Doxxing Safety Part II: Incident Response

38 minutes 46 seconds hence

Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimidate their target or worse. 

This guide is a followup from a previous post that describes a methodology for you to clean up your digital footprint and get a firm entry into the art of open source intelligence. There's a slight bit of repetition here, but with a slant towards using those now-familiar tools and methods toward what to do in the context of incident response. The best thing you can do is familiarize yourself with this post and its tactics before something happens, then return back to it for reference when needed.

Incident Log

An incident log is a way to keep track of suspicious or harmful activity online. It doesn't need to be beautiful or complex, just a place where you can quickly note details around the different things you're seeing online. Noting times, places, people, and the general nature of what you see ought to be enough. In the event that law enforcement gets involved, this sort of record will be helpful. 

The process of finding and noting hateful incidents online can be incredibly stressful, so now is a good time to revisit the team roles you might have already thought of in the previous blog post. If you haven't yet done that, here's a brief refresher:

Assign Team Roles

Remember, privacy–and responding to doxxing–is a team sport. Knowing who you trust is as important as identifying threat actors. Having trusted people ready to assist is invaluable in this type of situation. Refer them to this blog post or specific recommendations in it. If you've already plotted out a list of designated team roles, now is the time to remind everyone of their responsibilities. That might look like monitoring the hate forums where activity happens, keeping track of events in the incident log, setting up web alerts, locking down your social media accounts, or contacting law enforcement to reduce the likelihood of SWATing (a type of attack where bad actors call the police on their target, hoping to incite violence or disruption of peace by bringing law enforcement to their door).

Monitoring Hate Forums

So often the victims of doxxing and harassment campaigns are positioned that way because of bias or bigotry. If you're a part of a community who is the target of such abuse, you are likely already aware of the places where such bigots gather and the language they use. Safely and privately accessing those sites to check for organizing against you or those in your community is a crucial step to take. Take great care to do so privately. We recommend you use the Tor browser for such information-gathering missions. It’s also advisable that you don’t engage with anyone in those places.

Again, this step can be particularly stressful; asking a friend for help is a good idea, or you can thoughtfully apply some of the advice from the next section to automate the process.

Set Up Search Alerts

Google alerts is a free service that Google offers to alert you when a particular keyword—like your name—is freshly indexed by their search engine. Doxxing efforts done by anonymous trolls may not trigger an alert, but if you're the target of smear campaigns in the media, or the victim of abuse by very prominent media figures, those things are more likely to appear. Updates can come pretty frequently, so we advise leaving the monitoring of these alerts to a person that you trust.

For a more sophisticated approach, you could use a tool like Open Measures to automate the task of tracking coordinated campaigns. It's important to note that this type of tool is more likely to miss nuanced language or oblique references to you and your community.

Hardening Your Public Facing Accounts

For accounts that you can't or don't want to shut down, at the very least you must review the privacy and security settings on them and consider raising that bar. If two-factor authentication isn't already on, now is the time to do so. For social media accounts, consider switching the account to "private," where users have to request to have access to your page. For peace of mind, especially on accounts that you have to keep using, consider muting certain terms and blocking accounts so that you're less likely to encounter stressful content when on the app. Every app's options are different for this sort of thing, so be prepared to spend a few minutes figuring out what the menu is like and where the options are.

Shut Down Affected Accounts

If a particular account is being targeted with hate, or signs are pointing to an account of yours being the source of information people are using against you, shutting down that account may be the best decision for now. Depending on the app, account deletion may be temporary and you may be able to recover the account after you've done so and things have cooled off.

Revisit Your Data Broker Removal Strategies

Although this is more of a doxxing preventative measure, it's a good idea to get on top of removing the information that's available about you via data brokers. In case you're unaware, the data broker industry is an unregulated viper’s nest of privacy threats, often contributing to or directly supplying the sources of information that are used in doxxing campaigns. Although there are plenty of services that offer to file data broker opt-out requests on your behalf, a recent study revealed that doing it DIY is still more effective than relying on these paid services. That said, a paid service may still be worth its money if you'd rather have someone else take care of it.

Revisit Public Records

As covered in the previous blog post, your information may be made available through public records that you have little to no control over. You may be able to limit the convenience of that information being available by requesting to have it taken down from sites that republish it. Check through voter records, business registration records, court and property records, and the like. If you aren't able to limit that information from appearing on such mirroring sites, at least gaining awareness of where they are and the specific contours of what they contain will help you strategize against the harms they may cause.

Consider Contacting Law Enforcement

For many, talking to law enforcement will only make things worse. On the other hand, SWATing is a tactic often used in these types of coordinated attacks. If you think that's a possible outcome in your situation, it could be a good idea to get ahead of it and contact law enforcement to let them know what you're dealing with. It's in their best interest to be aware of fraudulent calls, and will make them less likely to show up at your door with guns drawn.

Revisit PACE Documents, Enact Those Steps

If you're involved in any kind of activism or community organizing you may be familiar with PACE documentation. It’s an acronym for coming up with contingency plan reactions if unwanted things come up: Primary, Alternate, Contingency, Escape/Emergency. Think of it like a panic button, a routine checklist of things to do if shit hits the fan. Maybe it involves some of the recommendations from this blog post. The point is to have something readymade, and some thoughts and strategies prepared, if the doxxing escalates to increased levels of harm and danger.

This is another step that's best done in a community with trusted people. The point is to keep your community organizing or community work moving, but with special contingency measures enacted to keep you and everyone else safe while remaining aware of this incident. This step is highly personalized and relies on a bit of prep work having already been done.

Put A Lock on Your Bank Accounts and Cell Subscriptions

One of the tactics those who are doxxing you might use is trying to get into your social media or other accounts through “SIM swapping,” an attack where they contact your cellular provider pretending to be you in order to hijack your phone number. They can then use that number and pivot to stealing other accounts you authenticate yourself to with your phone. Likewise, those targeting you might try to steal access to or disrupt your bank accounts through similar techniques. 

Get ahead of them by placing security passwords or pin codes on these highly sensitive accounts, if your bank or cellular provider provides this extra security measure. Most cell providers offer some sort of SIM swapping prevention method, but they all use different names for this feature, so be sure to look up the process in your provider’s documentation (here are guides for the major U.S. providers: Verizon, AT&T, and T-Mobile).

Regulate Your Nervous System

It’s an understatement to say that being doxxed is scary and potentially very dysregulating. You're much more likely to make safe, smart decisions if you are able to maintain a sense of control around your mental state. Recognizing that capability, as well as having a strategy to keep calm in the face of a crisis is just as important as having good digital security hygiene. Do what you need to do, be it involving the help of friends, taking a break, or whatever else, to stay afloat during this process. 

Flexibility and Resiliency

The reality is that the more you experience cultural marginalization, the higher the chances are that adversarial actors will resort to such tactics as doxxing and coordinated harassment campaigns. The fervor of those adversaries is often stoked by hateful public figures and politicians. And the plausible deniability of public records can limit the recourse you have to stop them. We hope that after reading this and the previous post, we’ve also brought to surface the idea that you can have great control over your digital footprint. Even more, that you can continue to share information online without unnecessarily compromising your safety and security. 

Until we have digital privacy protections for everyone, it’s up to us to take matters into our own hands. Privacy, security, and dignity online are achievable. If you follow this guide, the previous one, and stay clued into the strategies laid out on Surveillance Self-Defense, you're well on your way.

Daly Barnett

Doxxing Safety Pt I: Prevention and Footprint Management

28 minutes 54 seconds hence

Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against everyday internet folk when there's little to no comprehensive data privacy legislation keeping us safe. The responsibility is on each of us to protect ourselves, but the good news is that there's a lot you can do to reduce your digital footprint and take control of your data.

This post is part one of a two-part series discussing safety and response to doxxing. This first part focuses on prevention and ways to reduce your overall footprint. The second focuses on incident response, as in, steps to take if you're in the midst of being doxxed. There will be some crossover and redundancy between these two posts, so it's worth reading each and gaining familiarity with the steps well ahead of time.

OSINT

Open source intelligence (OSINT) is a broad term within information security. It focuses on the tools and means available to us for investigation and information retrieval. OSINT sits at the heart of doxxing campaigns but is also an important part of the process of preventing them. Typically it is a way of describing a methodology of piecing together scraps of information to form a dossier on a subject.

There are fancy multipurpose tools (like Maltego or Lampyre) that combine many datapoints into accessible graphs and datasets. As helpful as they can be for traditional penetration tests or corporate OSINT campaigns, they’re best used for investigations focused on organizations, mapping together details like employee email charts, LinkedIn profiles, and company network maps. They may not fit the needs of everyday people or liberation movement workers. Instead, we recommend referring to different OSINT resource lists that index together a bunch of different tools, then using those resources to create a list for yourself of which tools may be most helpful. 

Many, if not all, of the resources we cover below will be referenced in those guides, and themselves fall under the OSINT category. It’s important to note that the tools we reference in this particular blog post are only relevant at the time of publishing. The bigger ideas have a much longer shelf life than various tech tools. That said, in no particular order:

Breach Databases

When a company gets hacked and their customer data is leaked, that information often ends up in “breach databases,” that is, troves of peoples' data available for sale and reuse in illegal trades online. Because of the sensitivity of that type of information, it can potentially be used in doxxing campaigns. Some resources, like haveibeenpwned, note pieces of vulnerable identifying information in those databases and make it easy for people to see if their information is included. Others, like DeHashed, offer a similar sort of tracking, but for a fee. 

You may not have control over a company's digital security that could put your own data at risk, but you can gain insight into whether your information is already out there. This gives you the opportunity to control the accuracy of that data (such as changing your email address or phone number). Doing so is extremely inconvenient, but unfortunately, it may be the only agency you have when another’s company’s digital insecurity puts your own safety at risk.

Open Records

Public records (such as voter records, property records, business registration, medical licensing information, and more) present a dilemma. It is in the public interest for there to be levels of transparency on such information. On the other hand, making such personally-identifiable information accessible to those with ill-intent can lead to serious consequences. 

Instead of requiring a formal request through the courts, mirroring sites make this information easy to find online. Such sites often have forms where you can request your information be taken down. This doesn’t necessarily remove the records from existing, but it does remove a layer of convenience in accessing them.

Some states have programs called “Address Confidentiality Programs” that offer people the right to supplant address information with proxy addresses, keeping public records open but that specific piece of information potentially hidden.

Social Media

Going through and tightening the security and privacy settings of your various social media accounts is always a good idea, but it’s especially important if you are in the process of minimizing your digital footprint. Consider turning your discoverability to “private” or “hidden” (verbiage and details depend on the app) so that only users vetted by you are able to see your account.

To get a quick overview of the various accounts you have registered online, especially if you've been online for a long time, use a username search engine like What's My Name or Namechk to see where your usernames have been registered. They may not be entirely accurate, but they are effective and quick. These tools are also helpful if you are at risk of being impersonated online and want to get an overview of where that may be taking place.

Data Brokers and Removals

Data brokers are craven, pernicious companies that present an existential risk to everyone in the digital age. Until that industry is no more, it's up to us to protect ourselves and the ways that it endangers us by selling personal, sensitive information. The most effective way to get your information removed from their stores is to file requests manually. Yael Grauer's BADBOOL project compiles and prioritizes the worst offenders in this industry and the means you can use to request data removals from them. This process can be grueling and time-consuming, so it may be worth investing in a service that automates the process. Though they've been found to be less effective than the DIY approach, there are some services that have stood out amongst the others in terms of efficacy when tested by third-party reviewers. If you’re a resident of California, you can more easily opt out through the new and exciting DROP tool.

Reverse Image Searching and FR Services

Services like PimEyes and Lenso have jumped on the profit-driven opportunity to create facial recognition as a service. They contribute to law enforcement investigations and predictive policing systems, as well as providing commercial services to abusers and stalkers. The gist of their service: upload a picture of someone (in this case, yourself) and it will use facial recognition technology to determine where else online that person has appeared. If your image is being shared online without your consent, this service will find out. 

Willfully participating in these services does mean having your image mapped, scanned, and stored by their systems. But if you believe you're under the type of targeted harassment that includes your image being shared online against your will, it may be worth that tradeoff.

Extra Monitoring, Automated

This section is less about data minimization, and more about laying extra protections down in the event that doxxing or other coordinated harassment seems imminent. If you're in the Google ecosystem of products, consider enrolling in their Advanced Protection Program, which offers a number of different features to keep you and your account safe. 

If you're the focus of coordinated attacks that span from online communities to media outlets participating in the harassment, a service like Open Measures is worth looking into. It tracks, maps, and analyzes the spread of hateful information online. They provide free access to their open-source API, so with some technical fancy-footwork, you can automate this process.

Get Others Involved

Coordinated harassment is often a process of daisy-chaining targets and tactics together until there’s a meaningful process of harm being inflicted. This means that people in your community are also at risk. As we always say, privacy is a team sport. Get others involved in the process; there’s strength in numbers. 

A great way to do this is think of the activities you and your group are up to. What roles do individual members take on? Figure out a way to tack on some of the responsibilities you’re coming up with here onto those team members. Find ways to talk about it and share strategies, preferably using secure technology like Signal. You can coordinate together which tasks each person could take on, perhaps pulled from this blog post.

It's a Process; Keep Yourself Apace for the Marathon, Not the Race

The process of data minimization and reclaiming agency over your digital footprint can be grueling and stressful. Don't underestimate the toll it can take on your mental health. Take breaks, employ the help of friends, and take the time to make sure you're first addressing the parts that are most relevant to your threat model. It may feel like there’s nothing to be done about protecting your digital privacy, but that’s just a symptom of surveillance capitalism’s psychological effect on its victims. There’s much you can do to stay safe, to protect yourself and others. Refer to this post and to the Surveillance Self-Defense project

Daly Barnett

Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections

1 hour 34 minutes ago

Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should meet to shield individuals from pervasive location surveillance. Since then, state lawmakers across the country have begun responding to calls like these, with Connecticut, Maryland, New Jersey, Oregon, and Virginia enacting new consumer privacy restraints on an industry that profits off our physical movements.

Yet, even as these states move the ball forward to restrict location tracking, most of their laws leave significant gaps that still must be filled. Other states – and Congress – need to get into the game, too, and ensure protection of everyone.

Why Location Privacy Is Important

Imagine spending a couple of hours in a coffee shop, a friend's house, or a healthcare clinic, only to discover yourself under police investigation because your cell phone’s location data exposed your presence there.

This is the reality of geofence warrants for location data, the controversial surveillance technique recently scrutinized by the U.S. Supreme Court in Chatrie v. United States. Through geofencing, tech companies and law enforcement can map everyone who was present within a specific area over a certain window of time, inverting standard constitutional protections by turning every innocent bystander into a potential suspect. While the Supreme Court's ruling in Chatrie established that accessing location data via geofencing constitutes a Fourth Amendment search requiring constitutional protections, law enforcement demands via these warrants are only part of the problem. That same geolocation tracking is used by commercial data brokers operating in a largely unregulated market. These brokers regularly harvest, aggregate, and sell physical location data to anyone with a credit card (including government agencies, which are among their regular clients). Especially for individuals seeking reproductive or gender-affirming care, attending a protest, or visiting an immigration law clinic, this pervasive commercial location surveillance represents an immediate threat.

In Part 1 of this series, we urged lawmakers to protect people from the growing harms of location tracking tools across all areas of public life. The real-world consequences of this unregulated market impact us all. An anti-LGBTQ+ advocacy group spent millions of dollars buying app location data to track priests across multiple dioceses and used app-harvested location data to “out” a priest after purchasing his Grindr location signals. Privacy advocates posing as private investigators gained access to Locate X, a location-tracking tool developed by Babel Street, and demonstrated how the tool tracked a device traveling from Alabama, where abortion is banned, to an abortion clinic in Florida, where access is less restricted. Data brokers like Near Intelligence have sold precise location data of reproductive health clinic visitors directly to political groups. Location data has been used to locate U.S. military personnel in war zones. Law enforcement and private entities have also weaponized location tracking directly against political protesters: surveillance contractors and authorities have utilized location data derived from real-time bidding ad networks to track individuals attending demonstrations.

The unregulated sharing of location data has created an ever-larger funnel for data brokers to capture and monetize our movements. For example, a recent EFF investigation identified several advertising Software Development Kits (SDKs) in Android apps that by default collect and share users' location data whenever app-level location permissions are granted. These advertising libraries automatically feed users' location data into ad systems that location data brokers have used to track people. Because defaults direct real-world outcomes, app developers who fail to carefully scrutinize the third-party SDKs they use, and disable unnecessary data collection, could inadvertently expose their users’ movements to commercial data brokers.

State Legislative Progress

Last year, we outlined six essential core principles that any meaningful location privacy law must contain:

  • Strong definitions,
  • Clear rules,
  • Affirmation that all precise geolocation data is sensitive,
  • Empowerment of consumers through a strong private right of action,
  • Prohibition of “pay-for-privacy” schemes, and
  • Transparency through clear privacy policies.

While the bills we highlighted from California, Illinois, and Massachusetts are yet to pass into law, a new wave of state location privacy legislation has taken effect across Connecticut, Maryland, New Jersey, Oregon, and Virginia.

These five laws represent progress, and share two strong features.  First, all five of these states ban the sale of precise geolocation data. This will remove a strong incentive to collect and store this information in the first place. Other types of privacy laws have likewise banned the sale of sensitive types of data, like the Illinois Biometric Privacy Act (BIPA), which bans the sale of biometric information such as face scans.

Second, all five states broadly define the protected data to include all kinds of locations across the board within a particular distance of a person or their device, rather than protecting just narrowly-defined “sensitive” locations. This all-locations protection sets these laws apart from California’s A.B. 45 of 2025, for example, which only restricts location tracking within 1,850 feet of a family planning center. Protecting location data only near specific locations (like health care facilities) is insufficient: if an individual travels across state lines for care, a data broker can still track their route right up to the boundary of a protected zone and pick it up immediately upon departure, making it easy to infer their destination.

These five laws vary regarding whether, on top of the ban on sale, they require consent and/or minimization for other kinds of processing of precise geolocation data. Maryland’s Online Data Privacy Act (MODPA) requires strict minimization. Specifically, a data controller cannot collect, use, store, or disclose a consumer’s precise geolocation data (or other sensitive data) unless doing so is “strictly necessary to provide or maintain a specific product or service requested by [that] consumer.” Minimization is an important privacy protection because it imposes a duty where it belongs: on the company processing a person’s data. Maryland requires doubly strong minimization. First, the data processing must be “strictly necessary,” and not just “necessary,” or even worse, “reasonably necessary.” Second, the necessity of data processing must be tied to what the particular consumer requested, and not to what a generic customer might hypothetically have thought was reasonable, or the company’s own purposes, or whatever the company buried in its own long-winded legalese.

Connecticut requires both strong consent and weak minimization. Specifically, it forbids a data controller from collecting, using, storing, or disclosing a consumer’s precise geolocation data (among other sensitive data) “without first obtaining [that] consumer’s consent”. Connecticut has a strong definition of consent: “a clear affirmative act signifying freely given, specific, informed and unambiguous agreement,” which is absent from “agreement obtained through the use of dark patterns.” On top of this strong consent, Connecticut also requires a weak form of minimization: the data processing must be “reasonably necessary in relation to the purposes for which such sensitive data are processed”. But this does not weaken Connecticut’s strong consent rule.

New Jersey requires consent to collect, use, store, or disclose a person’s precise geolocation data (and other sensitive data).

Virginia protects location data with both minimization and consent, but only for one kind of people (known children) and only for one kind of data processing (collection). Under Virginia’s minimization rule, a data controller cannot collect such data from such people unless doing so “is reasonably necessary for the controller to provide an online service,” and in such cases, “only … for the time necessary” to do so. This would be a much stronger rule if the authors struck the modifier “reasonably” before the word “necessary,” or better yet, substituted the modifier “strictly.”

Beyond its ban on sale, Oregon does not limit the processing of precise geolocation data.

Gaps in Current Legislation

While these enacted bills mark steps in the right direction, major loopholes remain that leave users vulnerable.

The Enforcement Void: Why Every Law Needs a Private Right of Action

A privacy law without a Private Right of Action is a law "without teeth”.

None of these five state statutes expressly empower consumers to directly sue companies that violate their location privacy rights. Relying exclusively on state Attorneys General or specialized regulatory agencies creates a critical bottleneck, since no regulatory agency possesses the staffing or budget required to investigate every data privacy violation. Additionally, government enforcement priorities shift across administrations, leaving enforcement vulnerable to political pressures and corporate lobbying.

The best way to ensure effective enforcement is a free-standing, explicit Private Right of Action written directly into the privacy statute. Some legislative privacy proposals instead attempt to provide remedies by piggybacking on state laws against unfair, deceptive, or abusive practices (UDAP). But this is often hit-or-miss depending on each state’s specific UDAP law, including who must have what kind of injury to have standing to bring a private action, and the scope of remedies. For instance, while Maryland’s MODPA provides that a violation of the statute constitutes a banned UDAP, it appears that the new law’s enforcement mechanics were drafted in a way that provides only government enforcement through the Attorney General’s Consumer Protection Division, rather than granting consumers a private right of action.

Any a private right of action should come complete with statutory liquidated damages to remedy non-economic harm, and prohibitions against mandatory arbitration. This ensures that compliance isn't optional. Until corporate bad actors face direct accountability from the very people whose personal location data they unlawfully exploit, state privacy laws will rely on overworked regulators to police an industry that profits off our every move.

The "Pay-for-Privacy" Trap

Privacy is a fundamental right, not a luxury tier. So EFF opposes pay-for-privacy schemes, in which companies charge a higher price to people who exercise their privacy rights. To prevent these schemes, data privacy legislation must prohibit companies from retaliating against consumers who exercise their statutory privacy rights, including by charging a higher price. For example, if a statute bars a company from processing a person’s data absent their consent, and that person withholds consent, the statute must bar the company from responding by charging a higher price.

Unfortunately, all three of these states that require consent to process precise geolocation information (Connecticut, New Jersey, and Virginia) have only weakly limited pay-for-privacy schemes. While all three prohibit discrimination against customers who withhold consent, all three also have a wide loophole: for discount programs. To make matters worse, none of these three states prevent the discount programs from selling customer data to third parties. But people should not have to surrender their data privacy to join a discount club for regular customers. Thus, the far better approach is to eschew this loophole, as in the ban on pay-for-privacy in last year’s location data privacy bills in Illinois and Massachusetts.

These exceptions allow companies to charge higher prices or downgrade service quality for users who exercise their privacy rights. In practice, this converts privacy into a privilege for those who can afford it, forcing economically vulnerable communities to trade away their sensitive location movements in exchange for essential discounts or services.

Dark Patterns

Any law that requires consent also needs to ban company techniques that subvert consent. These are often called dark patterns, predatory design, and manipulative user interface (UI/UX) practices.

Connecticut’s definition of “consent” excludes “dark patterns,” as noted above. That state defines dark patterns as “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice,” including any practice that the FTC refers to as a dark pattern. Other consent-based privacy rules must do so, too.

Conclusion

The recent wave of state legislation demonstrates that momentum is building against location surveillance. However, state leaders must go further.

To build privacy protections that withstand corporate workaround attempts, future bills must apply to all locations universally, give individuals the legal standing to enforce their own rights in court, and fully prohibit pay-for-privacy. Until comprehensive data privacy legislation with real teeth is enacted nationwide, users can consult EFF's Surveillance Self-Defense Guide to learn practical steps for reducing location tracking on their personal devices.

Rindala Alajaji

【編集部EYE】文春砲の生みの親から依頼で出版=橋詰雅博

2 hours 23 minutes ago
 1988年東京で起きた女子高生コンクリート詰め殺人事件を題材にした『償い』は加害少年6人の「その後」を追った本だ。著者の山﨑裕侍氏(HBC北海道放送報道部デスク)は7月4日JCJオンライン講演で「更生」と「再犯」の分かれ道という主題とは別に出版にまつわる秘話も紹介した。 山﨑氏はこの事件を制作会社からテレビ朝日に出向しディレクターを務めた「ニュースステーション」やその後番組「報道ステーション」などで報じるだけでなく、ウエブメディアで詳報を配信した。 昨年1月配信記事などを見..
JCJ

LGBT Q&A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person?

2 hours 26 minutes ago

This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our TikTok or Instagram to watch! 

EFF answers all the queer digital rights questions you submit to us through our LGBT Q&A. You asked us: What’s one thing I can do today to improve my safety and security online as an LGBTQ+ person? 

And for this question, we’ve brought in our friends from the Trevor Project to answer together:

Hi, I’m Tommy from the Trevor Project! The Trevor Project’s mission is to end suicide among lesbian, gay, bisexual, transgender, queer, and questioning (LGBTQ+) young people. Our vision is to create a world where all LGBTQ+ young people see a bright future for themselves.

EFF and the Trevor Project know that digital security and online safety can feel overwhelming, especially because we all have different levels of concern for different parts of our online lives. Some might be focused on the dangers of doxxing, another might only want to ensure they're not outed. And queer people can be particularly vulnerable to these kinds of online threats. 

This might seem like a big task, but the one way you can do today to protect yourself is to revise the information you’ve shared with services and platforms to ensure you’re as in control of your information and data as possible:

Protect Your Personal Information

Be cautious about sharing sensitive details like your full name, address, school, phone number, and personal photos as it might expose identifying information you want to keep private. Consider using an avatar as your profile picture to avoid sharing your personal photos if that makes you more comfortable. Keep it lowkey when talking about work stuff or sharing details about where you’re studying.

If you do share personal photos, don’t accompany them with information that identifies your location or frequent whereabouts, and make sure EXIF data in photos is turned off (which could inadvertently include your location); the easiest way to do this is to take a screenshot of the photo and share that instead. Don’t post pictures with obvious spots in the background, like your front door or porch. 

Understand the Importance of Login Information

When you create an account on websites and platforms, you can often use your phone number or a third party account, such as Facebook, Google, or Apple. These external accounts might share data with the apps you're logging into, but they can be helpful if you struggle with managing a lot of logins. Deciding if that trade-off is worth it is up to you but, when you can, use strong, unique passwords for your accounts, and be sure to enable two-factor authentication when offered. 

Review Permissions with Social Media Apps

Review which apps have access to things like your location and camera roll, and possibly change those permissions in line with what information you would like to keep private. Location is particularly important. For example, some apps might need some location information to function. But you can typically at least deny access to your device's "precise location" or enter in a city or zip code manually.

Consider What You Share When Speaking with Others Online

It’s important to be mindful of what you share with others when you post online or speak with people. Avoid disclosing sensitive information like financial details, and trust your gut if something feels off. It’s also useful to review your profile’s privacy settings and information now and again to make sure you’re still comfortable sharing what you’ve listed there.

Good privacy decisions begin with proper knowledge about your situation and a community-oriented approach. To dig in deeper, read EFF’s blog post on Building a Community Privacy Plan and the Trevor Project’s Guide to Online Safety for LGBTQ+ Young People.

Paige Collings