Apple SWOT Analysis,

Financial Donation methods


Currently accepting submissions of whistleblower leaks ?


Explicit promises about Anonymity, Privacy or Security


Restrictive legal Terms & Conditions


Practical Advice on preserving Whistleblower Anonymity


Leak Submission Encryption

Digital Certificate fingerprints published on their website:


Qualsys SSLLabs SSL Server Test rating:


Overall rating: **A [85]**

Certificate: 100

Protocol Support: 85

Key Exchange 80

Cipher Strength: 90

PGP Public Encryption Key

URL to web page or downloadable .asc text file

Link to a key Public PGP Keyserver e.g.


PGP ID: 0xB2531933

Created: 31/07/2011

Expires: 03/09/2012

Type: RSA 4096/4096

Cipher: AES-256

PGP fingerprint: C376 54B8 01E7 4648 FF92 B7CF 9B98 3E17 B253 1933

TOR Hidden Service


I2P eepsite




Hushmail Secure Form


Leak Submission Anonymity

Some of these techniques are appropriate for a normal website like this wiki, but not for whistleblower or tipoff websites, where potential whistleblower source anonymity protection should be paramount:

TOR users blocked from access


3rd Party or persistent tracking cookies or graphics


CAPTCHA graphics generated from another website e.g. GoogleRe-Captcha


Mixed mode non-SSL graphics or style sheets


Embedded video clips or deep linked graphics etc. from another website e.g. YouTube


Flash file uploader class


Communications / Acknowledgement back to the whistleblower via the website

Acknowledgement of receipt of information

e.g. file upload success indicator - has the leak message or upload actually been received successfully ?


Leak analysis work flow status reporting

e.g. Has anyone actually looked at what the whistleblower has submitted ?


Private message box

e.g for 2 way communications back to the anonymous whistleblower, asking for clarification, offering advice etc.


Domain Name Resilience

The threats of legal court proceedings against Domain Name Registrars and Domain Name Service providers are lessons which WikiLeaks.org emulators should take note of:

Domain Name Registrar

Multiple Internet Service Providers, in different legal jurisdictions ?


Domain Name Server(s) & jurisdiction(s)

Alternate Domain Name aliases


Actual Physical Mirrors of the website:


Content available via BitTorrent etc P2P etc.


Hosting of Mirrors of other whistleblowing websites


Open Source software published


