Intelligence – A good collection of great OSINT Resources
github.com
github.com
If not, seems like a missed opportunity for value-add / lock-in.
And if they do provide such data, it'd be nice if one such platform would make either the scrapers, or the scraped data, open-source. It's all just cleaned+normalized forms of already-public data, after all. (Like how the Yellow Pages could always be seen as a cleaned+normalized form of phone numbers listed in public view on shop windows.)
This is on my mind recently after noticing that there's actually no public dataset of "all WHOIS data for every domain on the Internet", despite WHOIS data being something explicitly designed for public querying. Almost certainly, intelligence agencies compile such a dataset themselves in order to fill in some gaps in cybercrime network-analysis graphs. Almost certainly multiple of them do, such that the number of crawlers doing it probably hurts the WHOIS services. Almost certainly the WHOIS services would be better off partnering with one of them to act as an "official crawler" to build such an index for everyone's use.
You couldn't opt-out of WHOIS (some TLDs just didn't allow for WHOIS privacy / proxy registrations) in the past, and it's IMO quite a hard sell that the public interest in the historic WHOIS data of some personal website should have any weight at all in this case.
Since the information was committed knowingly and willingly to the public domain, though I do not know much about it to begin with, I don't see how GDPR applies at all.
You could IMO also make an argument that the collection and scraping of WHOIS data without consent was unlawful processing as a whole, as the data was not provided to the domain NIC with explicit consent for third-parties to collect and save them forever, which would even make any overriding legitimate grounds for processing moot.
17a may also apply: The reason for WHOIS is to find out who owns a domain now, right? There is no version history. Historical WHOIS data does not serve this purpose anymore.
It's quite the can of worms.
On something like whois, there are commercial vendors that provide history/change reporting, but its a pain in the butt to parse/normalize whois records and that is before you even get to the fact that many providers have shut down their whois feeds "for gdpr compliance".
I don’t know about OSINT, but in the consumer data landscape (Acxiom, Datalogix, etc) this is the standard MO
Do you know about a tool for managing personas (vulgo sockpuppets)? E.g. a little database where you store facts about fake identities: Name, age, location, hobbies, favorite topics, and so on. Maybe if you click on an identity, it will connect you with a preconfigured proxy or VPN and allow you to post as them on websites.
I don't really have a use case for myself. I'm just curious because I read a couple of years ago that the US Army was developing something like that for propaganda, and wonder if the OSINT or sousveilance people have come up with a version. A less nefarious use of such technology would be to keep your (real) online personalities separate.
You can still be fingerprinted across "personas" when your useragent/screen resolution/IP address/proxy provider/etc. are all identical, since you're presumably doing all of this from the same device. This does not mean spin up a bunch of EC2 instances.
Buy a bunch of different burner phones/old laptops from Goodwill or whatever-- use discrete hardware. Get SIM cards from different providers. Pay with Bitcoin or cash where possible. Etc.
These are the sorts of things scammer sweatshops do to avoid accountability. They'll have literal walls full of phones wired up, each preconfigured for a particular identity. Even teenaged fraudsters like Eleanor Williams think to do this sort of stuff to maintain opsec.
Track organizational structures and responsibility over time (especially public ones like government and public corporation executives).
Then enable searches of events / transgressions and claimed fallguys so more responsibility can be traced/blame for these important figures who usually get off scot free.
It would be useful to know "hey who likely was in charge of the divisions that suppressed early global warming research in oil companies" with a relatively simple search.
I do not know any more details.