An open-source whistleblower submission system — a project of @FreedomofPress Foundation
Joined October 2013
- Tweets1K
- Following48
- Followers17.2K
- Likes42
We have updated our guidance for sources, to warn against using AI chatbots or services linked to their personal identity.
We also strongly recommend that newsrooms using SecureDrop update their landing pages with these new warnings.
securedrop.org/news/updated-…
SecureDrop Inbox 1.7.0 is now available!
This release makes the sidebar width adjustable, lays the groundwork for right-to-left languages, and provides a number of correctness fixes.
securedrop.org/news/securedr…
We will be rotating the SecureDrop release signing key next year.
This is a routine signing key rotation; the current key is still secure and in active use.
The new key will be distributed in releases later this year and start signing releases in 2027.
securedrop.org/news/new-rele…
SecureDrop Workstation 1.9.0 is now available!
This release hardens the updater against some edge cases discovered during the 1.8.0 release.
securedrop.org/news/securedr…
SecureDrop Inbox 1.6.0 is now available!
This release adds support for double-encrypted messages and files, improves the source menu, and includes a small speedup to the sync process.
securedrop.org/news/securedr…
"It could be as significant an upgrade as HTTPS."
A nice explainer of WEBCAT, our project to make JavaScript tamper-proof and the web a safer place for everyone:
blog.siv.org/2026/07/verifia…
WEBCAT improves the security baseline
“Not just for high-stakes tools like SecureDrop, even an ordinary password login screen — every bank, email, and social account on the web — could finally adopt, and prove, designs where your raw password never leaves your device"
Verifiable Web Code — Why It's So Exciting
by @dsernst
blog.siv.org/2026/07/verifia…
SecureDrop Workstation 1.8.0 and SecureDrop Inbox 1.5.0 are now available!
These releases add support for Debian 13 “trixie” and automatically upgrade the underlying VMs.
securedrop.org/news/securedr…
SecureDrop 2.16.1, which fixes a low-severity security issue, is now available.
If your instance was affected, administrators will need to take manual action to rotate credentials.
securedrop.org/news/advisory…
SecureDrop 2.16.0 is now available, with a number of improvements to APIv2, and a fix for a low-severity security vulnerability:
securedrop.org/news/securedr…
Qubes 4.2 is now end-of-life. All SecureDrop Workstation users should be using Qubes 4.3.
If you have not upgraded, please contact support immediately.
securedrop.org/news/qubes-4_…
SecureDrop Inbox 1.4.0 is now available!
This release fixes a number of accessibility-related issues and fully removes the legacy client package:
securedrop.org/news/securedr…
SecureDrop Inbox 1.3.2 is now available!
This update adds warnings and safeguards when deleting large numbers of sources.
securedrop.org/news/securedr…
SecureDrop Workstation 1.6.2, for Qubes 4.2, and 1.7.1, for Qubes 4.3, are now available!
These releases remove the legacy SecureDrop Client and enable an upgrade script to make preparing for the Qubes 4.3 upgrade simpler.
securedrop.org/news/securedr…
SecureDrop Inbox 1.3.1 is now available!
This release fixes a low-priority security issue in the securedrop-proxy component.
securedrop.org/news/securedr…
SecureDrop Client, which has been replaced by SecureDrop Inbox, is now end-of-life.
securedrop.org/news/securedr…
SecureDrop Workstation 1.6.1 is now available, allowing administrators to begin the process of upgrading to Qubes 4.3.
securedrop.org/news/workstat…
SecureDrop Inbox 1.3.0 is now available!
This release adds a label to show the number of selected sources, disables downloading of files in offline mode, and updates a number of dependencies.
securedrop.org/news/securedr…