Keeping Our Home Addresses Offline: How To Graduate From Opt-Out Whack-A-Mole
Yael Grauer (Program Manager · Consumer Reports)
ShmooCon XX (Final) · Day 2 · Bring It On
Overview
In an era where personal information is increasingly commodified and exposed, Yael Grauer's ShmooCon talk, "Keeping Our Home Addresses Offline: How To Graduate From Opt-Out Whack-A-Mole," delivers a stark warning about the futility of individual efforts to safeguard privacy and a compelling argument for systemic policy change. Grauer, a program manager for cybersecurity research on the policy team at Consumer Reports and a freelance investigative tech reporter, meticulously dissects the pervasive problem of data brokers and people search sites that aggregate and sell sensitive personal data, including home addresses, often with devastating consequences.

Key moments
- 0:00 Welcome, personal motivation for doxing prevention
- 3:40 Data broker opt-out is a 'Whack-A-Mole' game
- 4:10 Consumer Reports study on paid data removal services
- 5:45 Misaligned incentives: removal services partner with data brokers
- 6:00 Speaker's address found in 15 minutes despite efforts
Keeping Our Home Addresses Offline: How To Graduate From Opt-Out Whack-A-Mole
Speakers: Yael Grauer
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=yIutY_X2FcU
Overview
In an era where personal information is increasingly commodified and exposed, Yael Grauer's ShmooCon talk, "Keeping Our Home Addresses Offline: How To Graduate From Opt-Out Whack-A-Mole," delivers a stark warning about the futility of individual efforts to safeguard privacy and a compelling argument for systemic policy change. Grauer, a program manager for cybersecurity research on the policy team at Consumer Reports and a freelance investigative tech reporter, meticulously dissects the pervasive problem of data brokers and people search sites that aggregate and sell sensitive personal data, including home addresses, often with devastating consequences.
The core of Grauer's presentation revolves around the concept of "opt-out whack-a-mole," illustrating how the current landscape forces individuals into an endless, frustrating battle to remove their data from countless, ever-changing platforms, only for it to reappear or be found through other means. Her personal experiences with doxing and her professional work in creating and maintaining the "Big Ass Data Broker Opt Out List" (BAD WOL) underscore the urgency of the issue. The talk critically examines the ineffectiveness of both manual opt-out procedures and commercially available data removal services, ultimately arguing that true privacy protection can only be achieved through robust legislative and regulatory intervention.
This presentation is highly relevant for anyone concerned about digital privacy, personal security, and the unchecked power of data brokers. It particularly resonates with marginalized communities, activists, journalists, and public figures who are disproportionately targeted by harassment and doxing campaigns. Grauer's call to action for policy reform, drawing on historical context and current legislative proposals like those from the Consumer Financial Protection Bureau, provides a tangible path forward beyond the exhausting cycle of individual data defense.
Background
▶ Watch: Welcome, personal motivation for doxing prevention (0:00)
Yael Grauer’s journey into the labyrinth of doxing prevention began not with the oft-cited Gamergate controversies, but surprisingly, through her work as an MMA writer. She discovered that publicly criticizing fighters for their questionable actions could provoke intense, personal retaliation, leading to early attempts to dox her. This initial exposure, where the perpetrator was easily identifiable through a moderated comment section, offered a "soft landing" into understanding the immediate threat of personal information exposure. However, it quickly escalated into a broader realization of how easily and extensively her own data, including past addresses, social media handles, relatives, and even a high school LiveJournal with a fake username, was accessible online.
This personal experience, coupled with her work as an activist and a woman online who frequently asks "follow-up questions that make people angry," highlighted the severe risks faced by individuals, particularly those in marginalized communities (e.g., queer community, people of color), who are often targets of doxing and swatting. Grauer initially believed her diligent efforts to scrub her address from people search sites provided sufficient protection, a form of security by obscurity.
Her frustration with the perpetual cycle of data reappearing, changing opt-out procedures, and the sheer volume of sites led her to create the BAD WOL (Big Ass Data Broker Opt Out List). This list aimed to guide individuals through the complex and time-consuming process of data removal, helping them prioritize efforts amidst the "whack-a-mole" nature of the problem. Despite these efforts, Grauer candidly admits that this individual approach is fundamentally flawed. The existence of adversaries with access to sophisticated data brokers, trace-skipping services, or even "sketchy private investigators" means that even the most meticulous personal data hygiene often proves insufficient. The problem, she argues, is deeply rooted in the unchecked collection and sale of publicly available information by data brokers, creating an ecosystem where personal privacy is continually undermined.
Key Findings
▶ Watch: Data broker opt-out is a 'Whack-A-Mole' game (3:40)
Grauer's talk presented several critical findings that underscore the pervasive and intractable nature of personal data exposure, particularly from people search sites and data brokers.
Firstly, a Consumer Reports study conducted with volunteers to evaluate paid data removal services revealed them to be largely ineffective. The study involved looking up volunteers' information on 13 "most invasive people search sites," signing them up for removal services, and then checking the data's presence a week, a month, and four months later. The results were disheartening: participants continued to find their information on many sites they had paid to have removed, weeks and even months later. While some services performed better than others—Opter and Easy Opt Outs were highlighted, with Easy Opt Outs noted for its affordability at $20/year—none offered complete coverage. Grauer emphasized that users still had to manually remove data not covered by these services.
A disturbing discovery from this study was the existence of misaligned incentives within the data removal industry. Some services, despite being paid by consumers to remove data, were found to have partnerships with the very people search sites they claimed to be scrubbing data from. Grauer expressed strong disapproval of this practice, questioning the motivations of companies that implicitly endorse a "problematic people search ecosystem" while ostensibly working against it.
Grauer also shared a powerful personal anecdote that illustrated the limitations of individual "security by obscurity" efforts. After a decade of meticulously attempting to wipe her data, a friend was able to locate her current address within 15 minutes using a paid version of a people search site. This site contained an old address she had intentionally left online as a misdirection, but the paid tier revealed her actual, current residence, along with old passwords and a "spicy email address" she used briefly years ago. This experience highlighted that even seemingly scrubbed information can persist in more obscure or commercial databases, accessible to those willing to pay.
Beyond commercial services, Grauer pointed out that personal information can be crowdsourced through unexpected channels. She cited instances where her address was found on "sketchy off-roading apps" that listed property owners, demonstrating the myriad, often obscure, sources data brokers can tap into. The overarching finding from these experiences and studies is clear: even experts in data privacy struggle to keep their information private, demonstrating that the problem extends far beyond individual vigilance. The "whack-a-mole" analogy is not just a metaphor for the effort required, but for the inherent impossibility of a complete, lasting solution through current methods.
Technical Deep Dive
▶ Watch: Consumer Reports study on paid data removal services (4:10)
The technical deep dive in Grauer's talk primarily focuses on the systemic failures and policy loopholes that enable data brokers, rather than intricate exploit mechanics. The core "technical" challenge identified is the persistent availability and re-aggregation of publicly available information, which undermines all individual and even state-level privacy efforts.
Grauer highlights the critical flaw in existing privacy legislation: the "publicly available information" carve-out. She notes that this loophole exists in every state with a consumer privacy law, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia. This carve-out means that even if a state law aims to give consumers control over their data, data brokers can still collect, share, and sell information if it's deemed "publicly available," such as property records, voter registration data, or court documents. Grauer's own study found that Californians, despite living in a state with a privacy law, did not have less data available online.
Maryland's data minimization law is presented as a step in the right direction, prohibiting companies from collecting information unless it's necessary to provide the service paid for, thus reducing the default sharing of data with brokers. However, even this progressive law retains the "publicly available data" carve-out, limiting its effectiveness against people search sites.
Grauer argues that the solution requires a fundamental re-evaluation of what constitutes public record and how it's accessed. She proposes adding "friction" to the inspection of public data. This isn't about making public records inaccessible, but about preventing their bulk copying and aggregation by data brokers. She draws parallels to existing precedents where public records requests require in-person visits, physical document retrieval, filling out forms, or providing identification. Such measures would make it significantly harder for data brokers to automate the mass harvesting of personal information.
Furthermore, Grauer points out that many states already have processes for public officials (e.g., police officers, judges) or victims of stalking/domestic violence to remove themselves from these records. She advocates for extending these protections preemptively to all individuals who wish to restrict their information, rather than waiting for them to become victims.
The discussion also touched on supposed "technical" solutions for individuals, such as buying property through an LLC (Limited Liability Company) or a Land Trust. Grauer debunks the notion that these are foolproof privacy solutions for home addresses. She explains that LLCs often require members to be registered with the state, making the information traceable. Land Trusts, while potentially more private (e.g., in Florida, where an attorney acts as trustee and the grantor/beneficiary names are not public), are state-specific and can present issues with property taxes or slow down the home-buying process, potentially causing buyers to lose out on bids. She advises consulting a lawyer in one's specific state due to the varied legal landscapes.
Finally, Grauer highlights the challenge of genetic and ancestry databases. Once data is submitted to these platforms, even if anonymized for scientific purposes, it is extremely difficult, if not impossible, to "put the toothpaste back in the tube." The data may be shared with family members who also use the services, and the anonymization process itself can be complex and difficult to verify, making individual data deletion requests arduous and often incomplete, as she experienced with 23andMe. This underscores the broader technical challenge of data immutability once it enters the digital ecosystem.
Demo / Proof of Concept
▶ Watch: Misaligned incentives: removal services partner with data brokers (5:45)
While Yael Grauer's talk did not feature a traditional live software demonstration or a step-by-step technical proof of concept, she provided a compelling real-world "proof of concept" through her personal experience. This anecdote served as a powerful, lived example of the talk's central premise: that even dedicated individual efforts to scrub personal data are ultimately insufficient against determined adversaries with access to sophisticated tools.
Grauer recounted how, after a decade of meticulously trying to remove her information from various people search sites, a friend successfully located her current home address within a mere 15 minutes. The method involved accessing a paid version of a people search site that contained her actual address, despite her having intentionally left an old address on the public version as a form of misdirection. This "demonstration" by her friend also uncovered other sensitive details, including variations of old passwords and a "spicy email address" she had used briefly years prior.
This incident served as a stark, practical illustration of several key points:
- Limitations of "Security by Obscurity": Her strategy of leaving an old address as a decoy failed because the paid service provided more accurate, current data.
- Tiered Access to Data: The existence of paid, more comprehensive versions of people search sites means that a determined individual can bypass superficial opt-out efforts.
- Persistence of Data: Information, even seemingly forgotten or briefly used, can linger in databases for years and be re-surfaced.
- Ease of Weaponization: Grauer emphasized that while her friend's intent was benign, the ease with which this information was found highlights how readily it could be weaponized for doxing, harassment, or worse.
Additionally, Grauer mentioned the discovery of her address on "sketchy off-roading apps" that list property owners, further illustrating how diverse and unexpected sources contribute to the overall data broker problem. These real-world examples, though not a formal demo, effectively served to prove the ineffectiveness of the current "opt-out whack-a-mole" paradigm and underscore the urgent need for a more systemic solution.
Defensive Implications
▶ Watch: Speaker's address found in 15 minutes despite efforts (6:00)
The defensive implications derived from Yael Grauer's talk are multifaceted, extending beyond individual actions to emphasize the critical need for collective advocacy and policy reform.
For individuals, the talk highlights the continued, albeit limited, utility of personal data hygiene:
- Manual Opt-Outs (Security by Obscurity): While Grauer acknowledges that manual opt-out efforts are a "whack-a-mole" game and ultimately a form of security by obscurity, she doesn't dismiss them entirely. They can still deter less tech-savvy adversaries. Individuals should continue to use resources like her BAD WOL list to prioritize and execute opt-out requests, understanding that this is a continuous, ongoing process.
- Paid Data Removal Services: If considering paid services, be aware of their limitations. The Consumer Reports study found them generally ineffective, and some have misaligned incentives (partnerships with people search sites). If used, Easy Opt Outs was noted as a cost-effective option ($20/year) that performed relatively well, but it must be supplemented with manual efforts for uncovered sites. Always research the service's practices and affiliations.
- Property Ownership Privacy: Individuals seeking to shield their home address should approach solutions like LLCs or Land Trusts with extreme caution. These methods are not foolproof, vary significantly by state, can have complex tax implications (e.g., homestead exemptions), and may complicate real estate transactions. Consulting a qualified attorney in your specific state is crucial.
- Digital Footprint Awareness: Be hyper-vigilant about what information is shared online, even on seemingly innocuous platforms (e.g., off-roading apps, social media, forums). Every piece of data contributed or linked can be aggregated by data brokers.
- Genetic/Ancestry Databases: Exercise extreme caution before submitting genetic data to commercial services. Once this highly sensitive information is shared, it is exceedingly difficult, if not impossible, to fully retract or control its use, especially with family members' participation.
However, the most significant defensive implication is the call for systemic policy solutions. Grauer firmly states that individuals cannot "graduate from opt-out whack-a-mole" without legislative action.
- Advocate for Policy Reform: Engage with policymakers and support initiatives aimed at regulating data brokers. Grauer specifically highlighted the Consumer Financial Protection Bureau (CFPB)'s proposed rules. If passed, these rules would classify data brokers as Consumer Reporting Agencies under the Fair Credit Reporting Act (FCRA). This reclassification would impose stricter regulations, including limiting the sharing of sensitive data, requiring consumer consent before data is sold, and providing consumers access to their information. The talk specifically mentioned a public comment period through March 3rd, urging attendees to participate.
- Address "Publicly Available Information" Carve-Outs: Defenders should advocate for the removal or significant modification of the "publicly available information" carve-out in state privacy laws. This loophole fundamentally undermines individual privacy efforts.
- Implement Friction for Public Records: Support policies that introduce "friction" into the process of accessing public records, such as requiring in-person requests, ID verification, or physical document retrieval, to prevent bulk scraping by data brokers. Extend existing protections for public officials and victims to all citizens proactively.
- Promote Data Minimization: Advocate for laws like Maryland's data minimization law, which prohibits companies from collecting information unless absolutely necessary for providing a service. Less data collected means less data to be sold or breached.
Ultimately, effective defense against the pervasive threat of data brokers requires a dual approach: individuals must continue their personal efforts, however imperfect, while simultaneously channeling significant energy into advocating for robust, comprehensive policy changes that tackle the problem at its root.
Key Takeaways
- Opt-out methods are a futile "whack-a-mole": Manually removing personal data from people search sites is an endless, frustrating battle because information reappears, sites change, and new sources emerge.
- Paid removal services are largely ineffective and have misaligned incentives: A Consumer Reports study found most commercial data removal services fail to completely remove information, and some even partner with the very data brokers they claim to fight.
- "Publicly available information" loopholes undermine state privacy laws: Existing state privacy laws (e.g., California, Maryland) are severely hampered by carve-outs that allow data brokers to collect and sell information deemed "publicly available," rendering them ineffective against people search sites.
- Individual efforts are insufficient; systemic policy solutions are essential: Relying on personal vigilance or technical workarounds like LLCs for property privacy is not a foolproof solution. The problem requires fundamental legislative and regulatory intervention to control data collection and distribution.
- The CFPB's proposed rules offer a promising path for federal regulation: Classifying data brokers as Consumer Reporting Agencies under the Fair Credit Reporting Act (FCRA) could impose crucial restrictions on data collection, sharing, and require consumer consent, marking a significant step towards federal oversight.
- Advocacy is a critical defensive strategy: Engaging in public comment periods and supporting policy changes that introduce friction to public data access and promote data minimization are vital actions for long-term privacy protection.
About the Speaker(s)
Yael Grauer is a distinguished figure in the realm of cybersecurity research and investigative journalism, with a strong focus on consumer privacy. She serves as a Program Manager for cybersecurity research on the policy team at Consumer Reports, a renowned non-profit organization dedicated to independent product testing and consumer advocacy. In this role, Grauer contributes to shaping policies that protect individuals in the digital landscape.
Beyond her work at Consumer Reports, Yael Grauer is an active freelance investigative tech reporter, often delving into complex issues surrounding data privacy, surveillance, and online security. Her personal experiences with doxing, stemming from her work as an MMA writer and an online activist, have profoundly informed her professional endeavors. She is the creator and maintainer of the "Big Ass Data Broker Opt Out List," affectionately known as BAD WOL, a valuable resource for individuals seeking to navigate the challenging process of removing their personal information from data broker sites. Grauer's unique blend of personal experience, technical understanding, and policy advocacy makes her a compelling voice in the fight for digital privacy.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This talk delivers a brutally honest assessment of the current state of personal information privacy, moving beyond the futile "opt-out whack-a-mole" to advocate for systemic policy solutions. Grauer, clearly an expert from her extensive work and personal experience, provides valuable insights into the ineffectiveness of current paid data removal services and highlights critical loopholes in existing state privacy laws. While the core problem is not new, the depth of research, the practical testing of services, and the concrete policy recommendations, particularly regarding the CFPB and adding friction to public records, make this a highly impactful and actionable session.
Heather Calloway (CISO) — STRONG ACCEPT
Yael Grauer's talk offers a critical assessment of personal data protection, forcefully arguing that individual 'opt-out whack-a-mole' efforts are futile against the systemic power of data brokers. She highlights significant governance gaps, particularly the 'publicly available information' loophole, that expose individuals and, by extension, institutions to profound risks. Grauer provides clear, actionable policy recommendations, urging security leaders to shift focus from reactive individual defense to proactive advocacy for robust legislative and regulatory change, making this a crucial discussion for anyone concerned with institutional accountability in the digital age.