Feeds

Wikileaks publishes secret donor list

Hoist by its own leaky petard

Securing Web Applications Made Simple and Scalable

Whistleblower website Wikileaks faced a dilemma this week when a list of email addresses for the site's donors was submitted as a leaked document.

The issue arose after a fund raising email on Saturday went out with all 58 addresses in the To field (instead of the bcc field). The all too common schoolboy error meant that all the recipients found out the online identities of other donors.

The list was promptly resubmitted as a leaked document which, to its credit, Wikileaks published along with the comment from the leaker that "WikiLeaks leaks its own donors, aww irony. BCC next time kthx".

In a note, Wikileaks described the list as a partial list of its donors, adding its speculation as to the likely motives of the leaker.

"A prankster, apparently connected to one of the donors, then submitted this list to Wikileaks, possibly to test the project's principles of complete impartiality when dealing with whistleblowers," it said.

Enterprisingly, the same page includes a link to make donations.

Some comments on the story try to reassure would-be leakers that the slip-up is unrelated to Wikileaks' procedures for protecting its sources.

"It doesn't reflect anything to do with the wikileaks source protection operations, which are separate to office admin," one comment states. "While the release of these addresses is not optimal, all such donations have bank records and confirmations that travel over plain email."

Other comments highlight concerns that the leaked list might be used to make life difficult for the controversial project. "Hopefully, Scientologists don't go after the people listed here. I wouldn't put it past them," one person notes.

Previous notable leaks that have come through the whistleblower website include Guantánamo Bay procedures, internal documents related to the Church of Scientology, the BNP membership list and a costing plan by Bavarian police related to a project to develop software capable of intercepting Skype traffic. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
BMW's ConnectedDrive falls over, bosses blame upgrade snafu
Traffic flows up 20% as motorway middle lanes miraculously unclog
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.