Oddbean new post about | logout

Notes by Marcus Hutchins :verified: | export

 I wouldn't put it past Joe Rogan to have endorsed Trump purely based on Kamala not coming on his podcast. 
 Every time I log into Threads it’s somehow gotten worse. Im at the point where i can’t tell if the leadership are completely useless or extremely talented. If the goal was to create a usable and fun social media platform, they’re doing a worse job than Elon. But if the goal was to create a rage bait driven click farm that drives share prices growth, they’ve knocked it out of the park. 
 What they don't tell you about living by the water in LA is you are going to actually lose your mind when May Gray, June Gloom, and whatever tf they call July results in you not seeing the sun for 3 months solid. 
 I like how the Google CEO is trying to use the excuse that new products always have issues to justify the fact their new AI powered search absolutely sucks, as if they didn't spend over a decade doing the same thing with featured snippets, which also absolutely sucked. 
 Bruh. I just want a nice luxury EV that doesn't fund the world's most obnoxious man baby and his awful social media platform. If you're gonna lock BYD out of the US market, at least ask one of the US manufactures to make some good cars first.

https://media.infosec.exchange/infosec.exchange/media_attachments/files/112/441/225/524/588/444/original/b0814b44b155a0fb.png 
 US College kids protesting genocide: "Hamas supporters"
Israeli occupiers setting fire to humanitarian aid trucks (a literal war crime): "activists"

Bruh.

https://media.infosec.exchange/infosec.exchange/media_attachments/files/112/437/384/480/045/344/original/ecbd7a2a77f01718.png 
 I can see the Northern Lights from Los Angeles lmao 
 Today on annoying physics: I put my bottle of coke in the freezer to cool it faster. Since higher co2 concentration means lower freezing point, it remained completely liquid until I opened the bottle to drink it, then the whole thing immediately turned into ice  😭 
 After a year off Twitter, I'm surprised that I don't have even a single regret about leaving. The more I think about it, the more I realize it wasn't the takeover that did it. Sure, there was a massive and harmful political shift, but there's just always been something about the platform that attracts extremely unhealed people regardless of political leaning.

You can make a post like "I just got a coffee and the milk was sour" then someone on the right will be like "Biden's border crisis is the reason we can't get good milk anymore" and then someone on the left will be like "do you think starving children in Africa would complain about sour milk?". Eventually, you just realize the platform is designed for people who's only form of therapy is logging on to the internet and being annoying as fuck. 
 The case for leaving Twitter

"You’re not fighting a war, you’re not stopping Twitter from falling into the hands of the far-right, you’re selling burgers in a Nazi bar, paying more than you profit in rent. Every dollar Twitter makes in ad revenue is a dollar against everything you stand for."

https://throwawayopinions.io/the-paradox-of-intolerance.html?1 
 I lived in LA during the first E-Scooter pilot program. Woke up one day and there was just these electric scooters everywhere. You unlock them with an app and can ride them anywhere you want to go. Once you're done, you just leave it wherever. Then someone else can come and take it to wherever they want to go. If you take one home and charge it, you get paid some money. 

It solved so many problems. You didn't have to find parking, it was often times faster to travel by bicycle like vehicles due to traffic, you didn't have to worry about getting your vehicle back home if you got drunk, nor worry about having to lock every part of your bike to every other part to stop thieves disassembling it. 

Ultimately, it wasn't a good business due to a multitude of reasons. The difference between ride cost and cost of production meant scooters had to do hundreds of hours of rides before people totaled them or threw them in the sea or they couldn't break even. People were force to ride on sidewalks and mow down pedestrians because there's no bike lanes. Residents petitioned and had them banned due to people leaving them blocking driveways or littered across the sidewalk. Literally every single one of those problems would be easily solvable if it were a public service instead of a private business. Some regulation, enforcement, bike lanes, and what you have is an incredible inner-city public transport system. 
 nostr:npub1nyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsr3vvvs lol you were sad you can’... 
 @dee34601 No, everyone can still fly on private planes. They just won't be able to share them with 30 other people to reduce the carbon footprint to near the same as a regular commercial jetliner. 
 Aight, I wasn't going to post the extra-spicy hot wings take. But, fuck it.

Reply-guy climate activists are the most annoying out of touch people on the planet. They'll literally show up in my mentions with shit like "why don't you bicycle down the freeway to the grocery store. You can just clench your re-usable grocery bags between your ass cheeks". 
"Need to go to NYC for an important meeting? Take the train....oh, the US doesn't have trains? Why don't you just build you own."

How someone can witness the entire covid pandemic and not only be like "yes, personal responsibility will for sure solve humanity's problems" but also propose nothing but the most braindead solutions imaginable is literally beyond me.

I get the frustration with the currency system, but annoying the shit out of random Mastodon users with the most garbage advice you can muster is just not it. Some of us are actually trying to make real systemic change.

https://media.infosec.exchange/infosecmediaeu/media_attachments/files/111/184/133/967/830/478/original/d7d2900f22915cfd.png 
 The Paradox Of Intolerance 
(And The Case For Leaving Twitter)

https://throwawayopinions.io/the-paradox-of-intolerance.html 
 Cyber Threat intelligence is such a wild industry. In regular intelligence the government has near total monopoly and everything is classified at TS/SCI. Whereas in CTI it'll just be some dude named Brad who got really baked one night and yolo'd his way into a major APT's backend server. 
 The good news is: if you're getting subpoenaed to testify before a grand jury, you're probably not the subject of the investigation. The time to worry is when you're only even finding out there was a grand jury proceedings when you get handed an indictment.

But for real, don't be going around accessing threat actor infrastructure from your home IP, unless you're in direct contact with all the relevant authorities. None of them talk to each other, they have no idea who you are, they have no idea what you're doing, or usually any idea what they're doing either. 

All they see is an IP logging in to criminal infrastructure, and whether or not they mistake you for a threat actor, they're still going to chase you down as a lead. There isn't really a law enforcement policy for "this person might be a good guy, let's ask them nicely to share", they're just gonna blow your door off its hinges and take your devices.

https://techcrunch.com/2023/09/27/sam-curry-chilling-effect-phone-search-airport/ 
 Got a question because I'm useless at business. I get a lot of emails from companies asking me to do webinars, interviews, be a podcast guest, etc. They never mention any payment (not just no payment amount, but no mention of it being paid at all). Then when I don't reply, they follow up later with "btw we can pay you" and it's always phrased like they simply forgot to mention that in the initial email. I understand me being responsible for negotiating my rate, but having to negotiate getting paid at all? Is this the norm or is this just unserious companies trying to see first if I'll work for free and I'm better to just not engage at all with them at all? 
 Very excited to find out if congress is going to be just regular useless, or useless so hard they shut down the entire government. 
 I just saw that Am I The Asshole reddit thread where the white girl started going to a black salon because she had extremely curly hair and the black salon was the only one that didn't massacre it. Her white friends straight up gaslit her into believe she was engaging in cultural appropriation and stealing resources from black people. WILD 💀​ 
 I like the economic system where we just alternate between housing costs rapidly increasing due to low interest rates enabling investors to buy them all, and housing costs rapidly increasing due to high interest rates making mortgages too expensive for everyone except investors.

It's kind of like free market capitalism, except instead of not having a government you just pay an insane amount of taxes so some useless boomers can argue about genitals and bomb Iraq. 
 I guess the economy really isn't going well because my apartment complex just sent out an email advertising a service that provides financing for paying your monthly rent 
 I always sucked at eating healthy because my brain won’t give me the motivation to cook food. Friend introduced me to this really cool local service where a professional chef does meal prep for you and and delivers them to your door. Since they’re cooking in bulk, you can have all different meals instead of eating the same this every day. They even customize the food to your diet requirements and weight loss goals. Works out around $17 a meal 
 Am I reading this right? The judge just dissolved all of Trump's companies and revoked their licenses to do business?

https://media.infosec.exchange/infosecmediaeu/media_attachments/files/111/133/887/333/506/257/original/b47e321f4e443adf.png 
 My thoughts on how Generative AI threatens to bring about the end of the free and open internet.

https://marcushutchins.com/blog/tech/opinions/the-end-of-the-free-internet.html 
 When I lived in the UK I went through security clearance and they made me sign something waiving my right to dual nationality. It was ages ago and I'm not really sure what it is I signed. Is a dual nationality waiver an enforceable thing? Do I have to undo it in order to apply for dual nationality, or was it more of a "I pinky promise I won't try and apply for a passport while I work for you"? 
 Between the collapse of the advertiser model, record high interest rates, and generative AI content farming, the next decade isn't looking great for the free and open internet. 
 I do wonder how many people are staying on Twitter due to follower count alone. Having had an account for over a decade, I'd have previously estimated about 20% of my followers were dead accounts. Based on now leaving and making new accounts on other platforms, my estimate is closer to 90%. 

As a blogger I've always known only like 1% of people who retweet/like a post actually clicked the link and read the article, but I assumed that was just a social media thing. Having experimented with basically every other platform, I learned it's more likely that a significant number of Twitter engagements are fake, and those that aren't don't really care enough to read your work, they'll just give you a retweet/like for appearances. 
 If I ever get accused of something and the only people who come to my defense are Andrew Tate and Elon Musk, you have my permission to kill me. 
 I often half-joke that moving from Western Europe to the US is the national equivalent of defense contractors opting to deploy to an active warzone because the hazard pay is good.

https://media.infosec.exchange/infosecmediaeu/media_attachments/files/111/071/323/845/889/427/original/8844974dc124512b.png 
 I say half-joking because last year some published data showing that per capita less civilians died in the Ukraine war than were murdered in several US cities 🥴​ 
 The concept of being a felon is so funny to me. It's like "hey, you did some crime when you were 19, so we're going to make it exponentially harder to not do crime in future by limiting basically all your options for survival". 
 IDK how to say this but if you're still mad about the Uber Eats post from two years ago, you have some serious psychological issues that you need to work through. It's understandable to be mad about the ultra wealthy whose very existence threatens your survival, but raging because someone has slightly more money than you and chose to spend it on something that improves their quality of life is just sad. 
 Does anyone ever wonder how rich they'd be if every time they foiled a ransomware attack companies who would have paid the ransom instead gave you some of the ransom amount. I think I'd actually be a billionaire lol 
 FML. My apartment management just showed up to install the new internet package, which sounded pretty good (Symmetrical Gbit). Dude comes in to set it up and is trying to install a wifi access point behind my couch. I told him I don't need an access point because I have my own mesh network, I just need to connect the new modem to my network rack. He starts trying to explain that the internet doesn't require a modem, so I'm like confused af. 

After like 10 minutes of trying to figure out wtf this guy is talking about, I realized they've installed an apartment complex wide wifi mesh network, so there is no individual internet packages anymore. Everyone in the entire apartment complex is just connected to one big wifi network. They claim all the users are segmented by VLAN, but I genuinely don't think I've ever wanted something less in my life. 
 The LinkedIn meta of creating fake Tweets from yourself, photoshopping in a verified badge, then quoting yourself by posting screenshots makes me want to kms. 

I genuinely did not think it was possible to be more cringe than chronically online Twitter users until I learned about LinkeInfluencers.

https://media.infosec.exchange/infosecmediaeu/media_attachments/files/111/053/578/120/689/498/original/99b82c7a13eaf7e4.png 
 Personally I'm ok with X getting a banking license because society would be much safer if Elon Musk stans didn't have any money left. 
 Outsourcing US defense capabilities to any corporation has always been a national security trade-off, but SpaceX specifically is a private company where a single extremely unhinged pro-Russia troll controls more voting shares than the entire rest of the shareholders combined. Anyone who doesn't see the national security issue with putting a nation's defense capabilities in the hands of a Wish.com Lex Luthor knock-off has actual soup for a brain.

https://infosec.exchange/@briannawu@mstdn.social/111024207167342302 
 This is absolutely crazy stuff. Chinese hackers were able to get into a bunch of government email accounts by forging Microsoft access tokens, but how it happened is wild.

Apparently an internal Microsoft system responsible for signing consumer access tokens crashed, then a bug in the crash dump generator caused the secret key to be written to the crash dump. Microsoft's secondary system for detecting sensitive data in crash dumps also failed, allowing the crash dump to be moved from an isolated network to the corporate one. The Chinese hackers compromised a Microsoft engineer's account and were able to get a hold of the crash dump. They were not only able to find the key and figure out that it's responsible for signing consumer access tokens, but were also able to exploit a software bug to use it to sign enterprise access tokens too, basically giving them the keys to the kingdom.

So many security system had to fail for this to happen. Either the hackers were very lucky or extremely patient.

https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ 
 This is a testament to just how hard cybersecurity is. Microsoft had the forethought to not store keys into crash dumps, had the forethought to build a secondary system to double check them, had the forethought to store them on an isolated network, but a cascading failure basically blitzed through all their security controls and allowed nation/state hackers to walk off with critical signing keys. 
 “The Chinese version of TikTok only allows educational content”
The Chinese version of TikTok:

https://media.infosec.exchange/infosecmediaeu/media_attachments/files/111/015/582/697/700/685/original/a0a105bac6ab4d99.mp4 
 “The Chinese version of TikTok only allows educational content”
The Chinese version of TikTok:

https://media.infosec.exchange/infosecmediaeu/media_attachments/files/111/015/676/100/996/232/original/cb391c2d0ecfb79b.mp4 
 "I'm getting rid of the block feature because it makes no sense" 
Translation: "a lot of people have blocked me because I behave like a 5.2 year old instead of the 52 year old I am and this hurts my feelings"