Why remove metadata: four real risks, with documented cases
A photo or a document carries data you do not see when you open it: where it was made, with what, when and, sometimes, by whom. Most of the time nothing happens. But when something does, it is usually because of something the person did not even know they were sending.
1. They say where you were
Your phone stores the GPS coordinates of every photo and video, to within a few metres. One photo says where it was taken; several, taken at home, at work or at your children’s school, draw your routine.
The McAfee case, 2012. John McAfee was on the run from Belize, where police wanted to question him over a neighbour’s death. Vice magazine published a photo of him, taken with an iPhone 4S, and a journalist read in its EXIF the coordinates of a spot in Guatemala. McAfee first said he had faked the data and the next day admitted he was there, as NPR and PetaPixel reported on 3 and 4 December 2012. It was the magazine, not McAfee, that published the photo: the location travelled inside the file without anyone deciding it should.
Parler and the Capitol, 2021. The social network Parler did not strip metadata from uploaded videos. When its public posts were downloaded, Gizmodo used the GPS in 618 videos to place users inside the US Capitol on 6 January 2021, as it reported on 12 January.
2. They let someone follow a person
You do not need a famous case to see the risk. With the date, time and place of a handful of photos, you can tell when someone leaves home, where they spend their afternoons or where they go on holiday. It is information the person never chose to publish: it was inside the files.
That is why it matters in specific situations: if someone is harassing you, if you sell something online and send photos taken at home, or if you share photos of children. In all of them, the problem is not the photo but what is written inside it.
3. They identify the device and whoever uses it
Besides the location, a photo can carry the phone’s make and model, sometimes its serial number, and the software it was edited with. That is data that can link an anonymous photo to a person.
The “w0rmer” case, 2012. An attacker who signed that way published data stolen from the website of the Alabama Department of Public Safety, next to a photo holding a taunting sign. According to the FBI’s criminal complaint, dated 15 March 2012, the EXIF showed the photo was taken with an iPhone 4, edited in Photoshop and carried coordinates in the outskirts of Melbourne, Australia, which the complaint says pointed to an address. From there the FBI got to the attacker’s partner, and to him. The photo was not the only evidence — the complaint also uses IP addresses, tweets and surveillance — but it was the one that led to his partner.
The helicopters in Iraq, 2007. In 2012, a US Army intelligence officer said on the Army’s official website that soldiers had posted online photos of newly arrived helicopters at a base in Iraq, and that from them the enemy located the helicopters and destroyed four in a mortar attack. It is one officer’s account, with no further details published, but the Army used it to warn its soldiers that a phone writes the latitude and longitude into every photo.
4. Documents say who wrote them
A Word file or a PDF can carry the author’s name, the company, who last changed it, how long it was edited and the software that produced it. None of that shows on the page.
The Iraq dossier, 2003. The British Government published on its website, as a Word file, a report on Iraq later found to be partly copied from an academic paper. Researcher Richard M. Smith downloaded the file and pulled out its revision log, hidden inside the document: the user names of the four people who had worked on it, whom a journalist identified as Downing Street and Foreign Office staff. Smith published it on 30 June 2003.
A warning: metadata is also evidence
The date and place of a photo, or a document’s author, can matter in court or in a dispute, for or against whoever holds them. Removing metadata before sharing a file protects your privacy; altering a file that is already part of a legal matter is something else. If that is your situation, keep the original untouched and get advice.
What to do
You do not have to stop sharing, only know what you share. Before sending a photo or a document, look at what it carries: the guide on how to see a photo’s metadata explains how on your phone, on your computer or on this site, without uploading it anywhere.
And if it carries something you do not want to give away, remove it. KillEXIF does it in your browser, without re-encoding the photo, and checks afterwards that nothing is left. If only the location worries you, the desktop apps for Mac and Windows also have a “Location only” profile.