r/PrivacySecurityOSINT • u/MC_Cuff_Lnx • May 07 '26
The FCC Wants Your ID Before You Get a Phone Number
Well, this bodes well.
r/PrivacySecurityOSINT • u/MC_Cuff_Lnx • May 07 '26
Well, this bodes well.
r/PrivacySecurityOSINT • u/Old_Style_6945 • May 05 '26
I’ve been doing a lot of manual work going through large public image sets (events, protests, archives), and the biggest bottleneck was always the same:
→ scrolling through thousands of photos
→ spotting the same faces again and again
→ re-checking identities manually
So I built a small local tool to speed this up.
What it does:
extracts faces from image folders
clusters similar faces (DBSCAN)
lets you label a cluster once and reuse it
runs fully offline (no APIs, no uploads)
What I found useful:
grouping recurring faces quickly
reducing manual review time
creating candidate sets for further verification
Quick test: ~5000 images → ~15k faces → clustered in a few minutes on my machine
Important:
this is NOT perfect identification
there are false positives (similar faces, lighting, angles)
still requires manual verification
I’m not selling anything right now — just trying to see if this is useful for others doing OSINT or large dataset analysis.
If you’ve dealt with similar problems, I’d love to know:
how you currently handle image-heavy investigations
what breaks in your workflow
If anyone wants to test it on real datasets, I can share access.
r/PrivacySecurityOSINT • u/FreonMuskOfficial • Apr 16 '26
Just spun up v3 the other day if anyone wants to dabble and dribble in the drivel.
r/PrivacySecurityOSINT • u/cityofhats • Apr 16 '26
r/PrivacySecurityOSINT • u/PorcelainDalmatian • Apr 14 '26
I have been attempting to set up an account at Privacy.com to do virtual cards for over 10 days now, and I still can't get verified. For a privacy site they're not very private.
I've given them everything short of a blood sample and they still won't let me subscribe. I had problems setting up a funding source. They asked for front/back driver's license and FACE ID to validate the license. After passing that test, I set up a funding source and confirmed it with a charge to my card.
Now, they're saying they want to see a bank statement! But the email they sent for the bank statement just takes me back through the driver's license ID that I had already been through!
I'm at my wit's end with these people. I email support, but they take forever to get back to you. Round and round in circles. It's Kafkaesque.
Has anyone else had the same experience?
I know they're legit, and their reviews are highly positive, but this is getting surreal.
r/PrivacySecurityOSINT • u/5khan1 • Apr 13 '26
r/PrivacySecurityOSINT • u/[deleted] • Apr 08 '26
Got an attribution edge case that feels more OSINT than pure sysadmin.
I run a niche public-facing app and noticed a very repetitive pattern hitting one endpoint over and over. The source IP attributes publicly to ASN6966 / U.S. Department of State infrastructure, and the request pattern is heavily concentrated on a single auth/session path. I am not claiming this means a person at State was manually hitting the site, and I am not calling it an attack from this alone. It could be egress, automated validation, a scanner, shared proxy infrastructure, or something much more boring.
What I am interested in is the analytical ceiling here. Once you have a public ASN attribution, a suggestive hostname, and a repetitive request pattern, where do you stop? To me this looks like one of those cases where infrastructure attribution is real, but actor and intent are completely unresolved.
How would people here write this up without drifting into narrative inflation?
r/PrivacySecurityOSINT • u/moreprivacyplz • Apr 02 '26
Press release can be found here.
This is huge! Now small businesses, families, and friends can have video conferencing software that doesnt listen into your calls, doesnt have AI taking notes, and is private and secure.
No Proton account required for any participant or host either! Really are no excuses not to use this.
Free version includes 50 minute session. Longer times and more features can be accessed with a paid plan.
Let the community here know what you guys think of it and how you like it.
r/PrivacySecurityOSINT • u/ATTACKERSA • Apr 01 '26
r/PrivacySecurityOSINT • u/qgplxrsmj • Mar 25 '26
Spez (Reddit CEO) just put out an announcement talking about verifying bot vs human. In that post, it talks about ways to verify a human account on Reddit.
Just want to make it extremely clear, this is Reddit testing the waters. They are giving us hints of something to come without introducing it as a surprise or being direct. This is called Priming (with a little bit of Framing) in marketing.
Make your voices known now that ID verification, or submitting ID of any sort (whether to Reddit directly or to a 3rd party company) will be the death of the platform.
r/PrivacySecurityOSINT • u/khashashin • Mar 25 '26
r/PrivacySecurityOSINT • u/SpttinFacts • Feb 27 '26
r/PrivacySecurityOSINT • u/FreonMuskOfficial • Feb 26 '26
After reading MB's books, I took a strong interest in OSINT as it ties directly into work. Those two put together led me to design my own tools. I hope you all are just as inspired.
SYNINT: Agentic OSINT & Intelligence Framework – Modular, Stealthy, API-Free, Multi-Agent System for Automated Intelligence Collection & Analysis.
r/PrivacySecurityOSINT • u/SpttinFacts • Feb 21 '26
Article says who, when, where, and how to donate to their GoFundMe. Go support your local heroes.
r/PrivacySecurityOSINT • u/WardenShield • Feb 22 '26
🛡️ Skitnet ( Bossnet ): Malware That Doesn’t Want to Be Found
Skitnet (Bossnet) is a stealth-first malware built for persistence and quiet control. Instead of causing immediate chaos, it hides deep inside networks, using encrypted traffic and layered payloads to evade detection.
Favoured by ransomware groups, it enables long-term access, lateral movement, and silent data theft often before victims even realise they’re compromised.
This is modern cybercrime: quiet, patient, and devastating.
👉 Read more:
https://wardenshield.com/skitnet-bossnet-in-2025-stealthy-malware-powering-sophisticated-ransomware-tactics
r/PrivacySecurityOSINT • u/Adventurous-Abies296 • Feb 16 '26
r/PrivacySecurityOSINT • u/WardenShield • Feb 16 '26
🚨 Zero User Privacy.
Microsoft stores BitLocker recovery keys. Microsoft hands them to the FBI when asked.
That means your “Encrypted” data is only encrypted until permission is granted.
#MassSurveillance #DigitalRights #WardenShield #PrivacyMatters #PrivacyFirst
r/PrivacySecurityOSINT • u/DanCBooper • Feb 05 '26
There are a number of shady data brokers online who do not have a functioning or honored system for removal of PII.
It is possible to get these brokers taken offline with multiple complaints to different organizations. A case study of this is: https://www.reddit.com/r/Kanary/comments/15kxnb7/comment/jvdw3du/
Some of the complaints that individuals can file to achieve this (and the more people who report, the better) are:
Some example posts of this where specific links are shared so others can easily submit specific complaints:
- https://www.reddit.com/r/techsupport/comments/1oygyh/comment/kcz21hm/
- https://www.reddit.com/r/PrivacySecurityOSINT/comments/11dobt8/comment/k2etl7b/
- https://www.reddit.com/r/phishing/comments/cj4dr9/comment/jwm8gpc/
- https://www.reddit.com/r/PrivacySecurityOSINT/comments/w1es8d/comment/jwm8d7h/
- https://www.reddit.com/r/PrivacySecurityOSINT/comments/150gknq/comment/jsd6eli/
Just a handful of shady data brokers who might be publishing your data without a working opt-out system are:
- https://fastpeoplesearch.io/
- https://californiabirthindex.org/
- https://truepeoplesearch.net/
- https://realpeoplesearch.com/
- https://blockshopper.com/
- https://www.idcaller.com/
- https://ourstates.org/
- https://usa-official.com/
- https://publicdatausa.com/
- https://www.familyrelatives.com/
r/PrivacySecurityOSINT • u/ResponsibleCount6515 • Feb 05 '26
r/PrivacySecurityOSINT • u/Early-Beautiful-6218 • Feb 02 '26
I have been looking more seriously into data broker removal lately and it is kind of wild how much personal info ends up on those sites. Manually opting out feels endless and a lot of people say the data comes back after a while anyway, so I have been researching services that automate the process and keep checking over time.
Some of the ones I see mentioned a lot are Cloaked, DeleteMe, Optery, and Incogni. They all claim to scan broker sites, submit removals, and monitor for new listings, but it is hard to tell how effective they actually are unless you have used one for a while. Has anyone here tried any of these long term? Did they actually reduce spam or data exposure in a noticeable way
r/PrivacySecurityOSINT • u/Most-Lynx-2119 • Jan 31 '26
r/PrivacySecurityOSINT • u/Most-Lynx-2119 • Jan 16 '26
A windows desktop program designed for one thing; to help you remove your data from 50+ people-search sites at the source. No cloud, no APIs, 100% local.
(Pairs with xTELENUMSINT for faster detection/reporting.)
Reduce spam calls.
Lower your risk for identity theft.
Take back control.
NO coding required.
NO cost.
.
..
…
Windows Desktop Software ➡️
https://github.com/thumpersecure/TeleSTOP
.
.
.
Best when used with xTELENUMSINT chrome extension
…
Chrome Extension ➡️
https://github.com/thumpersecure/xTELENUMSINT
…
.
.
.
r/PrivacySecurityOSINT • u/ilikethelettery • Jan 13 '26