OPSEC52 / Week 18 — File metadata: the photo has your GPS, the document has your name
You strip your identity everywhere — aliased email, compartmentalized phone, clean browser — then attach a photo, and the file quietly carries the exact GPS coordinates where you took it, the phone that took it, and the second the shutter fired. The content is what you meant to share. The metadata is everything you didn’t.
Threat model: anyone who receives a file you send — a forum mod, a marketplace counterpart, a support desk that logs attachments — plus every platform that doesn’t strip metadata on upload, and any analyst who collects your files over time and correlates the embedded author/device/GPS fields to merge a “pseudonymous” identity back into a real one. The leak isn’t in the picture; it’s in the header no one looks at.
The easy 20% most people know
“Photos have GPS.” True — most know a phone photo can carry EXIF location, and many turn off camera geotagging. That’s the easy part, and it’s worth doing. But EXIF is a fraction of the surface, and turning off geotagging doesn’t touch the rest of what a photo carries, nor documents at all.
What actually rides along
- Photos (EXIF/XMP): GPS lat/long to a few metres, exact timestamp, camera/phone make + model + serial, lens, and often a unique device identifier. Two “anonymous” photos with the same camera serial are the same camera.
- Documents (PDF, Word, Office): author name, the OS username, the software + licence, creation/modification times — and for Office files, frequently tracked-changes and revision history: text you cut before sending can still be recovered.
- Screenshots and “cropped” images: cropping in some apps only hides the removed area — the original pixels can be recoverable (the “Acropalypse” class of bug). A redaction drawn as a black box over selectable text isn’t a redaction at all.
- Thumbnails: a file can embed a small preview generated before you edited it — so the thumbnail shows the un-blurred, un-cropped original.
- The upload myth: big social platforms strip EXIF on upload — but forums, marketplaces, chat apps, email attachments, IPFS, and “download the original” links frequently do not. Never assume the receiving side cleans it.
The fix, by file type
- Photos: don’t rely on “geotagging off.” Run every image through a metadata stripper before it leaves your device —
exiftool -all= file.jpg(desktop), or ExifEraser / Scrambled Exif (Android), or “remove location” plus a re-export. Screenshotting a photo and sending the screenshot also drops most EXIF as a crude fallback. - Documents: use the built-in “Inspect Document → Remove Personal Information” (Word) or export to a flattened PDF and run it through a metadata scrubber (
exiftool,mat2). Better: for anything sensitive, paste the text into a plain editor and rebuild — no author, no revision history, no licence trail. - Redaction: never draw a box over text. Delete the content, flatten to an image, then redact the image — or use a real redaction tool that removes the underlying data.
- The universal tool:
mat2(Metadata Anonymisation Toolkit) handles images, PDFs, Office, audio — one command to strip a file clean. Make it a habit before any upload.
Verify — look at what you’re about to send
Assume a file is dirty until you’ve checked. exiftool <file> prints every embedded field; skim it for GPS, author, username, serial, timestamps. Do this once on a phone photo and once on a PDF you made — seeing your own name and coordinates staring back is the moment the habit sticks.
The privacy-coin corner
This is the quiet deanon of the no-KYC world. You buy Monero, run a clean node, keep a pseudonym — then post a photo of a receipt, a QR code, or a hardware wallet to prove a point or get support, and the EXIF hands over the GPS of your kitchen and your phone’s serial. A screenshot of a swap “proof” can carry your OS username. Every file you attach to a pseudonymous identity is a chance to staple your real one to it. Strip before you send, every time — the on-chain privacy you paid for shouldn’t be undone by a JPEG header.
One thing to do today: take the last photo you sent in any chat and run exiftool on the original (or drop it into an EXIF viewer). If it shows GPS or your device serial, that’s what your recipient got — install mat2 or a mobile EXIF stripper now and make cleaning files the reflex before every upload.
Curated by Cyber Satoshi. Part of OPSEC52 — 52 weeks, 52 privacy pillars, threat-model first. See also Week 13 (card metadata) and Week 14 (message metadata).