Protecting yourself against OSINT?Tool for public key cryptography where password is the private key?Contact...
Fantasy series about a human girl with gold tattoos who makes too much blood
Is there an unambiguous name for the social/political theory "liberalism" without "leftist"?
What does "away to insignificance" mean?
Why didn't Petunia know that Harry wasn't supposed to use magic out of school?
Options for passes to national parks in Arizona/Utah for 5 people travelling in one car
Are my triangles similar?
What are the advantages to banks being located in the City of London (the Square Mile)?
Why are there never-ending wars in the Middle East?
Could you use uppercase or special characters in a password in early Unix?
How can a stock trade for a fraction of a cent?
Why doesn't English employ an H in front of Ares?
Does using an img title attribute in addition to the alt attribute help image SEO?
Why do baby boomers have to sell 5% of their retirement accounts by the end of the year?
Is the phrase “You are requested” polite or rude?
Was Switzerland pressured either by Allies or Axis to take part in World War 2 at any time?
Do proteins interact through classical or quantum mechanics?
As a vegetarian, how can I deal with microwaves smelling of meat and fish?
Are Changelings immune to the Polymorph spell?
Protecting yourself against OSINT?
Did Bobby Fischer actually write "Bobby Fischer Teaches Chess"
Convexity of a QP
Is this sentence from a widely distributed current affairs publication correct?
Modeling the Round (Nearest Integer) function
Conveying the idea of "tricky"
Protecting yourself against OSINT?
Tool for public key cryptography where password is the private key?Contact person by phone, when their phone might have malwareCan I trust a security hash implementation after testing it with random inputs against another implementation?What precautions/training do companies have against social engineering strategies?How do I protect myself against SIM hijacking/social engineering?Defence methods against tailgatingHow safe is to have a LinkedIn account where you have published all the important information about yourself?
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty{
margin-bottom:0;
}
I recently watched a video about OSINT and learnt it can be quite a powerful agent. I've been on the internet for years, and at this point I'm not sure what I've posted and where.
Given this is now a form of recon in cybersecurity, do you have tips on how one can protect themsleves against it?
social-engineering opensource reconnaissance
New contributor
add a comment
|
I recently watched a video about OSINT and learnt it can be quite a powerful agent. I've been on the internet for years, and at this point I'm not sure what I've posted and where.
Given this is now a form of recon in cybersecurity, do you have tips on how one can protect themsleves against it?
social-engineering opensource reconnaissance
New contributor
add a comment
|
I recently watched a video about OSINT and learnt it can be quite a powerful agent. I've been on the internet for years, and at this point I'm not sure what I've posted and where.
Given this is now a form of recon in cybersecurity, do you have tips on how one can protect themsleves against it?
social-engineering opensource reconnaissance
New contributor
I recently watched a video about OSINT and learnt it can be quite a powerful agent. I've been on the internet for years, and at this point I'm not sure what I've posted and where.
Given this is now a form of recon in cybersecurity, do you have tips on how one can protect themsleves against it?
social-engineering opensource reconnaissance
social-engineering opensource reconnaissance
New contributor
New contributor
New contributor
asked 9 hours ago
iiSupaCannoniiSupaCannon
235 bronze badges
235 bronze badges
New contributor
New contributor
add a comment
|
add a comment
|
1 Answer
1
active
oldest
votes
Open source intelligence has been around for sometime even though it's received attention only in the recent past. Here's what I do to keep a check on myself.
Step 1: Hack yourself
Have you ever googled yourself? Try to gather information on yourself using OSINT techniques. Start somewhere, perhaps your most common username you use to access this website and move on from there. There are various tools available to search for usernames on the internet. You'll be able to find where you've signed up with that alias. Many times, it will be in places you don't even remember signing up at. Read through the posts and see how much information about you is given out.
In the meanwhile, start making a profile of yourself based on the information you've found. You'll be surpirsed what you end up with for each post you might've made or replied to will have something unique to tell about you. You might sometimes even find older usernames you used to use somehow having a connection. Branch out from there, search around for that now, all while noting your findings down. By now, you have a fair idea on the person's likes, dislikes, interests, views, etc. Now, in my opinion, things get dangerous when you can connect a person's online identity to their real identity. In some cases, you do it intentionally, in other cases, it happens unintentionally. You find a post that leads you to a username, that leads you to a blog post, that leads you to the user's LinkedIn profile. And now you have rich information on that person.
There are many great tools for reconning people. Google search filters being the first best example to really help you narrow down results. Your info is out there, it's just a matter of finding it. Here are some other tools that can help.
http://pipl.com
http://192.com
http://searchpeopledirectory.com
Step 2: Recalibrate
Once you've gathered a good amount of information on yourself, you need to start evaluating what do you want everyone to know, what should be seen with limited access (friends on facebook, connections on LinkedIn, etc), and what is up there but really shouldn't have been. Once you have this, you can backtrack, find these sources and tidy them up. You can also get a close friend to do the same recon on you to get a different perespective, maybe she finds something different about you.
Step 3: Control
I make it seem like the internet is bad, it really isn't. Some people like sharing and interacting with the community, posting things, tweeting their opinions, sharing experiences. And this is fine, as long as you know what you're doing and are okay with it. The internet is absolute, once it's up there, if you forget about it, it's going to be up there forever. So know that if you post something, don't be surprised if someone you've never met knows a lot about you. Even if it is a private forum, share assuming everyone is watching.
This entire thing is not a one time effort. I like doing it every now and then for I do a lot of things without realizing the impacts of it. As time goes by and your awareness increases, you'll automatically have a filter in your head that raise red flags if you're sharing something you shouldn't be. Some call it paranoia, I call it necessary (in limits).
Bottom line, get used to the fact that what you share on the interent is probably going to be seen by a lot more people than you'd expect and might tell a lot more about yourself than you'd have thought. Once you have this implicit filter in your head, you can control how much someone can gain on you with an OSINT based attack. Apologies if this answer is largely unstructued. There's no right or wrong answer here. Read other answers, get some ideas and make your own model. Goodluck!
Thanks for the tips. I have a lot of old aliases i've cycled through in the past. And for some of them, I can't remove the posts made from them. They're from years ago and are embarassing. I'd rather people didn't find those things about me.
– iiSupaCannon
1 hour ago
1
@Dreak1980 well. If you don't have control over them anymore, and you don't want anyone to find it, ensure that your current aliases have no link to them. Chances are, people may come across your embarassing posts via links to your most recent aliases. So get rid of the links between these is my advice. Tempted to see what these embarassing things are though.. just kidding :)
– Izy-
1 hour ago
add a comment
|
Your Answer
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "162"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/4.0/"u003ecc by-sa 4.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
noCode: true, onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
iiSupaCannon is a new contributor. Be nice, and check out our Code of Conduct.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsecurity.stackexchange.com%2fquestions%2f219531%2fprotecting-yourself-against-osint%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
Open source intelligence has been around for sometime even though it's received attention only in the recent past. Here's what I do to keep a check on myself.
Step 1: Hack yourself
Have you ever googled yourself? Try to gather information on yourself using OSINT techniques. Start somewhere, perhaps your most common username you use to access this website and move on from there. There are various tools available to search for usernames on the internet. You'll be able to find where you've signed up with that alias. Many times, it will be in places you don't even remember signing up at. Read through the posts and see how much information about you is given out.
In the meanwhile, start making a profile of yourself based on the information you've found. You'll be surpirsed what you end up with for each post you might've made or replied to will have something unique to tell about you. You might sometimes even find older usernames you used to use somehow having a connection. Branch out from there, search around for that now, all while noting your findings down. By now, you have a fair idea on the person's likes, dislikes, interests, views, etc. Now, in my opinion, things get dangerous when you can connect a person's online identity to their real identity. In some cases, you do it intentionally, in other cases, it happens unintentionally. You find a post that leads you to a username, that leads you to a blog post, that leads you to the user's LinkedIn profile. And now you have rich information on that person.
There are many great tools for reconning people. Google search filters being the first best example to really help you narrow down results. Your info is out there, it's just a matter of finding it. Here are some other tools that can help.
http://pipl.com
http://192.com
http://searchpeopledirectory.com
Step 2: Recalibrate
Once you've gathered a good amount of information on yourself, you need to start evaluating what do you want everyone to know, what should be seen with limited access (friends on facebook, connections on LinkedIn, etc), and what is up there but really shouldn't have been. Once you have this, you can backtrack, find these sources and tidy them up. You can also get a close friend to do the same recon on you to get a different perespective, maybe she finds something different about you.
Step 3: Control
I make it seem like the internet is bad, it really isn't. Some people like sharing and interacting with the community, posting things, tweeting their opinions, sharing experiences. And this is fine, as long as you know what you're doing and are okay with it. The internet is absolute, once it's up there, if you forget about it, it's going to be up there forever. So know that if you post something, don't be surprised if someone you've never met knows a lot about you. Even if it is a private forum, share assuming everyone is watching.
This entire thing is not a one time effort. I like doing it every now and then for I do a lot of things without realizing the impacts of it. As time goes by and your awareness increases, you'll automatically have a filter in your head that raise red flags if you're sharing something you shouldn't be. Some call it paranoia, I call it necessary (in limits).
Bottom line, get used to the fact that what you share on the interent is probably going to be seen by a lot more people than you'd expect and might tell a lot more about yourself than you'd have thought. Once you have this implicit filter in your head, you can control how much someone can gain on you with an OSINT based attack. Apologies if this answer is largely unstructued. There's no right or wrong answer here. Read other answers, get some ideas and make your own model. Goodluck!
Thanks for the tips. I have a lot of old aliases i've cycled through in the past. And for some of them, I can't remove the posts made from them. They're from years ago and are embarassing. I'd rather people didn't find those things about me.
– iiSupaCannon
1 hour ago
1
@Dreak1980 well. If you don't have control over them anymore, and you don't want anyone to find it, ensure that your current aliases have no link to them. Chances are, people may come across your embarassing posts via links to your most recent aliases. So get rid of the links between these is my advice. Tempted to see what these embarassing things are though.. just kidding :)
– Izy-
1 hour ago
add a comment
|
Open source intelligence has been around for sometime even though it's received attention only in the recent past. Here's what I do to keep a check on myself.
Step 1: Hack yourself
Have you ever googled yourself? Try to gather information on yourself using OSINT techniques. Start somewhere, perhaps your most common username you use to access this website and move on from there. There are various tools available to search for usernames on the internet. You'll be able to find where you've signed up with that alias. Many times, it will be in places you don't even remember signing up at. Read through the posts and see how much information about you is given out.
In the meanwhile, start making a profile of yourself based on the information you've found. You'll be surpirsed what you end up with for each post you might've made or replied to will have something unique to tell about you. You might sometimes even find older usernames you used to use somehow having a connection. Branch out from there, search around for that now, all while noting your findings down. By now, you have a fair idea on the person's likes, dislikes, interests, views, etc. Now, in my opinion, things get dangerous when you can connect a person's online identity to their real identity. In some cases, you do it intentionally, in other cases, it happens unintentionally. You find a post that leads you to a username, that leads you to a blog post, that leads you to the user's LinkedIn profile. And now you have rich information on that person.
There are many great tools for reconning people. Google search filters being the first best example to really help you narrow down results. Your info is out there, it's just a matter of finding it. Here are some other tools that can help.
http://pipl.com
http://192.com
http://searchpeopledirectory.com
Step 2: Recalibrate
Once you've gathered a good amount of information on yourself, you need to start evaluating what do you want everyone to know, what should be seen with limited access (friends on facebook, connections on LinkedIn, etc), and what is up there but really shouldn't have been. Once you have this, you can backtrack, find these sources and tidy them up. You can also get a close friend to do the same recon on you to get a different perespective, maybe she finds something different about you.
Step 3: Control
I make it seem like the internet is bad, it really isn't. Some people like sharing and interacting with the community, posting things, tweeting their opinions, sharing experiences. And this is fine, as long as you know what you're doing and are okay with it. The internet is absolute, once it's up there, if you forget about it, it's going to be up there forever. So know that if you post something, don't be surprised if someone you've never met knows a lot about you. Even if it is a private forum, share assuming everyone is watching.
This entire thing is not a one time effort. I like doing it every now and then for I do a lot of things without realizing the impacts of it. As time goes by and your awareness increases, you'll automatically have a filter in your head that raise red flags if you're sharing something you shouldn't be. Some call it paranoia, I call it necessary (in limits).
Bottom line, get used to the fact that what you share on the interent is probably going to be seen by a lot more people than you'd expect and might tell a lot more about yourself than you'd have thought. Once you have this implicit filter in your head, you can control how much someone can gain on you with an OSINT based attack. Apologies if this answer is largely unstructued. There's no right or wrong answer here. Read other answers, get some ideas and make your own model. Goodluck!
Thanks for the tips. I have a lot of old aliases i've cycled through in the past. And for some of them, I can't remove the posts made from them. They're from years ago and are embarassing. I'd rather people didn't find those things about me.
– iiSupaCannon
1 hour ago
1
@Dreak1980 well. If you don't have control over them anymore, and you don't want anyone to find it, ensure that your current aliases have no link to them. Chances are, people may come across your embarassing posts via links to your most recent aliases. So get rid of the links between these is my advice. Tempted to see what these embarassing things are though.. just kidding :)
– Izy-
1 hour ago
add a comment
|
Open source intelligence has been around for sometime even though it's received attention only in the recent past. Here's what I do to keep a check on myself.
Step 1: Hack yourself
Have you ever googled yourself? Try to gather information on yourself using OSINT techniques. Start somewhere, perhaps your most common username you use to access this website and move on from there. There are various tools available to search for usernames on the internet. You'll be able to find where you've signed up with that alias. Many times, it will be in places you don't even remember signing up at. Read through the posts and see how much information about you is given out.
In the meanwhile, start making a profile of yourself based on the information you've found. You'll be surpirsed what you end up with for each post you might've made or replied to will have something unique to tell about you. You might sometimes even find older usernames you used to use somehow having a connection. Branch out from there, search around for that now, all while noting your findings down. By now, you have a fair idea on the person's likes, dislikes, interests, views, etc. Now, in my opinion, things get dangerous when you can connect a person's online identity to their real identity. In some cases, you do it intentionally, in other cases, it happens unintentionally. You find a post that leads you to a username, that leads you to a blog post, that leads you to the user's LinkedIn profile. And now you have rich information on that person.
There are many great tools for reconning people. Google search filters being the first best example to really help you narrow down results. Your info is out there, it's just a matter of finding it. Here are some other tools that can help.
http://pipl.com
http://192.com
http://searchpeopledirectory.com
Step 2: Recalibrate
Once you've gathered a good amount of information on yourself, you need to start evaluating what do you want everyone to know, what should be seen with limited access (friends on facebook, connections on LinkedIn, etc), and what is up there but really shouldn't have been. Once you have this, you can backtrack, find these sources and tidy them up. You can also get a close friend to do the same recon on you to get a different perespective, maybe she finds something different about you.
Step 3: Control
I make it seem like the internet is bad, it really isn't. Some people like sharing and interacting with the community, posting things, tweeting their opinions, sharing experiences. And this is fine, as long as you know what you're doing and are okay with it. The internet is absolute, once it's up there, if you forget about it, it's going to be up there forever. So know that if you post something, don't be surprised if someone you've never met knows a lot about you. Even if it is a private forum, share assuming everyone is watching.
This entire thing is not a one time effort. I like doing it every now and then for I do a lot of things without realizing the impacts of it. As time goes by and your awareness increases, you'll automatically have a filter in your head that raise red flags if you're sharing something you shouldn't be. Some call it paranoia, I call it necessary (in limits).
Bottom line, get used to the fact that what you share on the interent is probably going to be seen by a lot more people than you'd expect and might tell a lot more about yourself than you'd have thought. Once you have this implicit filter in your head, you can control how much someone can gain on you with an OSINT based attack. Apologies if this answer is largely unstructued. There's no right or wrong answer here. Read other answers, get some ideas and make your own model. Goodluck!
Open source intelligence has been around for sometime even though it's received attention only in the recent past. Here's what I do to keep a check on myself.
Step 1: Hack yourself
Have you ever googled yourself? Try to gather information on yourself using OSINT techniques. Start somewhere, perhaps your most common username you use to access this website and move on from there. There are various tools available to search for usernames on the internet. You'll be able to find where you've signed up with that alias. Many times, it will be in places you don't even remember signing up at. Read through the posts and see how much information about you is given out.
In the meanwhile, start making a profile of yourself based on the information you've found. You'll be surpirsed what you end up with for each post you might've made or replied to will have something unique to tell about you. You might sometimes even find older usernames you used to use somehow having a connection. Branch out from there, search around for that now, all while noting your findings down. By now, you have a fair idea on the person's likes, dislikes, interests, views, etc. Now, in my opinion, things get dangerous when you can connect a person's online identity to their real identity. In some cases, you do it intentionally, in other cases, it happens unintentionally. You find a post that leads you to a username, that leads you to a blog post, that leads you to the user's LinkedIn profile. And now you have rich information on that person.
There are many great tools for reconning people. Google search filters being the first best example to really help you narrow down results. Your info is out there, it's just a matter of finding it. Here are some other tools that can help.
http://pipl.com
http://192.com
http://searchpeopledirectory.com
Step 2: Recalibrate
Once you've gathered a good amount of information on yourself, you need to start evaluating what do you want everyone to know, what should be seen with limited access (friends on facebook, connections on LinkedIn, etc), and what is up there but really shouldn't have been. Once you have this, you can backtrack, find these sources and tidy them up. You can also get a close friend to do the same recon on you to get a different perespective, maybe she finds something different about you.
Step 3: Control
I make it seem like the internet is bad, it really isn't. Some people like sharing and interacting with the community, posting things, tweeting their opinions, sharing experiences. And this is fine, as long as you know what you're doing and are okay with it. The internet is absolute, once it's up there, if you forget about it, it's going to be up there forever. So know that if you post something, don't be surprised if someone you've never met knows a lot about you. Even if it is a private forum, share assuming everyone is watching.
This entire thing is not a one time effort. I like doing it every now and then for I do a lot of things without realizing the impacts of it. As time goes by and your awareness increases, you'll automatically have a filter in your head that raise red flags if you're sharing something you shouldn't be. Some call it paranoia, I call it necessary (in limits).
Bottom line, get used to the fact that what you share on the interent is probably going to be seen by a lot more people than you'd expect and might tell a lot more about yourself than you'd have thought. Once you have this implicit filter in your head, you can control how much someone can gain on you with an OSINT based attack. Apologies if this answer is largely unstructued. There's no right or wrong answer here. Read other answers, get some ideas and make your own model. Goodluck!
answered 8 hours ago
Izy-Izy-
2591 silver badge7 bronze badges
2591 silver badge7 bronze badges
Thanks for the tips. I have a lot of old aliases i've cycled through in the past. And for some of them, I can't remove the posts made from them. They're from years ago and are embarassing. I'd rather people didn't find those things about me.
– iiSupaCannon
1 hour ago
1
@Dreak1980 well. If you don't have control over them anymore, and you don't want anyone to find it, ensure that your current aliases have no link to them. Chances are, people may come across your embarassing posts via links to your most recent aliases. So get rid of the links between these is my advice. Tempted to see what these embarassing things are though.. just kidding :)
– Izy-
1 hour ago
add a comment
|
Thanks for the tips. I have a lot of old aliases i've cycled through in the past. And for some of them, I can't remove the posts made from them. They're from years ago and are embarassing. I'd rather people didn't find those things about me.
– iiSupaCannon
1 hour ago
1
@Dreak1980 well. If you don't have control over them anymore, and you don't want anyone to find it, ensure that your current aliases have no link to them. Chances are, people may come across your embarassing posts via links to your most recent aliases. So get rid of the links between these is my advice. Tempted to see what these embarassing things are though.. just kidding :)
– Izy-
1 hour ago
Thanks for the tips. I have a lot of old aliases i've cycled through in the past. And for some of them, I can't remove the posts made from them. They're from years ago and are embarassing. I'd rather people didn't find those things about me.
– iiSupaCannon
1 hour ago
Thanks for the tips. I have a lot of old aliases i've cycled through in the past. And for some of them, I can't remove the posts made from them. They're from years ago and are embarassing. I'd rather people didn't find those things about me.
– iiSupaCannon
1 hour ago
1
1
@Dreak1980 well. If you don't have control over them anymore, and you don't want anyone to find it, ensure that your current aliases have no link to them. Chances are, people may come across your embarassing posts via links to your most recent aliases. So get rid of the links between these is my advice. Tempted to see what these embarassing things are though.. just kidding :)
– Izy-
1 hour ago
@Dreak1980 well. If you don't have control over them anymore, and you don't want anyone to find it, ensure that your current aliases have no link to them. Chances are, people may come across your embarassing posts via links to your most recent aliases. So get rid of the links between these is my advice. Tempted to see what these embarassing things are though.. just kidding :)
– Izy-
1 hour ago
add a comment
|
iiSupaCannon is a new contributor. Be nice, and check out our Code of Conduct.
iiSupaCannon is a new contributor. Be nice, and check out our Code of Conduct.
iiSupaCannon is a new contributor. Be nice, and check out our Code of Conduct.
iiSupaCannon is a new contributor. Be nice, and check out our Code of Conduct.
Thanks for contributing an answer to Information Security Stack Exchange!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsecurity.stackexchange.com%2fquestions%2f219531%2fprotecting-yourself-against-osint%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown