The article is from the public number: 爱 范 儿 (ID: ifanr) , author: Lee extraordinary, from the title figure: “Sherlock.”

Sparks happen in a flash.

On the ground a few kilometers below, it looks like a dim light from a match. However, the passenger aircraft at high altitude has risen into the sky with the explosion and bang, and there is a mournful sound in the cabin. The sleeping passengers are swallowed up before they can panic.

Ukraine International Airlines flight PS752 crashed near Khomeini International Airport in Tehran in the early morning of January 8. None of the 167 passengers and 9 crew members on board survived.

The wreckage of the crashed plane. Picture from: CNN

At the time when the United States and Iran were in a sensitive period due to an assassination incident, the air crash attracted worldwide attention.

Although the US Department of Defense pointed out that the aircraft might have been shot down by missiles, it did not give substantial evidence, while Iran insisted that the cause of the crash was “engine failure” and cited a series of evidence.

But on January 11, Iran suddenly declared that the crashed plane was hit by an accidental human error. It was not the U.S. intelligence service that first revealed the cause of the plane accident with meticulous evidence, but Bellingcat, an independent civilian investigation agency.

They are not special agents, some are just a computer, and the clues to the case are from public Internet data.

01 Beginning and End of Investigation of Iranian Wrecked Aircraft: Finding the Truth on the Internet

When the news of Flight PS752 broke out, Eliot Higgins, the founder of the independent investigation agency Bellingcat, received photos and videos from many netizens. Past experience has told him that the accident may notNon- “engine failure” is as simple as that.

As in the past, what Eliot Higgins wants to do is to use open source intelligence (open source intelligence) to collect, save, verify, and analyze publicly Available evidence, piece together the facts.

The wing fragments uploaded by some netizens have attracted the attention of investigators, because there are many black spots in the wing fragments, which may be caused by missiles scattered by the missile. In 2014, the missile was shot down on the Malaysia Airlines MH17 passenger aircraft. Bullet holes.

But after careful analysis, the investigators are still unable to determine whether these black spots are bullet holes or dirt stains, and can only give up this clue temporarily.

But investigators soon discovered another set of photos on social media, where Iranian netizens claimed to have photographed a conical mechanical part in a ditch near the scene.

After comparison and analysis, the investigators found that this cone-shaped object was originally the tip of the “Tor M-1” air defense missile. It is reported that the NATO code of this missile is SA-15. Iran imported it in 2007. 29 SA-15 launch vehicles were shown during the parade.

But this is not enough to prove that the missile shot down the passenger plane. Investigators need to verify the source of the photo and the specific location where it was taken. Bellingcat usually uses EXIF ​​data to obtain the camera type of the captured image and the exact latitude and longitude of the location where the photographer is standing, but if it is uploaded through an encrypted communication application such as Telegram, the metadata will be deleted.

As a result, investigators can only look for clues in the pictures. Because there is only a ditch in the photo, and there are no easily identifiable signs such as buildings or street signs, the investigators collected a large amount of road information in the suburbs of Tehran and tried to find The ditch, finally through the photos from other angles on the Internet, confirmed that the photos indeed came from Tehran.

The most important clue appeared the day after the accident, and a video began circulating on social platforms. Under the yellow street lights, a yellow fireball suddenly appeared over a group of buildings, and then the yellow light spot began to slide towards the ground.

Eliot HigginS realizes that this is likely to be the picture of a missile shooting down a passenger plane, but what about the evidence?

The resolution of the video is too low to identify what the yellow fireball is, and it is difficult to tell whether the video from unknown source is in Tehran, but with the building reference, it is easier than retrieving the source of the missile photo. Much more.

Investigators took a closer look at each of the buildings, street signs, and roads in the video, and attempted to map them to satellite imagery. They initially confirmed that the buildings were located in Palan near Tehran Airport. (Parand) .

Then compare the buildings and streets of this community with the video through Google Street View. Investigators also found the same trench in the video as the previous missile photo. It can basically be confirmed that this was the plane that was hit by the missile. Instantly.

The building that appeared in the video. Picture from: Twitter

Investigators even locate the exact position of the bomb in the aircraft through video. They don’t need any complicated tools. They only need the physics knowledge of junior high school-use the relationship between thunder and lightning to measure the distance of thunder.

Because there is a certain time difference between seeing lightning and hearing thunder, and the speed of sound propagation is 340 m / s, onlyTo multiply the propagation speed by the time difference, we can get the straight line distance between the thunder and ours.

In the video, the time difference between the flash and the explosion sound was 10.7 seconds, so the straight line distance between the passenger aircraft and the camera is about 3600 meters, and then the nearby reference objects are combined. According to the simple Pythagorean theorem, It can be determined that the passenger plane was hit by a missile at an altitude of 3,300 meters.

Investigators also combined with FlightRadar24, a software that provides real-time flight status, to draw the complete flight trajectory of the crashed airliner, cross-certified that the airliner did pass through the yellow light spot, and it basically coincided in time.

At this point, Bellingcat has solved the case, overthrowing the Iranian official conclusions with a complete and rigorous chain of evidence. This is reasoning based on open source intelligence and does not require any confidential information, but the speed of investigation is even faster than that of intelligence agencies in many countries.

Bellingcat, Sherlock Holmes in the Internet age.

02 Sherlock Holmes in the Internet Age

Bellingcat’s investigation of the crashed passenger plane in Iran has once again made the world see the power of open source intelligence. At first Bellingcat was a crowdfunding investigative news website founded by British journalist Eliot Higgins, using public information such as satellite imagery, social media, YouTube, and online databases for investigative reporting.

Eliot Higgins. Picture from: Interhacktives

The name Bellingcat comes from a famous fable. In order to eliminate the threat of cats, a group of mice decided to hang a bell around the cat’s neck. Although all mice supported this proposal, none of them wanted to do so.

In the past few years, Bellingcat has unveiled the truth of several controversial events through similar investigations, including the crash of Malaysia Airlines Flight MH17, the attack on Syrianized weapons, and the Russian double agent Sergei and his daughter in the UK Incidents such as being killed by poison.

The investigation of Malaysia Airlines Flight MH17 crashed Bellingcat’s reputation. As with this Iranian crash, Bellingcat uses social media, YouTube videos, and information on Google Maps to locate the accident, and even uses shadows to calculate the time to determine whether the exact time that the missile launcher passed through a place is the same as the final one. The missile launches coincided.


Open source intelligence soon began to receive more attention from other countries, and the United States also established a foreign broadcast monitoring office specialized in collecting and analyzing open source information during World War II. (FBMS ) , Before that, generally believed that valuable information was top secret, the application of open source intelligence in actual combat has reversed people’s perception.

Picture from: “Eavesdropping Storm”

Sherman Kent, known as the “Father of Intelligence Analysis” by the US intelligence community, (Sherman Kent) has pointed out that the intelligence community daily Approximately 80% of the intelligence used comes from public sources.

Although some information may be obtained through secret channels, a large amount of information must come from bland, unobtrusive observation and research.

In the Internet era, more massive and transparent public data makes the potential value of open source intelligence even greater. But it also means more redundant data, and it is more difficult to screen useful information from massive data and verify it.

Fortunately, with the growth of data in this era, there is technology. The United States Geospatial Intelligence Agency has commissioned researchers at the University of Missouri to develop AI tools for information search and analysis. It is reported that this technology The average search time in a square kilometer area is only 42 minutes, which is more than 80 times more efficient than humans, and the accuracy rate is almost the same as humans.

More than 100 years ago, Holmes’s case in Conan Doyle’s case relied on the talent of subtle observation and deductive reasoning. In the digital age of information explosion, anyone who can quickly extract useful information from public information can become Holmes.


The article is from the public account: , author: Lee extraordinary