Oddbean new post about | logout

Notes by Ian Campbell | export

 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d I don't even want to know h... 
 @6b24927c Oh geez I bet, sorry you have to deal with that! 
 As said elsewhere,

"Still punk as fuck," I whisper as I fill my pill containers for the month and make sure to email my Mom with where I'm staying on an upcoming work trip. 
 @494592e6 I saw a lot of malfeasance during a brief look at the Indonesian online gambling space, but I reckon that's different from casinos proper. 
 Note for new followers: if you’re looking for informative posts on cybersecurity/infosec, you... 
 @ae144dbc You're a joy and a pleasure to have on my timeline as-is, and I'm grateful for you. 
 Does organized crime still try to launder money through casino gambling?

Because I'm suddenly enamored with the idea of mafias and triads etc stomping up to ALPHV and going "What the fuck, dude?" 
 No window near Kadyrov? 
 @b88b35c7 oh now THIS is interesting, wonder if he had his tea 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d  Here here. Elizabeth Warre... 
 @ccb4768b Helllllll yes. Warren's one of my favorite people, and I'm so glad she represents my state. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d  Unfortunately she inherite... 
 @ccb4768b yep, FTC definitely needs even bigger teeth. Biden gave Khan a pretty clear consumer info protection mandate though, and she's been usin' it.

I'm always in favor of bigger regulatory teeth, though. ;) 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d  I hope their faces hadn't ... 
 @ccb4768b Khan's been taking some pretty good steps during her tenure - personal consent decrees for CEOs, among other things.

I have mad respect for her but also she merits several slides in one of my recent internal training sessions. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d SHE DID IT? 

I would have ... 
 @ccb4768b fair, but also, with both Caesars and MGM borked, you're looking at an off-strip motel if you want a last-minute Vegas room.

Can you imagine the exec's faces when they realized they checked Lina Khan in through this process, though? 
 Oh my holy god.

FTC Chair Lina Khan checked into the MGM Grand as their systems were down and they were having guests, including Khan, handwrite their credit card numbers on paper.

https://www.bloomberg.com/news/articles/2023-09-15/mgm-was-hacked-and-lina-khan-had-to-write-her-credit-card-number-down-on-paper 
 there can be no clearer sign that the universe despises you than having Lina Khan engage with your business as a customer as your security is trashed and your consumer-facing information handling has been reduced to a shrug emoji. 
 So the State Department was the first to alert on the Microsoft key compromise thanks to canaries they instituted in their email system.

This is, frankly, a huge win for State - for a good few years around DC, State's email was considered constantly compromised. 

Really nice to see that they upped their game and it paid off.

https://www.politico.com/news/2023/09/15/digital-tripwire-helped-state-uncover-chinese-hack-00115973 
 last boost: the distressed jeans of the future. 
 Therapy appointment this afternoon - and not only do I recommend psychotherapy for folks that aren't in crisis, I ESPECIALLY recommend it for folks who aren't in crisis.

Therapy can not only help you avoid crises but build internal tools and increase quality of life regardless of where you're at right now.

If you are in a place where you can access therapy, maybe try it out! 
 Random observation: a handful of new IDN homograph whois entries possibly emulating Vietnamese blockchain firm bingx[.]vn

I'm kinda hoping these are just preemptive/prophylactic registrations by BingX because otherwise it looks like campaign infra spinning up.

xn--bngx-vpa.com[.]vn

xn--bngx-5w5a[.]vn

xn--bngx-5w5a.com[.]vn

xn--bngx-qpa[.]vn

xn--bngx-vpa[.]vn 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d but with grit in it 
 @6b24927c salted rim maybe? coffee grounds? 
 Microsoft Threat Intelligence with a good post on an Iranian nation-state actor executing password sprays across industries.

Some good TTPs and other details here. If you've had a password spray attack lately, worth running the 4 IPs they provide through your auth logs.

https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/ 
 these threat actor group names need to go, though. "Peach Sandstorm" sounds like something cold and refreshing that I should be enjoying on a beach somewhere. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d Do you use the Obsidian clo... 
 @79adb0e9 I am pretty cloud averse, especially Google averse, but Obsidian's on-device encryption had me singing their praises. Works as it should as far as I can tell, but no frills 
 I fell in love with notetaking app Obsidian months ago but can understand some folk not taking to it.

This post highlights what looks like a good alternative!

https://mstdn.social/@redcrew/111058914522409440 
 little known fact, webp is short for "we be patchin" 
 New superhero idea: the pun-isher. Says it all really. Villains surrender in droves just to make ... 
 @0c1a9324 instead of the batsignal, you reach him on the punchline 
 Anyone have a recommendation for an Android-friendly smartwatch that isn't just corpo tracking augmentation?

I honestly don't care about steps or ekg or any of that stuff, really just want notifications on my wrist. 
 Curious to get thoughts from people with subject matter expertise in passwords and MFA. The Retoo... 
 @b902f84f I am no fan of Google but Google Authenticator requires user interaction to upload OTPs to the cloud and the interaction is surprisingly clear. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d Being in an elderly care si... 
 @4b5f5f4c Luckily my dad doesn't engage with the app store much at all, but yeah I can 100% see that being a larger problem that needs addressing. 
 New work blogpost is up - recently went through a situation where my aging father lost his cellphone. 

I took the moment to review what we did ahead of time that helped, and what we could've done better. 

If you're in a position of responsibility for aging loved ones, I hope this gives you some good pointers.

https://www.domaintools.com/resources/blog/smartphone-security-and-aging-parents/ 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d looks like I misread your p... 
 @6b24927c Always appreciate the second set of eyes - you're not wrong about not keeping all eggs in one basket. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d maybe. it also keeps someon... 
 @6b24927c When it's either got a typo homograph (like the CGS one) or has an MX record not pointing to the primary domain (like the riot games one) it raises my suspicion much, much higher. 
 yourokta[.]com - IONOS SE playing a supporting role

and let's take a peek at cgslnc-okta[.]com - that's an L - as software company CGS at cgsinc.com is probably a juicy target, with pivots to IBM, Microsoft, Dell, MasterCard, and more.

Registrars are the problem, people. 
 Riot Games bounces security@, help@, and info@, so I guess they don't wanna know.

If you know someone at Riot, maybe give them a heads-up. 
 testokta[.]com brought to you from the fine folks at Google's registrar and hosting.

oktaDOD.com from Namesilo/Aws

Oh, oh, oh, someone go thank the discerning folks at Namecheap and Amazon for okta-riotgames.com (primary domain uses markmonitor/akamai) 
 yourokta[.]com - IONOS SE playing a supporting role

and let's take a peek at cgslnc-okta[.]com - that's an L - as software company CGS at cgsinc.com is probably a juicy target, with pivots to IBM, Microsoft, Dell, MasterCard, and more.

Registrars are the problem, people. 
 okta365dev[.]cloud is legit, i'm sure. Thanks Godaddy/Google.

okta-route[.]com, route-okta[.]com, outreach-okta[.]com look super great for everyone, thanks Amazon/Network Solutions. 
 testokta[.]com brought to you from the fine folks at Google's registrar and hosting.

oktaDOD.com from Namesilo/Aws

Oh, oh, oh, someone go thank the discerning folks at Namecheap and Amazon for okta-riotgames.com (primary domain uses markmonitor/akamai) 
 well i guess it's time to go through  my Okta domain monitors again

Let's start with premera-okta[.]com, which differs from the primary domain across just about every profile factor.

Premera's a Blue Cross provider with 2.8M members. 
 okta365dev[.]cloud is legit, i'm sure. Thanks Godaddy/Google.

okta-route[.]com, route-okta[.]com, outreach-okta[.]com look super great for everyone, thanks Amazon/Network Solutions. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d
Wow, that looks cool. Do yo... 
 @d4d31b74 No clue, sorry! 
 Random vouch:

Dad's in the kitchen making pancakes, using a high-power mixer to mix the batter. Because my auditory processing is screwed, I get misophonic shivers from it ("brain says bad noise, must rage!").

With "Calmer" ear inserts, no shivers, no rage, but can still hear. I don't *like* the sound of the mixer but it doesn't make me hate everything.

#neurodivergent #actuallyautistic 
 In a private convo, a friend just astutely observed that slap bracelets were an early fidget toy of our generation.

Mind. Blown. 
 UPS Dispatch: "Yeah I know the driver was there at the address last night but I don't know what happened."

Me: "Guy, I'm not trying to jam anyone up, but I was sitting 10 feet from the front door until ten minutes after the delivery attempt was logged, my outside light was on, my driveway camera was on, and my doorbell records video locally when pressed. Nada. Zilch. Zero." 
 "In a first, spyware is found on phone of prominent Russian journalist"

(pegasus - gift link below)

https://wapo.st/3LnltAF 
 Delivery attempted my hairy ass, UPS. 
 Now when Starlink has an outage my first thought is "Hmm, is Elon providing material assistance to Putin's forces again?" 
 Wow - the iPhone 15 has USB C. That is super innovative. Time to chuck my 14 and those dirty ligh... 
 @57ccb1d2 #courage 
 Today I learned about "the Dutch Reach" which sounds like something particularly scandalous but is in fact much more wholesome than that. 

https://flipping.rocks/@colinpurrington/111041944797648010 
 i wish i had the self-discipline to sinkhole slack at the firewall during weekend hours 
 Was ordering Taco Bell smart for my health? Well, no.

But was it satisfying? Also, absolutely not. 

don't know why I do this, my eyes insist on cursing my stomach and brain... 
 WHY is it

ONLY 

THURSDAY? 
 which one of y'all raggedy motherfuckers got Dragula stuck in my head? 
 @b85e28d3 TOOT through the ditches

net WORK through the switches

SYN/ACK from the back of my DRAGULA 
 @0c1a9324 Back when Hale-Bopp was around the local police log of my sheltered hometown had the following entry:

"Comet-watchers mistaken for buddha worshippers."

Of course, why someone was calling the police about Buddha-worshippers is anyone's guess. 
 Messaged my PhD supervisor that I am getting anxious abt the results of my PhD because I was told... 
 @e64a89b1 Your thesis already sounds awesome. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d 

I use CalyxOS on a Pixel ... 
 @12e6396e great to know, thanks! 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d  I and a friend of mine bot... 
 @c6a2ac4c Good to know! Thanks very much for the info. 
 @c6a2ac4c Likely so - do you have experience with it? I've heard more about other options, less about CalyxOS though it's been on my radar. 
 "oh for your convenience we're just going to make the wifi button disconnect for a day, because fuck you"

i want a mobile device with an electromagnetic shotgun duct-taped to its forehead at this point, and it's all the ad industry's fault. 
 nostr:npub18c7wjmr8txk9u3xzrxl5rsx8mpt4dr84nyluufn4qg4x9xnar52qller9d I'm really happy with graph... 
 @9ca338cb good to know, thank you! i'll have to check out grapheneos again, been a while. 
 i really am gonna be one of those nutters with a stripped-down foss phone soon aren't i

all purely on the basis of not wanting every move fed into databroker stuff. 
 if anyone has suggestions for de-googled/foss/reputable tinfoil phones they have direct experience with, hit me up. 
Event not found
 @79adb0e9 not off the top of my head, sorry. I keep a pretty rigid folder hierarchy. But I wouldn't be surprised if a community plugin exists to solve this problem, or a plugin that enables scripting in order to automate your way out of it. 
Event not found
 @02b8aea4 Fair!

In this case, Google TAG found a cross-platform DPRK actor targeting security folk

https://blog.google/threat-analysis-group/active-north-korean-campaign-targeting-security-researchers/