← Back to list

How to Send a Secure Message

Photo by Nik on Unsplash

Liz Lucy Robillard · 2026-08-17 05:11 · 0 claps · 3.2 min read
#security #information-security #cyber-security-awareness #messaging
Open on Medium ↗

How to Send a Secure Message

Photo by Nik on Unsplash

Photo by Nik on Unsplash

Well, as I said before, Simplex.chat when downloaded from f-droid (Playstore alternative) is v cool. Signal is ok but packed with scripts as is Proton ..so anyway, here’s how to yak safely with chums or other friendly types

  1. Use a computer you control and get Tor but do it through Firefox and get it direct from Tor.

  2. For more separation, boot Tails from a USB drive.

  3. Open Tor Browser.

  4. Find the organisation's SecureDrop address from the organisation's website or the SecureDrop directory.

  5. Open the SecureDrop ".onion" address in Tor Browser.

  6. Follow the organisation's SecureDrop instructions.

  7. Remove metadata from files before uploading them.

  8. Do not include your name, email address, phone number, usernames or other identifying information unless needed.

  9. Upload the files and send the message.

  10. Save the codename SecureDrop gives you if you want to return for replies.

  11. Close SecureDrop and shut down Tails when finished.

It really can be this simple.

So it helps if you use a fresh, clean machine, or a computer that isn’t normally associated with you. You open Tor Browser. Through Tor, you find the official SecureDrop address — there is a list there-of the organisation you want to contact. You open its SecureDrop site and follow its instructions to send your message.

That's the basic process.

There are, however, a few things worth getting right so that you don't accidentally undo the privacy SecureDrop is designed to provide.

First: find the genuine SecureDrop address

Do not simply trust a random ".onion" address somebody has posted online.

Find the organisation’s SecureDrop details from a source you can verify — ideally the organisation’s own published SecureDrop instructions or the SecureDrop directory.

Then enter that address in Tor Browser.

SecureDrop is specifically designed for communication between sources and organisations such as newsrooms.

Second: separate this from your normal internet life

For stronger anonymity, don’t conduct the SecureDrop session alongside your normal accounts. Do not be logged in anywhere, that meta data and javascript crap is stalker stuff.

That means avoiding things such as:

  • logging into your normal email
  • Facebook
  • Google
  • personal cloud accounts
  • your usual social-media accounts

A dedicated environment such as Tails is preferable when the consequences of identification matter.

A public computer is not automatically safer. It may have logging, monitoring software, cameras, administrator controls or retained browser data. A computer you can control and boot into Tails can therefore be a better option.

Nice idea to remove meta data from files before doing anything with them.

*apology to security but this stuff is common knowledge to llm users, you need to start using evidence and actual science, sneaking about and stalking people is half the bloody problem we have, it enrages people and is violation- what kind of meat-head twat orders you to stalk for a living anyway sweetie?

SecureDrop can protect the communication route, but a document or photograph can itself contain identifying information.

Before uploading an attachment, consider its:

metadata.

Photographs can contain EXIF information.

Documents can contain author names, usernames, editing history, software information, dates and other properties.

Remove unnecessary metadata from a copy before sending it. Get your removers from f-droid.

Fourth: don't identify yourself in the message

You can have immaculate technical security and then type:

"As you know, I'm the only person working in the accounts department who attended Tuesday's 3:15 meeting…"

And there goes the anonymity.

Only include identifying details when they're actually necessary.

Fifth: keep the SecureDrop identity separate

SecureDrop may give you a generated codename that allows you to return and read replies.

Record it exactly as the SecureDrop instructions recommend.

Don't turn that codename into another password or username you use elsewhere.

The short version

Clean environment → Tor Browser → verify the organisation's SecureDrop address → open SecureDrop → remove identifying metadata from attachments → submit the message → securely retain the generated codename if you need to return.

That's it.

SecureDrop exists precisely because sending sensitive material shouldn't require you to be James Bond with a degree in network engineering.

The important part isn't making the procedure complicated.

It's making sure that, while using it, you don't accidentally carry your ordinary identity in with you.

Dola helped with this one, but as you prob know- the llm directory is useful.

Happy Monday. I had hot fresh baguette w butter, poached egg, nice mocha for breakfast and in uber control mode. Miffed but cool.

Liz Lucy Robillard

Photo by Shamin Haky on Unsplash

Photo by Shamin Haky on Unsplash


메타데이터
post_id
90d8af61fa12
slug
how-to-send-a-secure-message-90d8af61fa12
url
https://medium.com/@lizlucy1958/how-to-send-a-secure-message-90d8af61fa12
canonical_url
https://medium.com/@lizlucy1958/how-to-send-a-secure-message-90d8af61fa12
author_url
https://medium.com/@lizlucy1958
status
ok
fetched_at
2026-08-17 17:07:40