- By Charles HomansCharles Homans is a special correspondent for the New Republic and the former features editor of Foreign Policy.
WikiLeaks has caught a lot of grief from the media in the past year for its relative lack of concern for safeguarding the identities of individuals put at risk by its document dumps, so the organization is entitled to at least a small measure of Schadenfreude over the flak the Wall Street Journal has been getting today over the rollout of its own online drop box for leaked documents. The Journal site, SafeHouse, is the first of several WikiLeaks-inspired ventures that media organizations are launching (the New York Times and the Guardian, among others, have their own in the works) with the none-too-subtle aim of reaping the benefits of WikiLeaks without having to deal with its mercurial management.
In practice, this isn’t necessarily any less protection than a newspaper source would have under other circumstances in the United States — most states don’t have shield laws for journalists, and leakers basically have to take it on faith that the reporters they talk to are willing to go to jail if necessary to protect their anonymity (and reporters have a good track record of doing exactly that). All the same, it’s a little chilling to see it in writing.
The second problem is on the technical end of things. As the Atlantic‘s Alexis Madrigal reports, the Journal did build a number of safeguards into its submitting system:
SafeHouse runs on its own servers, separate from the servers that run the WSJ.com. File transfers occur through an encrypted connection and the documents themselves are encrypted, too. (Only a few Journal staffers will have the keys to unlock them.) Finally, the time that uploaded documents spend stored on computers with connections to the public Internet will be minimized by "a fairly complicated" internal document flow system.
But SafeHouse has taken a lot of heat from Internet security types on Twitter today for design flaws that make it less secure for anonymous users than the Journal suggests. Many of them have been pointed out by Internet anonymity guru Jacob Appelbaum — who, it should be noted, has worked closely with WikiLeaks for years — and are well-summarized here by Forbes‘s Andy Greenberg. Among other things, Appelbaum argues that users switching between unencrypted and encrypted versions of SafeHouse are vulnerable to programs that trick users into continuing to use the unencrypted version, rendering their data potentially accessible to third parties. None of the problems that have been pointed out are un-fixable kinks, but they’re a reminder that the buyer has to beware in the age of radical transparency.
Update: The Journal has posted a response to criticism of SafeHouse:
We take these issues very seriously. Development for eliminating the flash dependency, which is required for Tor compatibility, is complete, and we expect to implement the update within 48 hours. In addition, our system has been updated to limit the types of less secure connections it will accept. As is standard procedure, we will continue to assess new specifications and analyze any potential situation that may impact the privacy of our users.
Our priority is to ensure that SafeHouse fulfills its mission as a secure location that provides sources with access to highly skilled, experienced journalists.
Blake Hounshell is managing editor at Foreign Policy, having formerly been Web editor. Hounshell oversees ForeignPolicy.com and has commissioned and edited numerous cover stories for the print magazine, including National Magazine Award finalist "Why Do They Hate Us?" by Mona Eltahawy. He also edits The Cable, FP's first foray into daily original reporting, and was editor of Colum Lynch's Turtle Bay, which in 2011 won a National Magazine award for best reporting in a digital format.
Blake joined Foreign Policy in 2006 after living in Cairo, where he studied Arabic, missed his Steelers finally win one for the thumb, and worked for the Ibn Khaldun Center for Development Studies. Blake was a 2011 finalist for the Livingston Awards prize for young journalists for his reporting on the Arab uprisings, and his Twitter feed was named one of Time magazine's "140 Best Twitter Feeds of 2011." Under his leadership, in 2008, Passport, FP's flagship blog, won Media Industry Newsletter's "Best of the Web" award in the blog category. Along with Elizabeth Dickinson, he edited Southern Tiger: Chile's Fight for a Democratic and Prosperous Future, the memoirs of former Chilean president Ricardo Lagos, published by Palgrave Macmillan in 2012.
A graduate of Yale University, Blake speaks mangled Arabic and French, is an avid runner, and lives in Washington with his wife, musician Sandy Choi, and their toddler, David. Follow him on Twitter @blakehounshell.| Passport |