Private, Private, Private Access Everywhere
Meghan Jacquot
DEF CON 33 · Day 1 · Main Stage
Overview
Meghan Jacquot's DEF CON 33 workshop, "Private, Private, Private Access Everywhere," delved into the critical subject of personal digital privacy in an era where information is increasingly accessible. Against the backdrop of DEF CON's "Access Everywhere" theme, Jacquot, known by her handle Carpad DMT Tech, guided attendees through practical strategies for understanding, shrinking, and obfuscating their digital footprints. The talk emphasized that privacy is not a monolithic concept but a spectrum of personal decisions, balancing convenience against the desire for anonymity.

Key moments
- 0:00 Introduction, agenda, and workshop format
- 2:19 Speaker introduction and professional background
- 3:45 Why privacy matters: public, private, secret lives
- 4:39 Activity 1: Finding your digital footprint (OSINT)
- 6:18 Audience reaction to surprising OSINT findings
- 7:40 Advanced OSINT tips: Google dorking for data leaks
Private, Private, Private Access Everywhere
Speakers: Meghan Jacquot
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=luZgICp0wKw
Overview
Meghan Jacquot's DEF CON 33 workshop, "Private, Private, Private Access Everywhere," delved into the critical subject of personal digital privacy in an era where information is increasingly accessible. Against the backdrop of DEF CON's "Access Everywhere" theme, Jacquot, known by her handle Carpad DMT Tech, guided attendees through practical strategies for understanding, shrinking, and obfuscating their digital footprints. The talk emphasized that privacy is not a monolithic concept but a spectrum of personal decisions, balancing convenience against the desire for anonymity.
The core premise of the workshop was to empower individuals to take control of their online presence by first identifying what data exists about them, then learning techniques to minimize or even misdirect that information, and finally, applying threat modeling to make informed privacy choices in real-world scenarios, such as attending a major conference. While framed as a beginner-friendly "101" introduction, the workshop provided foundational knowledge and actionable steps that resonate with anyone concerned about their personal data exposure, from casual internet users to security professionals navigating high-risk environments.
Jacquot's presentation underscored the iterative nature of privacy management, highlighting that a one-time effort is insufficient in the face of continuous data generation and collection. It served as a vital call to action for attendees to critically evaluate their own privacy decisions, offering a toolkit of methods and resources to enhance personal security and maintain control over their "public, private, and secret" lives, a concept aptly introduced with a quote from Gabriel Garcia Marquez.
Background
▶ Watch: Introduction, agenda, and workshop format (0:00)
The pervasive nature of digital information in contemporary society has rendered personal privacy a complex and often elusive ideal. The internet, designed for connectivity and information sharing, inadvertently creates vast digital footprints for individuals, often without their explicit consent or full awareness. This problem is exacerbated by the existence of data brokers who aggregate and sell personal information, as well as the constant threat of data leaks that expose sensitive details, sometimes in unredacted forms, to the public domain. The DEF CON 33 theme, "Access Everywhere," served as a poignant reminder of this reality, challenging attendees to confront the ease with which their personal data can be accessed and exploited.
Prior to this workshop, the concept of personal OSINT (Open Source Intelligence) was primarily associated with intelligence gathering on targets, but Jacquot reframed it as a crucial self-assessment tool. The talk implicitly built upon the understanding that individuals make daily decisions about privacy, often weighing the convenience of online services against potential privacy risks. However, these decisions are often made without a full understanding of the long-term implications or the extent of publicly available data. The workshop aimed to bridge this knowledge gap, providing a structured approach to understand why the problem exists and how individuals can proactively address it.
The historical context of privacy discussions often highlights a tension between transparency and anonymity. Jacquot’s approach acknowledged this tension, particularly in the context of professional identity (e.g., using a government name vs. a handle) and the varying risk profiles of individuals. The core problem, as presented, is not merely the existence of data, but the lack of control individuals have over their own information and the need for practical, accessible methods to reclaim that control.
Key Findings
▶ Watch: Why privacy matters: public, private, secret lives (3:45)
The workshop yielded several key findings and reinforced critical principles for personal privacy management:
- Extensive Digital Footprint: Most individuals possess a significantly larger digital footprint than they realize. Through initial OSINT exercises (Activity 1), attendees often uncovered surprising amounts of personal information readily available online, including details from data breaches and public records. This immediate realization served as a powerful motivator for subsequent privacy efforts.
- Privacy is an Iterative and Personal Journey: Managing one's digital presence is not a one-time task but an ongoing, iterative process. Data continuously populates, requiring regular re-evaluation and action (e.g., quarterly or annually) to maintain desired levels of privacy. Furthermore, individual risk models and comfort levels with convenience versus privacy vary greatly, meaning there's no universal "correct" approach; personal decisions are paramount.
- Strategic Obfuscation and Disinformation are Valid Tools: Beyond simply removing data, actively adding "noise" or disinformation can be an effective privacy strategy. Techniques such as self-publishing false addresses or creating blogs with fabricated personal details can make it harder for adversaries to pinpoint accurate information, thereby increasing the effort required for OSINT.
- Threat Modeling is Essential for Informed Decisions: Applying threat modeling principles to personal scenarios (like attending a conference) allows individuals to systematically identify potential risks, assess their impact and likelihood, and develop tailored mitigation strategies. This structured approach moves privacy decisions beyond intuition to a more analytical framework.
- Automation and Specialized Services Can Aid Privacy Efforts: While many privacy-enhancing actions are manual (e.g., requesting data removal, de-indexing search results), tools like web scrapers can automate repetitive tasks. Additionally, commercial services exist to assist with data removal from brokers, offering a convenience-based alternative for those with higher risk profiles or limited time.
- Non-Digital Devices Enhance Physical and Digital Privacy: For sensitive activities like community activism, the physical separation from digital devices is crucial. Tools like Meshtastic devices offer encrypted, off-grid communication that is not tied to personal identities, providing a significant privacy advantage over traditional smartphones or even "burner" phones which can still be traceable.
Technical Deep Dive
▶ Watch: Activity 1: Finding your digital footprint (OSINT) (4:39)
The workshop provided a practical framework for enhancing personal privacy, drawing upon various technical and strategic approaches. The core of these techniques revolved around Open Source Intelligence (OSINT), data obfuscation, threat modeling, and data removal.
OSINT for Self-Discovery:
The initial activity, "Finding Yourself," served as a practical introduction to OSINT. Participants were encouraged to perform searches on themselves or public figures using common search engines. Key techniques highlighted included:
- Google Dorking: Utilizing advanced search operators, such as
site:,inurl:, or adding specific file types likefiletype:pdf, to uncover documents or specific information that might contain personal data. The example of searching for "PDF" alongside one's name was given to find potentially unredacted documents from data breaches. - Data Breach Awareness: Understanding that personal information, even if initially private, might have been exposed through data leaks. Tools and books like Michael Lee's work (mentioned in the talk) can help individuals identify if their data is part of such leaks.
- Data Brokers: Recognizing that these entities actively collect and sell personal information, making it readily accessible to anyone willing to pay. The existence of these brokers underscores the scale of the privacy challenge.
Obfuscation and Disinformation Techniques:
Once an individual's digital footprint is understood, the workshop moved to strategies for "Losing Yourself" by shrinking or obscuring this footprint.
- Strategic Disinformation: A non-traditional but effective technique involves self-publishing disinformation to create "noise" in search results. This could include:
- Fabricating Residential Information: Creating fake addresses (e.g., "I live on the eighth floor of an apartment complex that only has seven floors") and associating them with one's name.
- Creating False Narratives: Publishing blogs or online content with fabricated personal details to dilute genuine information. The goal is to make it difficult for an adversary to discern true facts from false ones.
- Canary Tokens: A more advanced, premium service mentioned was the use of canary tokens. These are digital tripwires (e.g., unique images, documents, or URLs) embedded in publicly accessible information. If someone accesses a canary token, the creator receives an alert, providing insight into who is searching for them and what information they are interacting with. This acts as a passive surveillance mechanism for one's own digital presence.
Data Removal and De-indexing:
A direct approach to shrinking the digital footprint involves actively removing data.
- Requesting Data Removal: Individuals, particularly those in regions like California with specific privacy laws (e.g., CCPA), can formally request data brokers to remove their information. The speaker noted that one could claim California residency even if not physically located there to leverage these protections.
- De-indexing Search Results: After data is removed from a source (e.g., a "people finder" site resulting in a 404 error), the URL might still appear in search engine results. Manual requests can be made to search engines (Google, Bing, etc.) to de-index these non-existent pages, effectively removing the link from public search.
- Automation with Web Scrapers: To combat the manual and iterative nature of data removal, the use of web scrapers was suggested. These scripts can automate the process of identifying and requesting removal from various sites, making the task more manageable over time.
Personal Threat Modeling:
The final technical aspect focused on applying threat modeling to personal privacy decisions, particularly in dynamic environments like conferences.
- Impact vs. Likelihood: Attendees were guided to identify potential threats (e.g., doxxing, identity theft, physical tracking) and assess their impact (severity of consequences) and likelihood (probability of occurrence).
- Decision Matrix: Developing a personal decision matrix to weigh risks against the convenience or necessity of certain actions (e.g., sharing a LinkedIn QR code vs. maintaining anonymity).
- Quantitative Risk Rating: Mentioned as a more formal approach, aligning with methodologies used in application security (e.g., OWASP), where numerical values are assigned to risks for systematic prioritization.
Privacy-Enhancing Technologies and Strategies:
For specific high-risk scenarios, Jacquot highlighted specialized tools and legal structures:
- Meshtastic Devices: For situations requiring secure, untraceable communication (e.g., community activism), Meshtastic devices were strongly recommended. These are low-cost (under $100), off-grid, encrypted mesh network devices that operate independently of personal smartphones, preventing tracking or association with personal digital identities.
- Burner Phones: While often suggested, the speaker cautioned that true burner phone anonymity is challenging. It requires cash payment for both the device and service, and many carriers still demand some form of ID, potentially linking the phone to an individual. Strict separation of use (never performing personal activities on a burner) is paramount.
- LLCs and Trusts for Property: To disassociate personal names from public property records, structuring ownership through Limited Liability Companies (LLCs) or trusts was presented as a high-level privacy technique. This requires careful setup to ensure the LLC/trust itself is sufficiently removed from the individual's name.
The workshop, while introductory, provided a robust set of technical concepts and practical strategies, emphasizing that effective personal privacy management requires a multi-faceted and persistent approach.
Demo / Proof of Concept
▶ Watch: Audience reaction to surprising OSINT findings (6:18)
The talk was structured as an interactive workshop, providing attendees with hands-on activities rather than a traditional demonstration of a specific tool or exploit. The "demos" were essentially the guided exercises attendees performed, designed to immediately illustrate the concepts being discussed.
- Activity 1: "Finding Yourself" (OSINT Discovery): This was the initial and most impactful activity. Attendees were instructed to use common search engines and OSINT techniques (like Google dorking with terms such as "PDF" alongside their name) to search for their own personal information online. The goal was to reveal the extent of their existing digital footprint. The immediate feedback from the audience, with some expressing how "quite scary the information you can find," served as a powerful proof of concept for how easily personal data can be uncovered. For those uncomfortable searching themselves, the option to search a celebrity was provided.
- Activity 2: "Losing Yourself" (Obfuscation & Removal Techniques): Building on the findings of Activity 1, this segment provided a structured approach to shrinking and obfuscating one's digital presence. While the workshop format limited the time for actual execution, the activity provided detailed, step-by-step instructions for tasks such as:
- Identifying data brokers that list personal information.
- Requesting data removal from these brokers (with a note about leveraging California privacy laws).
- De-indexing outdated or removed content from search engines.
- Strategies for creating disinformation (e.g., fake addresses, false blog entries) to add noise to an individual's online persona.
- The concept of canary tokens was introduced as a method to detect when someone is actively searching for you.
The detailed instructions served as a "take-home" blueprint for attendees to implement these strategies at their own pace.
- Activity 3: "Threat Modeling a Conference" (Risk Assessment): This activity shifted the focus to proactive privacy decision-making in a specific context. Attendees were asked to list potential threats to their privacy and safety while attending a large event like DEF CON. They were then guided to rank these threats based on impact and likelihood, and to consider mitigation strategies. An example scenario was provided in the workshop files to illustrate how one might approach this, covering aspects from physical security to digital privacy choices (e.g., what information to share on a badge or when networking). This activity served as a conceptual proof of concept for applying risk assessment to personal privacy.
In essence, the workshop itself was the "demo." By guiding attendees through these interactive exercises, Meghan Jacquot effectively demonstrated not only the vulnerability of personal data but also the practical, albeit iterative, steps one can take to regain control and enhance personal privacy. The lack of a traditional, pre-built technical demo was a deliberate choice, aligning with the workshop's goal of empowering individual action and critical thinking.
Defensive Implications
▶ Watch: Advanced OSINT tips: Google dorking for data leaks (7:40)
Meghan Jacquot's workshop provided a clear roadmap for individuals to transition from passive data subjects to active stewards of their digital privacy. The defensive implications are multifaceted, urging a proactive and iterative approach:
- Proactive OSINT and Digital Footprint Auditing: Defenders, whether individuals or those protecting others, must regularly perform Open Source Intelligence (OSINT) on themselves and their assets. This involves systematically searching for publicly available information, including names, addresses, professional affiliations, and any data exposed via data leaks or data brokers. Understanding the current exposure is the critical first step in any defensive strategy. Tools like Google dorking (e.g.,
site:example.com "your name" filetype:pdf) should be part of a routine audit.
- Strategic Data Minimization and Obfuscation: Beyond simply deleting data, defenders should adopt a strategy of data minimization, limiting what information is shared publicly. Furthermore, the workshop introduced the concept of strategic obfuscation and disinformation. This means intentionally publishing false or misleading information (e.g., fake addresses, fabricated professional details on a blog) to dilute genuine data and increase the adversary's effort in discerning truth from fiction. This technique can create "noise" that makes it harder for malicious actors to build an accurate profile.
- Active Data Removal and De-indexing: Defenders should actively engage in the process of removing their data from public platforms. This includes:
- Requesting removal from data brokers: Utilizing legal frameworks like California's CCPA (even if one only claims residency) to demand data deletion.
- De-indexing obsolete search results: Manually or semi-automatically requesting search engines (Google, Bing) to remove links to content that no longer exists (e.g., 404 pages from removed data broker profiles).
- Automating removal efforts: Exploring the use of web scrapers or specialized commercial services to automate the repetitive tasks of identifying and requesting data removal.
- Personal Threat Modeling and Risk Assessment: A fundamental defensive practice is to apply threat modeling to personal life scenarios. Before attending conferences, engaging in activism, or even adopting new online services, individuals should:
- Identify potential threats (e.g., doxxing, physical tracking, identity theft).
- Assess the impact (severity) and likelihood (probability) of each threat.
- Develop mitigation strategies that balance convenience with privacy needs. This iterative process allows for informed decision-making tailored to specific contexts and personal risk tolerance.
- Adoption of Privacy-Enhancing Technologies and Practices:
- Meshtastic Devices: For high-stakes, off-grid communication scenarios (e.g., protests, sensitive meetups), defenders should consider using Meshtastic devices. These low-cost, encrypted, mesh-network communicators operate independently of personal smartphones, offering a robust layer of anonymity and untraceability.
- Careful Burner Phone Use: While useful, burner phones require extreme diligence to ensure true anonymity (cash payment, avoiding personal data, strict usage separation).
- Legal Structures for Anonymity: For significant assets like property, exploring legal structures such as LLCs or trusts can help disassociate personal names from public records.
- Canary Tokens: Implementing canary tokens can serve as an early warning system, alerting individuals when their specific digital assets or profiles are being investigated.
- Continuous Education and Iteration: Privacy defense is not a static state but a continuous battle. Defenders must stay informed about new privacy threats, tools, and techniques. Regular re-evaluation of one's digital footprint and privacy posture (e.g., quarterly or annually) is crucial, as new data emerges and old data resurfaces. The resources provided, such as the "Extreme Privacy" book, offer ongoing guidance for deeper dives.
By adopting these defensive implications, individuals can significantly enhance their personal security, regain control over their digital identities, and navigate the "Access Everywhere" landscape with greater confidence and resilience.
Key Takeaways
- Your Digital Footprint is Extensive: Most individuals significantly underestimate the amount of personal information publicly available about them, often exposed through OSINT, data brokers, and past data leaks.
- Privacy is a Continuous, Personal Journey: Managing your digital privacy is an ongoing, iterative process, not a one-time fix, requiring regular effort and personal decisions balancing convenience against desired levels of anonymity.
- Threat Modeling is Crucial for Informed Decisions: Systematically identifying threats, assessing their impact and likelihood, and developing mitigation strategies is essential for making smart privacy choices in various contexts, from daily life to high-risk events like conferences.
- Strategic Obfuscation and Disinformation are Powerful Tools: Actively adding "noise" to your digital footprint through self-published disinformation (e.g., fake addresses, false narratives) can effectively make it harder for adversaries to pinpoint accurate information.
- Leverage Data Removal and De-indexing Techniques: Proactively request data removal from brokers and utilize search engine de-indexing features to erase outdated or unwanted information from public search results.
- Embrace Privacy-Enhancing Technologies: Tools like Meshtastic devices offer secure, untraceable communication for sensitive situations, while legal structures like LLCs can help disassociate personal names from public records.
About the Speaker(s)
Meghan Jacquot, known by her handle Carpad DMT Tech, is a multifaceted security professional and an enthusiastic member of the hacker community. She embodies her handle's spirit, actively engaging in a wide array of activities and roles. In her day job, Meghan works as a Security Engineer, where she also leads a privacy security interest group that collaborates with various government agencies. Her expertise extends into offensive security, focusing on pentesting high-value assets.
Beyond her professional roles, Meghan is a self-described serial volunteer and a highly curious individual, frequently seen at various conferences and events. She has a deep passion for travel, aspiring to visit all continents (with only two remaining on her list). A devoted fan of Doctor Who, Meghan expresses her creativity through making stickers, which she generously shares. She also runs the Defcon book club alongside other enthusiasts. Meghan is a proud sock goon and a pet owner to an "awesome" chinchilla. Her diverse interests and deep involvement in the security community underscore her commitment to both learning and sharing knowledge, particularly on vital topics like digital privacy.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent, well-structured privacy 101 workshop that does exactly what it sets out to do — no more. Jacquot knows her material and the interactive format is appropriate for the content level, but nothing here would surprise anyone who's read Michael Bazzell's Extreme Privacy or spent an afternoon on IntelTechniques.
Heather Calloway (CISO) — SOLID
A competent, well-structured personal privacy workshop aimed at individuals, not organizations. Jacquot delivers actionable fundamentals with real practitioner credibility, but the scope stops at the personal level — there's no bridge to institutional risk, workforce exposure, or the governance questions that would make this relevant to a security program.