<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Linas Jonas</title>
    <description>The latest articles on DEV Community by Linas Jonas (@zilijonas).</description>
    <link>https://dev.to/zilijonas</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4128479%2F18cbab60-a364-4a09-81e6-58e218190390.jpg</url>
      <title>DEV Community: Linas Jonas</title>
      <link>https://dev.to/zilijonas</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/zilijonas"/>
    <language>en</language>
    <item>
      <title>Three PDF redaction failures worth studying</title>
      <dc:creator>Linas Jonas</dc:creator>
      <pubDate>Sat, 03 Oct 2026 22:22:49 +0000</pubDate>
      <link>https://dev.to/zilijonas/three-pdf-redaction-failures-worth-studying-4cia</link>
      <guid>https://dev.to/zilijonas/three-pdf-redaction-failures-worth-studying-4cia</guid>
      <description>&lt;p&gt;You do not need a clever exploit to recover some badly redacted PDFs. You need a text editor and copy and paste.&lt;/p&gt;

&lt;p&gt;That sounds too simple for a serious leak. It has happened in military reports, airport-security documents and court filings.&lt;/p&gt;

&lt;h2&gt;
  
  
  2005: the Calipari report
&lt;/h2&gt;

&lt;p&gt;The US Army published a report about the incident in Iraq in which Italian intelligence officer Nicola Calipari was killed. Parts of the PDF appeared blacked out, but the underlying text remained recoverable.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://en.wikisource.org/wiki/Calipari_Report" rel="noopener noreferrer"&gt;preserved report on Wikisource&lt;/a&gt; records the failed redaction. The useful lesson is about the file, not its subject: content can be invisible on a rendered page and still exist in the document.&lt;/p&gt;

&lt;p&gt;A reviewer looking only at the page could miss that distinction.&lt;/p&gt;

&lt;h2&gt;
  
  
  2009: TSA screening procedures
&lt;/h2&gt;

&lt;p&gt;A TSA screening-procedures document posted on a federal procurement site contained improperly redacted sensitive security information. The incident prompted a &lt;a href="https://www.oig.dhs.gov/sites/default/files/assets/Mgmt/OIG_10-37_Jan10.pdf" rel="noopener noreferrer"&gt;Department of Homeland Security inspector general review&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The document was meant to be shared in a limited form. Covering portions of it did not make that form safe to publish.&lt;/p&gt;

&lt;p&gt;This is why a workflow needs a check on the exported file, not just a check that someone marked the right paragraphs.&lt;/p&gt;

&lt;h2&gt;
  
  
  2019: a Manafort court filing
&lt;/h2&gt;

&lt;p&gt;A filing by Paul Manafort’s lawyers displayed black rectangles over passages that were still accessible through copying and pasting. The &lt;a href="https://www.americanbar.org/content/dam/aba/publications/judges_journal/vol58no2-jj2019-tech.pdf" rel="noopener noreferrer"&gt;American Bar Association’s account&lt;/a&gt; explains how text transferred into a separate document became readable.&lt;/p&gt;

&lt;p&gt;The filing was later replaced, but replacement cannot make already downloaded copies disappear.&lt;/p&gt;

&lt;p&gt;You do not need to repeat the exposed material to learn from the failure. The publication check happened too late.&lt;/p&gt;

&lt;h2&gt;
  
  
  Same mistake, different offices
&lt;/h2&gt;

&lt;p&gt;These incidents span fourteen years. They do not show that PDFs are impossible to redact. They show why appearance is the wrong success criterion.&lt;/p&gt;

&lt;p&gt;A PDF can hold text, images and annotations as separate objects. Putting a solid shape over text changes what the reader sees. It does not necessarily remove the text object.&lt;/p&gt;

&lt;p&gt;Using a real redaction feature matters. So does applying the redactions, exporting correctly and testing the result before it leaves your control.&lt;/p&gt;

&lt;h2&gt;
  
  
  A check you can add today
&lt;/h2&gt;

&lt;p&gt;Open the exported file in another reader. Select across the covered region, copy and paste into a plain text editor. Search for distinctive words or numbers you intended to remove.&lt;/p&gt;

&lt;p&gt;If they appear, stop sharing that export.&lt;/p&gt;

&lt;p&gt;Passing this test is not a complete security proof. Inspect metadata, comments and attachments too. A scan may contain both an original image and an OCR layer, and either can preserve information. High-sensitivity material deserves a more thorough inspection than a quick visual pass.&lt;/p&gt;

&lt;p&gt;I build &lt;a href="https://hddn.app" rel="noopener noreferrer"&gt;hddn&lt;/a&gt;, a browser-based PDF redaction tool. My rule is the same regardless of the editor: check the file you are about to send. A page that looks right is only the beginning.&lt;/p&gt;

&lt;p&gt;Adapted from &lt;a href="https://hddn.app/guides/redaction-failures/" rel="noopener noreferrer"&gt;hddn’s guide to redaction failures&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
    </item>
    <item>
      <title>How to redact a PDF for GDPR</title>
      <dc:creator>Linas Jonas</dc:creator>
      <pubDate>Sat, 03 Oct 2026 22:22:20 +0000</pubDate>
      <link>https://dev.to/zilijonas/how-to-redact-a-pdf-for-gdpr-2eci</link>
      <guid>https://dev.to/zilijonas/how-to-redact-a-pdf-for-gdpr-2eci</guid>
      <description>&lt;p&gt;You remove the names from a staff report. Then you leave the job title, start date and a paragraph about the only person who works weekends.&lt;/p&gt;

&lt;p&gt;The name is gone. The person may still be obvious.&lt;/p&gt;

&lt;h2&gt;
  
  
  Read for identity, not just patterns
&lt;/h2&gt;

&lt;p&gt;A detector can find email addresses, phone numbers and IDs. It cannot reliably judge what your recipient already knows. Read the surrounding sentences, tables, signatures and captions. In a small team, a role or an unusual incident can identify someone without a name.&lt;/p&gt;

&lt;p&gt;Under GDPR, personal data includes indirect identification. Replacing names with codes is not necessarily anonymisation. If additional information can reconnect those codes to people, you may have pseudonymised personal data instead. Recital 26 asks whether identification is reasonably likely, not whether you personally intend to try.&lt;/p&gt;

&lt;p&gt;That distinction matters before you call a document “anonymous”.&lt;/p&gt;

&lt;h2&gt;
  
  
  Decide what needs sharing
&lt;/h2&gt;

&lt;p&gt;Start with the purpose and audience. What does this recipient need to understand? Keep information that serves that purpose and remove unnecessary personal details.&lt;/p&gt;

&lt;p&gt;Sometimes a summary is a better answer than a heavily redacted source document. It may preserve the useful facts without carrying pages of unrelated information along with them.&lt;/p&gt;

&lt;p&gt;For anything legally sensitive, involve your data protection officer or counsel. This is a practical file-handling checklist, not a compliance opinion.&lt;/p&gt;

&lt;h2&gt;
  
  
  Remove content, then check the export
&lt;/h2&gt;

&lt;p&gt;Use a real redaction operation and apply it. A black rectangle may be an annotation sitting above readable text. Keep the original separately, then export a sanitised copy.&lt;/p&gt;

&lt;p&gt;Open that copy in a different reader. Search for removed names and distinctive identifiers. Copy across the redacted region and paste into a text editor. Check document properties, comments, form fields and attachments too.&lt;/p&gt;

&lt;p&gt;Those checks catch common failures. They do not establish that every hidden object is clean. Scanned pages need their underlying pixels and any OCR text layer checked as well.&lt;/p&gt;

&lt;h2&gt;
  
  
  Local processing reduces one exposure
&lt;/h2&gt;

&lt;p&gt;Uploading an unredacted PDF gives the service the information you are trying to remove. Check whether that transfer is appropriate before making it.&lt;/p&gt;

&lt;p&gt;A genuinely local tool avoids that document upload. It does not exempt your organisation from GDPR. Your lawful basis, security controls and applicable record-keeping duties still matter. If a provider processes personal data on your behalf, assess the processor arrangements and any international transfers.&lt;/p&gt;

&lt;p&gt;I build &lt;a href="https://hddn.app" rel="noopener noreferrer"&gt;hddn&lt;/a&gt;, which processes documents in your browser and lets you review detection candidates. Local processing is useful. It is not a compliance certificate.&lt;/p&gt;

&lt;h2&gt;
  
  
  If a bad export has already left
&lt;/h2&gt;

&lt;p&gt;Stop further sharing and follow your incident process. Article 33 generally requires supervisory-authority notification within 72 hours of awareness, where feasible, unless the breach is unlikely to create risk to people’s rights and freedoms. Not every mistake automatically requires notification. Do not guess at that assessment alone.&lt;/p&gt;

&lt;p&gt;The legal reference is the &lt;a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng" rel="noopener noreferrer"&gt;GDPR regulation&lt;/a&gt;, particularly Recital 26 and Articles 4, 28 and 33.&lt;/p&gt;

&lt;p&gt;Adapted from &lt;a href="https://hddn.app/guides/redact-pdf-for-gdpr/" rel="noopener noreferrer"&gt;hddn’s GDPR redaction guide&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>privacy</category>
    </item>
    <item>
      <title>How to redact a scanned PDF</title>
      <dc:creator>Linas Jonas</dc:creator>
      <pubDate>Sat, 03 Oct 2026 22:20:51 +0000</pubDate>
      <link>https://dev.to/zilijonas/how-to-redact-a-scanned-pdf-2c1j</link>
      <guid>https://dev.to/zilijonas/how-to-redact-a-scanned-pdf-2c1j</guid>
      <description>&lt;p&gt;You drag across a name in a scanned contract. Nothing highlights. Every tutorial says “select the text”, but there is no text to select.&lt;/p&gt;

&lt;p&gt;The name may be pixels inside a page image. Redacting that page means removing those pixels from the exported file, not covering them with a separate object.&lt;/p&gt;

&lt;h2&gt;
  
  
  Check whether the scan has a text layer
&lt;/h2&gt;

&lt;p&gt;Many scanners create searchable PDFs. They keep the page image and add invisible OCR text over it.&lt;/p&gt;

&lt;p&gt;Now there are two copies of the name: a photograph and an extractable string. Covering one does not remove the other.&lt;/p&gt;

&lt;p&gt;Try selecting a line and searching for a word you can see. If either works, account for the OCR layer. Check every page. A typed cover sheet followed by scanned pages is common, and one test on page one says nothing about page twelve.&lt;/p&gt;

&lt;h2&gt;
  
  
  Burn the redaction into a new image
&lt;/h2&gt;

&lt;p&gt;A rectangle saved as an annotation is a separate PDF object. It may be movable or removable. Even if the reader offers no delete button, the original image can remain inside the file.&lt;/p&gt;

&lt;p&gt;An image-based export can work when it renders the page with the redaction already applied, then builds a fresh PDF from the resulting pixels. The sensitive pixels must be overwritten, and the original image must not be retained elsewhere in the output.&lt;/p&gt;

&lt;p&gt;Do not assume a button labelled “flatten” guarantees this. Different tools use the word differently. Printing to PDF is not a reliable substitute either; the result depends on the application and print pipeline.&lt;/p&gt;

&lt;h2&gt;
  
  
  OCR helps find things, not decide for you
&lt;/h2&gt;

&lt;p&gt;Recognition can find names, dates and ID-like numbers and return their page coordinates. That makes marking a long scan much easier.&lt;/p&gt;

&lt;p&gt;It also makes mistakes. Faint copies, skewed pages and handwritten notes are easy to miss. A 5 becomes an S. Read the pages yourself and treat detected candidates as a first pass.&lt;/p&gt;

&lt;p&gt;Then apply the image redactions and remove any corresponding OCR text. Accurate detection does nothing if the export keeps the underlying content.&lt;/p&gt;

&lt;h2&gt;
  
  
  Inspect the final file
&lt;/h2&gt;

&lt;p&gt;Open the export in another reader. Try selecting and searching again. Check that you cannot remove or move the covering shapes to reveal information.&lt;/p&gt;

&lt;p&gt;For sensitive work, inspect extracted images and text too. A clean-looking page can coexist with an unredacted thumbnail, attachment or older revision.&lt;/p&gt;

&lt;p&gt;Export to a fresh file, inspect document properties, and make sure the page is still readable. Some image exports reduce resolution enough to make the remaining text unpleasant to use.&lt;/p&gt;

&lt;p&gt;I build &lt;a href="https://hddn.app" rel="noopener noreferrer"&gt;hddn&lt;/a&gt;. OCR runs in the browser, candidates need your approval, and its flattened scan export burns confirmed boxes into the page bitmap. It does not pretend OCR pages are ordinary editable text.&lt;/p&gt;

&lt;p&gt;A scan that does not respond to copy and paste is not automatically safe. Find out what is inside it before drawing the first box.&lt;/p&gt;

&lt;p&gt;Originally published in &lt;a href="https://hddn.app/guides/redact-a-scanned-pdf/" rel="noopener noreferrer"&gt;hddn’s guides&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
    </item>
    <item>
      <title>How to remove text from a PDF permanently</title>
      <dc:creator>Linas Jonas</dc:creator>
      <pubDate>Sat, 03 Oct 2026 22:20:22 +0000</pubDate>
      <link>https://dev.to/zilijonas/how-to-remove-text-from-a-pdf-permanently-9i1</link>
      <guid>https://dev.to/zilijonas/how-to-remove-text-from-a-pdf-permanently-9i1</guid>
      <description>&lt;p&gt;Fixing a mistyped VAT number and removing a salary from a contract sound like the same task: delete some text from a PDF.&lt;/p&gt;

&lt;p&gt;They are different jobs. One needs a correct-looking page. The other needs the old information to be unrecoverable from the file you hand over.&lt;/p&gt;

&lt;h2&gt;
  
  
  Editing is not redaction
&lt;/h2&gt;

&lt;p&gt;Replacing a word is an editing operation. PDF text is positioned on a page, often glyph by glyph, so changing it can leave gaps or cause font problems.&lt;/p&gt;

&lt;p&gt;Embedded fonts may contain only the characters used in the original document. Your replacement might need a character that is missing. Check the exported page at full zoom, especially after changing more than a word or two.&lt;/p&gt;

&lt;p&gt;Sensitive text has a stricter requirement. A white rectangle, black box or replacement label can change the appearance while leaving the original content underneath.&lt;/p&gt;

&lt;p&gt;Use a redaction feature when the old text has to go. A warning that an operation cannot be undone is useful, but it is not proof of correct output. The exported file still needs checking.&lt;/p&gt;

&lt;h2&gt;
  
  
  Permanent means absent from the output
&lt;/h2&gt;

&lt;p&gt;PDFs can contain earlier revisions when changes are saved incrementally. A program may append an updated page instead of rewriting the old bytes.&lt;/p&gt;

&lt;p&gt;That is one reason a visual check is too weak. You need an output workflow that removes the sensitive content rather than simply hiding it or adding another version.&lt;/p&gt;

&lt;p&gt;If you are both editing and redacting the same area, check what happens where those operations overlap. A replacement typed over a redaction region must not accidentally survive the redaction you intended.&lt;/p&gt;

&lt;h2&gt;
  
  
  The page is only one place to look
&lt;/h2&gt;

&lt;p&gt;Metadata can name the author or client. Comments and annotations may quote the passage you removed. Attachments travel inside the PDF. A cropped image can retain pixels outside the visible crop.&lt;/p&gt;

&lt;p&gt;Inspect those separately. Exporting under a fresh filename is a good way to preserve your source, but it does not automatically sanitise everything in the new file.&lt;/p&gt;

&lt;h2&gt;
  
  
  Check what someone else receives
&lt;/h2&gt;

&lt;p&gt;Open the export in a different reader. Select across the removed area, copy and paste into a plain text editor. Search for distinctive text that should no longer exist.&lt;/p&gt;

&lt;p&gt;For a sensitive file, also extract the text with a tool such as &lt;code&gt;pdftotext&lt;/code&gt; and review that output. Empty search results are not a complete forensic guarantee, especially when information lives in images or attachments.&lt;/p&gt;

&lt;p&gt;Scanned pages need image redaction as well as removal of any OCR text. Changing a text layer does not erase a photographed name.&lt;/p&gt;

&lt;p&gt;I build &lt;a href="https://hddn.app" rel="noopener noreferrer"&gt;hddn&lt;/a&gt;, which supports native-text edits and confirmed redactions in the browser. Text editing has limits: scanned pages, rotated lines and right-to-left text are refused rather than silently altered.&lt;/p&gt;

&lt;p&gt;The editor shows your intention. The exported file is the evidence. Check the second one.&lt;/p&gt;

&lt;p&gt;Originally published in &lt;a href="https://hddn.app/guides/remove-text-from-pdf-permanently/" rel="noopener noreferrer"&gt;hddn’s guides&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
    </item>
    <item>
      <title>How to redact a PDF without uploading it</title>
      <dc:creator>Linas Jonas</dc:creator>
      <pubDate>Sat, 03 Oct 2026 22:19:59 +0000</pubDate>
      <link>https://dev.to/zilijonas/how-to-redact-a-pdf-without-uploading-it-2pf8</link>
      <guid>https://dev.to/zilijonas/how-to-redact-a-pdf-without-uploading-it-2pf8</guid>
      <description>&lt;p&gt;Some files should not go onto a stranger’s server just so you can remove four names. A client file. An HR investigation. A document covered by a confidentiality agreement.&lt;/p&gt;

&lt;p&gt;Dragging a PDF onto a web page feels like a small action. If that tool processes files on a server, it is a transfer of the whole document, before any redaction happens.&lt;/p&gt;

&lt;h2&gt;
  
  
  Deletion promises are still promises
&lt;/h2&gt;

&lt;p&gt;An uploaded file may pass through memory, temporary storage and backups. The exact path depends on the service. A vendor saying “deleted after one hour” may be telling the truth, but you cannot confirm its internal cleanup jobs from your browser.&lt;/p&gt;

&lt;p&gt;That does not make every server-side tool unsafe. It means choosing one involves trusting the operator and checking whether that processing is appropriate for your document.&lt;/p&gt;

&lt;h2&gt;
  
  
  A web tool can work locally
&lt;/h2&gt;

&lt;p&gt;There are two very different kinds of PDF website. One uploads your file, processes it elsewhere and returns a download. The other runs PDF code inside your browser and reads the file on your device.&lt;/p&gt;

&lt;p&gt;The interface can look identical. “Private” and “secure” do not tell you which model you are using.&lt;/p&gt;

&lt;p&gt;Desktop software is another local option. It may be the right answer if you already have a suitable application installed. You still need its actual redaction feature, not a drawing tool.&lt;/p&gt;

&lt;h2&gt;
  
  
  Test with a harmless file
&lt;/h2&gt;

&lt;p&gt;Make a test PDF with no private information. Use that for the checks, not a patient record or client contract.&lt;/p&gt;

&lt;p&gt;Open the browser’s developer tools and select Network. Enable Preserve log. Load the test PDF and complete the workflow, including export.&lt;/p&gt;

&lt;p&gt;Look at outgoing requests and their payloads. A POST or PUT carrying the file is a clear upload signal. Do not rely on matching file size alone: uploads can be split, compressed or encoded. A large incoming response is not evidence of an outgoing document transfer.&lt;/p&gt;

&lt;p&gt;Then test without a network connection. Let the application and any required assets load, disconnect, open the harmless file, redact it and export.&lt;/p&gt;

&lt;p&gt;If the complete job works while disconnected, that processing happened locally. It does not prove the application will never send anything later, which is why the network check matters too.&lt;/p&gt;

&lt;h2&gt;
  
  
  Local does not mean no downloads
&lt;/h2&gt;

&lt;p&gt;The page itself has to load. OCR tools may fetch recognition models on first use and cache them afterwards. Those downloads are different from sending your PDF to a server.&lt;/p&gt;

&lt;p&gt;A failed first offline attempt may mean an asset was not downloaded yet. It is not, by itself, proof of server-side processing.&lt;/p&gt;

&lt;p&gt;I build &lt;a href="https://hddn.app" rel="noopener noreferrer"&gt;hddn&lt;/a&gt;. Its document processing runs in the browser; OCR and detection assets may download when first needed. Detection produces candidates for you to review, not a promise that every sensitive detail was found.&lt;/p&gt;

&lt;p&gt;Run the checks on the version you are using. Tools change, and the interface does not have to change with them.&lt;/p&gt;

&lt;p&gt;Originally published in &lt;a href="https://hddn.app/guides/redact-pdf-without-uploading/" rel="noopener noreferrer"&gt;hddn’s guides&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
    </item>
    <item>
      <title>How to redact a PDF and know it worked</title>
      <dc:creator>Linas Jonas</dc:creator>
      <pubDate>Sat, 03 Oct 2026 22:19:11 +0000</pubDate>
      <link>https://dev.to/zilijonas/how-to-redact-a-pdf-and-know-it-worked-246</link>
      <guid>https://dev.to/zilijonas/how-to-redact-a-pdf-and-know-it-worked-246</guid>
      <description>&lt;p&gt;The file is open. Someone needs it this afternoon. You have marked the names and account numbers, and the page looks clean.&lt;/p&gt;

&lt;p&gt;That is not the end of the job. The file you export is what the recipient gets, and it may not match what your editor shows.&lt;/p&gt;

&lt;h2&gt;
  
  
  Start with the right file
&lt;/h2&gt;

&lt;p&gt;Use the original PDF when you can. Native text lets detection tools find patterns and lets you select exactly what needs removing. A printed-and-scanned copy turns the pages into pictures. That needs a different treatment.&lt;/p&gt;

&lt;p&gt;Try selecting a line. If nothing highlights, look for an image-redaction workflow that changes the pixels and rebuilds the page. A rectangle stacked above the original scan leaves that image intact. Some scans also have an invisible OCR text layer, so check each page rather than assuming the whole document is one format.&lt;/p&gt;

&lt;h2&gt;
  
  
  Decide what the recipient should see
&lt;/h2&gt;

&lt;p&gt;Before opening the redaction tool, write down who will receive the document and what they already know.&lt;/p&gt;

&lt;p&gt;Names are the obvious part. Check initials, signatures, contact details, IDs, account numbers, dates of birth, home addresses and salary figures too. Read the prose. “The contractor who left halfway through the March audit” might identify one person without naming them.&lt;/p&gt;

&lt;p&gt;Automatic detection helps with the first pass. It does not make the decision for you. Review the suggestions, reject false positives and look for what the detector missed.&lt;/p&gt;

&lt;h2&gt;
  
  
  Use redaction, then apply it
&lt;/h2&gt;

&lt;p&gt;Drawing a rectangle is a drawing operation. It can hide text on screen while leaving the original string in the PDF.&lt;/p&gt;

&lt;p&gt;Use the feature called Redact or Mark for Redaction. Marking alone may still be an annotation: many applications require a separate Apply step. Follow the tool’s documented workflow, then export a fresh file without overwriting your original.&lt;/p&gt;

&lt;p&gt;A new filename alone does not prove that old content or saved revisions are gone. Use a tool that removes the content and rewrites the output, then inspect it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Look beyond the page
&lt;/h2&gt;

&lt;p&gt;Document properties can contain an author, client name or title you did not mean to disclose. Comments, form fields and attachments can hold separate copies of the information. Cropping an image may hide its edges without deleting them.&lt;/p&gt;

&lt;p&gt;Remove sensitive material from those places as well.&lt;/p&gt;

&lt;h2&gt;
  
  
  Test the export
&lt;/h2&gt;

&lt;p&gt;Close the editor and open the exported PDF in another reader. Select across a redacted area, copy it and paste into a plain text editor. Search for a distinctive name or number you removed.&lt;/p&gt;

&lt;p&gt;If it comes back, stop. The export is not clean.&lt;/p&gt;

&lt;p&gt;Passing these quick checks is useful, but it is not proof that every hidden object is safe. For sensitive documents, inspect metadata, attachments and extracted text as well. Scans need their image pixels and OCR layer checked.&lt;/p&gt;

&lt;p&gt;I build &lt;a href="https://hddn.app" rel="noopener noreferrer"&gt;hddn&lt;/a&gt;, which processes PDFs in the browser and lets you review detected candidates before applying redactions. Whatever tool you choose, test the exported file. Your careful markup is not what leaves your computer.&lt;/p&gt;

&lt;p&gt;Originally published in &lt;a href="https://hddn.app/guides/how-to-redact-a-pdf/" rel="noopener noreferrer"&gt;hddn’s PDF redaction guides&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>privacy</category>
    </item>
    <item>
      <title>Your black rectangle is not redacting that PDF</title>
      <dc:creator>Linas Jonas</dc:creator>
      <pubDate>Wed, 16 Sep 2026 17:35:30 +0000</pubDate>
      <link>https://dev.to/zilijonas/your-black-rectangle-is-not-redacting-that-pdf-1knb</link>
      <guid>https://dev.to/zilijonas/your-black-rectangle-is-not-redacting-that-pdf-1knb</guid>
      <description>&lt;p&gt;Someone asks you to send a contract with the salary taken out. You open the PDF, grab the rectangle tool, drop a black box over the number, save, send. It looks right. The number is gone.&lt;/p&gt;

&lt;p&gt;It isn't. It's underneath.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the file actually contains
&lt;/h2&gt;

&lt;p&gt;A PDF is not a picture of a page. It's a list of instructions: draw this glyph at this coordinate in this font, then this one, then this one. The text you see is a real string sitting in the file's content stream, with the positions that let a reader lay it back out.&lt;/p&gt;

&lt;p&gt;When you draw a rectangle, you add one more instruction to that list. Paint a filled shape at these coordinates. That instruction runs after the text, so the shape lands on top and your eye stops there.&lt;/p&gt;

&lt;p&gt;The text instruction is still in the file. Untouched. Select the area and copy, and your clipboard gets the words, because selection reads the content stream, not the pixels. Run any extraction library over it and the same thing comes out. So does search. So does a screen reader.&lt;/p&gt;

&lt;p&gt;This is not a bug in whatever tool you used. Drawing a box is a drawing operation, and it did exactly what a drawing operation does.&lt;/p&gt;

&lt;h2&gt;
  
  
  It has gone wrong at scale
&lt;/h2&gt;

&lt;p&gt;In 2005 the US Army published its report on the shooting of Nicola Calipari in Iraq as a PDF with sections blacked out. Copy the page into a word processor and the blacked-out sections came back, including names and troop movements. The Pentagon pulled the file; by then it was mirrored everywhere.&lt;/p&gt;

&lt;p&gt;In 2009 the TSA posted its screening procedures manual with the sensitive sections covered the same way. Researchers had the full text out within hours.&lt;/p&gt;

&lt;p&gt;In 2019 Paul Manafort's lawyers filed a court document with black bars over several passages. Reporters copy-pasted them and found, among other things, that he had shared campaign polling data with Konstantin Kilimnik.&lt;/p&gt;

&lt;p&gt;Three organisations with lawyers, review processes, and a strong interest in getting it right. The failure mode does not care how careful you are, because it doesn't look like a failure until someone else finds it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Real redaction removes the content
&lt;/h2&gt;

&lt;p&gt;For the text to be gone, the instruction that draws it has to be deleted from the content stream and the file rewritten without it. Proper redaction tools do this. They mark a region, work out which glyphs fall inside it, strip those from the stream, then paint the black box as a visual marker of what was taken out.&lt;/p&gt;

&lt;p&gt;Two different operations that produce the same screenshot. Only one of them changes what the file contains.&lt;/p&gt;

&lt;p&gt;The same applies to everything else riding along in the document. Metadata with the author's name and the original filename. Previous versions kept in an incremental-save history. Comments and annotations. Attached files. A cropped image that still holds the full picture outside the crop box. Any of these can carry the thing you meant to remove.&lt;/p&gt;

&lt;h2&gt;
  
  
  Checking a file you already sent
&lt;/h2&gt;

&lt;p&gt;You don't need a specialist tool for the basic test.&lt;/p&gt;

&lt;p&gt;Open the PDF in any reader. Select across the area you redacted, copy, paste into a plain text editor. If your text appears, the file is not redacted. Then press Ctrl+F and search for a word you removed. A hit inside a black box means the same thing.&lt;/p&gt;

&lt;p&gt;That catches the common case in about ten seconds. It won't catch metadata, annotations, or content hiding outside the visible page area, so for anything sensitive, treat the copy-paste test as the floor rather than the ceiling.&lt;/p&gt;

&lt;h2&gt;
  
  
  The rest of it
&lt;/h2&gt;

&lt;p&gt;The full guide covers how to fix it at source: which tool operation actually&lt;br&gt;
removes content, what else in the file carries the thing you deleted, and why&lt;br&gt;
you have to verify the exported bytes rather than the document you were&lt;br&gt;
editing.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://hddn.app/guides/black-box-is-not-redaction/" rel="noopener noreferrer"&gt;Read the rest on hddn.app&lt;/a&gt;&lt;/p&gt;

</description>
      <category>pdf</category>
      <category>privacy</category>
      <category>security</category>
      <category>webdev</category>
    </item>
  </channel>
</rss>
