Leveraging OSINT to access compromised passwords
We need to start this discussion with an important set of caveats about Operational Security (OPSEC). The idea behind OPSEC is to ensure you avoid the compromise of your personal information, or information related to your systems, when engaging in work online. This section will involve accessing resources on the internet that may be…sketchy in some cases. There are things you can and should do to mitigate the risk of using these kinds of content, and while this section will not cover this in exhaustive detail, it will mention key controls you should consider utilizing. However, you (and only you) are responsible for the security of your own systems!
Many individuals will have many different opinions on this topic – and they all have some validity. Your individual position and risk model may be different. However, once you go beyond some typical internet-facing sites such as haveibeenpwned.com
, you need to consider what...