DEV Community

Nitiksh
Nitiksh

Posted on

You uploaded your passport to a website last week. I did too.

Think about the last time you used a free PDF converter. For most of us it was within the last week, and it took about ten seconds. Bank statement, ID scan, a signed contract. Drag, drop, download, done.

In those ten seconds, your file left your computer. That's the part nobody thinks about. Online converters work by uploading your document to someone else's server and processing it there. Your passport scan now sits on a machine you don't control, run by people you can't name, possibly in a country you couldn't point to on a map.

I did this for years without thinking. Then I started reading about what actually happens to those files.

Three ways it goes wrong

They're careless. In July 2024, Cybernews found the cloud storage of two converter services, PDF Pro and Help PDF, sitting wide open. 89,062 files. Passports, IDs, certificates, contracts. Nobody hacked anything; the door was just open. Documents like that are enough to take out a loan or rent an apartment in your name.

They're the trap. In March 2025, the FBI's Denver office warned about scam converter sites. They look exactly like the real thing (one cloned PDF Candy down to the design and URL), return your file with hidden malware inside, and quietly scan everything you upload for IDs, banking details, passwords, and crypto seed phrases.

They're "fine," and you still can't verify it. Plenty of sites promise to delete your files after a few hours. Maybe they do. But you can't audit their servers, you don't know where they're hosted, and you have no idea who has access. For health or finance documents, "trust us" isn't good enough.

The leak nobody mentions: metadata

Here's the one that surprised me. Photos and PDFs carry hidden baggage: usernames, software details, device IDs, sometimes GPS coordinates. An arXiv study found researchers leaking exactly this kind of data, including GPS pointing at home addresses. You upload a photo to strip its background and hand over your location with it.

What the experts actually say

Kaspersky's advice on this is refreshingly blunt: no online converter can guarantee confidentiality, so don't convert sensitive documents online. Notice the advice isn't "find a better converter site." It's "stop uploading."

So I stopped uploading

I built my file toolkit to run entirely on my own computer. The engines are the boring, reliable open-source ones: FFmpeg for video and audio, ImageMagick for images, qpdf and Poppler for PDFs, headless LibreOffice for documents. No server, no account, no upload. The file never leaves the machine.

It does the jobs I used to upload for: Word, Excel and PowerPoint to PDF. Merging PDFs. Pictures to PDF. Adding or removing PDF passwords. Stripping GPS and EXIF data from images. Stripping author info from PDFs.

Local isn't magic (honest caveats)

Running offline doesn't make you invincible. If your own computer is compromised, local tools don't save you. Download software only from official sources. Keep the underlying engines updated. And PDF-to-Word conversion through LibreOffice can mangle complex layouts, so check the output before you send it anywhere important.

The point was never that offline is perfect. It's that it removes an entire category of risk: the stranger's server. That's a trade I'll take every time.

It's called KinoFlux Editor. Free, for Windows and macOS.

Download: https://ntxm.org/products/kinoflux/videoeditor/
Also on the Microsoft Store: https://apps.microsoft.com/detail/9nxkr2gv1wm7?hl=en-US&gl=EG

Top comments (0)