Definition
Practices, operational procedures and technical tools chosen and combined to protect journalist–source confidentiality and the integrity and confidentiality of sensitive reporting communications, including threat assessment, end‑to‑end encryption, metadata minimization, secure storage, verification processes and operational hygiene tailored to the journalist’s threat model.
Principle
Principle
Security requires layered defenses: technical measures (e.g., end‑to‑end encryption, encrypted storage), operational practices (source vetting, compartmentalization, minimal retention), and threat‑appropriate verification; no single tool or practice by itself guarantees confidentiality against all adversaries.
Demonstration
Demonstration
Illustrative scenario → Situation: A reporter expects hostile state surveillance capable of network interception. Recognition: the reporter assesses the adversary’s capabilities and the sensitivity of the source. Action: the reporter arranges an in‑person meeting for initial contact, uses an end‑to‑end encrypted channel with verified keys for follow‑up, employs ephemeral contact identifiers, encrypts notes at rest, and limits metadata exposure. Consequence: the likelihood of source exposure and message interception is reduced, though legal compulsion or endpoint compromise remain residual risks.
Misapplication
Misapplication
Relying on a single technology (e.g., using an encrypted app without key verification) or focusing only on message content while ignoring metadata, device compromise, operational routines, or legal compulsion; assuming tools alone confer immunity.
Consequence
Consequence
Properly implemented practices reduce the probability of source disclosure and data compromise and can enable reporting on sensitive matters; they also impose operational costs, may limit accessibility for some sources, and cannot eliminate all legal or technical risks.
Reversal
Reversal
When sources lack digital access or fear using tools, secure communication may require trusted offline methods or intermediaries; in jurisdictions with broad legal powers (compelled decryption, metadata retention), technical measures may need to be complemented by legal strategies and operational caution.
Boundary
Boundary
Clearly within: methods and tools for protecting communications between reporter and source. Boundary case: organization‑wide cybersecurity policies that include but extend beyond journalist–source communications. Clearly outside: general IT administration unrelated to source confidentiality (e.g., public website maintenance).
Semantic Tension
Semantic Tension
Confidentiality and source protection ↔ Verifiability, transparency, and editorial workflows that require retained records.
Synthesis
Synthesis
Secure communication is a threat‑driven, layered practice: technology matters, but its effectiveness depends on operational discipline, source capacity, and legal context; treating any single measure as sufficient is a category error.