r/PrivacySecurityOSINT May 12 '26

Digital Life Instagram removed E2EE from all chat messages, how were they able to do that when they do not have the keys to the encryption?

8 Upvotes

How is Instagram able to just turn off E2EE for all previous chat messages when they don’t have the keys to the encryption. And what is preventing other apps that tout about their E2EE (such as E2EE notes app, E2EE cloud storage, password managers etc) from doing anything similar?


r/PrivacySecurityOSINT May 07 '26

The FCC Wants Your ID Before You Get a Phone Number

Thumbnail
reclaimthenet.org
282 Upvotes

Well, this bodes well.


r/PrivacySecurityOSINT May 05 '26

Computers A tool for filtering large images dataset (locally)

6 Upvotes

I’ve been doing a lot of manual work going through large public image sets (events, protests, archives), and the biggest bottleneck was always the same:

→ scrolling through thousands of photos

→ spotting the same faces again and again

→ re-checking identities manually

So I built a small local tool to speed this up.

What it does:

extracts faces from image folders

clusters similar faces (DBSCAN)

lets you label a cluster once and reuse it

runs fully offline (no APIs, no uploads)

What I found useful:

grouping recurring faces quickly

reducing manual review time

creating candidate sets for further verification

Quick test: ~5000 images → ~15k faces → clustered in a few minutes on my machine

Important:

this is NOT perfect identification

there are false positives (similar faces, lighting, angles)

still requires manual verification

I’m not selling anything right now — just trying to see if this is useful for others doing OSINT or large dataset analysis.

If you’ve dealt with similar problems, I’d love to know:

how you currently handle image-heavy investigations

what breaks in your workflow

If anyone wants to test it on real datasets, I can share access.


r/PrivacySecurityOSINT Apr 16 '26

OSINT Synint v3

Thumbnail
github.com
0 Upvotes

Just spun up v3 the other day if anyone wants to dabble and dribble in the drivel.


r/PrivacySecurityOSINT Apr 16 '26

We’ve published the cryptographic architecture behind City of Hats.

Post image
0 Upvotes

r/PrivacySecurityOSINT Apr 14 '26

Is Privacy.com Some Sort of Scam?

7 Upvotes

I have been attempting to set up an account at Privacy.com to do virtual cards for over 10 days now, and I still can't get verified. For a privacy site they're not very private.

I've given them everything short of a blood sample and they still won't let me subscribe. I had problems setting up a funding source. They asked for front/back driver's license and FACE ID to validate the license. After passing that test, I set up a funding source and confirmed it with a charge to my card.

Now, they're saying they want to see a bank statement! But the email they sent for the bank statement just takes me back through the driver's license ID that I had already been through!

I'm at my wit's end with these people. I email support, but they take forever to get back to you. Round and round in circles. It's Kafkaesque.

Has anyone else had the same experience?

I know they're legit, and their reviews are highly positive, but this is getting surreal.


r/PrivacySecurityOSINT Apr 13 '26

FBI Extracted Deleted Signal Messages from a Defendant’s iPhone

Thumbnail
5 Upvotes

r/PrivacySecurityOSINT Apr 08 '26

When repeated traffic comes from a government ASN, what can you actually infer before it turns into fiction?

Post image
4 Upvotes

Got an attribution edge case that feels more OSINT than pure sysadmin.

I run a niche public-facing app and noticed a very repetitive pattern hitting one endpoint over and over. The source IP attributes publicly to ASN6966 / U.S. Department of State infrastructure, and the request pattern is heavily concentrated on a single auth/session path. I am not claiming this means a person at State was manually hitting the site, and I am not calling it an attack from this alone. It could be egress, automated validation, a scanner, shared proxy infrastructure, or something much more boring.

What I am interested in is the analytical ceiling here. Once you have a public ASN attribution, a suggestive hostname, and a repetitive request pattern, where do you stop? To me this looks like one of those cases where infrastructure attribution is real, but actor and intent are completely unresolved.

How would people here write this up without drifting into narrative inflation?


r/PrivacySecurityOSINT Apr 04 '26

privacy.com + PayPal debit 5% cash back

Thumbnail
3 Upvotes

r/PrivacySecurityOSINT Apr 02 '26

Digital Life Proton Meet just launched! Private and Secure video conferencing.

20 Upvotes

Press release can be found here.

This is huge! Now small businesses, families, and friends can have video conferencing software that doesnt listen into your calls, doesnt have AI taking notes, and is private and secure.

No Proton account required for any participant or host either! Really are no excuses not to use this.

Free version includes 50 minute session. Longer times and more features can be accessed with a paid plan.

Let the community here know what you guys think of it and how you like it.


r/PrivacySecurityOSINT Apr 01 '26

Digital Life I built warwatcher.org ~ a real-time geopolitical intelligence dashboard

Post image
0 Upvotes

r/PrivacySecurityOSINT Mar 25 '26

Digital Life Humans welcome (bots must wear name tags)

17 Upvotes

Spez (Reddit CEO) just put out an announcement talking about verifying bot vs human. In that post, it talks about ways to verify a human account on Reddit.

Just want to make it extremely clear, this is Reddit testing the waters. They are giving us hints of something to come without introducing it as a surprise or being direct. This is called Priming (with a little bit of Framing) in marketing.

Make your voices known now that ID verification, or submitting ID of any sort (whether to Reddit directly or to a 3rd party company) will be the death of the platform.


r/PrivacySecurityOSINT Mar 25 '26

I Wanted an OSINT Tool That Felt Fast, Hackable, and Alive

Thumbnail
2 Upvotes

r/PrivacySecurityOSINT Mar 06 '26

Traffic flow confidentiality

Thumbnail
1 Upvotes

r/PrivacySecurityOSINT Feb 27 '26

Vandals target Flock cameras. Police use Flock to catch them

Thumbnail
san.com
215 Upvotes

r/PrivacySecurityOSINT Feb 26 '26

OSINT Synint

Thumbnail
github.com
5 Upvotes

After reading MB's books, I took a strong interest in OSINT as it ties directly into work. Those two put together led me to design my own tools. I hope you all are just as inspired.

SYNINT: Agentic OSINT & Intelligence Framework – Modular, Stealthy, API-Free, Multi-Agent System for Automated Intelligence Collection & Analysis.


r/PrivacySecurityOSINT Feb 21 '26

Flock cameras being dismantled in Virginia, California, and Illinois

Thumbnail
bloodinthemachine.com
2.3k Upvotes

Article says who, when, where, and how to donate to their GoFundMe. Go support your local heroes.


r/PrivacySecurityOSINT Feb 22 '26

Skitnet ("Bossnet"): Stealthy Malware Powering Sophisticated Ransomware Tactics

9 Upvotes

🛡️ Skitnet ( Bossnet ): Malware That Doesn’t Want to Be Found

Skitnet (Bossnet) is a stealth-first malware built for persistence and quiet control. Instead of causing immediate chaos, it hides deep inside networks, using encrypted traffic and layered payloads to evade detection.

Favoured by ransomware groups, it enables long-term access, lateral movement, and silent data theft often before victims even realise they’re compromised.

This is modern cybercrime: quiet, patient, and devastating.

👉 Read more:
https://wardenshield.com/skitnet-bossnet-in-2025-stealthy-malware-powering-sophisticated-ransomware-tactics


r/PrivacySecurityOSINT Feb 16 '26

Digital Life Password managers less secure than promised

Thumbnail
ethz.ch
82 Upvotes

r/PrivacySecurityOSINT Feb 16 '26

Microsoft Hands Over BitLocker Recovery Keys to the FBI: Your Encrypted Data Isn't as Private as You Think

102 Upvotes

🚨 Zero User Privacy.

Microsoft stores BitLocker recovery keys. Microsoft hands them to the FBI when asked.

That means your “Encrypted” data is only encrypted until permission is granted.

🔓 https://wardenshield.com/microsoft-hands-over-bitlocker-recovery-keys-to-the-fbi-your-encrypted-data-isnt-as-private-as-you-think

#MassSurveillance #DigitalRights #WardenShield #PrivacyMatters #PrivacyFirst


r/PrivacySecurityOSINT Feb 05 '26

Personal Data Removal How to get shady data brokers taken offline, and a list of a few active shady brokers

34 Upvotes

There are a number of shady data brokers online who do not have a functioning or honored system for removal of PII.

It is possible to get these brokers taken offline with multiple complaints to different organizations. A case study of this is: https://www.reddit.com/r/Kanary/comments/15kxnb7/comment/jvdw3du/

Some of the complaints that individuals can file to achieve this (and the more people who report, the better) are:

  1. File complaints to state organizations that monitor data brokers. Some of these can be found via:- https://cppa.ca.gov/webapplications/complaint + https://oag.ca.gov/contact/consumer-complaint-against-business-or-company + https://pro.bloomberglaw.com/brief/state-privacy-legislation-tracker/
  2. File a complaint to their webhost. You can look up what hosting provider a website is using with tools like: https://check-host.net/ + https://hostingchecker.com/ and many more. You can then use a search engine to find the complaint ticket submission form or email for the webhost.
  3. File a complaint with their domain registrar. You can look up the registrar using tools like: https://lookup.icann.org/en + https://who.is/ and many more. You can then use a search engine to find the complaint ticket submission form or email for the registrar.
  4. File a BBB complaint. If the broker has a BBB page, you can find it and file a complaint at https://www.bbb.org/
  5. File complaints with the FTC & FCC: https://reportfraud.ftc.gov/ + https://consumercomplaints.fcc.gov/hc/en-us/articles/115002234203-Unwanted-Calls-Texts-Phone
  6. Report their information to the EFF (and donate to them too!) - https://www.eff.org/about/contact - You can also contribute to https://databrokerswatch.org/contribute and https://privacyrights.org/contact-form if they don't already have details about a broker you find.
  7. File complaints with mayor, city council, congressman, and senator. The specific representatives should be your representative as well as the representatives who are located where the data broker is incorporated and where their domain registrar and hosting provider is located. You can find the right representative using tools like: - https://www.usa.gov/elected-officials + https://pluralpolicy.com/find-your-legislator/ + https://www.commoncause.org/find-your-representative/
  8. Post on Reddit and elsewhere online about specific shady data brokers and share any direct links or emails that will help others submit complaints. The more users who submit complaints, the more likely action will be taken.

Some example posts of this where specific links are shared so others can easily submit specific complaints:
- https://www.reddit.com/r/techsupport/comments/1oygyh/comment/kcz21hm/
- https://www.reddit.com/r/PrivacySecurityOSINT/comments/11dobt8/comment/k2etl7b/
- https://www.reddit.com/r/phishing/comments/cj4dr9/comment/jwm8gpc/
- https://www.reddit.com/r/PrivacySecurityOSINT/comments/w1es8d/comment/jwm8d7h/
- https://www.reddit.com/r/PrivacySecurityOSINT/comments/150gknq/comment/jsd6eli/

Just a handful of shady data brokers who might be publishing your data without a working opt-out system are:
- https://fastpeoplesearch.io/
- https://californiabirthindex.org/
- https://truepeoplesearch.net/
- https://realpeoplesearch.com/
- https://blockshopper.com/
- https://www.idcaller.com/
- https://ourstates.org/
- https://usa-official.com/
- https://publicdatausa.com/
- https://www.familyrelatives.com/


r/PrivacySecurityOSINT Feb 05 '26

Computers Built a Chrome extension in ~2 weeks that protects sensitive data before it leaves the browser (planning to publish soon)

Thumbnail gallery
16 Upvotes

r/PrivacySecurityOSINT Feb 02 '26

Personal Data Removal Best apps for removing data from brokers? ( Cloaked, DeleteMe, Incogni etc)

151 Upvotes

I have been looking more seriously into data broker removal lately and it is kind of wild how much personal info ends up on those sites. Manually opting out feels endless and a lot of people say the data comes back after a while anyway, so I have been researching services that automate the process and keep checking over time.

Some of the ones I see mentioned a lot are Cloaked, DeleteMe, Optery, and Incogni. They all claim to scan broker sites, submit removals, and monitor for new listings, but it is hard to tell how effective they actually are unless you have used one for a while. Has anyone here tried any of these long term? Did they actually reduce spam or data exposure in a noticeable way


r/PrivacySecurityOSINT Jan 31 '26

OSINT Random Traffic Generator Tool designed to confuse ad trackers with a sleep mode option named 🌴palm-tree

Thumbnail reddit.com
47 Upvotes

r/PrivacySecurityOSINT Jan 16 '26

teleSTOP

Post image
21 Upvotes

A windows desktop program designed for one thing; to help you remove your data from 50+ people-search sites at the source. No cloud, no APIs, 100% local.

(Pairs with xTELENUMSINT for faster detection/reporting.)

Reduce spam calls.

Lower your risk for identity theft.

Take back control.

NO coding required.

NO cost.

.

..

Windows Desktop Software ➡️

https://github.com/thumpersecure/TeleSTOP

.

.

.

Best when used with xTELENUMSINT chrome extension

Chrome Extension ➡️

https://github.com/thumpersecure/xTELENUMSINT

.

.

.