Urgent.News

What's breaking now, across thousands of outlets.

Tech

Doxxing Safety Pt I: Prevention and Footprint Management

Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against everyday internet folk when there's little to no comprehensive data privacy legislation keeping us…

Doxxing Safety Pt I: Prevention and Footprint Management

Doxxing is the act of intentionally revealing a person's private information to cause harm. This issue is particularly challenging to prevent when the perpetrator can use legal and accessible methods to carry out the attack. There is a lack of comprehensive data privacy legislation to protect everyday internet users, placing the responsibility on individuals to safeguard their personal information.

However, there are several steps one can take to reduce their digital footprint and minimize the risk of doxxing. This first part of a two-part series focuses on prevention and ways to manage one's online footprint. The second part will cover incident response if someone finds themselves doxxed.

Open source intelligence (OSINT) plays a crucial role in both doxxing campaigns and their prevention. OSINT involves gathering information from publicly available sources to create a dossier on a subject. While advanced tools like Maltego or Lampyre can be useful for organizations, they may not be as effective for everyday users or activists.

Instead, it is recommended to use OSINT resources lists to compile a personalized list of helpful tools. The effectiveness of these tools may vary over time, but the underlying concepts remain relevant.

One important aspect of OSINT is monitoring breach databases, which contain leaked data from breached companies. Websites like Have I Been Pwned and DeHashed provide information on compromised data, allowing individuals to check if their information has been exposed. While changing sensitive information such as email addresses or phone numbers can help mitigate the risk, it can be inconvenient and may not always be feasible.

Public records, such as voter registration and business registration, present another challenge. While these records are publicly accessible to promote transparency, they can also be used by malicious actors. Some sites offer options to request the removal of personal information from public records, although this may not completely eliminate the data's availability.

Social media accounts should also be secured by adjusting privacy settings to limit discoverability. Utilizing username search engines like What's My Name or Namechk can help identify online accounts associated with a particular username, potentially revealing additional points of exposure. Finally, data brokers are companies that sell personal information, posing a significant threat to digital privacy.

Removing data from these brokers often requires manual requests to various vendors, which can be time-consuming and may necessitate the use of specialized services.

Written by urgent.news from EFF Deeplinks's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at eff.org →

More in Tech

More from Monday 31 August →