{"id":"8cda910a-43f2-4767-8a42-e494490cf43a","engagementId":"010338d0-0bb5-4a07-9d32-3cae46ff29db","data":{"brief":{"id":"87cdff1f-2503-4759-b33f-bc1b80fae5f0","name":"SecureDrop","tagline":"The open-source whistleblower submission system managed by Freedom of the Press Foundation","description":"\u003cp\u003eSecureDrop is an open-source whistleblower submission system that media organizations can use to securely accept documents from and communicate with anonymous sources. It is currently a project of Freedom of the Press Foundation and was originally created by the late Aaron Swartz.\u003c/p\u003e\n\n\u003cp\u003eSecureDrop aims to help parties communicate securely by using a number of privacy enhancing tools, including Tor, Tails, Qubes OS and OpenPGP. There are three main components:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eSecureDrop Server: A Python web application (Flask/SQLAlchemy) and associated Ansible provisioning logic.\u003c/li\u003e\n\u003cli\u003eSecureDrop Workstation: Runs on Qubes OS, provisioning multiple VMs that interact with each other to provide a virtual airgap for handling documents.\u003c/li\u003e\n\u003cli\u003eSecureDrop Inbox: Electron application that runs inside a Qubes VM that fetches and decrypts submissions for journalists to triage.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eThe server runs on dedicated hardware and is isolated from the media organization's corporate network with a dedicated network firewall.\u003c/p\u003e\n\n\u003cp\u003eSecureDrop provides two web interfaces, both of which are only accessible as onion services in the Tor network; a public one that sources use to send messages or upload documents, and a private one that journalists use to check submitted information and reply to sources. All communication happens over the Tor network, and submissions are encrypted at rest using OpenPGP.\u003c/p\u003e\n\n\u003cp\u003eSecureDrop is in the process of transitioning journalists from an airgapped Tails system (where the journalist interface was accessed) to the new SecureDrop Workstation, which is built on top of Qubes. Within the Workstation is the SecureDrop Inbox, an Electron application that syncs with the server, automatically downloading and decrypting messages and replies, and allowing journalists to view submitted documents in an offline, disposable virtual machine.\u003c/p\u003e\n\n\u003cp\u003eWe appreciate all security concerns brought forth and are constantly striving to keep on top of the latest threats. Being proactive rather than reactive to emerging security issues is a fundamental belief at the Freedom of the Press Foundation. We appreciate the community's efforts in creating a more secure ecosystem.\u003c/p\u003e\n\n\u003cp\u003eTo learn more, please read the \u003ca href=\"https://securedrop.org/faq\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFAQ\u003c/a\u003e and \u003ca href=\"https://docs.securedrop.org/en/latest/threat_model/threat_model.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ethreat model document\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eIf you have any questions, contact securedrop@freedom.press with “BugCrowd” in the subject line.\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003eIn order to give researchers as much access to the SecureDrop system as possible, and thus provide a bounty that is more effective than just a black box test or code review, we recommend that researchers set up their own instance of SecureDrop for testing and analysis. You can do this quickly and easily with our automated deployment process.\u003c/p\u003e\n\n\u003cp\u003eYou can choose to deploy SecureDrop server code locally in a virtualized environment (Docker, Vagrant + Virtualbox or Libvirt), or you can deploy it on dedicated hardware to most accurately emulate a production installation. We recommend choosing the environment based on what you are interested in testing: for example, vulnerabilities in the web application or the server stack will be most likely auditable from a virtualized environment. Similarly, for the Workstation and Inbox, some functionality can be tested in development mode, but interactions with Qubes are best verified in Qubes itself.\u003c/p\u003e\n\n\u003cp\u003eNote that all production instances are run on dedicated hardware and that virtualized environments are only meant for development and testing. Vulnerabilities that rely on those non-production environments will not be considered for a reward.\u003c/p\u003e\n\n\u003ch2\u003eUsing SecureDrop\u003c/h2\u003e\n\n\u003cp\u003eOnce you've set up a SecureDrop environment for testing, see these resources to learn how it is typically used:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://docs.securedrop.org/en/latest/source.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSource User Manual\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.securedrop.org/en/latest/journalist.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eJournalist User Manual\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.securedrop.org/en/latest/admin.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAdministrator User Manual\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eHere is some relevant background for the SecureDrop Workstation:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.qubes-os.org/intro/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eIntroduction to Qubes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.qubes-os.org/doc/installation-guide/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eQubes Installation Guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eEligible Submissions\u003c/h2\u003e\n\n\u003cp\u003eAttacks that rely on components other than the SecureDrop application code, such as Tor Browser or Qubes, will be considered as long as the attacks can be used to successfully exploit the SecureDrop system.\u003cbr\u003e\nThe following are minimum awards for the following attacks:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e$500\u003c/strong\u003e - Stored or reflected XSS on the Server’s Journalist Interface\u003cbr\u003e\n\u003cstrong\u003e$750\u003c/strong\u003e - SQL injection on the Server’s Journalist Interface\u003cbr\u003e\n\u003cstrong\u003e$1000\u003c/strong\u003e - Authentication bypass on the Server’s Journalist Interface\u003cbr\u003e\n\u003cstrong\u003e$1500\u003c/strong\u003e - Stored or reflected XSS on the Server’s Source Interface\u003cbr\u003e\n\u003cstrong\u003e$2000\u003c/strong\u003e - SQL injection or Authentication bypass on source interface. \u003cbr\u003e\n\u003cstrong\u003e$2000\u003c/strong\u003e - XSS or SQL injection in the SecureDrop Inbox\u003cbr\u003e\n\u003cstrong\u003e$2000\u003c/strong\u003e - Code execution on a SecureDrop Workstation VM other than the Disposable VM used to open submissions (sd-viewer).\u003cbr\u003e\n\u003cstrong\u003e$2500\u003c/strong\u003e - RCE on the SecureDrop Server’s source or journalist interfaces.\u003cbr\u003e\n\u003cstrong\u003e$2500\u003c/strong\u003e - Extraction of private key material, successful extraction of decrypted SecureDrop submissions.\u003c/p\u003e\n\n\u003ch2\u003ePrioritization\u003c/h2\u003e\n\n\u003cp\u003eThis program adheres to the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e for the prioritization/rating of other findings. \u003c/p\u003e\n\n\u003cp\u003eGenerally we will reward more for an issue exploitable through the source interface than through the journalist interface, since an attacker needs a valid ATHS token to access the journalist interface whereas the source interface is accessible by any Tor user. \u003c/p\u003e\n\n\u003cp\u003eSimilarly, attacks that require a compromised or malicious server will usually be treated as lower priority and receive lower rewards. Attacks against the SecureDrop Inbox that require a compromised or malicious server must be demonstrated with proof-of-concept server code or responses sufficient to demonstrate the attack on an unmodified client.\u003c/p\u003e\n\n\u003ch2\u003eIneligible Submissions\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePre-existing \u003ca href=\"https://github.com/freedomofpress/securedrop/issues\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGitHub issues\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAll Common \"Non-qualifying\" Submission Types from the \u003ca href=\"https://bugcrowd.com/resources/standard-disclosure-terms\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Standard Disclosure Terms\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSubmissions related to projects that are not in production usage. Pull requests are always welcome!\u003c/li\u003e\n\u003cli\u003eNetwork and application level Denial of Service (DoS/DDoS) vulnerabilities. This includes continuous large submissions and continuous codename generation.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, e.g. codename word lists or test-only PGP keys.\u003c/li\u003e\n\u003cli\u003eAttacks that rely on other browsers (our threat model assumes Tor Browser or Tails).\u003c/li\u003e\n\u003cli\u003eAttacks on 3rd party providers, e.g. use of Google for DNS and SMTP.\u003c/li\u003e\n\u003cli\u003eAttacks that rely solely on the development environment and/or the virtualized platform (this includes the use of default credentials in these environments).\u003c/li\u003e\n\u003cli\u003eFunctional, UI and UX bugs and spelling mistakes.\u003c/li\u003e\n\u003cli\u003ePointing out that pip, npm or Rust packages aren't signed.\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003ePointing out the lack of HTTPS since Tor Onion services are used.\u003c/li\u003e\n\u003cli\u003ePointing out that metadata is not removed from uploaded documents (this is intentional in order to allow journalists to use metadata to validate documents).\u003c/li\u003e\n\u003cli\u003eMissing \u003ca href=\"https://www.owasp.org/index.php/List_of_useful_HTTP_headers\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHTTP security headers\u003c/a\u003e, such as pointing out missing Cache-Control headers.\u003c/li\u003e\n\u003cli\u003eAttacks on the SecureDrop workstation initiated from arbitrary commands run in dom0.\u003c/li\u003e\n\u003cli\u003eAttacks on the SecureDrop Workstation that rely on the attacker having access to dom0.\u003c/li\u003e\n\u003cli\u003eIDOR vulnerabilities based on every journalist and admin user having full access to all sources and submissions.\u003c/li\u003e\n\u003cli\u003ePointing out that the \u003ca href=\"https://github.com/freedomofpress/securedrop/issues/204\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFlask session cookie discloses the source codename/passphrase\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003ePointing out that after installation of SecureDrop Workstation, credentials are left behind in dom0, or that these credentials have insufficient permissions.\u003c/li\u003e\n\u003cli\u003ePointing out that HOTP or TOTP shared secrets or tokens can show up in server logs.\u003c/li\u003e\n\u003cli\u003ePointing out that a 2FA reset does not prompt for re-authentication.\u003c/li\u003e\n\u003cli\u003eAttacks that can lockout a journalist that rely on knowing the journalist’s username and 2FA credentials, as well as the authenticated onion service token.\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"bad90687-94a9-4aee-a05e-aa3c3962f02d","name":"In Scope Targets","targets":[{"id":"c7c62b13-a1e2-4983-8355-9075ed97f8ef","uri":"https://github.com/freedomofpress/securedrop","name":"https://github.com/freedomofpress/securedrop","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2d328169-b6d1-45c1-abc7-57a7f672a650","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c7c62b13-a1e2-4983-8355-9075ed97f8ef"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"c7c62b13-a1e2-4983-8355-9075ed97f8ef"}],"recentChangeFlags":null},{"id":"48e706b8-d643-4fa9-9b47-075b97aa3e46","uri":"https://github.com/freedomofpress/securedrop-workstation","name":"https://github.com/freedomofpress/securedrop-workstation","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"88db3f21-0b93-4e2a-b17f-5eda79a72954","sortOrder":0},"sortOrder":0,"tags":[{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"48e706b8-d643-4fa9-9b47-075b97aa3e46"}],"recentChangeFlags":null},{"id":"7fc510c2-f081-4e60-bdcf-7d9f89824868","uri":"https://github.com/freedomofpress/securedrop-client","name":"https://github.com/freedomofpress/securedrop-client","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"47c0bc01-1585-41db-ba10-dec4641245ee","sortOrder":0},"sortOrder":0,"tags":[{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"7fc510c2-f081-4e60-bdcf-7d9f89824868"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"07ab9b18-ed90-4600-b45e-6fab87639ae1","p1MaxCents":250000,"p1MinCents":200000,"p2MaxCents":150000,"p2MinCents":100000,"p3MaxCents":75000,"p3MinCents":50000,"p4MaxCents":20000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2000,"max":2500},"2":{"min":1000,"max":1500},"3":{"min":500,"max":750},"4":{"min":100,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"010338d0-0bb5-4a07-9d32-3cae46ff29db","code":"freedomofpress","state":"in_progress","endsAt":null,"bountyId":"2e761cbd-3e52-40e8-8c13-c8481f466f40","startsAt":"2015-06-04T16:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/9f59/4131/f9eb558d/b8030a1ada7f1ea9ef5b46f4e86e1fa4_sd-logo-cube.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2015-06-04T16:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/freedomofpress","changelogs":"/engagements/freedomofpress/changelog","submissions":null,"announcements":"/engagements/freedomofpress/announcements","hallOfFame":"/engagements/freedomofpress/hall_of_fames","crowdstream":"/engagements/freedomofpress/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/freedomofpress/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=freedomofpress\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/freedomofpress/engagement_subscribers","engagementChangelogsUrl":"/engagements/freedomofpress/changelog","publishedAt":"2026-08-26T18:55:50.108Z","engagementChangelogUrl":"/engagements/freedomofpress/changelog/8cda910a-43f2-4767-8a42-e494490cf43a","createUserFeedbacksUrl":"/engagements/freedomofpress/feedbacks","engagementCrowdstreamUrl":"/engagements/freedomofpress/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}