Skip to content
← Threat modelling and risk for people at risk

Lesson 4 of 4 · 9 min

Special cases: sources, borders, and when to ask for help

Protecting a source or a client’s confidentiality, what happens when a device is searched at a border, and when self-taught security stops being enough.

The previous lessons built a general method: name the adversary, weigh likelihood and impact, choose proportionate controls. Some situations are common enough among journalists, lawyers, and NGO workers that they deserve specific attention, and a specific answer to the question the whole course has been building toward: when do you stop doing this yourself?

Protecting a source, before they ever contact you

Freedom of the Press Foundation’s guidance is blunt about timing: “the effort to protect your sources needs to start before they contact you.” By the time a source reaches out, a phone number, an email header, or a contacts app entry may already exist somewhere outside your control. Its practical guidance includes moving sensitive first contact to Signal rather than a phone number-based channel, being deliberate about what a tip line or contact page collects, and treating your own address book as an asset in its own right — a list of “who talks to this journalist” is itself sensitive, even without message content. The same logic applies to lawyers holding a client list: who you represent can matter as much as what was said.

Client confidentiality is a threat model, not just a duty

A lawyer’s ethical duty of confidentiality and a security threat model describe the same problem from two angles. The adversary might be opposing counsel seeking early access to strategy, a government seeking a client’s asylum evidence before it is filed, or simply a shared office computer where privilege could be waived by accident. Applying the previous lesson’s method — what is the asset, who wants it, how would they get it — turns “keep it confidential” into concrete steps: separate storage for the most sensitive files, care about which cloud service holds them (the cloud-security course in this university covers who else could access that data), and caution before discussing a case over an unencrypted channel.

Device searches at borders

The Electronic Frontier Foundation’s guide to digital privacy at the US border explains that border agents currently claim authority to search travelers’ devices “with or without individualized suspicion”, a power that is broader than what applies away from the border and legally contested. Its concrete preparation advice includes: minimise what you carry by leaving sensitive devices home or shifting data to storage you can access after arrival rather than data physically on the device; enable full-disk encryption with a strong, memorised password rather than relying on a fingerprint or face unlock alone at the crossing; and power devices off before reaching the checkpoint. If a device is searched or an officer asks for a password, EFF’s guidance is that your options depend on your citizenship and immigration status — a US citizen cannot be denied entry for declining, but non-citizens may face different consequences — which is exactly the kind of decision worth planning before you are standing at the desk, not during it.

When to bring in expert help

The risk-analysis method in this course is meant to handle everyday decisions well. It is not meant to replace expert help once the stakes cross a certain line — a state-level adversary, an active legal threat, or a source whose safety depends on getting this right the first time. Three organisations exist specifically for that gap. Access Now runs a Digital Security Helpline offering, in its own description, “rapid response for digital security incidents” in ten languages with a two-hour typical response time, for civil society groups, journalists and human rights defenders. Freedom of the Press Foundation’s digital security team works directly with newsrooms and reporters on exactly the source-protection and field-reporting situations above. EFF’s Surveillance Self-Defense guide is the reference this whole course has drawn from, and EFF itself can be contacted directly (its border guide lists [email protected] for rights violations at a crossing).

A rule of thumb

If the honest answer to “how bad are the consequences if I fail”, from the first lesson in this course, is that someone could be hurt, arrested, or lose their asylum case — stop relying on general guidance, including this course, and ask one of the organisations above. None of them, or any tool, can promise safety. What they can do is bring current, situation-specific knowledge that a course written for a general audience cannot.

Key takeaways

  • Source protection has to start before a source makes first contact: phone numbers, contact forms, and address books are assets too.
  • Client confidentiality benefits from the same threat-model thinking as any other risk: name the asset, the adversary, and the plausible access route.
  • Border agents in some jurisdictions claim broad authority to search devices; minimising what you carry and using full-disk encryption are common preparation steps.
  • Border-search consequences differ by citizenship and immigration status, so plan a decision in advance rather than deciding at the checkpoint.
  • Access Now’s Digital Security Helpline and Freedom of the Press Foundation exist specifically for cases where the stakes are high enough that expert help, not self-taught security, is the right next step.

Check yourself

  1. 1. Per Freedom of the Press Foundation, when should source-protection measures begin?

    • Only after a source explicitly asks for anonymity
    • Before the source ever makes contact — Right.
    • Only once a story is published
    • Source protection is unnecessary if Signal is used

    The guidance stresses that infrastructure like a secure tip line has to exist and be deliberately designed before a source reaches out.

  2. 2. According to EFF’s border-privacy guide, what is one concrete way to reduce risk before crossing a border?

    • Leave all devices fully unlocked for faster inspection
    • Enable full-disk encryption and power the device off before reaching the checkpoint — Right.
    • Share your password with a travel companion in advance
    • Disable device encryption to avoid suspicion

    EFF recommends full-disk encryption with a strong password and powering devices off before arrival, rather than relying on biometric unlock alone.

  3. 3. What is the Access Now Digital Security Helpline?

    • A paid consulting firm for large corporations
    • A rapid-response support service for civil society, journalists and human rights defenders facing digital security incidents — Right.
    • A government-run device search program
    • A commercial antivirus subscription

    Access Now describes the helpline as offering rapid response and guidance in multiple languages to civil society groups and at-risk individuals.

Do it with FireAI

Put this lesson into practice on your own Mac.

Sources

Put it into practice on your Mac

Try every feature free for 17 days, no card needed.

Download for Mac Docs