Skip to content

Instantly share code, notes, and snippets.

@DrWhax
Last active May 29, 2025 00:25
Show Gist options
  • Select an option

  • Save DrWhax/61978d4e7df5291d4cf308f10dc20d5a to your computer and use it in GitHub Desktop.

Select an option

Save DrWhax/61978d4e7df5291d4cf308f10dc20d5a to your computer and use it in GitHub Desktop.

Revisions

  1. DrWhax revised this gist May 29, 2025. 1 changed file with 10 additions and 2 deletions.
    12 changes: 10 additions & 2 deletions README.md
    Original file line number Diff line number Diff line change
    @@ -83,15 +83,23 @@ On Signal you can reach me using: jurre_ai.01 as username.

    ### Stories I've worked on

    **Amnesty International**

    - [How do authorities use firewalls and other tools for internet control?](https://securitylab.amnesty.org/latest/2024/11/understanding-national-firewalls-and-other-tools-for-internet-control/)
    - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/)
    - [India: Damning new forensic investigation reveals repeated use of Pegasus spyware to target high-profile journalists](https://securitylab.amnesty.org/latest/2023/12/india-damning-new-forensic-investigation-reveals-repeated-use-of-pegasus-spyware-to-target-high-profile-journalists/)
    - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/)
    - [The Predator Files: Caught in the Net](https://www.amnesty.org/en/documents/act10/7245/2023/en/)

    **OCCRP**

    - [When your “friends” spy on you: the firm pitching orwellian social media surveillance to militaries](https://forbiddenstories.org/story-killers/osint-s2t-unlocking-cyberspace-journalists-activists/)
    - [Hacks, bots and blackmail. How secret cyber mercenaries disrupt elections](https://www.occrp.org/en/storykillers/hacks-bots-and-blackmail-how-secret-cyber-mercenaries-disrupt-elections)
    - [Indian spy agency bought hardware matching equipment used for Pegasus](https://www.occrp.org/en/daily/16915-indian-spy-agency-bought-hardware-matching-equipment-used-for-pegasus)


    **Independent**

    - [Israeli spy tech sold to Bangladesh, despite dismal human rights record
    ](https://www.haaretz.com/israel-news/security-aviation/2023-01-10/ty-article/.premium/israeli-spy-tech-sold-to-worlds-third-largest-muslim-country/00000185-9692-d16a-a987-f6b75dd00000)
    - [Indian spy agency bought hardware matching equipment used for Pegasus](https://www.occrp.org/en/daily/16915-indian-spy-agency-bought-hardware-matching-equipment-used-for-pegasus)
    - [Fox-IT in Rusland (Dutch)](https://www.burojansen.nl/category/observant/observant-77/)
    - [AIVD-toezichthouder deed zaken met Moebarak en Assad; Fox-IT in het Midden-Oosten](https://www.burojansen.nl/category/observant/observant-73/)
  2. DrWhax revised this gist May 29, 2025. 1 changed file with 29 additions and 4 deletions.
    33 changes: 29 additions & 4 deletions README.md
    Original file line number Diff line number Diff line change
    @@ -4,11 +4,10 @@ While both websites are encrypted, visiting a more generic website gives you mor

    ## Who am I

    I'm a technologist at Amnesty's [Security Lab](https://www.amnesty.org/en/tech/).

    Formerly, I was a senior security analyst at [OCCRP](https://www.occrp.org/en/).
    I'm a technologist at Amnesty's [Security Lab](https://securitylab.amnesty.org/).

    - [Twitter](https://twitter.com/drwhax)
    - [BlueSky](https:// )
    - [Mastodon](https://infosec.exchange/@drwhax)
    - [Linkedin](https://www.linkedin.com/in/jurre-van-bergen-4a7079250/)

    @@ -20,7 +19,31 @@ I have various ways of establishing contact, some are more anonymous than others

    ### PGP

    You can encrypt securely using PGP to my e-mail address: drwhax [ @ ] riseup . net
    You can encrypt securely using PGP to my e-mail address and pick your security level.

    me [ @ ] jurrevanbergen [dot] nl (low security)

    ```
    -----BEGIN PGP PUBLIC KEY BLOCK-----
    xjMEaDdw8BYJKwYBBAHaRw8BAQdAtCV/XdzdcfuYOwj4FR8CzuQdWXro1y7r
    RNxx4i+vIzbNK21lQGp1cnJldmFuYmVyZ2VuLm5sIDxtZUBqdXJyZXZhbmJl
    cmdlbi5ubD7CwBEEExYKAIMFgmg3cPADCwkHCZD/49EtdkgS4kUUAAAAAAAc
    ACBzYWx0QG5vdGF0aW9ucy5vcGVucGdwanMub3JnbSJBzED9UKRmvKq0BrZo
    e4eIc0hdOU88QybXdhSrs3cDFQoIBBYAAgECGQECmwMCHgEWIQQs7axqPcPT
    DokxX6r/49EtdkgS4gAA5icA/ROVPU/vzdX1GiDqRSJfQqqcMYvx+mrRh0H/
    o+NADgQ9AQCNmccwy0KeySwL/tkT9rBA4ptQRXstKXj1jmFaFj07As44BGg3
    cPASCisGAQQBl1UBBQEBB0Dk2vF3c8Xww5r+onHVRef26aDOiu8GkKeuRtiK
    K+cXPAMBCAfCvgQYFgoAcAWCaDdw8AmQ/+PRLXZIEuJFFAAAAAAAHAAgc2Fs
    dEBub3RhdGlvbnMub3BlbnBncGpzLm9yZ+tm8CNVECQFsTw+V3/h6AnxvRcY
    gZIWUyuuRfzItRE3ApsMFiEELO2saj3D0w6JMV+q/+PRLXZIEuIAAGmSAPwK
    5vjsHPXj+YAGSXFf7Jgns8ZTyEBNYf6s4WdeaStQogD/XOZK8CZwAqP4Qt1x
    OTQqU5enLOwXikUAZ93vNkdAPQM=
    =MPs0
    -----END PGP PUBLIC KEY BLOCK-----
    ```

    drwhax [ @ ] riseup . net (high-security)

    ```
    -----BEGIN PGP PUBLIC KEY BLOCK-----
    @@ -60,6 +83,8 @@ On Signal you can reach me using: jurre_ai.01 as username.

    ### Stories I've worked on

    - [How do authorities use firewalls and other tools for internet control?](https://securitylab.amnesty.org/latest/2024/11/understanding-national-firewalls-and-other-tools-for-internet-control/)
    - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/)
    - [India: Damning new forensic investigation reveals repeated use of Pegasus spyware to target high-profile journalists](https://securitylab.amnesty.org/latest/2023/12/india-damning-new-forensic-investigation-reveals-repeated-use-of-pegasus-spyware-to-target-high-profile-journalists/)
    - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/)
    - [The Predator Files: Caught in the Net](https://www.amnesty.org/en/documents/act10/7245/2023/en/)
  3. DrWhax revised this gist Mar 24, 2025. 1 changed file with 10 additions and 9 deletions.
    19 changes: 10 additions & 9 deletions README.md
    Original file line number Diff line number Diff line change
    @@ -25,15 +25,16 @@ You can encrypt securely using PGP to my e-mail address: drwhax [ @ ] riseup . n
    ```
    -----BEGIN PGP PUBLIC KEY BLOCK-----
    xjMEYRmNJxYJKwYBBAHaRw8BAQdAuz6guveq3EZUOHm7bF71ALK3pTYsBSwk1b/xcp1JCR3NJEp1
    cnJlIHZhbiBCZXJnZW4gPGRyd2hheEByaXNldXAubmV0PsKWBBMWCAA+FiEEYq9fVr76ttS7hIAc
    qtuaRu4r2tYFAmEZjScCGwMFCQeEzgAFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQqtuaRu4r
    2tZcmgD+OXYmqUkQ2CwKFb8PHBJDtQiWUlMAR8kbmETnpfnaxwgA/1+vcHa7FUWxNmZAccFtrKbx
    7u2xM2JPoFjt0yuzBKkCzjgEYRmNJxIKKwYBBAGXVQEFAQEHQEdoE/ohoqcAqS+y9AoyVYq8f2Ro
    JyNPmHJWzeJfz5prAwEIB8J+BBgWCAAmFiEEYq9fVr76ttS7hIAcqtuaRu4r2tYFAmEZjScCGwwF
    CQeEzgAACgkQqtuaRu4r2tbLywD+MCqIMApp0/ynDjwPEM23/FRPYQoa2wq+Lyou/y1U9P0BANzn
    oiwiFcUBRO/j8/de/NVVkP+p9VP/AmL0ocSSB48M
    =64HK
    xjMEYRmNJxYJKwYBBAHaRw8BAQdAuz6guveq3EZUOHm7bF71ALK3pTYsBSwk1b/x
    cp1JCR3NJEp1cnJlIHZhbiBCZXJnZW4gPGRyd2hheEByaXNldXAubmV0PsKWBBMW
    CAA+FiEEYq9fVr76ttS7hIAcqtuaRu4r2tYFAmfhSPkCGwMFCQ5NMtkFCwkIBwIG
    FQoJCAsCBBYCAwECHgECF4AACgkQqtuaRu4r2tbOegEArc5EVRh4UyS+zNOhFsbB
    MtZ63A0kptbbzavwCZQqL1MA/3XJMhMqIC6hF35FG4g/aeAnppH1p6Sv5Y1PSSHB
    fcEIzjgEYRmNJxIKKwYBBAGXVQEFAQEHQEdoE/ohoqcAqS+y9AoyVYq8f2RoJyNP
    mHJWzeJfz5prAwEIB8J+BBgWCAAmFiEEYq9fVr76ttS7hIAcqtuaRu4r2tYFAmfh
    SPkCGwwFCQ5NMtkACgkQqtuaRu4r2ta5sQEAqXLBViq99+uavorC/cLKJdZpE6yh
    3SQg8yKyKLsvYyAA/ioZBrX9RiJYhobSihbI/BLYl4mP0gMrjGF6sbZhBLUA
    =DST+
    -----END PGP PUBLIC KEY BLOCK-----
    ```

  4. DrWhax revised this gist Jan 14, 2025. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion README.md
    Original file line number Diff line number Diff line change
    @@ -55,7 +55,7 @@ I'm reachable on Ricochet Refresh as: ```ricochet:htyjymsbqubhyxhohosx2nu75repen

    ### Signal

    On Signal you can reach me using: jurre.01 as username.
    On Signal you can reach me using: jurre_ai.01 as username.

    ### Stories I've worked on

  5. DrWhax revised this gist Nov 1, 2024. 1 changed file with 3 additions and 0 deletions.
    3 changes: 3 additions & 0 deletions README.md
    Original file line number Diff line number Diff line change
    @@ -59,6 +59,9 @@ On Signal you can reach me using: jurre.01 as username.

    ### Stories I've worked on

    - [India: Damning new forensic investigation reveals repeated use of Pegasus spyware to target high-profile journalists](https://securitylab.amnesty.org/latest/2023/12/india-damning-new-forensic-investigation-reveals-repeated-use-of-pegasus-spyware-to-target-high-profile-journalists/)
    - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/)
    - [The Predator Files: Caught in the Net](https://www.amnesty.org/en/documents/act10/7245/2023/en/)
    - [When your “friends” spy on you: the firm pitching orwellian social media surveillance to militaries](https://forbiddenstories.org/story-killers/osint-s2t-unlocking-cyberspace-journalists-activists/)
    - [Hacks, bots and blackmail. How secret cyber mercenaries disrupt elections](https://www.occrp.org/en/storykillers/hacks-bots-and-blackmail-how-secret-cyber-mercenaries-disrupt-elections)
    - [Israeli spy tech sold to Bangladesh, despite dismal human rights record
  6. DrWhax revised this gist Oct 19, 2024. 1 changed file with 1 addition and 8 deletions.
    9 changes: 1 addition & 8 deletions README.md
    Original file line number Diff line number Diff line change
    @@ -45,12 +45,6 @@ https://wire.com/en/

    I'm reachable on the encrypted messaging application Wire, you can connect with me by messaging @drwhax

    ### Threema

    https://threema.ch/en - works for both Android and iPhones.

    I'm reachable on the encrypted messenger Threema as: W8YD6F6C

    ### Richochet Refresh

    Is an encrypted anonymous messenger over the Tor network. While it's the most anonymous option, you might not want to connect from your home or work place on Ricochet Refresh. I recommend a more public place like a library, coffee shop or similar.
    @@ -71,5 +65,4 @@ On Signal you can reach me using: jurre.01 as username.
    ](https://www.haaretz.com/israel-news/security-aviation/2023-01-10/ty-article/.premium/israeli-spy-tech-sold-to-worlds-third-largest-muslim-country/00000185-9692-d16a-a987-f6b75dd00000)
    - [Indian spy agency bought hardware matching equipment used for Pegasus](https://www.occrp.org/en/daily/16915-indian-spy-agency-bought-hardware-matching-equipment-used-for-pegasus)
    - [Fox-IT in Rusland (Dutch)](https://www.burojansen.nl/category/observant/observant-77/)
    - [AIVD-toezichthouder deed zaken met Moebarak en Assad; Fox-IT in het Midden-Oosten
    ](https://www.burojansen.nl/category/observant/observant-73/)
    - [AIVD-toezichthouder deed zaken met Moebarak en Assad; Fox-IT in het Midden-Oosten](https://www.burojansen.nl/category/observant/observant-73/)
  7. DrWhax revised this gist Feb 29, 2024. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion README.md
    Original file line number Diff line number Diff line change
    @@ -61,7 +61,7 @@ I'm reachable on Ricochet Refresh as: ```ricochet:htyjymsbqubhyxhohosx2nu75repen

    ### Signal

    When Signal launches their usernames, you can reach me on @drwhax or reach out through other methods to be able to contact me over Signal.
    On Signal you can reach me using: jurre.01 as username.

    ### Stories I've worked on

  8. DrWhax revised this gist Jul 31, 2023. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion README.md
    Original file line number Diff line number Diff line change
    @@ -4,7 +4,7 @@ While both websites are encrypted, visiting a more generic website gives you mor

    ## Who am I

    I'm a technologist at Amnesty's Security Lab.
    I'm a technologist at Amnesty's [Security Lab](https://www.amnesty.org/en/tech/).

    Formerly, I was a senior security analyst at [OCCRP](https://www.occrp.org/en/).

  9. DrWhax revised this gist Jul 31, 2023. 1 changed file with 5 additions and 3 deletions.
    8 changes: 5 additions & 3 deletions README.md
    Original file line number Diff line number Diff line change
    @@ -4,13 +4,15 @@ While both websites are encrypted, visiting a more generic website gives you mor

    ## Who am I

    I'm a senior security analyst for [OCCRP](https://www.occrp.org/en/) but I help out on stories occasionally.
    I'm a technologist at Amnesty's Security Lab.

    Formerly, I was a senior security analyst at [OCCRP](https://www.occrp.org/en/).

    - [Twitter](https://twitter.com/drwhax)
    - [Mastodon](https://infosec.exchange/@drwhax)
    - [Linkedin](https://www.linkedin.com/in/jurre-van-bergen-4a7079250/)

    I operate on London time, but cyber is 24/7.
    I operate on London time.

    ## Reasonably secure contact methods

    @@ -59,7 +61,7 @@ I'm reachable on Ricochet Refresh as: ```ricochet:htyjymsbqubhyxhohosx2nu75repen

    ### Signal

    When Signal launches their usernames, you can reach me on @drwhax
    When Signal launches their usernames, you can reach me on @drwhax or reach out through other methods to be able to contact me over Signal.

    ### Stories I've worked on

  10. DrWhax created this gist Mar 1, 2023.
    73 changes: 73 additions & 0 deletions README.md
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,73 @@
    I'm writing this on Github as it will give the reader wanting to get in contact some level of plausible deniability as opposed to visiting my website.

    While both websites are encrypted, visiting a more generic website gives you more plausible deniability. Any institution that can wiretap or has metadata retention will only see you connecting to https://gist.github.com/ and not which page youre visiting.

    ## Who am I

    I'm a senior security analyst for [OCCRP](https://www.occrp.org/en/) but I help out on stories occasionally.

    - [Twitter](https://twitter.com/drwhax)
    - [Mastodon](https://infosec.exchange/@drwhax)
    - [Linkedin](https://www.linkedin.com/in/jurre-van-bergen-4a7079250/)

    I operate on London time, but cyber is 24/7.

    ## Reasonably secure contact methods

    I have various ways of establishing contact, some are more anonymous than others, please assess which communication method might fit your situation best.

    ### PGP

    You can encrypt securely using PGP to my e-mail address: drwhax [ @ ] riseup . net

    ```
    -----BEGIN PGP PUBLIC KEY BLOCK-----
    xjMEYRmNJxYJKwYBBAHaRw8BAQdAuz6guveq3EZUOHm7bF71ALK3pTYsBSwk1b/xcp1JCR3NJEp1
    cnJlIHZhbiBCZXJnZW4gPGRyd2hheEByaXNldXAubmV0PsKWBBMWCAA+FiEEYq9fVr76ttS7hIAc
    qtuaRu4r2tYFAmEZjScCGwMFCQeEzgAFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQqtuaRu4r
    2tZcmgD+OXYmqUkQ2CwKFb8PHBJDtQiWUlMAR8kbmETnpfnaxwgA/1+vcHa7FUWxNmZAccFtrKbx
    7u2xM2JPoFjt0yuzBKkCzjgEYRmNJxIKKwYBBAGXVQEFAQEHQEdoE/ohoqcAqS+y9AoyVYq8f2Ro
    JyNPmHJWzeJfz5prAwEIB8J+BBgWCAAmFiEEYq9fVr76ttS7hIAcqtuaRu4r2tYFAmEZjScCGwwF
    CQeEzgAACgkQqtuaRu4r2tbLywD+MCqIMApp0/ynDjwPEM23/FRPYQoa2wq+Lyou/y1U9P0BANzn
    oiwiFcUBRO/j8/de/NVVkP+p9VP/AmL0ocSSB48M
    =64HK
    -----END PGP PUBLIC KEY BLOCK-----
    ```

    ### Wire

    Is an open-source messenger supported for all major operating systems, both desktop and mobile. You don't need an phone number to create an account on Wire.

    https://wire.com/en/

    I'm reachable on the encrypted messaging application Wire, you can connect with me by messaging @drwhax

    ### Threema

    https://threema.ch/en - works for both Android and iPhones.

    I'm reachable on the encrypted messenger Threema as: W8YD6F6C

    ### Richochet Refresh

    Is an encrypted anonymous messenger over the Tor network. While it's the most anonymous option, you might not want to connect from your home or work place on Ricochet Refresh. I recommend a more public place like a library, coffee shop or similar.

    https://www.ricochetrefresh.net/

    I'm reachable on Ricochet Refresh as: ```ricochet:htyjymsbqubhyxhohosx2nu75repenhfixvbeu7ihtxc64dudclz3ead```

    ### Signal

    When Signal launches their usernames, you can reach me on @drwhax

    ### Stories I've worked on

    - [When your “friends” spy on you: the firm pitching orwellian social media surveillance to militaries](https://forbiddenstories.org/story-killers/osint-s2t-unlocking-cyberspace-journalists-activists/)
    - [Hacks, bots and blackmail. How secret cyber mercenaries disrupt elections](https://www.occrp.org/en/storykillers/hacks-bots-and-blackmail-how-secret-cyber-mercenaries-disrupt-elections)
    - [Israeli spy tech sold to Bangladesh, despite dismal human rights record
    ](https://www.haaretz.com/israel-news/security-aviation/2023-01-10/ty-article/.premium/israeli-spy-tech-sold-to-worlds-third-largest-muslim-country/00000185-9692-d16a-a987-f6b75dd00000)
    - [Indian spy agency bought hardware matching equipment used for Pegasus](https://www.occrp.org/en/daily/16915-indian-spy-agency-bought-hardware-matching-equipment-used-for-pegasus)
    - [Fox-IT in Rusland (Dutch)](https://www.burojansen.nl/category/observant/observant-77/)
    - [AIVD-toezichthouder deed zaken met Moebarak en Assad; Fox-IT in het Midden-Oosten
    ](https://www.burojansen.nl/category/observant/observant-73/)