up:: For Press

Protecting your sources

Every other page here is about the people you write for. This one is about you.

If you communicate with sources electronically, your traffic sits in the same collection this whole resource describes. A source’s identity needs to stay confidential for their working life and often longer, which is exactly the confidentiality horizon that makes data worth storing today to read later.

The good news is real and specific: the messaging tool most newsrooms already use was among the first systems anywhere to deploy post-quantum protection, in 2023. The bad news is that email was not, and most source contact still starts with email.

The short version:

  • A source’s identity has a lifetime horizon, which is the property that makes traffic worth collecting now.
  • Metadata is usually more dangerous than content. Who contacted whom, and when, identifies a person without reading a word.
  • Signal deployed post-quantum protection in 2023, ahead of nearly everything else.
  • Email did not, and it remains where most source contact begins.
  • This has happened before. A 2011 certificate breach exposed the email of roughly 300,000 Iranian users behind a padlock that looked correct.
  • Communications already sent cannot be retrieved. That’s the part with no remedy.

Why does this reach reporting specifically?

Because source protection is one of the few obligations that genuinely runs for a lifetime.

Most data stops mattering. A source’s identity does the opposite: in many cases the risk to them grows as a story’s consequences unfold, and in hostile jurisdictions the exposure is physical rather than professional. A promise of confidentiality made in 2026 is a promise about 2046.

That’s precisely the profile that makes recorded traffic worth storing. An adversary deciding what to keep is looking for material whose value survives a decade of storage, and a journalist’s contact history qualifies more cleanly than almost anything else.

The agencies describing this concern named the pattern in general terms: attackers “could be targeting data today that would still require protection in the future.”

Source: CISA, NSA, and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 21, 2023, cisa.gov.

What is actually exposed, the content or the contact?

The contact, and this is the part most coverage of encryption gets backward.

Reading the text of an exchange is damaging. Establishing that a particular person contacted a particular reporter, on a particular date, is frequently sufficient on its own, and it requires no decryption of message bodies at all where the surrounding information travels unprotected.

What travelsTypical protectionWhat it reveals
Message contentStrong end-to-end encryption in modern messengersWhat was said
Who contacted whomVaries enormously by toolThe identification, often by itself
When, and how oftenRarely protected as strongly as contentCorrelation with a publication date
Email headersRoutinely exposed in transit and stored by providersSender, recipient, timing, subject
Phone recordsHeld by carriers under retention rulesContact patterns

A tool that protects content perfectly and leaks the contact pattern has not protected the source. That’s true today, with no quantum computer involved, and a later decryption of stored traffic makes the same problem retroactive.

What has already happened?

In 2011 a Dutch certificate authority was breached and the attacker minted at least 531 fraudulent certificates. One was used to intercept the email of roughly 300,000 users in Iran. Those included dissidents, journalists, and ordinary citizens, and their browsers displayed a valid padlock throughout, because the certificates were mathematically correct.

Source: Fox-IT, “Black Tulip: Report of the investigation into the DigiNotar Certificate Authority breach,” 2012, Fox-IT Black Tulip report, hosted by ENISA.

That incident needed no quantum computer, only a compromised authority. The relevance here is the shape rather than the method: the padlock was showing, the encryption was working as designed, and the people relying on it were being read anyway.

What is already protected, and what is not?

ToolPost-quantum statusWhat that means for sources
SignalDeployed in 2023The strongest widely available option, and the one to move sensitive contact to
Apple iMessageDeployed February 2024Protected between Apple devices
Web traffic (Chrome, Edge, Firefox)Deployed 2024 to 2025Your connection to a web-based tip form is likely protected
EmailLargely notContent and headers both. This is the significant gap
SMSNoNever appropriate for source contact, for older reasons than this one
Most collaboration toolsVaries, usually notWorth asking your organization directly

Source: Signal, “PQXDH,” signal.org; Apple Security Research, “iMessage with PQ3,” February 2024, security.apple.com; Google Security Blog, September 2024, security.googleblog.com; Mozilla, Firefox 135 release notes, mozilla.org.

The email gap is the practical finding. Most source relationships begin with an email, often before either party has judged how sensitive the material will become. That first message is frequently the one that establishes the connection, and it’s the least protected thing in the sequence.

What can you actually do?

Six things, in order of how much they change.

  1. Move sensitive contact to Signal early, rather than after a story turns sensitive. The protection applies from the first message, and the first message is often the identifying one.
  2. Treat email as a public channel for source identification. Use it to move a conversation elsewhere rather than to conduct one.
  3. Use your organization’s secure tip system where one exists, since these are built to limit what metadata is retained at all.
  4. Minimize what exists. Communications that were never created cannot be collected, and contact that happened offline leaves no record to store.
  5. Delete on a schedule, and know your organization’s retention. Archives held for legal reasons are archives an adversary would also value.
  6. Ask your organization what it runs. The question that works is the same one this Guide gives everyone else: can you produce an inventory of where your cryptography lives, and what’s the post-quantum timeline for our communications tools?

What cannot be fixed?

Communications already sent.

If a source’s contact with you crossed a network under the older encryption, and somebody recorded it, no action now changes that. Migrating today protects future contact and does nothing for past contact. This is the same retroactive property described everywhere else in this resource, and for source protection it’s the part with genuine consequence.

Two honest qualifications. Nobody can tell you whether any particular traffic was collected, because collection leaves no trace. And the overwhelming majority of communications, including most journalistic ones, will never be worth an adversary’s storage and attention.

What follows from that is a proportionate response rather than alarm: identify the small number of source relationships where exposure would be genuinely dangerous, and treat those differently from the rest.

Questions people ask

Is Signal actually enough? For content, it’s the strongest widely available option and it has been post-quantum since 2023. It doesn’t erase the fact that the two of you communicated, so the operational question of how the contact was established still matters.

Does my newsroom’s encrypted email help? It protects content in transit and typically leaves headers exposed. Headers alone are frequently sufficient to identify a source.

Should I stop using email with sources? Use it to move the conversation, not to hold it. The realistic goal is limiting what the first contact reveals.

What about my notes and files? Stored material follows the same rules as any organization’s data. See What is technically happening to our systems.

Are my past stories’ sources at risk? Unknowable, and for most, no. The relationships worth reviewing are the ones where identification would still endanger someone in 10 or 20 years.

Should I tell sources about this? For high-risk sources, a plain sentence about which channel you’d prefer is more useful than an explanation of the underlying problem.

Does this change how I report the story? It shouldn’t. It’s disclosed here because the resource covers who’s exposed, and reporters are on that list.

Where to go next


Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.