Mastodon Feed: Posts

Mastodon Feed

rmrenner ("The Old Gay Gristle Fest") wrote:

oh right, there are also charms that give you extra XP and extra tera shards. The XP charm isn't that useful if you're already in the end game and mostly using xp candy to raise new monsters. The tera charm is also of kinda limited usefulness because giving your fighters a zany teratype is rarely worthwhile if you're just doing raids.

Mastodon Feed

Reblogged by kornel ("Kornel"):

gknauss ("Greg Knauss") wrote:

I propose a day, once a quarter, where the team maintaining an open source project sits down with a new user and silently watches them try to compile it, using only the instructions on the website.

Mastodon Feed

rmrenner ("The Old Gay Gristle Fest") wrote:

I finished off the Pokemon DLC last night. It was cute but it feels like it has less reason to exist than the Sw/Sh one. We'll see what the 2nd half is like.

A lot of the benefits to the DLC update are available even if you don't get the DLC: a bunch of older pokemon + dramatic performance improvements to the pokemon storage system. The only thing you're fully missing out on right now by not having it is the 4 legendaries (+1 unique form of Ursaluna) and a bunch of neat little places to wander.

Mastodon Feed

rmrenner ("The Old Gay Gristle Fest") wrote:

I am so glad I never moved off of dot social.

Mastodon Feed

Reblogged by kornel ("Kornel"):

wellingtonrock ("Denis Buckley") wrote:

Attachments:

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

this should be interesting

https://www.nytimes.com/2023/09/14/us/trump-chesebro-powell-trial-georgia.html?smid=nytcore-ios-share&referringSource=articleShare

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

almost successful:

On Sep 14, 1874: White Militia Wages Coup Against Integrated Louisiana Government

https://calendar.eji.org/racial-injustice/sep/14

Mastodon Feed

pzmyers@octodon.social ("pzmyers 🦑") wrote:

These are pretty cheap-ass fake alien corpses, you know.

https://freethoughtblogs.com/pharyngula/2023/09/14/these-aliens-wouldnt-be-out-of-place-in-a-roadside-museum/

https://www.youtube.com/watch?v=V3NgLNO0cSw

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

Satellite images show damage to Russian naval vessels struck in Ukraine attack

ouch, let us say *former* “Russian landing ship and submarine”

https://www.reuters.com/world/europe/satellite-images-show-damage-russian-naval-vessels-struck-ukraine-attack-2023-09-14/

Mastodon Feed

Reblogged by kornel ("Kornel"):

pikuma@mastodon.gamedev.place wrote:

If you're programming a game where a boat moves through water, you might be tempted (as I would) to change the V-shape angle of the waves behind the boat based on how fast the boat was moving!

What if I told you that that V-shaped angle is always 19.47°, regardless of how fast the boat is travelling? 😱

This pattern even holds true for a duck traversing a pond. 🦆

The envelope of these waves stands at a fixed angle, and the wake has a characteristic feathered pattern.

Attachments:

Mastodon Feed

pzmyers@octodon.social ("pzmyers 🦑") wrote:

A tragedy in one line.

https://freethoughtblogs.com/pharyngula/2023/09/14/he-should-have-stopped-with-the-first-line/

Attachments:

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

time to trim some roses

Attachments:

Mastodon Feed

pzmyers@octodon.social ("pzmyers 🦑") wrote:

I saw Meg2. I hand out all the spoilers so you don't need to suffer, too.

https://freethoughtblogs.com/pharyngula/2023/09/14/this-is-no-way-to-run-a-movie-theater/

Attachments:

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

idiocy

https://www.nytimes.com/2023/09/14/climate/sultan-al-jaber-uae-cop28.html?smid=nytcore-ios-share&referringSource=articleShare

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

good piece https://www.npr.org/2023/09/13/1199231632/tv-review-other-black-girl-dreaming-whilst-black

Mastodon Feed

Gargron ("Eugen Rochko") wrote:

A little snippet ☺️

#vinyl #nowplaying

Attachments:

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

when you perceive politics as a game

https://www.nytimes.com/2023/09/13/us/politics/trump-gop-biden-impeachment.html?smid=nytcore-ios-share&referringSource=articleShare

Mastodon Feed

Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):

breadandcircuses@climatejustice.social ("Bread and Circuses") wrote:

I like this quote:

“The problem is that electric cars are popular with politicians precisely because they provide an excuse to avoid doing harder things, like rebuilding our cities, or changing the habits of lifetimes. Persuading people to switch from their old gasoline car to a shiny Tesla is much easier than persuading them that they can live without a car. Hence governments are pushing electric cars, often with incentives that make no sense.” - Daniel Knowles, author of Carmageddon

Mastodon Feed

Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):

drj@typo.social ("David Jones") wrote:

In Python, the list syntax is [1, 2, 3]; in Oxford Python, the list syntax is [1, 2, and 3];

#Python

Mastodon Feed

Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):

dredmorbius@toot.cat ("Doc Edward Morbius ⭕​") wrote:

@drj

tired: Oxford
wired: 0xF04D
inspired: 0x4D

#TiredWiredInspired

Mastodon Feed

Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):

trabern@mas.to ("18 USC 241") wrote:

Live your life such that the only gripe about you with traction is your age

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

huh, this looks good.
trust me: doing a decent job of teaching design is *hard*

https://mastodon.social/@antlerboy/111063202580409123

Mastodon Feed

Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):

antlerboy ("Benjamin P. Taylor") wrote:

Design’s secret partner in research: Cybernetic practices for design research pedagogy – Sweeting and Sutherland (2023) https://stream.syscoi.com/2023/09/13/designs-secret-partner-in-research-cybernetic-practices-for-design-research-pedagogy-sweeting-and-sutherland-2023/

Mastodon Feed

Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):

racheltobac@infosec.exchange ("racheltobac :verified:") wrote:

Here’s how I used AI to clone a 60 Minutes correspondent’s voice to trick a colleague into handing over Sharyn's passport number. I cloned Sharyn’s voice then manipulated the caller ID to show Sharyn’s name on the caller ID with a spoofing tool.
The hack took 5 minutes total for me to steal the sensitive information.

So, how do we protect ourselves, our loved ones, and our organizations?
1. Make sure the people around you know that caller ID is easily faked (spoofed) and that voices can also be easily impersonated.
2. If they receive a dire call from “you”, verify it’s really you with another method of communication (text, DM, FT, call, etc) before taking an action (like sending money). Kind of like human MFA.

Some suggest setting up a secret “verification word” with their folks ones so that if someone impersonates & demands money/access etc you can ask for the verification word to see if it’s a real crisis. This won’t work for all people but could work for some. If it’s a match, use it.

In general, I recommend keeping advice simple: if premise of call is dire use a 2nd method of communication to confirm a person is in trouble before taking action (like wiring money or sensitive data). Rapid text, email, DM, have others message repeatedly — before wiring money.

Bottom line is:
Scammers use urgency & fear to convince victims to take actions (like sending money, data, etc).
If premise of a call, text, email, or DM is too dire (or too good to be true), that’s a likely scam.
Use a 2nd method of communication to check it’s real before taking action!

https://www.cbsnews.com/news/how-digital-theft-targets-people-from-millennials-to-seniors-60-minutes-2023-05-21/

Attachments:

Mastodon Feed

Gargron ("Eugen Rochko") wrote:

Figured this was worth getting on LP 🙂

#vinyl #nowplaying

Attachments:

Mastodon Feed

Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):

racheltobac@infosec.exchange ("racheltobac :verified:") wrote:

The MGM attackers claimed they used one of the easiest ways to breach/ransom a company, a method I use often in my hacking:
1. Look up who works at a org on LinkedIn
2. Call Help Desk (spoof phone number of person I’m impersonating)
3. Tell Help Desk I lost access to work account & help me get back in

While we wait for attack method confirmation, I’ll say that the attack method they claim worked for them does indeed work for me. Most orgs aren’t ready for phone based social engineering.

Most companies focus on email based threats in their technical tools and protocols — many are not yet equipped with the social engineering prevention protocols necessary to catch and stop a phone based attacker in the act. Teams need protocols to verify identity before taking action.

The 1st teams I go after when hacking are the folks who deal with requests from people constantly — IT, Help Desk, Customer Support, etc.
I often pretend to be an internal teammate to convince them to give me access, and I usually start with phone attacks bc they work fast.

Email phishing attacks can get caught in good spam filters and reported.
The soft spot for many teams are the folks who handle the phone call requests.
There’s a perfect storm: lack of verification protocols, easy spoofing, compensation tied to how fast they handle requests.

Questions to ask internally to see if your team is prepared to catch this attack:
- Do the folks who handle requests from team/customers use identity verification protocols?
- Do we rely on knowledge based authentication? DOB + caller ID matches ☎️ number in system, for example.
- Are our IT/Help Desk/Support teams compensated or promoted on the speed of saying yes to requests? Have we incentivized time for security protocols in Support?
- How do we verify identity first?

Remember, most folks at work want to do a good job and often times “good work” means “fast work”. We can’t expect every employee to be able to come up with their own identity verification protocols on the fly — it’s our job to provide the right human protocols to catch this fast.

We’ll need to wait to learn the details of the attack and get confirmation.
In the meantime, I can tell you I compromise orgs w/ the exact phone attack the attackers claim to use and many orgs don’t have phone call based identity protocols to catch it yet.

Update your phone based identity verification protocols to catch account takeover attempts!
You know your org best & there’s no one size fits all.
You can move from KBA (like DOB) to OTP on 2nd verified comm channel, call back to thwart spoof, service codes, pins, and much more.

After hacking & educating orgs on how they can catch me, the biggest task I spend my time on is updating verification protocols to spot me next time. It’s maddening to get caught on their new identity verification protocol on the next pentest but there’s also nothing I love more.
More details here: https://x.com/RachelTobac/status/1701801025940971792?s=20

Attachments:

Mastodon Feed

Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):

pts@octodon.social ("Paul Starr") wrote:

It’s simply false that the typical Mastodon user hasn’t heard of jokes. The typical Mastodon user has, in fact, been heavily involved in reverting inaccurate edits to the Wikipedia article on “Humour.”

Mastodon Feed

kornel ("Kornel") wrote:

Now that everyone is pissed at #Unity, #Godot is having a moment.

It's fascinating that #Epic saw that coming. The way to screw your #2 competitor is to help your #3 competitor:

https://godotengine.org/article/godot-engine-was-awarded-epic-megagrant/

Mastodon Feed

collinsworth@hachyderm.io ("Josh Collinsworth") wrote:

Several years ago, I had the idea to start a Vietnamese soup counter named "Pho Queue," and I honestly can't be sure any decision I've made ever since has been the correct one.

Mastodon Feed

Reblogged by slightlyoff@toot.cafe ("Alex Russell"):

dangillmor ("Dan Gillmor") wrote:

If Gov. Newsom signs this California right-to-repair legislation into law, it will be by far the biggest piece of good news in this arena so far. https://arstechnica.com/gadgets/2023/09/calif-passes-strongest-right-to-repair-bill-yet-requiring-7-years-of-parts/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social