banner
kasstoner.bsky.social
@kasstoner.bsky.social
Reposted
Today, a new OSINT lesson with MJ landed in the inboxes of our paid subscribers. This one takes you on a journey to answer the question: Is the sex worth the OPSEC risk? Subscribe today and find out.

www.bullshithunting.com/p/a-free-osi...
A Free OSINT Lesson: How Your "Friend with Benefits" Became an Insider Threat
The sex is great though...
www.bullshithunting.com
July 30, 2025 at 6:24 PM
Reposted
God I mourn 2019 Twitter.
August 12, 2025 at 5:37 PM
Reposted
In all inboxes: The Trick to Cooperation. Systems may run on routine, but for those pulled into them, that routine can feel destabilizing and demeaning. Today, Kennedy reflects on what it means to navigate a case from the other side, from the witness stand.

www.bullshithunting.com/p/the-trick-...
The Trick to Cooperation
How clarity and compassion creates results
www.bullshithunting.com
September 24, 2025 at 3:19 PM
Reposted
🚨NEW!

From @kennedycatherine.bsky.social and arguably one of her best: open.substack.com/pub/bullshit...
The Trick to Cooperation
How clarity and compassion creates results
open.substack.com
September 24, 2025 at 3:21 PM
Reposted
🚨NEW! From yours truly and @kennedycatherine.bsky.social

A Fake Prince, a Game Show Contestant and the Devil

open.substack.com/pub/bullshit...
A Fake Prince, a Game Show Contestant and the Devil
How an intelligence officer's trivia show winnings were a gift to us all
open.substack.com
October 1, 2025 at 2:40 PM
Reposted
Going no-contact with my partner for a week (she left her phone in an Uber on the way to the airport , leaving me to negotiate over the phone with the driver I found on Instagram to get the phone back, a man who seemingly believed I could have psychic knowledge of a strangers phone)
October 25, 2025 at 6:04 PM
Reposted
👏 NEW! Witchgrass - a podcast from us pirates on the Permanent Record Research crew, featuring @kennedycatherine.bsky.social and @mjbanias.bsky.social.

A cold, Canadian story that will teach you how us maniacs do what we do.

Wherever you get your podcasts:

open.spotify.com/episode/4vWj...
Witchgrass: Episode One
open.spotify.com
October 30, 2025 at 4:53 PM
Reposted
deck.blue is the 3rd-party TweetDeck for Bluesky!

- Multi-column & multi-account
- Bookmark posts
- Chat/DM columns
- Disable reposts
- #hashtag columns
- Keyboard shortcuts
- Color themes
- Gallery/Grid Mode
- Filter notifications by type
- Inline translations
- Scheduling

Patreon | Ko-fi
deck.blue
Get the most out of Bluesky with a multi-column layout
deck.blue
December 23, 2024 at 6:58 PM
Reposted
Got an image from a conflict zone? Stop guessing the location. Use Maxar satellite imagery for context and LiDAR data to literally see through tree cover. That's the advanced geolocation OSINT tradecraft we get into this week. Theosintoutput.com

#podcast #geolocation #osint #imagery
The OSINT Output Hosted by Tim and Chris
Join Tim and Chris as they share the latest updates on open-source intelligence, new content, and opportunities for collaboration. Discover insights, connect with us, and gather fresh ideas for you…
Theosintoutput.com
November 10, 2025 at 7:32 PM
Reposted
The Human is the Most Obvious Vulnerability. (They literally just called and pretended to be IT.) The Scattered Lapis Hunters hack on Salesforce was pure social engineering genius. They stole a database of CEOs and government contacts. Listen now: theosintoutput.com

#podcast #socialengineering
The OSINT Output Hosted by Tim and Chris
Join Tim and Chris as they share the latest updates on open-source intelligence, new content, and opportunities for collaboration. Discover insights, connect with us, and gather fresh ideas for you…
theosintoutput.com
November 13, 2025 at 9:41 PM
Reposted
If you use WhatsApp, assume your number is already in someone's database.
Source: www.wired.com/story/a-simp...
November 18, 2025 at 4:48 PM
Reposted
What you can do NOW: Go to WhatsApp Settings > Privacy and set your profile photo, about info, and status to "My Contacts" or "Nobody." This won't hide your number, but it limits what strangers can see. This is recommended as well for platforms like Telegram & Signal.
November 18, 2025 at 4:48 PM
Reposted
Meta's response? They thanked the researchers and called it "basic publicly available information." They fixed rate limiting in October 2024, but provided no evidence they stopped malicious actors from doing the same scraping over the years...
November 18, 2025 at 4:48 PM
Reposted
Who's at risk? Scammers of course have a goldmine. But worse: researchers found 2.3M WhatsApp numbers in China & 1.6M in Myanmar...countries where the app is banned. Governments could hunt down users. People in China have been detained just for having WhatsApp installed.
November 18, 2025 at 4:48 PM
Reposted
Not only numbers were exposed. 57% of accounts had profile photos, 29% had public bio text. In India, 62% had exposed photos. In Brazil, 61% had photos exposed. Most users don't enable privacy settings (More on this soon...)
November 18, 2025 at 4:48 PM
Reposted
A researcher warned WhatsApp about this exact vulnerability in 2017. Meta dismissed it, saying privacy settings were "working as designed" Fast forward 8 years later, still vulnerable until October 2024 😅
November 18, 2025 at 4:48 PM
Reposted
Here's how simple it was: WhatsApp lets you check if a phone number is registered. Researchers automated this for every possible number combination at ~100 million checks per hour. Meta had ZERO effective rate limiting in place (because why would anyone want that?)
November 18, 2025 at 4:48 PM
Reposted
🚨 MASSIVE: Researchers scraped 3.5 BILLION WhatsApp phone numbers using the app's contact discovery feature, along with profile photos and bios for millions of people. This would be "the largest data leak in history" if it hadn't been done by researchers 🧵
November 18, 2025 at 4:48 PM
Reposted
The problem with that, too, is if there's a clear enough pattern of life with the phone, you can use the absence of its movement and identification at a second location as probative information.
September 17, 2025 at 3:51 PM
This. If people don't realize what kind of databases/websites are online. As someone in the #osint community there is SO much
People radically underestimate the sophistication of OSINT tools that aren't "looking at posts on the internet" and with a few pictures of your location and trajectory through an area, someone could connect you to your device in maybe an hour or so.
September 18, 2025 at 9:23 AM
Reposted
People radically underestimate the sophistication of OSINT tools that aren't "looking at posts on the internet" and with a few pictures of your location and trajectory through an area, someone could connect you to your device in maybe an hour or so.
September 17, 2025 at 3:49 PM
Reposted
Yes more pls 🙏 How should citizens be intentional and skeptical online as law enforcement and government surveillance expand in “Trump’s America”? How should we be vigilant w encryption and digital hygiene since SSA data, AI, Palantir, and Israeli tech increase risks?

This seems a helpful resource:
We study mass surveillance for social control, and we see Trump laying the groundwork to ‘contain’ people of color and immigrants
Create a moral panic. Blame it on certain people. Commence monitoring. Deploy droves of security agents. Detain or remove the targets. Sound familiar?
dornsife.usc.edu
September 16, 2025 at 4:11 AM
Reposted
I am always trying to share tips—plus legal + political insights. If you found this helpful, follow me @elizaorlins.bsky.social for more. ✨
September 15, 2025 at 4:58 AM
Reposted
You don't have to stop sharing online. Just be intentional about what you post and when.

I have a whole TEDx talk on unlawful surveillance, so let me know if you want more tips about how the government may be surveilling you.
September 15, 2025 at 4:58 AM
Reposted
10. Financial & identity protection: Never share financial info, full birthdates, or other verification details online. Don't take online quizzes and watch for scams using your publicly available information.
September 15, 2025 at 4:58 AM