Home  /  Blog  /  Digital discretion
Founder’s analysis

What your phone reveals about you before you even say hello

  ·  9 min read  ·  12 min listen
Robert Václavík — Bodyguard Group ®
Listen to the articleaudio version0:00 / 12:28

For 17 years I have protected people on the street. Yet today a client’s browser can tell you more than an hour of surveillance. Here is what your device quietly gives away about you, and how to shrink that footprint.

No one was following him, yet they knew everything

A few years ago we were protecting a client who was convinced someone was following him. We went through our standard procedure: we checked the area around his home, his routes and the cars behind us. Nothing. No car, no face that appeared twice. And yet the other side always knew where he was. It took us a while to realise that the surveillance was not happening on the street but in his pocket. His phone and laptop were giving away more about him than an entire team could have uncovered in a week of fieldwork.

In 17 years of close protection I have grown used to reading my surroundings: who is watching, who turns round, which window is not empty by chance. But the world has moved on. Today you can learn more about a public figure from their digital footprint than from physical surveillance. And what strikes me most is that the bulk of this information leaks out automatically, without you clicking anything. Simply opening a web page is enough.

That is exactly why we created our short Digital Exposure test. In a few seconds it checks 20 things your device says about you and gives you a score. This article is its companion. Calmly and without scaremongering, I will explain what each item means and what you can realistically do about it.

Where you are calling from, and whether the line is secure

Test items covered here: IP address and network · encrypted connection (HTTPS) · connection type · battery status

Let me start with the most basic point. The moment you open a website, you reveal your IP address. Think of it as the return address on an envelope. It shows which network and provider you are connecting through, and roughly where you are, down to the city. In protection work, location is a sensitive matter. If someone can work out where a client connects from, they can also work out where that client lives or works.

The second question is whether your connection is encrypted. That is the HTTPS at the start of the address; some browsers show it as a padlock, while Chrome now shows a settings icon next to the address. Without encryption, data travels in the open between you and the website, and anyone along the way, on public hotel Wi-Fi for instance, can read it. I think of it as locking the car door: an obvious precaution, yet one many people still overlook.

Some devices and browsers can also reveal what kind of connection you are on: mobile data or Wi-Fi, and roughly how fast it is. It seems trivial, but mobile data often means you are on the move, while home Wi-Fi suggests you are at home or at work. It is a quiet clue to your movements. On phones, even the battery level can be read. It sounds harmless, but combined with other details, the charge percentage becomes another small marker by which you can be recognised and followed across websites for a while. Firefox and Safari have closed this channel completely; Chrome unfortunately still leaves it open, which is one more reason your choice of browser matters. I will come back to that below.

The fingerprint that survives even when you delete everything

Test items covered here: canvas fingerprint · graphics chip (WebGL) · audio fingerprint · screen resolution

This is where the most interesting and least understood part begins. There is a technique that can recognise you even after you delete your cookies, sign out of your accounts and hide behind a VPN. It is called fingerprinting. The principle is simple: every device is slightly different, and dozens of tiny differences can be combined into an almost unique signature.

Here is how it works in practice. A website asks your browser to draw an image or some text on a hidden canvas. Depending on your graphics card, drivers and fonts, the result comes out slightly differently on each device. This is known as a canvas fingerprint. The graphics chip can be exploited in a similar way through WebGL, by testing how your device renders a three-dimensional scene. Even sound can be used: the browser is asked to compute an inaudible tone, and tiny differences in how it is processed produce an audio fingerprint (AudioContext).

Your screen is just as obliging. Without a murmur, it reports its resolution and colour depth, in other words how many pixels it has and how many colours it can show. The combination of “this exact monitor, set up like this, with this graphics card and this sound chip” is surprisingly rare. I would not have believed how easily it picks you out of a crowd. It is like recognising someone not by their name but by their walk, their posture and the way they sit down. None of that changes just because you put on a different coat.

Robert Václavík during a consultation
Digital protection is not about technology but about habit, and about who you choose to trust.

What gives you away even behind a VPN

Test items covered here: IP leak via WebRTC · time zone · browser languages · device performance

Many people buy a VPN and think the job is done. A VPN is a good tool, and I recommend one myself, but it is not an invisibility cloak. There are several channels through which your real identity can leak despite it.

The first is WebRTC, the technology behind video calls made directly in the browser. It has one unpleasant trait: it can reveal your real IP address even while you are using a VPN. Whether it does depends on the browser, its settings and how well the VPN itself deals with the leak. I have seen a client with his VPN switched on and his home IP address still showing, simply because no one knew about this leak. The second channel is your time zone. A VPN may place you in another country, but the clock on your computer still shows Central European Time, and that gives away your region. The third is the list of languages set in your browser. If Czech comes first, it is not hard to guess your nationality, wherever you appear to be connecting from.

Finally, the device also reports its own performance: how many processor cores it has and roughly how much RAM. On its own this will not put anyone at risk, but it is another piece of the fingerprint mosaic. The more of these small details match, the more confidently someone can tell that the person behind the new connection is you again.

Trackers, cookies and a signal nobody listens to

Test items covered here: tracker blocker · “Do Not Track” signal · persistent storage · anti-fingerprinting protection · cookies

When you open an ordinary news website, you are rarely communicating with that site alone. Third-party tracking elements, known as trackers, load in the background. Advertising and analytics companies use them to follow which pages you visit and to build a profile of you. A tracker blocker is therefore one of the most effective tools you can have. It cuts off most of these silent observers before they even have a chance to load.

There is also a polite way to say “I do not want to be tracked”: the Global Privacy Control signal, or GPC. Your browser sends it to websites as a courteous request not to sell or share your data. Browsers are gradually dropping its older predecessor, DNT (Do Not Track), because websites treated it as a non-binding request and mostly disregarded it. GPC goes a step further: in some US states, California for example, it already carries legal weight, so companies there cannot simply brush it aside. That is why it is worth switching on in your browser.

Websites also store data about you directly in your browser, in what is called persistent storage, or localStorage. This data outlives your visit: it survives after you close the window and can simply sit there until you come back. It is like a pocket that slowly fills with other people’s notes. Every so often it is worth emptying it, in other words deleting the data stored by individual websites. In your browser settings you will find it under “site data”; otherwise the trail you leave keeps growing. The same goes for cookies. Cookies themselves are not the problem; they are what keep you signed in. The problem is tracking cookies, which follow you from site to site. That is why those irritating cookie consent banners exist. The advice is simple: reject everything that is not essential. And if your browser offers anti-fingerprinting protection, switch it on. It deliberately rounds off the small technical values I mentioned above and adds a little noise to them, so you stand out less from the crowd.

Outdated software is an unlocked door, and so is hardware access

Test items covered here: up-to-date browser · operating system · hardware access

There are two things we still underestimate. The first is keeping your browser and operating system up to date. Every update closes holes through which someone could get in. An outdated browser is like a lock for which a master key is already doing the rounds. In our line of work the rule is simple: anything that is not updated is a weak point. When the update prompt appears, it is not a nuisance; it is a free change of locks. And whether you use Windows, macOS, Android or an iPhone, the system itself reveals what kind of device you are coming from, which adds another line to your profile.

The second is hardware access. Browsers built on Chromium can give a website access to Bluetooth, USB, so-called HID devices such as keyboards or game controllers, and even the serial port. Firefox and Safari deliberately do not allow this, for security reasons. There are legitimate uses, such as connecting a payment terminal. But it is a powerful permission, and not every website that asks for it should get it. The best door is a closed door. I treat it like my car keys: I do not lend them to someone just because they asked nicely.

This leads to a general rule I repeat to clients over and over: hand out permissions as carefully as if you were paying for them out of your own pocket. When a website or app asks for your location, microphone, camera or Bluetooth, ask why. In most cases it does not need them at all and is simply adding another detail to the picture it is building of you.

What you can do today, without paranoia

I do not want you to finish this article, throw away your phone and move to the woods. A digital footprint cannot be erased completely, and that is not the goal. The goal is not to be the easiest person in the room to read. Physical protection works in exactly the same way: the point is not to disappear, but not to be needlessly conspicuous or an easy target. Blending into the crowd is usually the best protection.

Six steps give you the most for the least effort, and you can manage them in a single afternoon. First, use a browser that looks after your privacy by default, such as Brave or a properly configured Firefox. Second, add the uBlock Origin extension, which blocks most trackers and adverts. Its full version no longer works in Chrome, which is another reason I recommend Firefox or Brave in step one. Third, get a trustworthy VPN; I personally recommend Proton VPN or Mullvad, and treat it as one layer of protection, not a cure-all. Fourth, update your browser and operating system as soon as you can. Fifth, reject non-essential cookies and switch on anti-fingerprinting protection if your browser offers it. And sixth, be stingy with permissions.

That gets you most of the result for a fraction of the effort. The rest is habit and awareness, just as on the street. Once you start noticing how much your device says about you, it will stop catching you off guard.

When you want to know where you stand

Our Digital Exposure test shows how your own device measures up right now and gives you a score across all 20 points I have described here. It is a good starting point if you want to know where you stand.

And if protection is a more serious matter for you, whether that means personal security, discreet transport or the digital trail you leave behind, get in touch for an initial consultation. Over 17 years we have learned that physical and digital protection now belong together. I will be glad to talk you through, calmly, what your situation genuinely requires and what is just needless alarm. No pressure, no obligation.

“Protection has long been about more than who stands beside you. It is also about what your device quietly says about you to anyone who knows how to look.”— Robert Václavík

The complete series is now published

Nine practical parts on digital discretion, from what your device reveals about you to a secure network, communication and removing your data from data broker databases. You can read each part on its own or work through them in order.

Open the full series overview →

Found this useful?Share it
Share on Facebook

Would you like to discuss your digital footprint face to face?

For you, your family or your business, arranged discreetly around your situation. The first consultation is confidential and without obligation.

How we can help: TSCM Protective SweepTSCM Protective Sweep →