# How does OSINT affect information security? Yuri Barkalov · Forensics Science Centre MOSCOW FORENSICS DAY ’25 · Day 2 — Friday, 12 September 2025: information security day · Scheduled 11:05–11:35 · In the recording 04:13:53–04:50:29 Talk summary · https://2025.moscow-forensics-day.workers.dev/en/summary/11-barkalov Transcript: https://2025.moscow-forensics-day.workers.dev/en/transcript/11-barkalov · Slides: https://2025.moscow-forensics-day.workers.dev/en/slides/10-barkalov-osint · Watch from 04:13:53: https://youtu.be/4V7Wez3L_58?t=15233 --- ## In brief The talk is polemical rather than practical: the speaker refuses from the outset to touch on methods. The thesis — "OSINT isn't what it used to be": there is intelligence — so there is counterintelligence too, that is, disinformation, and open sources have become a channel for influencing the consumer. The rest — cases from practice and the classics of information security: the main threat — the human being. The talk does not examine what OSINT is good for in information security: asked directly, the speaker replies that he "was actually talking of something else". The last ≈9 minutes — an argument about what counts as OSINT. ## Key points - A thesis flagged as a personal opinion: there is intelligence — so there is counterintelligence too, "And what is counterintelligence? It's disinformation", hence "brainwashing the population". - Social engineering aimed at him: a Telegram message "on behalf of the head of the Interior Ministry institute" about a call from "an FSB representative" and questions about how information is protected at the institute. - "It's enough for scammers to know some tiny bit" — a name, passport details; a "safe account" is absurd: "put it under the bed, under the pillow". - The Information Security Doctrine of the Russian Federation — this too is "protecting society from information that is harmful": the example — a rumor about a currency reform from "an assistant to some janitor" at Sberbank. - At a forensic examination of an ATM, a conversation with the developer of its protection yielded the spots "where I needed to drill, and connect". - The platforms' "closed OSINT" (cookies, Yandex Metrica, the Yandex Browser and Microsoft agreements) worries him most of all, but "the main threat is the insider threat, it's the human being": "64 million stolen" from one organization; at the one next door, with "a pile of tokens" — "there's nothing to steal". - Federal Law 152-FZ (personal data, Art. 19) and the security policy — "it doesn't always work"; an insider "stole personal data", and flash drives were tracked. - Protecting an organization from OSINT — counterintelligence only: "Launch some disinfo, see who leaks what." ## Tools, artifacts, technologies - **Yandex Metrica, cookies, Yandex Browser** — criticized — the collection of "personal data of site visitors". **"Alice"** — the source of the questions for a forensic examination. **Microsoft** — "the most malicious system" (in Olga Vladislavovna's words), a Gates quote. - **Google** — the MH17 investigation. **GetContact** — in the discussion, planting disinfo "from 10 different numbers". - **Fido (FidoNet)** — the first OSINT in his practice, "prescriptions for narcotic-class drugs". **USB tokens, flash drives** — "a pile of tokens … in the laptop", logged in the personal data leak case. - **Mitnick's book** (the title is not spoken), **"CyberDed"** (who that is — not explained), **NLP** — panic through a rumor. ## Legal and organizational context - The framework of OSINT's legality — a list of articles, garbled in the recording (see below). - **Federal Law 152-FZ**: personal data — "any information relating directly or indirectly to an identified … natural person", Art. 19 — security measures during processing; legal and technical protection, a security policy — "isn't complied with". - Legal proceedings in the Russian Federation are held in Russian — an argument against anglicisms ("competitive intelligence or computer intelligence" instead of OSINT): a forensic examination has to be conveyed to the judge "in a form they understand". - Operational-search activities (ORD) versus OSINT: there you have "closed, special information", which "you can trust 100%". The restriction of foreign messengers — "bad and inconvenient", but "how else do you do it?". The speaker teaches at the International Institute of Computer Technologies and has been "retired three years"; the moderator invites the argument to "a third day of MFD, done purely for lawyers". ## Questions from the audience Speakers are not labeled; who asks the first three questions has not been established — "So, the little speaker. Dmitry, I see you." points to the moderator Dmitry Yankovoy; there is no confirmation. - How does OSINT differ from operational-search activities? → "the depth of immersion"; "Is the answer clear?" — "No". OSINT — "unreliable information … it's reference information". Why do people use it so fiercely, "quite a fashionable topic … for the last 7–8 years"? → "it's been hyped". - How is OSINT useful methodologically, given that the talk does "hint at the usefulness"? → "Well, I was actually talking of something else"; for information security — look at what has been posted about you. - Olga Vladislavovna (per the speaker map — Tushkanova): on "a third level of information" — a specialist sees that about their own field "they write rubbish". - Igor Bederov (day 1; not named out loud, attribution per the speaker map): OSINT — a methodology for verifying information that is open, lawfully obtained and re-verifiable, and usable "in court as an evidentiary basis". → "But we're not in the West, thank God." - The argument runs another ≈4 minutes: verification — "the main task of an OSINT investigation"; Barkalov — "what if it's well-crafted disinformation?", the GetContact example. ## The speaker's position Classic OSINT, in his words, works; his argument is with the uncritical consumption of open information, and he sees no solution against well-crafted disinformation. He does not argue with Bederov on the substance ("I won't even argue with that"), but considers verification a different task, and he provokes the discussion deliberately: "honestly, that's what I was after". The tone — opinion journalism, not a lecture and not a sales pitch. ## Quotes - "But I did say: not intelligence, but counterintelligence. That is, brainwashing the population through open sources." - "Launch some disinfo, see who leaks what." - "…OSINT is unreliable information, it's reference information. You must never trust it 100%." - "But we're not in the West, thank God."