Whoever reports wrongdoing often attaches proof: a photo, a screenshot, a spreadsheet. Each of these files carries data nobody sees. A phone photo holds GPS coordinates and the camera's serial number. An Office file holds its author. An anonymous report is only as anonymous as its attachment.
So OpenWhistle removes that data on upload, before anything is stored. A file that cannot be cleaned is refused, never stored as it came.
The old way: paint the picture again
Up to version 2.0, OpenWhistle read an image and wrote only its pixels into a new file. Metadata could not come along. Neither, always, could the pixels. A bug bounty run measured it:
| Attachment | Before | After cleaning (up to 2.0) |
|---|---|---|
| PNG with a colour palette, typical for screenshots | Red (200, 10, 30) | Black (0, 0, 0) |
| Animated PNG or WebP | 2 frames | 1 frame |
| JPEG photo | 5.5 MB | 14.4 MB, over the 10 MB limit |
| PNG of 12,000 × 12,000 pixels | 450 KB file | 1.1 GB of memory |
An evidence photo that looks different after the upload is poor evidence. And every JPEG was compressed again: not a single pixel stayed as it was.
Why no test noticed
The tests asked whether the metadata was gone. It was. Nobody asked whether the image still showed the same thing. And the test images were plain colour photos, with no palette and no animation. The fault sat exactly where nobody looked.
The new way: cut out only the metadata
Since version 2.1 an image is no longer written again. JPEG, PNG and WebP consist of separate chunks. OpenWhistle keeps the chunks that describe the image and drops all others. The pixels stay identical bit for bit, and the file does not grow. Only the orientation is kept, so a portrait photo stays upright.
The same run found more gaps, now closed:
- Word and Excel stored the Windows user name in folder paths such as
C:\Users\<name>\…. - PDFs carried the author not only in the document, but on single pages and images too.
- Motion photos from phones had a short video attached behind the picture.
- A preview embedded in a JPEG could show the picture before it was cropped.
The measured numbers and every single fix are in the changelog. Which formats are accepted is in the guide for whistleblowers.
Try it yourself
The live demo accepts attachments. Upload a photo and check the stored file with an EXIF tool of your choice.
Open the demo →More resources: GDPR-compliant whistleblowing system · HinSchG compliance guide · GitHub issues