In brief
The talk is polemical rather than practical: the speaker refuses from the outset to touch on methods. The thesis — "OSINT isn't what it used to be": there is intelligence — so there is counterintelligence too, that is, disinformation, and open sources have become a channel for influencing the consumer. The rest — cases from practice and the classics of information security: the main threat — the human being. The talk does not examine what OSINT is good for in information security: asked directly, the speaker replies that he "was actually talking of something else". The last ≈9 minutes — an argument about what counts as OSINT.
Key points
- A thesis flagged as a personal opinion: there is intelligence — so there is counterintelligence too, "And what is counterintelligence? It's disinformation", hence "brainwashing the population".
- Social engineering aimed at him: a Telegram message "on behalf of the head of the Interior Ministry institute" about a call from "an FSB representative" and questions about how information is protected at the institute.
- "It's enough for scammers to know some tiny bit" — a name, passport details; a "safe account" is absurd: "put it under the bed, under the pillow".
- The Information Security Doctrine of the Russian Federation — this too is "protecting society from information that is harmful": the example — a rumor about a currency reform from "an assistant to some janitor" at Sberbank.
- At a forensic examination of an ATM, a conversation with the developer of its protection yielded the spots "where I needed to drill, and connect".
- The platforms' "closed OSINT" (cookies, Yandex Metrica, the Yandex Browser and Microsoft agreements) worries him most of all, but "the main threat is the insider threat, it's the human being": "64 million stolen" from one organization; at the one next door, with "a pile of tokens" — "there's nothing to steal".
- Federal Law 152-FZ (personal data, Art. 19) and the security policy — "it doesn't always work"; an insider "stole personal data", and flash drives were tracked.
- Protecting an organization from OSINT — counterintelligence only: "Launch some disinfo, see who leaks what."
Tools, artifacts, technologies
- Yandex Metrica, cookies, Yandex Browser — criticized — the collection of "personal data of site visitors". "Alice" — the source of the questions for a forensic examination. Microsoft — "the most malicious system" (in Olga Vladislavovna's words), a Gates quote.
- Google — the MH17 investigation. GetContact — in the discussion, planting disinfo "from 10 different numbers".
- Fido (FidoNet) — the first OSINT in his practice, "prescriptions for narcotic-class drugs". USB tokens, flash drives — "a pile of tokens … in the laptop", logged in the personal data leak case.
- Mitnick's book (the title is not spoken), "CyberDed" (who that is — not explained), NLP — panic through a rumor.
Legal and organizational context
- The framework of OSINT's legality — a list of articles, garbled in the recording (see below).
- Federal Law 152-FZ: personal data — "any information relating directly or indirectly to an identified … natural person", Art. 19 — security measures during processing; legal and technical protection, a security policy — "isn't complied with".
- Legal proceedings in the Russian Federation are held in Russian — an argument against anglicisms ("competitive intelligence or computer intelligence" instead of OSINT): a forensic examination has to be conveyed to the judge "in a form they understand".
- Operational-search activities (ORD) versus OSINT: there you have "closed, special information", which "you can trust 100%". The restriction of foreign messengers — "bad and inconvenient", but "how else do you do it?". The speaker teaches at the International Institute of Computer Technologies and has been "retired three years"; the moderator invites the argument to "a third day of MFD, done purely for lawyers".
Questions from the audience
Speakers are not labeled; who asks the first three questions has not been established — "So, the little speaker. Dmitry, I see you." points to the moderator Dmitry Yankovoy; there is no confirmation.
- How does OSINT differ from operational-search activities? → "the depth of immersion"; "Is the answer clear?" — "No". OSINT — "unreliable information … it's reference information". Why do people use it so fiercely, "quite a fashionable topic … for the last 7–8 years"? → "it's been hyped".
- How is OSINT useful methodologically, given that the talk does "hint at the usefulness"? → "Well, I was actually talking of something else"; for information security — look at what has been posted about you.
- Olga Vladislavovna (per the speaker map — Tushkanova): on "a third level of information" — a specialist sees that about their own field "they write rubbish".
- Igor Bederov (day 1; not named out loud, attribution per the speaker map): OSINT — a methodology for verifying information that is open, lawfully obtained and re-verifiable, and usable "in court as an evidentiary basis". → "But we're not in the West, thank God."
- The argument runs another ≈4 minutes: verification — "the main task of an OSINT investigation"; Barkalov — "what if it's well-crafted disinformation?", the GetContact example.
The speaker's position
Classic OSINT, in his words, works; his argument is with the uncritical consumption of open information, and he sees no solution against well-crafted disinformation. He does not argue with Bederov on the substance ("I won't even argue with that"), but considers verification a different task, and he provokes the discussion deliberately: "honestly, that's what I was after". The tone — opinion journalism, not a lecture and not a sales pitch.
Quotes
- "But I did say: not intelligence, but counterintelligence. That is, brainwashing the population through open sources."
- "Launch some disinfo, see who leaks what."
- "…OSINT is unreliable information, it's reference information. You must never trust it 100%."
- "But we're not in the West, thank God."