Last active
May 29, 2025 00:25
-
-
Save DrWhax/61978d4e7df5291d4cf308f10dc20d5a to your computer and use it in GitHub Desktop.
Revisions
-
DrWhax revised this gist
May 29, 2025 . 1 changed file with 10 additions and 2 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -83,15 +83,23 @@ On Signal you can reach me using: jurre_ai.01 as username. ### Stories I've worked on **Amnesty International** - [How do authorities use firewalls and other tools for internet control?](https://securitylab.amnesty.org/latest/2024/11/understanding-national-firewalls-and-other-tools-for-internet-control/) - [India: Damning new forensic investigation reveals repeated use of Pegasus spyware to target high-profile journalists](https://securitylab.amnesty.org/latest/2023/12/india-damning-new-forensic-investigation-reveals-repeated-use-of-pegasus-spyware-to-target-high-profile-journalists/) - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/) - [The Predator Files: Caught in the Net](https://www.amnesty.org/en/documents/act10/7245/2023/en/) **OCCRP** - [When your “friends” spy on you: the firm pitching orwellian social media surveillance to militaries](https://forbiddenstories.org/story-killers/osint-s2t-unlocking-cyberspace-journalists-activists/) - [Hacks, bots and blackmail. How secret cyber mercenaries disrupt elections](https://www.occrp.org/en/storykillers/hacks-bots-and-blackmail-how-secret-cyber-mercenaries-disrupt-elections) - [Indian spy agency bought hardware matching equipment used for Pegasus](https://www.occrp.org/en/daily/16915-indian-spy-agency-bought-hardware-matching-equipment-used-for-pegasus) **Independent** - [Israeli spy tech sold to Bangladesh, despite dismal human rights record ](https://www.haaretz.com/israel-news/security-aviation/2023-01-10/ty-article/.premium/israeli-spy-tech-sold-to-worlds-third-largest-muslim-country/00000185-9692-d16a-a987-f6b75dd00000) - [Fox-IT in Rusland (Dutch)](https://www.burojansen.nl/category/observant/observant-77/) - [AIVD-toezichthouder deed zaken met Moebarak en Assad; Fox-IT in het Midden-Oosten](https://www.burojansen.nl/category/observant/observant-73/) -
DrWhax revised this gist
May 29, 2025 . 1 changed file with 29 additions and 4 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -4,11 +4,10 @@ While both websites are encrypted, visiting a more generic website gives you mor ## Who am I I'm a technologist at Amnesty's [Security Lab](https://securitylab.amnesty.org/). - [Twitter](https://twitter.com/drwhax) - [BlueSky](https:// ) - [Mastodon](https://infosec.exchange/@drwhax) - [Linkedin](https://www.linkedin.com/in/jurre-van-bergen-4a7079250/) @@ -20,7 +19,31 @@ I have various ways of establishing contact, some are more anonymous than others ### PGP You can encrypt securely using PGP to my e-mail address and pick your security level. me [ @ ] jurrevanbergen [dot] nl (low security) ``` -----BEGIN PGP PUBLIC KEY BLOCK----- xjMEaDdw8BYJKwYBBAHaRw8BAQdAtCV/XdzdcfuYOwj4FR8CzuQdWXro1y7r RNxx4i+vIzbNK21lQGp1cnJldmFuYmVyZ2VuLm5sIDxtZUBqdXJyZXZhbmJl cmdlbi5ubD7CwBEEExYKAIMFgmg3cPADCwkHCZD/49EtdkgS4kUUAAAAAAAc ACBzYWx0QG5vdGF0aW9ucy5vcGVucGdwanMub3JnbSJBzED9UKRmvKq0BrZo e4eIc0hdOU88QybXdhSrs3cDFQoIBBYAAgECGQECmwMCHgEWIQQs7axqPcPT DokxX6r/49EtdkgS4gAA5icA/ROVPU/vzdX1GiDqRSJfQqqcMYvx+mrRh0H/ o+NADgQ9AQCNmccwy0KeySwL/tkT9rBA4ptQRXstKXj1jmFaFj07As44BGg3 cPASCisGAQQBl1UBBQEBB0Dk2vF3c8Xww5r+onHVRef26aDOiu8GkKeuRtiK K+cXPAMBCAfCvgQYFgoAcAWCaDdw8AmQ/+PRLXZIEuJFFAAAAAAAHAAgc2Fs dEBub3RhdGlvbnMub3BlbnBncGpzLm9yZ+tm8CNVECQFsTw+V3/h6AnxvRcY gZIWUyuuRfzItRE3ApsMFiEELO2saj3D0w6JMV+q/+PRLXZIEuIAAGmSAPwK 5vjsHPXj+YAGSXFf7Jgns8ZTyEBNYf6s4WdeaStQogD/XOZK8CZwAqP4Qt1x OTQqU5enLOwXikUAZ93vNkdAPQM= =MPs0 -----END PGP PUBLIC KEY BLOCK----- ``` drwhax [ @ ] riseup . net (high-security) ``` -----BEGIN PGP PUBLIC KEY BLOCK----- @@ -60,6 +83,8 @@ On Signal you can reach me using: jurre_ai.01 as username. ### Stories I've worked on - [How do authorities use firewalls and other tools for internet control?](https://securitylab.amnesty.org/latest/2024/11/understanding-national-firewalls-and-other-tools-for-internet-control/) - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/) - [India: Damning new forensic investigation reveals repeated use of Pegasus spyware to target high-profile journalists](https://securitylab.amnesty.org/latest/2023/12/india-damning-new-forensic-investigation-reveals-repeated-use-of-pegasus-spyware-to-target-high-profile-journalists/) - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/) - [The Predator Files: Caught in the Net](https://www.amnesty.org/en/documents/act10/7245/2023/en/) -
DrWhax revised this gist
Mar 24, 2025 . 1 changed file with 10 additions and 9 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -25,15 +25,16 @@ You can encrypt securely using PGP to my e-mail address: drwhax [ @ ] riseup . n ``` -----BEGIN PGP PUBLIC KEY BLOCK----- xjMEYRmNJxYJKwYBBAHaRw8BAQdAuz6guveq3EZUOHm7bF71ALK3pTYsBSwk1b/x cp1JCR3NJEp1cnJlIHZhbiBCZXJnZW4gPGRyd2hheEByaXNldXAubmV0PsKWBBMW CAA+FiEEYq9fVr76ttS7hIAcqtuaRu4r2tYFAmfhSPkCGwMFCQ5NMtkFCwkIBwIG FQoJCAsCBBYCAwECHgECF4AACgkQqtuaRu4r2tbOegEArc5EVRh4UyS+zNOhFsbB MtZ63A0kptbbzavwCZQqL1MA/3XJMhMqIC6hF35FG4g/aeAnppH1p6Sv5Y1PSSHB fcEIzjgEYRmNJxIKKwYBBAGXVQEFAQEHQEdoE/ohoqcAqS+y9AoyVYq8f2RoJyNP mHJWzeJfz5prAwEIB8J+BBgWCAAmFiEEYq9fVr76ttS7hIAcqtuaRu4r2tYFAmfh SPkCGwwFCQ5NMtkACgkQqtuaRu4r2ta5sQEAqXLBViq99+uavorC/cLKJdZpE6yh 3SQg8yKyKLsvYyAA/ioZBrX9RiJYhobSihbI/BLYl4mP0gMrjGF6sbZhBLUA =DST+ -----END PGP PUBLIC KEY BLOCK----- ``` -
DrWhax revised this gist
Jan 14, 2025 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -55,7 +55,7 @@ I'm reachable on Ricochet Refresh as: ```ricochet:htyjymsbqubhyxhohosx2nu75repen ### Signal On Signal you can reach me using: jurre_ai.01 as username. ### Stories I've worked on -
DrWhax revised this gist
Nov 1, 2024 . 1 changed file with 3 additions and 0 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -59,6 +59,9 @@ On Signal you can reach me using: jurre.01 as username. ### Stories I've worked on - [India: Damning new forensic investigation reveals repeated use of Pegasus spyware to target high-profile journalists](https://securitylab.amnesty.org/latest/2023/12/india-damning-new-forensic-investigation-reveals-repeated-use-of-pegasus-spyware-to-target-high-profile-journalists/) - [A Web of Surveillance: Unravelling a murky network of spyware exports to Indonesia](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/) - [The Predator Files: Caught in the Net](https://www.amnesty.org/en/documents/act10/7245/2023/en/) - [When your “friends” spy on you: the firm pitching orwellian social media surveillance to militaries](https://forbiddenstories.org/story-killers/osint-s2t-unlocking-cyberspace-journalists-activists/) - [Hacks, bots and blackmail. How secret cyber mercenaries disrupt elections](https://www.occrp.org/en/storykillers/hacks-bots-and-blackmail-how-secret-cyber-mercenaries-disrupt-elections) - [Israeli spy tech sold to Bangladesh, despite dismal human rights record -
DrWhax revised this gist
Oct 19, 2024 . 1 changed file with 1 addition and 8 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -45,12 +45,6 @@ https://wire.com/en/ I'm reachable on the encrypted messaging application Wire, you can connect with me by messaging @drwhax ### Richochet Refresh Is an encrypted anonymous messenger over the Tor network. While it's the most anonymous option, you might not want to connect from your home or work place on Ricochet Refresh. I recommend a more public place like a library, coffee shop or similar. @@ -71,5 +65,4 @@ On Signal you can reach me using: jurre.01 as username. ](https://www.haaretz.com/israel-news/security-aviation/2023-01-10/ty-article/.premium/israeli-spy-tech-sold-to-worlds-third-largest-muslim-country/00000185-9692-d16a-a987-f6b75dd00000) - [Indian spy agency bought hardware matching equipment used for Pegasus](https://www.occrp.org/en/daily/16915-indian-spy-agency-bought-hardware-matching-equipment-used-for-pegasus) - [Fox-IT in Rusland (Dutch)](https://www.burojansen.nl/category/observant/observant-77/) - [AIVD-toezichthouder deed zaken met Moebarak en Assad; Fox-IT in het Midden-Oosten](https://www.burojansen.nl/category/observant/observant-73/) -
DrWhax revised this gist
Feb 29, 2024 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -61,7 +61,7 @@ I'm reachable on Ricochet Refresh as: ```ricochet:htyjymsbqubhyxhohosx2nu75repen ### Signal On Signal you can reach me using: jurre.01 as username. ### Stories I've worked on -
DrWhax revised this gist
Jul 31, 2023 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -4,7 +4,7 @@ While both websites are encrypted, visiting a more generic website gives you mor ## Who am I I'm a technologist at Amnesty's [Security Lab](https://www.amnesty.org/en/tech/). Formerly, I was a senior security analyst at [OCCRP](https://www.occrp.org/en/). -
DrWhax revised this gist
Jul 31, 2023 . 1 changed file with 5 additions and 3 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -4,13 +4,15 @@ While both websites are encrypted, visiting a more generic website gives you mor ## Who am I I'm a technologist at Amnesty's Security Lab. Formerly, I was a senior security analyst at [OCCRP](https://www.occrp.org/en/). - [Twitter](https://twitter.com/drwhax) - [Mastodon](https://infosec.exchange/@drwhax) - [Linkedin](https://www.linkedin.com/in/jurre-van-bergen-4a7079250/) I operate on London time. ## Reasonably secure contact methods @@ -59,7 +61,7 @@ I'm reachable on Ricochet Refresh as: ```ricochet:htyjymsbqubhyxhohosx2nu75repen ### Signal When Signal launches their usernames, you can reach me on @drwhax or reach out through other methods to be able to contact me over Signal. ### Stories I've worked on -
DrWhax created this gist
Mar 1, 2023 .There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -0,0 +1,73 @@ I'm writing this on Github as it will give the reader wanting to get in contact some level of plausible deniability as opposed to visiting my website. While both websites are encrypted, visiting a more generic website gives you more plausible deniability. Any institution that can wiretap or has metadata retention will only see you connecting to https://gist.github.com/ and not which page youre visiting. ## Who am I I'm a senior security analyst for [OCCRP](https://www.occrp.org/en/) but I help out on stories occasionally. - [Twitter](https://twitter.com/drwhax) - [Mastodon](https://infosec.exchange/@drwhax) - [Linkedin](https://www.linkedin.com/in/jurre-van-bergen-4a7079250/) I operate on London time, but cyber is 24/7. ## Reasonably secure contact methods I have various ways of establishing contact, some are more anonymous than others, please assess which communication method might fit your situation best. ### PGP You can encrypt securely using PGP to my e-mail address: drwhax [ @ ] riseup . net ``` -----BEGIN PGP PUBLIC KEY BLOCK----- xjMEYRmNJxYJKwYBBAHaRw8BAQdAuz6guveq3EZUOHm7bF71ALK3pTYsBSwk1b/xcp1JCR3NJEp1 cnJlIHZhbiBCZXJnZW4gPGRyd2hheEByaXNldXAubmV0PsKWBBMWCAA+FiEEYq9fVr76ttS7hIAc qtuaRu4r2tYFAmEZjScCGwMFCQeEzgAFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQqtuaRu4r 2tZcmgD+OXYmqUkQ2CwKFb8PHBJDtQiWUlMAR8kbmETnpfnaxwgA/1+vcHa7FUWxNmZAccFtrKbx 7u2xM2JPoFjt0yuzBKkCzjgEYRmNJxIKKwYBBAGXVQEFAQEHQEdoE/ohoqcAqS+y9AoyVYq8f2Ro JyNPmHJWzeJfz5prAwEIB8J+BBgWCAAmFiEEYq9fVr76ttS7hIAcqtuaRu4r2tYFAmEZjScCGwwF CQeEzgAACgkQqtuaRu4r2tbLywD+MCqIMApp0/ynDjwPEM23/FRPYQoa2wq+Lyou/y1U9P0BANzn oiwiFcUBRO/j8/de/NVVkP+p9VP/AmL0ocSSB48M =64HK -----END PGP PUBLIC KEY BLOCK----- ``` ### Wire Is an open-source messenger supported for all major operating systems, both desktop and mobile. You don't need an phone number to create an account on Wire. https://wire.com/en/ I'm reachable on the encrypted messaging application Wire, you can connect with me by messaging @drwhax ### Threema https://threema.ch/en - works for both Android and iPhones. I'm reachable on the encrypted messenger Threema as: W8YD6F6C ### Richochet Refresh Is an encrypted anonymous messenger over the Tor network. While it's the most anonymous option, you might not want to connect from your home or work place on Ricochet Refresh. I recommend a more public place like a library, coffee shop or similar. https://www.ricochetrefresh.net/ I'm reachable on Ricochet Refresh as: ```ricochet:htyjymsbqubhyxhohosx2nu75repenhfixvbeu7ihtxc64dudclz3ead``` ### Signal When Signal launches their usernames, you can reach me on @drwhax ### Stories I've worked on - [When your “friends” spy on you: the firm pitching orwellian social media surveillance to militaries](https://forbiddenstories.org/story-killers/osint-s2t-unlocking-cyberspace-journalists-activists/) - [Hacks, bots and blackmail. How secret cyber mercenaries disrupt elections](https://www.occrp.org/en/storykillers/hacks-bots-and-blackmail-how-secret-cyber-mercenaries-disrupt-elections) - [Israeli spy tech sold to Bangladesh, despite dismal human rights record ](https://www.haaretz.com/israel-news/security-aviation/2023-01-10/ty-article/.premium/israeli-spy-tech-sold-to-worlds-third-largest-muslim-country/00000185-9692-d16a-a987-f6b75dd00000) - [Indian spy agency bought hardware matching equipment used for Pegasus](https://www.occrp.org/en/daily/16915-indian-spy-agency-bought-hardware-matching-equipment-used-for-pegasus) - [Fox-IT in Rusland (Dutch)](https://www.burojansen.nl/category/observant/observant-77/) - [AIVD-toezichthouder deed zaken met Moebarak en Assad; Fox-IT in het Midden-Oosten ](https://www.burojansen.nl/category/observant/observant-73/)