Big Data, Small Details: How Metadata Creates Security Risks

What happens when you put a photograph online? In most cases, not much happens at all. It simply exists in cyberspace – permanently – with the trillions of other user-generated images. And the fact is that, besides there being an overwhelming number of photos on the web, most of them don’t contain any valuable information. What information there is, though, is hidden in the metadata.
With the rise of big data, that metadata is suddenly becoming valuable. If a picture is worth a thousand words, the metadata is infinitely more so. And now it could pose a security risk.
There are many kinds of information tucked into your photos’ metadata. One of the primary pieces of information, though, is a GPS position as found in the Exif file. Whenever you take a picture with your phone, it embeds your location data into the file. If you upload that photo immediately – or regularly upload from a private location such as your home – then you reveal your whereabouts. It’s why actress Emma Watson doesn’t take photos with fans anymore; the security risk is too great.
Photo metadata typically becomes more complex over time as users modify them. There are fields for titles, photographer name, copyright information, and more. The more you do with a photo before you upload it, the more information that goes with it.
New technologies like facial recognition software have only increased the dangers associated with photo metadata – and the risks of photo mining and app breaches more generally. We’ve seen this happen before with shifts in all kinds of technology. User technology takes a step forward, but hackers and data analysts move even more quickly. 110 million people were affected by Target’s 2014 security breach, and we can expect worse. The growth of big data comes with bigger security risks, but with everything it’s capable of, we’re compelled to keep moving forward. Our role, then, is to identify the greatest risks and minimize them.


