---
title: "My Pre-Deploy Name Check Only Read Text, and 13 Live Images Carried the Name"
canonical: https://dxdev.com/blog/2026-08-28_exif-and-false-claims-through-publish-gate/
datePublished: 2026-08-28
---
A real name sat in the EXIF data of 13 images on a pseudonymous site, and both of our name checks had passed.

An adversarial review pass over a recent commit fetched a JPEG from our live site and read the name in its EXIF Artist tag. The commit says every image in one directory carried the name, 13 files in all, and that one fetched from the live site proved it was already public.

## The rule we had

The commit message that fixed it describes the safeguard: "The standing rule is to grep for the surname before deploying." On this site that grep was the protection we had for the pseudonym, and for binary files it was the wrong tool. The build also ran a forbidden-terms script that scans 472 text files.

## What was wrong

The images were JPEGs, and each one carried the real name in its EXIF Artist tag. The review confirmed it by fetching one of them from the live site. The commit message puts the flaw in one line: "That grep is text-only and these are binaries, so nothing was ever going to catch it." The forbidden-terms script "never opens an image." Neither check could look at the place the name was.

## What changed

The 13 files were re-encoded, pixels only, into a fresh image object so no metadata rides along. The check afterward was concrete: 0 of 13 still contain the surname, all 13 open and report their original dimensions, and `getexif()` is empty on every one. The files grew about 9% at q88. The commit calls that "the honest cost of not shipping a name." The full build chain was green, with forbidden-terms clean, code-safety clean and 529 pages built. A ticket was filed for the scanner gap. When it was written it said nothing stops the next image from doing it again.

## What I did not verify

I did not re-check the live images for this post. The ticket for the scanner gap is now marked Done, but the notes I have do not show which check shipped or whether it covers PDFs and other binaries. The counts above (472 text files scanned, 529 pages built) measure different things and are not meant to match.

## Check this tomorrow

Open the metadata of every image you serve, for example with `getexif()` in Python, and read the Artist and any author or name fields, which is where the name sat in this story. Then open your pre-deploy check and find the line where it opens an image. If there is no such line, the 13 files from this story are what it would have missed.
