R/E/P > R/E/P Saloon

Geotagging: Something to be careful with

(1/9) > >>

ktownson:
I've been doing a security presentation at work about phones with GPS and camera capabilities providing means to stalk the unsuspecting user. A lot of people here were totally unaware their phone is providing this info, so I thought I would pass it along.

In a nutshell, iPhones, Androids and Blackberries among others record the GPS coordinates of the phone (called "geotags) when the picture is snapped. This info is saved in the metadata of the photo.

If you upload the photo to many webservices, including facebook, twitter, Flickr, etc., the metadata goes with it, so, by extracting the metadata and putting the coordinates into a map service, you can get an exact location of where the picture was taken.

Some people and websites see this as a feature. Unfortunately, it can also be a stalker's favorite tool. Imagine a cute picture of your 9-year-old daughter in the living room, excitedly holding a Justin Bieber calendar. Her name is on a certificate on the wall behind her. You post it on Flickr. "Mary's just crazy about Justin."  

Creep drives to Fairhope, AL. "Hey, little Mary, want to see a cool picture of Justin Bieber?" The metadata tells the unscrupulous when you shot the picture, how to get directions to the house, and, to boot, he can see a flat panel TV and computer in the background, just in case burglary and not child abduction is his thing.

Yeah, it's a bit paranoid, but just another bit of personal data you should know about so you can manage it. Features like this are usually defaulted to on, and only a few web services prompt you to not include metadata.

Here's some links:  

http://redtape.msnbc.com/2010/12/ten-things-web-users-should -fear-in-2011.html

http://icanstalku.com

http://www.nytimes.com/2010/08/12/technology/personaltech/12 basics.html?_r=4

Our company issues iPhones to certain personnel. So far all but one were defaulted on for the coordinates to be included in the metadata.

RMoore:
Incredible,

Its just a matter of time before enterprising criminals utilize this info - probably most likely for theft, as they already do with google earth

YZ:
ktownson wrote on Thu, 30 December 2010 17:09
by extracting the metadata and putting the coordinates into a map service, you can get an exact location of where the picture was taken.


No need to to all that manually...  at least one freeware image viewer can do it for you in a couple of clicks. (IrfanView)

Nice gal I was chatting with the other day sent me a pic taken with her iPhone, indoors; you should have seen her reaction when a minute later I asked her about some places near her home - and she hadn't even mentioned before in which country she lived, let alone the address...

This is frightening.

ktownson:
the iPhone even told us what direction he was facing when he took the picture. Call me old school, but this is TMI.

YZ:
TMI for sure...  imagine you took a few pics of some gear you want to sell and posted them "anonymously" to a "safe" e-business site.

Anyone can locate the gear and try to have a go at it.

Navigation

[0] Message Index

[#] Next page

Go to full version