Digital dead drops in 2026. SecureDrop, OnionShare, and what is actually used now.

Short answer

Digital dead drops in 2026 mean two tools, used by different people for different reasons. SecureDrop is the newsroom tool for receiving leaks from anonymous sources. OnionShare is the file-transfer tool used between people who already know each other and want zero metadata to survive the exchange. The most common failure is confusing the two; the second is using either of them outside its actual design envelope.

SecureDrop, what it is and is not

SecureDrop is the platform built by the Freedom of the Press Foundation that lets a source send documents to a newsroom without revealing their identity. The architecture is built around that specific guarantee. The newsroom hosts a SecureDrop server, accessible only over Tor, with a hardware-isolated review workflow. Sources connect through Tor Browser, upload documents, and receive a code name. The newsroom downloads the documents to an air-gapped machine for review. No traceable connection back to the source is preserved at any stage.

SecureDrop is not for personal communications. It is not for ongoing relationships. It is not for sources who want to negotiate or follow up. It is the one-way submission channel, designed for the highest-risk leak scenarios. When a major news organization documents a SecureDrop submission as the origin of a story, the architecture is what made the source’s identity recoverable to no one, including the newsroom.

When SecureDrop is the right answer

Three conditions, all of which must hold.

The source has documents to deliver and is willing to break contact afterward. SecureDrop sources who establish ongoing communication through the platform’s reply feature lose some of the identity protection because the pattern of replies is itself a signal. The cleanest pattern is upload from a non-attributable location, then walk away and let the newsroom work.

The newsroom has a real SecureDrop deployment with trained staff. Many publications have a SecureDrop URL but inconsistent practices on the receiving side. The cleanest example pattern: The Intercept, the New York Times, ProPublica, the Washington Post. Smaller publications are mixed.

The friction is acceptable when the threat model genuinely justifies it. Tor Browser usage is itself a signal in some monitored networks. A source on a network where Tor is logged should reach a SecureDrop endpoint from a non-attributable location. The framework around when this kind of exposure matters is the same one we cover in how to build a threat model in 20 minutes.

OnionShare, what it does

OnionShare is the peer-to-peer file transfer tool that uses the Tor network to create temporary, anonymous endpoints. You launch OnionShare, drag a file in, and OnionShare gives you a Tor hidden service URL. The recipient opens that URL in Tor Browser and downloads the file. When you close OnionShare, the URL goes away.

The architecture is different from SecureDrop in three meaningful ways. OnionShare runs on your own machine, not on a third-party server. The transfer is direct, peer-to-peer over Tor, with no intermediate storage. The temporary URL works for one or many downloads, your choice, and stops working when you decide.

The use case is between people who already have established trust and need a single-use channel that leaves no metadata. A journalist sharing a draft with a co-author. A lawyer transferring sealed documents to a co-counsel. A photographer sending a high-resolution archive to a researcher who already knows the photographer. The recipient does not need to be anonymous to the sender (unlike SecureDrop). The world outside the two participants does not need to know the transfer happened.

When neither is the right answer

Both tools have specific use cases. Many situations that look like they need SecureDrop or OnionShare actually need something simpler.

Routine attorney-client communication is better served by Signal with disappearing messages enabled, the same posture we walked through in when law enforcement requests your client communications. The privilege analysis is the same and the friction is much lower.

Routine source-journalist communication is better served by Signal as well, often with the source moving onto a dedicated phone for that contact and the journalist using a separate device for source contact. SecureDrop carries the leak itself, while Signal carries the conversation that surrounds it.

Routine business document transfer is better served by an end-to-end encrypted file-sharing service (ProtonDrive, Tresorit, Sync.com). The metadata exposure stays small and the usability is high enough for daily work. OnionShare is overkill for routine business document transfer.

Practical SecureDrop guidance for sources

Connect from a clean network

Not your home Wi-Fi and not your work network: use a public Wi-Fi at a location not associated with you, accessed from a device that is not your daily-driver phone. The cleanest version is a separate, prepaid laptop that lives off the grid until needed for a SecureDrop submission.

Use Tor Browser, not Tor over a VPN

Tor Browser is configured for SecureDrop. Adding a commercial VPN in front of Tor adds a signal (the VPN provider knows you used Tor) without adding meaningful protection. The exception is bridge nodes for users in countries where Tor itself is blocked, and that configuration uses Tor’s built-in bridge support, not a commercial VPN.

Strip metadata from documents before upload

Documents have authorship metadata. Photos have EXIF data including GPS. PDFs have creator and editor metadata. Strip everything before submission. ExifTool is the standard for the photo work. PDF metadata strippers are widely available. The framework around metadata exposure is the broader pattern in metadata vs content in court.

Read the newsroom’s specific instructions

Each SecureDrop deployment has its own configuration. Read the page. Follow the instructions specific to that newsroom. The general principles above are correct. The newsroom-specific details (file size limits, supported formats, the wording of the code-name protocol) matter operationally.

Practical OnionShare guidance

The threshold for using OnionShare correctly is lower than for SecureDrop. Three rules cover the common errors.

Share the URL through a verified channel. The OnionShare URL itself is not secret in the cryptographic sense, but anyone who has it can connect during the window the URL is active. Share through Signal or another E2EE channel. Do not share through email.

Set a download limit. OnionShare lets you limit a share to a single download. For one-on-one transfers, set the limit to one. The URL stops working after the recipient downloads. The transfer is complete and no one else can connect to the same URL afterwards.

Close OnionShare when done. The Tor hidden service is up only while OnionShare is running on your machine. Closing it ends the service. Do not leave it running overnight assuming the recipient might want to download tomorrow. If they need it again later, generate a fresh URL at that moment instead of leaving the original service exposed.

Frequently asked questions

Can my employer detect that I used Tor?

Yes, on the work network. Tor traffic to entry guard nodes is recognizable to enterprise network monitoring tools. The protective measure is to not use Tor on the work network. Use it from a personal device on a personal network or from public Wi-Fi at a location not associated with you. The bossware framework we covered in the 12 tools your employer is probably running applies here: assume monitoring on the work device and the work network.

Is it legal to use Tor and SecureDrop?

Yes in the United States, the EU, the UK, and most democracies. The use of the tool is not illegal. The actions taken with the tool can be illegal in specific cases (leaking classified information is its own offense regardless of the channel). The tool’s existence is protected speech in most jurisdictions. The specific actions are governed by the laws applicable to the substance.

Are there alternatives to OnionShare for the same use case?

Magic Wormhole and Croc are smaller, simpler peer-to-peer file transfer tools that do not use Tor. They reduce the metadata exposure compared to email or shared cloud storage but do not match OnionShare’s protection. For most users in routine situations the lower-friction tools are fine, but when the metadata of the transfer itself matters at a state-actor threat level, OnionShare remains the cleaner choice.

Do major newsrooms still receive SecureDrop submissions in 2026?

Yes, regularly. The volume is smaller than the volume of source-journalist communications that happen on Signal, but SecureDrop is still the right channel for the highest-risk submissions. Several major stories in 2024 and 2025 originated on SecureDrop, including documented cases at the Washington Post and ProPublica. The platform still works, and the use cases that justified building it in the first place have not disappeared.


There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.

Similar Posts