With journalist Silkie Carlo I have co-authored a 'handbook' on practical information security for journalists commissioned by the UK Centre for Investigative Journalism. The CIJ handbook 'Information Security for Journalists' was launched at the CIJ Summer School 2014 in London. The book will be forever freely available in a range of electronic formats - see download links below. In the four months after the initial publication in we have rewritten certain parts based on feedback from the initial readers and updated other parts to stay current with the latest software changes. Many thanks to all who gave us valuable feedback.
Altough this book was originally written for investigative journalists most of the described concepts and technical solutions are just as usable by lawyers or advisors protecting communications with their clients, doctors protecting medical privacy and of course politicians, activists or anyone else who engages powerful state and corporate organisations. Really, we're all journalists now. Inside the book is a mailadres for getting in touch, please let us know how your are using it and what we can do better.
If you have reasons to suspect your online movements are already under some form of surveilance you should not download this book using a computer or netwpork associated with your identity (such as your home or work systems).
Several participants of journalist training programs have written articles: Information security for journalists: staying secure online by Alastair Reid (from journalism.co.uk) - A day with the surveillance expert by Jason Murdock, Offtherecord.in - Valentina Novak wrote this interview after a lecture & workshop in Slovenia last November.
From the 'backflap' of the book:
With journalist Silkie Carlo I have co-authored a 'handbook' on practical information security for journalists commissioned by the UK Centre for Investigative Journalism. The CIJ handbook 'Information Security for Journalists' was launched at the CIJ Summer School 2014 last weekend in London. The book will be freely available in electronic format and in print after the summer. Just like last year I gave lectures (slides) and ran a hands-on workshop to get journalists 'tooled-up' so they can better protect their sources, themselves and their stories in a post-Snowden world.
From the 'backflap' of the book:
This handbook is a very important practical tool for journalists. And it is of particular importance to investigative reporters. For the first time journalists are now aware that virtually every electronic communication we make or receive is being recorded, stored and subject to analysis and action. As this surveillance is being conducted in secret, without scrutiny, transparency or any realistic form of accountability, our sources, our stories and our professional work itself is under threat.
After Snowden’s disclosures we know that there are real safeguards and real counter measures available. The CIJ’s latest handbook, Information Security for Journalists, lays out the most effective means of keeping your work private and safe from spying. It explains how to write safely, how to think about security and how to safely receive, store and send information that a government or powerful corporation may be keen for you not to know, to have or to share. To ensure your privacy and the safety of your sources, Information Security for Journalists will help you to make your communications indecipherable, untraceable and anonymous.
Although this handbook is largely about how to use your computer, you don’t need to have a computer science degree to use it. Its authors, and the experts advising the project are ensuring its practical accuracy and usability, and work with the latest technology.
Director of the Centre for Investigative Journalism
This handbook is being translated into Arabic, Chinese, French, German, Portugese, Spanish, and other languages
I will be speaking and workshopping at the 2014 Dataharvest+ conference in Brussels. This conference brings together investigative journalists, (big)data wranglers, coders & hackers to kick journalism into the 21st century.
My contribution will be a series of presentations about applied information security for investigative journalists and hands-on workshops to get security tools working on laptops. So bring yours! Slides I used are here: PPT, PDF. Some tips and links to tools. A video from a comparable worshop last year, since then the situation has turned out to be much more dire.
(this post text started as an email to a Dutch employee of the national broadcast service NOS - somewhat equivalent to the British BBC) - also on Sargasso.nl. See Dutch version of this blog for links to the complete follow-up (in Dutch). Overview of this on Sander Venema's blog in English.
Yesterday you felt it tweet-worthy that Russia Today TV had cut off a guest who used the platform he was given not to discuss the Bradley Manning trail but instead staged a protest against the horrible LGBT-rights situation in Russia. This incident was to you 'proof' that RT could not be trusted as a good information source in other things. As a reference you picked the Dutch newspaper 'De Telegraaf'. This, in my view, was a rather unfortunate choice since this newspaper has itself a long and sordid history of collaborating with the German occupation, misinforming of misrepresenting world events and generally being a publication that only cares about human rights when it suits their political agenda. All in the tradition of FOX-news and the Daily mail.
At OHM2013 I talked about implications of accelerating tech, some ways to understand the various crisis we're in right now and some questions we can ask about the strange things our governments seem to be up to these days.
I was critical of most western 'mainstream' media because they see quite incapable of asking basic questions such as: "why are we putting Bradley Manning on trial and not the helicopter-gunner who shot up over a dozen civilians including children?" Shooting at children with an anti-tank gun and then lying about it to the world is probably a war-crime, certainly something worth digging into in the context of a war that itself has been started based on lies.
The UK Centre for Investigative Journalism is a non-profit organisation dedicated to educating and training journalists to benefit the quality of journalism and thus public debates on important topics in society. Every year the CIJ holds a 3-day summer school where journalists can follow lectures, participate in workshops and meet with some of the foremost professionals in their field. Several months ago, when the CIJ asked me to help set up a workshop in information security, we had no idea then how hot the subject would become after the revelations by former NSA-contractor Edward Snowden. I was very happy to see the room at London City University was packed with journalists eager to learn both theory and practice of securing their communications and protecting their data. An overview of theory & tools for those who missed it, slides here, video below.
Being in London for a few days also allowed me to contribute to a cryptoparty (a workshop for teaching info security basics to anyone interested) that was kindly hosted and wonderfully supported by the London Hackerspace. Dozens of people from all walks of life showed up and we had a great time.
If you would like to attend such a workshop contact your local hackerspace and join or look at this list of upcoming cryptoparties. If nothing is planned in your area start a group yourself. The time for it has never been more propitious. The links above can get you started. If you get stuck mail me and I'll be happy to put you in contact with people near you.
Below a recording of the theory introduction part of the workshop at the 2013 summer school. After this intro the whole class worked together for several hours setting up software tools for email-encryption, anonymous browsing and testing these new capabilities with colleagues. By the end of the day over 30 journalists were tooled up to receive scoops from high-risk whistleblowers.