Whoever reports wrongdoing often attaches proof: a photo, a screenshot, a spreadsheet. Each of these files carries data nobody sees. A phone photo holds GPS coordinates and the camera's serial number. An Office file holds its author. An anonymous report is only as anonymous as its attachment.

So OpenWhistle removes that data on upload, before anything is stored. A file that cannot be cleaned is refused, never stored as it came.

The old way: paint the picture again

Up to version 2.0, OpenWhistle read an image and wrote only its pixels into a new file. Metadata could not come along. Neither, always, could the pixels. A bug bounty run measured it:

AttachmentBeforeAfter cleaning (up to 2.0)
PNG with a colour palette, typical for screenshotsRed (200, 10, 30)Black (0, 0, 0)
Animated PNG or WebP2 frames1 frame
JPEG photo5.5 MB14.4 MB, over the 10 MB limit
PNG of 12,000 × 12,000 pixels450 KB file1.1 GB of memory

An evidence photo that looks different after the upload is poor evidence. And every JPEG was compressed again: not a single pixel stayed as it was.

Why no test noticed

The tests asked whether the metadata was gone. It was. Nobody asked whether the image still showed the same thing. And the test images were plain colour photos, with no palette and no animation. The fault sat exactly where nobody looked.

The new way: cut out only the metadata

Since version 2.1 an image is no longer written again. JPEG, PNG and WebP consist of separate chunks. OpenWhistle keeps the chunks that describe the image and drops all others. The pixels stay identical bit for bit, and the file does not grow. Only the orientation is kept, so a portrait photo stays upright.

The same run found more gaps, now closed:

  • Word and Excel stored the Windows user name in folder paths such as C:\Users\<name>\….
  • PDFs carried the author not only in the document, but on single pages and images too.
  • Motion photos from phones had a short video attached behind the picture.
  • A preview embedded in a JPEG could show the picture before it was cropped.

The measured numbers and every single fix are in the changelog. Which formats are accepted is in the guide for whistleblowers.

Try it yourself

The live demo accepts attachments. Upload a photo and check the stored file with an EXIF tool of your choice.

Open the demo →

More resources: GDPR-compliant whistleblowing system · HinSchG compliance guide · GitHub issues