Independent Tor encyclopedia Guides
Guides

Source vs Journalist Path

A role map of SecureDrop: how the source path (Tails, public onion) differs from the journalist path (workstation, then air-gap) — not a leak walkthrough.

Source path versus journalist path Two rows. Source: Tails live USB, then a public onion, and no air-gap role. Journalist: Tails workstation, authenticated onion, then an air-gapped viewing station. ROLE 01 Tails 02 Onion 03 Air-gap SOURCE Live USB Amnesic session Public drop Checked v3 onion Not this role No decrypt here JOURNALIST Workstation Separate Tails box Auth interface Fetch ciphertext Viewing station Decrypt offline Tails → onion → air-gap. Two jobs, one system — not a leak walkthrough. SOURCE 01 Tails — live USB Amnesic session 02 Onion — public drop Directory-checked onion 03 Air-gap — not this role JOURNALIST 01 Tails — workstation Separate Tails box 02 Onion — auth interface Fetch ciphertext only 03 Air-gap — viewing station Decrypt offline
Source: Tails → verified public onion → submit (no air-gap). Journalist: Tails workstation → authenticated onion → transfer stick → air-gapped viewing station. Two jobs, one system.

Short answer: SecureDrop is two jobs on one system. The source reaches a public onion — often from Tails. The journalist uses a separate Tails workstation to fetch ciphertext, then decrypts only on an air-gapped viewing station. The picture is Tails → onion → air-gap. This page maps those roles. It is not instructions to leak anything.

Canon lives at Freedom of the Press Foundation and SecureDrop. How a reader checks the onion: verify a newsroom onion. Broader context: press freedom.

Source path

  1. Prefer a Tails live session (amnesic). A normal OS keeps install logs even when the circuit is clean. SecureDrop’s overview also names Tor Browser; Tails is the stronger default.
  2. Verify the newsroom onion against the FPF directory and the outlet landing page: verify a newsroom onion.
  3. Strip photo and PDF metadata from files you created before upload.
  4. Submit on the public source onion. No account, no mail provider in the middle. Submissions are encrypted on the newsroom’s application server as they arrive.
  5. Do not open newsroom downloads in a host app on a live PC: don’t open downloaded files while online.

The source does not run an air-gapped viewing station. That is the journalist role.

Journalist path

Journalists do not open submissions on the office laptop. SecureDrop’s journalist guide is a two-machine ritual:

  1. Journalist Workstation — Tails USB. Connects to an authenticated onion (not the public source address). Downloads GPG-encrypted bundles.
  2. Transfer device — a stick or DVD, physically moved.
  3. Secure Viewing Station — air-gapped, also Tails. Holds the submission private key. Decrypt, read, print. Decrypted files stay off the internet unless the newsroom later publishes them on purpose.

Some newsrooms now run SecureDrop Workstation on Qubes, which folds those steps into isolated VMs on one machine (networkless qubes for keys and viewing). The role split is the same: fetch over Tor, open without a path back to the net.

OnionShare and email are not this diagram

OnionShare hosts a file on your PC. Useful between two people who can stay online together. OnionShare’s docs call receive mode a simpler, not-as-secure cousin of SecureDrop: no newsroom air-gap, no second key on an offline box, and whoever has the address can hit the share.

Email — even encrypted — still leaves a provider who can be asked who spoke to whom. SecureDrop’s purpose statement is to take that third party out. Signal and a tip page are first-contact tools FPF documents separately; they are not a substitute for the air-gap once documents are in the newsroom.

Sources

See also: verify a newsroom onion, OnionShare.