Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Doxxing Safety Part II: Incident Response

31 August 2026 at 19:02

Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimidate their target or worse. 

This guide is a followup from a previous post that describes a methodology for you to clean up your digital footprint and get a firm entry into the art of open source intelligence. There's a slight bit of repetition here, but with a slant towards using those now-familiar tools and methods toward what to do in the context of incident response. The best thing you can do is familiarize yourself with this post and its tactics before something happens, then return back to it for reference when needed.

Incident Log

An incident log is a way to keep track of suspicious or harmful activity online. It doesn't need to be beautiful or complex, just a place where you can quickly note details around the different things you're seeing online. Noting times, places, people, and the general nature of what you see ought to be enough. In the event that law enforcement gets involved, this sort of record will be helpful. 

 Where/Site, Date & Time, Brief Description of Action, Threat-Actor Name/Description, Any Other People Involved.

The process of finding and noting hateful incidents online can be incredibly stressful, so now is a good time to revisit the team roles you might have already thought of in the previous blog post. If you haven't yet done that, here's a brief refresher:

Assign Team Roles

Remember, privacy–and responding to doxxing–is a team sport. Knowing who you trust is as important as identifying threat actors. Having trusted people ready to assist is invaluable in this type of situation. Refer them to this blog post or specific recommendations in it. If you've already plotted out a list of designated team roles, now is the time to remind everyone of their responsibilities. That might look like monitoring the hate forums where activity happens, keeping track of events in the incident log, setting up web alerts, locking down your social media accounts, or contacting law enforcement to reduce the likelihood of SWATing (a type of attack where bad actors call the police on their target, hoping to incite violence or disruption of peace by bringing law enforcement to their door).

Monitoring Hate Forums

So often the victims of doxxing and harassment campaigns are positioned that way because of bias or bigotry. If you're a part of a community who is the target of such abuse, you are likely already aware of the places where such bigots gather and the language they use. Safely and privately accessing those sites to check for organizing against you or those in your community is a crucial step to take. Take great care to do so privately. We recommend you use the Tor browser for such information-gathering missions. It’s also advisable that you don’t engage with anyone in those places.

Again, this step can be particularly stressful; asking a friend for help is a good idea, or you can thoughtfully apply some of the advice from the next section to automate the process.

Set Up Search Alerts

Google alerts is a free service that Google offers to alert you when a particular keyword—like your name—is freshly indexed by their search engine. Doxxing efforts done by anonymous trolls may not trigger an alert, but if you're the target of smear campaigns in the media, or the victim of abuse by very prominent media figures, those things are more likely to appear. Updates can come pretty frequently, so we advise leaving the monitoring of these alerts to a person that you trust.

For a more sophisticated approach, you could use a tool like Open Measures to automate the task of tracking coordinated campaigns. It's important to note that this type of tool is more likely to miss nuanced language or oblique references to you and your community.

Hardening Your Public Facing Accounts

For accounts that you can't or don't want to shut down, at the very least you must review the privacy and security settings on them and consider raising that bar. If two-factor authentication isn't already on, now is the time to do so. For social media accounts, consider switching the account to "private," where users have to request to have access to your page. For peace of mind, especially on accounts that you have to keep using, consider muting certain terms and blocking accounts so that you're less likely to encounter stressful content when on the app. Every app's options are different for this sort of thing, so be prepared to spend a few minutes figuring out what the menu is like and where the options are.

Shut Down Affected Accounts

If a particular account is being targeted with hate, or signs are pointing to an account of yours being the source of information people are using against you, shutting down that account may be the best decision for now. Depending on the app, account deletion may be temporary and you may be able to recover the account after you've done so and things have cooled off.

Revisit Your Data Broker Removal Strategies

Although this is more of a doxxing preventative measure, it's a good idea to get on top of removing the information that's available about you via data brokers. In case you're unaware, the data broker industry is an unregulated viper’s nest of privacy threats, often contributing to or directly supplying the sources of information that are used in doxxing campaigns. Although there are plenty of services that offer to file data broker opt-out requests on your behalf, a recent study revealed that doing it DIY is still more effective than relying on these paid services. That said, a paid service may still be worth its money if you'd rather have someone else take care of it.

Revisit Public Records

As covered in the previous blog post, your information may be made available through public records that you have little to no control over. You may be able to limit the convenience of that information being available by requesting to have it taken down from sites that republish it. Check through voter records, business registration records, court and property records, and the like. If you aren't able to limit that information from appearing on such mirroring sites, at least gaining awareness of where they are and the specific contours of what they contain will help you strategize against the harms they may cause.

Consider Contacting Law Enforcement

For many, talking to law enforcement will only make things worse. On the other hand, SWATing is a tactic often used in these types of coordinated attacks. If you think that's a possible outcome in your situation, it could be a good idea to get ahead of it and contact law enforcement to let them know what you're dealing with. It's in their best interest to be aware of fraudulent calls, and will make them less likely to show up at your door with guns drawn.

Revisit PACE Documents, Enact Those Steps

If you're involved in any kind of activism or community organizing you may be familiar with PACE documentation. It’s an acronym for coming up with contingency plan reactions if unwanted things come up: Primary, Alternate, Contingency, Escape/Emergency. Think of it like a panic button, a routine checklist of things to do if shit hits the fan. Maybe it involves some of the recommendations from this blog post. The point is to have something readymade, and some thoughts and strategies prepared, if the doxxing escalates to increased levels of harm and danger.

Example spreadsheet of a PACE document for a hypothetical group attending a protest. It has four columns, Primary, Alternate, Contingency, and Emergency. Each column describes what the hypothetical group plans to do in the event of various disruptions taking place, with agreements to each other about communications strategies, meeting times and places.

This is another step that's best done in a community with trusted people. The point is to keep your community organizing or community work moving, but with special contingency measures enacted to keep you and everyone else safe while remaining aware of this incident. This step is highly personalized and relies on a bit of prep work having already been done.

Put A Lock on Your Bank Accounts and Cell Subscriptions

One of the tactics those who are doxxing you might use is trying to get into your social media or other accounts through “SIM swapping,” an attack where they contact your cellular provider pretending to be you in order to hijack your phone number. They can then use that number and pivot to stealing other accounts you authenticate yourself to with your phone. Likewise, those targeting you might try to steal access to or disrupt your bank accounts through similar techniques. 

Get ahead of them by placing security passwords or pin codes on these highly sensitive accounts, if your bank or cellular provider provides this extra security measure. Most cell providers offer some sort of SIM swapping prevention method, but they all use different names for this feature, so be sure to look up the process in your provider’s documentation (here are guides for the major U.S. providers: Verizon, AT&T, and T-Mobile).

Regulate Your Nervous System

It’s an understatement to say that being doxxed is scary and potentially very dysregulating. You're much more likely to make safe, smart decisions if you are able to maintain a sense of control around your mental state. Recognizing that capability, as well as having a strategy to keep calm in the face of a crisis is just as important as having good digital security hygiene. Do what you need to do, be it involving the help of friends, taking a break, or whatever else, to stay afloat during this process. 

Flexibility and Resiliency

The reality is that the more you experience cultural marginalization, the higher the chances are that adversarial actors will resort to such tactics as doxxing and coordinated harassment campaigns. The fervor of those adversaries is often stoked by hateful public figures and politicians. And the plausible deniability of public records can limit the recourse you have to stop them. We hope that after reading this and the previous post, we’ve also brought to surface the idea that you can have great control over your digital footprint. Even more, that you can continue to share information online without unnecessarily compromising your safety and security. 

Until we have digital privacy protections for everyone, it’s up to us to take matters into our own hands. Privacy, security, and dignity online are achievable. If you follow this guide, the previous one, and stay clued into the strategies laid out on Surveillance Self-Defense, you're well on your way.

Doxxing Safety Pt I: Prevention and Footprint Management

31 August 2026 at 18:52

Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against everyday internet folk when there's little to no comprehensive data privacy legislation keeping us safe. The responsibility is on each of us to protect ourselves, but the good news is that there's a lot you can do to reduce your digital footprint and take control of your data.

This post is part one of a two-part series discussing safety and response to doxxing. This first part focuses on prevention and ways to reduce your overall footprint. The second focuses on incident response, as in, steps to take if you're in the midst of being doxxed. There will be some crossover and redundancy between these two posts, so it's worth reading each and gaining familiarity with the steps well ahead of time.

OSINT

Open source intelligence (OSINT) is a broad term within information security. It focuses on the tools and means available to us for investigation and information retrieval. OSINT sits at the heart of doxxing campaigns but is also an important part of the process of preventing them. Typically it is a way of describing a methodology of piecing together scraps of information to form a dossier on a subject.

There are fancy multipurpose tools (like Maltego or Lampyre) that combine many datapoints into accessible graphs and datasets. As helpful as they can be for traditional penetration tests or corporate OSINT campaigns, they’re best used for investigations focused on organizations, mapping together details like employee email charts, LinkedIn profiles, and company network maps. They may not fit the needs of everyday people or liberation movement workers. Instead, we recommend referring to different OSINT resource lists that index together a bunch of different tools, then using those resources to create a list for yourself of which tools may be most helpful. 

Many, if not all, of the resources we cover below will be referenced in those guides, and themselves fall under the OSINT category. It’s important to note that the tools we reference in this particular blog post are only relevant at the time of publishing. The bigger ideas have a much longer shelf life than various tech tools. That said, in no particular order:

Breach Databases

When a company gets hacked and their customer data is leaked, that information often ends up in “breach databases,” that is, troves of peoples' data available for sale and reuse in illegal trades online. Because of the sensitivity of that type of information, it can potentially be used in doxxing campaigns. Some resources, like haveibeenpwned, note pieces of vulnerable identifying information in those databases and make it easy for people to see if their information is included. Others, like DeHashed, offer a similar sort of tracking, but for a fee. 

You may not have control over a company's digital security that could put your own data at risk, but you can gain insight into whether your information is already out there. This gives you the opportunity to control the accuracy of that data (such as changing your email address or phone number). Doing so is extremely inconvenient, but unfortunately, it may be the only agency you have when another’s company’s digital insecurity puts your own safety at risk.

Open Records

Public records (such as voter records, property records, business registration, medical licensing information, and more) present a dilemma. It is in the public interest for there to be levels of transparency on such information. On the other hand, making such personally-identifiable information accessible to those with ill-intent can lead to serious consequences. 

Instead of requiring a formal request through the courts, mirroring sites make this information easy to find online. Such sites often have forms where you can request your information be taken down. This doesn’t necessarily remove the records from existing, but it does remove a layer of convenience in accessing them.

Some states have programs called “Address Confidentiality Programs” that offer people the right to supplant address information with proxy addresses, keeping public records open but that specific piece of information potentially hidden.

Social Media

Going through and tightening the security and privacy settings of your various social media accounts is always a good idea, but it’s especially important if you are in the process of minimizing your digital footprint. Consider turning your discoverability to “private” or “hidden” (verbiage and details depend on the app) so that only users vetted by you are able to see your account.

To get a quick overview of the various accounts you have registered online, especially if you've been online for a long time, use a username search engine like What's My Name or Namechk to see where your usernames have been registered. They may not be entirely accurate, but they are effective and quick. These tools are also helpful if you are at risk of being impersonated online and want to get an overview of where that may be taking place.

Data Brokers and Removals

Data brokers are craven, pernicious companies that present an existential risk to everyone in the digital age. Until that industry is no more, it's up to us to protect ourselves and the ways that it endangers us by selling personal, sensitive information. The most effective way to get your information removed from their stores is to file requests manually. Yael Grauer's BADBOOL project compiles and prioritizes the worst offenders in this industry and the means you can use to request data removals from them. This process can be grueling and time-consuming, so it may be worth investing in a service that automates the process. Though they've been found to be less effective than the DIY approach, there are some services that have stood out amongst the others in terms of efficacy when tested by third-party reviewers. If you’re a resident of California, you can more easily opt out through the new and exciting DROP tool.

Reverse Image Searching and FR Services

Services like PimEyes and Lenso have jumped on the profit-driven opportunity to create facial recognition as a service. They contribute to law enforcement investigations and predictive policing systems, as well as providing commercial services to abusers and stalkers. The gist of their service: upload a picture of someone (in this case, yourself) and it will use facial recognition technology to determine where else online that person has appeared. If your image is being shared online without your consent, this service will find out. 

Willfully participating in these services does mean having your image mapped, scanned, and stored by their systems. But if you believe you're under the type of targeted harassment that includes your image being shared online against your will, it may be worth that tradeoff.

Extra Monitoring, Automated

This section is less about data minimization, and more about laying extra protections down in the event that doxxing or other coordinated harassment seems imminent. If you're in the Google ecosystem of products, consider enrolling in their Advanced Protection Program, which offers a number of different features to keep you and your account safe. 

If you're the focus of coordinated attacks that span from online communities to media outlets participating in the harassment, a service like Open Measures is worth looking into. It tracks, maps, and analyzes the spread of hateful information online. They provide free access to their open-source API, so with some technical fancy-footwork, you can automate this process.

Get Others Involved

Coordinated harassment is often a process of daisy-chaining targets and tactics together until there’s a meaningful process of harm being inflicted. This means that people in your community are also at risk. As we always say, privacy is a team sport. Get others involved in the process; there’s strength in numbers. 

A great way to do this is think of the activities you and your group are up to. What roles do individual members take on? Figure out a way to tack on some of the responsibilities you’re coming up with here onto those team members. Find ways to talk about it and share strategies, preferably using secure technology like Signal. You can coordinate together which tasks each person could take on, perhaps pulled from this blog post.

It's a Process; Keep Yourself Apace for the Marathon, Not the Race

The process of data minimization and reclaiming agency over your digital footprint can be grueling and stressful. Don't underestimate the toll it can take on your mental health. Take breaks, employ the help of friends, and take the time to make sure you're first addressing the parts that are most relevant to your threat model. It may feel like there’s nothing to be done about protecting your digital privacy, but that’s just a symptom of surveillance capitalism’s psychological effect on its victims. There’s much you can do to stay safe, to protect yourself and others. Refer to this post and to the Surveillance Self-Defense project

Primed for Malware: Stop Selling Compromised Android Devices

Time and time again, researchers have found numerous compromised Android devices for sale at large online retailers like Amazon. When these devices get individually reported, we have seen some noted efforts to take them down. But this is a systemic problem and Amazon and other major online retailers must make a corresponding systemic and intentional effort to stop these devices from entering people’s homes and ultimately their networks.

As a refresher: Last year, Google wrote that one major campaign, deemed BADBOX, affected 10 million uncertified devices that were running Android’s open-source software (Android Open Source Project or AOSP). These devices span from TVs and streaming devices to digital picture frames. Even now, someone can go on Amazon and Walmart and buy one of these devices. Not all of them come from Amazon and Walmart, but it’s fair to assume since they have the lion’s share of the market.

Most well-known Android-based devices don’t come with just “stock Android.” The operating system is usually Android plus additional features that the manufacturer wanted. These custom versions of Android often come with pre-installed applications that range from useful to innocuous bloatware to actual malware. Many Android OEMs (original equipment manufacturers) pre-install apps that may not be visibly represented by an icon in your list of installed apps. This obscurity makes the issue particularly hard for users to identify any potential threats.

Since the initial BADBOX analysis, there have been more reports of large campaigns and clusters of different devices participating in malicious activities that utilize people’s home networks to engage in illegal activity. Task forces in the private sector have made an effort to take down these existing Command and Control structures, but these actors may pivot and evolve to flood the market with more devices. 

Online retailers can stop this cycle. A multi-billion dollar company like Amazon should offer more resources, like their anti-fraud efforts, given that these products may have facilitated conditions for large scale attacks and illegal activity. It would also be helpful if they communicated malware-related take downs in a more visible way to consumers who are seeking very similar devices with shared characteristics.

Identifying these devices can be tricky, but it’s not impossible because they tend to follow a pattern. For example, the FBI warned consumers this year to avoid TV streaming devices that claim to provide free sports, tv shows, and movies, a common tactic used by the makers of these malware-filled Android devices that leverages people’s exhaustion from spending money on countless streaming services. We detailed what sorts of indicators to look for on a device you’ve purchased.

But it’s not just the storefronts. There are other parts of this ecosystem that need to improve too, like increased engagement in firmware transparency and the actual manufacturers of the devices themselves being held accountable for these malware laced products.

On Prime Day, we urge retailers like Amazon to better empower users with information they need to make safe and smart decisions.

Field Notes from a Year of OPSEC Training

Late last year, as part of our annual “Year in Review” series, we summarized our efforts providing digital privacy and security advice to at-risk communities. OPSEC trainings (short for operational security, a catch-all term we use to describe any kind of workshop, advising session, assessment, or presentation about operational security for individuals and organization) are something we've long provided, but until recently, something we’ve never broadcasted.

This has become a critical aspect of our work over the years, keeping us grounded and in touch with the realities of tech-enabled violence as well as evolving resistance strategies used by movement workers. Hoping other security trainers and organizers copy our homework, here’s a more thorough breakdown.

NOT TRADITIONAL PENTESTING

To be clear, we're not a 'pentesting' company, which refers to the methodological process of testing a person or organization's security and privacy posture, nor an information security (infosec) firm that offers anything within scopes of traditional security assessments.  Infosec companies almost always adhere to a cycle of: discovery/reconnaissance; > vulnerability scanning and testing; > exploitation of vulnerabilities found; > and a reportback of recommended mitigation strategies. Such full-spectrum audits can run the gamut of testing network security, physical security, organization posture against phishing or ransomware attacks, web app security, and more. For many organizations, the value of such engagements is immeasurable.

Such companies—although equipped with the technical sophistication to do full-spectrum digital security auditing and testing—often lack the critical points of view of human rights defenders and activists. Many human rights defenders and liberation movement workers are critically under-resourced and unable to meet the high costs of engagement with such infosec companies.  But that’s not what we offer. Our trainings center the needs of people on the ground, and offer this work pro bono. 

The cycle of engagement our work tends to take is similar to the lifecycle of pentesting outlined above, but with some key differences better suited to people-powered movements. 

We begin with a period of discovery about the organization we’re engaging with, learning about their work, the issue space they’re working in, and the types of threats their peers have faced in the past. Relying on our knowledge of known threat actors (state-operated threats, non-state actors, surveillance mechanisms, and more), we conduct a thorough threat modeling and risk assessment exercise, surfacing critical pieces of information about what we ought to prioritize protecting and from what. Sometimes that’s enough for a group to get started on improving their security plans, and we send them on their way.

After receiving consent from the group to do so, we may perform some OSINT (open source intelligence) investigation and map out a sketch of their digital footprint. This often looks like some combination of discoverability through public records, data broker ecosystems, and breach databases, as well as risks they may incur through the services they rely on for their web presence. That latter part can be done with typical pentesting reconnaissance tools, as well as our own project Privacy Badger for mapping the trackers on their website, which pose them and their users some amount of risk. Working from this sketch of their digital footprint, opportunities to lessen the reach of their data exposure, or at least the more sensitive areas they ought to be aware of, become apparent.

For a more in-depth engagement, we take the information gathered from the guided threat modeling exercises, as well as the digital footprint we’ve developed for them, and we move on to training the participants on what they need to address their threats. Sometimes that looks like a deep dive on encryption and how it can be used to protect data backups and secure communications. Other times it looks like getting very knowledgeable and practiced on the various ways to stay safe from surveillance threats encountered at a protest. Often though, our engagement with those asking for advice on how to strengthen their OPSEC is as simple as presenting materials covered in our Surveillance Self-Defense (SSD) project, but with EFF staff to help apply those lessons to their context.

MOVEMENTS AND COMMUNITIES ADVISED

Requests for such training mostly arise organically, either via referral, from our participation in external media, or driven by an interest in SSD. Naturally, the demand for accessible OPSEC advice escalates along with the general sophistication and reach of surveillance technology. And as authoritarianism creeps and continues to threaten the movement workers fighting against it, there's a marked urgency for that demand.

The types of communities and liberation movement workers that reach out run a wide array of experiences, but some commonalities stick out. Since the fall of Roe v. Wade, we've seen a huge uptick in abortion access activists like clinic escorts and information distribution networks reaching out. So too are providers of criminalized healthcare services, both abortion services and gender affirming care alike. The list goes on: advocates for transgender rights such as art collectives and archivists, sex worker rights activists, survivors of intimate partner violence, climate justice activists, legal defense groups focusing on immigrant justice and Black liberation. And many, many others, often stemming from experiences of distinct marginalization and state-powered violence.

We’re dressing the wounds the violence of surveillance inflicts.

TAXONOMY OF THREATS

When there's a cast of common threat actors that so often emerge during risk assessment (ideologically motivated harassers, lawmakers, cops, negligent leadership at large tech platforms, etc) there is a level of predictability about their capabilities. We use that information to make knowledgeable risk assessments for those we’re working with, determining the means that threat actors have to cause them harm, as well as the likelihood.

For community organizers and grassroots activists we most often see concerns around doxxing (and harassment driven by OSINT), social media monitoring, content suppression on tech platforms, and insider threats such as infiltration within trusted communication channels. Often this comes with a tension between publicity and privacy—needing to spread their message and further their cause, while recognizing that digital privacy has a profound impact on their personal safety. Some activists may instead hope to organize other more covert forms of direct action. They're more likely to be concerned about the types of street level surveillance that they may encounter.

Small organizations nonprofit and otherwise may share the concerns around doxxing, as well as traditional digital security concerns around their web presence. Website defacement and data exfiltration are particular concerns for organizations that don't have the resources to commit to IT security staff. And for those that do have meager budgets for such things, organizational compliance and ease-of-use regarding privacy and security technologies are a whole other concern. The question then becomes how to manage a system of distributed devices that are uncontrolled by the organization, but operationally necessary for each member of their community. 

Generally speaking, the threats most commonly encountered in these spaces have to do with the opacity and unchecked reach of surveillance systems. With every single individual or group that we encounter in this type of work, threat modeling comes number one in terms of priority. There is no way to protect against every theoretical threat. Instead, we walk others through the process of identifying and then prioritizing known and perceived threats, based on their specific context and the type of work that they do, before moving on to recommended mitigation and resistance strategies. 

STRATEGIES OF RESISTANCE

Developing a threat model without a course of action often does more to stoke privacy nihilism than remedy the risks communities face. The more we engage with at-risk communities and offer reasonable, accessible OPSEC advice, the greater our instinct develops for recognizing such strategies. At the core of these recommendations lie the backbones of privacy and security fundamentals, such as encryption, access controls, sophisticated backup plans, OSINT skills, and resistance to online tracking.

Over the years, we've found it easiest to begin with non-technical recommendations first. These strategies often mesh well with the community's extant organizing procedures, such as designating team roles and thought out contingency plans for specific risks. This may look like identifying those extant plans and tacking on responsibilities like data backups, code words for community vetting, and developing workarounds or contingency plans for if they lose access to specific technologies. 

Eventually, though, the strategies must become more technical, like switching to more private and secure technology alternatives, developing a sophisticated and encrypted data backup plan, and having technical contingency plans in place for if/when they are deplatformed or their services interrupted. Developing patience and compassion when walking groups through unfamiliar technologies is an essential tool of this work. So too is the habit of checking ourselves, as privacy and security nerds, to know the difference between the most secure technologies and those which will actually be used by at-risk community members. Any step towards more thoughtful OPSEC is better than one too difficult to use. The last thing we want is a recommendation that results in people frustratedly giving up on doing anything at all. After all, the whole point of this is to empower movement workers, not inhibit them.

HOLISTIC MITIGATIONS

It is painfully obvious how many identified threats could be protected against if there were comprehensive data privacy legislation protecting all people. The lack of such is an existential threat to everyone. Bills that undermine peoples' right to privacy are never clear about what they're doing, and often come wrapped in some paternalistic guise of addressing some other harm elsewhere. They often use confusing, oblique language that preys on the public's interest to correct the course of other social harms. The reality is that when it’s clearly explained, every person online wants better privacy. And as we know, every individual's personal security and wellbeing are entwined with their access to privacy. The capacity with which a person can decide what to share online, rather than have sensitive information non-consensually taken from them by creepy surveillance technologies, is a matter of self-determination. And it's in all our best interests to fight for the right to self-determination.

WHAT WE GET BACK

An unexpected outcome of identifying so many common threat actors across such varied issue spaces is revealing potential avenues of collaboration and camaraderie. Some movements are already keen on this allyship, such as those focusing on various aspects of bodily autonomy and self-determination. Abortion access activists and trans liberation activists are often in concerted allyship. Other less obvious connections are legal defense groups that offer "know-your-rights" style educational materials and other issue-specific activists who have questions about the legal threats they're facing while fighting for their cause. 

Recognizing the common threat actors across different issue spaces begins to highlight opportunities for collective action against those threats. As a digital rights organization, this is very much our wheelhouse, and precisely why our technologist team is self-described as one working toward the public interest. It’s also from this point of view that we continue to win. And why it’s critical for lawmakers to pay attention when we say particular pieces of bad legislation are harmful to public safety. And finally, why it is necessary for public interest technologists and digital rights activists to connect with other communities to learn about the specific technology risks they’re worried about. As Mariame Kaba says, “Nothing that we do that is worthwhile is done alone.” This very blog post is in an effort to provoke thought for digital security trainers, so that we as a community don’t work atomized and alone, reproducing the same work, exhausting ourselves and creating unnecessary redundancy.

We do what we can to keep up. And thankfully, we participate within an ecosystem of digital security providers that have a keen mind towards fighting for digital rights. We share resources, referrals, and expertise. Our Surveillance Self-Defense project is stress-tested by the experiences shared by the liberation movement workers we engage with and provide this work to. If you’re interested in becoming a digital security resource for your community, start with the SSD. If you’re a human rights defender with questions about how to stay safe, reach out. And if you’re not sure what else to do, you can always help us keep it going.

How Push Notifications Can Betray Your Privacy (and What to Do About It)

A phone’s push notifications can contain a significant amount of information about you, your communications, and what you do throughout the day. They’re important enough to government investigations that Apple and Google now both require a judge’s order to hand details about push notifications over to law enforcement, and even with that requirement Apple shares data on hundreds of users. More recently, we also learned from a 404 Media report that law enforcement forensic extraction tools can unearth the text from deleted notifications, including those from secure messaging tools, like Signal. The good news is that you can mitigate some of this risk. 

There are two points where notifications may betray your privacy: when they’re transmitted over cloud servers and once they land on the device. Let’s start with the cloud. It might seem like push notifications come directly from an app, but they are typically routed through either Apple or Google’s servers first (depending on if you use iOS or Android). According to a letter sent to the Department of Justice by Senator Wyden, the content of those notifications may be visible to Apple and Google, and at the very least the companies collect some metadata about what apps send a notification and when. App providers have to make the decision to hide the content from Apple and Google and implement that functionality; Signal is one app that does this. 

Then, once the notifications land on your phone, depending on your settings, the notification content may be visible on your lock screen without needing to unlock the device. This can be dangerous if you lose your device, someone steals it, or it’s confiscated by law enforcement. 

You may clear notifications after looking at them. But it turns out the content notifications get recorded in your device’s internal storage, which then makes them susceptible to recovery with certain types of forensic tools. Notification content may even persist after the app is deleted, if the OS doesn’t fully purge the app’s notification data. 

We still have a lot of unanswered questions about how the notification databases work on devices. We do not know how long notifications are stored, or whether they’re backed up to the cloud, in which case the cloud provider could get backdoor access to the content of messages if the backups are enabled and not end-to-end encrypted. This may also make backups vulnerable to law enforcement demands for data. 

Which is all to say that there are myriad ways that law enforcement can access the content or metadata of push notifications. Let’s fix that.

Consider the Strongest Notification Protections for Your Secure Messaging Apps

Secure chat tools are designed to keep the content of the messages safe inside the app. So, for secure chat apps like WhatsApp and Signal, that means the company that makes those apps cannot see the content of your messages, and they’re only accessible on your and your recipients’ devices. Once messages land on a device, it’s still important to consider some privacy precautions, particularly with notifications. 

Signal
Signal offers three levels of information to include in notifications, all which are pretty self explanatory:

  • Name, Content, and Actions (Name and message on Android) shows the entirety of a message as well as who sent it (on iPhone you can also slide to reply, mark as read, or call back). 
  • Name only only shows the name of the sender. 
  • No Name or Content (No name or message on Android) will only show that you have a message from Signal, not who sent it or what it’s about. 

To change your settings:

  • On iPhone: Tap your profile picture, then Settings > Notifications > Show.
  • On Android: Tap your profile picture, then Notifications > Show

WhatsApp
WhatsApp only has one option for this, and it’s currently limited to iPhone, but you can at least tell the app not to include the content of a message in the notification:

  • Open WhatsApp for iPhone, tap the “You” bar, then Notifications, and disable the Show preview option.

Check your other apps to see if they offer similar settings.

Limit Your Notifications Device-Wide

Since Apple and Google manage push notifications for their respective devices, they also have some visibility into certain data. Push notification data can include certain types of metadata, like which app sent a notification and when, as well as the account ID associated with the phone. In some cases, Apple and Google may have access to unencrypted content, including the content of the text in a notification or other information from the app itself. 

For most app notifications, there’s no simple way to easily figure out what metadata might be gleaned from a notification, or if the notification is unencrypted or not. But some app developers have described details along these lines. For example, Signal president Meredith Whittaker explained on social media how the Signal app handles notifications entirely on-device. Searching online for an app name along with “notification privacy,” “notification encryption” or “notification metadata” may help answer your questions, or you may need to dig around in support forums for the app.

 push notifications for Signal NEVER contain sensitive unencrypted data & do not reveal the contents of any Signal messages or calls-not to Apple, not to Google, not to anyone but you & the people you're talking to. 1/ In Signal, push notifications simply act as a ping that tells the app to wake up. They don't reveal who sent the message or who is calling (not to Apple, Google, or anyone). Notifications are processed entirely on your device. This

It’s also good to reconsider whether any app should be sending you notifications to begin with. Aside from a potential decrease in the number of distractions you endure throughout the day, or the level of chaos on display on your lockscreen, limiting the apps that can send notifications and what content is visible in them can improve your privacy with respect to the sorts of metadata that may be gathered by the companies, as well as any content that may be viewable if someone has physically accessed your device.

To check and change your settings on iPhone

  • Open Settings > Notifications.
  • On the Show Previews option, you can choose whether to show the content of notifications on the lock screen, “Always,” which doesn’t require unlocking the device, “When Unlocked,” which does, and “Never,” which means notifications won’t have any details, just that you have a notification in an app. 
  • Alternatively, you can scroll down and change these settings per app. Just tap the app name, then the Show Previews menu, and choose how you’d like them to appear. Or, if you’ve decided you don’t want notifications from that app at all, uncheck the Allow Notifications option.

To check and change your settings on Android
The core version of Android relies on app developers to develop specific settings more than controlling them on a platform-wide level.

  • Open Settings > Notifications > App notifications to disable notifications from any app completely. Some apps may also offer internal notification options for specific types of notices, like new messages, that you can control in the app itself. Tap an app name, then tap the Addition settings in the app option to potentially customize it more.
  • You can also experiment with the sensitive content setting. This is up to the developer to set properly, but when done so, most notifications will require at least unlocking the device to see them. Open Settings > Notifications > Notifications on lock screen and disable “Show sensitive content.”

Control What Notifications AI Tools Can Access

In an attempt to make notifications easier to skim, both Android and iOS offer optional ways to get notification summaries using their AI tools that summarize the content of notifications. On an individual app level, WhatsApp offers this as well. Some of these summarization tools, like Apple’s, run on the device, while others, like WhatsApp’s, do not. This can all be a lot to keep track of, and sending data off device may create some level of risk for some messages.

Since this is a bit more complicated, we have another blog post that walks through the steps to take to protect messaging from accidentally ending up in AI tools built into Apple and Google's devices. For WhatsApp specifically, we have a blog detailing when you might want to turn on the app’s “Advanced Chat Privacy” feature, which can disable summaries for both yourself and others in the chat.

Balancing security, privacy, and usability with something like push notifications is a complicated task. At the very least, Apple and Google should better ensure that the content of these notifications isn’t transmitted over their servers in plain text. The companies need to also make sure that device operating systems don’t back up the notification database to the cloud, and when an app is deleted, that all notification data is purged.

We appreciate that apps like Signal allow you to control what’s visible with notifications on a per-app basis, and we’d like to see this level of granularity of choices in other secure messaging tools, like WhatsApp. Likewise, more apps should handle push notifications similarly to the way Signal does, where a ping is sent to wake up the app to check for messages, and the content of that message is never sent across servers.

❌
❌