Tips
Documents, leads, a record someone hoped nobody would read. I read everything. I protect sources. I don't promise a story.
◇ Encrypted email
Encrypt to my PGP key and send to [email protected]
Check the fingerprint before you trust the key:
5D30 A33E 08E3 5B89 15B4 C7E2 E207 8E65 3FE3 89CD
- /pgp.txt · the armored key
- gpg --locate-keys [email protected] · fetched from this domain (WKD)
- keys.openpgp.org · keybase.io/ejfox
Encryption hides what you said, not that you said something. The subject line, the time and both addresses travel in the clear.
○ Before you send anything
- Use your own device on your own network. Work laptops and office Wi-Fi belong to someone who isn't you.
- Don't forward documents from a work account. Assume the logs remember who opened what, and when.
- Files carry their history: author names, edit trails, printer dots, the exact copy only five people received. Tell me how you got it and I'll work out what's safe to show.
- If you're the only person who could have known it, say so up front. Protecting you starts before anything is published.
- Timing is metadata. Sending the hour after a meeting narrows the list of who was in the room. If it can wait, let it.
Reporting a vulnerability in this site instead? See security.txt