JIOWC/OPSEC Support  (OS)<br />Personal Data Aggregators<br />Joint Information Operations Warfare Center<br />OPSEC Suppo...
Personal Data Aggregators<br />
OPSEC Concerns<br />“But it’s personal information and not<br />mission or operational information!”<br /><ul><li>  Code o...
  Criminal Threat
 Coercion
 Surveillance
 Affiliation</li></ul>Bottom Line:<br />Personally Identifiable Information is critical/sensitive<br />
OPSEC Countermeasures<br /><ul><li>  Awareness
 Remove links from data aggregation sites  (if applicable)
 You usually can’t remove public record information
  Be cognizant of what information you are posting
 Don’t update incorrect information
 Keep yourself informed!</li></li></ul><li>Examples<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
SPOKEO.COM<br />Remove<br />Spokeo Data Link<br />
SPOKEO.COM<br />
SPOKEO.COM<br />Click  “Privacy”<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
SPOKEO.COM<br />
PEOPLEFINDER.COM<br />
Upcoming SlideShare
Loading in …5
×

OPSEC awareness data aggregation

2,137 views

Published on

Published in: Education
0 Comments
2 Likes
Statistics
Notes
  • Be the first to comment

No Downloads
Views
Total views
2,137
On SlideShare
0
From Embeds
0
Number of Embeds
1
Actions
Shares
0
Downloads
38
Comments
0
Likes
2
Embeds 0
No embeds

No notes for slide
  • Data aggregation refers to the phenomenon of single pieces of data collected into a whole that is more than the individual parts. Single pieces of personal data may not be damaging or even pose a threat, but when combined, that data may give a threat, whether it be criminal or otherwise, enough data to do some damage. Personal Data Aggregators on the internet pull all those bits of pieces together. They gather data from different resources (such as public records databases, social networking sites, and other internet databases) and present it as an easy to find, browse, and navigate package.
  • Personal data aggregators started off relatively harmless with sites offering no more than an address or telephone number. But recently, these sites have become adapt at pulling much more information. The data they return can include the basics such as address and telephone numbers to much more personal information such as religion, estimated wealth, and family information.
  • Many people will try to make the argument that personal data aggregators are not an OPSEC concern because it deals with personal information and not mission or operational information. However, personnel are part of the mission and operations!The Code of Conduct states that a US military member should give only their name, rank, service number, and date of birth if taken as a prisoner of war. In 1955, the US government understood that the more information the adversary had, the more apt they were to use that information against the individual or the US as a whole. If a service member were to be taken as a prisoner of war today, even if they only gave the adversary his or her name, rank, service number, and date of birth, how much more information do you think the adversary could get off the internet just using the information provided? Terrorists and nation states are not the only threats we face. Criminals can also use the personal information they find to cause us harm. If a criminal was to use data gathered from an aggregator and use that information to commit a crime against your family, how much of your time would that cost you away from work or even if you were at work, would you be able to focus on the mission?Adversaries could also use the information and conduct surveillance. Perhaps with what they observe, they could learn what your unit is doing by your activities. Are you preparing (i.e. visiting a law office, putting items in storage, getting a series of shots from a medical provider, visiting the Family Support Group, etc.) for a long TDY or deployment? Or maybe they could just use something they observed against you in order for you to provide them with more information?The bottom line is Personally Identifiable Information (PII) is critical and/or sensitive information and can be found on most organizations Critical Information List (CIL).
  • The best countermeasure is awareness. Go out and find what information exists about you and your family. To start with, “Google” yourself and your family. Then, search for yourself and your family members on these personal data aggregation sites.Some sites, such as spokeo.com and peoplefinder.com, will allow you to remove the link(s) to your information from their sites. However, if you do this, remember that you are not actually removing the information from the databases where these sites got the information. You are only removing the compilation of the data from their site. Usually, you can only remove “public record” information with a court order under certain circumstances. Also, remember to remove the links to your family members information if applicable.Be aware of what information you post and what information you share with others. Inform your family members of the risk this type of information can present when compiled.Some personal data aggregation sites allow you to “correct” information that they have compiled about you. Do not correct this information. If you can’t remove the information, at least the information will be incorrect.Keep yourself informed by periodically “googling” yourself and your family members. Google offers a “Google alerts” service. With this, you can set up keyword lists that Google will alert you too if their web crawler comes across one of these keywords. Again, don’t forget about your family members!
  • Lets take a look at two examples,spokeo and peoplefinders.
  • Spokeo, according to its website, is a search engine specializing in aggregating and organizing vast quantities of people-related information from a large variety of public sources. The public data is amassed with lightning speed, and presented almost instantly in an integrated, coherent, and easy-to-follow format.Spokeo aggregates data from hundreds of online and offline sources, including but not limited to: phone directories, social networks, marketing surveys, mailing lists, government censuses, real estate listings, and business websites. All of the data aggregated is publicly available, and accessible by anyone from those respective sources. Finding, consolidating, and organizing all of the data meaningfully, however, could take an individual weeks, whereas Spokeo automates the data aggregation process and offers it at lightning speed.
  • When you search for an individual by name, Spokeo returns all the results from the entire US.
  • You can then click on the state links on the left to further refine your results to the listings of that particular name in the cities/towns in that state.
  • Then Spokeo will lists all the known individuals with that name in that city/town. In this example, there is only one instance of a particular person in San Antonio, TX. The map on the right shows the address of that particular individual in that city/town.
  • When you click on the result on the left hand side of the screen, a box will pop-up over the map containing the information on that individual. Some of the information is free but in order to see all the information, a user would have to purchase a membership from Spokeo. You can buy a membership for 3 months, 6 months, or a year and are $14.85, $23.70, and $35.40 respectively.
  • Copy the entire URL from your browsers address bar thatshows the name and city and state of the listing you want deleted from Spokeo.
  • At the bottom right of the web page, there are some links, to include About, Blog, Directory, Privacy, Terms, Help, and Contact. Click on the Privacy link.
  • The Privacy link will take you to the page where you can remove a listing. Simply paste in the URL, provide an email address where you can receive a verification link, and type the captcha code. Once you have all the fields filled in, click the “Remove Listing” button.
  • Once you click the button, a new, but very similar screen, will appear. The only noticeable difference you will see is the text from the captcha box will be gone and a confirmation message (“Please check your email for further instructions.”) will appear below the captcha box.
  • Open your email where you had the verification link sent. You should have an email with a subject line of “Spokeo Directory Removal Confirmation”. Open the email and click the link in the middle where it says “To complete the removal process, please click here.”
  • Once you click on the link in the email, a web page should pop up that looks like the one shown here. Notice it is the same URL with the name, city, and state of the information you removed.
  • The removal should be instantaneous. To be sure, try to search for the name in the same city and state again. The listing you had removed should no longer be listed.
  • One thing to note, in order to prevent “abuse”, Spokeo limits the number of privacy removal request per email address to three. You may have to use separate email addresses to remove all your information from Spokeo if you have lived in lots of different locations.Another interesting observation is Spokeo asks government officials to use a .gov email address for priority processing. Due to OPSEC concerns, and because removal is instantaneous with a regular email address, the JIOWC/OS highly recommends that you do not use an official email address.
  • Peoplefinder.com is a one stop resource for free people searching on the web. People Finder claims to have indexed billions of publicly available records and provides a simple format to search for up to 80% of people currently residing in United States. In addition to the free people search and free white pages, People Finder has search portals for all other public records services. Public records include background checks, criminal records, cell phone directory, and more.
  • To begin with, type in the First and Last name of the person you are searching for. In addition, input the city or zip code of the person and the state.
  • The results, to include name, address, and phone number will appear for free. For additional information, you can purchase separate reports for such things as criminal history.
  • To remove your compilation link, go back to the main page, www.peoplefinder.com, and at the bottom of the page, click the “Remove Me” link.
  • On the resulting page, fill out the form presented and submit the form.
  • Once you click “Remove Me” on the previous page, you should receive a “Submission Accepted” page. Notice that it says it will take 1 business day to remove your information. Allow it a couple business days to remove the compilation link and then go back and check to ensure your information was removed. Again, don’t forget to remove your family members information.
  • OPSEC awareness data aggregation

    1. 1. JIOWC/OPSEC Support (OS)<br />Personal Data Aggregators<br />Joint Information Operations Warfare Center<br />OPSEC Support Directorate<br />This Presentation is UNCLASSIFIED<br />
    2. 2. Personal Data Aggregators<br />
    3. 3. OPSEC Concerns<br />“But it’s personal information and not<br />mission or operational information!”<br /><ul><li> Code of Conduct
    4. 4. Criminal Threat
    5. 5. Coercion
    6. 6. Surveillance
    7. 7. Affiliation</li></ul>Bottom Line:<br />Personally Identifiable Information is critical/sensitive<br />
    8. 8. OPSEC Countermeasures<br /><ul><li> Awareness
    9. 9. Remove links from data aggregation sites (if applicable)
    10. 10. You usually can’t remove public record information
    11. 11. Be cognizant of what information you are posting
    12. 12. Don’t update incorrect information
    13. 13. Keep yourself informed!</li></li></ul><li>Examples<br />
    14. 14. SPOKEO.COM<br />
    15. 15. SPOKEO.COM<br />
    16. 16. SPOKEO.COM<br />
    17. 17. SPOKEO.COM<br />
    18. 18. SPOKEO.COM<br />
    19. 19. SPOKEO.COM<br />Remove<br />Spokeo Data Link<br />
    20. 20. SPOKEO.COM<br />
    21. 21. SPOKEO.COM<br />Click “Privacy”<br />
    22. 22. SPOKEO.COM<br />
    23. 23. SPOKEO.COM<br />
    24. 24. SPOKEO.COM<br />
    25. 25. SPOKEO.COM<br />
    26. 26. SPOKEO.COM<br />
    27. 27. SPOKEO.COM<br />
    28. 28. PEOPLEFINDER.COM<br />
    29. 29. PEOPLEFINDER.COM<br />
    30. 30. PEOPLEFINDER.COM<br />
    31. 31. PEOPLEFINDER.COM<br />Remove<br />People Finder Data Link<br />
    32. 32. PEOPLEFINDER.COM<br />Click “Remove Me”<br />
    33. 33. PEOPLEFINDER.COM<br />
    34. 34. PEOPLEFINDER.COM<br />
    35. 35. Personal Data Aggregators<br />These are just two examples of information data aggregation services that are currently available on the Internet. Although you have removed the information from Spokeo and People Finder, remember that they obtained this information from publicly available sources. Therefore, this type of information still exists somewhere in a publicly accessible database. <br />
    36. 36. Personal Data Aggregators<br />If you have any further questions, feel free to contact the JIOWC/OS.<br /> 2 Hall Blvd Suite 217 <br />San Antonio, TX 78243-7074 <br />Phone: 210.977.5544/5653 (DSN 969) <br />Fax: 210.977.6506 <br />osstaff@jiowc.osis.gov<br />

    ×