Passphrase Best Practices — SecureDrop latest documentation (2024)

All SecureDrop users—Sources, Journalists, and Admins—are required tomemorize at least one passphrase. This document describes best practices forpassphrase management in the context of SecureDrop.

General Best Practices

  1. Do memorize your passphrase.

  2. If necessary, do write your passphrase down temporarily while youmemorize it.

    Caution

    Do store your written passphrase in a safe place, such as asafe at home or on a piece of paper in your wallet. Dodestroy the paper as soon as you feel comfortable that you havethe passphrase memorized. Do not store your passphrase onany digital device, such as your computer or mobile phone.

  3. Do review your passphrase regularly. It’s easy to forget a long orcomplex passphrase if you only use it infrequently.

    Tip

    We recommend reviewing your passphrase (e.g. by ensuring that youcan log in to your SecureDrop account) on at least a monthly basis.

  4. Do not use your passphrase anywhere else.

    If you use your SecureDrop passphrase on another system, a compromise of thatsystem could theoretically be used to compromise SecureDrop. You should avoidreusing passphrases in general, but it is especially important to avoid doingso in the context of SecureDrop.

For Sources

Your passphrase is associated with your pseudonymous account and all of youractivity on the SecureDrop server. In order to preserve your anonymity, youshould avoid creating physical or digital associations between yourself and yourpassphrase as much as possible.

For Journalists/Admins

While Sources only have one passphrase that they are required to manage,Journalists and Admins unfortunately have to manage a veritablemenagerie of credentials.

We have tried to minimize the number of credentials that Journalists andadmins actually have to remember by automating the storage and entryof credentials on the Tails workstations wherever possible. For example,a dedicated SecureDrop Menu is provided on each Tails workstation to make iteasy to access the onion services without having to look up their.onion addresses every time.

Ideally, each admin would only have to:

  1. Keep track of their Admin Workstation Tails USB.

  2. Remember the passphrase to unlock the persistent storage on that Tails USB.

And each Journalist would only have to:

  1. Keep track of their Journalist Workstation Tails USB.

  2. Keep track of their Secure Viewing Station Tails USB (and the associatedSecure Viewing Station computer).

  3. Remember the passphrases to unlock the persistent storage on both of theseTails USBs.

Memorizing further passphrases beyond the ones listed above is counterproductive:an attacker with access to any of those environments would be able to pivot toanything they wish to access, and increasing the burden of keeping track ofadditional credentials is unpleasant for journalists and admins andincreases the risk that they will either forget their credentials, compromisingthe availability of the system, or compensate for the difficulty by using weakor reused credentials, potentially compromising the security of the system.

There is a detailed list of the credentials that must be managed by each enduser role in Passphrases. We recommended using the KeePassXC passwordmanager included in Tails to store your credentials and minimize the passphrasesthat you need to memorize to just the passphrases for the persistent storage onyour Tails USBs.

For the Transfer Device and the Export Device, which are used to copyfiles to and from the air-gapped Secure Viewing Station, we recommend usingencrypted USB drives with passphrases stored in the journalist’s own passwordmanager (preferably one which is accessible on their smartphone). This ensuresthat the journalist will have quick access to these passphrases when they needthem.

If your organization is not using a password manager already, please seethe Freedom of the Press Foundation guideto choosing one.

Passphrase Best Practices — SecureDrop latest documentation (2024)
Top Articles
Life Science: Career Guides: Career Exploration & Student Employment: Indiana University Bloomington
Helium One Global Share Price - LON:HE1 Stock Research
Jail Inquiry | Polk County Sheriff's Office
Wisconsin Women's Volleyball Team Leaked Pictures
Archived Obituaries
Mychart Mercy Lutherville
FFXIV Immortal Flames Hunting Log Guide
Chris wragge hi-res stock photography and images - Alamy
AB Solutions Portal | Login
2013 Chevy Cruze Coolant Hose Diagram
Planets Visible Tonight Virginia
12 Best Craigslist Apps for Android and iOS (2024)
18443168434
Slushy Beer Strain
C Spire Express Pay
ocala cars & trucks - by owner - craigslist
Seattle Rpz
Alejos Hut Henderson Tx
Voy Boards Miss America
Classic | Cyclone RakeAmerica's #1 Lawn and Leaf Vacuum
10 Fun Things to Do in Elk Grove, CA | Explore Elk Grove
Mychart Anmed Health Login
Drift Boss 911
Melissababy
Amortization Calculator
Panolian Batesville Ms Obituaries 2022
Shadbase Get Out Of Jail
Colonial Executive Park - CRE Consultants
Cognitive Science Cornell
800-695-2780
Tinyzonehd
Lindy Kendra Scott Obituary
What we lost when Craigslist shut down its personals section
Turns As A Jetliner Crossword Clue
Weather Underground Durham
Viduthalai Movie Download
Die wichtigsten E-Nummern
Elanco Rebates.com 2022
Workboy Kennel
2024 Coachella Predictions
Poster & 1600 Autocollants créatifs | Activité facile et ludique | Poppik Stickers
Craigslist Albany Ny Garage Sales
2012 Street Glide Blue Book Value
Domino's Delivery Pizza
Dynavax Technologies Corp (DVAX)
Priscilla 2023 Showtimes Near Consolidated Theatres Ward With Titan Luxe
Cdcs Rochester
Gotrax Scooter Error Code E2
Aurora Southeast Recreation Center And Fieldhouse Reviews
303-615-0055
Obituary Roger Schaefer Update 2020
7 National Titles Forum
Latest Posts
Article information

Author: Kieth Sipes

Last Updated:

Views: 5958

Rating: 4.7 / 5 (47 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Kieth Sipes

Birthday: 2001-04-14

Address: Suite 492 62479 Champlin Loop, South Catrice, MS 57271

Phone: +9663362133320

Job: District Sales Analyst

Hobby: Digital arts, Dance, Ghost hunting, Worldbuilding, Kayaking, Table tennis, 3D printing

Introduction: My name is Kieth Sipes, I am a zany, rich, courageous, powerful, faithful, jolly, excited person who loves writing and wants to share my knowledge and understanding with you.