Library Header Image Library Header Image

Cybersecurity Awareness: How Your Digital Trail Becomes a Profile


Posted on by Erik Dierks

Key Takeaways:
  • Small pieces add up. Cookies, device details and public posts that look harmless alone can combine into a detailed profile.
  • Public details deserve a second look. Clues that are fine alone can be combined, by scammers or by AI, so a little care about what you post goes a long way.
  • Small choices work. Fewer optional cookies, built-in browser protections, fewer profile details and careful AI prompts all shrink your footprint.

You look up a pair of shoes. The shoes follow you around the internet for three days. Apparently, they have separation anxiety.

Those ads are the visible part of a system that can connect your browsing, purchases, location and public posts into a profile: a picture of your interests, habits and sometimes your identity. A profile need not begin with your name. A recognizable device or account can be enough to predict interests, and other records can help attach an identity later. You went shopping. Your data went networking.

You do not have to go offline to take back some control. This is the first article in a three-part series on privacy at work and home. It explains how the trail gets built, how public information and AI can speed up the assembly, and a handful of small, practical steps that make a real difference.

Your browser leaves calling cards

A browser is the software you use to view websites, such as Chrome, Safari, Edge or Firefox. A cookie is a small file a website saves in your browser. Cookies are useful for remembering what is in your cart or keeping you signed in, and they can also connect your visits over time. A tracking pixel is a tiny, invisible image that reports your visit to another service when a page loads. Advertising and analytics code can bring outside companies (often called third parties) into the exchange. Analytics means measuring behavior, such as clicks or time on a page. That is often harmless; the privacy question is who receives the measurement and what else they do with it.

A browser fingerprint is a pattern built from your device’s characteristics, such as screen size, language settings and how it draws graphics. Think of recognizing someone by their coat, their walk and an unfortunate hat. No single detail is remarkable, but the combination can pick out one browser, even after you delete cookies.

Curious what this looks like for your own browser? EFF (the Electronic Frontier Foundation, a nonprofit digital rights organization) offers a free tool called Cover Your Tracks that demonstrates some of these techniques. Read its privacy notice, run the test, switch on your browser’s built-in protections, then run it again and compare. A result labeled “unique” describes the test’s own comparison data, not every person on Earth, and a good result is not an invisibility certificate. On work devices, check with IT before adding browser extensions (small add-on programs) or changing managed settings (the settings your IT team controls).

Public details deserve a second look

OSINT (pronounced “oh-sint”), short for open source intelligence, means gathering and analyzing information that anyone can openly obtain in order to answer a question. “Open source” here describes access to information, not free software. Journalists and security teams use OSINT for good reasons. So can someone preparing a targeted scam, meaning a scam tailored to a specific person or company rather than sent to everyone (security teams sometimes call this spear phishing).

Imagine Susan’s public biography names her employer, a conference schedule reveals a trip, and a photo shows a work badge. Someone could combine those clues into a convincing travel-related request, such as a message from “the company travel desk” about a booking change. This is an illustration, not a documented incident. No password needed to be cracked; the material was sitting outside, waving. Now picture Susan with two small habits: she crops badges out of photos, and she confirms any booking change through the company’s own travel system rather than through the message. The clues lead nowhere.

Data brokers are companies that collect personal information from many sources and sell or share it with others. People-search sites are one kind: they can combine public records with commercial information to list addresses and relatives. Opting out of a listing helps reduce your exposure, but it does not erase the underlying public record, and listings can reappear, so an occasional check is worthwhile.

AI makes the assembly line faster

A language model is the kind of AI behind many chatbots. It can organize text you give it and make inferences from clues, meaning it draws a conclusion rather than finding an explicit statement. In a 2024 research study, Staab and colleagues showed that certain AI models could infer personal details, such as a person’s likely location or occupation, from the text of Reddit profiles. Those results concern particular models, tasks and data. They do not mean every AI can accurately profile everyone.

For example, posts about a distinctive commute and local events might narrow down where you live, even if your name appears nowhere. AI can speed up that kind of analysis. It can also make things up (people call this hallucination), producing an invented biography with the serene confidence of someone who has never had to correct a spreadsheet.

Optional experiment: if you would like to see your public footprint the way a stranger might, start a fresh conversation in a company-approved AI service, with memory and connected accounts (such as email or calendar) turned off where possible. Then try a prompt like this:

“Using only public sources, write a short professional biography of [my name and public employer or city]. Cite the original source for every fact. Flag uncertain identity matches. Do not infer sensitive traits, include home addresses or family details, or invent missing information. If you cannot browse or verify a claim, say so.”

Then check its work: open each source and ask whether it is actually about you and whether it supports the claim. A surprising answer could come from public pages, earlier context in the chat, connected tools or plain fabrication, and the biography alone cannot tell you which. A model that cannot browse the web cannot map your current public footprint, and a blank answer does not prove you are private. Do not upload private records to help it “discover” you. Expect a mix of the accurate, the outdated and the occasionally fictional. Each one tells you something useful about what to keep, tidy or ignore.

Give away fewer puzzle pieces

Every piece you withhold makes the puzzle harder to assemble, and most of these steps take only minutes.

Tame the trackers. Reject optional cookies when a site offers the choice. Turn on your browser’s built-in tracking protection, which blocks many known trackers automatically (Mozilla documents what Firefox blocks, and most major browsers offer some version of this). Consider Global Privacy Control, a browser signal that tells websites you opt out of the sale or sharing of your data. It works in supported browsers or through trusted extensions, and its legal force depends on where you live. It is not a physical barrier against dishonest collection. And go easy on extensions: each unfamiliar add-on is one more thing you have to trust.

Know what “private” buttons really do. Private browsing mainly limits what remains on your device after a session, such as history and cookies. A site still recognizes the account you sign into. A VPN, or virtual private network, routes your internet traffic through a provider, which changes who can see it: you are trusting the VPN company instead of your local network operator. It does not erase your cookies, fingerprint or account identity. The word “private” on the button has a smaller job description than most people assume.

Share fewer details. Skip optional profile fields. Consider an email alias, a second address that forwards to your main inbox, for shopping and sign-ups; it helps separate your accounts but does not guarantee anonymity. Check photo backgrounds before posting, hold travel posts until you are back, and avoid linking sensitive personal accounts through a distinctive shared username. Treat AI prompts and attachments as disclosures: for work, use approved tools only, and check the tool’s retention settings (how long your inputs are kept) and training settings (whether your inputs can be used to improve the AI).

Try this today

Look at one of your public profiles the way a stranger would, and remove one unnecessary detail. Run Cover Your Tracks once. Change one privacy setting that makes sense for you. Small improvements count; a perfect score is not required.

Sources and answers to common questions

Selected bibliography and practical reading. Sources reviewed October 5 2026. Follow official instructions for your device and region; settings and policies can change.

How does browser tracking work?

EFF. Cover Your Tracks explanations and test.

Explains cookies, fingerprints and the limits of privacy tools. The test has its own data collection notice.

What settings should I change?

Mozilla. Trackers and scripts Firefox blocks in Enhanced Tracking Protection.

Official guidance on browser protections; stronger settings may affect some websites.

Can I tell sites not to sell my data?

CalPrivacy. Enable opt-out preference signals.

Explains Global Privacy Control and how to enable supported opt-out signals.

What is OSINT?

Office of the Director of National Intelligence. 2024. Intelligence Community OSINT Strategy 2024–2026.

A formal explanation of open source intelligence; more technical than this article.

Can AI infer private details?

Robin Staab, Mark Vero, Mislav Balunović and Martin Vechev. 2024 revision. Beyond Memorization: Violating Privacy via Inference with Large Language Models.

Research underlying the inference discussion. Study results should not be treated as universal accuracy claims.

What should I share with an AI?

EFF Surveillance Self-Defense. Privacy Considerations with AI Tools.

Practical guidance on prompts, provider trust and privacy settings.

How do I remove people search listings?

FTC Consumer Advice. What To Know About People Search Sites That Sell Your Information.

Explains free opt-outs, paid services and why records can return.

Stay tuned for part three of our Cybersecurity Awareness blog series.

Contributors
Erik Dierks

Director, IT Security, RSAC

Blogs posted to the RSAConference.com website are intended for educational purposes only and do not replace independent professional judgment. Statements of fact and opinions expressed are those of the blog author individually and, unless expressly stated to the contrary, are not the opinion or position of RSAC™ Conference, or any other co-sponsors. RSAC Conference does not endorse or approve, and assumes no responsibility for, the content, accuracy or completeness of the information presented in this blog.


Share With Your Community

Related Blogs