Alright, to ao3's soon to be arriving Wattpad Refugees, a basic guide to general user culture:
1.) Unlike Wattpads vote system that let's you like each chapter, the ao3 equivalent kudos only allows one per work. Everyone is generally quietly annoyed about this. To engage with each chapter, you're heavily encouraged to comment. Trust me, it makes people's day.
2.) Ao3 has no algorithm. By default it's latest updated work first. You can find things to your taste through searches, filters and tags.
3.) 'No archive warnings apply' and 'user has chosen not to use archive warnings' mean two very different things. No archives warnings means the work is free from any content that could require a warning tag (character death, graphic depictions of violence, non-con, etc). User has chosen not to use archive warnings means it could contain any of the warning content, be it hasn't been explicitly tagged. Treat it like an allergen. No archive warnings apply is allergen free. User has chosen not to use archive warnings, may contain traces or whole chunks of the allergen. If you're likely to have a bad reaction, maybe don't take the risk.
4.) Speaking of warnings, ao3 has very few restrictions on the type of work that's allowed. Whatever your personal thoughts or feelings on that are, thats how the site is. You're likely to run across some dark subject matters and a lot of people are uncomfortable with reading that. You're well within your rights not like these works and have your opinion on whether they should be allowed, but harassing the authors of such works (or any works) is more likely to come back on you than them. Ao3 operates on a strong policy of 'don't like, don't read'. Use the tagging system to your full advantage to only engage with the kind of works you want to see.
We look forward to welcoming you all and seeing the fantastic works you create. Happy writing!
5.) AO3 doesn't have an app. AO3 will probably never have an app. AO3 is optimized to run in your mobile browser on your phone or tablet. Anything that is selling itself as an official AO3 app is lying to you.
Itâs all in the way that girl/boys shirts are made.
Girls shirts have less armpit room then boyâs do and are generally shorter so pulling it off over your head is more practical because by lifting your arms all the way up you make enough room for the sleeves to just slip off.
Boys shirts have more room and are generally longer so it is easy to slip them off over your head.
but if you take a girls shirt off like a boys shirt you will get your arms caught because there isnât much armpit space.
and if you take a boys shirt off like a girls shit you will still have your head in it when youâve lifted your arms all the way up because of the shirtâs length.
It has nothing to do with us. It is entirely to do with how our shirts are made. I figured it out for you. YOUâRE WELCOME!
To other people, youâre the special, unlockable character that they worked and worked to finally get- and when they do theyâre so happy because they got the game just so they could find you.
The fact y'all are still passing around this post, eight years after I made it. Exquisite. I hope itâs still resonating with people outside of mid-2010âs tumblr.
worst relationship status to have w someone is âobjectively theyâre a fine person who is nice but i donât enjoy their company as much as they enjoy mineâ
secret third technically more harmless but in practicality more frustrating relationship status is âobjectively theyâre a fine person and they like so many of the same things i do but they like them in a fundamentally different way that is harmless but reads wrong to my brain and it has made attempts at forming an actual bond with them aggravating more than anythingâ
tbh i think stuff like this is why so many people, especially younger people, fall into this trap of âwell if i donât like a person or thing, they must be badâ. it would be so much easier if you could dismiss them as bad and move on. but itâs like, no, Objectively Fine people or things can just not mesh well with you for totally subjective reasons. and sometimes when theyâre people you mesh much better with their brain than they do with yours. and sometimes you have to live with that.
So, I'm trans. And several years ago, I was at my great grandfather's funeral. 17, newly on T, barely out to anyone other than my close friends and family. And I'm standing there at the refreshment's table, surrounded by strangers and members of my family's church, when George walks up to me.
This man is ancient, bent like a finger and frail. Tufts of white hair surround his wrinkled face. Like always, he's wearing thick glasses, massive hearing aids, and his veteran's hat. George was my first introduction to the concept of war, when he told me as a child why he was missing two fingers on his hand. He's been a fixture at church since I can remember. I've only ever seen him at there or in uniform at parades, the rest of his time spent in a nursing home somewhere. He picks up a deviled egg and says, in his quiet voice,
"You know, before your grandfather died, he told me that now he had 3 grandsons."
I'm frozen in place. I don't know what to say to that, if I should say anything at all. This is not a conversation I expected to have, especially not with this man. But he continues.
"I didn't know what he meant! So he explained it to me."
And I can imagine it. My great grandfather, uninformed and opinionated but supportive, explaining to his friend the news he barely understood himself over after-service coffee and cookies. His eldest grandchild was now a boy.
"And, you know, I didn't know what to think."
Here, George looks me up and down. This 90-something year old war veteran, who knew me mostly as the little girl playing in the church kitchen with his wife, processing what my great grandfather had really meant. It feels like a long pause, even thought it probably passed in a second.
"But you look good. So, eh!"
And then he smiled, shrugged, and walked away without another word. If I was fine, if I was happier, then that's all that mattered.
George passed away this week, at the age of 99. This memory has been bouncing around in my head for a while, but I wasn't sure if or how I should share it. It was a conversation that meant very little, but also meant the world. It was scary, and funny, and the moment when I realized that sometimes the people you least expect will accept you. Sometimes, even if they don't fully understand, even if they barely know you, someone will choose to support you. And that will always matter.
It's a lot easier to prevent cramps from getting bad than to stop them once they already are. Take the medicine sooner and use the heating pad sooner rather than later.
This is true of pain medication for ANY condition. My mom drilled this into me back when she worked as an O.R. nurse: Do not wait until the pain is bad. If you know itâs going to be, get ahead of it. First cramp? Medicate now. Twinges of a headache? Medicate now. Pulled your back and you know youâll feel it later? Medicate NOW.
As my doctor back in the US (who looked like a biker Santa in overalls) used to tell me, "You gotta get on top of the pain instead of chasing it, 'cause that shit's a lot harder to catch once you give it a head start."
Or the other version, "You let that pain go too long, it'll take you twice the meds to get half the relief."
âNo one is finally dead until the ripples they cause in the world die away, until the clock he wound up winds down, until the wine she made has finished its ferment, until the crop they planted is harvested. The span of someoneâs life is only the core of their actual existence.â
Reaper Man - Terry Pratchett
Nine years. It took me almost six of them to finally read Shepherd's Crown. I couldn't bear the idea of ever reaching the end of the story.
âIf you really want to be a critical reader, it turns out you have to step back one step further, and ask not just whether the author is telling the truth, but why heâs writing about this subject at all.â
One other one for How: âhow could this be exploited by someone acting in bad  faith?â Closely coupled with a What: âwhat are the limits on the ill-effects this could produce?â
And a quick check for double standards: âwho, or what, is the speaker not applying this principle to?â
(This is also a great guide for interrogating historical documents such as, say, a constitution, a press release, a speech, a letter, a diary, a bill of rights, political policies, &c)
Please don't ask me for relationship advice unless you are prepared to receive some truly upsetting information because some people are ready for the "He's exhibiting the literal textbook signs of a psychological abuser and you need to get away from him before he successfully cuts you off from your support network" talk and some people aren't
There is never any justification for someone putting their hands on you in any way without your consent short of immediate risk of harm or death.
If someone tells you that "the way I'm acting is your fault because you know that doing X thing would make me do it and you chose to do it anyway" is just fancy bullshit talk for, "I know my behaviour is wrong, but I don't want to be held responsible for it so I'm pushing it on you"
Nothing good ever, ever comes from someone who tells you, "I don't want you talking about our relationship with anyone". This person cannot handle accepting responsibility and processing criticism so they need you to never, ever question them. That's easier if they control the narrative and your friends aren't there to cut in.
Nothing constructive comes from screaming.
"It's not like that all the time" is optimistic and sweet, but the truth is, it shouldn't be like that at all. Sweet words and gifts and gestures don't erase being frightened for yourself or for your loved ones. That is not normal. Don't minimize it.
It is not healthy or normal to be genuinely afraid of saying "no" to someone, for any reason at all. Violence, outbursts, retaliation, anything. You should not have to be afraid of someone's reaction to your boundaries.
You are not responsible for saving anyone. Even if you love them. Even if they have nobody else. At the end of the day, if they want to hurt themselves in any way, they will, and you can't stop them forever. People need to want to improve before they can actually improve, and if they're threatening to harm themselves to keep you around, they're using your love to hold themselves hostage. You do not decide their choices for them, and they don't get to shunt that off on you.
There will always be other people who can love you better. You will not be alone forever. This will not be the last time you care for someone like this and it will not be the last time someone cares for you
Ninjas donât wear black. They used to disguise themselves as civilians. Unlike ninjas in movies, the real guys were smart enough to know that wearing a black outfit with a face mask wasnât the best strategy for blending in. Source
But this leaves out the really neat part! The reason we equate the above image with a ninja comes from Kabuki theatre. Within Kabuki theatre thereâs a convention of having Kuroko (stage hands) dress in all black (with a full face covering) and move around among the costumed actors in full view, moving scenery, props and costumes. In a similar way, Bunraku puppeteers dress in all black, and only the lead puppeteerâs face would be uncovered. The audience knew to ignore these people and focus on the actors, and to only see that the scene was âmagicallyâ changing. So when a play called for a ninja assassin to jump out of nowhere and kill someone, the easiest way to create the surprise reveal was to disguise the ninja in the all black garb of the Kuroko and to remove the face covering and start acting at the last second. This would shock the audience, who were conditioned to not focus on them. Pretty cool, yeah?
If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
More specifically, I was tricked by a phone-phisher pretending to be from my bank, and he convinced me to hand over my credit-card number, then did $8,000+ worth of fraud with it before I figured out what happened. And then he tried to do it again, a week later!
Here's what happened. Over the Christmas holiday, I traveled to New Orleans. The day we landed, I hit a Chase ATM in the French Quarter for some cash, but the machine declined the transaction. Later in the day, we passed a little credit-union's ATM and I used that one instead (I bank with a one-branch credit union and generally there's no fee to use another CU's ATM).
A couple days later, I got a call from my credit union. It was a weekend, during the holiday, and the guy who called was obviously working for my little CU's after-hours fraud contractor. I'd dealt with these folks before â they service a ton of little credit unions, and generally the call quality isn't great and the staff will often make mistakes like mispronouncing my credit union's name.
That's what happened here â the guy was on a terrible VOIP line and I had to ask him to readjust his mic before I could even understand him. He mispronounced my bank's name and then asked if I'd attempted to spend $1,000 at an Apple Store in NYC that day. No, I said, and groaned inwardly. What a pain in the ass. Obviously, I'd had my ATM card skimmed â either at the Chase ATM (maybe that was why the transaction failed), or at the other credit union's ATM (it had been a very cheap looking system).
I told the guy to block my card and we started going through the tedious business of running through recent transactions, verifying my identity, and so on. It dragged on and on. These were my last hours in New Orleans, and I'd left my family at home and gone out to see some of the pre-Mardi Gras krewe celebrations and get a muffalata, and I could tell that I was going to run out of time before I finished talking to this guy.
"Look," I said, "you've got all my details, you've frozen the card. I gotta go home and meet my family and head to the airport. I'll call you back on the after-hours number once I'm through security, all right?"
He was frustrated, but that was his problem. I hung up, got my sandwich, went to the airport, and we checked in. It was total chaos: an Alaska Air 737 Max had just lost its door-plug in mid-air and every Max in every airline's fleet had been grounded, so the check in was crammed with people trying to rebook. We got through to the gate and I sat down to call the CU's after-hours line. The person on the other end told me that she could only handle lost and stolen cards, not fraud, and given that I'd already frozen the card, I should just drop by the branch on Monday to get a new card.
We flew home, and later the next day, I logged into my account and made a list of all the fraudulent transactions and printed them out, and on Monday morning, I drove to the bank to deal with all the paperwork. The folks at the CU were even more pissed than I was. The fraud that run up to more than $8,000, and if Visa refused to take it out of the merchants where the card had been used, my little credit union would have to eat the loss.
I agreed and commiserated. I also pointed out that their outsource, after-hours fraud center bore some blame here: I'd canceled the card on Saturday but most of the fraud had taken place on Sunday. Something had gone wrong.
One cool thing about banking at a tiny credit-union is that you end up talking to people who have actual authority, responsibility and agency. It turned out the the woman who was processing my fraud paperwork was a VP, and she decided to look into it. A few minutes later she came back and told me that the fraud center had no record of having called me on Saturday.
"That was the fraudster," she said.
Oh, shit. I frantically rewound my conversation, trying to figure out if this could possibly be true. I hadn't given him anything apart from some very anodyne info, like what city I live in (which is in my Wikipedia entry), my date of birth (ditto), and the last four digits of my card.
Wait a sec.
He hadn't asked for the last four digits. He'd asked for the last seven digits. At the time, I'd found that very frustrating, but now â "The first nine digits are the same for every card you issue, right?" I asked the VP.
I'd given him my entire card number.
Goddammit.
The thing is, I know a lot about fraud. I'm writing an entire series of novels about this kind of scam:
And most summers, I go to Defcon, and I always go to the "social engineering" competitions where an audience listens as a hacker in a soundproof booth cold-calls merchants (with the owner's permission) and tries to con whoever answers the phone into giving up important information.
But I'd been conned.
Now look, I knew I could be conned. I'd been conned before, 13 years ago, by a Twitter worm that successfully phished out of my password via DM:
That scam had required a miracle of timing. It started the day before, when I'd reset my phone to factory defaults and reinstalled all my apps. That same day, I'd published two big online features that a lot of people were talking about. The next morning, we were late getting out of the house, so by the time my wife and I dropped the kid at daycare and went to the coffee shop, it had a long line. Rather than wait in line with me, my wife sat down to read a newspaper, and so I pulled out my phone and found a Twitter DM from a friend asking "is this you?" with a URL.
Assuming this was something to do with those articles I'd published the day before, I clicked the link and got prompted for my Twitter login again. This had been happening all day because I'd done that mobile reinstall the day before and all my stored passwords had been wiped. I entered it but the page timed out. By that time, the coffees were ready. We sat and chatted for a bit, then went our own ways.
I was on my way to the office when I checked my phone again. I had a whole string of DMs from other friends. Each one read "is this you?" and had a URL.
Oh, shit, I'd been phished.
If I hadn't reinstalled my mobile OS the day before. If I hadn't published a pair of big articles the day before. If we hadn't been late getting out the door. If we had been a little more late getting out the door (so that I'd have seen the multiple DMs, which would have tipped me off).
There's a name for this in security circles: "Swiss-cheese security." Imagine multiple slices of Swiss cheese all stacked up, the holes in one slice blocked by the slice below it. All the slices move around and every now and again, a hole opens up that goes all the way through the stack. Zap!
The fraudster who tricked me out of my credit card number had Swiss cheese security on his side. Yes, he spoofed my bank's caller ID, but that wouldn't have been enough to fool me if I hadn't been on vacation, having just used a pair of dodgy ATMs, in a hurry and distracted. If the 737 Max disaster hadn't happened that day and I'd had more time at the gate, I'd have called my bank back. If my bank didn't use a slightly crappy outsource/out-of-hours fraud center that I'd already had sub-par experiences with. If, if, if.
The next Friday night, at 5:30PM, the fraudster called me back, pretending to be the bank's after-hours center. He told me my card had been compromised again. But: I hadn't removed my card from my wallet since I'd had it replaced. Also, it was half an hour after the bank closed for the long weekend, a very fraud-friendly time. And when I told him I'd call him back and asked for the after-hours fraud number, he got very threatening and warned me that because I'd now been notified about the fraud that any losses the bank suffered after I hung up the phone without completing the fraud protocol would be billed to me. I hung up on him. He called me back immediately. I hung up on him again and put my phone into do-not-disturb.
The following Tuesday, I called my bank and spoke to their head of risk-management. I went through everything I'd figured out about the fraudsters, and she told me that credit unions across America were being hit by this scam, by fraudsters who somehow knew CU customers' phone numbers and names, and which CU they banked at. This was key: my phone number is a reasonably well-kept secret. You can get it by spending money with Equifax or another nonconsensual doxing giant, but you can't just google it or get it at any of the free services. The fact that the fraudsters knew where I banked, knew my name, and had my phone number had really caused me to let down my guard.
The risk management person and I talked about how the credit union could mitigate this attack: for example, by better-training the after-hours card-loss staff to be on the alert for calls from people who had been contacted about supposed card fraud. We also went through the confusing phone-menu that had funneled me to the wrong department when I called in, and worked through alternate wording for the menu system that would be clearer (this is the best part about banking with a small CU â you can talk directly to the responsible person and have a productive discussion!). I even convinced her to buy a ticket to next summer's Defcon to attend the social engineering competitions.
There's a leak somewhere in the CU systems' supply chain. Maybe it's Zelle, or the small number of corresponding banks that CUs rely on for SWIFT transaction forwarding. Maybe it's even those after-hours fraud/card-loss centers. But all across the USA, CU customers are getting calls with spoofed caller IDs from fraudsters who know their registered phone numbers and where they bank.
I've been mulling this over for most of a month now, and one thing has really been eating at me: the way that AI is going to make this kind of problem much worse.
Not because AI is going to commit fraud, though.
One of the truest things I know about AI is: "we're nowhere near a place where bots can steal your job, we're certainly at the point where your boss can be suckered into firing you and replacing you with a bot that fails at doing your job":
I trusted this fraudster specifically because I knew that the outsource, out-of-hours contractors my bank uses have crummy headsets, don't know how to pronounce my bank's name, and have long-ass, tedious, and pointless standardized questionnaires they run through when taking fraud reports. All of this created cover for the fraudster, whose plausibility was enhanced by the rough edges in his pitch - they didn't raise red flags.
As this kind of fraud reporting and fraud contacting is increasingly outsourced to AI, bank customers will be conditioned to dealing with semi-automated systems that make stupid mistakes, force you to repeat yourself, ask you questions they should already know the answers to, and so on. In other words, AI will groom bank customers to be phishing victims.
This is a mistake the finance sector keeps making. 15 years ago, Ben Laurie excoriated the UK banks for their "Verified By Visa" system, which validated credit card transactions by taking users to a third party site and requiring them to re-enter parts of their password there:
This is exactly how a phishing attack works. As Laurie pointed out, this was the banks training their customers to be phished.
I came close to getting phished again today, as it happens. I got back from Berlin on Friday and my suitcase was damaged in transit. I've been dealing with the airline, which means I've really been dealing with their third-party, outsource luggage-damage service. They have a terrible website, their emails are incoherent, and they officiously demand the same information over and over again.
This morning, I got a scam email asking me for more information to complete my damaged luggage claim. It was a terrible email, from a noreply@ email address, and it was vague, officious, and dishearteningly bureaucratic. For just a moment, my finger hovered over the phishing link, and then I looked a little closer.
On any other day, it wouldn't have had a chance. Today â right after I had my luggage wrecked, while I'm still jetlagged, and after days of dealing with my airline's terrible outsource partner â it almost worked.
So much fraud is a Swiss-cheese attack, and while companies can't close all the holes, they can stop creating new ones.
Meanwhile, I'll continue to post about it whenever I get scammed. I find the inner workings of scams to be fascinating, and it's also important to remind people that everyone is vulnerable sometimes, and scammers are willing to try endless variations until an attack lands at just the right place, at just the right time, in just the right way. If you think you can't get scammed, that makes you especially vulnerable:
I really recommend everyone read this; it is applicable to most anyone and is also rather reassuring to read. I think sometimes we think about scams with the same flawed thinking that we have for cults or propaganda; we tell ourselves that it could never be us falling for something, because we are too smart or suspicious or whatever else. That "immunity" line of thinking is not only incorrect, it makes us even more vulnerable.
But if Cory Doctorow, someone I think of as admirably skeptical and tech-savvy, can get scammed, then I certainly don't have cause to be overcritical of myself when it happens to me, nor being uncompassionate when it happens to others. And neither does anyone else.
Also, the part about scammers getting more aggressive and escalating when you express a hint of skepticism is very important. This has happened to me as well, only it was in-person rather than over the phone, so I was eventually physically threatened when I tried to leave before they got everything they wanted.
The idea of being set up for this by the poor quality of legitimate service makes so much sense. The scammers I mention scammers acted rudely in the beginning, but no more aggressively than some of the more unethical methods utilized by legitimate services. My window to leave the situation safely passed, because I had no way to know they were any different than your average poor-quality business, until they reacted so scarily when I tried to say no.
Even their initial unwillingness to believe I wanted to pay in cash and their insistence that I give them my credit card didn't raise any red flags, because I have had that exact experience inside my own workplace. But while it looked the same on the surface, my workplace doesn't accept cash for the sake of their convenience (along with some other influences that I find concerning, but that someone else would be better qualified to elaborate upon). The scammers didn't want cash because it's a lot easier to charge someone unspecified amounts on a credit card than it is to deceive to someone about how much cash they are handing you.
The only times Iâve ever been scammed or phished have been because of this.
The one time I fell for a scam credit card call it was because I was traveling, it was the first time Iâd used my card on the trip, and it was to pay for a big meal. The card went through but I got a call in the parking lot telling me there was suspicious activity and I needed to prove that it was legitimate but providing some details. I did it without thinking.
The next day a friend mentioned that they had received an identical call with no extenuating circumstances, and it was only then that it clicked and I reported the fraud.
one thing that Iâd like to add is that itâs not hard (or that expensive) to have at least decent customer service. I wonât cast judgement on a small cu. But something like an airline could probably benefit from a decent in-house support team.
Unions are why you have 5 day, 40 hour full-time work weeks. Unions are why they have to pay you in actual dollars instead of âcompany creditsâ that you can only spend at the company-owned stores. Unions are why there are fucking fire exits at your place of work. Unions are why itâs not okay for your supermarket ground beef to be any percentage human.
You think your company pays you out of the goodness of their hearts? Or even out of âmarket pressure?â The âjob marketâ is a myth perpetuated by the capitalists. Corporations would pay you nothing if they could get away with it. And you argue âoh, but if they paid me nothing Iâd just go to another one.â Wrong. Because to maximize profits, they all want to pay you nothing. Corporations exist to maximize profits while reducing risk for investors. Itâs part of their entire function to find ways to cut costs as much as possible, and that includes finding ways to pay you nothing.
Unions are your defense against that. You think all a union does is strike? If you pay union dues, a lot of that is spent on lobbyists in various governments reminding your lawmakers that you have rights as a living human being that a corporation should not be able to stomp all over. Unions hire lawyers so that if youâre fired for bullshit reasons, the union can stand up for you against your boss. Theyâre called unions because workers are uniting to pool resources so that they can stand up to these corporate overlords with more money than God. Unions exist because you might not have the words, resources, or time to fight workplace injustices all by yourself. Thatâs the whole fucking point.
And if a business shuts down because a union is striking, itâs because the business was abusing people and didnât deserve to be in business anyway. Donât make excuses for the corporations. They already have trillions of dollars and a couple million lawyers to do that for themselves. They donât need your help.
[ ID: A thread of five successive tweets by C.W. Howell @ cwhowell123 that read as follows: So I followed @ GaryMarcus's suggestion and had my undergrad class use ChatGPT for a critical assignment. I had them all generate an essay using a prompt I gave them, and then their job was to "grade" it--look for hallucinated info and critique its analysis. *All 63* essays had / hallucinated information. Fake quotes, fake sources, or real sources misunderstood and mischaracterized. Every single assignment. I was stunned--I figured the rate would be high, but not that high. / The biggest takeaway from this was that the students all learned that it isn't fully reliable. Before doing it, many of them were under the impression it was always right. Their feedback largely focused on how shocked they were that it could mislead them. Probably 50% of them / were unaware it could do this. All of them expressed fears and concerns about mental atrophy and the possibility for misinformation/fake news. One student was worried that their neural pathways formed from critical thinking would start to degrade or weaken. One other student / opined that AI both knew more than us but is dumber than we are since it cannot think critically. She wrote, "I'm not worried about AI getting to where we are now. I'm much more worried about the possibility of us reverting to where AI is." /end ID. ]
doubly funny that I saw a compilation of all the corporate accounts like "aw thanks elmo, we're doing well" meanwhile all the flesh and blood real human people are extremely not okay