Encrypted messaging is one layer of source protection, not the whole job. Knowing how to protect sources with encrypted messaging means pairing a properly configured app like Signal with device hardening, contact verification, metadata discipline and a written emergency plan before the first message goes out.
The honest truth is that most source-protection failures I’ve seen in newsroom security advisories are behavioural, not cryptographic. A reporter runs a perfect encrypted conversation on a phone full of outdated apps, using a work contact name that names the assignment. The encryption worked. Everything around it failed.
This guide walks the whole workflow, from the threat assessment before you ever meet a source to the seizure response after the worst happens. It takes about an hour to read and a couple of hours to apply.
Table of Contents
- What You Need
- Step-by-Step
- How to Protect Sources with Encrypted Messaging Before Contact
- Install and Verify the Messaging Apps
- Set a Conversation Security Check
- Verify Identity Without Exposing the Source
- Protect the Devices and Accounts
- Use SecureDrop for High-Risk Submissions
- Prepare for Compromise or an Emergency
- Common Mistakes at Each Stage
- Common Mistakes
- Frequently Asked Questions
- Is Signal alone enough to protect a confidential source?
- How long should disappearing messages be enabled for sensitive conversations?
- Do journalists and sources need a VPN when using encrypted messaging?
- Should a source back up an encrypted messaging conversation?
- What should a journalist do immediately after losing a source’s device?
- Conclusion: Start With the Highest Consequence Risk
What You Need
Start with a threat model, not an app. Before you download anything, write down what you are actually protecting against: a nosy employer, a subpoena, a criminal investigation, a state actor, or physical coercion at a checkpoint. Those have very different answers, and picking the right tool before you pick the risk is how people end up over-equipped for a stalking ex and under-equipped for a state agency.
Most source protection lives in one of three tiers:
| Risk tier | What you are facing | Core tool set |
|---|---|---|
| Baseline | Curiosity, employer oversight, ordinary device loss | Signal, full-disk encryption, password manager, screen lock |
| Sensitive source | Documents, internal affairs, a named investigation | Baseline plus disappearing messages, contact sync off, separate device or profile, no cloud backup |
| High-risk whistleblower | State surveillance, criminal exposure, retaliation at work | Self-hosted SecureDrop, compartmentalized device, no app-based first contact, documented response plan |
Your inventory, in plain terms, is a correctly configured Signal or comparable encrypted messaging account, a way to verify the other person’s identity without relying on the app itself, unique randomly generated passwords held in a reputable password manager, a current device with encryption at rest turned on, and, where the threat model calls for it, a SecureDrop service your newsroom operates or trusts.
A VPN belongs on that list only when your model justifies it. It hides your network position from the local network and your internet provider. It does not make you anonymous, it does not fix a compromised device, and it adds a company that can log your connection times.
One more thing no tool supplies: a written record of what your newsroom promises a source and what it cannot promise. The Perugia Principles and Committee to Protect Journalists guidance exist precisely because that promise cannot be delegated to software.
Step-by-Step
Here is the operational order. Each step gives you the action, the way to verify it, and the signal that it worked.
How to Protect Sources with Encrypted Messaging Before Contact

Do the thinking before you open the app. Assess the source’s legal exposure, their digital exposure, their physical safety and whether anyone is coercing them. Then decide what must stay unlinkable: a phone number, an employer, a project name, a city.
Establish three things and write them down where the note itself carries no names. A code name you will both use instead of a project name. A reporting cadence, so a missed check-in is not itself a warning sign. An emergency plan covering withdrawal, a lost device and a legal demand.
You know it worked when you could brief someone else in the newsroom on the plan without naming the source.
Install and Verify the Messaging Apps
Install Signal from its official app store listing on a supported Android or iOS device, then update the operating system before you do anything else. Create the account over a network consistent with your threat model, and resist the urge to rush through registration.
Signal will show a safety number, or a username-derived identifier in newer versions. Compare it with the person on the other end over a channel you already trust. Out of band means something other than the Signal conversation itself: a phone call you placed from a number both parties already knew, an in-person meeting, a code word agreed months earlier.
You know it worked when both of you read the same digits out loud, on two separate channels.
Set a Conversation Security Check
Turn on disappearing messages and pick a timer that matches the purpose. A week of work will not fit a 24-hour timer, and a source who needs to preserve evidence for a lawyer should not enable it at all.
Disappearing messages delete from both devices after the timer expires. They do not stop screenshots, camera photos, forwarding, or a recipient who saves a note. Say that out loud to the source rather than letting them assume it.
Use one thread per project so a metadata glance does not connect two unrelated investigations. Keep the contact profile to a code name with no job title, no organisation and no project detail, and turn off message previews so the lock screen shows nothing useful to a bystander.
You know it worked when a colleague picking up your unlocked phone learns nothing about who you are reporting.
Verify Identity Without Exposing the Source
Verification matters most when you have least access to the person. Three methods, in order of strength: a code word arranged before the contact existed, a safety number compared on a second channel, and a document or account detail confirmed through an independent route.
When something does not line up, investigate gently. Someone under pressure may have a new phone, a new number, or genuinely bad timing. Repeated interrogation on a live encrypted channel can burn a source faster than an honest mismatch.
You know it worked when the person on the other end can explain a discrepancy without being pushed into it.
Protect the Devices and Accounts
Turn on device encryption and a strong screen lock: FileVault on macOS, BitLocker on Windows, full-disk encryption on Android with a real screen lock set. Signal’s app lock adds a second gate inside the app.
Use unique randomly generated passwords through a reputable password manager, and require a PIN for Signal’s two-step verification so a new linked device cannot be added without it. Remove app permissions the source conversation does not need, and disable cloud backup of the Signal conversation on high-risk threads.
On Android the setting path is Settings, then Apps, then Signal, then Permissions. On iOS it is Settings, then Signal, then Privacy, then Lock App. Menus shift between releases, so check the app’s own help page when a path is missing.
You know it worked when a linked-devices list you did not authorise would have triggered a warning.
Use SecureDrop for High-Risk Submissions
Sometimes the safest channel is not a conversation. SecureDrop is a submission system designed so a stranger can send documents without giving you anything except the material itself. When the newsroom runs its own instance, a legal demand for the server content alerts staff rather than quietly handing it over.
Direct a high-risk source to the published onion address, keep the conversation free of identifying detail, and preserve the original files you receive. The SecureDrop client decrypts submissions locally, so the files should not be copied to a cloud account or a personal laptop drive.
Check the service’s own instructions and current system status before pointing anyone at it. If your newsroom has no instance, a partner outlet’s service or an established third-party submission page is the fallback, not your personal inbox.
Channel choice matters as much as tool choice. The same journalist can do all three of these safely if the exposure is handled differently in each:
| Channel | Best for | What the service can still see | Use it when |
|---|---|---|---|
| Encrypted messaging (Signal) | An established source and an ongoing conversation | Account is tied to a phone number; sealed sender limits message metadata | You already know who you are talking to and need a two-way thread |
| SecureDrop | An unknown or high-risk source sending documents | No sender metadata and no account | First contact, or the material itself could end a career |
| Encrypted email | A short, auditable handoff | Connection metadata and headers still travel | A source wants a written record they can show a lawyer |
You know it worked when the submission arrived with no sender metadata attached to it.
Prepare for Compromise or an Emergency
Write the response plan before you need it. Six scenarios: a device lost or stolen, a contact name exposed, a Signal account warning or number change prompt, a legal demand, a source withdrawing, and immediate physical danger.
Name one editor or security contact who does not need unnecessary source detail to act. Rehearse the lost-device steps on a device you do not mind wiping. If a device is seized or a legal demand arrives, note the time, the issuing authority and what was requested, seek counsel, and avoid amplifying an incident through your own channels before facts are established.
You know it worked when the plan fits on one page and someone other than you could execute it.
Common Mistakes at Each Stage
The workflow compresses to a short sequence, and the mistakes cluster around it.
- Before contact: naming the project or employer in the contact profile, and using a personal phone with a personal SIM for work conversations.
- During the conversation: leaving contact sync on, using a shared family device, or discussing the source’s identity in a thread that mixes personal and work chat.
- Before file exchange: sending ordinary attachments straight through, without sanitizing document metadata.
- After each interaction: keeping one long thread for every project, and treating disappearing messages as a backup strategy.
Encryption is one layer. The rest is the habit around it.
Common Mistakes
The most common failure is treating one app as the whole plan. Signal leaves copies on both phones, so the source’s own device is part of the risk surface, and the encryption is rarely what gets you caught. Second on the list is putting a source’s real name in a contact profile, which hands over the exact link you spent months hiding.
Forwarding identifying messages to a colleague who was not briefed is the third. Treat the forward as a disclosure: assume anything you send now sits in someone else’s risk profile, permanently.
Sending ordinary attachments is the fourth. Documents arrive carrying author names, edit history, tracked changes and location data. Run files through a sanitization tool such as Dangerzone, or strip metadata with ExifTool, before they reach a shared drive.
Reusing credentials is the fifth. One breached password on a personal account is enough to walk into the work account, so nothing personal and nothing professional shares a password or a recovery email address.
Confusing disappearing messages with backups is the sixth. A timer deletes forward in time; it does not restore anything and it does not touch screenshots, photographs or notes taken by the other party.
Discussing sensitive work over an ordinary phone call is the seventh. Voice calls expose the participants to the network and to anyone in the room.
Skipping identity verification is the eighth. An impersonated contact is how fraudsters insert themselves into a real conversation, and comparing a safety number takes under a minute.
Promising perfect anonymity is the ninth. You cannot deliver it. Being straight about the limits is what keeps a source informed enough to make their own choice.
Using consumer clouds for high-risk material is the tenth. Personal email, consumer file sync and consumer chat backups hand material to a company with an account-recovery process you do not control.
Two habits close the gaps. Work through a written newsroom source-protection policy so the standard does not depend on who is on shift, and run training on a specific beat rather than a general security lecture, using checklists a reporter can follow at 11pm in a hotel room. When reporters are asked which habit cost them most, the same three come back: public Wi-Fi, unpatched systems and reused personal accounts.
Frequently Asked Questions
Is Signal alone enough to protect a confidential source?
No. Signal encrypts message content end to end and sealed sender hides the sender from the service, but the account still requires a phone number, and the source’s own phone holds a copy of everything. Encryption does not stop a lost device, a coercion attempt, a profile that names the project, or a subpoena for records held elsewhere. Treat Signal as the channel inside a wider plan.
How long should disappearing messages be enabled for sensitive conversations?
Match the timer to the task. Short timers suit quick check-ins where nothing needs to survive. Ongoing investigations usually run for weeks, so a 24-hour setting will destroy context you need. If a source may need to hand material to a lawyer or regulator, leave timers off entirely and keep a separate record of consent to retain. Always tell the source the timer does not block screenshots or forwarding.
Do journalists and sources need a VPN when using encrypted messaging?
Sometimes, and for a narrow reason. A VPN can stop an untrusted local network from seeing which service you are connecting to, which matters in a hotel or a hostile office. It does not make you anonymous, it does not fix an infected phone, and it hands a new party a log of when you connected. Include one only when your threat model names that specific risk.
Should a source back up an encrypted messaging conversation?
Generally no, and especially not for high-risk work. A backup creates another copy in another place, often in a consumer cloud account with an account-recovery process you do not control. If a source needs a record for legal or evidentiary reasons, agree that in advance and store it deliberately on encrypted media rather than relying on an automatic thread backup. The source decides what to retain, not the app.
What should a journalist do immediately after losing a source’s device?
Act on the account first. Signal linked devices can be removed and the account unregistered, which also signs the phone out remotely, though local data on the handset may remain. Then notify your security contact so a compromised contact name or assignment can be rotated. If the loss came with a legal demand or physical danger, treat it as an emergency and seek counsel. Rules and protections vary by country, so confirm what your own law requires before deciding what to record.
Conclusion: Start With the Highest Consequence Risk
Find the single piece of information or connection that would do the most damage if exposed, and protect that one first. Then pick a channel proportionate to that risk, verify both the person and the channel through a second route, and run the newsroom’s security or legal process before the first source contact whenever the stakes justify it.
Everything in this guide is downstream of that one decision. Before you touch a single setting, work out what the highest consequence risk actually is for this story and this source.


