Or maybe images having metadata like Exif could contribute to leaking PII about OP e.g. location, device used to take the picture, etc.
Do we strip that before persisting to S3?
ETA: I think services like imgur strip that data for you, but I am not certain. There's so many image hosting services out there, idk how common this functionality is.
Oh that'd be cool!
reply