We're grateful to @torproject@mastodon.social and Funding the Commons for including us in this crowdfunding campaign alongside nine other cool projects as a new way to fund internet freedom!
SecureDrop
mastodon 4.7.2Free and open source whistleblower submission platform. A @freedomofpress@social.freedom.press project.
Web applications are only as trustworthy as the servers that serve them, and servers can get hacked. That’s why we are introducing WEBCAT, a tool allowing web browsers to verify the origin of code before they run it.
🌞 Today, WEBCAT enters alpha testing! If you like to experiment with cutting-edge software, give it a try:
https://securedrop.org/news/webcat-alpha/
SecureDrop 2.16.0 is now available, with a number of improvements to APIv2, and a fix for a low-severity security vulnerability:
The inaugural release of SecureDrop Inbox is now available! 🎉
The Inbox is a full rewrite of our client, and includes many new features and performance improvements for journalists.
Tor is a critical component that helps make SecureDrop an effective tool for connecting journalists with anonymous sources.
Learn more about @torproject@mastodon.social's efforts to Free the Internet: https://blog.torproject.org/2025-fundraiser-donations-matched/
SecureDrop Inbox 1.4.0 is now available!
This release fixes a number of accessibility-related issues and fully removes the legacy client package:
https://securedrop.org/news/securedrop-inbox-1_4_0-released/
SecureDrop Inbox 1.3.2 is now available!
This update adds warnings and safeguards when deleting large numbers of sources.
SecureDrop 2.15.1 is now available, improving memory management while handling APIv2 requests, and fixing an issue with restoring backups without transferring over the network:
SecureDrop Inbox 1.2.0 is now available! This release increases the number of results returned by search, improves file handling and sync performance, and carries out other internal cleanup.
SecureDrop Inbox 1.1.0 is now available!
This version fixes a number of small issues that didn’t make it into the previous release.
RE: @securedrop@social.freedom.press
We're getting closer to the release of the brand new SecureDrop Inbox — today we're publishing results from the security audit we commissioned to ensure it's safe before putting it in the hands of journalists.
https://securedrop.org/news/audit-of-securedrop-inbox-completed/
SecureDrop Inbox, the new window into the SecureDrop Workstation, has been rewritten from the ground up to replace the previous client application for existing journalist users.
Improving upon the core functionality, it also includes bug fixes, speed improvements, and a range of new features.
https://securedrop.org/news/new-features-in-securedrop-inbox/
SecureDrop Workstation 1.6.2, for Qubes 4.2, and 1.7.1, for Qubes 4.3, are now available!
These releases remove the legacy SecureDrop Client and enable an upgrade script to make preparing for the Qubes 4.3 upgrade simpler.
https://securedrop.org/news/securedrop-workstation-1_6_2-and-1_7_1-released
SecureDrop Client, which has been replaced by SecureDrop Inbox, is now end-of-life.
https://securedrop.org/news/securedrop-client-is-end-of-life/
SecureDrop 2.16.1, which fixes a low-severity security issue, is now available.
If your instance was affected, administrators will need to take manual action to rotate credentials.
https://securedrop.org/news/advisory-securedrop-2_16_1-released
SecureDrop Workstation 1.5.2 has been released, as well as SecureDrop Client 0.17.4.
This update contains multiple security fixes, all of which are low or informational priority. We are not aware of any exploitation in the wild for any vulnerability.
https://securedrop.org/news/securedrop-workstation-1_5_2-released/
Qubes 4.2 is now end-of-life. All SecureDrop Workstation users should be using Qubes 4.3.
If you have not upgraded, please contact support immediately.
SecureDrop Inbox 1.3.0 is now available!
This release adds a label to show the number of selected sources, disables downloading of files in offline mode, and updates a number of dependencies.
We are looking for a contract security-focused developer to work on WEBCAT (https://github.com/freedomofpress/webcat), a browser extension and a few other components that bring code integrity and transparency to the web.
Read more and submit a proposal here:
SecureDrop Workstation 1.7.0 has been released!
This is a Qubes 4.3-only release, and takes advantage of some of its new features to provide a more robust and secure way for journalists to review submissions.
https://securedrop.org/news/securedrop-workstation-1_7_0-released
Journalists are increasingly relying on insider sources, and protecting those sources is more important than ever.
Here's how SecureDrop is rising to the challenge, safeguarding whistleblowers’ anonymity against ever-evolving threats.
What does it take to make web applications auditable?
Here's why reproducibility matters, and how WEBCAT—a framework for signing and verifying web applications—approaches the problem in practice.
https://securedrop.org/news/webcat-towards-auditable-web-application-runtimes/
SecureDrop is bringing our WEBCAT and SecureDrop Protocol projects to the Real World Crypto Symposium on March 9-11 in Taipei, Taiwan.
We’ll be presenting on establishing trust in web applications and on the next generation of SecureDrop!
Read more: https://securedrop.org/news/real-world-crypto-2026/
SecureDrop Client 0.17.2 has been released! This release addresses potential undefined behavior in a dependency.
https://securedrop.org/news/securedrop-client-0_17_2-released/
SecureDrop 2.14.0 has been released. This release ensures KeePassXC remains installed on Tails. It also lays groundwork for the upcoming SecureDrop App.
SecureDrop is building the next generation of anonymity tools for whistleblowers. SecureDrop software engineer Cory Myers and ETH Zurich researcher Felix Linker gave a talk in Montreal earlier this month about our new, custom messaging protocol:
SecureDrop 2.13.0 is now available. This release primarily provides the securedrop-admin tool as a Debian package within Tails, and prepares for future availability of the securedrop-admin utility on Qubes OS.
SecureDrop Workstation 1.6.1 is now available, allowing administrators to begin the process of upgrading to Qubes 4.3.
https://securedrop.org/news/workstation-qubes-4_3-upgrade-available/
SecureDrop Client 0.17.1 has been released! This release addresses a low-impact, high-complexity denial-of-service issue:
https://securedrop.org/news/securedrop-client-0_17_1-released/
SecureDrop Workstation 1.5.0 has been released! This version simplifies the installation process by allowing you to install a bootstrap package from the Qubes-Contrib repo, and removes the remaining dependencies on Whonix.
https://securedrop.org/news/securedrop-workstation-1_5_0-released/
SecureDrop 2.15.0 is now available, which enables the updated API needed for the upcoming SecureDrop Inbox.
SecureDrop 2.12.10 has been released. This is a Journalist and Admin Workstation-only release, which adds support for the recent Tails 7 version.
SecureDrop Client 0.17.5 has been released to address a low-priority security issue. Exploiting this vulnerability would require a compromised server, and we are not aware of any exploits in the wild.
https://securedrop.org/news/securedrop-client-0_17_5-released
SecureDrop Workstation 1.4.0 has been released! This version integrates Tor directly in the sd-proxy VM instead of using Whonix, and fixes an issue that prevented USB devices from automatically attaching.
https://securedrop.org/news/securedrop-workstation-1_4_0-released
SecureDrop Workstation 1.5.1 has been released! This minor fix addresses a Tails config location change found in version 2.13.0 of the SecureDrop server.
https://securedrop.org/news/securedrop-workstation-1_5_1-released/
We're simplifying how SecureDrop Workstation is installed!
Previously, users needed to manually download and verify an OpenPGP key; now we're eliminating that step without compromising on security.
Learn more in our blog post: https://securedrop.org/news/bootstrapping-securedrop-workstation-via-qubes-contrib/
SecureDrop Inbox 1.3.1 is now available!
This release fixes a low-priority security issue in the securedrop-proxy component.