Social Hacking with                                 GlobaLeaks                  Secure and anonymous Open Source Whistlebl...
Whistleblowing                   • Whistleblower speaks up in the public                             interest on an issue ...
The WB ecosystemWednesday, December 28, 11
Whistleblowing                      International Network                   • A network of researchers and                ...
Existing platform                   • Anonymity is not technologically supported                   • Security is not verifi...
Wednesday, December 28, 11
Wednesday, December 28, 11
Wednesday, December 28, 11
Where WB is used                   • Old-Media and New-Media                   • Transparency Activism                   •...
LeakDirectory                   • Most comprehensive whistleblowing                             resource                  ...
Sounds good?Wednesday, December 28, 11
Why GlobaLeaks?                   • To promote whistleblowing across civil                             society            ...
GL Dependencies                                   =                                       GLOBALEAKSWednesday, December 28...
GlobaLeaks actors                   • Node Administrator                        •    Sets up and promotes a site on a Topi...
GlobaLeaks issues                   • Anonymous and secure by default                   • Simple to deploy                ...
GlobaLeaks                                       architecture                                                             ...
GlobaLeaks                                    deployment                   • Self contained system (ie: GlobaLeaks.exe)   ...
GL Cross-platform                   • Usable on Mobile, web, desktop, fax etc.Wednesday, December 28, 11
GlobaLeaks 0.1                   •         Resilient file upload                   •         Anonymity of WB               ...
GlobaLeaks 0.1                   • Demo!Wednesday, December 28, 11
GlobaLeaks 0.1 issues                   • Low responsiveness over Tor HS (white page                             effect)  ...
GlobaLeaks future                   • Modularized                   • GLClient and GLBackend separation                   ...
GLBackend                   • Flask                   • SQLAlchemy                   • Modular storage system             ...
GLClient                   • Backbone.js                   • Require.js for minify and uglify                   • Preloade...
Fax2social                   • Allows people to submit documents                             through fax machines         ...
Tor2web                   • Exposes Tor Hidden Services to the surface                             web                   •...
Let’s setup a                               GlobaLeaks node                   • Howto: https://github.com/globaleaks/     ...
Upcoming SlideShare
Loading in …5
×

Social hacking with GlobaLeaks

736 views

Published on

Slides of GlobaLeaks and Social Hacking workshop at 28C3.
More info on following links

* http://events.ccc.de/congress/2011/wiki/Workshops/GlobaLeaks

* http://events.ccc.de/congress/2011/wiki/SocialHacking_LeakDirectory

Published in: Technology, Career
0 Comments
2 Likes
Statistics
Notes
  • Be the first to comment

No Downloads
Views
Total views
736
On SlideShare
0
From Embeds
0
Number of Embeds
1
Actions
Shares
0
Downloads
5
Comments
0
Likes
2
Embeds 0
No embeds

No notes for slide

Social hacking with GlobaLeaks

  1. 1. Social Hacking with GlobaLeaks Secure and anonymous Open Source Whistleblowing platformWednesday, December 28, 11
  2. 2. Whistleblowing • Whistleblower speaks up in the public interest on an issue • Related to Transparency and Public Disclosure • Whistleblowing is not just WikileaksWednesday, December 28, 11
  3. 3. The WB ecosystemWednesday, December 28, 11
  4. 4. Whistleblowing International Network • A network of researchers and organizations dedicated to WB • Internation Whistleblowing Conference in LondonWednesday, December 28, 11
  5. 5. Existing platform • Anonymity is not technologically supported • Security is not verified by third parties • Closed source, no implementation details • Improvements are limited to vendors willWednesday, December 28, 11
  6. 6. Wednesday, December 28, 11
  7. 7. Wednesday, December 28, 11
  8. 8. Wednesday, December 28, 11
  9. 9. Where WB is used • Old-Media and New-Media • Transparency Activism • Citizen driven initiatives • Private and Public organizationsWednesday, December 28, 11
  10. 10. LeakDirectory • Most comprehensive whistleblowing resource • Community driven, wiki • In future it will allow WB the right site for their submission • http://leakdirectory.orgWednesday, December 28, 11
  11. 11. Sounds good?Wednesday, December 28, 11
  12. 12. Why GlobaLeaks? • To promote whistleblowing across civil society • Allow people to easily start a WB initiative • Be flexible to suit every needWednesday, December 28, 11
  13. 13. GL Dependencies = GLOBALEAKSWednesday, December 28, 11
  14. 14. GlobaLeaks actors • Node Administrator • Sets up and promotes a site on a Topic • Whistleblower • Has material to share on the Topic • Receivers • Is knowledgeable in the Topic and will make information into actionWednesday, December 28, 11
  15. 15. GlobaLeaks issues • Anonymous and secure by default • Simple to deploy • Easy to use by the WB in any environment • Customizable usability/security-anonymity tradeoffWednesday, December 28, 11
  16. 16. GlobaLeaks architecture Audience WhistleBlower Submission Output pre NGO ss download Node Administrator Targets node • the node administrator notification select a list of targets • A Tulip is createdWednesday, December 28, 11
  17. 17. GlobaLeaks deployment • Self contained system (ie: GlobaLeaks.exe) • Automatic exposure (Tor HS / Tor2web) • Can be published and indexed by LeakDirectory • Build Free Mobile ApplicationWednesday, December 28, 11
  18. 18. GL Cross-platform • Usable on Mobile, web, desktop, fax etc.Wednesday, December 28, 11
  19. 19. GlobaLeaks 0.1 • Resilient file upload • Anonymity of WB • Customizable submission fields (XML) • Submission receipt for WB-Receiver interaction • Unique, Temporary URI for tip access • Comment / Statistics • TorCheck (https://github.com/globaleaks/TorCheck) • Anonymity awareness for Whistleblower • Web widget for Anonymity checkingWednesday, December 28, 11
  20. 20. GlobaLeaks 0.1 • Demo!Wednesday, December 28, 11
  21. 21. GlobaLeaks 0.1 issues • Low responsiveness over Tor HS (white page effect) • Limitation of MVC framework • Not properly designed • Not modularized • Big code baseWednesday, December 28, 11
  22. 22. GlobaLeaks future • Modularized • GLClient and GLBackend separation • Future features on: https://github.com/ globaleaks/GlobaLeaks/issuesWednesday, December 28, 11
  23. 23. GLBackend • Flask • SQLAlchemy • Modular storage system • Modular notification systemWednesday, December 28, 11
  24. 24. GLClient • Backbone.js • Require.js for minify and uglify • Preloaded into browser • Let’s show some mockups of how it looks likeWednesday, December 28, 11
  25. 25. Fax2social • Allows people to submit documents through fax machines • Through in the internet kill switch use case • Automatic OCR • One number for each nation • Anonymizing of sender dataWednesday, December 28, 11
  26. 26. Tor2web • Exposes Tor Hidden Services to the surface web • Tomorrow we will go into more detailWednesday, December 28, 11
  27. 27. Let’s setup a GlobaLeaks node • Howto: https://github.com/globaleaks/ GlobaLeaks/wiki • Configuration: https://github.com/ globaleaks/GlobaLeaks/wiki/ Configurationfile • Let’s setup a GlobaLeaks node!!Wednesday, December 28, 11

×