Leak Authenticity Triangulation
Verify extraordinary leaks through technical, documentary, and independent checks.
- Difficulty
- Moderate
- Time to result
- ~days to results
- Steps
- 5
- Confidence
- 96%
This framework validates a leak by combining evidence that would be difficult for one source to fabricate. Begin with the primary documents and assess their detail, terminology, structure, and consistency with known systems. Then involve a technically capable domain expert who can connect modules, patents, research papers, legal testimony, and platform conventions. Because the original investigator and first reviewer may both want the material to be genuine, add independent reviewers with different incentives, ideally former insiders. Confidence rises when the documentation matches internal conventions, obscure project names connect to independently known systems, and multiple reviewers conclude that fabrication would require implausible expertise and effort. The output is a calibrated authenticity judgment rather than absolute certainty.
Origin
Rand Fishkin described this process on Marketing Against The Grain while explaining how he verified leaked Google Search API documentation.
Core principles
- 01Treat extraordinary claims as unverified until corroborated.
- 02Separate documentary evidence from personal testimony.
- 03Consult experts with different incentives and perspectives.
- 04Test whether details match known systems and conventions.
How to run it
- 1
Inspect the primary evidence
Read the underlying documents rather than relying on the source's interpretation. Note internal terminology, technical depth, and structural consistency.
Pro tip Look for obscure details that can be checked independently.
Watch out Polished presentation alone is not evidence of authenticity.
- 2
Recruit a technical verifier
Ask a respected domain expert to connect the material with known patents, papers, testimony, and platform conventions.
Pro tip Choose someone capable of tracing dependencies rather than merely recognizing keywords.
Watch out A single sympathetic expert can share your confirmation bias.
- 3
Check surrounding evidence
Compare the documents with prior disclosures and independently documented systems. Verify unfamiliar project names or internal references where possible.
Pro tip Prior evidence can validate details without proving every interpretation.
Watch out Do not treat correlation between documents as proof that every feature is currently active.
- 4
Seek independent insider reviews
Ask multiple former insiders to assess whether the documents resemble authentic internal material.
Pro tip Include reviewers who have little personal benefit from validation.
Watch out Respect anyone who declines to review potentially sensitive material.
- 5
Calibrate the conclusion
State what the evidence establishes, what it merely suggests, and what remains unknown.
Pro tip Use confidence language instead of claiming certainty.
Watch out An authentic API reference does not prove that every documented capability is deployed.
In the wild
A researcher receives alleged internal ranking documentation. She inspects its API conventions, asks a search engineer to trace the modules, compares obscure names with court exhibits, and obtains assessments from two former employees. She reports that the documents are probably authentic while distinguishing available features from confirmed production use.
→ The disclosure is credible without overstating what the evidence proves.
Common mistakes
Trusting the source's confidence
A sincere source can still misunderstand or misattribute genuine-looking material.
Using only friendly reviewers
People who want the claim to be true may independently reproduce the same confirmation bias.
Equating capability with deployment
Documentation can show that a system can use a feature without proving when or how often it does.
Is it for you?
Best for
Journalists, analysts, researchers, and marketers evaluating consequential technical disclosures.
Not ideal for
Low-stakes claims that can be confirmed directly through an authoritative public source.
From the transcript
“the first thing I did, Kip and Kieran, is I contacted Mike King”
“I reached out to some ex-Google engineer friends on private messaging apps and asked them if they'd take a look.”
“everything about this checks out and looks authentic.”
From the episode
How To Rank #1 With Google’s Secret Algorithm (Google Leak Explained)