PART 20 · 🔴

Anonymity & OPSEC

For the pseudonymous account and the whistleblower. Here you no longer protect just a message: you protect an identity.

Pseudonymity vs anonymity

The golden rule: never cross your real identity with your public one. Not the same email, number, device, network, posting hours or writing style. A single leak links the two.

  • Identity-less accounts : SimpleX and Session need no number; pair them with disposable email aliases. Beware resold, traceable “virtual numbers”.
  • Clean metadata : a posted photo often carries the date, device model and sometimes GPS coordinates (EXIF data). Strip it with Metadata Cleaner, mat2 or ExifTool before posting; watch file names and document metadata too.
  • Network anti-correlation : use Tor/Tails to decouple your activity from your home IP. Never mix your personal and pseudonymous networks. A SIM in your name betrays your location no matter what else you do.
  • Compartmentalisation : a device, or at least a profile, dedicated to the public identity, a separate password manager, and never a cross-login between the two worlds.

Passing documents as a source

SecureDrop is the anonymous submission system many newsrooms use to receive documents from sources. Many outlets also publish a PGP key and a Signal contact. Never submit from your work hardware or usual network.

Honesty, don’t overestimate yourself

Strong anonymity against a state adversary is hard and fallible. This guide gives bearings, not guarantees. If lives depend on it, train with the authoritative references: EFF Surveillance Self-Defense, Freedom of the Press Foundation, Privacy Guides. Strictly defensive and journalistic context.

Not sure where to start? Take the 12-question quiz →