Help me figure out how I lost this bet to an engineer
blog.close.io
blog.close.io
- This isn't the actual photo but looks similar, except that she was alone. Justin was afraid of reposting the same photo after the results of handing over a photo last time :)
- There was no useful exif data in the image.
- We knew her high school and approximate age in Austin, but were unable to find any yearbooks / class rosters online. (Idea not pursued: try to acquire a yearbook offline).
- Facebook Graph Search and LinkedIn with the criteria we knew didn't help.
- Google Image search didn't help.
> "I'm sure there's a lot of information missing from this story"
Quite true.
Ultimately we had several methods going at once to try to figure it out.
The one that came back with results first relies on some information Justin still doesn't know we had (though he would still be impressed), but other approaches we also expected to work would be possible with only what's in the story, and haven't yet been mentioned here.
EDIT: shared more at https://news.ycombinator.com/item?id=6369751
At that point, if the bartender knows some of her backstory or friends or anything - maybe only has a first name - things get much simpler.
The "extra" information we got came later after we already started working on it, and came as surprise. It just happened to bring the result back sooner than the other approach.
If you don't mind me asking, would other approaches discussed here have brought the result nonetheless? or did they?
If Justin observed correctly, you guys were very impressed with yourselves. Had you retrieved the answer by methods of which you were confident, you would've still been impressed, but not greatly.(I'm making a lapse conjecture here, of course)
Since you were confident that you would be able to find her, prior to looking at the picture, according to the article, I don't think you were looking for any information in the picture other than for confirmation.
However, some extra information in the picture(since it was taken very recently) enabled you to look further, which returned a result. Perhaps a building, an address, or some sort of landmark-ish location which narrowed whereabouts of the picture vastly? If this were the case, then I can understand that you guys were very impressed, because well, it is.
EDIT: Just saw the 'solution'; very nice touch!
So it seems you weren't even confident when you got your confirmation, a.k.a., it was an informed guess but could have just as easily been a girl that looked alike at an event at the time she was supposedly at an event?
Tricky ol' Phil.
It is also possible that during the few days' correspondence one of the engineer guys had some other piece of info that we are not familiar with. Seeing how the engineers already knew her high school, I'm sure Justin talked about her with co-workers.
I think the key information that's missing here is what the engineers knew but Justin didn't know that they knew.(Sounds like a quote out of a Friends episode, mmm)
* Everyone was at the original bar at the same time - someone else had photos from the night that had her and other people in them, and those people (her friends) could be found online.
* The bar had some kind of "sign-up for x" list, or some kind of contest, or some kind of photos of the night, which were helpful.
* You searched twitter/facebook/whatever for a girl posting about a boy she just met at bar X, blah blah
* We know she was going to some kind of event - you guys figured out what that was, and found a guest list or something.
* You guys did a some wi-fi sniffing and read a few emails. He did say he emailed you the photo, so you know which account to listen for.
Are any of those close?
OK then, there is something identifying about this girl, which the second photo gave you
* Tattoo
* Glasses
* Hair
* Amputee
* Scar/burn, etc.
* particular purse/hat/watch/accessory
* etc.
A credit card slip with her name on it perhaps?
I'm not sure what the rules are concerning tagging suggestions, but I have noticed that it suggests that I tag people I know in other people's photos so you KNOW they recognize everybody in every photo - the trick is meeting the right conditions for it to allow it to share that recognition match with you based on her privacy settings I think...
Or maybe you knew that she wanted him to meet her at an event and you found a roster for that event- or ie if it was a real estate convention you would have a pretty good idea that she was a realtor and could look at websites for realtors in Austin.
Or maybe you checked his recent facebook friends, looked at his recent twitter followers, and everyone who liked/commented on his recent photos/posts on Instagram and whatever other social networks he's on- as well as the photos/posts he liked/commented on.
I think you took a (relatively) low-tech approach to this.
- Create an ad on Facebook with her picture.
- Target people that went to her high school within 4 years of the range of years we thought she graduated within. Was only a few hundred people so the cost of running the ad would likely only be a few bucks.
- The ad copy / landing page just needed to be convincing that we weren't stalking her. We went with the "help us win a bet" approach but the "lost camera" approach would have been good also.
Ultimately we got the answer sooner from another approach after we found out that we had another picture of the girl that Justin didn't know we had. So we canceled the ad, but I think this would have worked if given enough time.
No, we weren't. And she knew about it, was amused by it herself. No bad intentions.
stalk. slang defination: hound, spy, solicitation for a certain kind of information
But you knew that.
her opinion and agreement apparently doesn't matter, the internet knows better.
Find the event Thursday night at 8:00pm in Austin and start tracking down from there.
Her dress, which was very unique had never been worn by her, because she bought it the day before
...should narrow down the events that this person wanted to attend. Here are the events that happened that day:
http://www.austinchronicle.com/calendar/2013-09-05/
...which, to me, only had one really unique event that evening:
http://www.facebook.com/events/1405498132998020
...which, possibly, would include a picture of that person either in the same outfit or include a profile picture of that person commenting or liking the event.
But this is just a guess...
The second photo you realized you had showed the subject holding the device used to take the picture sent to your colleague. You investigated that particular device and found a way to uniquely identify it's pictures based off some characteristic of it's photos, not necessarily EXIF, then scoured the Internet for photos with the same unique characteristic until you found one that revealed more information about the subject?
At this point he could not see my screen (he was standing directly in
front of me), but offered me a simple bet – He said if I sent him the
picture of the girl he could find out her name.
Reminds me of: Sky Masterson: One of these days in your travels, a guy is going to show you a
brand-new deck of cards on which the seal is not yet broken. Then this guy
is going to offer to bet you that he can make the jack of spades jump out of
this brand-new deck of cards and squirt cider in your ear. But, son, do not
accept this bet, because as sure as you stand there, you're going to wind
up with an ear full of cider.
http://www.youtube.com/watch?v=d8Wvgs9q3jsSimplest explanation: He knew before he made the bet.
Of course one of the first things I did was ask another friend who I thought met her. But no, ultimately the answer did come from the internet, not from anyone I knew.
Advice to woman: Run.
Advice to startups: Don't let your sales and engineering teams be giant douche canoes and if they are certainly don't publicly brag about it.
- This was just a fun bet between friends. Justin really didn't think it could be done and I wanted to show him how a little information goes a long way online.
- Justin treated this girl well and she even knew about this bet.
- "Look up online" != Stalking
- None of the discovered information has been posted publicly online. This isn't even her photo.
No, from what you guys have said you didn't tell her about it until after the fact. That's super douchey and retroactive permission doesn't change anything. If you grabbed a girl's butt and she laughed it off as "fun between friends," it doesn't make it ok. You need to ask permission first.
If you think cyberstalking is only bad if you add doxing to it, then you don't understand cyberstalking.
I've just re-read the definitions for "stalking", "cyberstalking", and "harassment" and I can assure you none of what we did qualifies given the actual scenario of how things really occurred.
So which one of you is telling the truth?
Keep in mind that the information that they were looking for could just as easily have been volunteered by the sales guy in other circumstances, so it's not like this information was tightly under her control in the first place. "What's her name? Where does she live?" - these are pretty common questions when discussing romantic liaisons with friends and colleagues.
You are totally lying. I just saw your other comment on this where you admitted you posted her pic in a Facebook ad. I will quote:
>This is the closest I've heard to one of the ideas that we expected to work, so I'll share.
>- Create an ad on Facebook with her picture.
>- Target people that went to her high school within 4 years of the range of years we thought she graduated within. Was only a few hundred people so the cost of running the ad would likely only be a few bucks.
>- The ad copy / landing page just needed to be convincing that we weren't stalking her. We went with the "help us win a bet" approach but the "lost camera" approach would have been good also.
>Ultimately we got the answer sooner from another approach after we found out that we had another picture of the girl that Justin didn't know we had. So we canceled the ad, but I think this would have worked if given enough time.
https://news.ycombinator.com/item?id=6369859
I especially like the part about making the ad copy "convincing that we weren't stalking her."
"stalk [verb]: to follow, watch, and bother (someone) constantly in a way that is frightening, dangerous, etc."
-- merriam-webster
This very much was not the case.
If it makes you feel better, the ad was also taken down very quickly.
This would be much more meaningful if you hadn't already stated that you took it down because you already got the information you wanted.
Yeah, no one would ever possibly be creeped out by that.
You think it's ok because you have good intentions. Guess what? So does every other creep. It's not up to you to decide whether your actions are frightening. You took a bet that you could stalk (message all her classmates!) and dox (post her picture online!) a girl without her permission and without even the slightest self-awareness that it's invasive behavior. And then you tried to lie about key details.
You, sir, are exactly the kind of male-privileged "brogrammer" that is giving this industry a bad name these days.
Also the ad didn't say that she was flirting with anybody and it was designed with an attempt to not make her look bad in any way.
Finally, she is aware of the whole deal and has been a good sport, and is not upset.
You said you didn't post any of her info online.. you ran a friggin Facebook ad campaign with her picture on it (which you obtained not from her)! Now you've just edited your comment to say you didn't post any other info about her that you obtained.
You did all this without her permission, according to your colleague. Now you're trying to weasel out of that too with ambiguous phrases like "she is aware". Yeah, after you told her what you already did.
Did it not even occur to you that it could be potentially embarrassing or invasive? What if she wasn't cool with it? What if she's just playing cool because you forced her hand? It's wrong of you to assume it's ok to cyberstalk someone for "fun" because your intentions are good -- your intentions being having a laugh with your bros.
The other point here, even if you think bro'ing out like this is perfectly acceptable workplace behavior / way to treat women, is that it's just incredibly stupid for a startup to tarnish their brand this way. Just don't do it.
Why is “stalking” a woman bad in the first place? Because the stalker might get so obsessed that they get violent with or rape the woman. Or because the woman might feel like her privacy has been violated. Or the woman might feel nervous around the stalker, not knowing what they want.
None of these bad situations were going to result from this type of information-gathering. The engineer was not planning to hurt this woman or interfere with her in any way. The woman would not feel that her privacy has been violated, because they just want her name, and the woman probably wouldn’t mind if the bet-taker just told the engineer her name. And the woman knows what this “stalker” wants – to win a one-time bet. So she won’t be nervous about his intentions – winning a bet to find out a name is a harmless action that does not inspire worry.
As for posting her information online, yes, it seems like the engineer had an unintentional privacy leak in that they showed Facebook users from her high school her picture. (I don’t think he was purposefully lying about posting her info, I think he just didn’t consider the photo significant.) Showing the photo could be bad if the woman didn’t want anyone seeing that dress she bought, or didn’t want her alumni to be reminded of her. You could argue that showing the photo to those users was a mistake on the engineer’s part.
But you should keep in mind that the chances were pretty low that this woman’s picture leaked anything significant to her former high school classmates. It’s very likely that they didn’t care what dress she is wearing. Many of them saw her face already when she was actually in high school, and as for the ones who had not, seeing a normal photo of a random woman in a dress is unlikely to cause anything bad. There was a possibility, but it was very low.
You say no privacy violations "were going to result from this type of information-gathering". However you then concede that it resulted in a "privacy leak in that they showed Facebook users from her high school her picture," mentioning several reasons why the target may find this invasive. You frame it as "unintentional", but that is irrelevant; you've contradicted your claim.
I would certainly not argue that the critereon is intent to do physical harm, which is how you define "stalking". Boy, would an awful lot of stalking no longer be considered "stalking" under that definition. By your definition cyberstalking is ok if you only want to date them and/or joke with your bros about it, not rape someone.
Rather the issue is whether the actions of, say, posting your photo in a Facebook ad campaign -- and otherwise pursuing means of "information-gathering" so extraordinary that one needs to post to Hacker News to explain them -- might reasonably considered a willful invasion of a person's privacy. Certainly it could be, and these guys just didn't care, because they're just having a laugh, and she's probably cool with it, and if she's not, well screw her because girls should be cool with that sort of thing.
Why would this post be hosted on the close.io blog and not on a personal blog? It has nothing to do with close.io.
Why would he mention close.io so many times?
Why would he ask about the quality of the "close.io engineers" instead of just his coworker or friend?
Smells fishy to me.
Edit: The girl is Lennay Kekua!
But yeah, the post clearly emphasizes that they have smart engineers.
oh wait :p
That's only a couple hundred kids, each with a couple hundred friends.
If you still get nothing, start doing friend requests for the people that don't show their friends. I'll bet you'd get another 25-30 kids that way.
I don't see why you'd need facial recognition software to go thru 20,000 pictures.
3/4ths of them would be the wrong gender/age and be immediately disqualified.
But if you're a programmer, you can probably scrape and aggregate to speed things up - drop out the males, other high schools, only show pictures once, etc.
So you've found an attack vector where you can get a woman's name and address off the 'net with a picture and a small amount of information. Maybe it doesn't work all the time, but it worked at least once. What are you going to do with that attack vector? Are you going to make an iPhone app, so that others can snap pictures of random women and recreate your exploit automatically? Or are you going to come up with ways the attack vector can be shut down, things that either individuals (eg, the woman herself) or organizations (like Facebook or Google) can do to block the attack?
Huh? Nothing... this was a just a fun bet between two friends with no bad intentions. I didn't discover anything, as evidenced by the dozens of others in this discussion with similar ideas.
Coincidentally this is 9/11 day... It turns out that anyone of room temp or above IQ can easily do something fairly awful, but the fact it almost never happens provides some faith in humanity that basically no one (on a statistical basis) is actually awful.
So, here's a thought. Let's say the Engineer has access to the SMS logs (NSA-style) for Justin's phone. (Maybe his phone goes through their system. But even if not, maybe it's company-provided, so there's an admin interface provided by the telecom that lists this information.)
Justin probably doesn't regularly text people in Texas, since the team is based out of Palo Alto. So look through his logs for a number in a Texas area code (http://en.wikipedia.org/wiki/List_of_Texas_area_codes) that he's been texting more often than usual.
That gets you the girl's phone number; probably a cell phone. Now, you need to go from the cell phone number to a last name. Reverse Phone Lookup probably won't work for this, although it's certainly worth a first try. More likely candidates: looking through the users table at close.io for a matching phone number, or doing a google search for the phone number. Or, try calling in the middle of the night and seeing what the voicemail says. Any of these approaches might work.
Once you've got a last name, grab a copy of the white pages. Most public schools publish their district boundaries, so go grab a copy of that. Look through all entries that match the last name, and see how many of them fall within (or close to, in the case politics made the boundary change) the district boundary. You probably will get a handful (maybe three or four). If you only get one, bingo!
If you get more than one, I'd call the cell phone to see if I can get a first name somehow. Then, I'd go through the landlines in the White Pages and call them one at a time, "Hello, may I speak to X? Sorry, wrong number." until one matches.
I did have an idea that we could try to hack his Verizon account to look at his SMS log, figuring that Forgot Password questions might be easy or that we could intercept an email. But we didn't do this.
Note the convoluted written responses about not talking to anyone he knew and so forth which technically does not exclude the girl, herself, saying her own name.
The other alternative is she's somebody's buddy/family member so it would be trivial to know before hand that she's so and so's ex or sister or whatever and given that intel, figure it out.
I assume the author is not a Facebook friend with the girl. Otherwise it would have been too easy. But friends of friends is not the only privacy leak on Facebook. There is a very old feature (which is about to get deprecated) called Networks.
Networks are created for schools, universities and other big organizations. They had the name of the high school so they have to list it as their own high school in their Facebook profiles.
This will automatically put them in the same network as the girl. I am assuming here that she has listed that on her Facebook profile.
Then performing a graph search for women who has gone to that high school and live in Austin with an age between X and Y will narrow the search a lot. Even if some of that information is not public on Facebook it would be public to them if they are not same network if she has the default settings. This is a neat trick which is still usable.
I don't think looking through the pictures would take more than half an hour.
"- Facebook Graph Search and LinkedIn with the criteria we knew didn't help."
This stuff should worry you, not be lauded as some kind of amazing engineering feat. 4chan does this all the time and they call it doxxing.
At least that's what I might have done.
>My Ask
Nails on a freaking chalkboard. What is so bad about the word "question"?There are no digital yearbooks from the high school. I checked
And then scrolling thru all the friends lists of all their friends on Facebook.
(Especially if they have nicely sorted their friends into "High School" friends.)
Twitter lets you do the same thing.
I've seen entire classes all "Friend" and "Follow" each other.
1) They were running software on a computer for hours
They are engineers!
2) The first couple of tries didn’t work
Are you sure they weren't debugging?
3) They knew what high school she went too prior to searching
If they know the high school they only have to find one or two established teachers who were around for a long period of time. It is not unlikely they can call a name from a picture after all those years.
This smells like viral marketing to me (too bad I still don't know what close.io is, should have added some information to the article. Or are you looking for new engineers? "Hey look! At close.io we seal bets with engineers. About girls! Come work for us!").
I find it very likely that she was found on the internet somewhere.
From there, if he had an idea of where they went that night, a club or bar, perhaps he could do some Facebook/Twitter searching magic to search for pictures of that night, taken by other people. Then they could look for her face in the background.
Not sure where to go from there... perhaps they got lucky with one of the pictures being tagged with name. Or perhaps they identified everyone she was shown to be associating with, and found intersections in their Facebook friends list? Does it have to do with Facebook?
Option 1: Step 1) Find copies of yearbooks going back a few years, 2) find her face in the yearbook.
Option 2: Step 1) Search facebook for people who went to the same high school as she did in the probable time frame. 2) Look for her in that set, or in the set of friends that the people who matched the search have.
Feel free to sprinkle in face detection on the yearbook/facebook photos to make it more engineer-ey.
As a matter of fact, how did they find out what high school she went to? I can't imagine you telling them that if you were not providing much information about her to anyone else.
FYI, I am a sales guy...not an engineer
As someone who has been a software developer for quite a long time, this statement makes a big assumption.
A good software developer knows it is often far easier and faster to flip through a couple of hundred photos and process them with your meat-brain rather than write a one-off bit of software to do the matching, even if you start from an existing base like OpenCV or whatever.
That's why I said "Feel free to sprinkle in face detection on the yearbook/facebook photos to make it more engineer-ey."
FWIW, as others have pointed out, I do find this a bit creepy too, on two levels. First, the initial bet is a bit creepy. Guy involved said girl laughed it off, but that doesn't necessarily mean she didn't find it creepy that some guy she recently met was betting other people they couldn't track her down Enemy of the State style. And then on top of that, inviting the entire Internet into the game via the second obscured photo adds a much bigger layer of creep on to it, especially since in the process a lot of secondary information on her was leaked. Probably enough along with the photo of her face missing for others to find her, and you've kind of made that a public challenge indirectly. (Not one I have any interest in pursuing because like I said, the whole thing seems a bit creepy to me).
"This isn't the actual photo but looks similar, except that she was alone. Justin was afraid of reposting the same photo after the results of handing over a photo last time :)"
Which to me suggests it is the same girl in a different photo. I would still find it creepy even if the photo is not of her at all, though somewhat less so.
- using tools like http://www.pictriev.com/ or similar offline solutions to get a pretty good estimate of her age.
- using image analysis to "fingerprint" the camera used to take the picture. Then crawling sites where she would be likely to post pictures (twitter, etc.) based on the suspected area and comparing to find matches (i.e. pictures taken with the same camera). I'm not sure what the current state-of-the-art is for those algorithms, but if for instance the camera displayed an obvious visible flaw (darker spot), it would have made it easier. On a perfectly clean camera without visible defects I assume that more than one picture is necessary for effective camera fingerprinting.
- using tools like http://graphics.cs.cmu.edu/projects/im2gps/ to try and determine the location just based on visual features.
If your engineers as self-satisfied about finding her as it sounds, then they'll be happy to describe their process over a beer or two. I've never known an engineer who doesn't like discussing how they solved some riddle.
If the photo was taken at her home and there is any landscape in the background, the obvious initial point of attack would be to identify the location the photograph was taken.
1. Compose tactful email text explaining the bet. This is optional if you don't care about tact or a potential negative impact on your or your company image.
2. Go to fiverr and get a person or three to find teachers, administrators, and students who were at the same high school around the same time. Have them send the letter you composed to these potential teachers, staff, and peers. Track with close.io.
3. Get answers and try to confirm results.
4. With new data, iterate text of email and/or task request for fiverr if appropriate.
If you are skilled at chatting up gatekeepers (many sales folks are good at this), then you can call the school admin, explain the situation to her, and the answer would be yours in a few minutes.
There are some other options that are of questionable legality and/or ethics, but I will stay away from those.
The inside of her thumb is visible through the glass, so with enough detail it might be possible to record her thumb print. Even if you could do that, though, odds are against her print being present in any publicly-available database.
You probably know the year she graduated, you can run subsequent queries using +-1 based off of that graduation year. What you're after at first are rosters. The end goal is to place a picture for each name discovered.
Over 10 years since high school graduation? I'd be looking at one of the classmate or facebook groups regarding reunions. Less than 10 years since graduation? I'd still look trying to compile a list of names from these places. Old high school sports and club rosters maybe? Build a graph of people who did go to that high school during those years. Start building 1 degree of separation.
Once you've gotten a list of names, start cross referencing local groups, meet ups, colleges starting with the University of Texas -- possibly even spamming people using generated you've collected )lastname_firstletter@utexas@edu). Perhaps a phishing Email as follows "information regarding blah blah, looking for the person in this pic, we think they left their purse/cell phone etc"? Or post something in a local Austin Reddit.
I'd also do simple searches based on individual names and generated college emails. Start cross referencing all college clubs past/present with names and/or generated emails. If the person is/was in graduate school they will probably have even more school related information online.
If the person has graduated, start working the job route. Online career profiles monster, linkedIn, facebook. Have they done any sort of volunteering? Lot's of pics associated with volunteer work are out there.
5K results are a treasure trove, location, name and age ripe for searching. Some 5K's have corresponding flickr sets where you can match name to race number to a face. Once you have faces either look at them or run them through some CV for possible matches. Even if the name you've found isn't the person you're looking for such pictures might lead you to them anyway, if that person appears in a picture with your target. If you know that the person you found knows your target, start looking at that person's information. Who do they follow on pinterest, twitter, etc...
Does this person own a house do searches against the tax databases for full address of home. Even if the address isn't useful you might learn their middle name - re search with middle initial and middle names in lieu of first names.
Look at old social networking sites like myspace - the target might have old profiles up?
Did she sign up for a free trial of close.io?
To try and guess what happened:-
1) One of them followed you and got information. (You say this didn't happen.)
2) They had information about the event and worked from there.
3) There were other people in the photo, and they got face-matched, and their friends lists were not hidden, and they got it from that.
4) They had snippets of other information and just trawled through very many searches to get the name.
I'm a bit confused how they didn't already have her name. You told them you met someone, but didn't give any kind of name?
I am positive they didn't have number 2
There were no other people in the photo
What other snippets of information would be useful?
And they never met her, only I did. So they didn't know her name. And yeah, I said "I met a cute girl." I didn't say I met "name"
If the girl and the engineers have no complain about each other, who the fuck are you to decide?
More than likely the author is an idiot and the image had EXIF data. Considering they already knew her highschool, it wouldn't had been to hard to go through the year books in a few hours.
I still remember the time I said something impolite about David Brin. Brin took offense and replied.
I'm actually a huge fan of David Brin. That sucked.
Calling EXIF "back end stuff" is pretty stupid, I don't care if the author's ego is bigger than that statement, it's still true. The article might as well be how many apples fit in a bag or how long is a string.
edit: I'm aware of the irony in criticizing online geek culture and then bringing out a foul-mouthed meme pic.
Seriously: given your story, if, say, they are colleagues, too, they may be in on it, and lie to you about the EXIF data (if they _are_ engineers, they certainly lied; how can there ever be 'nothing interesting' in EXIF data :-)?)
Most of the time, the simple answer is the likely one. My money is on the high school-yearbook line, but it might have been anything (did one of your colleagues go to the same school?).
If one strips all of the metadata a photo, or replaces it with metadata from another photo, or makes up some bogus metadata.
A photo without EXIF data? Someone must be trying to hide something from me. Let's see how good he is, and check whether there still are parts of the file with metadata in the disk's free blocks.
"or replaces it with metadata from another photo"
A Nikon F5 at f/5.6 and 1/100s? No way! If so, that car must have done a thousand kilometers an hour or so. Also, the aberration looks more like that of an Canon lens, but I'm not 100% sure of the model. I wonder whether it is possible to train a model on the 'JPG to camera model' problem.
"or makes up some bogus metadata."
Hm, I thought the Eiffel Tower clone in Japan was in Shanghai. The GPS coordinates seem to indicate that Tokio has one, too. Let's google to check that.
OK, that's more for the hacker engineer, but I thought one would not have to make that explicit on HN.
Umm, No, many popular photo-sharing sites at least give you the option to strip metadata from photos when posting. IIRC, fb does this as well, by default.
> and check whether there still are parts of the file with metadata in the disk's free blocks.
Good luck.
>A Nikon F5 at f/5.6 and 1/100s? No way!
It doesn't have to be believable metadata to be practically useless.
>Also, the aberration looks more like that of an Canon lens, but I'm not 100% sure of the model.
> I wonder whether it is possible to train a model on the 'JPG to camera model' problem.
Sure, but not for beer money. You could probably even have some success identifying individual cameras by characterizing their CCD/image sensor, and comparing to known photos.
Given what Phil does, the most cost effective (rational) method he could have used was to spend those hours working, and then pay a private investigator.
If he wanted to do it himself, the easiest way is to facebook search for people who went to her high school in the right date range, then ask them who is in the photo. Given the start time and end time, Phil probably didn't do that, he probably browsed their photos & friends until he found her.
Not a very good use of time, but it would work.
I think guessing the exact method used isn't interesting, because the problem isn't a particularly hard one. He's done the social engineering equivalent of picking the lock on your filing cabinet.
You could pay a puzzle solver to solve a puzzle, but that defeats the purpose.
A good riddle is about the best way to do something, not about the way someone else happened to do it.