Entries

2026-10-10

No more full-screen agreement; cleaner summaries; SerpApi case status

  • Slim notice instead of a full-screen gate. First-time visitors no longer have to click through an Acceptable Use Agreement before seeing the page. The same terms (lawful use only; no stalking, harassment, doxxing or FCRA purposes) now sit in one slim bar at the bottom, combined with the cookie choice, with an Italian courtesy translation where relevant. Every tool page keeps its own disclaimer.
  • Duplicate summaries removed. The Google Dorks, Search Engine Landscape and Tool Graveyard guides each opened with two near-identical summaries; each now has one, with nothing lost. The Tool Graveyard's later summary said “roughly twenty” degraded tools while the top said ~27 (the October re-check figure); the duplicate count was removed.
  • Google Dorks guide: the SerpApi lawsuit section said a hearing was “set” for 29 September. It now says SerpApi’s renewed motion to dismiss (filed 24 August) is pending, that no ruling had been published as of 10 October, and links the court docket.
2026-10-10

Human-reader pass: tools first, quieter citations, shorter sentences

  • Why. The site's SEO/GEO methodology now includes human-reader optimisation: fewer people click through from search, so each visit has to work. Every page was measured on a 375px phone screen.
  • Tools first. On 44 tool pages the explanation boxes, update notes, related links and the top ad slot now sit below the tool instead of above it. The median tool page now shows its input on the first phone screen (was 1.2 screens down); pages with the input below the first screen fell from 57 to 27.
  • Quieter citations. Inline source links stay on every claim but render smaller and in body colour, so sentences read without bright mid-sentence links.
  • Shorter sentences. The six most-visited guides (Username OSINT, Wayback Machine, Google Dorks, Search Engine Landscape, Tool Graveyard, Fake Image Detection) were edited so almost no sentence runs over 25 words, with technical terms explained at first use. Wording only: no facts, numbers, links or dates changed, so their “Last updated” dates stay as they were.
  • Layout stability. The HIBP Catalog and URL Pivot Encyclopedia no longer jump as their live counters load.
2026-10-10

New dataset: 345 police statements on license plate reader rules

  • Police Statements on ALPR Rules compiles every public law-enforcement response we could find to Missouri’s Executive Order 26-18 (22 statements from 11 agencies and groups, none opposed) and to similar actions nationwide: Florida’s state-road removal order, Texas’s funding pause, Washington’s SB 6002, Connecticut’s new law and others. 345 statements from 294 agencies and groups in 48 states and DC, coded for stance, retention, commitments, outcomes and every number cited.
  • Recurring figures tracked: 30-day retention (30 of 48 agencies that named a period), Flock’s switch to a 7-day default, case numbers per search, audit frequency, out-of-state and immigration-related search counts. The 30 quotes on the page were re-checked word for word; the full data is free as CSV and JSON.
2026-10-10

Four new tools and six new guides from a demand check of 74 ideas

  • Method. 74 candidate topics were scored by how early Google, Bing, DuckDuckGo and YouTube autocomplete suggest them, and checked against this site’s own Search Console queries. These pages were picked for demand, fit and a gap on the site.
  • New tools: Email Header Analyzer (trace Received hops and IPs, read SPF, DKIM and DMARC results, spot Reply-To tricks; parsed in your browser); AI Image Detector (reads C2PA Content Credentials, IPTC AI labels and Stable Diffusion/ComfyUI data locally and reports evidence, not a score); Public Records Search by State (official inmate, sex offender, court and LLC portals for all 50 states and DC, 199 of 204 links verified at the source); Codice fiscale e partita IVA (calcolo, codice fiscale inverso e verifica, in Italian).
  • New guides: Remove Yourself From Google & Blur Your House; comparisons for Intelbase, OSINT Industries, Epieos, the IntelTechniques Search Tool and OSINT Framework, each quoting the vendor’s own published pricing and saying where the paid tool is better.
  • Known gaps, stated on the pages: the codice fiscale tool decodes foreign-birth Z codes without country names, because ISTAT’s download for that list is no longer available; five state portals (South Dakota inmate locator, Oklahoma, South Carolina and Tennessee courts, Virginia business search) are marked “not verified yet” rather than guessed; no official Bing Streetside blur route could be found.
  • Site: 93 tools and 62 guides; the “Continue” boxes on 44 older pages had out-of-date totals (50 guides, 79 tools), now corrected.
2026-10-10

October demand harvest: one new tool, four new guides, three refreshes

  • Method. Autocomplete was harvested from Google, Bing, DuckDuckGo and YouTube on 10 October (327 seeds, 9,066 suggestions), then scored on demand, absence of a good existing answer, and whether it could be sourced properly. Pages were built around the questions people actually typed.
  • New tool: Is This Website Legit? Evidence Checker shows domain age, first certificate, archive history, DNS and email setup, hosting and look-alike hints as evidence, and deliberately gives no safety score.
  • New guides: Is My Phone Being Tracked? (vendor-free iPhone and Android checklist with a survivor-safety section); Can Wi-Fi See You Through Walls? (what the research showed versus what ships); Drone Overhead? Remote ID and ADS-B; Pig Butchering Scams (stages, IC3 2025 figures, tracing and where to report).
  • Refreshed: the Flock guide covers the “De-Flock” Halloween posts and the law on damaging cameras, adds October cancellations (Milton, Lafayette, Reno) and updates the Institute for Justice count to 265; the age-verification guide now covers how Discord and Roblox check age; Face Finder adds a sourced comparison of PimEyes, FaceCheck.ID and Lenso.ai with opt-out steps.
  • Corrections found along the way: the UK fraud reporting service is now Report Fraud (it replaced Action Fraud in December 2025), and the FTC’s ReportFraud site showed a government-shutdown notice on 10 October; both new scam pages say so with the date.
2026-10-10

New guide: Tor and Onion OpSec for Investigators

  • Tor and Onion OpSec for Investigators (2026): what Tor hides and what it doesn't, Tor Browser security levels, bridges and Snowflake, Tails vs Whonix vs Qubes, why downloaded files are the classic leak, keeping research identities separate, verifying onion addresses, and how real operators were identified, sourced to court opinions and Justice Department releases. Every claim links the Tor Project, project or court document it rests on.
  • Correction: the dark web OSINT guide suggested adding a VPN to Tor. The Tor Project advises against that unless you are an advanced user; the line now says so and links the new guide.
2026-10-10

Three new dark-web investigation tools

  • Tor Relay Lookup. Enter an IP, relay fingerprint, nickname or AS number and see whether it is a Tor relay or exit, using the Tor Project’s own Onionoo data: flags, exit policy, family, operator contact, version, and uptime and bandwidth history on request. A date box links to ExoneraTor for “was this IP a Tor relay on that day?”. Bulk mode checks up to 200 IPs against one download of the relay list, matched in your browser.
  • Onion Page Pivot Extractor. Paste or drop a page you saved in Tor Browser and get every identifier worth searching on: v3 onion addresses checked against the Tor specification’s checksum (with dead-v2 and look-alike-clone flags), Bitcoin, Ethereum and Monero addresses with checksum checks, PGP keys, emails, messaging IDs, analytics IDs and server banners, plus a Shodan-style favicon hash. It never visits the onion site and never renders the pasted page.
  • PGP Key Inspector. Decodes an OpenPGP key, signature or message in the browser: v4 and v6 fingerprints (RFC 9580), key IDs, every identity with the date it was added, photo IDs, subkeys, expiry, revocations and third-party certifications, with keyserver and search pivots. Fingerprints were checked against GnuPG on every test key. Signatures are parsed, not verified.
  • Linked from the dark web OSINT guide. Tool count is now 88.
2026-10-09

Site re-audited against the October 2026 SEO/AEO/GEO methodology

  • Scope. All 151 pages checked against the October 2026 edition of the SourceCited AI Search Methodology Report (which supersedes the August edition this site was last audited against): answer-first openings, inline sourcing, FAQ text/schema parity, honest dates, crawler tokens, structured-data hygiene, hidden-text defence, title and description lengths, internal linking.
  • Passed without change: 0 invalid JSON-LD blocks; FAQ visible text identical to FAQPage schema on every page; every page has a canonical and at least two inbound internal links; no hidden text, zero-width or Unicode tag characters outside emoji and code; robots.txt, llms.txt and the AI SEO guide already matched the October corrections (IndexNow scoped to Bing, Google-Extended explained, FAQ schema treated as hygiene, decay figures with their definitions).
  • Fixed — sourcing. Four pages made documentation-based claims with no links to that documentation. Photo Forensics Software Compared and Video Forensics Software Compared now link every product's public page and the specific documentation behind each table cell; three cells were corrected against those sources (Forensically does display C2PA data since April 2024; Ghiro does compare EXIF thumbnails; Amped Authenticate’s quantization database is 14k+ tables) and two unsourced “depends on version” cells now say the product page does not state it. Forensics Methods cites the originating papers and specifications (Krawetz 2007, Farid 2009, Kee/Johnson/Farid 2011, Fridrich/Soukal/Lukáš 2003, Westfeld/Pfitzmann, C2PA 2.4, SWGDE 18-I-001). The tool audit links the APIs and standards it names. Every link was fetched and read before it was added; claims whose source could not be reached were left unlinked rather than guessed.
  • Fixed — metadata. 18 titles over 60 characters and 22 descriptions over 160 characters (mostly the pages added in October) rewritten to fit, with og: and twitter: tags kept identical. Metadata-only changes, so those pages’ dates were not touched.
  • Fixed — crawler list. robots.txt now names every token in the methodology’s §10.1 table (added Meta-ExternalAgent, Amazonbot, MistralAI-Training and OAI-AdsBot, all allowed, with the Cloudflare preset caveat).
  • Judgement call recorded. 29 pages changed their “Last updated” date since 8 September while their visible prose barely changed. Each was a documented functional change to the page’s tool or a directory correction (entries in this changelog), so the dates stand; the methodology’s date-bumping warning is about cosmetic changes, and none were.
2026-10-09

Archive tools: quick checks by default, full scans with the new Archive Helper

  • No more shared proxy for the Wayback Machine. When many people scanned at once, the Internet Archive rate-limited the single Max Intel proxy and everyone’s scans stalled. Ghost Finder, Career Intel, WHOIS History, Wayback Recon, Sitemap Historian, Exposed and Domain Recon now send every Wayback Machine request from the visitor’s own browser and IP.
  • Quick check (default, nothing to install). Each tool checks a short list of URLs with the archive.org availability API, the one Wayback endpoint browsers can read directly, and links the most recent capture. Results are labelled as quick checks, and “not found” is described as not conclusive, because that API misses some archived URLs.
  • Full scan (optional). The new Max Intel Archive Helper is a short Tampermonkey/Violentmonkey userscript that only runs on maxintel.org and only contacts archive.org and web.archive.org. With it installed, the tools run their full CDX-index and snapshot scans as before, from the visitor’s IP.
  • Pacing fix (same day): a real 90-platform Ghost Finder scan was blocked by archive.org after about 60 quick lookups in three minutes, and the retry 30 seconds later was blocked too. Quick checks now run one lookup every 5 seconds, shared by every tool and tab in the browser. When the archive pushes back they pause for 1, 2, 4 and then 8 minutes and resume on their own, instead of retrying into the block. Only after about 8 minutes of refusals do they stop and mark the rest “not checked”, with the time to retry: 15 minutes, then 30, then 60 if the block continues, because archive.org blocks have lasted about an hour in testing. A remembered block is shown on every archive tool before the next scan starts, and log times are now shown in your local time. Ghost Finder also tries fewer spellings of alternate profile addresses (x.com, threads.com and so on), and Stop now cancels a pause immediately.
  • Privacy policy section 5 updated: Wayback Machine requests no longer pass through Max Intel infrastructure, and the proxied-tools list now includes MAC Address Lookup, which was missing.
2026-10-08

Ghost Finder: 90 platforms, select-all and presets

  • Platforms 32 → 90. 42 live additions (Threads, Bluesky, Telegram, Snapchat, Truth Social, Substack, Linktree, Gravatar, Hacker News, GitLab, VK and more) and 16 defunct networks whose profiles now survive only in archives (Parler, Periscope, Ello, Formspring, Posterous, Xanga, FriendFeed, Identi.ca, Delicious, Klout, Storify, Mixer, Picasa, Windows Live Spaces, GeoCities, AOL Hometown). Twitter now checks twitter.com, x.com and mobile.twitter.com (previously x.com twice and never twitter.com).
  • Selection: Select all, Select none, Invert and Major / Live / Defunct presets, a live “N of 90 selected” counter, a filter box, keyboard-operable chips and remembered settings.
  • Scanning stays sequential with the adjustable delay, as before. If the Wayback Machine or the proxy cannot be reached, the scan now stops after three failed lookups and says so, instead of reporting “no snapshots” for every platform; log lines and extracted bios are now escaped. (A parallel scanner was tried the same day and withdrawn.)
  • Reliability fix (same day): the Wayback Machine takes 20–40 s to answer searches for usernames it has never indexed and rate-limits the shared proxy, so lookups were timing out at 20 s and the scan stopped early. Archive searches now wait up to 45 s, a rate limit (HTTP 429/503) triggers a real back-off of 15–60 s with a log message instead of a quick retry, searches are spaced 0.8 s apart, and the rarely-archived mobile.twitter.com variant was dropped to save a lookup per username. Tested live from maxintel.org: a 14-platform scan now completes and finds archived profiles.
  • Adaptive pacing (9 Oct): long scans kept hitting the archive’s rate limit on almost every platform. The scan now spaces archive requests itself, doubling the gap (up to 12 s) whenever the archive pushes back and easing off after a run of successes, so it stays just under the limit instead of tripping it repeatedly. Profiles that still could not be checked get a “Retry not-checked” button that re-runs only those and keeps the results already found.
2026-10-08

ALPR Camera Finder retired

The ALPR Camera Finder added earlier today has been withdrawn: it mapped the same crowd-sourced OpenStreetMap data that DeFlock’s map already presents better. Every page that pointed to it now links to DeFlock’s map, the old address redirects to the Flock & ALPR guide, and the site’s browser permissions policy no longer allows geolocation, which only that tool used. Homepage now lists 85 tools.

2026-10-08

Directory audit: every link-list page checked for new, missed and dead services

All 24 link-list and pivot pages were re-checked: every existing link was tested, and new or missing services were added only after their sites (and any pre-filled search URL format) were verified on 8 October. Paid and freemium services are labelled.

  • Removed or replaced: Radaris (domain transferred to Atlas Data Privacy by a New Jersey court order, 27 Aug 2026), Lullar (shows invented “found” counts to sell reports), Ask.com (closed 1 May 2026), Stract and EntireWeb (domains repurposed), Sentinel Hub EO Browser (shut 20 Mar 2026), StalkFace, Montage, Google Podcasts Manager, TruePic Lens, the GLTR demo, Homesnap, and two OSINT programs that fall under our exclusions (Trape — phishing/keylogging; Chiasmodon — sells compromised credentials). Infoga, InstaLooter and Creepy removed as dead. All dead, moved or paywalled ones are logged in the Tool Graveyard, along with PeekYou (its domain passed to Atlas Data Privacy under a settlement), CallerIDTest (shut down citing Daniel’s Law), Homesnap (now Homes.com), Foundation Directory Online (now Candid’s paid search), the Vanderbilt beta archive and Waldo. Lullar, Trape and Chiasmodon still exist and were removed for policy reasons, so they are not graveyard entries.
  • Added (selection): CourtListener, Justia Dockets, judyrecords, PACER locator, BOP inmate locator and OpenCorporates officer search (people/business); Bluesky, Kick, Hugging Face, Gravatar, Sherlock and Maigret (username); Proton and keys.openpgp.org key lookups, Holehe, Hunter verifier (email); Truecaller and Canada411 reverse lookup (phone); NETR Online, Regrid, Nominatim and KartaView (address); six new free opt-outs plus Google’s Results about you (removal guide); Arctic Shift, PDSls, Meta Ad Library, Mastodon/Tootfinder/Truth Social (social); Hive Detect, SynthID Detector, OpenAI Verify, Hiya, Adobe Content Authenticity, ImageWhisperer and Copyseeker (media and AI detection); FreeBMD, Reclaim The Records, Portale Antenati and more (vital records); Google Dataset Search, Internet Archive full text, GovInfo, FOIA.gov (documents); airplanes.live, adsb.fi, ADSB.lol, Global Fishing Watch, Realtime Trains (transport); NMVTIS, Transport Canada recalls and Nordic/Dutch registries (VIN); Tonviewer, Suiscan, Aptos, Hypurrscan, Blockscout, MetaSleuth, MistTrack (crypto); Hurricane Electric DNS, host.io, Whoxy, Validin (domain); Overpass Turbo, ShadeMap, Bellingcat OSM Search, PeakFinder, GeoConfirmed (geo); beaconDB, nPerf, fccid.io, RadioReference (wireless); Media Cloud, Kagi News, Delpher (news); 12 new URL pivot patterns (157 total); Yahoo Scout (engines); and 15 OSINT programs including Blackbird, twscrape, gau, waymore, yt-dlp, gallery-dl and four Bellingcat tools (directory now 93).
  • Fixed: dozens of moved or broken URLs (New York and Arizona entity search, FDIC BankFind, FDA inspections, USPTO, Chronicling America, Threads → threads.com, RadarBox → AirNav Radar, Arkham, Censys Platform, ZoomEye, DNSlytics, YouMail, PeopleConnect and ThatsThem opt-outs, and more); stated counts corrected site-wide (username search 65 sites, 157 pivot patterns, 80+ engines, 90+ OSINT programs).
2026-10-08

Open items closed

  • Career Page Intelligence: when the Wayback Machine or the proxy could not be reached, the tool spent about four and a half minutes retrying and then reported "No career pages found", which read as a real answer. It now gives up immediately on a rate limit and after three consecutive failures, says plainly that the archive was unreachable or rate-limited (with how many lookups failed), and warns when results are partial. Tested: proxy down — honest message in 14 seconds; rate-limited — immediately; normal scan unchanged.
  • OSINT Tool Graveyard: four entries found during the guide refresh added — XTEA.io (now a blog), Pyrogram and RansomWatch (repositories archived), and AIMSICD (dormant, not archived). Counts now 16 dead / 6 paywalled / ~21 reduced or changed.
  • FOIA guide: the request generator now includes the District of Columbia (D.C. Code § 2-531 et seq.) and hands each generated request to the Records Request Tracker with the jurisdiction and agency filled in.
  • Password managers: Proton Pass prices corroborated by an independent price tracker, with a note that Proton's own pricing page renders amounts in JavaScript.
  • AI Dorks hub: refreshed to describe the October prompt-page improvements and link the safe-agent checklist. The 13 tools moved onto the shared proxy-failover client now show their 8 October update date.
2026-10-08

Fact refresh of 11 older pages; Identifier Validator; proxy failover; llms.txt rewritten

  • Commercial comparisons re-priced from vendor pages (8 Oct): password managers (Bitwarden's January price rise, the ETH Zurich server-compromise study, the April Bitwarden CLI npm incident, Proton Pass no longer $1.99), Maltego alternatives (credit-metered plans from €3,000/yr; Community Edition commercial use allowed), encrypted email (prices; the Swiss surveillance-ordinance revision sent back for consultation), Optery vs DeleteMe price check, and the HIBP catalog browser (1,042 breaches live; required CC BY attribution added; escaping fixes).
  • Guides re-verified: Telegram OSINT (paid native post search since July 2025, police data disclosure since September 2024, dead tools removed), Is OSINT legal? (hiQ and Meta v. Bright Data outcomes corrected, Reddit v. Perplexity and Google v. SerpApi rulings, EDPB scraping guidelines, UK CMA reform status), Dark web OSINT (2025–26 takedowns, corrected statistics), OpSec (age-assurance laws, fingerprinting changes), Predictive policing (corrections and removals of unsourced figures; Pasco County settlement), IMSI catchers (Rayhunter v0.13, supported hardware, Android 16 network alerts). Unverifiable claims were removed rather than kept.
  • Identifier Validator (new tool): offline check-digit and format validation for IBAN (SWIFT registry release 101, 89 countries), BIC, IMEI/IMEISV, ICCID, payment cards (masked, never put in links), US ABA routing and EU VAT numbers; cross-checked against python-stdnum on 6,670 cases.
  • Proxy failover: the 14 tools that use the CORS proxy now share mi-proxy.js, which spreads requests across the workers in workers.json and moves to the next on errors, timeouts and rate limits. A hardened, allowlisted worker is ready to deploy as a second pool member.
  • llms.txt rewritten from current page titles and descriptions (86 tools, 50 guides); tools.json completed with 28 tools that were missing from it. Homepage lists 86 tools.
2026-10-08

New: Records Request Tracker, Platform ID Decoder, Coordinate Converter; AI-agent guide refreshed; tool fixes

  • Public Records Request Tracker (new tool). Tracks FOIA and state records requests in your browser. Response-deadline rules for federal FOIA, all 50 states and DC with a source per jurisdiction (unconfirmed rules are marked "verify" rather than guessed), business-day due dates that skip weekends and federal holidays, extension and appeal-deadline handling, follow-up and appeal letter templates, overdue dashboard, CSV/JSON/ICS export.
  • Platform ID Decoder (new tool). Creation time from Discord, X/Twitter, Instagram, TikTok, Bluesky and Mastodon IDs or links, plus ULID, KSUID, UUID v1/v6/v7 and MongoDB ObjectIds; batch mode and exports. Tested against the Discord, X, RFC 9562, ULID, KSUID, MongoDB and AT Protocol published examples.
  • Coordinate Converter (new tool). Decimal, DMS, UTM, MGRS, Plus Codes, geohash and Maidenhead with auto-detect and batch CSV. UTM agrees with PROJ to well under a millimetre; MGRS matches NGA GEOTRANS output; passes the full Open Location Code test data.
  • AI-Agent OSINT & MCP updated: current MCP specification revision (2026-07-28) and the protocol's move to the Agentic AI Foundation, a sourced table of client support, a verified table of 11 MCP servers useful for OSINT, a security section (prompt injection, tool poisoning, malicious packages, CVEs) and a safe-setup checklist; outdated OpenOSINT and SpiderFoot details corrected.
  • Tool fixes: Cloud IP Identifier now matches IPv6 (and no longer lists Azure, which it never checked); "WHOIS History" renamed WHOIS & Contact History and its copy corrected — it scrapes archived pages, it is not a historical WHOIS database — and it now also reads archived public WHOIS lookup pages; perceptual hashing moved into one shared script with identical output, and the Reverse Image Hub and Image Verification Workbench hand their hash to the Near-Duplicate Finder. The proxy notice on 13 tools and the privacy policy now describe data flows accurately: most lookups go directly from the browser, the proxy is a fallback, and the Reverse Image Hub itself never uploads.
  • Homepage lists 85 tools.
2026-10-08

New: ALPR Camera Finder, Image Verification Workbench, ALPR and the 2026 midterms

  • ALPR Camera Finder (new tool). Maps license-plate readers recorded in OpenStreetMap (the data DeFlock contributes to) around any address, coordinates or map click, or along a driving route with a 30–200 m buffer. Direction cones, manufacturer and operator filters and counts, CSV and GeoJSON export with ODbL attribution, deep links, and a "report a missing camera" link. Geocoding (Nominatim), camera data (Overpass, with two fallback servers) and routing (OSRM demo) are disclosed before each request.
  • Image Verification Workbench (new tool). A seven-step guided check of a single photo — intake and hashes, C2PA provenance, metadata and GPS, earliest copy, forensics, context, conclusion — reusing the Photo Forensics Studio and C2PA Inspector engines, saving the case locally and exporting one printable/JSON evidence report.
  • License-Plate Readers and the 2026 Midterms (new guide). State ALPR laws passed in 2025–26 (restrictions and expansions), governors' orders, six federal bills, local ballot questions, sheriff races and what candidates from both parties have said, quoted and dated. Snapshot as of 8 October; review scheduled after 3 November.
  • Corrections: the Flock guide no longer says Colorado SB 26-070 and Minnesota HF 4205 "are copying" Washington's law — Colorado's bill was laid over on 4 July 2026 without passing; its federal section now lists the six ALPR bills introduced since July. Site permissions policy now allows geolocation and camera for this site only (both still prompt), which the ALPR finder's "use my location" and the OCR tool's camera capture need.
  • Homepage lists 82 tools; guides hub 50 guides; cross-links added across the ALPR cluster and the image-verification pages.
2026-10-08

New: C2PA Content Credentials Inspector, Reverse Image Search Hub rebuilt, video verification guide

  • C2PA Content Credentials Inspector v1.0.0 (new). Reads the manifest store from JPEG, PNG, WebP, WAV, MP4/MOV/HEIC/AVIF, MP3, SVG and .c2pa sidecars; decodes claims, assertions (actions, ingredients, thumbnails, CreativeWork, training-mining), the COSE signature and the signer certificate chain; recomputes assertion and content hashes (including BMFF box hashes) and verifies ES256/384/512, PS256/384/512, RS256 and Ed25519 signatures with WebCrypto; reports RFC 3161 timestamps; detects stripped and remote manifests. Verified field-by-field against the c2pa-rs reference reader on 26 fixtures. States plainly that the signer is not checked against the C2PA trust list. Nothing is uploaded.
  • Reverse Image Search Hub rebuilt as a static page. SHA-256 and perceptual hashes, EXIF-stripped download, pre-filled URL searches on eleven engines, upload-page launcher for local files, face-search section with the authorisation notice, archive and forensics pivots, ?url= deep links. The old image.php remains only as a temporary-public-URL helper (noindex, canonical to the new page); every internal link now points at image.html.
  • How to Verify a Video in 2026 (new guide). C2PA for video and platform labels, SynthID and Sora marks, InVID keyframe reverse search, container metadata, temporal and per-frame checks with their limits, geolocation, audio, chain of custody; 12-step workflow, free-vs-paid table, 35 cited sources.
  • C2PA hub: inspector added to the verification tools; Sora FAQ updated (app discontinued 26 April 2026, API 24 September 2026); device list corrected (iPhones do not embed Content Credentials; Pixel 10 and Galaxy S25 do). Cross-links added from the forensics studios, EXIF viewer, image forensics guide and video OSINT page. Homepage lists 80 tools; guides hub 49 guides.
2026-10-07

October content refresh: Flock/ALPR, California DROP, dorking, graveyard, search landscape; audit article

  • New: We Audited 71 of Our Own OSINT Tools — transparency report on the 6 October audit with the per-tool findings table and the maintenance checklist.
  • Flock & ALPR (6 pages): October 2026 update boxes covering Flock's 13 August safeguards (7-day default retention for new deployments only, mandatory Audit Assistance and case codes by end of 2026, automatic lockouts, MFA, Bishop Fox review, CVD programme), the OS Investigate / "Nightshift" movement-pattern tool reported by WIRED, the Washington Post misuse count (≥50 officials, Flock in 46), and the cancellation wave (Institute for Justice: 252 local governments since 2025 as of 6 October; DeFlock 153; Henrico, El Paso, Arlington, Milwaukee County, Hamilton County, Nantucket named). The flagship guide gained a safeguards table and an OS Investigate section; stale "30-day retention" and "163/249 cancellations" statements corrected everywhere; tracker links added; FAQs added and schema synced.
  • California DROP: page reworked for the live system (consumer requests since 1 January 2026; ~300–345k requests; broker processing from 1 August; 45-day cadence; $200/request/day penalty), with a filing walkthrough, timeline and "DROP vs paid removal" section; the people-search removal guide and Optery vs DeleteMe comparison updated to reflect it.
  • Google Dorking Reference: per-engine operator support table (Google, Bing, DuckDuckGo, Yandex, Brave), "dorks that stopped working in 2025–2026", Dork Generator deep links; fixed an unterminated table and stray text. Tool Graveyard: 11 entries from the audit (Oscobo, Mullvad Leta, Google cache:, abuse.ch feeds, Kick, Reddit about.json, Proton, HackerTarget, Warpcast, Robtex, a Hugging Face model id). Search Engine Landscape: OSINT Navigator, Oscobo and Leta shutdowns, directory counts. Search Engine Directory: Mullvad Leta marked defunct (shut down 27 November 2025); 61 engines pre-filled.
  • Guides hub now lists 48 guides.
2026-10-06

Tool audit: 71 interactive pages reviewed, 308 defects fixed

Every built-in tool was read line by line and exercised in a headless browser with generated test inputs. The pass recorded 29 critical, 83 high, 129 medium and 67 low-severity defects; all were fixed and each page was re-tested with zero script errors. The full per-page record is in the audit report that accompanies this release.

  • Tools that did not work at all and now do: Stylometry Lab, Data Wrangler, Entity Graph and Steganalysis Lab (all referenced a worker file that was never deployed; engines are now embedded, Pyodide pinned to 0.29.2 with a visible load/retry state); Cookie & Tracker Exposer and Repo Security Auditor (receiver rejected every bookmarklet message because of a wrong origin check); OCR Text Extractor and ZIP↔JSON Converter (results panel never became visible); Voice Print Matcher (model id did not exist); Reverse Image Search (unclosed <noscript> hid the whole page); Exposed scanner (proxy list read as the wrong type, so breach, botnet and archive checks silently reported "clean"); Threat Intel (duplicate element ids let the dashboard hijack the IOC scanner); Wayback Delta (bookmarklet pointed at a deleted page); Shodan panel in Tech Stack Detector (raced the DNS lookup).
  • Wrong results fixed: Robtex NDJSON parsed as JSON (IP, Domain Recon, Threat); HackerTarget rate-limit text shown as DNS data; pHash median convention and flip matching in Near-Duplicate Finder; nearest-neighbour 16 kHz resampling replaced with OfflineAudioContext in all speech tools; Diceware list had 2,019 of 7,776 words and three of five password RNG engines were non-cryptographic (now CSPRNG with rejection sampling); VIN model-year disambiguation and check-digit scope; Discord snowflakes treated as Unix milliseconds; PDF "clean" left Info keys and the XMP stream intact; steganography destroyed hidden bits in transparent pixels; weather lookups used the 92-day forecast API for historical dates (archive API added); Sitemap Historian merged sibling sitemaps and called every 404 "live"; MAC lookup vendor table refreshed.
  • Security: unescaped innerHTML of third-party API data or user input (stored/reflected XSS) removed from IP lookup (~40 sinks), Domain Recon, RDAP, WHOIS History, CT Monitor (including attribute injection and prototype pollution via a constructor label), Cloud IP, Wayback Recon, DHCP Lease Parser, Tech Stack, Facebook OSINT, Career Intel, Video Person Tracker, Notes (" not escaped), ZIP↔JSON, EXIF Viewer and the pivot hubs; zip-slip paths blocked both directions; javascript: URLs from archives never rendered as links; every target=_blank carries rel=noopener (including the consent overlay); CSV exports guard against formula injection; Google Suggest in the Dork Generator is now opt-in.
  • Reliability: every CDN library pinned to a real version (jsQR 1.4.0, exifr 7.1.3, Leaflet 1.9.4, pdf-lib, Tesseract 5.1.1, ORT 1.19.2, JSZip, Pyodide 0.29.2) with a visible error when it fails to load instead of a dead page; static ES-module imports made lazy; WebGPU adapter probed before the first ONNX session so WASM fallback actually works; fetch timeouts, busy states, try/finally re-enabling of buttons, 429 short-circuits, ObjectURL and canvas leaks closed; localStorage wrapped with quota handling and export/import (Notes, Evidence Logger, ai-dork pages).
  • New capabilities: Address, Geo, Crypto, Video, Transport and Search Engine Directory pages that advertised a search but shipped a static list now parse input locally (DMS/decimal/map-URL coordinates; BTC/EVM/LTC/DOGE/BCH/TRON/SOL/XRP/XMR/ENS detection) and generate pre-filled links; URL Pivot Encyclopedia fills all 145 patterns from a typed value; Evidence Logger has a verifiable SHA-256 hash chain with Verify and Import; Wikidata Bridge renders every external identifier via Wikidata formatter URLs; Cloud IP covers Oracle, DigitalOcean and Linode; Repo Auditor checks GitHub Actions, Docker and dependencies with 26 secret patterns; DHCP parser reads Windows audit logs, netsh and dnsmasq; CSV/JSON/SRT/VTT exports, Copy buttons, Enter-to-submit, keyboard-accessible drop zones, aria-live status and ?q= deep links across the board.
2026-10-06

Adsterra tag format updated

Adsterra's ad tags moved from https://www.highrevenueformat.com/<key>/invoke.js to https://bauval.org/22/<key>. The unit keys are unchanged. ad-frame.php now holds a per-host tag template (both formats allowed, nothing else), mi-adslots-config.js points at the new host, and the legacy srcdoc frame in mi-adslots.js builds the same URL. Site content is unaffected.

2026-10-06

Site-wide accuracy pass on pages linked from the forensics studios

Every page the two studios and their companion articles link to was re-read for currency and factual accuracy.

  • Removed the stale "30+ image analysis techniques" description of the Photo Forensics Studio from the homepage, OSINT tools directory, geolocation guide, steganography guide, C2PA hub and AI voice page; each now lists what version 2.0 actually runs (ELA, JPEG ghost, copy-move, noise, LSB chi-square, metadata, C2PA, hashes, evidence report). Homepage description of the Video Forensics Studio updated to version 2.0 (container parsing, hashed frame export, report).
  • Image forensics guide: C2PA section updated to the Content Authenticity Initiative's January 2026 figure of 6,000+ members (was 5,000+), specification v2.4 (April 2026) and the Conformance Program; camera and phone list extended (Leica M11/Q3/SL3, Nikon Z8/Zf/Z6III, Canon EOS R1/R5 II, Sony a1/a9 III/PXW-Z300, Samsung Galaxy S25); the Pixel 10 "first smartphone" claim is now attributed to Google; Sensity's 98% accuracy is labelled vendor-reported wherever it appears; the disputed "90% of web content will be AI-generated by 2026" prediction was removed; the tool table row now describes the studio's real passes and links to the comparison and methods pages; a broken related-links fragment was repaired. FAQ schema re-synchronised with the visible answers.
  • Guides hub: the photo forensics comparison, video forensics comparison and forensics methods pages added under Media & Forensics (47 guides, was 44); the "All 56 guides" footer link corrected on every page.
  • A mangled run of navigation links that had been injected into a sentence on the C2PA hub and into a FAQ answer (and its schema) on the steganography guide was removed; the C2PA hub's classical-forensics list now includes the Photo Forensics Studio.
  • Tool pages that labelled the studio "Forensics Lab" (Data Wrangler, Entity Graph, Face Finder, Steganalysis Lab, Stylometry Lab) now use its name.
2026-10-06

Photo Forensics Studio 2.0.0 and Video Forensics Studio 2.0.0

Fixed: the Photo Forensics Studio's analysis engine (forensics-lab.worker.js, a Python/WebAssembly build) was missing from the site, so the "Load analysis engine" step failed for every visitor since at least 19 August 2026. The engine has been rewritten in plain JavaScript (forensics-engine.js, ~60 KB, loads with the page, no 16 MB download) and the page no longer has a separate load step.

  • New passes: bit-plane/LSB view with chi-square test; EXIF-thumbnail comparison; metadata and file-structure audit (EXIF/GPS/XMP history/IPTC/ICC, JPEG quality and quantization-table check, progressive/subsampling, APP markers, trailing data, embedded JPEG count); C2PA/JUMBF presence; generative-AI markers.
  • Reworked passes: ELA with edge-normalised block statistics and cold-region detection; JPEG ghost sweep (40–100) at native resolution with own-quality exclusion and per-quality clustering; copy-move with brightness-normalised features, offset voting and coherence; noise map judged on low-texture blocks.
  • Plain-language verdicts per method (no signal / weak / notable) with the statistics behind each.
  • SHA-256, SHA-1 and MD5 of the original file; case ID, exhibit prefix, examiner and notes; batch queue; evidence report as printable HTML/PDF and JSON; per-pass PNG download.
  • RAW support (DNG, CR2, NEF, ARW, PEF, ORF, RW2, RAF, CR3) through metadata and embedded-preview analysis; PNG, WebP, HEIF/AVIF metadata.
  • Calibration: untouched camera photographs (Nikon COOLPIX P6000 with GPS, a 3264×2448 Jolla phone capture, GIMP-exported Canon and Nikon samples) return no signal on all methods; a clone-stamped region, a q50 paste re-saved at q90 and sequential LSB embedding are flagged.
  • Video: SHA-256/SHA-1/MD5; MP4/MOV and Matroska/WebM container parsing with provenance findings; exhibit fields; frame export at native resolution with SHA-256; printable/JSON evidence report including per-frame metrics and inspected frames; light-theme fixes.
  • Page copy rewritten to match the shipped feature set (earlier text described FFT, Benford, PCA and weather look-ups that the tool did not have). New pages: methods & limitations, photo forensics software compared, video forensics software compared.
2026-10-04

Flock surveillance guide

  • New section and FAQ: whether anti-AI clothing or car wraps defeat Flock cameras, based on 404 Media/WIRED's examination of a removed camera, the adversarial-T-shirt (ECCV 2020) and Cap_able results, and Indiana's colour-change reporting rule.
2026-10-03

AI search methodology report and site-wide corrections

  • AI SEO guide and search-engine landscape updated to the corrected SourceCited October 2026 methodology report (revision 2): domain-authority comparison scope, Sistrix AI Mode figure, Uberti-Bona Marin 117-query overlap study, Qwairy's 60-answer Copilot sample, Wix professional-services figure, Cloudflare 15 September defaults, Semrush entry price, C2PA ISO/CD 22144 status, Search Console generative-AI report rollout.
  • FAQ structured data synchronised with visible FAQ text on 41 pages.
  • robots.txt: named crawler groups now repeat their Disallow lines; Cloudflare comment corrected.
  • Password generator: fixed a script-order error (TLS panel) that could stop the page from generating.

This changelog starts in October 2026. Earlier updates are recorded per page in the freshness tracker, which lists every page's last-updated date and review cadence.