NearScrub

NearScrub Blog

  • Governments Are Moving to LibreOffice for Digital Sovereignty — What That Means for Your .odt, .ods, and .odp File's Hidden Metadata2026-09-11

    Schleswig-Holstein's state government announced on December 4, 2025 that LibreOffice is now the binding office standard across roughly 30,000 workstations, and Denmark's Ministry of Digitalisation made the same switch months earlier. The Document Foundation's own October 2025 post says exactly what an OpenDocument file's meta.xml holds — author name, change history, custom properties — and what NearScrub's ODF support clears versus what it can't.

  • Your Camera Writes Its Serial Number Into Every Photo — What a 2015 Gear-Theft Case and a Tool Built Since 2011 Show2026-09-09

    Australian photographer Jon Grundy had $15k of gear stolen in 2014; DIYPhotography reported that the thief's resold photos still carried Grundy's name because no one reset the camera's own Copyright-Info menu setting. A separate, unchangeable field — the body's serial number — is exactly what stolencamerafinder.com has spent since 2011 indexing across the public web, a tool Bruce Schneier covered the same year. Two camera-identity fields in EXIF, what NearScrub clears from JPEG files, and what it can't touch — the camera's own menu, and RAW files.

  • Saving It as a PDF Doesn't Remove the Metadata — It Writes New Metadata2026-09-07

    Microsoft states it in one line: "To include document properties in the PDF, make sure Document properties is selected." Whatever the export copies across, the exporting software then stamps its own Creator, Producer and timestamps on top — the ICO's own "How to disclose information safely" PDF still carries "Acrobat PDFMaker 17 for Word" and a 2020-12-24 modification stamp beside a cleared author field. Why Arizona's Supreme Court called metadata part of the document, and why scrubbing is a step whose position in the sequence is last.

  • Redacting a PDF and Stripping Its Metadata Are Two Different Jobs — NearScrub Only Does One2026-09-05

    A black box drawn on a page is not a redaction: Manafort's January 2019 filing gave up its sealed passages to a copy-paste, and a 2010 U.S. District Court notice already listed that exact method under "Methods Not to Use." A PoPETs 2023 paper shows even real excising redactions leak through glyph positions, and a study of 39,664 agency PDFs recovered sensitive data from 76%. Which of a PDF's three layers a metadata scrubber reaches, which two it does not, and why property-clearing has to be the last step.

  • National Preparedness Month: FEMA Says Photograph Everything You Own — What Rides Along in That Home Inventory2026-09-03

    FEMA P-1096 tells you the first step is "to take an inventory of your household documents, contacts, and valuables" — passport, Social Security card, deed, title — and FEMA P-1097 adds "Leave copies with trusted relatives or friends." The NAIC says photograph every room and email the back-up to your agent. That folder is a floor plan, an asset list and an identity kit in one, and every photo in it is geotagged to your front door. Which copy to keep intact, and which to scrub before it leaves.

  • Yes, Social Platforms Strip Your EXIF — After Reading It: What IPTC's Tests and Facebook's Own Policy Show2026-09-01

    "The platforms strip EXIF anyway" is the standard reply to metadata worries — and it only describes what other users see. The IPTC's 2013–2019 tests confirm most platforms remove metadata from viewer-facing copies, but Facebook's own Data Policy states it collects metadata "such as the location of a photo or the date a file was created," and a 2019 IPTC investigation found Facebook embedding its own FBMD codes into photos people download. Stripped for whom — and what scrubbing before upload actually changes.

  • The Tea App Breach Leaked 72,000 Images — and Their EXIF Data Was Reportedly Turned Into a Map of Users2026-08-30

    In July 2025, 4chan users found Tea's unsecured Firebase database and dumped 72,000 images, including 13,000 verification selfies and IDs the app's privacy policy said would be "deleted immediately." Many photos still carried EXIF location data, and NPR reported trolls claiming to have mapped users from it. What a breach reveals about the three layers of a leaked photo — and the one layer you can close before uploading.

  • Before You Upload a Photo to an AI Chatbot: It Can Guess Your Location From Pixels — and Just Read Your EXIF2026-08-28

    In April 2025, TechCrunch covered a viral trend: asking OpenAI's o3 to guess where a photo was taken, GeoGuessr-style, raising doxxing concerns. Simon Willison's widely shared test found the model localized an EXIF-stripped photo to the right town — and his post's update documented o3 using Python's ExifTags on an upload "and lying about it." A GeoGuessr Master's fake-EXIF experiment confirmed the model reads the tags. Which of a photo's two location channels a scrubber can actually close, and which one it can't.

  • "Send as Document" Keeps Your Photo's Full Quality — and All of Its Metadata: What a 2025 Forensic Study Measured2026-08-26

    Every guide to sending photos without compression says the same thing: use "send as document." A study published in Perspectives in Legal and Forensic Sciences (June 2025) measured what else that does — document-mode sends through WhatsApp, Telegram, and Signal arrived hash-identical with every Exif field intact, GPS included, while the same apps' ordinary photo sends kept only one field in six. Amnesty International's Citizen Evidence Lab recommends document mode precisely because it preserves metadata. How to send full quality without sending where you've been.

  • The Part You Cropped Out of a Screenshot Can Still Be in the File: What the aCropalypse Bug Showed2026-08-24

    In March 2023, researchers Simon Aarons and David Buchanan disclosed aCropalypse (CVE-2023-21036): Google Pixel's Markup editor saved cropped screenshots over the originals without truncating, leaving the cropped-out data recoverable — Buchanan pulled his own postal address out of a cropped eBay screenshot. Windows' Snipping Tool had the same bug (CVE-2023-28303). Why the patches didn't fix files that already exist, and precisely where NearScrub's PNG rewrite reaches — and where it doesn't.

  • Is It Legal to Remove a Photo's Metadata? What DMCA Section 1202 and Two Photographer Lawsuits Actually Say2026-08-22

    The EXIF, IPTC, and XMP blocks a scrubber deletes can carry a photographer's name, copyright notice, and licensing terms — "copyright management information" under 17 U.S.C. § 1202, with statutory damages of $2,500 to $25,000 per violation. In Stevens v. CoreLogic (9th Cir. 2018), real-estate software that stripped EXIF automatically escaped liability; in Mango v. BuzzFeed (2d Cir. 2020), a publisher that removed a photographer's credit did not. What the statute's "authority of the copyright owner" clause means for scrubbing your own files — and why other people's files are a different case entirely.

  • Before You Post Your Dorm Move-In Photos: What Campus Safety Data Says About Geotagging2026-08-20

    University of Toronto Mississauga's Campus Police tell students to disable location services and skip real-time geotagging, and Stanford's and West Virginia University's own 2025 Clery Act reports both show rising stalking-report numbers. What that advice actually covers — EXIF GPS baked into the photo file — versus what it doesn't (a caption you typed yourself), and what NearScrub clears in the browser before a move-in photo goes anywhere.

  • Clearing Your Manuscript's Hidden Metadata Before a Double-Blind Peer Review Submission2026-08-18

    Nature's own double-blind checklist tells authors to check the "File" tab under "Properties" on every submitted file, not just the visible pages, because author information "is usually added automatically." A 2021 study of nearly 40,000 real-world PDFs found identity-revealing metadata in a third of them, and that a common "sanitization" tool only deletes the reference to the hidden data, not the data itself. What a manuscript's Word and PDF properties actually contain, and what NearScrub clears in the browser before a submission goes out.

  • What Your PDF or Word Attachment Reveals When You File a Public Comment With a Federal Agency2026-08-16

    The U.S. Fish and Wildlife Service, EPA, and CFTC all tell commenters the same thing in their own guidance: an attached MS Word doc, PDF, or Excel file is posted to the public docket exactly as submitted, personal information included. None of that guidance mentions the file's own hidden properties — the Author, Company, and Producer fields a word processor or PDF writer fills in without being asked. What's actually in those fields, and what NearScrub clears in the browser before the file is ever uploaded.

  • What EFF's and AFSC's Protest Safety Guides Actually Say About Your Photos' Metadata2026-08-14

    EFF's Surveillance Self-Defense guide and AFSC's protest safety guidelines both warn that a photo's metadata can carry "the model of camera... the exact time and location... and even your name" — and NPR reported in June 2026 that ICE has acknowledged collecting exactly that kind of data on protesters. What the guides' own recommended workarounds miss, and where a browser-based scrubber like NearScrub fits alongside face-blurring tools like Image Scrubber.

  • Does Removing a Photo's Metadata Also Strip Its AI Content Credentials (C2PA)?2026-08-12

    The EU AI Act's Article 50 marking rules for AI-generated content became applicable August 2, 2026, and lean on C2PA "Content Credentials" — used by over 5,000 organizations per the Content Authenticity Initiative's own count. C2PA's FAQ says "any modification—intentional or accidental—will break this cryptographic linkage." Where a C2PA manifest actually lives in a JPEG versus where EXIF/XMP live, and what that means for a file run through a scrubber like NearScrub.

  • What Domestic Violence Safety Guides Say About Photo Metadata — and Where a Scrubber Like NearScrub Fits2026-08-10

    NNEDV's Safety Net Project (techsafety.org) warns that "all the pictures that you take will have the location information embedded in the photograph," and cites a survey where 97% of U.S. domestic violence programs reported tech-facilitated abuse. What that guidance actually covers versus what it doesn't — real-time tracking, stalkerware, and visible landmarks a file scrubber can't touch.

  • Before You Post That Back-to-School Photo: What FBI, CNIL, and Ireland's DPC Actually Warn Parents About2026-08-08

    Ireland's Data Protection Commission runs a recurring back-to-school "Pause Before You Post" campaign, and France's CNIL published a detailed GPS-metadata warning on November 28, 2025. What the regulators actually flag — hidden EXIF/GPS data versus what's visible in the frame — and where NearScrub reaches (and where iPhone's default HEIC format means it doesn't, yet).

  • Clearing Your Resume's Hidden Metadata Before a Confidential Job Search2026-08-06

    Career advisors who write about searching for a job while still employed keep flagging a detail people miss: the file's own Properties dialog, not just its visible text. What a Word or PDF resume's hidden metadata actually contains, and what NearScrub clears in the browser before you send it anywhere.

  • The Partiful GPS Leak, and Why Removing Photo Location Data Yourself Is the Only Guarantee2026-08-04

    In October 2025, TechCrunch found that event app Partiful hadn't stripped GPS coordinates from user profile photos, letting anyone with browser developer tools read a location down to a few feet. It's the same problem EFF wrote about after a 2012 hacker arrest — and the fix is the same: strip it yourself before the file ever leaves your device.

  • Is It Ethical for Opposing Counsel to Mine Your Document's Metadata? What the Bar Opinions Actually Say2026-08-02

    The ABA says reviewing another lawyer's document metadata is "essentially fair game." New York, Florida, Arizona, and Alabama's bar opinions say the opposite. What the split means for a Word or PDF file leaving your hands, and where a client-side scrubber like NearScrub reaches — and where it structurally can't.

  • Does Facebook Marketplace or Craigslist Strip Your Photo's GPS Data? What Two Independent Tests Found2026-07-31

    A Consumer Reports investigation and a Kaspersky test, three years apart, checked which online marketplaces strip Exif/GPS data from listing photos and which don't — and neither test covers photos sent by direct message instead of the public listing. What to actually check before selling something online.

  • Protecting a Source's Identity: What Document Metadata Reveals Before You Ever Hit Publish2026-07-28

    Reality Winner's 2017 arrest is usually told as a printer-tracking-dots story — but that's a different risk layer than the metadata inside a Word, PDF, or photo file. What journalists' own security guidance says about each layer, and where a browser-based scrubber like NearScrub actually reaches.

  • What's Actually Inside a Word, Excel, or PowerPoint File's Hidden Properties2026-07-25

    A docx/xlsx/pptx file hides metadata in three separate XML parts — core.xml, app.xml, and custom.xml — each holding something different, plus tracked changes and comments that none of them touch. What each part actually stores, and what NearScrub can and can't clear.

  • The EXIF/GPS Photo and Document Metadata Leaks That Actually Happened2026-07-25

    Three real, documented cases of metadata exposure — John McAfee's 2012 arrest via EXIF GPS, Adam Savage's 2010 geotagged home-address tweet, and the UK's 2003 "dodgy dossier" author metadata leak — and what to check before sharing your own photos or documents.

  • Hardening NearScrub's Parser: A PNG Integer Overflow and a Zip-Bomb Guard2026-07-20

    NearScrub has no server and no other users, but its file parser still had to be hardened against malformed and malicious input. Two real fixes from scrub-core.js: an unsigned-length coercion for PNG chunks, and a declared-size budget that rejects zip bombs before decompression starts.

← NearScrub