OnionShare lets you send files securely and anonymously
Posted on 22 May 2014.
A new programming project that allows users to send files anonymously over Tor has been made available on GitHub by its author Micah Lee, former staff technologist at the EFF and the current one at The Intercept, the investigative online publication run by Glenn Greenwald, Laura Poitras, and Jeremy Scahill.

It's called OnionShare, and allows users to securely and anonymously share a file of any size with someone - even if that someone does not use OnionShare.

"It works by starting a web server, making it accessible as a Tor hidden service, and generating an unguessable URL access and download the file," Lee explained on the project page. "It doesn't require setting up a server on the internet somewhere or using a third party filesharing service. You host the file on your own computer and use a Tor hidden service to make it temporarily accessible over the internet. The other user just needs to use Tor Browser to download the file from you."

"OnionShare relies on Tor. You need to either have a system Tor installed, or you can open Tor Browser so that OnionShare can use the Tor server provided there," he added. "At the moment OnionShare is a command line program. It works in normal desktop GNU/Linux distributions, Tails, and Mac OS X (Windows coming soon)."

When the intended recipient follows the sent link and loads the website hosting it in the Tor Browser, a direct link is formed between the two computers, and the file is downloaded directly from the sender's computer (preferably in encrypted form).

The recipient doesn't (have to) know who sent the link and made the file available for download, making this a perfect tool for whistleblowers who wish to remain anonymous.

Once the server set up by the "sender" is shut off, the file becomes inaccessible once again.


DMARC: The time is right for email authentication

Posted on 23 January 2015.  |  The DMARC specification has emerged in the last couple years to pull together all the threads of email authentication technology under one roof—to standardize the method in which email is authenticated, and the manner in which reporting and policy enforcement is implemented.

Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.

Daily digest

Receive a daily digest of the latest security news.

Mon, Jan 26th