesn't appear in standard call logs. For in-person conversations about sensitive source matters, a private physical location without smartphones present is the most secure option.


Research Privacy

A journalist's research trail — which searches they conducted, which documents they accessed, which databases they queried — can in some cases be used to infer who a source is or what materials a source provided.

Separate research devices and accounts:

Sensitive investigative research should be conducted on a device and with accounts not associated with the journalist's primary identity. An investigation-specific Firefox profile with no personal logins, using DuckDuckGo for search, reduces the research trail.

Tor Browser for sensitive research:

Research on topics where even the fact of research could be sensitive (financial records of specific individuals, location data, personnel records) benefits from Tor Browser. Tor prevents the ISP from seeing which domains are visited; websites see the Tor exit node IP, not the journalist's.

Database query privacy:

Journalistic investigation often involves accessing public records databases, court records systems, and similar resources. These systems log user access. For investigations that are under-the-radar before publication, access logging in research databases is a potential exposure — the subject of an investigation who has access to those logs can determine that they've been researched.

Mitigations: use databases that can be accessed without authentication; be aware of which database systems retain and disclose access logs; consider which queries are most sensitive.

Metadata in received documents:

Documents received from sources may contain metadata that identifies the source: author fields in Word documents, GPS coordinates in photographs, printer tracking dots in printed-then-scanned documents.

Tools for metadata examination and removal:

  • ExifTool: examines and strips metadata from images and many other file types
  • Metadata Anonymisation Toolkit (MAT2): open-source tool for stripping metadata from various file types
  • Dangerzone: Freedom of the Press Foundation's tool for converting documents to PDFs while stripping potential malware and metadata

Before publishing or sharing a document received from a source, strip the document's metadata. Before publishing photographs, examine EXIF data for GPS coordinates (which could reveal where and when the photo was taken, potentially identifying the photographer).

Printer steganography:

Many color printers embed invisible dots in printed documents — a pattern of yellow dots that encodes the printer's serial number and the date the document was printed. This is known as Machine Identification Code (MID) or printer tracking dots.

A document printed at a specific office printer and then provided to a journalist can, in principle, be traced back to that specific printer — potentially identifying who had access to it. The Electronic Frontier Foundation maintains a list of printers known to use this system.

Journalists receiving physical documents should be aware that a printed document may encode the source printer's identity. For extreme sensitivity, document images can be processed to remove or obfuscate the dot pattern.


Legal Considerations: Shield Laws and Compelled Disclosure

Shield laws protect journalists from being compelled to reveal their sources in legal proceedings. The protection varies significantly by jurisdiction:

United States: There is no federal shield law. Federal shield protection is case-by-case common law (the Branzburg v. Hayes 1972 Supreme Court decision provides limited protection). 49 of 50 states have some form of shield law, but the strength and scope of protection varies. Federal subpoenas to journalists in national security contexts have historically received limited shield protection.

UK: There is statutory source protection under the Police and Criminal Evidence Act 1984 (PACE). However, courts can override this protection in some circumstances.

European Union: Many EU member states have constitutional or statutory source protection. The EU has been working toward common minimum standards.

The practical implication for journalists:

Shield laws protect against compelled testimony (being forced to testify in court about who a source is). They do not protect against technical surveillance (the government obtaining communication records from a carrier or cloud provider) or against data recovered from a journalist's seized device.

This is the gap that technical security measures address: even when a shield law protects the journalist from testifying about a source's identity, the communication records, browsing history, and documents on a seized device may reveal that identity through technical means. Tools that produce no metadata and use end-to-end encryption reduce what can be recovered even from a seized device.


Protecting Specific Source Categories

Government whistleblowers:

Government employees who leak classified or sensitive information face federal criminal liability (Espionage Act charges in the US). Their sources of exposure are primarily: communication metadata, document access logs (who accessed specific files and when), and printer tracking data.

Technical recommendations: SecureDrop submissions (no email, no phone, Tor-routed); physical meetings in locations without smartphones; awareness of document metadata.

Corporate insiders:

Corporate employees who provide evidence of wrongdoing risk termination, civil suits, and potentially criminal liability. Their primary exposure: email logs, internal monitoring systems, document access logs.

Technical recommendations: Signal (on a personal device, not a work device) or SecureDrop; never using work systems or work networks to communicate with a journalist; physically printed documents stripped of printer tracking data if possible.

Sources in high-risk jurisdictions:

Sources in countries with limited press freedom or with sophisticated surveillance capabilities face risks beyond subpoena: physical surveillance, network surveillance by state actors, and potential criminal prosecution. For sources in these contexts, the journalist's technical security choices directly affect the source's physical safety.

Recommendations: SecureDrop accessed via Tor Browser, from public internet access points unconnected to the source's identity; Signal with disappearing messages; no digital record of the communication if avoidable.


Operational Security Practices

Technical tools are necessary but not sufficient. Operational security practices:

Don't discuss sources on insecure channels. The most sensitive detail — that a source exists and their approximate identity — often doesn't need to be communicated at all. Not over email, not over standard messaging, not over the phone.

Limit who knows about the source. The number of people who know a source's identity should be the minimum required. Each additional person who knows is an additional exposure point.

Don't keep unnecessary records. Notes that identify a source, communication logs, and other source-identifying material that isn't necessary for the journalism should be disposed of securely. Digital files: permanent deletion with a file shredder; physical documents: cross-cut shredding or burning.

Manage device security. A journalist's devices, if seized, may contain extensive source-identifying information. Full-disk encryption (FileVault on macOS, BitLocker on Windows) protects against data extraction from a seized powered-off device. A strong device password (not just biometrics) prevents physical access.

Know the legal landscape. Understanding the shield law protections (and their limits) in the relevant jurisdiction is essential. The Reporters Committee for Freedom of the Press maintains resources on journalist legal rights in the US. Consult legal counsel before an investigation enters a phase where legal process is likely.


Worked Example: An Investigative Journalist's Source Protection Setup

Setup: A journalist at a regional newspaper is receiving documents from a government employee about contracting irregularities. The source has significant legal exposure. The journalist expects legal pressure if the story is published.

What the journalist does:

She sets up a Signal account on a work phone (separate from her personal phone) with a number not linked to her primary identity. She gives the source her Signal handle; they communicate only through Signal with disappearing messages enabled (7-day deletion).

Documents come through SecureDrop, which her publication runs. The source submits through Tor Browser on a personal device, not a work device. The source uses the SecureDrop codename for all follow-up communication.

She examines received documents with ExifTool before printing or sharing them. She removes all metadata from document files. She is aware of printer tracking dots and avoids printing source documents on her office's networked printers.

Research is conducted in a dedicated Firefox profile with no personal logins. She uses Startpage for research queries that she's not comfortable linking to her primary identity.

Notes about the source are kept in a Joplin notebook with E2EE enabled. The notebook contains no identifying information about the source — only information needed for verification and for the story.

She has consulted with her publication's legal counsel about the jurisdiction's shield law before beginning source communication.


Key Takeaways

  1. SecureDrop is the gold standard for anonymous document submission: Tor-routed, no email, no phone number, codename-based identity — it provides the strongest source anonymity available.
  2. Signal with disappearing messages is the baseline for ongoing communication: end-to-end encrypted, minimal metadata if registered with a non-primary number, and disappearing messages reduce the retained record.
  3. Document metadata can reveal source identity independent of communication security: examine received documents with ExifTool or MAT2 before using or publishing them; be aware of printer tracking dots.
  4. Shield laws protect against compelled testimony, not against technical surveillance or seized-device forensics: technical measures close the gap between what shield laws protect and what surveillance can extract.
  5. Limit who knows about the source and dispose of source-identifying material not needed for the journalism: the smallest possible set of people with source knowledge is the most secure configuration.

Conclusion

Source protection is a multi-layered practice combining secure communication channels, research privacy practices, document metadata management, operational security discipline, and legal preparedness. No single tool provides complete protection; each layer addresses a different failure mode. The baseline — Signal for communication, awareness of document metadata, full-disk encryption on devices — addresses the most common risks for most investigative journalism. High-stakes investigations involving sources with significant legal exposure benefit from SecureDrop, Tor-based research, and legal counsel engaged before the investigation goes public. The underlying commitment is consistent: the trust that makes sources willing to come forward depends on the journalist's demonstrated ability and willingness to protect them.

Try WebSnips free — capture and annotate source protection resources, journalism security guides, and press freedom toolkits with your own context notes, tag by threat type and tool, and build the organized knowledge base that supports secure investigative practice.

Keep reading

More WebSnips articles that pair well with this topic.

Privacy & SecurityAugust 18, 202611 min read

How to Audit a browser extension's permissions

How to Audit a browser extension's permissions — a practical, example-driven guide with honest tool comparisons and a clear place for WebSnips. Written for Lawyers.

aeaudit-a-browser-extension-s-permissions-guidesecure-audit-a-browser-extension-s-permissionsprivate-audit-a-browser-extension-s-permissions
Read article
Privacy & SecurityAugust 18, 202610 min read

How to Avoid Vendor Lock-in with Your Notes

How to avoid vendor lock-in with your notes — a practical guide for individuals and teams who want to keep their personal knowledge base portable, format-independent, and recoverable regardless of which application or service they use.

aeavoid-vendor-lock-in-with-your-notes-guidesecure-avoid-vendor-lock-in-with-your-notesprivate-avoid-vendor-lock-in-with-your-notes
Read article
Privacy & SecurityAugust 18, 202611 min read

How to Back Up Your Notes Safely

How to back up your notes safely — a practical guide for individuals and professionals who want reliable, secure backups of their personal knowledge base, covering backup strategies, encrypted backup tools, and recovery testing for note-taking applications.

aeback-up-your-notes-safely-guidesecure-back-up-your-notes-safelyprivate-back-up-your-notes-safely
Read article
Privacy & SecurityAugust 18, 202610 min read

How to Capture Sensitive Research Securely

How to capture sensitive research securely — a practical guide for researchers, journalists, legal professionals, and privacy-conscious individuals who need to gather and store sensitive information without creating avoidable exposure through insecure capture tools or storage practices.

aecapture-sensitive-research-securely-guidesecure-capture-sensitive-research-securelycapture-sensitive-research-securely-tools
Read article
Privacy & SecurityAugust 18, 20269 min read

How to Choose a Private Web Clipper

How to choose a private web clipper — a practical guide for privacy-conscious researchers, journalists, and professionals who want to clip and save web content without exposing their browsing patterns, source materials, or clipped content to third-party services.

aechoose-a-private-web-clipper-guidesecure-choose-a-private-web-clipperchoose-a-private-web-clipper-tools
Read article
Privacy & SecurityAugust 18, 202611 min read

How to Comply with GDPR in Your Knowledge Base

How to comply with GDPR in your knowledge base — a practical guide for teams and organizations who store personal data in their internal wikis, documentation systems, and knowledge management tools, covering data minimization, retention policies, access controls, and subject rights.

aecomply-with-gdpr-in-your-knowledge-base-guidesecure-comply-with-gdpr-in-your-knowledge-baseprivate-comply-with-gdpr-in-your-knowledge-base
Read article