Journalist Security Checklist
Journalist Digital Security Guide
Protecting Sources, Stories, and Yourself By Liz Howard, The Multiverse School
๐จ Critical Understanding
You are NOT "most people." When security experts say "this is probably fine for most people," they're talking about average users, not journalists. You face state-sponsored actors, corporate espionage, and targeted harassment. Your threat model is in the top tier.
Your sources' lives may depend on your security practices.
๐ฏ The Journalist Threat Landscape
You Face:
State-Level Adversaries: - NSA/Five Eyes surveillance - Foreign intelligence services - Law enforcement investigations - Court-ordered disclosure - Border searches - FISA warrants
Corporate Threats: - Private investigators - Corporate security teams - SLAPP suits with discovery - Hacked law firms - Competitive intelligence
Individual Threats: - Doxxing campaigns - Harassment networks - Source compromise - Metadata exposure - Physical surveillance
๐ง The Psychology of Security
It's a Marathon AND a Sprint
Security fatigue is real. You can't maintain perfect security 24/7, so:
- When afraid: Take ONE security action immediately
- Weekly: Host "security parties" with colleagues
- Use checklists: activistchecklist.org
- Build habits: Small daily practices > perfect occasional security
Managing the Paranoia
- Some paranoia is justified - you ARE being watched
- But constant fear degrades your work
- Set specific "security time" vs. "work time"
- Trust but verify your instincts
๐ก๏ธ Phase 1: Identity Protection & Anti-Doxxing
A. Accept the Inevitable
You WILL be doxxed. Plan for it now:
- Credit Lockdown:
- [ ] Freeze all credit reports NOW
- [ ] Only unfreeze when applying for credit
-
[ ] Use verbal passwords with agencies
-
Financial Fortress:
- [ ] Unique password for every bank account
- [ ] 2FA on all financial services
- [ ] Separate "public" and "private" bank accounts
-
[ ] Consider credit union over big banks
-
Document Security:
- [ ] Get new driver's license number if compromised
- [ ] Use P.O. Box for public records
- [ ] Remove address from voter rolls if possible
B. Disinformation as Defense
Confuse the bots and trolls:
- Create Decoy Profiles:
- [ ] Make 3+ fake accounts with your name/photo
- [ ] Post plausible but false information
- [ ] Different birthdays, schools, jobs
-
[ ] Keep them semi-active
-
Poison the Well:
- [ ] Old/wrong info is your friend
- [ ] Multiple "official" websites
- [ ] Conflicting biographical details
- [ ] Let errors propagate
C. Know Your Doxxers
- Most are teenagers/early 20s
- Some work for sophisticated actors unknowingly
- Government doxxing requires minimal effort
- Corporate doxxing is often outsourced
๐ฑ Phase 2: Device Security Architecture
A. The Three-Device System
1. Daily Driver (Your regular phone/laptop): - Assume compromised - Never for sensitive sources - Public-facing work only - Full encryption enabled
2. Source Device (Dedicated secure device): - Never connects to personal accounts - Tails OS or GrapheneOS - Tor/VPN always - Different location use only
3. Burner Device (Disposable): - For high-risk temporary needs - Cash purchase, no activation - Destroy after use - Never bring home
B. Smartphone Hardening
Your Phone is a Hot Mic:
Daily Phone Security: - [ ] Keyboard apps spy - don't type keywords - [ ] Assume all apps can access all data - [ ] Lockdown mode when possible - [ ] Biometrics = legally compellable - [ ] Cover cameras when not using
Signal Configuration: - [ ] Disappearing messages ALWAYS for sources - [ ] Registration lock enabled - [ ] PIN reminder frequency to never - [ ] Screen security enabled - [ ] Relay calls through Signal servers
Location Discipline: - [ ] WiFi/Bluetooth OFF except at home - [ ] Yes, Bluetooth headphones identify you - [ ] Location services fully disabled - [ ] Airplane mode isn't enough
C. Computer Hardening
The Basics: - [ ] NOTHING plugs into journalism computer - [ ] Camera covered with tape - [ ] Microphone physically disconnected if possible - [ ] Full disk encryption mandatory - [ ] Separate user accounts for different work
Backup Strategy: - [ ] Daily to offline drive - [ ] Weekly to large memory card - [ ] Monthly mail backup to trusted friend - [ ] Multi-cloud with different emails - [ ] Test restore process quarterly
๐ต๏ธ Phase 3: Source Protection
A. Initial Contact
Never Compromise at First Touch: - SecureDrop for anonymous tips - Signal with disappearing messages - Separate device for source comms - Meet in person when possible - Assume all digital = recorded
B. Ongoing Communication
Compartmentalization is Key: - One source = one device ideally - Never mix source pools - Different passwords per source - Separate encrypted volumes - Regular security reviews with sources
C. Document Handling
The Printer Problem: - [ ] Printers add tracking dots - [ ] Reality Winner was caught this way - [ ] Use DEDA to add noise - [ ] Better: Don't print sensitive docs - [ ] Best: Old printers from flea markets
๐ญ Phase 4: Sock Puppet Mastery
A. Account Creation
The Golden Rules: 1. Separate device (never your main) 2. Different location (never home/office) 3. Different network (never your WiFi) 4. Different habits (posting times, style) 5. Never cross the streams
Device Selection: - [ ] Secondhand older phone - [ ] Factory reset twice - [ ] No SIM activation - [ ] WiFi only (public/borrowed) - [ ] Wear mask if using FaceID device
B. Operational Security
Location Discipline: - [ ] Pick dedicated "posting location" - [ ] Never bring device home - [ ] Store in separate location - [ ] Different transport route - [ ] Cash for everything
Digital Hygiene: - [ ] No weather apps (location) - [ ] No personal accounts ever - [ ] Different email per identity - [ ] VPN + Tor for all access - [ ] Regular device rotation
๐น Phase 5: Protest & Event Coverage
A. Pre-Event Preparation
48 Hours Before: - [ ] Scout location without devices - [ ] Memorize routes (no Google Maps) - [ ] Identify safe houses/exits - [ ] Coordinate with legal support - [ ] Prep all equipment
Device Decisions: - [ ] Leave primary phone at HOME (not car) - [ ] Bring only burner if needed - [ ] Hidden cameras > obvious ones - [ ] Memory cards, not WiFi/Bluetooth - [ ] Faraday bag for transport
B. On-Scene Security
The Stingray Problem: - Assume IMSI catchers present - All phones in area surveilled - Airplane mode insufficient - Better to have no phone - If livestreaming, accept compromise
Alternative Comms: - [ ] Mesh networking (Meshtastic) - [ ] Pre-arranged signals - [ ] Dead drops for footage - [ ] Courier handoffs - [ ] Time-delayed publishing
C. Post-Event Protocol
Immediate Actions: 1. Don't go straight home 2. Check for physical surveillance 3. Transfer footage to secure device 4. Wipe/destroy burner devices 5. Debrief with team securely
๐ Phase 6: Advanced Techniques
A. Voice Anonymization
When You Need Different Voice: - Speech Conversion Tools - Coqui TTS for generation - Amphion Toolkit for processing - Real-time vs. post-processing - Test with voice printing tools
B. VPN Reality Check
What VPNs Actually Do: - Hide IP from websites (not governments) - Prevent ISP data collection/sales - Change apparent location - That's it.
What VPNs Don't Do: - Make you anonymous - Protect from state surveillance - Hide traffic patterns - Prevent browser fingerprinting
Best Practice: - Mullvad VPN (accepts cash) - VPN + Tor, not VPN alone - Different VPN per identity - Assume VPN provider compromised
C. Tool Selection
Avoid: - Zoom โ Use Jitsi - Gmail โ Use ProtonMail - Dropbox โ Use Tresorit - WhatsApp โ Use Signal
More alternatives: prism-break.org
๐ฐ Phase 7: Acquiring Technology
A. Purchase Security
Never: - Use your Amazon account - Use credit cards - Buy from big box stores - Create patterns
Always: - Pay cash at sketchy electronics stores - Buy at flea markets/yard sales - Use different locations - Vary purchase times - Consider proxy buyers
B. "Burner Phone" Reality
The Truth: - True burner phones barely exist - All phones have unique identifiers - Activation = identification - "Burner phone dealers" often compromised - Better: Rotating old devices
๐ Phase 8: Metadata Discipline
A. Understanding Metadata
What Kills Sources: - Call records (who, when, duration) - Location data (where you met) - Message timestamps (patterns) - File metadata (creation, edits) - Network connections (IP addresses)
B. Metadata Stripping
Every File, Every Time: - [ ] Photos: Remove EXIF data - [ ] Documents: Clear properties - [ ] PDFs: Sanitize with tools - [ ] Audio: Strip recorder info - [ ] Video: Remove all metadata
Tools: - ExifTool for images - MAT2 for multiple formats - PDF Redactor for documents - Metadata Cleaner for bulk
๐ง Phase 9: Sustainable Security
A. Building Habits
Daily (5 minutes): - Check device for new apps - Review recent logins - Clear browser data - Check for updates
Weekly (30 minutes): - Full device backup - Security news review - Source OPSEC check - Tool updates
Monthly (2 hours): - Threat model review - Complete security audit - Rotate passwords - Test disaster recovery
B. Mental Health
Warning Signs of Security Fatigue: - Skipping steps because "tired" - Paranoia affecting relationships - Not leaving house - Checking locks repeatedly - Isolating from colleagues
Recovery Practices: - Regular offline time - Security buddy system - Professional support - Boundaries with work - Exercise and nature
๐ Quick Reference Cards
Source Meeting Checklist
``` Before: โก Leave all devices behind โก Counter-surveillance route โก Cash for everything โก Meeting location secured โก Legal contact ready
During: โก No phones present โก White noise/music โก Visual surveillance check โก Note-taking discipline โก Establish future comms
After: โก Different route home โก Transcribe notes immediately โก Secure all materials โก Schedule followup โก Update threat assessment ```
Daily Security Card
``` Morning: โก Check overnight alerts โก Review day's risks โก Select appropriate devices โก Verify backups current
Workday: โก Source comms on secure device only โก Metadata stripped from all files โก Disappearing messages enabled โก Location services managed
Evening: โก Devices backed up โก Accounts reviewed โก Tomorrow's security planned โก All devices charging securely ```
๐ Resources
Essential Tools:
- SecureDrop: For anonymous tips
- Tails OS: https://tails.net
- Signal: https://signal.org
- ProtonMail: https://proton.me
- VeraCrypt: https://veracrypt.fr
Training:
- CPJ Safety Kit: https://cpj.org/safety-kit/
- Totem Project: https://totem-project.org
- Article 19: https://article19.org
- Rory Peck Trust: https://rorypecktrust.org
Emergency Contacts:
- CPJ Emergencies: +1 212 465 1004
- RSF Hotline: +33 1 44 83 84 84
- Article 19: +44 20 7324 2500
๐ช Remember:
Your security protects:
- Your sources' lives
- Your stories' integrity
- Democracy itself
- Future journalists
- The truth
You're not paranoid if they're really watching you.
Stay sharp. Stay safe. Keep reporting.
Secure support: liz@themultiverse.school
Private consultation: https://jitsi.themultiverse.school
The best security is the security you'll actually use.
Clear your browser history. Protect your sources. ๐ฐ
Secure Technology Acquisition Guide
For Journalists Needing Untraceable Devices
๐ซ Never Do This:
- โ Use your Amazon/eBay account
- โ Use credit/debit cards
- โ Buy from Best Buy/Apple Store
- โ Create patterns (same store, same time)
- โ Buy "burner phones" from dealers
- โ Register devices with real info
- โ Turn on near home/office
โ Safe Acquisition Methods:
1. Flea Markets & Yard Sales
Best for: Old laptops, printers, basic phones - Pay cash only - Different markets each time - Wear hat/sunglasses - No small talk about use - Test before leaving
2. Sketchy Electronics Stores
Best for: USB drives, cables, accessories - The dustier, the better - Independent shops only - Cash transactions - Buy common items too - Never fill out warranty cards
3. Craigslist/Local Classifieds
Best for: Older smartphones, tablets - Meet in public places - Bring exact cash - Use different email each time - Factory reset immediately - Never meet near home
4. Pawn Shops
Best for: Diverse device selection - Negotiate prices down - Check multiple locations - Avoid shops with cameras - Don't provide ID - Pay cash only
๐ฑ Device Selection Tips:
For Phones:
- 2-3 generation old models (less tracking)
- Popular models (blend in)
- Unlocked devices (no carrier ties)
- No 5G (simpler baseband)
- Removable battery (if possible)
For Computers:
- ThinkPads (Linux-friendly)
- 5+ years old (pre-Intel ME issues)
- Business models (better built)
- No touchscreen (less complexity)
- Upgradeable RAM (future-proof)
For Printers:
- Pre-2005 models (no tracking dots)
- Laser over inkjet (reliability)
- No WiFi/network (air-gapped)
- Common brands (toner availability)
- Test thoroughly (before buying)
๐ญ Purchase Personas:
"The Student"
- Buying for school project
- Limited budget story
- Ask about student discounts
- Seem unsure about specs
"The Grandparent"
- Buying for grandkid
- Don't understand technology
- Ask basic questions
- Have specs written down
"The Repair Person"
- Buying for parts
- Know technical terms
- Buying multiple items
- Seem uninterested in new features
๐ Transportation Security:
- Never drive your car to purchase
- Use public transit (pay cash)
- Walk final blocks to store
- Different routes each time
- No patterns in timing
๐ฐ Cash Management:
- Withdraw over time (not all at once)
- Different ATMs (not your bank)
- Small bills preferred
- Exact change when possible
- No sequential bills (mix them up)
๐ Post-Purchase Protocol:
- Don't go straight home
- Remove batteries immediately
- Check for tracking devices
- Factory reset at secure location
- Never turn on at home first
- Install OS at public WiFi
- Different location for each step
๐จ Red Flags to Avoid:
- Sellers who ask too many questions
- Requests for contact information
- "Too good to be true" deals
- Sellers who want to "help set up"
- Any documentation requirements
- Shops with extensive CCTV
- Anyone offering "burner phones"
๐ Shopping Checklist:
Before Shopping: - [ ] Cash prepared (mixed bills) - [ ] Transportation planned - [ ] Cover story ready - [ ] Hat/sunglasses packed - [ ] Shopping list memorized
During Shopping:
- [ ] Stay in character
- [ ] No personal conversations
- [ ] Check for cameras
- [ ] Count change carefully
- [ ] Get generic receipt only
After Shopping: - [ ] Indirect route away - [ ] Check for surveillance - [ ] Remove batteries - [ ] Secure devices properly - [ ] Document nothing
Remember: The goal isn't perfection, it's breaking patterns and avoiding easy tracking. Every layer of anonymity costs your adversaries more resources.
"The best technology is technology they don't know you have."