Metadata erasure and resistance

Contents

Metadata is data about data, i.e. information about other information. Metadata erasure is the removal of metadata. Metadata resistance is the ability of a digital system not to create metadata in the first place, or to encrypt the metadata it creates so that it cannot be read by an adversary.

Examples of metadata

Examples of metadata include:

Metadata erasure

For digital files, metadata erasure can be accomplished using MAT2[2] or similar software. Some security-oriented operating systems include metadata erasure tools by default.

Metadata resistance

Examples of metadata resistance include:

See also

See AnarSec's guide “Remove Identifying Metadata From Files”[4] on how to remove metadata from digital files.

Techniques addressed by this mitigation

NameDescription
Forensics
Digital

An adversary can use digital forensics to retrieve and analyze metadata. To mitigate this, you can erase metadata from files before publishing them online or sending them to others.