The Luddites Guide To Love… Or Operational Security For Online Dating.
Note: This is based off of a presentation I gave, for the purposes of maintaining good Opsec, I've removed the slides, and personal…
The Luddites Guide To Love… Or Operational Security For Online Dating.

Note: This is based off of a presentation I gave, for the purposes of maintaining good Opsec, I've removed the slides, and personal information pertaining to my background. This article has been stripped down to it's ossature, but contains 90% of the same information as my initial presentation.
I’m publishing this here because I feel it will benefit the community, and I found there haven’t been any really in depth guides towards understanding, and mitigating data risks in online dating.
Any questions, comments, or suggestions are welcome.
Forward: “The Luddites Guide To Love”, is a presentation that seeks to explain various dating methods for those concerned with their privacy, understanding why securing your data is important, and how to mitigate data leakage when using “mainstream” non-anonymous dating apps.
Risks associated with online dating:
The risks associated with relinquishing your personal data with online dating are several, but the primary ones are your personal data being sold to third parties, hackers leaking and selling your information on the deep web, stalkers, and government agencies pursuing you for political, or other reasons. We are quickly going to discuss these potential threats:
Personal information being sold to third parties — 99% of dating sites make there money by selling your personal data to third parties, as well as the use of premium features, this is potentially dangerous because a lot of dating sites collect extremely sensitive dating information including real name, birth date, credit card number, pictures, ID’s, email address, physical address, as well as personal, and political information.
This information is then sold to third parties for research purposes, the process to buy this information is generally pretty lax, and even anonymized data can be reverse engineered to link it to real names, this has been explained extensively in Svea Eckert’s Defcon 25 presentation “Dark Data
Link: https://www.youtube.com/watch?v=1nvYGi7-Lxo
Hackers — Hacker’s tend to target dating sites to sell the exfiltrated information online, in the past this information has been used by malicious actors to blackmail people in positions of power, or the vulnerable, as covered by the advocate news piece on gay African’s being extorted¹.
As well as so called “moral-fags”, hacker slang for someone who hacks for “moral reasons”, these malicious hackers are not interested in money, and hack to either shut down a service, or scare and humiliate their targets. An example of this being the Ashley Madison hack, Ashley Madison is a website where married spouses seeking to have an affair could connect, wherein the hackers of the site requested Ashley Madison shut down the service, or they would publicly release it’s users information, which they did end up doing².
Sources: 1). https://www.advocate.com/crime/gay-nigerians-blackmailed 2). https://www.wired.com/2015/08/happened-hackers-posted-stolen-ashley-madison-data/
Stalkers — Stalkers can often use the overabundance of personal information on display to threaten, and harass their victims, in the past dating sites that don’t properly sanitize data have allowed the harasser to track victims down to specific locations using photo metadata¹.
Sources: 1). https://www.colorado.edu/today/2012/01/12/some-dating-websites-do-not-remove-gps-data-photos-cu-boulder-students-find
Government Agencies:
Several government agencies have used personal data from social media websites to prosecute individuals for political reasons, as I feel was the case with the arrest of Cody Wilson. To be terse, Cody Wilson was the inventor of the 3D printed gun, and has openly sparred with the US government, defiant that printing a firearm qualifies “Freedom of Speech” under the constitution. He was arrested and charged for having sex with a minor (statutory rape) he met off of a dating site for “sugar daddies”. In order to use the website, the terms of use state you must be over the age of consent in your state, he has stated that he did not know she was a minor, and I personally believe him, I think it was a witch hunt by an overzealous government prosecutor, to embarrass and punish someone who was engaged in legal political dissent¹.
The Government has been known to scrape personal information from social media sites to go after individuals for civil forfeiture, and using profile pictures to do so as admitted by the IRS in a slate, and intercept news articles² ³
Sources:
1). https://www.wired.com/story/cody-wilson-accused-child-sexual-assault/ 2). https://slate.com/technology/2021/03/dating-apps-data-brokers-transparency-government.html 3). https://theintercept.com/2022/02/18/location-data-tracking-irs-dhs-digital-envoy/
Anonymous non online methods:
With the risk vectors out of the way, we can now discuss a couple of offline methods to date without giving much, or any personal information.
1). In person at events, bars, ect. It’s happening less and less, and it’s more of an art than a science, but people do still meet randomly in person, at social settings.
2). Speed dating events, you can usually pay in person at the door, and limited information is collected.
Pro’s — Pretty private, cheap.
Con’s — May be awkward depending on the venue and participants preferences, may not happen often or be available in your area.
3). Dating agencies, these are in person physical services that exist to match members, members are provided with a matchmaker (sometimes coach) it’s usually a good option for more affluent, and older individuals.
Pro’s — Private information is only held by the dating agency, and can often be destroyed upon request, highly specialized service that matches people via a matchmaker. Convenient as the dating process is handled by a matchmaker. Does tend to work to find serious long term partners.
Con’s — These services are extremely expensive, and usually start at $3000.00 per year, potentially much more if coaching is requested. On a balance these services cater towards career people, and these individuals are generally older. These services tend to only exist in massive cities.
Examples:
1). https://executivesearchdating.com/ 2). https://www.divinematchmaking.com/
Anonymous online methods:
These are dating sites where not only is the use of a picture is not required, but also where it is not a massive detriment to not have a photo posted, these are privacy oriented by design. Many of these websites while usable, and very good under certain circumstances, do have massive potential caveats.
1). Craigslists personals:
Pro’s — Massive broad audience, extremely private by design, near zero censorship, FREE.
Con’s — Does not exist anymore, but this was the gold standard for anonymous online dating.
2). Doublelist personals:
Pro’s — extremely private by design. It is possible to find people seeking an LTR relationship (Long Term Relationship), not a massive usage, censorship abounds (can’t swear in ads).
Con’s — Paid subscription required for additional features, not a broad audience, is used more for “pay for play hookups”, and “no strings attached encounters” rather than LTR relationships.
3). Locanto personals:
Pro’s — extremely private by design. It is possible to find people seeking an LTR relationship (Long Term Relationship)
Con’s — Not a broad audience, is used more for “pay for play hookups”, and “no strings attached encounters” rather than LTR relationships. Limited adoption
4). Fetlife:
Pro’s — Very private by design, not owned by a megacorp, substantially more features than competing personal sites, 95% free, tenured site with a large audience, LTR personals, vanilla personals, near zero censorship, active inclusive friendly community. One time lifetime subscription available.
Con’s — Near zero censorship (extreme consensual pornographic content is allowed, and celebrated) may not be for those with more sensitive sensibilities. Is not technically a dating site. Is designed for “kinksters” and by virtue of that fact is not for everyone, learning curve required to use the site for dating purposes. Vanilla personal boards are small, and limited to bigger cities.
5). Lex:
Pros — Very private by design, 95% free, wide adoption, high security ranking from mozilla.
Cons: By design is ONLY meant for the LGTBQ community.
How to respond to matches via anonymous online dating:
So someone responded to your ad, or you got a response back from someone you messaged, and now you are wondering where to go from here? From my experience this is the best way to go about things:
The slow and steady tit for tat method:
1). If you are posting an ad you should include a “test line” in the ad to make sure an actual person responds to it, and not a scammer, or bot. Something akin to “when responding please include the name of your favorite pokemon”
2). You should initially speak on the app, or email where you met (anyone that wants to speak off the app immediately should be a red flag).
3). Once comfortable you can trade phone numbers, and begin to text each other, take note of the phone number to make sure it is local to wherever the ad was located.
4). Try to set up an in person date within two weeks, obviously this is dependent on scheduling and external factors. In setting up the date if you want to remain completely anonymous until you meet in person you should give the other party is much of a physical description as possible, and wear something to the date that is easily distinguishable. If you opt to send pictures make sure to scrub metadata (more on this after), and not send something you’re not comfortable leaking (in my case it’s never happened, and I believe on a strong balance people are good, but it’s important to take caution in the event it happens).
When selecting a place to meet it should be public, and ideally the choice of where to meet should be given to the party that reached out to you, or who responded to you, as long as both parties feel safe meeting somewhere, that’s all that matters, don’t be too picky.
Mainstream online dating:
I need to preface this, when I discuss “mainstream” dating sites I am not referring to the user preferences the site is catered around. Rather I am referring to the “standard” format for online dating, that being to provide a picture, followed by personal information, and a writeup.
With the following list serving as some of the more popular mainstream apps:
- Tinder
- PlentyOfFish
- OkCupid
- Grinder
- Eharmony
- Bumble
Aside from the larger more popular mainstream dating apps there is a cornucopia of niche websites that make use of the mainstream dating format:
- farmersonly.com (for farmers, survivalists, and unofficially libertarians)
- christianmingle.com (religious based)
- blackspeoplemeet.com (black people dating)
- wherewhitepeoplemeet.com (wheat dating)
- equestriansingles.com (for adult women who still want ponies)
- and of course clowndating.com
Note: Just because these niche websites exist does not mean that they are popular.
Now of the popular mainsteam dating sites, most have been rated abysmally when it comes to privacy, and security according to the mozilla foundations “privacy not included” dating site reviews, a link which I will include:
https://foundation.mozilla.org/en/privacynotincluded/categories/dating-apps/
A guide for mitigating information security risks when using a mainstream dating site:
So you’ve decided you want to use a mainstream dating site where the majority of the population are mingling, as a consequence you are going to need to relinquish some personal data. However this guide seeks to heavily mitigate the risk, so even in a worse case scenario you will retain as much privacy as possible.
For this guide bumble was selected as the popular mainstream dating site for several reasons:
1). The premium version of the site has enhanced privacy, via a feature called “incognito mode”. 2). A lifetime premium membership can be purchased for $240.00 (believe me this is important, you are not going to want to go through these steps again once you do this the first time). 3). A popular mainstream site where women hit on men, it’s safer by design, and more convenient for both parties seeking serious long term relationships.
Prior to opening a bumble account several steps, and best practices should be taken.
Hardware:
In order to use bumble’s incognito mode you need to use a cell phone (even though a desktop app can be used for the service this specific feature is limited to phone usage). So your ideally going to want to get a burner sim, and place it in a privacy phone when using the service.
Of the two privacy focused phones on the market, that being, the partitioned Sirin Finney blockchain phone, or the Purism Librem 5, for these purposes the Librem 5 is the more secure device.
This is because the camera, microphone, and wifi card on the Librem 5 can all be easily manually switched off, these dating sites all require permissions to use these features, otherwise they won’t work. In being physically able to enable and disable these features, this maximizes physical security so your phone isn’t doing stuff in the background your not aware of.
The downside is the Librem 5 is a very expensive device with non stellar parts.
Link: https://puri.sm/products/librem-5/
The second more economical option is to buy a burner smart phone with cash (it needs to be a smart phone), from somewhere like 7–11 where they do not require ID. Then activate it using fake information (through a VPN), and top up the device using top up codes you buy with cash. AND only use this phone for online dating, and when not in use ideally turn off the device, take out the battery, and keep in in a faraday bag.
Now this is important when buying a burner phone, you do not want to activate it right away, you want to wait at least a month, that is because the store will retain that video footage of you buying the device for that long, you want that video footage to be overwritten first for maximum privacy.
When activating a burner phone you do not want to use your real information, most of the required information for these types of phones consists of only a name and address:
I used the following:
Name: Duncan Mccockin Address: The address of a hotel I found online through google
Prerequisites:
- A burner prepaid credit card: You are going to need to pick up a burner credit card to sign up for the premium service, as well as get a VPN to further enhance your privacy.
Much like the burner phone, you will be buying this card with cash, waiting a month, then using fake information to activate it for online use. The card should be in a denomination of $500.00 to be able to pay for a lifetime premium service in one go, as well as for the VPN.
They sell these cards with this specific monetary value, at saveonfoods, as well as other vendors like some moneymarts, call around.
As a bonus when initially activating your accounts you will be doing this from a public place with open wifi like a coffee shop. Once you have your VPN running you may relax a bit… Or not
- VPN: You are going to sign up and get a VPN service, I strongly recommend express VPN, you are going to sign up for this service using your burner phone number, burner credit card, and fak information.
Signing up for Bumble:
With all these elements in place, you are going to run your VPN to sign up for the service, you are going to use your prepaid burner credit card to get the lifetime subscription, you are going to get the code for the service by using your burner phone.
You are then going to fill out your personal information with slightly inaccurate stats, this is to prevent your actual information coming out if the website gets hacked, or it being pooled to thrid parties.
You will select a clever but polite nickname, you can use the fake name associated with the burner card as your “real name”, or use a misspelt version of your real name depending on the level of operational security you wish to achieve. When listing your age, height, body specs you do not want to make it drastically different than what it really is, otherwise it’s going to come off looking really disingenuous to a prospective match when this is discussed in person.
Now comes the trickest part, the pictures, and the reason why incognito mode is so important.
Bumbles incognito mode hides your pictures from the pool of standard user pictures, the only people that can see these pictures are those that you decide to show by matching with them first.
Photo good practices vs bad practices (non technical):
Pictures uploaded to the website should be of you looking good, you however are going to want to make sure the pictures do not include anything offensive in the background, or anything that can get you into trouble (for example weed, license plates, rolo watches, highly specific location landmarks, ect).
Let’s quickly discuss some risk factors with photos using the following examples:
- If you have drugs in your picture, even if it is legal in the jurisdiction you are in, it may not be legal in a different country. In the past if Canadians went to the US, and the border agent asked you to show them your social media, or other online profiles you would need to provide that or be potentially be arrested (these searches could be performed without grounds according to the privacy commissioner of Canada¹). If they saw pictures of a drug not legal in their country they could not only deny you entry, but also start a record on you, you do not want to be on a watch list².
Source: 1). https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/your-privacy-at-airports-and-borders/#toc2a 2). https://www.latimes.com/world/la-fg-canada-marijuana-immigration-20181015-story.html
- Wearing expensive jewelry, clothing, or being photographed in your nice car is a risk. As you could be the target of thieves, or worse the CRA, or police that may think you are somehow living beyond your means, you do not want to end up on the “anti-terrorism, and money laundering” watchlist based on a wild hair some “alphabet boy” has up their ass.
- Overtly specific location photo’s, do not take pictures of yourself at your home, or workplace, or somewhere you visit often, or that is close to where you live, these can be used by stalkers, exes, trolls, or private investigators to try and determine your patterns/location.
Photo good practices vs bad practices (technical):
Meta data sanitation: When you take a photo using a digital device, this device will often mark certain attributes of the photo using what is called EXIF metadata, this data can include the date, time, location, what device the picture was taken with, ect. By default most dating sites will scrub this data themselves, however it is still a good practice to scrub that data yourself to prevent it being seen by the dating app itself.
Windows guide to remove metadata: https://www.microsoft.com/en-us/microsoft-365-life-hacks/privacy-and-safety/how-to-remove-metadata-from-photos
Kali linux metadata removal exiv2 tool page: https://www.kali.org/tools/exiv2/
Defeating facial recognition using Fawkes:
Your pictures can be collected and pooled into facial recognition databases, to prevent this and screw up the AI algorithms these databases use, you can download the tool Fawkes, run your pictures through the program before uploading them. Fawkes makes changes to the pictures invisible to the human eye that make it difficult for this kind of facial recognition software to work properly against your pictures.
Fawkes tool link: https://sandlab.cs.uchicago.edu/fawkes/
Congratulations!:
You done did it, you set up a dating profile relinquishing the least amount of personal info possible. You found a match, and are living happily ever after. But wait! You’ve forgotten about your dating profile, and there was a hack and the information you used was haxxored, this is what the bad actor will see:
- Your credit card number (it was a burner, attributed to a fake name and address, the prepaid money has already been spent so the bad actor is left with some useless numbers).
- Your name and address (You faked these, so the bad actor could in theory try and ask around for your fake name at the address, but they’ll get laughed out of Texas when they ask someone if they know where Duncan Mccockin resides).
- You’re phone number (“Hello Mr.Duncan Mccockin, I’m blackhat here to try and extort you”, you response should be a caustic laugh, followed by a click, before tossing the sim into the trash).
- They got your photo’s (Oh no! they have some pictures of you looking nice in a non specific location, they pull the metadata, and nada. A spook tries to run it through a facial recognition database and nada).
- They can try to trace your address via IP (it’s not you’re real address, but the VPN address. They can try and subpoena log information from expressVPN, but it’s a company that has gone to court and won over it’s clientele privacy, and oh yeah don’t forget you used fake information to sign up for it, so it’s moot point anyway).
- You want to nuke your account, so you use the VPN to change to the California region where under the CCPA (California Consumer Protection Act) they have very strong legal protections for the deletion of personal information, you then send the request to “Oppenheimer” the account, and the dating site will be legally compelled to do so (source: https://epic.org/california-consumer-privacy-act-ccpa/)
Have fun online dating, and here’s to finding love the Luddite way.
메타데이터
- post_id
- acc959ef640e
- slug
- the-luddites-guide-to-love-or-operational-security-for-online-dating-acc959ef640e
- url
- https://medium.com/@seccult/the-luddites-guide-to-love-or-operational-security-for-online-dating-acc959ef640e
- canonical_url
- https://medium.com/@seccult/the-luddites-guide-to-love-or-operational-security-for-online-dating-acc959ef640e
- author_url
- https://medium.com/@seccult
- status
- ok
- fetched_at
- 2026-06-26 03:39:16