CCS2026

The SecureDrop Protocol: End-to-End Encrypted Whistleblowing for All

Giulio Berra, Felix Linker, Luca Maier, Cory Francis Myers, Kenneth G. Paterson, Rowen Shane, Shannon Veitch

Abstract

Confidential sources are vital for investigative journalism and thus for holding those in power to account. However, sources often face great risks to their privacy and safety. SecureDrop is a system that enables sources to anonymously contact journalists, including at major news organisations around the world. Despite its widespread use, the current design requires physical servers hosted on premises. While cloud-based deployment would alleviate this burdensome requirement and improve SecureDrop's usability and accessibility, it would also introduce new threats to security that are not addressed by the current design. In particular, a lack of end-to-end encryption presents serious risks in the event that a cloud service provider is coerced into revealing information. In this work, we present and formally analyse a new protocol for SecureDrop which addresses the challenges of off-premises deployment. Our protocol composes an encryption scheme with hybrid post-quantum guarantees and an identity-hiding message-fetching mechanism to provide strong anonymity guarantees. In contrast to existing systems, we minimise incriminating evidence against whistleblowers by providing message-level deniability and by having sources remain stateless. Our formal security analysis combines the Tamarin prover for symbolic analysis and game-based proofs for computational analysis. Finally, our benchmarks demonstrate that the protocol achieves practical levels of performance in a browser context. The Freedom of the Press Foundation plans to deploy the new protocol, with integration efforts beginning in 2026. Source Server Journalist Newsroom News Organisation Setup (Section 4.1.1) Journalist key generation (Section 4.1.3) Source key generation (Section 4.1.2) Source → Journalist Key fetching (Section 4.1.4) Message sending (Section 4.1.5) Message retrieval (Section 4.1.7) Journalist → Source Key fetching (Section 4.1.4) Message sending (Section 4.1.5) Message retrieval (Section 4.1.7) Journalist Server Repeat for number of ephemeral key bundles