up:: For Press
Protecting your sources
Every other page here is about the people you write for. This one is about you.
If you communicate with sources electronically, your traffic sits in the same collection this whole resource describes. A source’s identity needs to stay confidential for their working life and often longer, which is exactly the confidentiality horizon that makes data worth storing today to read later.
The good news is real and specific: the messaging tool most newsrooms already use was among the first systems anywhere to deploy post-quantum protection, in 2023. The bad news is that email was not, and most source contact still starts with email.
The short version:
- A source’s identity has a lifetime horizon, which is the property that makes traffic worth collecting now.
- Metadata is usually more dangerous than content. Who contacted whom, and when, identifies a person without reading a word.
- Signal deployed post-quantum protection in 2023, ahead of nearly everything else.
- Email did not, and it remains where most source contact begins.
- This has happened before. A 2011 certificate breach exposed the email of roughly 300,000 Iranian users behind a padlock that looked correct.
- Communications already sent cannot be retrieved. That’s the part with no remedy.
Why does this reach reporting specifically?
Because source protection is one of the few obligations that genuinely runs for a lifetime.
Most data stops mattering. A source’s identity does the opposite: in many cases the risk to them grows as a story’s consequences unfold, and in hostile jurisdictions the exposure is physical rather than professional. A promise of confidentiality made in 2026 is a promise about 2046.
That’s precisely the profile that makes recorded traffic worth storing. An adversary deciding what to keep is looking for material whose value survives a decade of storage, and a journalist’s contact history qualifies more cleanly than almost anything else.
The agencies describing this concern named the pattern in general terms: attackers “could be targeting data today that would still require protection in the future.”
Source: CISA, NSA, and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 21, 2023, cisa.gov.
What is actually exposed, the content or the contact?
The contact, and this is the part most coverage of encryption gets backward.
Reading the text of an exchange is damaging. Establishing that a particular person contacted a particular reporter, on a particular date, is frequently sufficient on its own, and it requires no decryption of message bodies at all where the surrounding information travels unprotected.
| What travels | Typical protection | What it reveals |
|---|---|---|
| Message content | Strong end-to-end encryption in modern messengers | What was said |
| Who contacted whom | Varies enormously by tool | The identification, often by itself |
| When, and how often | Rarely protected as strongly as content | Correlation with a publication date |
| Email headers | Routinely exposed in transit and stored by providers | Sender, recipient, timing, subject |
| Phone records | Held by carriers under retention rules | Contact patterns |
A tool that protects content perfectly and leaks the contact pattern has not protected the source. That’s true today, with no quantum computer involved, and a later decryption of stored traffic makes the same problem retroactive.
What has already happened?
In 2011 a Dutch certificate authority was breached and the attacker minted at least 531 fraudulent certificates. One was used to intercept the email of roughly 300,000 users in Iran. Those included dissidents, journalists, and ordinary citizens, and their browsers displayed a valid padlock throughout, because the certificates were mathematically correct.
Source: Fox-IT, “Black Tulip: Report of the investigation into the DigiNotar Certificate Authority breach,” 2012, Fox-IT Black Tulip report, hosted by ENISA.
That incident needed no quantum computer, only a compromised authority. The relevance here is the shape rather than the method: the padlock was showing, the encryption was working as designed, and the people relying on it were being read anyway.
What is already protected, and what is not?
| Tool | Post-quantum status | What that means for sources |
|---|---|---|
| Signal | Deployed in 2023 | The strongest widely available option, and the one to move sensitive contact to |
| Apple iMessage | Deployed February 2024 | Protected between Apple devices |
| Web traffic (Chrome, Edge, Firefox) | Deployed 2024 to 2025 | Your connection to a web-based tip form is likely protected |
| Largely not | Content and headers both. This is the significant gap | |
| SMS | No | Never appropriate for source contact, for older reasons than this one |
| Most collaboration tools | Varies, usually not | Worth asking your organization directly |
Source: Signal, “PQXDH,” signal.org; Apple Security Research, “iMessage with PQ3,” February 2024, security.apple.com; Google Security Blog, September 2024, security.googleblog.com; Mozilla, Firefox 135 release notes, mozilla.org.
The email gap is the practical finding. Most source relationships begin with an email, often before either party has judged how sensitive the material will become. That first message is frequently the one that establishes the connection, and it’s the least protected thing in the sequence.
What can you actually do?
Six things, in order of how much they change.
- Move sensitive contact to Signal early, rather than after a story turns sensitive. The protection applies from the first message, and the first message is often the identifying one.
- Treat email as a public channel for source identification. Use it to move a conversation elsewhere rather than to conduct one.
- Use your organization’s secure tip system where one exists, since these are built to limit what metadata is retained at all.
- Minimize what exists. Communications that were never created cannot be collected, and contact that happened offline leaves no record to store.
- Delete on a schedule, and know your organization’s retention. Archives held for legal reasons are archives an adversary would also value.
- Ask your organization what it runs. The question that works is the same one this Guide gives everyone else: can you produce an inventory of where your cryptography lives, and what’s the post-quantum timeline for our communications tools?
What cannot be fixed?
Communications already sent.
If a source’s contact with you crossed a network under the older encryption, and somebody recorded it, no action now changes that. Migrating today protects future contact and does nothing for past contact. This is the same retroactive property described everywhere else in this resource, and for source protection it’s the part with genuine consequence.
Two honest qualifications. Nobody can tell you whether any particular traffic was collected, because collection leaves no trace. And the overwhelming majority of communications, including most journalistic ones, will never be worth an adversary’s storage and attention.
What follows from that is a proportionate response rather than alarm: identify the small number of source relationships where exposure would be genuinely dangerous, and treat those differently from the rest.
Questions people ask
Is Signal actually enough? For content, it’s the strongest widely available option and it has been post-quantum since 2023. It doesn’t erase the fact that the two of you communicated, so the operational question of how the contact was established still matters.
Does my newsroom’s encrypted email help? It protects content in transit and typically leaves headers exposed. Headers alone are frequently sufficient to identify a source.
Should I stop using email with sources? Use it to move the conversation, not to hold it. The realistic goal is limiting what the first contact reveals.
What about my notes and files? Stored material follows the same rules as any organization’s data. See What is technically happening to our systems.
Are my past stories’ sources at risk? Unknowable, and for most, no. The relationships worth reviewing are the ones where identification would still endanger someone in 10 or 20 years.
Should I tell sources about this? For high-risk sources, a plain sentence about which channel you’d prefer is more useful than an explanation of the underlying problem.
Does this change how I report the story? It shouldn’t. It’s disclosed here because the resource covers who’s exposed, and reporters are on that list.
Where to go next
- Is someone stealing my data right now covers the collection itself.
- Did my phone already fix this covers what has shipped, with dates.
- What of mine is worth stealing covers the lifetime-horizon question generally.
- If you are a high-risk person covers people whose exposure is a safety question.
- For Press returns to the index.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.