There aren't words for how insidiously disgusting and blatant this is. (Link)
Misplaced Lens Cap

Origami Around
RMH
Today's Document
š
No title available

romaā
Not today Justin
almost home

Game Changer & Make Some Noise

pixel skylines
d e v o n

titsay

#extradirty

blake kathryn
Doug Jones
Claire Keane

No title available

No title available
Interview Vampire Daily

seen from Türkiye

seen from United States
seen from United States
seen from Vietnam
seen from Canada

seen from Türkiye

seen from United States

seen from France
seen from Singapore
seen from Singapore
seen from Hungary
seen from United States

seen from Malaysia

seen from Ireland
seen from Singapore

seen from Malaysia
seen from United States

seen from Singapore
seen from United States

seen from United States
@angrycybersecurity
There aren't words for how insidiously disgusting and blatant this is. (Link)
About ten, fifteen years ago I wrote a story about a guy living in a Capitalist dystopia. His walls, furniture, and tableware are all covered in smart displays. Basically animated wallpaper. It's sold as being able to turn your room or objects into anything - A nice forest view, outer space, a fantasy realm... but the companies that run this stuff keep sneaking ads in.
It gets so bad he's always being woken up by adverts that offer insomnia cures and better bedding that play when he tries to sleep.
So he buys the ad-free tier, and it's great... for a few months. And then he starts getting adverts from 'premium partners'. So he goes up a level... and the same thing happens.
So he jailbreaks his wallpaper and sends all the ad servers to 0.0.0.0 and voila... he can sleep.
Until this SWAT team blows his door off and drag him off to jail. The Ad companies are suing him for loss of revenue for the products he' notionally have bought if he'd watched their adverts, based on some weird 'The average consumer buys X products with an average value of Y' calculation.
The judge is like 'well I dun wanna annoy the sponsors' so he RICO's this guy's house and possessions and sends him to jail.
... which is a nice relaxed non-volent offender jail for the corporately disenfranchised. But because these people have no money... there's no ads and now he's happy because the only place he's free... is in prison.
Which at the time was a bit much and now it's like: Called it.
Elon's suing companies for not advertising because he's losing revenue. He's also cranking the price of Ad Free Twitter. Disney and Amazon play adverts on their paid service when services used to be free because of the adverts... and now you have to pay to watch the adverts or go up a couple of tiers.
And google's going around freaking out about ad-blockers.
OP did it hurt when Apollo's dodgeball hit you and made you write that story?
The midjourney stuff just reminds of when we were trying to find a new platform to host the ao3 donation form, and companies kept trying to tell me about all their "ai" features that would track donor engagement, and figure out the optimal pattern to email individual donors asking for follow up donations, and all the ways they suggest we manipulate people into staying on our websites. It was a great way to filter out who either wasn't listening to us when we described our ethics and donor base, or just didn't believe us.
Now granted ao3 is a unique case based on a) the amount of page views we get in any given time period and b) the fact that most donors absolutely do Not want to be identified as such anywhere, (the default "list of recent donors" module got nuked Immediately) but it surprised me some that the concept of "donors who value their privacy and would be furious at even the whiff of AI" is unique. Some of us really are just existing in different worlds.
Op's tags
#I just started dropping '2.5 Billion page views a month'#into conversations as early as possible bc they would Not believe me otherwise#it was right up there with having to say 'csam attacks' to get them to take my compartmentalization of information concerns seriously#turns out those are the magic words#otw#op
The last part was kind of insane, honestly. When we started changing platforms for the donor database, I kept telling them that yes I was aware we already had an account for the volunteer database, and no that could not be connected to the donor database. And they said yes fine sure and then connected them anyway. And I called them back and said, excuse me, I'm confused, I can see both databases. And they said, well, yeah, but it's only you, someone has to be able to see both databases to give other users access. The other users can't see both. And I said, no, we have been asking for a completely separate database. I should not be able to see both. And they said, you are one organization, one organization can't have two databases. And I said, last year someone used our volunteer email list to commit approximately one thousand felonies. Please feel free to imagine how much worse it could have been had they had a way to use volunteers' email addresses to get their legal names. We do not want this to be something anyone can do no matter how much we trust them. Let me describe those felonies to you in more detail. And they emailed me two hours later and said, you can have two separate databases.
This post feels like watching an iceberg go by in clear water. The amount of stuff going on beneath the surface of AO3 just astonishes.
(ID in alt)
Approximately one THOUSAND felonies
This insane update from Neocities
jobs for girls who can't focus and are tired all the time and aren't rlly that good looking and get startled easily
Hey, so this may be a weird place to put this, but if your college or school uses Canvas, it was likely affected by the recent data breach. As of right now, the most likely personal information swept up in this hack is names and email addresses. Login and financial information were not included in the breach (as far as we know).
Right now, as a student you should beware of phishing attempts. Do not click on links seeking your login or financial information. Do not respond to emails about financial aid until verifying the email is legitimate first. Call your school or go speak to an admin in person if you have to. Report any suspicious emails to your school's IT department.
took me a minute to find, but the company that owns canvas has confirmed a "cybersecurity incident"
its being reported on by mashable, some smaller tech outlets, and Inside Higher Ed. i was also able to find a local news station reporting on their scool district's response to the attack
Huge apologies, I swear I had sources linked but Tumblr mobile loves stripping my links for some reason.
(Also for clarity to some reblogs - Canvas is an Learning Management System in which online classes are hosted. Canva is the graphic design website. They are not the same, despite being frustratingly similarly named.)
The cybercrime group ShinyHunters claimed to have hacked Instructure again, defacing the login pages of several Instructure customer schools
Whelp.
Just as an update on this, Instructure agreed to pay the ransom, which... is not great, but seems to indicate your data is not going to be leaked. As before, the biggest thing you have to be on the lookout for as a Canvas user are phishing attacks.
Do not attempt to out-malicious-compliance the staff at the malicious compliance conference.
Some dipshit decided to pay the conference fee ($250) in quarters. He handed us a wrapped plastic bag full of loose change. "It's all there," he said with a shit-eating grin, "you can count it."
Oh buddy. We're going to count it. What were you expecting?
At about the time I got to $60, he offered to give us $300 collateral so he could get his badge and go to the conference.
No, bud. You get to watch the most dyscalculic staffer count to a thousand while all your friends go in to the breakfast and find seats for the first talk.
"Ruining someone's day" is the favorite hobby of everyone here. Why would you hand us the perfect opportunity to wreck your shit and think that was an own? Half the con is calling him "Untraceable," the other half is calling him "Quarter Boy" and nobody cares what he says his handle is.
I spent an hour counting that and made him go fetch me baggies to hold it every fifty dollars.
This ended up being a good bonus prank for me too, because when the counting was done I wrapped the bags in gaffer's tape and spent the rest of the day handing it to people very casually while saying "oh here, hold this for a sec" and then watching they weren't ready for the weight (I only did this to people I know well enough to know this wouldn't hurt them).
It's an infosec conference, so it's a weekend in a hotel full of people whose favorite thing is breaking the law and whose second favorite thing is following the letter of the law while cheerfully violating the spirit.
Thank you, that means a lot coming from you, @unyanizedcatboys
Every Website right now: Give us a scan of your driver's license or be banished. It's for safety.
Every Website for the last 10 years: Oopsies we had another massive data breach! Tee-hee!
real talk i have become a problem recently. the hospital wanted my fingerprint and i said no. the receptionist was like: but its such a convenient way to check in! and i said ok i dont want you to have my biometric data. and she was so baffled. i said, can you not check me in using an id card?
well of course but dont you want to provide your biometric data for your convenience?
nope thanks!
fuck this happened again i was buying some LPs and the clerk was like: can i have your email? and i was like no.
she full on stared at me. she was like: but i need to put you into the system.
and i was like: need to? you NEED to? i don't want to give my email
and she was like: but...how are you going to return items without an account?
and i was like, with a fucking receipt??? wtf is going on right now. if i can't return them i guess i'll die??whatever
Hit them with the "if you need my email to return these items I am not buying them" and see how fast they reassure you that they don't need your email
why are there so many posts about asexuals being immune to sirens. people. sirens donāt lure you in with sex (necessarily). they sing about whatever it is that you want most. they could sing about mothman or cinnamon toast crunch and guess what then your asexual pirate is fucking dead
this is the only kind of ace discourse i ever want to see on my dash. the only kind. ever again. good job
Do you think the sirens would be grateful that they finally get some variety?Ā
āOh my god we can finally just sing about pasta thank the fucking gods.āĀ
Iām not asexual but Iām fairly certain sirens would do a far better job luring me into the depths with a song about pasta rather than sexā¦
I mean.Ā
āWHAT THE FUCK STAY AWAY FROM THE ROCKS.ā
āFUCKER THEY SAID THEY HAVE FETTUCCINE CARBONARA AND HOT GARLIC BREAD OVER THERE HANG ON BITCH.āĀ
This is true; Odysseus heard them promising him knowledge of the future. Ā So the next time you see artwork like this:
Remember those sultry naked chicks are sayingĀ āWeāll tell you the winning lotto numbers.ā
Them: āWe have unlimited wifi at incredible speeds~ā Me: *diving headfirst into the water*
This post is a blessing
Congratulations! Odysseus! Youāve been selected as a winner for the free $1000 Amazon Gift Card, Apple iPhone X 256G or Samsung Galaxy S8! Claim your prize now!
Oh my god sirens were literally scam websites
Oh my god they were phishing
"We're gonna achieve immortality by turning ourselves into machines" buddy I want you to find yourself a 15 year old laptop and try to run a 10 year old piece of software on it please. Connect to the internet, if you can, and attempt to log into any of your online accounts
I'm seeing warnings about scammers trying to commission artists but the "reference sheet" for their character they want commissioned isn't an image but a .vbs file ("visual basic script"), and will run a script when you open it, probably to yoink your account(s), but I haven't seen this from anyone who's actually clicked it yet. Just be careful and never open a file like that, 'cause people suck.
For reference (heh)
At a glance, file name checks out. But!! Do not open a .vbs file!!!
a reCAPTCHA will not request a sequence of keys, and what to do if you got scammed
(The basics of) what this actually does, because nothing is magic:
In the Reddit screenshot we see three instructions:
Press & hold the Win key + R
In verification window, press Ctrl key + V
Press Enter key on your keyboard
(We also see some odd grammatical errors - "Complete these verification steps use keyboard" instead of "using keyboard" or "To complete" - which should be a red flag as well.)
The first instruction - Win+R - opens the Run dialog:
You might notice that this looks like it's part of Windows; that's because it is. This dialog isn't part of the CAPTCHA but part of your own computer (a huge red flag!!)
The description says that Windows will open a file for you, but it's actually more advanced than that: this can run any command-line command you type into it. (If you don't know what that means, the command line is a way to interact with your computer by typing commands, and lets you do basically anything Windows can do.)
The second instruction - Ctrl+V - you might recognize: it pastes whatever you have copied to the clipboard.
Usually, you'd have copied this with a Ctrl+C or Ctrl+X, but websites are able to modify what's in your clipboard directly. (You might have experienced this with something like the "Share results" button in Wordle.)
In this case, they've copied a malicious command into your clipboard already, so when you hit Ctrl+V the command gets pasted directly into the Run dialog. I don't know the details of the specific command, but it has the power to do basically anything you can: download files, run programs, delete files, whatever.
The third instruction - Enter - is the same as hitting the OK button in the dialog: Windows executes the command you've pasted in for it.
In short, Win+R opens a tool to use commands, Ctrl+V pastes in a malicious command, and Enter executes it.
Many of you might be saying, hey, I already know what Ctrl+V does! That's great! I'm just trying to clarify how exactly the keyboard presses "run a command that can download malware onto your device", so you or anyone can understand what your keypresses are doing in general (not just in this specific fake CAPTCHA attack), and be aware when they might be doing something dangerous.
(That being said, if you scrolled past the entire post, don't press keyboard shortcuts that start with Win or Ctrl or Cmd or anything like that if you don't know what they're doing. That's all.)
āAttempting To Read News In 2025ā (medium: safari with ads, screencap, 2025)
If this shit happened in 2005 it meant your computer had a virus
crossposting from bsky - glad I stopped using spotify when I did and that I unlinked it from my discord, but still
[ reddit thread | bsky post ]
helpful to know on 1,234 days left