Last week, the Lockbit ransomware group (one of the most active and professional groups of cyber criminals in the world) got hacked by the FBI. Lockbit's signature move is their public countdown timers for any company that got hacked, telling the world that company's files would be released if they didn't pay up. So the FBI put a countdown timer in their website, with the same design and style as the old Lockbit site, until they would release the name of the head of the organization.
Today, 2 days after the countdown timer expired (with no name being released as far as I'm aware), Lockbit finally released their own statement. it's pretty funny (Although, of course, take it with a grain of salt)
Tumblr media
he claims that he may have information stolen from the Trump prosecution in Fulton county, and that's why the FBI hacked him. And now that this has taught him the vulnerabilities in his system, he needs to double down on hacking more government data:
Tumblr media
He also offers to hire the hacker who found the vulnerability in his system, saying that the FBI won't ever pay him the millions of dollars he's worth:
Tumblr media
and their designer, because he thought the logo they put on the takedown site was super cool:
Tumblr media
since we've seen so many bad examples of posting through it recently I thought I'd share one of the better examples of the genre. hope his security is as good as he thinks it is lmaooo
A link-clump demands a linkdump
Tumblr media
Cometh the weekend, cometh the linkdump. My daily-ish newsletter includes a section called "Hey look at this," with three short links per day, but sometimes those links get backed up and I need to clean house. Here's the eight previous installments:
The country code top level domain (ccTLD) for the Caribbean island nation of Anguilla is .ai, and that's turned into millions of dollars worth of royalties as "entrepreneurs" scramble to sprinkle some buzzword-compliant AI stuff on their businesses in the most superficial way possible:
All told, .ai domain royalties will account for about ten percent of the country's GDP.
It's actually kind of nice to see Anguilla finding some internet money at long last. Back in the 1990s, when I was a freelance web developer, I got hired to work on the investor website for a publicly traded internet casino based in Anguilla that was a scammy disaster in every conceivable way. The company had been conceived of by people who inherited a modestly successful chain of print-shops and decided to diversify by buying a dormant penny mining stock and relaunching it as an online casino.
But of course, online casinos were illegal nearly everywhere. Not in Anguilla – or at least, that's what the founders told us – which is why they located their servers there, despite the lack of broadband or, indeed, reliable electricity at their data-center. At a certain point, the whole thing started to whiff of a stock swindle, a pump-and-dump where they'd sell off shares in that ex-mining stock to people who knew even less about the internet than they did and skedaddle. I got out, and lost track of them, and a search for their names and business today turns up nothing so I assume that it flamed out before it could ruin any retail investors' lives.
Anguilla is a British Overseas Territory, one of those former British colonies that was drained and then given "independence" by paternalistic imperial administrators half a world away. The country's main industries are tourism and "finance" – which is to say, it's a pearl in the globe-spanning necklace of tax- and corporate-crime-havens the UK established around the world so its most vicious criminals – the hereditary aristocracy – can continue to use Britain's roads and exploit its educated workforce without paying any taxes.
This is the "finance curse," and there are tiny, struggling nations all around the world that live under it. Nick Shaxson dubbed them "Treasure Islands" in his outstanding book of the same name:
I can't imagine that the AI bubble will last forever – anything that can't go on forever eventually stops – and when it does, those .ai domain royalties will dry up. But until then, I salute Anguilla, which has at last found the internet riches that I played a small part in bringing to it in the previous century.
The AI bubble is indeed overdue for a popping, but while the market remains gripped by irrational exuberance, there's lots of weird stuff happening around the edges. Take Inject My PDF, which embeds repeating blocks of invisible text into your resume:
The text is tuned to make resume-sorting Large Language Models identify you as the ideal candidate for the job. It'll even trick the summarizer function into spitting out text that does not appear in any human-readable form on your CV.
Embedding weird stuff into resumes is a hacker tradition. I first encountered it at the Chaos Communications Congress in 2012, when Ang Cui used it as an example in his stellar "Print Me If You Dare" talk:
Cui figured out that one way to update the software of a printer was to embed an invisible Postscript instruction in a document that basically said, "everything after this is a firmware update." Then he came up with 100 lines of perl that he hid in documents with names like cv.pdf that would flash the printer when they ran, causing it to probe your LAN for vulnerable PCs and take them over, opening a reverse-shell to his command-and-control server in the cloud. Compromised printers would then refuse to apply future updates from their owners, but would pretend to install them and even update their version numbers to give verisimilitude to the ruse. The only way to exorcise these haunted printers was to send 'em to the landfill. Good times!
Printers are still a dumpster fire, and it's not solely about the intrinsic difficulty of computer security. After all, printer manufacturers have devoted enormous resources to hardening their products against their owners, making it progressively harder to use third-party ink. They're super perverse about it, too – they send "security updates" to your printer that update the printer's security against you – run these updates and your printer downgrades itself by refusing to use the ink you chose for it:
It's a reminder that what a monopolist thinks of as "security" isn't what you think of as security. Oftentimes, their security is antithetical to your security. That was the case with Web Environment Integrity, a plan by Google to make your phone rat you out to advertisers' servers, revealing any adblocking modifications you might have installed so that ad-serving companies could refuse to talk to you:
WEI is now dead, thanks to a lot of hueing and crying by people like us:
But the dream of securing Google against its own users lives on. Youtube has embarked on an aggressive campaign of refusing to show videos to people running ad-blockers, triggering an arms-race of ad-blocker-blockers and ad-blocker-blocker-blockers:
The folks behind Ublock Origin are racing to keep up with Google's engineers' countermeasures, and there's a single-serving website called "Is uBlock Origin updated to the last Anti-Adblocker YouTube script?" that will give you a realtime, one-word status update:
One in four web users has an ad-blocker, a stat that Doc Searls pithily summarizes as "the biggest boycott in world history":
Zero app users have ad-blockers. That's not because ad-blocking an app is harder than ad-blocking the web – it's because reverse-engineering an app triggers liability under IP laws like Section 1201 of the Digital Millenium Copyright Act, which can put you away for 5 years for a first offense. That's what I mean when I say that "IP is anything that lets a company control its customers, critics or competitors:
I predicted that apps would open up all kinds of opportunities for abusive, monopolistic conduct back in 2010, and I'm experiencing a mix of sadness and smugness (I assume there's a German word for this emotion) at being so thoroughly vindicated by history:
The more control a company can exert over its customers, the worse it will be tempted to treat them. These systems of control shift the balance of power within companies, making it harder for internal factions that defend product quality and customer interests to win against the enshittifiers:
The result has been a Great Enshittening, with platforms of all description shifting value from their customers and users to their shareholders, making everything palpably worse. The only bright side is that this has created the political will to do something about it, sparking a wave of bold, muscular antitrust action all over the world.
The Google antitrust case is certainly the most important corporate lawsuit of the century (so far), but Judge Amit Mehta's deference to Google's demands for secrecy has kept the case out of the headlines. I mean, Sam Bankman-Fried is a psychopathic thief, but even so, his trial does not deserve its vastly greater prominence, though, if you haven't heard yet, he's been convicted and will face decades in prison after he exhausts his appeals:
The secrecy around Google's trial has relaxed somewhat, and the trickle of revelations emerging from the cracks in the courthouse are fascinating. For the first time, we're able to get a concrete sense of which queries are the most lucrative for Google:
The list comes from 2018, but it's still wild. As David Pierce writes in The Verge, the top twenty includes three iPhone-related terms, five insurance queries, and the rest are overshadowed by searches for customer service info for monopolistic services like Xfinity, Uber and Hulu.
All-in-all, we're living through a hell of a moment for piercing the corporate veil. Maybe it's the problem of maintaining secrecy within large companies, or maybe the the rampant mistreatment of even senior executives has led to more leaks and whistleblowing. Either way, we all owe a debt of gratitude to the anonymous leaker who revealed the unbelievable pettiness of former HBO president of programming Casey Bloys, who ordered his underlings to create an army of sock-puppet Twitter accounts to harass TV and movie critics who panned HBO's shows:
These trolling attempts were pathetic, even by the standards of thick-fingered corporate execs. Like, accusing critics who panned the shitty-ass Perry Mason reboot of disrespecting veterans because the fictional Mason's back-story had him storming the beach on D-Day.
The pushback against corporate bullying is everywhere, and of course, the vanguard is the labor movement. Did you hear that the UAW won their strike against the auto-makers, scoring raises for all workers based on the increases in the companies' CEO pay? The UAW isn't done, either! Their incredible new leader, Shawn Fain, has called for a general strike in 2028:
The massive victory for unionized auto-workers has thrown a spotlight on the terrible working conditions and pay for workers at Tesla, a criminal company that has no compunctions about violating labor law to prevent its workers from exercising their legal rights. Over in Sweden, union workers are teaching Tesla a lesson. After the company tried its illegal union-busting playbook on Tesla service centers, the unionized dock-workers issued an ultimatum: respect your workers or face a blockade at Sweden's ports that would block any Tesla from being unloaded into the EU's fifth largest Tesla market:
Of course, the real solution to Teslas – and every other kind of car – is to redesign our cities for public transit, walking and cycling, making cars the exception for deliveries, accessibility and other necessities. Transitioning to EVs will make a big dent in the climate emergency, but it won't make our streets any safer – and they keep getting deadlier.
Last summer, my dear old pal Ted Kulczycky got in touch with me to tell me that Talking Heads were going to be all present in public for the first time since the band's breakup, as part of the debut of the newly remastered print of Stop Making Sense, the greatest concert movie of all time. Even better, the show would be in Toronto, my hometown, where Ted and I went to high-school together, at TIFF.
Ted is the only person I know who is more obsessed with Talking Heads than I am, and he started working on tickets for the show while I starting pricing plane tickets. And then, the unthinkable happened: Ted's wife, Serah, got in touch to say that Ted had been run over by a car while getting off of a streetcar, that he was severely injured, and would require multiple surgeries.
But this was Ted, so of course he was still planning to see the show. And he did, getting a day-pass from the hospital and showing up looking like someone from a Kids In The Hall sketch who'd been made up to look like someone who'd been run over by a car:
In his Globe and Mail article about Ted's experience, Brad Wheeler describes how the whole hospital rallied around Ted to make it possible for him to get to the movie:
He also mentions that Ted is working on a book and podcast about Stop Making Sense. I visited Ted in the hospital the day after the gig and we talked about the book and it sounds amazing. Also? The movie was incredible. See it in Imax.
That heartwarming tale of healing through big suits is a pretty good place to wrap up this linkdump, but I want to call your attention to just one more thing before I go: Robin Sloan's Snarkmarket piece about blogging and "stock and flow":
Sloan makes the excellent case that for writers, having a "flow" of short, quick posts builds the audience for a "stock" of longer, more synthetic pieces like books. This has certainly been my experience, but I think it's only part of the story – there are good, non-mercenary reasons for writers to do a lot of "flow." As I wrote in my 2021 essay, "The Memex Method," turning your commonplace book into a database – AKA "blogging" – makes you write better notes to yourself because you know others will see them:
This, in turn, creates a supersaturated, subconscious solution of fragments that are just waiting to nucleate and crystallize into full-blown novels and nonfiction books and other "stock." That's how I came out of lockdown with nine new books. The next one is The Lost Cause, a hopepunk science fiction novel about the climate whose early fans include Naomi Klein, Rebecca Solnit, Bill McKibben and Kim Stanley Robinson. It's out on November 14:
Tumblr media
If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
go-learn-esperanto · 10 months
Nooo I just saw some guys make a conspiracy theory that there weren't hackers in the Ao3 DDOS attack and it was actually Ao3 trying to get more money 💀
Do they realise Ao3 has to declare everything they do? OTW ia a non-profit organisation that is tax reducible in the US, they won a Hugo award. They're more than well known and are probably well observed. What do you think they're doing with the money???? You can literally see their financial expenses!
"Why are people saying they're gonna donate since that money isn't going to the UNPAID volunteers 🙁" I donate because donating money means the website can remaim FUNCTIONING. Because it's a service that I and a lot of use for free. Because servers cost MONEY. Because domains cost MONEY. Because sometimes they might need to hire some outsiders to fix something or do something the volunteers aren't able to do. Because they have to host a very big amount of works AND be able to have a lot of users on the website at the same time, because they have to keep some saved in case they have to fight in court for something!!! Because if you follow Ao3's TOS and some company decided to try to use copywrite against you and claiming you're stealing their money Ao3 will go to court for you!!!!
I have seen a lot of stupid conspiracy theories and this one is definitely one of them.
missmitchieg · 2 months
i don’t go here but what happened to penelope garcia’s hair ? isn’t it like shoulder length ? did she cut it ? !
/lh , tell me about penelope garcia please ?
Tumblr media
Yay! I love talking about babygirl! Ok, so it looks like she did indeed cut her luscious locks so rip to her long princess curls. They will be missed until they grow back. 💖
Ok, so season 1-15 Penelope was MY GIRL, ok? She was MY GIRL.
She's, like, a super genius super cutie and she's super sweet and kind and loves animals. (Seriously, one of the reasons she started working for the FBI is she was a computer hacker and hacked into the website of a cosmetic company that tests on animals and her options when she got caught were literally work for the FBI or her ass is getting thrown in prison. She chose the FBI. We love a queen that fights for animal wellfare. The other reason was she wanted to get away from her garbage, and I do mean GARBAGE, boyfriend and have a better life.)
I'm pretty sure she has ADHD. Maybe autism. IDK, but she's definitely some kinda neurospicy.
She's a walking sparkly neon rainbow. You know the way Flynn's bedroom is described in the one jatp book? Season 1-15 Penelope is that and I love it.
She went ginger once and it was a whole vibe.
Tumblr media
Wow, I love her.
She was super nice to her ex boss all the way from s1 to his departure in early s12, and I'm 99% sure was the only one that actually called him bossman or sir bc everyone else just called him Aaron or by his nickname, Hotch. She was really good at making him smile, which actually wasn't that hard but people exaggerate the rarity of a Hotch smile for some reason.
Tumblr media
After that, she was still really nice to the replacement he handpicked, Emily Prentiss, who she already adored after working with her since s2.
Tumblr media
Hotch was literally physically incapable of saying no to this woman and she fully knew and took advantage of that shit, ok? Seriously, one time, Penelope made a joke like "who could say no to me?" and Hotch just smirked a little bit because he knew he couldn't say anything. Penelope does an incredible imitation of the pleading emoji. Or the Puss In Boots face. Whatever you wanna call this:
Tumblr media Tumblr media
"Boss, I want you to hire Tara. 🥺" "Ok. Tell everyone else the position has been filled." "Boss, I don't wanna eat dinner alone. Do you want a veggie omelette? 🥺" "Ok. Do you have jalapeños?"
The hilarious thing is she doesn't even have to make that face. She does it to mess with him.
And then there's her, uh...... interesting little flirtationship with Derek Morgan. Or as Penelope calls him, chocolate thunder. He loves that name and encourages it. He calls her babygirl. They also have about a million other adorable pet names for each other.
Tumblr media Tumblr media
*gestures at these gifs* They love each other so much, it's kind of gross. I've said before that before I actually started watching and only had the massive comp of him calling her that, I genuinely really thought Morcia was canon. Like, oh, my GOD, dude. These two are disgustingly obsessed with each other. The shit they say on work calls. He calls her sexy and brilliant Goddess and told her it drives him crazy when "she talks that voulez coucher stuff to him". Like, hello? Honestly, I'm amazed Derek only had to sit through one HR lecture about creating a hostile work environment. Or at least, we only saw one.
Then there's her very sweet friendship with baby genius, boy wonder, good doctor, Agent Doctor Spencer Reid.
Tumblr media
MY BABIES. I LOVE THEM. I want them back. Gimme back my Penny², damnit.
And her very sweet friendship with Matt Simmons! Oh, my god. I love them. 🥰🥰🥰
Tumblr media
They're cute and I wish at least Penelope mentioned Matt in season 16 more.
Penelope and Luke! Oh, my God. Penelope and Luke.
Tumblr media
They are in love and both think it's unrequited and it's exhausting but at least s12-15 were FUN. Mostly.
Season 16 Penelope, though....
Tumblr media
Season 16 Penelope got abducted by aliens. Or lobotomized. Hard to tell.
bunsofhoney · 1 year
Peter: I need to go apartment shopping. I can't stay here when my new arch-nemesis knows where I live.
Wade: I could come with you. Give you some professional advice on...security.
Peter: Professional advice, huh? From a professional criminal?
Wade: Hey, baby, nobody knows the business better than me. Want to make your website secure, hire a white-hat hacker. Want to make your apartment secure, hire the guy who broke in and kidnapped you.
Peter: *Massive eye roll*
From Bed Bugs
renemesis · 10 months
"Waaaah waaaah the alt-right are keeping our fics from us waaaah waaaaah!!!" ... y'know if you presented a 'fictional' scenario to a group of people (let's pretend, for a moment, that this hypothetical crowd isn't absolutely brainrotted from constant internet usage) where you told them a group running a website get almost- if not even MORE than- half a million dollars on a yearly basis to run a service that is fuels almost entirely by USER CONTRIBUTIONS but never improve it, most would think it's at best overcompensation and at worst a Scam.
Now if you told these people that, Somehow, the people who get hundreds of thousands of dollars yearly for this service can't even use that money to prevent their service from being DDoS'd, or to use the money to hire people specifically specialized in solving these cases, you might get a bit more suspicion from the audience.
Now, if you tell them the cherry on top is that the service runners, instead of just quietly taking care of the problem and giving minimal details about what's going on, allow for and even HELP in the spreading of the narrative THAT THEY'VE BEEN ATTACKED BY AN ALT-RIGHT GROUP 'CLAIMING' TO BE SUDANESE? Oh, but when its explained that the hackers aren't ACTUALLY Sudanese, people jump to it being the Russians instead! The people listening to you explain this oh so fictitious scenario would QUITE OBVIOUSLY THINK THIS IS BLATANTLY FEARMONGERING AND USING XENOPHOBIA AS A MEANS OF COVERING THEIR OWN EXPOSED ASS, RATHER THAN JUST TAKING ACCOUNTABLE.
Please p ease PLEASE take a step back and check the absolutely INSANE biases being displayed right now. Sure, maybe an Alt-Right group IS keeping y'all from reading your diet yaoi, but let's be fucking realistic here. The AO3 moderators are taking advantage xenophobia on both ends of the spectrum, whether they openly 'denounce' the alleged origins of the 'hacker group' directly or not, because sooo many people are so willing to take the bait and fall down the conspiracy rabbit hole rather than acknowledging they might have an unhealthy attachment to a website run by people who only see them as wallet fillers
Please, if you're crying and screaming about losing ao3... take a step outside. Sit on the ground. Take in the sun. Read a book. Pick up a pen and paper and write or draw. Hell, if you're REALLY desperate go explore the Wonders of alternative fic websites, go check out our old friends at ff.net. just PLEASE do something other than complain and throw nationality-based blame at the hackers. You guys sound like Trumpies rn
