For some reason I just never trust the PDF tool (or human error on my end) actually redacting the info, even if I were to do a print to PDF.
For some reason I just never trust the PDF tool (or human error on my end) actually redacting the info, even if I were to do a print to PDF.
I would absolutely not trust pdf not to leak metadata. Although now you risk metadata leak from the printer or scanner, which may or may not affect your threat model.
if you have the source document, redacting from the source (by actually removing and replacing with an appropriate placeholder, not obscuring, the content) and regenerate the static (e.g., PDF) version.
If you are working from print, I think scan and redact by digital replacement (not overlay or otherwise obscure) would be sufficient. Redact->print->scan probably helps somewhat (especially if the scan is low quality) if you are using a bad redaction method to start with, but why do that?
Of course, the artifacts introduced by printing and scanning (especially with contrast turned way up) gives it an air of legitimacy, although these can also be simulated.
Usually I'm in full control of the software myself so I just output X instead of the secret data.
This degrades quality and wastes paper and toner. There are software tools to convert PDF to raster graphics.