{"id":4942,"date":"2024-01-31T22:12:37","date_gmt":"2024-01-31T22:12:37","guid":{"rendered":"https:\/\/osintme.com\/?p=4942"},"modified":"2024-02-01T00:13:08","modified_gmt":"2024-02-01T00:13:08","slug":"the-osint-mindset-obstacles-considerations","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2024\/01\/31\/the-osint-mindset-obstacles-considerations\/","title":{"rendered":"The OSINT mindset: obstacles &#038; considerations"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4942\" class=\"elementor elementor-4942\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ecfe08d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ecfe08d\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-61d7556\" data-id=\"61d7556\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c56a89e elementor-widget elementor-widget-text-editor\" data-id=\"c56a89e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Over 2 years I wrote <a href=\"https:\/\/osintme.com\/index.php\/2022\/01\/17\/examples-of-opsec-and-privacy-fails-when-doing-osint\/\">this blog post<\/a> on opsec and privacy fails when doing OSINT. Basically a list of examples (practical, not theoretical) of what could go wrong and how it could damage or impede your investigation.<\/p><p>Today&#8217;s post might as well be read in conjunction with the old one. It was triggered by some recent discussions and reading on various legal (and illegal, or at least borderline) aspects of OSINT.<\/p><p>Let me explain what I mean by it.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-81817f7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"81817f7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c500ca9\" data-id=\"c500ca9\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0ad8380 elementor-widget elementor-widget-heading\" data-id=\"0ad8380\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">All OSINT is legal, it's open source &amp; openly available. Right?<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a3038bf elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a3038bf\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-de1b234\" data-id=\"de1b234\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4058320 elementor-widget elementor-widget-text-editor\" data-id=\"4058320\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Generally yes and it&#8217;s a universal truth that all OSINT practitioners globally accept.<\/p><p>But some exceptions might apply and here is how various jurisdictions can approach the topic from totally different viewpoints.<\/p><p>For example, you might be as surprised as I was that in the United Kingdom there is currently <strong>NO legal requirement<\/strong> or formal qualification standard for a person who wants to become a private investigator. Literally anybody can don the PI mantle and practice the tradecraft as professionally or as poorly as they like.<\/p><p>Apparently, legislative efforts are currently underway to change this situation and make PI licensing mandatory.<\/p><p>Right now there is a weird duality on the UK private investigations market &#8211; <span class=\"O-KfW\">there is a body called <a href=\"https:\/\/www.gov.uk\/government\/organisations\/security-industry-authority\">Security Industry Authority<\/a> (SIA) and they do issue licenses, but these licenses mainly focus on private security workers, from regular security guards, door supervisors to CCTV operators and close protection agents. <\/span><\/p><p><span class=\"O-KfW\">When it comes to private investigators, they are not required to have the SIA license, nor is there any level of scrutiny of enforcement.<\/span><\/p><p>Private investigators can use OSINT techniques and engage in many OSINT-related activities, from conducting background and reputation checks on people to undertaking efforts to locate missing persons.<\/p><p>Now, this is drastically different in Ireland, where the <a href=\"https:\/\/www.psa-gov.ie\/\">Private Security Authority<\/a> (PSA) regulates and licences private investigators (along with other types of private security employment). The following is a definition of a &#8220;private investigator&#8221; (taken from <a href=\"https:\/\/www.psa-gov.ie\/wp-content\/uploads\/2022\/11\/PSA-53-2022-Information-Note-on-Licensing-of-Private-Investigator-Contractors.pdf\">here<\/a>):<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-39acfc8 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"39acfc8\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8760fd3\" data-id=\"8760fd3\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-093c41f elementor-widget elementor-widget-text-editor\" data-id=\"093c41f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>A Private Investigator is defined as a person who in the course of a business, trade or profession conducts investigations into matters on behalf of a client and includes a person who:<\/em><\/p><p><em>a) obtains or furnishes information in relation to the personal character, actions or occupation of a person,<\/em><br \/><em>b) obtains or furnishes information in relation to the character or kind of business in which a person is engaged,<\/em><br \/><em>c) searches for missing persons,<\/em><br \/><em>d) obtains or furnishes information in relation to the loss or damage of property<\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8fdcb76 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8fdcb76\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1cf8d52\" data-id=\"1cf8d52\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d39ad17 elementor-widget elementor-widget-text-editor\" data-id=\"d39ad17\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Does any or all of the above sound like OSINT-able information? Absolutely.<\/p><p>An important distinction here however is that this applies to persons who do this for monetary gain and &#8220;on behalf of a client&#8221;. So the focus is on the contractual nature of the business relationship between a private investigator and the client.<\/p><p>Licensing for the above activities does not for example apply to people who carry out these actions as part of their regular employment for a company (business risk managers, compliance staff, etc).<\/p><p>To clarify it further, here is a list of those who don&#8217;t require licensing, taken from the same source as the requirements listed above:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c294409 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c294409\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-16f9eb1\" data-id=\"16f9eb1\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-dfb9f81 elementor-widget elementor-widget-text-editor\" data-id=\"dfb9f81\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>\u2022 a person who undertakes technical surveillance counter measures,<\/em><br \/><em>\u2022 a person who provides information technology security measures,<\/em><br \/><em>\u2022 a person who has statutory powers to carry out investigations for their employer,<\/em><br \/><em>\u2022 a person who carries out workplace investigations with the consent or knowledge of the person under<\/em><br \/><em>investigation and where the matters under investigation are subject to regulation under the enactments<\/em><br \/><em>listed in Schedule 1 of the Workplace Relations Act 2015,<\/em><br \/><em>\u2022 store detectives in the normal course of their duties who hold a valid PSA Security Guard (Static) or PSA<\/em><br \/><em>Security Guard (Guarding) licence,<\/em><br \/><em>\u2022 law searchers conducting documentation searches,<\/em><br \/><em>\u2022 a person whose activities relate to accessing publicly available information,<\/em><br \/><em>\u2022 the professional activities of accountants, auditors, barristers, broadcasters, journalists and solicitors*,<\/em><br \/><em>\u2022 any other such person as the PSA may decide.<\/em><\/p><p><em>*where these persons engage third parties outside of these professions to undertake activities falling within<\/em><br \/><em>the definition at (1) above, such third parties will require a licence.<\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-db5850f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"db5850f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-470d759\" data-id=\"470d759\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-02c95f3 elementor-widget elementor-widget-text-editor\" data-id=\"02c95f3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Based on the above (and on the individual circumstances) the answer to the &#8220;Is all OSINT legal?&#8221; question changes from &#8220;Hell, yes&#8221; to &#8220;Well, it depends&#8221;.<\/p><p>If you work in a private capacity, as a freelancer investigator and engage in any or all of the four investigative activities for monetary gain, you can&#8217;t do your OSINT legally in Ireland without a PSA licence. Period.<\/p><p>Note that there could be many other jurisdictions with abundant examples of similar tricky legislation.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-77cec6b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"77cec6b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1e59302\" data-id=\"1e59302\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c02651e elementor-widget elementor-widget-heading\" data-id=\"c02651e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Accidental disclosure<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f3a0417 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f3a0417\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-17e033d\" data-id=\"17e033d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-240ab66 elementor-widget elementor-widget-text-editor\" data-id=\"240ab66\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>&#8220;Whoever fights monsters should see to it that in the process he does not become a monster. And if you gaze long enough into an abyss, the abyss will gaze back into you.&#8221;<\/em> &#8211; Friedrich Nietzsche<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-00fdadd elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"00fdadd\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4e33574\" data-id=\"4e33574\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bd11124 elementor-widget elementor-widget-text-editor\" data-id=\"bd11124\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>I use this ill-suited quote from a philosopher to illustrate the point of accidental disclosure during OSINT investigations. Let&#8217;s consider the following scenarios:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-cac1f0c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cac1f0c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-919e8f2\" data-id=\"919e8f2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2c2ffd9 elementor-widget elementor-widget-text-editor\" data-id=\"2c2ffd9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"text-decoration: underline;\"><strong>Scenario 1<\/strong><\/span> &#8211; your searches for sensitive keywords or personal information on various websites, social media platforms, forums and so on are recorded not only by all those very resources you searched, but also by third party vendor tools that you could be using to assist your investigation. This can lead not only to generating interest around your search criteria, but it can also result in alerting potential targets that somebody is sniffing around. Suddenly shady forums begin profiling your activity based on various technical parameters (see <a href=\"https:\/\/osintme.com\/index.php\/2019\/10\/17\/what-user-information-will-a-website-collect-on-you\/\">here<\/a> for examples of what is collected).<\/p><p><span style=\"text-decoration: underline;\"><strong>Scenario 2<\/strong><\/span> &#8211; you are researching threat actor activity and examining some files acquired in the process. You want to keep your findings confidential but you also want to err on the side of caution and avoid accidentally downloading malware to your machine. You upload sample files to online malware sandbox services like Virus Total. Then you suddenly realise that uploads of files to Virus Total and similar sites can be viewed, accessed and downloaded by thousands of other users who have a paid subscription plan for the platform. Obviously, it&#8217;s too late now to stuff the genie back into the bottle.<\/p><p><span style=\"text-decoration: underline;\"><strong>Scenario 3<\/strong><\/span> &#8211; you are navigating a shady website hosted in what could be considered a high risk country. You&#8217;re behind a VPN and follow good opsec rules. Suddenly your VPN connection drops and you suddenly realise you don&#8217;t have a kill switch enabled. Your computer automatically re-establishes the connection to the site, but this time from your true home IP address :\/<\/p><p><span style=\"text-decoration: underline;\"><strong>Scenario 4<\/strong><\/span> &#8211; you are on the other side of the proverbial fence; this time you&#8217;re responding to a Freedom of Information Act request, likely made by a journalist or maybe an OSINT researcher. In the course of collecting the response material, you somehow accidentally append a spreadsheet containing personal information of ALL other employees and send it to the requesting person.<\/p><p>(If this sounds far-fetched, check out the details of the <a href=\"https:\/\/www.psni.police.uk\/sites\/default\/files\/2023-12\/Protecting%20from%20Within%20a%20review%20of%20the%20PSNI%20data%20breach%208th%20August%202023.pdf\">2023 Police Service of Northern Ireland data breach<\/a>).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-105eb20 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"105eb20\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2103dc6\" data-id=\"2103dc6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1f9a252 elementor-widget elementor-widget-text-editor\" data-id=\"1f9a252\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>To sum up &#8211; accidental disclosure is a thing in OSINT. Learn about it in order to protect your own privacy and the integrity of your research.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-3e1be92 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"3e1be92\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-16254e0\" data-id=\"16254e0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2cba5fb elementor-widget elementor-widget-heading\" data-id=\"2cba5fb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Examples of illegal or \"grey area\" OSINT<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7ac905b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7ac905b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5e5053b\" data-id=\"5e5053b\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8596fda elementor-widget elementor-widget-text-editor\" data-id=\"8596fda\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The most obvious example of when OSINT gets out of hand and laws could get broken is crowdsourced investigating.<\/p><p>Although using the word &#8220;investigating&#8221; is too much here, since very often these activities are just glorified social media witch hunts. They usually happen after a shocking incident takes place; people take to social media to find out more, to search for the identity of the suspect or the victim and the location.<\/p><p>Sometimes it could be the news (true or false) that a convicted sex offender was either seen in the area or is about to get housed in an area after the release from prison. A spontaneous quasi-OSINT effort takes place (minus the intelligence and the analysis part) and very quickly personal information, images and addresses appear online in a full-blown vigilante doxxing spree.<\/p><p>It&#8217;s often the case that the information shared was either inaccurate or completely wrong &#8211; but this fact gets noticed much later, when it&#8217;s already too late and somebody&#8217;s property or health (or both) had been damaged.<\/p><p>Naturally, professional OSINT investigators don&#8217;t act in this manner, so this example is not really applicable to the wider OSINT community.<\/p><p>So let&#8217;s take a look at one that is.<\/p><p>The context for this is Ireland-specific, but it might be relevant elsewhere too.<\/p><p>For the last 2 &#8211; 3 years or so, any large scale data breach in Ireland (typically as a result of a ransomware attack; see <a href=\"https:\/\/osintme.com\/index.php\/2023\/02\/14\/ransomwary-february\/\">last year&#8217;s BlackCat attack<\/a> against Munster Technological University in Cork) is handled in accordance with a playbook that includes making a legal application to the High Court for an injunction against anybody who would download, leak or share any data unlawfully disclosed as a result of the attack.<\/p><p>This step was also taken in the aftermath of the 2021 Conti ransomware attack against the Health Service Executive. The idea behind this is to limit the proliferation of the data breach &#8211; not by the cyber criminals, they don&#8217;t care &#8211; but by others, meaning everybody from the casual snooper to an OSINT practitioner.<\/p><p>High Court injunctions might not deter a cyber criminal in russia, but anybody living in Ireland will think twice about the possible consequences of accessing and sharing the data dump, even if it&#8217;s only for OSINT research purposes and even if it&#8217;s already publicly available somewhere else. The <a href=\"https:\/\/www.mtu.ie\/news\/update-11-feb-it-breach-cork-campus\/\">injunction notice<\/a> published at the time by the MTU reflected their determination to minimise the impact from the incident:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-aff0563 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"aff0563\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5ced016\" data-id=\"5ced016\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9378501 elementor-widget elementor-widget-text-editor\" data-id=\"9378501\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>MTU (&#8230;) secured an interim injunction from the High Court in order to help prevent the sale, publication, possession, or other use of any data that may have been illegally taken from our systems. MTU will seek to enforce that injunction as far as possible. To that end, MTU has engaged specialist services to closely monitor the internet for any possible leak of data.<\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ade0de1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ade0de1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-93bfcc5\" data-id=\"93bfcc5\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f548bd5 elementor-widget elementor-widget-text-editor\" data-id=\"f548bd5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>So what&#8217;s the impact of this on OSINT? Well, if you rely on collecting data breaches for investigating digital footprints of individuals you should bear in mind that in some cases downloading a particular database, even if already publicly available, is against the law.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-d181dab elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d181dab\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6c27bd7\" data-id=\"6c27bd7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f47286e elementor-widget elementor-widget-text-editor\" data-id=\"f47286e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The last example I have also touches on data breach records ingestion and processing for OSINT purposes. Publicly available records or not, these still contain personal and private information of thousands of people. Processing, storing and using those records for business purposes (either as an OSINT freelancer or a company) could easily be classed as data processing under the EU General Data Protection Regulation (GDPR). This to me is a grey area as it seems to depend on specific details of how, where and why the data collection and its further processing took place. One thing is certain, the people whose data is in the breaches collected and processed by OSINT companies did not express their consent &#8211; but professional legal expertise might be needed to drill into this topic effectively.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-84c0279 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"84c0279\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-64d26cf\" data-id=\"64d26cf\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-16cff15 elementor-widget elementor-widget-text-editor\" data-id=\"16cff15\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>PS. If you&#8217;re interested in examples from Belgium, France and beyond, check out these four blog posts by the OSINT FR collective, they are really informative:<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8f92ecc elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8f92ecc\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7f5e3a3\" data-id=\"7f5e3a3\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ec08cf7 elementor-widget elementor-widget-text-editor\" data-id=\"ec08cf7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><blockquote class=\"wp-embedded-content\" data-secret=\"GP7TJT7Vl6\"><a href=\"https:\/\/osintfr.com\/en\/osint-what-is-the-legal-basis-for-it-1-4\/\">OSINT: what is the legal basis for it? (1\/4)<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;OSINT: what is the legal basis for it? (1\/4)&#8221; &#8212; OSINT-FR\" src=\"https:\/\/osintfr.com\/en\/osint-what-is-the-legal-basis-for-it-1-4\/embed\/#?secret=Dv9oUtjSBW#?secret=GP7TJT7Vl6\" data-secret=\"GP7TJT7Vl6\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p><p><blockquote class=\"wp-embedded-content\" data-secret=\"UL7hNwe6s3\"><a href=\"https:\/\/osintfr.com\/en\/osint-lawfulness-of-collection-and-use-of-information-2-4\/\">OSINT: lawfulness of collection and use of information (2\/4)<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;OSINT: lawfulness of collection and use of information (2\/4)&#8221; &#8212; OSINT-FR\" src=\"https:\/\/osintfr.com\/en\/osint-lawfulness-of-collection-and-use-of-information-2-4\/embed\/#?secret=yhN45N4rx6#?secret=UL7hNwe6s3\" data-secret=\"UL7hNwe6s3\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p><p><blockquote class=\"wp-embedded-content\" data-secret=\"JMEEejkeXg\"><a href=\"https:\/\/osintfr.com\/en\/osint-what-compliance-with-the-gdpr-3-4\/\">OSINT: what compliance with the GDPR ? (3\/4)<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;OSINT: what compliance with the GDPR ? (3\/4)&#8221; &#8212; OSINT-FR\" src=\"https:\/\/osintfr.com\/en\/osint-what-compliance-with-the-gdpr-3-4\/embed\/#?secret=PRZhlODPgZ#?secret=JMEEejkeXg\" data-secret=\"JMEEejkeXg\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p><p><blockquote class=\"wp-embedded-content\" data-secret=\"KcfiafTABX\"><a href=\"https:\/\/osintfr.com\/en\/osint-what-admissibility-of-the-information-collected-in-litigation-4-4\/\">OSINT: what admissibility of the information collected in litigation? (4\/4)<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;OSINT: what admissibility of the information collected in litigation? (4\/4)&#8221; &#8212; OSINT-FR\" src=\"https:\/\/osintfr.com\/en\/osint-what-admissibility-of-the-information-collected-in-litigation-4-4\/embed\/#?secret=qeIOYuvBV4#?secret=KcfiafTABX\" data-secret=\"KcfiafTABX\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>A devil&#8217;s advocate view on why not all OSINT is legal; accidental disclosures and grey areas.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6],"tags":[152,58,30,14,15],"class_list":["post-4942","post","type-post","status-publish","format-standard","hentry","category-open-source-intelligence","tag-fail","tag-opsec","tag-personal-data","tag-privacy","tag-security"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/4942","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=4942"}],"version-history":[{"count":58,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/4942\/revisions"}],"predecessor-version":[{"id":5005,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/4942\/revisions\/5005"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=4942"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=4942"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=4942"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}