Porn & Privacy
ET
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
In the rapidly evolving landscape of digital security, the talk "Porn & Privacy" by ET (Edna Johnson) at DEF CON 32 delivered a critical examination of the escalating threats to personal privacy, particularly concerning intimate online content. This presentation transcended typical cybersecurity discussions by delving into the sensitive intersection of evolving obscenity laws, the pervasive issue of non-consensual intimate image abuse (NCIIA), and the emerging dangers of deepfakes and sextortion. ET, a cybersecurity professional and master's student, underscored the urgent need for robust digital hygiene and proactive measures to safeguard personal information in an increasingly vulnerable digital world.

Key moments
- 0:00 Introduction, content warning, and talk roadmap
- 2:00 State obscenity laws and ID verification privacy risks
- 4:00 Essential digital privacy practices and account security basics
- 6:00 Security hygiene: separate emails for adult websites
- 8:00 Defining non-consensual intimate image abuse (revenge porn)
- 8:25 First steps after image leak: conducting self-OSINT
Porn & Privacy
Speakers: ET, Cybersecurity Professional, Master's Degree Student
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=RyuDq0cjap0
Overview
In the rapidly evolving landscape of digital security, the talk "Porn & Privacy" by ET (Edna Johnson) at DEF CON 32 delivered a critical examination of the escalating threats to personal privacy, particularly concerning intimate online content. This presentation transcended typical cybersecurity discussions by delving into the sensitive intersection of evolving obscenity laws, the pervasive issue of non-consensual intimate image abuse (NCIIA), and the emerging dangers of deepfakes and sextortion. ET, a cybersecurity professional and master's student, underscored the urgent need for robust digital hygiene and proactive measures to safeguard personal information in an increasingly vulnerable digital world.
The talk highlighted how legislative efforts, ostensibly aimed at child protection, are inadvertently creating new vectors for privacy erosion by mandating identity verification for adult content. This seemingly simple requirement carries profound implications, linking individuals' most private online activities to their real-world identities, a dangerous precedent for surveillance and potential exploitation. Furthermore, ET addressed the devastating impact of NCIIA, commonly known as "revenge porn," and provided actionable strategies for both prevention and recovery. The relevance of this talk is paramount for anyone navigating the complexities of digital life, offering essential insights into protecting oneself from both state-mandated data collection and malicious actors.
Background
▶ Watch: Introduction, content warning, and talk roadmap (0:00)
The digital age has brought unprecedented convenience and connectivity, but it has also ushered in a new era of privacy challenges. At the core of these challenges is the persistent tension between individual anonymity and the increasing demand for identity verification, often under the guise of public safety or moral regulation. ET's talk commenced by addressing a pressing legislative trend: the proliferation of obscenity laws in various U.S. states that mandate age verification—specifically, the upload of government identification—to access adult content online. This legislative push, often bundled with broader "child protection internet bills" such as Florida's law setting a minimum age for social media use, presents a paradox. While intended to shield minors, these laws compel adult users to surrender Personally Identifiable Information (PII), thereby creating a centralized database of individuals' adult content consumption habits linked directly to their identities.
This legislative backdrop directly impacts major platforms. Pornhub, for instance, has responded by blocking access for users in states like Utah, North Carolina, and Texas, which have implemented such laws, citing the unacceptable privacy implications. This forces users in affected states to either comply with intrusive ID verification, potentially use less reputable or "sketchy" websites that might not adhere to these laws (and thus offer less security), or resort to Virtual Private Networks (VPNs) to circumvent geographical restrictions. Each of these alternatives introduces its own set of risks, from direct privacy compromise to exposure to malware or less secure platforms.
Beyond the legislative sphere, the talk established fundamental concepts of digital privacy, defining it as the protection of private citizens' online information, encompassing everything from corporate data collection to personal sharing on social media. Every online activity leaves a digital footprint, a trail of data that can be aggregated and used to identify individuals. This leads to the critical concept of PII, which includes any information that can be used to uncover an individual's identity, such as social security numbers, full names, email addresses, and phone numbers. The talk emphasized that a lack of awareness or adherence to basic digital security hygiene significantly exacerbates these risks, making individuals more susceptible to various forms of abuse, including the non-consensual sharing of intimate images. The historical context of NCIIA, exemplified by cases like that of Katelyn Bowden, underscores the long-standing nature of this problem, which has only been amplified and complicated by new technologies and legislative actions.
Key Findings
▶ Watch: Essential digital privacy practices and account security basics (4:00)
ET's presentation illuminated several critical findings concerning the intersection of pornography, privacy, and digital security in the contemporary landscape:
- Legislative Mandates Create Paradoxical Privacy Risks: The most immediate finding is that state-level obscenity laws requiring government ID for adult content access, despite their stated intent of child protection, are actively undermining user privacy. By forcing individuals to link their PII to their consumption of adult material, these laws create a centralized, vulnerable repository of highly sensitive personal data. This data, if compromised, could lead to severe reputational damage, blackmail, or other forms of exploitation. Pornhub's decision to block access in affected states underscores the industry's recognition of these inherent privacy dangers.
- Ubiquity and Devastating Impact of Non-Consensual Intimate Image Abuse (NCIIA): The talk underscored that NCIIA, often termed "revenge porn," remains a widespread and emotionally devastating form of digital abuse. It involves the distribution of sexually graphic images without the subject's consent, regardless of whether the images were initially obtained consensually within a private relationship or illicitly. The psychological and social fallout for victims is immense, making prevention and effective recovery strategies paramount.
- Fundamental Digital Security Hygiene is Often Lacking: A significant underlying finding is that many individuals, even those aware of general digital risks, fail to implement basic but crucial security measures. The talk identified common vulnerabilities stemming from weak passwords, lack of Two-Factor Authentication (2FA), and the broad use of single email addresses across diverse online activities. This lack of robust security hygiene makes users more susceptible to account compromises, which can then escalate into NCIIA or other forms of digital harm.
- Emerging Threat of Deepfakes and Sextortion: While not explored in extensive technical detail within the provided transcript, the inclusion of deepfakes and sextortion in the content warning and roadmap signifies their growing prominence as threats. Deepfakes, synthetic media generated by artificial intelligence, can fabricate intimate images or videos, making it possible to create non-consensual content without any original source material. Sextortion, leveraging compromised or fabricated intimate content, represents a potent form of blackmail, highlighting the evolving sophistication of digital attackers.
- Proactive Self-OSINT and Online Hygiene are Essential for Recovery: For victims of image leaks, a crucial finding is the necessity of immediate, proactive steps. The recommendation for Open Source Intelligence (OSINT) on oneself, potentially with the aid of a trusted friend, is a practical, if emotionally challenging, first response. This process, coupled with rigorous "online hygiene" to remove or secure exposed information, is presented as a vital pathway towards reclaiming digital safety and mitigating further damage.
Technical Deep Dive
▶ Watch: Security hygiene: separate emails for adult websites (6:00)
The technical core of ET's talk revolved around both the mechanisms of privacy erosion and the foundational practices for robust digital self-defense. The discussion began with the obscenity laws being enacted in states such as Utah, North Carolina, Texas, and Florida. These laws mandate that users upload government IDs to access adult content providers. From a technical perspective, this creates a direct link between an individual's Personally Identifiable Information (PII)—such as their full name, date of birth, and potentially address—and their browsing habits for adult material. This information, once collected by content providers or third-party age verification services, becomes a potential target for data breaches, blackmail, or government surveillance, fundamentally eroding the concept of private online activity. The speaker noted that Pornhub, a major adult content platform, has responded by geoblocking users from these states, displaying a message explaining the privacy implications of these laws. This forces users to either comply, use less secure "sketchy websites," or employ Virtual Private Networks (VPNs) to mask their geographical location and IP address, thereby bypassing the blocks. While VPNs offer a layer of anonymity, their effectiveness depends on the VPN provider's trustworthiness and security practices.
ET then provided a primer on digital privacy fundamentals, emphasizing that all online activities leave a digital footprint that can be used for identification. PII was defined as any data connected to a specific individual that can be used to uncover their identity, including social security numbers, full names, email addresses, and phone numbers. The talk stressed that protecting this information is paramount.
To combat these threats, the presentation outlined essential account security basics:
- Strong Passwords: ET advocated for the use of passphrases—longer, more memorable sequences of words—rather than short, complex passwords. Key recommendations included passwords of at least 10 characters or more, incorporating multiple character types (numbers, special characters, uppercase, and lowercase letters). To manage these complex credentials, the use of a password manager was highly recommended, with examples like Bitwarden, KeePass, and 1Password being cited. Password managers securely store and generate unique, strong passwords for each account, significantly reducing the risk of credential stuffing and brute-force attacks.
- Two-Factor Authentication (2FA) / Multi-Factor Authentication (MFA): This crucial security layer adds an additional verification step beyond just a password. ET detailed various forms:
- SMS/Text Messages: While convenient, SMS-based 2FA is generally considered less secure due to risks like SIM swapping.
- Authenticator Applications: More secure options like Google Authenticator, Microsoft Authenticator, and Duo generate time-based one-time passwords (TOTP) that are less susceptible to interception.
- Hardware Tokens: The most secure option mentioned, such as a YubiKey, provides physical proof of presence and is highly resistant to phishing and man-in-the-middle attacks.
- Security Hygiene for Sensitive Accounts: A key practical recommendation was to limit the amount of personal information shared on "spicy websites" or adult content platforms. More critically, ET advised using separate email addresses for different categories of online activity. For instance, one email for personal communications, another for banking and financial services, and a distinct, anonymous email for adult content sites. This compartmentalization, a form of damage scope limitation, ensures that if one account or service is compromised, the impact is isolated, preventing a single breach from exposing an individual's entire digital life.
Finally, ET defined Non-Consensual Intimate Image Abuse (NCIIA) as the distribution of sexually graphic images without the individual's consent. This broad definition covers both images obtained without permission and those initially shared consensually within a private or confidential relationship but later distributed maliciously. The technical implication here is that the ease of digital sharing and replication means that once an image is online, it can be extremely difficult to control its spread, underscoring the importance of prevention and rapid response.
Demo / Proof of Concept
▶ Watch: Defining non-consensual intimate image abuse (revenge porn) (8:00)
While ET's talk did not include a live, technical demonstration in the traditional sense of exploiting a vulnerability or showcasing a new tool, it did outline a crucial practical methodology for individuals who suspect their intimate images have been leaked online. This can be considered a proof of concept for self-recovery and mitigation.
The speaker described the initial indicators that someone's images might have been compromised: an unexplained "off" feeling, a sudden influx of friend requests on platforms like Facebook, an unusual surge of new followers on Twitter, or an overflowing email inbox. These social signals often precede direct notification of a leak or can be the first signs of exposure.
The core recommended action, functioning as a practical demonstration of proactive defense, is to perform OSINT (Open Source Intelligence) on oneself. This involves systematically searching the internet for one's own name, usernames, email addresses, and any potentially identifying information, specifically looking for leaked images or associated discussions. ET acknowledged that this can be an emotionally taxing experience and strongly advised enlisting the help of a trusted friend. This "buddy system" provides emotional support and an objective perspective during a potentially distressing search.
Following the discovery of leaked information, the next step in this recovery proof of concept is to implement rigorous online hygiene. This includes:
- Identifying the source of the leak, if possible.
- Documenting all instances of the leaked images (screenshots, URLs).
- Utilizing platform-specific reporting mechanisms to request removal.
- Searching for and removing any other personal information that might exacerbate the situation (e.g., old forum posts with PII, outdated social media profiles).
- Strengthening all remaining online accounts with the security measures discussed earlier (strong passwords, 2FA, separate emails).
Although not a technical demo in the traditional sense, this outlined process serves as a vital, actionable framework for victims, demonstrating a concrete, step-by-step approach to regaining control and minimizing harm after a privacy breach involving intimate images.
Defensive Implications
▶ Watch: First steps after image leak: conducting self-OSINT (8:25)
The defensive implications stemming from ET's "Porn & Privacy" talk are multifaceted, requiring a combination of individual vigilance, robust technical practices, and an understanding of the evolving legal landscape. For defenders—whether individuals, privacy advocates, or cybersecurity professionals—the key is to proactively mitigate risks and establish resilient recovery mechanisms.
- Prioritize Digital Hygiene as a Foundation: The most immediate defensive action is to adopt and rigorously maintain fundamental digital security hygiene. This includes:
- Strong, Unique Passwords/Passphrases: Utilize password managers like Bitwarden, KeePass, or 1Password to generate and store complex, unique credentials for every online account.
- Mandatory Two-Factor Authentication (2FA)/Multi-Factor Authentication (MFA): Implement 2FA on all sensitive accounts, favoring authenticator apps (Google Authenticator, Microsoft Authenticator, Duo) or hardware tokens (YubiKey) over less secure SMS-based methods.
- Email Compartmentalization: Create and use separate email addresses for distinct online activities (e.g., personal, financial, adult content, gaming). This limits the blast radius of any single data breach, preventing a compromise in one sector from affecting others.
- Limit PII Exposure: Be highly conscious of the personal information shared online, especially on platforms that are not critical for professional or essential personal use.
- Navigate Age Verification Laws with Extreme Caution: Individuals in states implementing mandatory ID verification for adult content must understand the profound privacy risks. Defenders should advise against uploading government IDs to such platforms, as this links highly sensitive PII to intimate browsing habits, creating a significant target for data breaches and state surveillance. Alternative strategies include:
- Using Reputable VPNs: Employing a trusted VPN can mask one's geographical location, allowing access to content providers that do not require ID verification. However, users must research and select VPN providers with strong no-logging policies and a proven track record of security.
- Avoiding "Sketchy" Websites: Steer clear of less reputable sites that may not comply with laws but often lack robust security, increasing the risk of malware infection, data theft, or further privacy compromise.
- Prepare for and Respond to Non-Consensual Intimate Image Abuse (NCIIA): For individuals, the defense against NCIIA involves both prevention and a robust response plan:
- Pre-emptive Education: Understand the definition of NCIIA and the various ways intimate images can be obtained and distributed without consent. Be cautious about sharing intimate content, even with trusted partners, as relationships can change.
- Proactive Self-OSINT: Regularly conduct searches for one's own name, images, and other PII online. This allows for early detection of potential leaks.
- Rapid Response Protocol: If a leak occurs, the immediate steps outlined by ET are crucial:
- Document all instances of the leaked content.
- Utilize platform reporting mechanisms to request removal.
- Perform thorough online hygiene to remove any other exposed PII that could escalate the situation.
- Seek emotional support from trusted friends or mental health professionals.
- Awareness of Deepfake and Sextortion Threats: While not detailed extensively, the mention of deepfakes and sextortion highlights an evolving threat landscape. Defenders should:
- Cultivate Media Literacy: Develop skills to identify fabricated or manipulated media.
- Understand Extortion Tactics: Be aware of how attackers leverage compromised or fabricated intimate content for blackmail. Never engage with or pay extortionists, as this rarely guarantees removal and can lead to further demands.
In essence, the talk serves as a call to arms for individual digital self-defense. It emphasizes that while external threats are growing, a significant portion of vulnerability stems from a lack of fundamental security practices. By adopting robust digital hygiene and understanding the implications of legislative and technological developments, individuals can significantly bolster their defenses against privacy erosion and image-based abuse.
Key Takeaways
- State-mandated age verification for adult content poses significant privacy risks, linking PII to browsing habits and creating vulnerable data repositories.
- Strong digital hygiene is non-negotiable: Use unique, complex passphrases with a password manager, and enable Two-Factor Authentication (2FA) using authenticator apps or hardware tokens on all critical accounts.
- Compartmentalize your digital identity: Employ separate email addresses for personal, financial, and sensitive (e.g., adult content) online activities to limit the scope of damage from potential breaches.
- Non-Consensual Intimate Image Abuse (NCIIA) is a serious threat: Understand its definition and be cautious about sharing intimate content, even consensually, given the potential for future non-consensual distribution.
- Proactive self-OSINT and online hygiene are crucial for recovery: If intimate images are leaked, immediately conduct Open Source Intelligence (OSINT) on yourself (with support), document findings, report content for removal, and secure all other online accounts.
- Be aware of emerging threats like deepfakes and sextortion, which leverage advanced technology to create or exploit intimate content for malicious purposes, demanding constant vigilance and media literacy.
About the Speaker(s)
ET, also known as Edna Johnson, is a dedicated cybersecurity professional and a master's degree student. They use they/them pronouns. ET is actively involved in the cybersecurity community, notably competing in OSINT (Open Source Intelligence) CTF (Capture The Flag) competitions. Beyond their professional and academic pursuits, ET is passionate about empowering others, frequently advising friends on critical digital safety practices. Their expertise spans practical cybersecurity measures, digital privacy, and the sensitive issues surrounding online intimate content.