Paper 2026/1484

The SecureDrop Protocol: End-to-End Encrypted Whistleblowing for All

Giulio Berra, Freedom of the Press Foundation
Felix Linker, ETH Zurich
Luca Maier, ETH Zurich
Cory Francis Myers, Freedom of the Press Foundation
Kenneth G. Paterson, ETH Zurich
Rowen Shane, Freedom of the Press Foundation
Shannon Veitch, ETH Zurich
Abstract

Confidential sources are vital for investigative journalism and thus for holding those in power to account. However, sources often face great risks to their privacy and safety. SecureDrop is a system that enables sources to anonymously contact journalists, including at major news organisations around the world. Despite its widespread use, the current design requires physical servers hosted on premises. While cloud-based deployment would alleviate this burdensome requirement and improve SecureDrop's usability and accessibility, it would also introduce new threats to security that are not addressed by the current design. In particular, a lack of end-to-end encryption presents serious risks in the event that a cloud service provider is coerced into revealing information. In this work, we present and formally analyse a new protocol for SecureDrop which addresses the challenges of off-premises deployment. Our protocol composes an encryption scheme with hybrid post-quantum guarantees and an identity-hiding message-fetching mechanism to provide strong anonymity guarantees. In contrast to existing systems, we minimise incriminating evidence against whistleblowers by providing message-level deniability and by having sources remain stateless. Our formal security analysis combines the Tamarin prover for symbolic analysis and game-based proofs for computational analysis. Finally, our benchmarks demonstrate that the protocol achieves practical levels of performance in a browser context. The Freedom of the Press Foundation plans to deploy the new protocol, with integration efforts beginning in 2026.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Major revision. CCS 2026
Keywords
anonymous communicationwhistleblowing
Contact author(s)
giulio @ freedom press
flinker @ inf ethz ch
luca maier @ gmx com
cory @ freedom press
kenny paterson @ inf ethz ch
ro @ freedom press
shannon veitch @ inf ethz ch
History
2026-07-23: approved
2026-07-20: received
See all versions
Short URL
https://ia.cr/2026/1484
License
Creative Commons Attribution-ShareAlike
CC BY-SA

BibTeX

@misc{cryptoeprint:2026/1484,
      author = {Giulio Berra and Felix Linker and Luca Maier and Cory Francis Myers and Kenneth G. Paterson and Rowen Shane and Shannon Veitch},
      title = {The {SecureDrop} Protocol: End-to-End Encrypted Whistleblowing for All},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1484},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1484}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.