r-cybersecurity / list-of-security-resources-for-ukraine

List of companies or individuals offering cybersecurity services, data, or other tangible assets to assist in Ukraine's defense of its independence.
Other
67 stars 7 forks source link

New Security Resource for Ukraine #20

Closed GerbalSnowCrashGitHub closed 2 years ago

GerbalSnowCrashGitHub commented 2 years ago

Please fill out all data in [brackets].

Services offered by: [Hypasec, Chris Kubecks]

Source of information: [self reported by Chris Kubecka]

Services being offered: [Incident Response services]

Who is eligible: [EU-based NATO members, Ukranians, journalists, other]

How are the services accessed: [by email form or phone call listed on hypasec.com]

tweedge commented 2 years ago

Hi! Appreciate the offer, would it be possible to confirm your identity, for example unifying your GitHub and Twitter with a Keybase account? I can also email your hypasec.com email address if preferable. Just let me know!

GerbalSnowCrashGitHub commented 2 years ago

Dear Chris,

I feel as though any hoop you want me to jump through it will never be enough. You could have asked Kirbstr, checked my Twitter, my wiki page, my domain etc.

I will tell the folks I am working with it is impossible to work with you. Have a great evening.

Warmest regards,

Chris Kubecka CEO, HypaSec

Follow me!

@SecEvangelism

@HypaSec

Schedule me!

https://calendly.com/hypasec

Author of the book Hack the World with OSINT https://amzn.to/2NiEFlD

Author of Down the Rabbit Hole and OSINT Journey https://amzn.to/2P65pbN

Wikipedia: https://en.wikipedia.org/wiki/Chris_Kubecka

-------- Original Message -------- On Mar 12, 2022, 08:55, Chris Partridge < @.***> wrote:

Hi! Appreciate the offer, would it be possible to confirm your identity, for example unifying your GitHub and Twitter with a Keybase account? I can also email your hypasec.com email address if preferable. Just let me know!

— Reply to this email directly, view it on GitHub, or unsubscribe. Triage notifications on the go with GitHub Mobile for iOS or Android. You are receiving this because you authored the thread.AHECKMTF566X2ZRZRJV7HUTU7REWBA5CNFSM5QPDBKXKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOH6DV4WQ.gifMessage ID: @.***>

tweedge commented 2 years ago

You made a GitHub issue, the only information we have is your GitHub account name. Your email isn't public on your GitHub. Anyone can name their GitHub account whatever they want and list any Twitter account they like - to showcase this, I have just made my GitHub profile link to your Twitter, your workplace, and use your name. You can view my GitHub profile showing this here: https://web.archive.org/web/20220313231112/https://github.com/tweedge

I checked your About page on your website (https://www.hypasec.com/), and it does not list the GitHub account as affiliated with you. The same goes for your Twitter, @SecEvangelism. No GitHub link I can see.

We want to do a basic check - and I want to be clear in case I wasn't before, that anything works as long as it validates you are the real requester - because we don't want malicious actors to use this as a way to harass people, flood their email or Twitter messages, etc.

If you are unable or unwilling to verify that you own this GitHub account, that's OK, but I hope you understand that means we wouldn't be able to add you to this list.

tweedge commented 2 years ago

Hey again Chris, with @monsterjeep's help we have reasonable confirmation that this GitHub account belongs to you.

I'm chalking this up to a misunderstanding and hope your time in Ukraine was fruitful, it's admirable work and beyond-understandable you'd be stressed and busy at this time, where a request to verify your association with a GitHub account could sound unreasonably small.

If you have further concerns or would no longer like to be added to this list, please leave a note here or in the email I sent and we'll get you removed.

tweedge commented 2 years ago

Added in 6c91782.