सामग्री पर जाएँ
HexaTransfer
ब्लॉग पर वापस
एन्क्रिप्शन और सुरक्षा

पत्रकारों के लिए सुरक्षित फ़ाइल शेयरिंग: अपने सोर्स की रक्षा करें

पत्रकारों को सोर्स के साथ फ़ाइल शेयर करते समय अधिकतम सुरक्षा चाहिए। सोर्स की पहचान सुरक्षित रखने वाले एन्क्रिप्शन टूल जानें।

सोर्स की रक्षा पहले दस्तावेज़ share होने से पहले शुरू होती है। पत्रकार का threat model compelled disclosure, subpoenas, border पर device seizure, state-level surveillance, और यह simple risk शामिल करता है कि सोर्स का metadata — IP addresses, file hashes, login timestamps — story चलने के बाद लंबे समय तक survive कर सकता है। Practical tools: anonymous intake के लिए SecureDrop, ongoing conversation के लिए disappearing messages के साथ Signal, दस्तावेज़ों के लिए HexaTransfer या OnionShare जैसा zero-knowledge transfer service, और handling device के लिए Tails OS या Qubes। Committee to Protect Journalists ने 2023 में globally 363 journalists जेल में document किए — सोर्स protection abstract नहीं है।

Baseline threat model

अधिकांश journalists GCHQ या MSS face नहीं करेंगे, लेकिन हर कोई कुछ न कुछ face करता है। Plan के लिए तीन tiers:

  • Civil subpoena risk. Prosecutors और civil litigants communication records seek करते हैं। Democratic jurisdictions में हर journalist को affect करता है। 2021 Justice Department subpoenas New York Times, Washington Post, और CNN को reporter phone records के लिए — threat को concrete बनाया।
  • Targeted surveillance. एक specific actor actively आपका सोर्स identify करने की कोशिश में। Operational discipline चाहिए: separate devices, VPN या Tor, encrypted messengers, careful metadata hygiene।
  • Nation-state surveillance. Rare लेकिन real national security, human rights, और cross-border reporting के लिए। Pegasus spyware Citizen Lab द्वारा confirm 45+ journalists के खिलाफ deploy किया गया।

Tooling decisions tier के साथ scale होते हैं। एक local court reporter को basic encryption चाहिए; authoritarian regime cover करने वाले foreign correspondent को Tails, air-gapped review, और compartmentalized devices चाहिए।

Anonymous intake के लिए SecureDrop

SecureDrop, Freedom of the Press Foundation द्वारा maintained, anonymous सोर्स submission का professional standard है। The Guardian, New York Times, Washington Post, ProPublica, The Intercept, और 80+ अन्य newsrooms द्वारा use।

यह कैसे काम करता है:

  1. Sources newsroom के .onion address को Tor Browser के ज़रिये access करते हैं।
  2. वे random codename generate करते हैं और files या messages submit करते हैं।
  3. Journalists Tails चलाने वाले separate air-gapped viewing station से submissions access करते हैं।
  4. Files केवल viewing station पर decrypt होती हैं, जो internet कभी नहीं touch करता।

यह strong क्यों है: Tor सोर्स IP hide करता है, air-gap malware exfiltration prevent करता है, GPG encryption का मतलब है server-side plaintext नहीं, और retrieval के बाद automatic deletion forensic footprint limit करती है।

Installation nontrivial है — dedicated hardware और careful setup का एक हफ्ता चाहिए — लेकिन sensitive submissions accept करने वाले किसी भी newsroom के लिए, यह एकमात्र credible option है।

Peer-to-peer drops के लिए OnionShare

जब SecureDrop overkill हो, OnionShare (Micah Lee द्वारा developed) simpler Tor-based file sharing offer करता है। यह आपकी machine पर one-shot hidden service चलाता है, एक .onion URL देता है, और download के बाद shut down होता है।

Properties journalists care करते हैं:

  • कोई third-party server file hold नहीं करता।
  • Tor दोनों endpoints के IPs hide करता है।
  • URL में random authentication token होता है, इसलिए file publicly listed नहीं है।
  • macOS, Windows, और Linux पर काम करता है; Tails के साथ bundled।

उस सोर्स के साथ one-off exchanges के लिए best जो Tor Browser install कर सकता हो। जब सोर्स work laptop पर software restrictions के साथ हो तो उतना अच्छा नहीं — उस case में, browser-based services ज़रूरी हो जाती हैं।

जब Tor option नहीं है: Browser-based E2EE

कुछ sources Tails या Tor नहीं चला सकते। उनके पास work computer है, borrowed laptop है, या ऐसी situation है जहाँ new software install करना suspicious लगे। उनके लिए, browser-based end-to-end encrypted service pragmatic choice है।

क्या देखना है:

  • Browser में client-side AES-256-GCM encryption।
  • URL fragment में key (# के बाद), server को कभी नहीं भेजी जाती।
  • Configurable TTL के साथ expiring links (24 घंटे या कम)।
  • Link के ऊपर password protection।
  • No account required — signup खुद metadata generate करती है।

Qualify करने वाली services: HexaTransfer, SwissTransfer E2EE tier, Tresorit Send, Proton Drive shared links। जो नहीं करतीं: WeTransfer standard, Google Drive, Dropbox share links — ये सभी provider को file contents की visibility देती हैं।

Conversation के लिए Signal

Files rarely बिना context के आती हैं। "यह क्या है" और "मैं इसे verify कैसे करूं" की conversation को अपना channel चाहिए।

Signal, nonprofit Signal Foundation द्वारा maintained, journalist default है:

  • Signal Protocol (Double Ratchet, X3DH) से default E2EE।
  • Configurable timers के साथ disappearing messages (5 seconds से 4 weeks)।
  • Early 2024 से एक बार username हो जाए तो message के लिए phone number ज़रूरी नहीं।
  • Timer expire होने पर दोनों devices पर messages delete।
  • PIN-protected backups, जब तक explicitly configured न हो cloud backup नहीं।

सोर्स काम के लिए iMessage avoid करें। Apple metadata देख सकता है, और iCloud Messages sync का मतलब है backups Apple servers पर हो सकते हैं जो legal process के अधीन हैं।

Metadata ही assassin है

The Intercept का 2017 Reality Winner case canonical example है: leaked document पर printer tracking dots, newsroom की handling के साथ, days के भीतर सोर्स identification की। Publish या share करने से पहले scrub करने के लिए metadata:

  • Images पर EXIFexiftool -all= photo.jpg GPS, camera serial, timestamps remove करता है।
  • PDF metadata — author name, creation date, editing software। exiftool -all= doc.pdf plus अच्छे measure के लिए qpdf --linearize
  • Microsoft Office metadata — File → Info → Inspect Document → Remove All।
  • Printer microdots — कई color laser printers पर blue light में visible। B&W laser पर air-gap printing, या EFF के detection guide use करें।
  • File timestamps — relevant होने पर sharing से पहले neutral time पर touch करें।

उन दस्तावेज़ों के लिए जिन्हें authenticity preserve करनी हो (legal evidence), original hash करें, copy से काम करें, और chain of custody preserve करें।

High-risk reporting के लिए device hygiene

Sensitive काम के लिए dedicated hardware पहली बार laptop seizure होने पर खुद for itself pay करता है। Recommended stack:

  • Work device: locked-down Mac या ThinkPad FileVault/LUKS के साथ, OS updates 7 days में, कोई personal software नहीं, personal accounts पर कोई sync नहीं।
  • Review device: air-gapped document review के लिए Tails USB। USB से boot, कोई trace नहीं छोड़ता।
  • Personal device: entirely separate, कभी सोर्स काम के लिए use नहीं, work device पर कुछ भी sync नहीं।
  • Burner phones high-risk jurisdictions में travel के लिए, return पर wiped।

Pegasus और similar spyware iMessage और WhatsApp में zero-click vulnerabilities exploit करते हैं। iOS और Android current रखें; targeted subjects के लिए iPhone पर Lockdown Mode enable करें।

Border crossings

Border cross करने वाले journalists device searches face करते हैं। US CBP को entry पर devices inspect करने का legal authority है। UK border officials Schedule 7 of the Terrorism Act के तहत disclosure compel कर सकते हैं। Practical response:

  • Clean device के साथ travel करें — कोई सोर्स material नहीं, कोई Signal history नहीं, कोई browser login cookies नहीं।
  • Necessary materials एक secure cloud (Proton Drive, Tresorit) पर device के keychain में नहीं रहे password से encrypt करके send करें, arrival पर retrieve करें।
  • एक second device अलग से ship करने पर consider करें।
  • अपनी jurisdiction के rules जानें — कुछ countries unlock करने से इनकार को crime treat करती हैं, दूसरी नहीं।

Freedom of the Press Foundation updated border-crossing guides publish करता है। Travel से पहले review करें।

एक reporting workflow जो hold up करे

अधिकांश sensitive stories के लिए काम करने वाला routine:

  1. Dedicated work number से Signal के ज़रिये initial contact, या SecureDrop के ज़रिये।
  2. Out of band identity verify करें अगर possible हो — public records, mutual contact, prior work।
  3. 24-hour expiration और shared secret से password के साथ document exchange के लिए HexaTransfer, OnionShare, या Tresorit पर move करें।
  4. Tails या air-gapped Mac पर documents review करें। High-sensitivity material के लिए कभी networked device पर नहीं।
  5. Review environment छोड़ने से पहले किसी भी copy से metadata scrub करें।
  6. Publication के बाद Signal thread और shared keys delete करें, editors के साथ agreed retention policy के साथ।
  7. Shield-law और editorial protection के लिए अपनी प्रक्रिया document करें।

शुरुआत करना

अगर आप शुरू कर रहे हैं: Signal install करें, password manager set up करें, FileVault या BitLocker turn on करें, और routine sharing के लिए browser-based E2EE transfer service चुनें। SecureDrop और Tails पर graduate करें जैसे-जैसे आपकी reporting demands हों। "अधिकांश stories के लिए काफी secure" और "nation-state adversaries के लिए काफी secure" के बीच gap wide है लेकिन learnable है।

hexatransfer.com पर आज़माएं — मुफ्त, बिना अकाउंट, 10 GB तक।

एंड-टू-एंड एन्क्रिप्शन के साथ बड़ी फ़ाइलें सुरक्षित रूप से भेजें

एंड-टू-एंड एन्क्रिप्शन के साथ 10 GB तक की फ़ाइलें मुफ़्त में ट्रांसफ़र करें। अकाउंट की आवश्यकता नहीं। अपलोड से पहले आपकी फ़ाइलें ब्राउज़र में एन्क्रिप्ट की जाती हैं — कोई और उन्हें पढ़ नहीं सकता।

फ़ाइल भेजें