Metadata erasure and resistance

Contents

Metadata is data about data, i.e. information about other information. Metadata erasure is the removal of metadata. Metadata resistance is the ability of a digital system not to create metadata in the first place, or to encrypt the metadata it creates so that it cannot be read by an adversary.

Examples of metadata include:

For digital files, metadata erasure can be accomplished using MAT2[2] or similar software. Some security-oriented operating systems include metadata erasure tools by default.

Examples of metadata resistance include:

Techniques addressed by this mitigation

NameDescription
Forensics
Digital

An adversary can use digital forensics to retrieve and analyze metadata. To mitigate this, you can erase metadata from files before publishing them online or sending them to others.