Wall Street Journal faces backlash over WikiLeaks rival

SafeHouse criticised as a 'total anonymity failure' by web security and privacy experts

The Wall Street Journal is facing a backlash from web security and privacy experts over its WikiLeaks-inspired whistleblowers' site, SafeHouse.

SafeHouse, which launched on Thursday to allow anyone to upload documents to the Journal, has been described by one encryption analyst as a "total anonymity failure" that could compromise the security of whistleblowers.

Other researchers have told the Guardian that SafeHouse needs "basic improvements" and that – in its current state – should not have been launched.

"These are technical issues that only technical experts will notice," said Rik Ferguson, a security analyst at Trend Micro. "But given the kind of data that the Journal will hope to get from this, if I [was a whistleblower] there would absolutely be enough for me not to choose that site to upload to.

"There are certainly some relatively basic improvements that could and should have been made before the site went live."

Jacob Appelbaum, a security researcher and senior developer on the Tor online anonymity network, was also critical of SafeHouse: "They're negligent and this is the wrong project to beta-test on an open internet," he said.

Within hours of SafeHouse being launched, security experts pointed out that the site has an insecure way of redirecting whistleblowers who visit the unencrypted version of the site. "This leaves any potential whistleblower open to the chance of getting their traffic – and any documents they're uploading – intercepted by someone on the same network," said Ferguson.

SafeHouse's terms and conditions includes a disclaimer that it "cannot ensure complete anonymity" of whistleblowers who opt to use the most secure form of uploading to the site – and recommends using "cloaking" tools such as Tor, which hide the online identities of web users.

However, uploading from Tor did not work on Thursday or Friday when tested by security researchers. "This is quite worrying and makes you think that it's quite risky if you're going to put information on there," Paul Mutton, a web security tester, told the Guardian.

Mutton added it was also "surprising" the Journal had not opted for an independently-verified SSL certificate – as used by PayPal and other companies which transmit sensitive information – which notifies site visitors of its enhanced protection with a green address bar.

"Not only would this instil more confidence in submitters, but it would also be more difficult for someone else to impersonate the site," Mutton said.

SafeHouse is also facing criticism for its terms and conditions, which state the Journal "reserve[s] the right to disclose any information about you to law enforcement authorities or to a requesting third party, without notice, in order to comply with any applicable laws and/or requests under legal process [...]".

The Journal confirmed to the Guardian on Friday that it would shortly update SafeHouse in an attempt to eliminate some potential vulnerabilities.

Ashley Hutson, a spokeswoman for the Journal, said: "We take these issues very seriously. Development for eliminating the Flash dependency, which is required for Tor compatibility, is complete, and we expect to implement the update within 48 hours.

"In addition, our system has been updated to limit the types of less secure connections it will accept. As is standard procedure, we will continue to assess new specifications and analyse any potential situation that may impact the privacy of our users.

"Our priority is to ensure that SafeHouse fulfils its mission as a secure location that provides sources with access to highly skilled, experienced journalists."

• To contact the MediaGuardian news desk email editor@mediatheguardian.com or phone 020 3353 3857. For all other inquiries please call the main Guardian switchboard on 020 3353 2000. If you are writing a comment for publication, please mark clearly "for publication".

• To get the latest media news to your desktop or mobile, follow MediaGuardian on Twitter and Facebook.

Contributor

Josh Halliday

The GuardianTramp

Related Content

Article image
Wall Street Journal launches WikiLeaks-style site
SafeHouse service allows whistleblowers to upload documents. By Josh Halliday

Josh Halliday

05, May, 2011 @3:58 PM

Article image
Wall Street Journal rapped over climate change stance
Leading scientists, including climate change experts, complain about opinion piece akin to 'dentists practising cardiology'

Suzanne Goldenberg, US environment correspondent

01, Feb, 2012 @7:12 PM

Article image
Wall Street Journal circulation figures to be investigated
European edition of Rupert Murdoch's flagship title under scrutiny over allegations of artificially boosting sales figures. By Mark Sweney

Mark Sweney

13, Oct, 2011 @5:46 PM

Wall Street Journal waives online fees

7.45am: The Wall Street Journal's online version is to abandon charges during the crisis in America, writes Owen Gibson.

Owen Gibson

13, Sep, 2001 @3:31 PM

Article image
Phone hacking: Wall Street Journal wins ruling on reporting restrictions

US-based newspaper will be able to report fully report on the trial of Rebekah Brooks and others without signing written agreement. By Lisa O'Carroll

Lisa O'Carroll

17, Jan, 2014 @1:55 PM

Article image
Murdoch puts rebranded Wall Street Journal at centre of publishing push
Financial paper, to be renamed WSJ, likely to be business model as publisher seeks to generate revenue on multiple platforms. By Lisa O'Carroll

Lisa O'Carroll

29, Jun, 2012 @11:06 AM

Article image
Rupert Murdoch says Chinese hackers are still targeting Wall Street Journal
Media mogul tweets: 'Chinese still hacking us' as Communist newspaper accuses US of fanning fear of China

Tania Branigan in Beijing

06, Feb, 2013 @10:31 AM

New York Times and Wall Street Journal clash over 'anti-Obama' claims
WSJ hits back after rival states it has been 'tilting rightwards' and that owner Rupert Murdoch uses it to 'play politics'. By Stephen Brook

Stephen Brook

14, Dec, 2009 @6:24 PM

Article image
Wall Street Journal chief gets personal in battle with New York Times
Robert Thomson criticises NYT's 'journalistic elite' for producing 'social activist journalism' as WSJ launches metro section. By Ed Pilkington

Ed Pilkington in New York

26, Apr, 2010 @3:58 PM

Wall Street Journal restores online charges

11.15am update: WSJ.com has abandoned its free access just hours after dropping subscription charges. By Owen Gibson.

Owen Gibson

13, Sep, 2001 @10:24 AM