Traditional source protection relied on reporter privilege, editorial discretion, and limited law enforcement surveillance capability. Digital communication has eroded these protections significantly. A journalist's email metadata (who they communicated with, when, how often) can be obtained through legal process without content decryption. Phone records identify source contacts through carrier metadata. Browser history and DNS queries logged by ISPs reveal research patterns. Even when content remains protected, metadata provides powerful investigative leads.
The only effective defense against metadata surveillance is preventing the metadata from being collected in the first place. Tor prevents IP-level metadata collection by routing communication through multiple encrypted relays. A Tor-based communication between a journalist and a source leaves no IP-level record at the source's ISP or the journalist's ISP. The metadata simply does not exist to subpoena.
Newsrooms that have deployed this infrastructure include the New York Times, Washington Post, and Guardian. Their SecureDrop deployments receive thousands of tips annually from sources who specifically chose anonymous digital channels over riskier traditional contact methods. The infrastructure works and its deployment is now standard practice for major investigative journalism organizations.