Video summary
Comment retrouver n'importe qui sur Internet ? (Sensibilisation OSINT)
Main summary
Key takeaways
Main ideas, concepts, and lessons
- Online anonymity is an illusion: The video argues that being “anonymous behind your screen” doesn’t hold up once identifiers are reused and data from different sources is linked together.
- OSINT (Open Source Intelligence): Introduces OSINT as a discipline used by investigative journalists, intelligence services, and cybercriminals—focused on searching and correlating public information rather than hacking.
- No malicious hacking (but serious tracing risk): The walkthrough is presented as legal OSINT intended to demonstrate how easily personal data can be assembled and how to protect oneself.
- User/data reuse creates an investigation path:
- Using the same nickname/username everywhere (“user reuse”) is described as the core vulnerability.
- Combining username → accounts → location hints → email → map/geolocation → identity is portrayed as a step-by-step “loop closure.”
- Geolocation via imagery and metadata: A mundane social post (photo) plus shadows, architecture, and mapping tools can narrow from city-level to a specific building.
- Email is “ultimate digital identity”: Reverse-searching an email can reveal connected Google services, reviews, and location-relevant patterns.
- French administrative transparency: In France, the video claims it can be easier to connect people to real identities via indexed public company/association records.
- Phishing threat scenario: If an attacker knows accurate personal details, they can craft highly convincing targeted phishing (e.g., “hello Guillaume, your package at …”).
- Protective guidance (“digital hygiene”):
- Compartmentalization (separate addresses for leisure vs. serious use).
- Don’t reuse usernames across platforms.
- Regular self-checking (search your own data using OSINT tools).
Practical methodology / step-by-step workflow (as demonstrated)
0) Setup: use safer searching conditions (anti-leak framing)
- Rule: Don’t do OSINT searches directly from your personal computer or home network.
- Reason: Clicking malicious links or exposing your IP could make the investigator identifiable (“hunter becomes prey”).
- Demonstrated approach: Use a VPS (described as a disposable/isolated “digital bunker”) so requests come from the VPS IP.
1) Start with a username (initial clue)
- Input example: A fictional nickname found in a YouTube comment (e.g., “xx retrogamer”).
- Goal: Expand the username into other online handles to discover more linked accounts.
2) Find other accounts using username reuse
- Step A: Run “Sherlock”
- A script/tool that queries many websites for the same username.
- Output is used to identify sites where the username appears.
- Note: may yield false positives and may miss sites if blocked.
- Step B: Check “What’s My Name”
- A web database to search the username and find associated profiles.
3) Pivot: use the most informative discovered platform(s)
- Concept: “pivot”
- Move from information set A to set B that opens new leads (e.g., from social profiles to marketplace location).
- Example pivot in the video: Vinted
- Marketplace profiles can include a location.
- Extract location like city (Lyon) from the profile.
- This narrows search scope from the whole world to a single city.
4) Extract contact identifiers (email) from forums/social bios
- Step: Check an older forum account profile for a listed email address.
- Claim: The video finds an email and treats it as a key identity anchor.
5) Reverse-search the email to reveal linked services and location signals
- Tool introduced: Epios (email reverse lookup described as “vicious/brilliant”).
- Process:
- Enter the email into Epios.
- It queries Google-linked services to find associations.
- Specific outputs highlighted:
- Public Google Calendar (if exposed)
- Google Maps reviews left by the user
- Inference: “pattern of life”
- If reviews exist for multiple nearby businesses (e.g., within ~300m), the person may live or work near the center of that triangle.
6) Automate/extend discovery with additional scripting (OL)
- Tool introduced: “OL” (name partially garbled in subtitles).
- What it does (as described):
- Automates checking “forgot password” on many popular sites using the target email.
- Interpretation:
- If it returns “unknown email” → likely not registered
- If it sends a recovery email → likely registered
- Outcome claimed: psychological/profile inferences
- Example inference targets:
- Strava → potentially athletic
- Dating site → possibly single
- Betting site → possibly gambler
- Example inference targets:
- Result: Add findings back into the Maltego graph for visualization.
7) Obtain more personal identifiers (phone number) via listings
- Method described: location + vehicle/objects + local classifieds
- If an old profile indicates a car model and location, search local classifieds (e.g., LeBoncoin).
- Look for ads posted by someone with similar username/first name.
- Contact/responses can reveal a phone number.
- Also mentioned: The same logic applies to apartment rentals.
8) Geoint (geolocation): from city/building to exact building
- Goal: Move from “Lyon (city/district)” to the exact building.
- Step A: Use a Twitter photo
- A photo with a view and shadows provides geometry cues.
- Look for identifiable elements:
- Street/route segment
- Opposite-side buildings/architecture
- A sign suggesting a tram/bus stop
- Step B: Use Google Earth (3D mode)
- Validate the building layout by matching the view.
9) Use shadows + time to identify the correct facade/floor context
- Tool introduced: “SunCalc” (called “suncalk” in subtitles).
- Method:
- Use the photo’s date/time (from tweet or metadata).
- Simulate the sun position and shadow direction.
- Align with observed shadows to confirm the photo angle and point to the building facade.
- Draw inference line from a shadow to the light source direction.
10) Close the loop: connect pseudonym to real identity via public records
- Claimed France-specific advantage: Administrative/public corporate data is indexed.
- Tools/websites mentioned:
- Papers.com (subtitle mentions “papers.com”)
- societe.com
- Method (as described):
- Use search queries on these services, sometimes through “Google dorks” style queries to find indexed documents.
- Search by elements like name fragments, Lyon, street name, and/or email/username.
- Download free documents (articles of association, general meeting minutes).
- Final linkage example described:
- Official document containing: full name, birth date, birth city, and current address.
11) Threat model: why attackers care
If malicious actors have real name, exact address, contextual details, and timestamps/behavioral patterns, targeted scams become more convincing (e.g., package delivery phishing).
Protection: “golden rules” recommended in the video (digital hygiene)
- Compartmentalization
- Use separate “junk/leisure” vs “serious” addresses for different purposes.
- Keep banking/tax/official matters on a dedicated serious address.
- Avoid username reuse
- Don’t use the same nickname/handle everywhere.
- Cleaning / self-audits
- Regularly “google yourself” by searching your:
- username
- Run your email through reverse/OSINT tools (video specifically recommends Epios / similar tools referenced).
- Regularly “google yourself” by searching your:
- Optional community call
- Join an “associationfr” community (mentioned as an investigative resource).
Speakers or sources featured (as named in subtitles)
- Host / narrator: “Franzo” (speaker and channel/person presenting the video)
- Sponsor mentioned: Hostinger (VPS provider)
Tools (named sources used in the demonstration)
- Maltego
- Sherlock
- What’s My Name
- Epios
- OL (script for automated password-recovery/registration checking)
- Overpass Turbo
- Google Earth (3D mode)
- Google Maps
- SunCalc
- Papers.com
- Societe.com
Communities/services referenced
- YouTube (video where the username was supposedly found)
- TikTok
- Spotify
- Tinder
- GitHub
- Vinted
- gbatemp.net
- LeBoncoin
- Google services (Calendar, Maps)