PRIVACY Logs
It re-recognizes users without storing anything on their device — using standard browser APIs that need no permission or consent.
What makes it stateless and stealthy:
API-based & consent-free — uses the standard HTML5 Canvas API; no special permission or user consent is require...
Q How does mobile app tracking fundamentally differ from web tracking?
Apps bypass the browser entirely — they have direct, privileged access to hardware sensors, OS APIs, and persistent storage, enabling far more comprehensive data collection than web tracking.
Why apps are more invasive:
No HTTP-based tracking — apps use proprietary communication...
Q Traffic and movement data are especially sensitive because they reveal where people go and when. Wha...
Three key techniques protect traffic data: differential privacy adds statistical noise, geo-fencing excludes sensitive areas, and thresholding sets minimum data volumes before publishing.
Differential Privacy.
Add carefully calibrated mathematical noise to datasets so that indivi...
Q Privacy by Design is a legal obligation. But what technologies actually make it work at a technical...
Privacy by Design rests on three technical pillars: anonymity technologies, privacy-preserving computations, and privacy policy enforcement.
* Tor onion routing, an anonymity PET. — Tga.D, CC BY-SA 4.0, via Wikimedia Commons. *
Anonymity technologies:
TOR for anonymous browsing...
Q Who bears responsibility for the OSINT threat landscape? Is it purely a technical problem to solve?
Everyone shares responsibility, from platform operators to individual users, and the concept of Privacy by Behaviour means each person must understand and manage their own OSINT exposure.
The strategic approach combines three layers:
Technical design. Privacy-preserving architec...
Q Looking at PETs, TOMs, Privacy by Design, and OSINT together, what is the overarching message about...
Privacy protection is a three-front battle, requiring technical tools like PETs, organizational frameworks like TOMs, and personal behavior awareness in the age of OSINT, and all three must work together.
Technical measures through PETs minimize data exposure at the source. Diffe...
Q A classic hands-on OSINT exercise goes "from pixel to person": starting from one social-media photo...
Two tasks: a location analysis (GEOINT) on the photo, and username tracking across platforms — using free tools like geospy.net, Google Reverse Image Search, and namevine.com.
Task 1: Location analysis (GEOINT).
You're given a photo the person posted and asked a deceptively simpl...
Q What are some go-to resources and communities for learning OSINT/SOCMINT techniques?
A small set of well-known practitioners and projects publish the field's working knowledge — Bellingcat, OSINTCurious, Week in OSINT, and IntelTechniques among them.
Because tools and platforms change constantly, staying current means following the people who track those changes....
Q What two forces — regulation and browsers — are killing the third-party cookie, and what is the busi...
GDPR requires explicit consent (fines up to 4% of annual revenue) and browsers (Safari ITP, Firefox/Edge by default, Chrome) systematically block third-party cookies, cutting personalized-ad revenue by 20–60%.
* The converging pressures killing the third-party cookie and the rev...
Q How does Safari's Intelligent Tracking Prevention (ITP) defend against browser fingerprinting?
Safari deliberately standardizes system configuration — generic user agent, rounded screen resolution, default fonts, and random "noise" added to canvas data — so devices look alike and are harder to single out.
The four standardizations:
User Agent — reports generic versions
Sc...