@neurovagrant@masto.deoan.org cover
@neurovagrant@masto.deoan.org avatar

neurovagrant

@neurovagrant@masto.deoan.org

Security ops engineer, former congressional sysadmin, writer, voracious reader. he/him. Opinions here mine only. No LLM content from me, all flaws detected are human-generated. Autistic/depressed/anxious/hungry.

#infosec #cybersecurity #privacy #actuallyautistic #neurodivergent

This profile is from a federated server and may be incomplete. For a complete list of posts, browse on the original instance.

jerry , (edited ) to random
@jerry@infosec.exchange avatar

🤯😱

EDIT: many people have pointed out that the breaker will still trip, and in fact this is actually required by fire code.

neurovagrant ,
@neurovagrant@masto.deoan.org avatar

@catsalad @jerry funny, that was my nickname in college.

alice , to random
@alice@lgbtqia.space avatar

I just went on a follow-fest for women with a PhD, but realized I'm already mutuals with almost everyone who shows up in the limited search results 😋

If you're a Dr. Gal or other female science communicator type, pop into the thread, say hi!

I'd love to learn about what you do 💜
(and I'm sure lots of others would too)

(on Tuesday)

neurovagrant ,
@neurovagrant@masto.deoan.org avatar

@alice this was a fantastic thread to find new folks to follow, thank you for it.

jerry , to random
@jerry@infosec.exchange avatar

It’s a rather humbling thing to have the HR person that’s supported me for years ask where I want the box sent so I can return my company laptop and how many days of vacation I took so they can pay out the balance. A rather disappointing end to a 25 year run, first with Netrex that was bought in 1999 by Internet Security Systems, which was bought in 2006 by IBM.

Anyway, here we goooo

neurovagrant ,
@neurovagrant@masto.deoan.org avatar

@jerry in before "@humanresources" account appears and things get much weirder

jerry , to random
@jerry@infosec.exchange avatar

I find it interesting that around 90% of spam account signups on Infosec.exchange use a gmail address to register. Now, that’s partly biased because I’ve blocked most of the junk email services that allow creating email addresses without needing to sign in or register, so I don’t know what it would look like if those were permitted, however it must be quite efficient for people to create large numbers of gmail accounts.

neurovagrant ,
@neurovagrant@masto.deoan.org avatar

@jerry whatever gets those gmail user metrics up for the execs, right?

email is a frickin' cartel...

dangoodin , to random
@dangoodin@infosec.exchange avatar

A reminder that if you're a member of a union or consider yourself pro labor you should avoid buying from Amazon whenever possible.

https://www.404media.co/amazons-ai-warehouses-isolate-workers-impact-union-organizing-new-report-finds/

neurovagrant ,
@neurovagrant@masto.deoan.org avatar

@chux0r @dangoodin

I've had really good experiences with bookshop.org for physical books and libro.fm for audiobooks so far!

neurovagrant , to random
@neurovagrant@masto.deoan.org avatar

This is a cool advance, but also some top-notch nightmare fuel.

Makes me think of the chemical the Panther Moderns pretended they put in the Sense/Net building water supply during Molly’s run.

https://au.news.yahoo.com/the-worlds-first-tooth-regrowing-drug-has-been-approved-for-human-trials-174423381.html

neurovagrant OP ,
@neurovagrant@masto.deoan.org avatar

“The intravenous drug deactivates the uterine sensitization-associated gene-1 (USAG-1) protein that suppresses tooth growth. Blocking USAG-1 from interacting with other proteins triggers bone growth and, voila…”

jerry , to random
@jerry@infosec.exchange avatar

[Thread, post or comment was deleted by the author]

  • Loading...
  • neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @jerry project itself is legit, lead dev/founder dude loves to pick fights so there's regularly some toxic swagger going in any given direction around it.

    have interacted with a couple other folks involved, who seem fine and cool.

    jerry , to random
    @jerry@infosec.exchange avatar

    The sheriff is out doing very low flybys to try to get people out of the water today due to strong rip currents. It’s not working so well.

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @jerry gotta justify that helicopter budget somehow

    jerry , to random
    @jerry@infosec.exchange avatar

    Hypothetically speaking, if I needed a university text book on short notice, where could one find those to download? This is totally not because my son forgot to buy a book for an assignment that is due today.

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @jerry 🏴‍☠️ you should add this to your display name now and fly it proudly

    lowqualityfacts , to random
    @lowqualityfacts@mstdn.social avatar

    Turned 32 today. I share a birthday with Bob Dylan, John C. Reilly, and billions of ants.

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @lowqualityfacts Happy birthday!

    Ah, I remember 32. Terrible year, but at least I didn't need upstairs ibuprofen and downstairs ibuprofen. That came a few years later.

    jerry , to random
    @jerry@infosec.exchange avatar

    I do wonder how long till systemd has Recall-like functionality

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @jerry jerry, you just had to go there, didn't you

    molly0xfff , to random
    @molly0xfff@hachyderm.io avatar

    back in my day we called this spyware

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @molly0xfff the windows stalkerware industry is gonna take a hit over this free offering, boy howdy

    neurovagrant , to random
    @neurovagrant@masto.deoan.org avatar

    You'd think Mozilla would work hard to differentiate themselves from other corporations in that sphere, rather than making the same stupid, user-antagonistic choices.

    https://blog.mozilla.org/en/products/firefox/firefox-search-update/

    neurovagrant OP ,
    @neurovagrant@masto.deoan.org avatar

    @AAKL Agreed.

    My quest for a decent amount of privacy feels like it's more and more quixotic

    Nonya_Bidniss , to random
    @Nonya_Bidniss@mas.to avatar

    Why do I keep getting no-follower, locked, French language accounts trying to follow me? Seems like what could be called "inauthentic behavior." I've been blocking them.

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @Nonya_Bidniss seeing similar

    lowqualityfacts , to random
    @lowqualityfacts@mstdn.social avatar

    Look, I get it. Jack wants the freedom to sport that godawful beard and Twitter is genuinely the only place where wannabe billionaire simps won't roast him for having facial hair that somehow screams "white supremacist billy goat".

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @lowqualityfacts To me Jack Dorsey’s beard evokes nothing so much as “Responsibility Duck Dynasty”

    Em0nM4stodon , to random
    @Em0nM4stodon@infosec.exchange avatar

    If you are the tech-savvy person within your family or friends group :blobcatcool: :

    Never ever shame someone for coming to you for advice after being the victim of a scam, malware, or for using an unsecure product.

    If you do this,
    they might never come back to you later. They might just feel so ashamed they will just stay alone with their tech problems.

    Instead, always tell them:

    1. It was a good idea to come to you with this. Be empathetic with them 💚

    2. Give them advice on how to minimize the damage now. Actionable advice 🚑

    3. Help them harden their security for now and for the future. Recommend better products to them. But be careful not to overwhelm them with advice. One step at the time 🔒

    4. Talk to them with respect and empathy. Tell them how the people who abused their trust are horrible and anyone can fall for the right scam. Remind them there are things to do to reduce the risks of being victimized again in the future, and help them slowly implementing these 💪

    5. Be thankful they trusted you with this. It means they think highly of you 🥰

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @Em0nM4stodon There's a few people I've sent this Feb '24 post by @pluralistic on how he got scammed specifically to say "if they can bag this guy, you sure as hell shouldn't feel ashamed about what happened to you"

    https://pluralistic.net/2024/02/05/cyber-dunning-kruger/

    jerry , to random
    @jerry@infosec.exchange avatar

    So, it turns out today was “chainsaw adoption day” at Home Depot. I just couldn’t let that poor chainsaw stay homeless.

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @jerry heathens

    neurovagrant , to random
    @neurovagrant@masto.deoan.org avatar

    "where were you radicalized?"

    the iphone i couldn't secure outgoing data on,

    the tv i couldn't avoid injected ads on,

    the quiet of my own home penetrated by 801 data processing partners

    simply for wanting to connect.

    neurovagrant , to random
    @neurovagrant@masto.deoan.org avatar

    I got to spend a while talking about @pluralistic on the work infosec podcast (his recent article about getting scammed was a fantastic writeup).

    As a bonus, I also got to pull in @Wolven 's impressive work on AI as @NotTheLinux and I pondered about the future of scams.

    https://www.domaintools.com/resources/podcasts/breaking-badness-cybersecurity-podcast-179-scamily-matters/

    neurovagrant , to random
    @neurovagrant@masto.deoan.org avatar

    Apple: Hey dude this domain keeps getting contacted by multiple apps, it may be building a profile on you.

    Me: Okay so you’re going to let me regulate device traffic to that domain, right?

    Apple: uh…

    pluralistic , to random
    @pluralistic@mamot.fr avatar

    I wuz robbed.

    More specifically, I was tricked by a phone-phisher pretending to be from my bank, and he convinced me to hand over my credit-card number, then did $8,000+ worth of fraud with it before I figured out what happened. And then he tried to do it again, a week later!

    --

    If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

    https://pluralistic.net/2024/02/05/cyber-dunning-kruger/#swiss-cheese-security

    1/

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @pluralistic My 76-year-old father is still smarting from falling for CC fraudsters last year.

    I sent him this article with a preface explaining who you are, and saying "If they can get Cory Fucking Doctorow, you can give yourself a little more slack."

    Thanks.

    neurovagrant , to random
    @neurovagrant@masto.deoan.org avatar

    just sayin’

    ALT
  • Reply
  • Loading...
  • lowqualityfacts , to random
    @lowqualityfacts@mstdn.social avatar

    Nicotine withdrawal sounds rough.
    https://patreon.com/lowqualityfacts

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @lowqualityfacts i see this one brought out a bunch of guys talking about their experiences.

    what a buncha manspleeners

    neurovagrant , to random
    @neurovagrant@masto.deoan.org avatar

    Five years ago today, on AI and jobs...

    ALT
  • Reply
  • Loading...
  • lowqualityfacts , to random
    @lowqualityfacts@mstdn.social avatar

    Those were the good old days.
    https://patreon.com/lowqualityfacts

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @lowqualityfacts you forget the "And Hotpot."

    That's where the whole "dunkin" thing came from.

    neurovagrant , to random
    @neurovagrant@masto.deoan.org avatar

    Fortify.

    I dig it.

    ALT
  • Reply
  • Loading...
  • neurovagrant , to random
    @neurovagrant@masto.deoan.org avatar

    Hello friends, I've seen the below image come up a few times elsewhere and am going to expound a little!

    While the hyperlinks in the image display correctly, those aren't actually the addresses of those sites! Instead, they're the Internationalized Domain Name replacements - examples of what are called IDN Homograph Attacks.

    It's incredibly hard to include all characters from all active alphabets in the mechanisms that resolve domain names - so currently that letter set is restricted, and instead uses a translation system called Punycode to move between a visual URL with the correct characters and a domain name your computer can actually resolve to a website.

    So while neurovagrant[.]com is fine either way, nӘ̃urovagrant[.]com isn't! The actually domain would be xn--nurovagrant-rkg322d[.]com.

    Notice that xn-- ! That's what tells browsers and other software that it's an IDN domain, and to try and translate it.

    Attackers use this to their benefit. So:

    xn--mcrosoft-security-teams-1ec[.]com can appear in your email, on your twitter feed, in other places visually as: mícrosoft-security-teams[.]com

    You may think you're signing in to check your retirement at vanguarɗ[.]com but it's actually sent you to xn--vanguar-4cd[.]com

    A link that appears as vḙnmo[.]com actually sends you to the website xn--vnmo-q64a[.]com

    They even target kids! Take a look at xn--rblox-jua[.]com - which looks like röblox[.]com in most settings. Note the diacritical mark above the first o.

    If anything looks off, there's a reason. Always view links with skepticism, don't click on things unnecessarily, and always sign into the sites you use by going to the domain name you know.

    Stay frosty out there, friends.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines