A Secure Submission System for Online Whistleblowing Platforms
Volker Roth, Benjamin G\"uldenring, Eleanor Rieffel, Sven Dietrich,, Lars Ries

TL;DR
The paper introduces AdLeaks, an innovative online submission system that uses ubiquitous online ads to enable whistleblowers to submit disclosures anonymously and untraceably, even under high surveillance.
Contribution
It presents the design and analysis of AdLeaks, a novel system leveraging online advertising to ensure sender unobservability for whistleblowing disclosures.
Findings
AdLeaks provides high probability of receiving disclosures with minimal traffic processing.
The system ensures complete sender unobservability even under increased network surveillance.
Performance analysis confirms the feasibility of deploying AdLeaks at scale.
Abstract
Whistleblower laws protect individuals who inform the public or an authority about governmental or corporate misconduct. Despite these laws, whistleblowers frequently risk reprisals and sites such as WikiLeaks emerged to provide a level of anonymity to these individuals. However, as countries increase their level of network surveillance and Internet protocol data retention, the mere act of using anonymizing software such as Tor, or accessing a whistleblowing website through an SSL channel might be incriminating enough to lead to investigations and repercussions. As an alternative submission system we propose an online advertising network called AdLeaks. AdLeaks leverages the ubiquity of unsolicited online advertising to provide complete sender unobservability when submitting disclosures. AdLeaks ads compute a random function in a browser and submit the outcome to the AdLeaks…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Spam and Phishing Detection · Network Security and Intrusion Detection
