Moderator's introduction
And the next topic, which opens our day today, is quite a broad one. It's not Apple devices, it's OSINT, about which lately there's been a lot of interesting stuff in the info space. Interesting not because it's like it used to be — you took something off the net, opened it, found it, and then somehow used that information. It has become interesting because OSINT has now turned into a real gray area that generates a huge amount of debate. And how to use it now is, in fact, not really clear. Let's try, after all, to figure out how OSINT is used in information security, and Yuri Mikhailovich Barkalov will help us. Let's support him with applause, because, Yuri Mikhailovich, we're placing a lot of hope in you today.
Here's the microphone. Thank you. Your clicker. —
Talk and Q&A
Actually, yesterday there was already a talk on OSINT — it was the closing one. So, accordingly, today will be the beginning of the continuation.
So, this is from the prose of life. Okay, down, right? —
— Ah, there it is. Well, a bit about myself. Here again, when it comes to OSINT, there's a bit of information missing. I now also teach at the International Institute of Computer Technologies. On top of everything else, that is. Well, let's move on.
Well, OSINT, as a matter of fact, everyone knows the translation: collecting info from open sources, intelligence. The word "intelligence" is still there in the English name. Personally, "competitive intelligence" or "computer intelligence" is closer to me. Why? Because, well, we do have such a term here, OSINT is international, everyone gets it, everyone brags about it. But I'm not too fond of English-language terms, for the reason that for example, legal proceedings in the Russian Federation are held in Russian. And then explaining what it means in English and in Russian, maybe a young judge would understand.
Well, collecting information from open sources, it's all clear. But the main thing here: comply with Art. 272, and 152.1, 152.2 of the Civil Code, so as not to break the law and not get caught, not incur liability. But actually, I'm not going to touch now on the topics of how OSINT is conducted or what it's for. I want to talk about something else. Actually, well, maybe I decided this for myself, maybe it really is so. But OSINT can be divided into at least two parts. There's professional OSINT. Well, we've got the Positive Technologies folks here, well, all the rest — anyone who does professional analysis of incidents in the field of information security, knows what OSINT is for and how to use it.
And there's civilian OSINT. Any of you, everyone tries to find something online. That is, everyone is a subject of OSINT, both on the side of receiving information and of providing information. And here's what's interesting, if you think about it: did OSINT appear long ago? The first civilian OSINT was probably the grannies who sat — well, the older generation remembers — the grannies who sat at the entrance and handed out information about the persons of low social responsibility living in that building. Well, I hope you understand what I mean. Now those grannies, pardon me, have been replaced by young people who sit on social media, and who knows what they discuss there. And now here's the interesting question, the main thing. So
there are consumers of OSINT, and there are those who supply information there. And since the key word is "intelligence", accordingly, counterintelligence exists. And what is counterintelligence? It's disinformation. So, if it comes to that, look, I'll say a bit more now about civilian OSINT. And by the way, about yesterday's remarks on when I did a forensic examination. So, recently, someone brings me an order appointing a forensic examination, well, a lawyer brings it, and there are questions. I read the questions. Excuse me, Elena Rafailovna Susova — they can take a rest with their question list, which they came up with back then and which some people still use. Who knows what's in there.
Turns out — where did you get the questions from? Alice helped. Alice — that's the Yandex one, right? You see? So it collected something, did something, provided something. And people, well, quite — artificial intelligence or whoever it is, I don't know, but the information is there, it can be used.
Next — that's not all, naturally. Well, it's clear what they collect it for. Well, I put pluses and minuses here, actually. Well, let's take the minuses: preparing attacks. Well, I really did get a call — I mean, a message, then they call. First, a Telegram message on behalf of the head of the Interior Ministry institute, saying: "Yuri Mikhailovich, an FSB representative will contact you soon, you must assist him." Some time later, a call, he calls, obviously asks about something, I say something, and they ask me: "Well, tell us how information security is organized at your institute." I say: "I've been retired three years." "How would I know?" "We know, you tell us anyway." Well, you see, I just collect things like this. I find it interesting to talk with people like that.
Well, we talked, we chatted. Well, obviously, then it comes: "Well, we'll soon invite you to Lubyanka." I say: "Well, fine, I'll come." Olga Vladislavovna told me today: "Don't say what's next, so it won't get out." So I won't tell you what I answered them. Let's move on. Well, it's clear what else they collect it for: blackmail. Well, again, what do they blackmail with, exactly? Well, many of you have seen it: it's mostly, let's say, photos and videos of an intimate nature. Including, maybe, deepfaked ones, I don't know. Such things happen. Recently there was a request to do a forensic examination of two sodomites in cassocks, excuse me.
Was it a deepfake? I had such an examination. But I'll say right away why I didn't do it: because the recording quality left a great, great deal to be desired. Well, the fact remains that this happens too and this is possible. Well, obviously, theft as well. Look, actually, theft of what? Not just theft of information, but theft in the ordinary sense of the word. Look how nicely I'm relaxing at a resort, somewhere far away from home, right? and nobody's at home, so, like, come in, take it, nobody's there, help yourself, and look what nice things, bought this, bought that, so, well, there's something to take. Well, I won't even talk about fraud, that goes without saying, they gather some OSINT, something, well, actually, that'll be discussed later, it's enough for scammers to know some tiny bit, a name, something else, they cite some passport details, which can also be found.
And then what? Then come social engineering methods. How does it go, remember, the film about Buratino? "As long as there are fools in this world, living by deception suits us fine." So what? Here you go: they withdrew the money, it's in your hands, and now put it in a "safe account". Why put money in a safe account when it's already in your hands? Far safer: put it under the bed, under the pillow. But people get brainwashed, well, what can you do, it's human psychology. And by the way, on that note, here's the thing: that information... it's no accident that right now, on the one hand, of course, it's bad and inconvenient, this restriction of foreign messengers, but on the other hand, well, how else do you do it? Because again, people swallow whatever information is shoved at them.
How did the old ladies at the fence, by the entrance, know who lives where, and what the social responsibility of certain residents was? Same here. Who posts the information? Where does it get gathered from? Well, now we can move on to the pluses, for the good things. But I've practically already said that, well, even some of my own students are sitting here, who carry out that first item in certain organizations, well, yes, they collect information, so what. And you: don't post anything bad about yourself online, and make sure nobody else posts it about you. Well, you understand what I mean: well, got drunk, sorry, or something else happened, I'm not talking about last night.
Yes, checking for data leaks, well, obviously, I already said, well, this is probably the most common case of using OSINT from the digital security point of view, well, when you check whether your data is actually online, whether it leaked or not. But crime investigation — here's a very interesting thing, which is sort of where I'm going. Crime investigation I marked with a plus, but you could also give it a minus Look, the flight, now I'm getting to the not-so-good things, MH17, who investigated the incident, when the plane was shot down over those regions. Well, their investigation was done through Google. Actually, they really did have information there, because they assume that people post correct information.
But who, where did they get the information from, who posted it? That's what I want to stress now. Actually, I say OSINT isn't what it was. Or maybe it is, it's still there, the classics exist. I'm saying, about CyberDed there's nothing to even say. They work, they're all great. They have their task, they do their task. There are other organizations. I mean something slightly different. I mean information security, but not that broadly, just from the point of view of the Information Security Doctrine of the Russian Federation.
Why? All the information that's out there online and which, excuse me, you and I as consumers, and everybody else receive, and we receive it constantly. And this information, what can it be about? What can it be preparing? And, excuse me, the Information Security Doctrine clearly says that protecting information includes protecting society from information that is harmful.
That is, involuntarily, every one of us becomes, every citizen of Russia, a consumer of who knows what. So, basically, this information has arrived. Well, you know, here's the first thing one could say right now. A sister-in-law's brother-in-law's nephew said there's a currency reform tomorrow. And he works at Sberbank as an assistant to some janitor. Doesn't matter, people don't think, what matters is the keywords are there. Well, again, that's NLP, that's all social engineering. Create panic, get something done. You'll say, that's not OSINT. And I say, it's possibly not OSINT. But there is a consumer: you search for something, you receive something. It's an open source, open. So what exactly is wrong?
But I did say: not intelligence, but counterintelligence. That is, brainwashing the population through open sources. The opposite. But it exists, it must be accounted for. Unfortunately, there's no getting away from it. Well, about commercial activity, fine, we've all been through that. So, where the data comes from, I've already said, basically: we post it ourselves, we post it ourselves, and not only ourselves.
Theft, all the rest, that's clear, that's the classics, but again I want to say about the information that we didn't post, but that was posted for us.
Well, or just, well, even simply, look, even ordinary information security, I already mentioned here yesterday, they said, when I cracked a phone... no, I didn't; the last one was an ATM, I'll tell you about that, it's also OSINT. Look, actually, yesterday I talked to many people here, many are into this, and even when I was already leaving, I was chatting, we were walking down the street and got to talking about OSINT, and I had a case like that too, because OSINT gets its information not only from the internet. Me talking to you, maybe, information about Vienna could also be used. So, there was a forensic examination: they ordered an ATM reliability check.
Well, I arrived, it had to be done here in Moscow, and the developer of the system, the new protection system. I went out with him, we talked, took a walk, well, next day we come in, I already knew the spots where I needed to drill, and connect. In short, what did we do? I started a computer inside without tripping the alarm. Well, obviously, no need to say more, after that it's just a matter of technique. So, well, and now, after all, I've already said it: that was for the consumer, and now here's what worries me most of all, irritates me, I don't know how to put it, it's that OSINT which you can't say is open, but it exists, and has existed for a long time and constantly.
Well, let me flip through this. So, first, an agreement with Yandex. Open, not open, doesn't matter. This site collects and processes cookie files and personal data of site visitors by means of the internet service for web analytics, Yandex Metrica. By continuing to use the site, you consent to the processing of cookies under the site's policy, and so on. Yesterday, the last talk was about this too, among other things. And now cookies, well, cookies, yes, cookies, right, well, when you go online in your browser, your passwords are saved, you automatically log in somewhere, right? Now clear the cookies, what happens? Type the password again. I don't mean to say anything about what's in cookies, whether that's good or bad, just think about why every site collects cookies, is it only to bring you the information you need, after all, you enter a site belonging to, excuse me, who knows whom, including... well, here, maybe, the protection is excellent, well, further on: License agreement for the use of Yandex Browser software.
The user is notified and agrees that the Rights Holder, so, Yandex.Technologies, processes their personal data, including but not limited to... Well, read the rest yourselves. I don't mean to say anything about Yandex, that it sells information, nothing, that it does anything.
Although, it supposedly isn't obliged to hand it over to third parties. But, look, always, if we're considering information security, information protection, always remember the classics. The classics of information security. The main threat is the insider threat, it's the human being. No matter what you do, how you protect yourself, there'll always be someone who neglects it and says, "I'm so smart, I'm fine." Again, I'll tell you a case from life: so, two organizations, one has lots of money in its account, they got hacked, 64 million stolen, well, by the standards of those days. I come to another organization, a day later, also needed there, well, on a different case, we look: a secretary sits there, nails like this, a pile of tokens in the computer, in the laptop, right, a token, like this, right, and nothing gets stolen from them.
You know why? There's nothing to steal. Well, they know it from somewhere — why go on a job, so to speak, if we don't know what to steal, really. And the same thing happens here.
Will there be a vulnerability, will there be a person who passes it on. I don't want to accuse anyone, the information just appears from somewhere. Well, next, this is Microsoft. Olga Vladislavovna said yesterday that the most malicious system is Microsoft. And Microsoft itself doesn't deny it. It writes it right there in the Microsoft Privacy Statement.
There you go. Basically, if you don't agree, don't install it. Well, sorry, they say so themselves. Back in the day Bill Gates said that the ordinary American shouldn't have to think about what's on his computer. We'll decide that for him. Now they decide for the whole world.
That's a normal thing. Information is money. Accordingly, if there's information, that's money, and accordingly, it has to be used. Well, you remember the phrase: whoever owns the information owns the world.
That's how it is.
Well, and now a bit about the legal side of this. This is the personal data protection law, everyone knows it, Federal Law 152-FZ. What is personal data? Actually, a lot of ink has been spilled over what it covers, but here the definition is the usual one: any information relating directly or indirectly to an identified or identifiable natural person.
And Article 19, measures to ensure the security of personal data during processing. Well, I understand that all of this must be complied with, all this must be protected, but somehow, I don't know why, it doesn't always work.
Alas, that's how it is. Next, as I was saying, since we're touching on information security, for some reason everyone forgets the basic concepts of information security, of infrastructure security. That there is legal information protection and technical information protection. But legal information protection — well, remember: organisational measures, technical measures.
There's the organisation's security policy — again, it has to be developed. You know, once an examination came in: got a security policy at all? Well, we did an examination once. In short, a person stole personal data from a company. Well, all was tracked: how he plugged in flash drives, how he copied what, and so on. You'd think, what's OSINT got to do with it?
But the thing is, he was also, sort of, looking for someone to sell it to. And look, this information gets disclosed. And where, and how is it protected? I've said it again and again: if information isn't protected, it will, accordingly, be accessible. And once it's accessible, it can be obtained, posted, sold, and so on and so forth. But there's no escaping that. Well, I won't talk about technical information protection either, because, well, what am I going to tell people who know all this, who all studied it. But my point is different: it exists, but for some reason isn't complied with. Information security is a costly thing, yes.
But losing information is an even costlier thing.
But this is my cry from the heart: all the data gathered by Microsoft, Yandex, any sites collecting cookies — naturally, it's all protected. Because it says right here that your data must be — we accept it personally, we protect it, and we won't give it to anyone. Well yes, I believe it.
All data is protected. Where else would it go? Well, and now: OSINT isn't just gathering information, it's, really, serious analytics. Analysing that data — now that's an art. The thing is, everyone knows that 2×2=4, but when 2×2=4 applies to something, to some product, that's another matter. That is: what have you got? Are we selling or buying? What are we selling? What are we buying?
So, it doesn't matter how the information was obtained. Well, the OSINT classics: that this information has qualitative, quantitative and value characteristics. Those who've done this all know it. For attackers, basically, as I've already said, no need to collect much information, they just need to get your minimal data, at which point you — well, not you, but you know who — they can be blackmailed or something else can be done to them. And, as I said, it's all like the Field of Miracles in the Land of Fools — well, and that's the phrase I already said — but again, if they aren't aimed at some large-scale actions, again involving social engineering methods — well, remember the irreplaceable Mitnick, the book: how he got into an organisation. First I found the phone directory, then I called a department; with one it didn't work, the second said, well, my mail isn't working — yes, yes, our IT guys are doing a bad job, but you tell me what's next, send the file — and so on, it gradually unravelled; again, he got the information, he got it, the information wasn't hidden, it wasn't, so think about what ends up on the internet.
But there's something else here too: when an incident is investigated, they looked at the information, but then — how did it get there? In what way? First, I told you about the plugged-in flash drive. The person — who am I? Who had access? Who could've posted it? Well, here it's all classic information security, I'm saying it again. Well, and here again, I've already said repeatedly: is there any protection? That's the question.
Well, again, the rule: follow the rules of infosec. And countering it. Well, you've got an organisation to protect from OSINT. Well, counter-measures. Launch disinformation about your system. After all, if you recall again the classic, the classic fundamentals of information security, it's, first of all, hiding information on the informatisation object itself and how it's all protected. Well, what's there to say? Again, counterintelligence methods. Launch some disinfo, see who leaks what. Everyone's seen the Stierlitz films, and everyone else roughly knows how it works. Actually, other ways of countering and using OSINT by the classic method I simply don't see. But once again I want to stress something else.
Once again, I say: OSINT isn't what it used to be. There's the classic kind, but what's happening now — I don't know, I'm ready to debate it, this is just my personal opinion for now. But I'm saying something is happening now, because every consumer, everyone tries to find information. What's foisted on him depends on others. Well, I fit into exactly half an hour. Thank you for your attention. Any questions — I'll answer as best I can. So, the little speaker. Dmitry, I see you. —
— Good afternoon. Could you please give a definition of how exactly OSINT differs from, say, operational-search activities? I can. Look, the thing is, it's the depth of immersion. Is the answer clear? No. Using databases — I mean, OSINT exists in operational-search activities, but a different kind. I'd call it not OSINT but computer intelligence. How's computer intelligence relevant? Huh? How's computer intelligence relevant? Databases, big data. Look, OSINT for us is open sources. We kind of know. But what's in open sources? If earlier — the first OSINT I saw, back when I was still in service, we did it, it was still FidoNet. And we launched this thing and found prescriptions for narcotic-class drugs. —
— There really was correspondence there, we collected that data. It's just that in operational work, look, actually OSINT is unreliable information, it's reference information. You must never trust it 100%. But there is, let's say, in operational work, information you can trust 100%. But that's closed, special information. So that, basically, is the difference: not only open but also closed information is used. —
— Fine, but then why is everyone so fiercely trying to use OSINT? What's the point? It's quite a fashionable topic. For the last 7–8 years. Because it's been hyped, I'm saying, well, everyone uses it, everyone — I don't know, I have people here — remember, there were classes on OSINT, I gave, I just gave the data: find, collect data about me and analyse it. Well, everyone likes it, I'm saying, people here already came up, we talked, well. So we're talking about OSINT as some kind of thing that everyone likes. —
— Yes, and it's fashionable, on everyone's lips, but I'm saying, what I'm getting at, really, isn't that it exists and everyone likes it; I'm getting at the fact that information in open sources now can't be fully trusted. —
— But it never could be. I mean, I'm just trying to find out from you how exactly OSINT can be useful methodologically. Because your talk does after all somehow hint at the usefulness and use of this methodology.
Help with information security? Well, I was actually talking of something else — I talked about the information security doctrine, that people need to be prepared somehow not to fully trust the information everyone has now rushed to; and from the standpoint of classic infosec proper — well, that's all known anyway: look at the information I laid out for you; to protect yourselves, put out disinfo about your system.
Olga Vladislavovna, well, all right, of course. You know, there's also a third level of information that gets put on the internet at all. Here's what I want to say. Each of us is a specialist in some field of knowledge, knows it well. You read newspapers, interviews, whatever, on your own field, and you're amazed. Good Lord, what are they writing? Then you think: what about the rest I don't know — the approaches there are just the same, they write rubbish. So OSINT is trusting those databases, open sources, state ones or otherwise, when you need to find something, dig up dirt on a competitor, search around, or get some orienting information that you still have to dig into.
I say, the main thing is analytics.
— Colleagues, let's start with a very simple thing. OSINT is a methodology that lets you collect, analyse and verify information that is publicly available. And the basic principles we follow are that the information must be open, it must be lawfully obtained, and it must be re-verifiable. Those are the main points, and that's how, in fact, it differs from operational-search activities. That's why, in fact, people use this methodology. Not because it's cool, but because it's genuinely a method for verifying information and using it, say, in court as an evidentiary basis.
But we're not in the West, thank God.
— Look, I often act, let's say, as a specialist in court, specifically assisting in court cases. We're not at a hearing.
— Wait, we're discussing OSINT now. A real discussion's started, and honestly, that's what I was after.
— Excellent. So look, OSINT: we already know the information needs verification, but it's there. I'll throw in one more provocation: lawyers are in the room, and I'd really like them, at least at the next forum, to get up themselves and speak, because I debate with them, I've long worked with them, and I know that yesterday's problems with the questions, I understand why they came up. Same here. Thing is, sorry, a forensic examination, and generally getting info to a lawyer, to a judge, has to be in a form they understand. They're not specialists. And if you also tell them, yes, I found this information in an open source, that's it, great, so it exists. I recently brought up flight 17. For them it's yes, that's a yes. It's online, so it's correct. But is it?
Are we definitely talking about the same thing? Yes, absolutely. Literally two minutes ago I said this is a methodology that lets you verify information so that it can be re-verified in the future, including for use in court cases. Yes, of course, the lawyers thing is great. Just last night we were sitting with our respected colleague, Ms. Yulova, the younger one; we've quite often worked in this area, specifically with her. You've thrown it all into one big pile; for instance, it's unclear to me, some of the definitions you give, and they seem, I'm sorry. No, that's fine, that's fine. The thing is, that's exactly the point for discussion.
It needs to be discussed. It's a problem; once we understand it exists, it needs to be solved. What's the problem? —
— What are we discussing now? The questions or OSINT? No, let's talk about OSINT then. The problem is that you propose using the information, but it has to be verified, right? How do you verify it? —
— There are several verification methods that are used precisely for this. —
— But that's another task. Why? That's the main task of an OSINT investigation. Look, I understand, look: we found the information, and then comes the confirmation of that information, true or not. Yes, there's a lot of information, heaps of it, and our task in the process of investigation is precisely not to find information but to analyse and verify it, so that the information can be considered true. Ah, but again, look, I meant something slightly different: what if it's well-crafted disinformation? If it's well-crafted disinformation, there are always ways to verify it, to refute the hypothesis or confirm the hypothesis based on that. To plant disinfo, for example, about any of us, just go into GetContact, you know, a wonderful tool, and post from 10 different numbers that, excuse me, Yuri is a bad person.
Yes, of course, since that information is easily manipulated. But methodologically, again, the task of a specialist doing intelligence work, including OSINT, is precisely to verify the information and make it evidentiary.
— I won't even argue with that. But that's exactly where the problem lies.
— Colleagues, one small point: the roast was yesterday, and frankly, let's not... let bygones be bygones. Hallway conversations, we fully support them, but this discussion, I think, Yuri Mikhailovich, belongs on a third day of MFD, done purely for lawyers. We could set up a table. Yes, good it's there, I'm glad, thank you. And so, let's see off Yuri Mikhailovich with a round of applause and slowly move on.