Oddbean new post about | logout

Notes by Ian Campbell | export

 TP-link has earned a reputation as a producer of insecure routers. They seem to push things out a... 
 @Dr. Hax pretty much the angle I'm looking at it from, wondering (as usual) if I missed something 
 Any user-friendly antivirus for linux?

(no, clamav doesn't count)

If not, why are you recommending regular folks use linux? I'm concerned by this trend. 
 i have a confession

i found a fresh ecig while cleaning the other day and i've been vaping nicotine lightly but regularly since and it has been sooooooo fucking nice.

pleasure has been fleeting for me (thanks depression) and nicotine lights up my brain like little else.

but a week or so in, another problem flared, and so i sat down (gingerly) to research. And...

...did anyone else know that nicotine aggravates hemorrhoids? 🙃 

i share this story as a warning. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d Yeah so for me, as a busine... 
 @663e5b60 Gotcha. Thanks! 
 Super cool that paying for LinkedIn Premium means I now have an unavoidable AI suggestion box on ... 
 @663e5b60 I've been vaguely thinking about LinkedIn Premium just to see how it benefits me platform-wise, but I'm not on the job hunt.

If you're willing to share, how are you finding it? 
 Why is it so hard to keep eyeglasses clean, and furthermore why is this an attack on me, personally, on this grim Monday morning? 
 One of the things that continues to give me hope - and this may be silly to some - is just how actively @749d2a0c continues to improve and expand in organic ways.

I moved from GMail to Proton and haven't had a second of doubt. They respond quickly and clearly to support requests and provide multiple avenues to usability that emphasize user privacy.

(I have no connection to Proton AG other than as a happy paying customer.)

https://mastodon.social/@protonmail/111726406129916106 
 After a month or so of working with it, had my first significant grapheneOS issue: Google Play Store repeatedly crashing.

Device reboot fixed it.

I do kind of worry about Graphene's longevity as Google moves more and more of Play/etc into core Android services (but it's entirely viable for now).

#TurnItOffAndOnAgain #grapheneOS 
 Curious if this is Okta's LastPass moment. 
 Gettin a very pronounced vibe of "We're sick of your shit, Okta" from many directions this fine Friday evening.

https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/ 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d 

Let us know how that work... 
 @c28f48f4 Samsung is even more info-grabby than Google; otherwise, I love Samsung phones. 
 After a few weeks and a work trip with the Google Pixel Fold:

-It's a solid folding phone so far in a consumptive/tablet sense

-It's actually kinda neat to read kindle books in a two-column format with the phone a bit creased like a small book.

-I've tried half a dozen different stylus types on it and none worked really well, and the handling on it for trying to write/do much besides read/watch things is awkward. 

-It's nice to not have Samsung bloatware, but jesus h christ the amount of weird Google stuff that needs network permissions is annoying. 
 Any good books out there that provide a good intro to (FDM) 3D Printing for someone with zero background or applicable skills? 
 it is so cool out and i love it so much. 
 Random Maker question: if I want to make enclosures, in the context of creating cyberdeck/custom laptop kinds of things, am I looking at a particular 3D printer, or a CNC, or am I better off getting the materials and grinding/altering/constructing more conventionally? 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d 
Wait wait wait and WHAT!

... 
 @2da21b15 yeah I don't buy their explanation either, really 
 @6f64499d Thanks very much for that info - I don't have the brain to carve out cryptography nuance at the moment, so it is very appreciated. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d  Right?  Because Freaking h... 
 @ed85e5af i'm speechless 
 wtaf 

"In the trial, Issam Najm, an environmental engineer who specializes in water chemistry and testing, testified that the hydrazine likely formed in the "ionizer," which was just titanium tubes electrified with what looked like jumper cables used to charge a car battery."

https://arstechnica.com/health/2023/10/jury-awards-229m-to-victims-of-real-water-tainted-with-rocket-fuel-chemical/ 
 "He said that the person who developed the water treatment process for Real Water bought the titanium tubes "from some Russian guy in the 80s" and spent four to five months making alkaline waters in his garage, working until he had a formula that didn't make him vomit or have diarrhea." 
 23andMe: "Oh it's everyone else's fault, it's credential stuffing."

But that's worse, right? You get how not having credential stuffing mitigations in your fucking gene registry is worse? 
 Had to warn my boss,

"So... this next blog post I wrote for GTM is... a little unique. Maybe a little unhinged. So if Marketing comes to you and asks 'Is Ian okay?!' that's probably why." 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d I got nothin' specific, but... 
 @d7a8a49d appreciate the boost, friend. 
 i hate feeling like i'm not doing my best work. covid brain suuuuuucks. 
 @d7a8a49d if anyone i know has ideas here, you might: https://tech.lgbt/@hpux735/111184192554424272 
 Just spent the last 10 minutes figuring out why I had no internet connection after upgrading to m... 
 @b902f84f negative, upgraded to Sonoma earlier this week with no LittleSnitch issue. I did see there's an update pending to LS yesterday on my macbook, but have not installed it yet. 
 Gmail tab on chrome, just sitting there: memory usage of 700+ MB.

what the hell, people 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d These are still quite expen... 
 @748d6504 given that they're sort of complex pokey wire, I'd be surprised if these were used as hair ties. 
 Note for neurodivergents/etc with strong sensory components: one of the items I've found most useful are these spiky "sensory rings" that easily roll on and off any finger, producing unique pressure and sensation.

They've been a great, subtle stim, including a good distraction from other sensory problems and sensory-related covid symptoms. And they're quite cheap.

#neurodivergent #ActuallyAutistic

https://www.amazon.com/gp/product/B08D3VSRFV/

https://masto.deoan.org/system/media_attachments/files/111/182/814/800/661/395/original/1783f28783c92956.png 
 For folks headed to BSides Orlando, my bud Dan Fernandez will be speaking on machine learning security issues.

Details here: https://www.linkedin.com/posts/dafdz_bsidesorlando-cybersecurity-machinelearning-activity-7113591646797094914-Bat5?utm_source=share&utm_medium=member_desktop 
 How many ways is this creepy?

"Walmart[] ... has been using anonymized sales data to see if it c... 
 @8e5af139 Can you provide a link to the NYT article, please?

Searching, but NYT doesn't make it particularly easy. 
 I think it's fundamentally unfair that I have rebound covid when I don't even play basketball. 
 aw son of a bitch, i just tested positive for covid again. finished paxlovid on saturday, negative tests on sunday and tuesday.

(this is not unheard of; see term post-paxlovid covid rebound - it just sucks) 
 oh man, Permission Slip is the ultimate mobile game.

Once set up each request takes three taps and gives me a little dopamine hit for fucking with data brokers.

All it needs is a satisfying slot machine type sound effect. 
 Wondering how many dummies brought phones into SCIFs and other clean areas only to have them go off today.

"Smith... is that your phone?"

"No, uh, that's my Emotional Support FEMA Alert..." 
 too relatable, from a private IRC channel:

<redacted> hahahaha, i just went to file a bug report on an instance of the issue i detected

<redacted> THE GOD DAMN BUG REPORT TICKET FEATURE ON THE GOD DAMN WEB SITE THREW A 400 BAD REQUEST 
 Just finished interviewing on an infosec podcast, pushing da neurodivergent propaganda as i do

feelsgoodyall.jpg

I'll link it when it comes out. 
 Ah, this'll go well.

TorchServe, a production server for machine learning framework PyTorch, exposes its management console to the world in default config with what looks like multiple paths to remote command execution.

https://www.oligo.security/blog/shelltorch-torchserve-ssrf-vulnerability-cve-2023-43654 
 Anyone else ever see the RJ45 inputs of rack-mounted switches as rows of teeth with tentacles, or is this another one of those things I should keep to therapy?

#spooktober 
 Aaaaaahaahahhahahahahahahahahaha aaaaaaaaaaaaaaaaahahahahahahhaa fuck you McCarthy 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d 

Do you have any other con... 
 @3aafc8d6 i do not. Should be fun! 
 @f0b14579 

googleads100[.]ru
googleads100kms[.]agency
googleads100kms[.]buzz
googleads100kms[.]club
googleads100kms[.]co
googleads100kms[.]info
googleads100kms[.]live
googleads100kms[.]online
googleads100kms[.]shop
googleads100kms[.]site
googleads100kms[.]space
googleads100kms[.]store
googleads100kms[.]website
googleads100kms[.]work
googleads100kms[.]xyz
track100googleads[.]blog
track100googleads[.]buzz
track100googleads[.]com
track100googleads[.]fun
track100googleads[.]info
track100googleads[.]live
track100googleads[.]shop
track100googleads[.]solutions
track100googleads[.]space
track100googleads[.]top
track100googleads[.]website
track100googleads[.]xyz 
 Just delivered a spooky October blogpost to Marketing that will likely leave folk with one overriding reaction:

"da fuq did I just read?!"

We'll see if they dig it... ;) 
 Did Zip drives really exist or was it just some fever dream?  :itsaliens: 
 @6a2035f3 About a decade after they disappeared, my dad came up to me with a zipdisk marked "My Documents" all excited.

"Can you get anything off this?! It looks like it has a bunch of my old writings!"

As the dutiful techie son, I snagged a cheap zipdrive and popped in the disk. Then began to laugh sadly.

Instead of copying the contents, Dad had just dragged-and-dropped Windows' "My Documents" - which was just a symlink to the actual folder. 

He had faithfully copied a shortcut. 
 How do you say "Happy Cybersecurity Awareness Month" in Elvish?

(filched from elsewhere.)

https://masto.deoan.org/system/media_attachments/files/111/171/042/558/365/606/original/fba69ef7e58c56f9.jpg 
 Ohhhh, Michael Lewis' book on Sam Bankman-Fried, Going Infinite, is out today.

This promises many lulz. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d
Oh.... Oh no. 
 @3aafc8d6 nightmare fuel, right? 
 Well I *WAS* gonna go all white knight and help Captain No Luck take down the Crimson Fleet but then he decided to get all high and mighty about me wasting a few generic corporate security guards, 

so I guess it's a pirate's life for me. 
 @316ce00a Oh geeez, thanks nak! Very much appreciate you digging it up and sending it my way. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d yeah I got them too. logged... 
 @208f2b00 Weird. Thanks for confirming. 
 Did anyone else get a weird email from Amazon about the danger of their Google Play Gift Card order despite never having done so, and nothing appearing in order history? 
 so, @316ce00a for the win - just sent this relevant reddit thread my way, and the wording is exactly what I saw.

https://www.reddit.com/r/Scams/comments/16wnr2l/important_information_about_your_gift_card_order/ 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d be safe. Glad you’re doin... 
 @8e30f6c4 Thanks man! 
 Well that's one negative covid test on the books.

Continuing with same precautions (indoor masking, isolation, good airflow, surface cleaning) till at least Tuesday, when I will test again.

We've been careful, but feeling real lucky dad seemingly hasn't caught it yet. 
 Which is not to say I'm jumping back into everything full speed. 

Still easily winded/tired, but getting better each day. 
 Remember folks, if you give a fuck, always get a receipt so you can recover it if needed. 
 @ae152217 I used to record all my fucks given on the blockchain.

Somehow they all ended up in North Korea. 
 Oh this gives me serious pause about Framework laptops.

https://octodon.social/@jalefkowit/111156703105077035 
 Random service note: I've been happy enough that I'm upgrading my Proton Mail/etc subscription from Unlimited ($10/mo) to Proton Family ($30/mo if monthly; $20/mo if paid ahead).

The latter ups Proton Drive space from 500GB to 3TB so I can move any cloud storage needs there; it also allows for 6 separate users, 90 addresses,  3 custom domains, and a bunch of other stuff.

That's how well Proton is doing service-wise for me, with an emphasis on privacy. 

And as a reminder, I have no ties to Proton AG other than as a happy paying customer.

#privacy #security 
 Halloween decor, DEPLOYED! 
 @b88b35c7 where'd ya source the bodies from this year? 
 Watching the movie Blackberry, I just got chills when the first finished device flashed onto the ... 
 @c8440f0e First was probably ebooks for me; going from carrying around 4-6 books at once (because ATTENTION SPAN) in my bag to a little reader? heeeeeck yeah. I had so much knowledge at my fingertips, still do. 
 it always amazes me when i look at some corporate attempt to be mildly creative, that has cross-neuronal possibilities, and my synesthesia exhibits absolutely no response.

https://unstable.systems/@AmyZenunim/111155060958943493 
Event not found
 (That was a gourd joke if I do say so myself.) 
Event not found
 @b73da01f Totally fair points! Just wanted to make sure it had reached your radar at some point. 
Event not found
 @b73da01f Suggest you check out Obsidian - it's an incredibly powerful markdown platform but you don't need to know markdown.

Lots of community plugins that make it amazing, privacy-centric, and versatile.