← The Signal Report Work with me

Report 048 · Luxury Home Security

Can someone buy your home address?

Estate security is sold as a perimeter: cameras, gates, sensors, a response plan. All of it starts working at the property line. But target selection happens long before anyone reaches the property line, and it runs on data. A Duke research team went and bought that data to find out what it costs. Then Consumer Reports tested whether you can get it taken back down.

In targeting, the hard part is almost never the last hundred feet. It's deciding which hundred feet. I spent my Army career on the side of that problem where you try to understand how an adversary picks, because once the pick is made, everything downstream is just execution.

I've written here about how crews physically case a wealthy home, with cameras in the landscaping and jammers for the night of. That's the surveillance phase. This report is about the phase before it, the one where a target gets chosen off a list, and about the only two studies I know of that measured it instead of speculating about it.

What it costs to buy a household

In November 2023 a team at Duke University's Sanford School of Public Policy published a study that did the obvious thing nobody does: rather than describe the data-broker market, they went shopping in it. The work was sponsored by the United States Military Academy, and the population they bought data about was U.S. servicemembers and veterans. I'm one of them, which is part of why I read it closely.

They scraped hundreds of broker sites, then contacted brokers from a U.S. domain and, separately, from a .asia domain with a Singaporean IP address, and made purchases both ways.

Here is one of the datasets they bought, described in their own inventory. From a U.S. domain, one broker sold them records on 4,951 active-duty personnel, geofenced to Washington, DC, Maryland and Virginia. Each record included, and I'm quoting the field list, "their name, home address, email address, political affiliation, gender, age, income, net worth, credit rating, occupation, presence of children in the home (yes/no), marital status, homeowner/renter status, home value, and religion."

The price was 21.3 cents per person.

Read that field list again as a security problem rather than a privacy one. Home address. Home value. Homeowner or renter. Net worth. Whether there are children in the home. Marital status. That is not a marketing profile that happens to be sensitive. That is, functionally, a target package: where the house is, roughly what's in it, and who is likely to be inside.

Across the study, purchased records ran between $0.12 and $0.32 each. One broker's published volume pricing dropped to a penny per person at orders above 1.5 million. In total the team bought 34,951 identified contact records through the U.S. domain for $6,931.69, and another 15,048 through the .asia domain for $3,362.

"Anyone with a few hundred dollars can obtain the same type of data that we did and use it for any purpose, good or bad."

The controls, such as they are

The part that should concern anyone who designs security systems is not the price. It's what stood between the researchers and the data.

The study reports "a lack of robust controls" around identity verification, background checks, or any attempt to establish intended use. Their cleanest example: one broker said it would have to verify their identity before selling data on the military unless they paid by wire instead of credit card. They paid by wire. The broker "provided us with the data we requested on members of the U.S. military without asking about or verifying our identity."

The foreign-domain results were worse. Buying as a .asia domain from a Singaporean IP, they obtained records on 5,048 servicemembers and veterans geofenced to Fort Bragg, Fort AP Hill, and Quantico, at 25 cents each, with name, home address, and a long demographic tail. The report's conclusion on that transaction is one flat sentence: "We did not observe any controls that differentiated the location of the purchasing entity."

Some brokers did behave better, and the study says so. Two refused to sell because the researchers had no website and were not a verified company. One location-data broker declined to sell geolocation around sensitive sites including military installations, though it offered the rest of the country. Two others demanded NDAs, and the team walked away rather than sign.

One precision that matters, because secondary coverage of this study routinely blurs it: the team did not buy location or movement data. The report states that location data "is also available, though the team did not purchase it." Granular geofencing down to specific buildings and addresses, including foot-traffic tracking, was offered to them by brokers they chose not to buy from. What they proved they could buy cheaply and with almost no friction was the identified household profile, not a live track of where someone goes.

So take it down

The natural response is to remove yourself. An entire industry exists to do that for you, priced like a security service, and in 2024 Consumer Reports ran the experiment on whether it works.

Their study, "Data Defense: Evaluating People-Search Site Removal Services," published August 8, 2024 and led by Yael Grauer, recruited 32 participants split into four groups: New York homeowners, New York renters, California homeowners, California renters. Seven removal services were tested against 13 people-search sites, with one participant in each group opted out manually as a control. They ran it from May to September 2023, checking each site at one week, one month, and four months.

The headline result: of 332 instances of participant information found on those sites, "only 117, or 35%, were removed within four months." And "without exception," information about every single participant still appeared on some of the 13 sites at every checkpoint.

The per-service spread is wide enough to matter. At four months: Confidently 4 percent, ReputationDefender 6 percent, DeleteMe 27 percent, Kanary 34 percent, IDX 40 percent, EasyOptOuts 65 percent, Optery 68 percent. Annual prices ran from $19.99 to $249, and the cheapest service was among the two best, so the market does not price on effectiveness.

The control group is the finding, though. Manual opt-outs, at a cost of $0, removed 70 percent, and did it inside the first week, against a first-week range of 0 to 58.7 percent for the paid services. Doing it yourself beat everything anyone would sell you.

Two more results worth carrying. The study found "no significant difference in the success rate of removing data between renters and homeowners" (about 40 percent removed for New York homeowners against 46 percent for renters; 34 against 38 percent in California), so a bigger house does not buy better erasure. And some removal services "advertised on or even partnered with people-search sites," which Consumer Reports called "an implicit endorsement of the inherently problematic people-search ecosystem."

What these studies don't show

Both papers are narrow, and using them honestly means saying where they stop.

The Duke work is about servicemembers and veterans, because that was the question the Military Academy funded. It does not establish that the same brokers maintain curated lists of wealthy households, and I'm not going to claim it does. What it establishes is that the commercial machinery sells identified records indexed by home value, homeowner status, net worth, and presence of children, to buyers it makes little effort to identify. Anyone in those databases is reachable by those selectors. It's also a 2023 study, and the regulatory picture around bulk data sales has been moving since.

The Consumer Reports study is smaller than it looks: four participants per service, in two states. Its own limitations section is candid that participants never touched their dashboards, never answered follow-up questions, and never supplied relatives' names or ID documents that might have improved results. And one thing it explicitly did not test is reappearance. In their words, they "did not test for the reappearance of profiles after finding that the user had been deleted," assuming a deleted profile stayed deleted. So the widely repeated claim that removed data comes roaring back at some measured rate is not a finding of this study, and I'm not going to launder it into one.

The signal

Put the two together and the practical conclusion is uncomfortable but clean: you cannot subtract yourself from the data market, so stop designing as though you might.

Do the manual opt-outs. They're free, they were the best performer measured, and they raise the cost of casual research. But treat them as friction, not as a perimeter, because 70 percent is not zero and the databases refill from public records regardless.

Then design the actual security for the world you're in, where a motivated adversary already knows the address, roughly what the home is worth, and whether there are children in it. That posture is the one I keep arriving at from different directions in this publication: a system that is integrated rather than merely extensive, and one whose real job is verification, so that a response actually comes. Neither of those depends on the adversary being ignorant. That's the point.

The gate assumes nobody knows the address. Twelve cents says otherwise. Build for the version where they do.

Designing security around what an adversary can already know, rather than around what you hope they can't find, is the work I do on this beat, and I'll be exact about my role: I help design the AI security systems for a veteran-owned (SDVOSB) home-security company run by fellow veterans. I don't own that company and earn nothing from this link; I flag it because it's a field I build in, not just write about. Full policy here.

Sources

  1. Justin Sherman, Hayley Barton, Aden Klein, Brady Kruse, Anushka Srinivasan, "Data Brokers and the Sale of Data on U.S. Military Personnel: Risks to Privacy, Safety, and National Security," Duke University Sanford School of Public Policy, November 2023. (PRIMARY. Opened and read in full; the PDF was downloaded and text-extracted locally. Research sponsored by the United States Military Academy under Cooperative Agreement W911NF-22-2-0099. Source for: the methodology of scraping broker sites and purchasing via a U.S. domain and a .asia domain with a Singaporean IP; the 4,951-record dataset and its verbatim field list at $0.213 per person; the $0.12-$0.32 per-record range; the volume table reaching $0.01 per individual above 1.5 million; the totals of 34,951 records for $6,931.69 and 15,048 for $3,362; the wire-transfer identity-verification failure; the Fort Bragg / Fort AP Hill / Quantico dataset at $0.25 per record and "We did not observe any controls that differentiated the location of the purchasing entity"; the brokers that did refuse or required NDAs; and the statement that location data "is also available, though the team did not purchase it." The blockquote is verbatim from this report.)
  2. Yael Grauer, "Data Defense: Evaluating People-Search Site Removal Services," Consumer Reports, August 8, 2024. (PRIMARY. Full report opened and text-extracted locally. Source for: 32 participants in four groups, seven removal services, 13 people-search sites, testing from May to September 2023 with checks at one week, one month and four months; "only 117, or 35%, were removed within four months" of 332 instances; the "without exception" finding; the full per-service table at four months and the $19.99-$249 price range; the manual opt-out control at 70 percent versus a 0 to 58.7 percent first-week range for paid services; "no significant difference in the success rate of removing data between renters and homeowners" with the state-by-state figures; the finding that some removal services advertised on or partnered with people-search sites and the "implicit endorsement" characterization; and the limitations section, including that the study "did not test for the reappearance of profiles.")
  3. Consumer Reports, "Consumer Reports evaluation of people-search site removal services finds that they are largely ineffective," August 8, 2024. (Opened. Used to confirm the publication date and the study's summary figures against the full report.)
Onur Oncer
Onur Oncer

U.S. Army combat veteran (Counter-IED / Electronic Warfare), peer-reviewed researcher in microwave spectroscopy, and founder & CEO of Shroombiosis. Consults on laboratory operations, AI, and supplement formulation.

← All reports