My point is: you didn't get phished until you give away any info other than "someone received the email and clicked on the link"
Never heard of drive-by malware attacks? Malicious ads? Zero-click attacks? That link is Schrödinger’s zero-day ransomware attack, which may or may not exist. And there’s no way for you to know which it is, until after you’ve already clicked it. Sandboxing your browser is fine, but they weren’t testing to see if your browser would allow an attack to happen. They were testing to see if you would allow an attack to happen.
The actual method of attack (and any protections you have set up for your browser) is irrelevant, because they’re not testing to see if your browser is hardened. If they were going to do a software audit to see if browsers were vulnerable, you probably wouldn’t ever even hear about it. Because IT would handle it directly, via the access they already have to your company computer.
Tricking you into disclosing sensitive info is only one specific type of attack. The phishing link isn’t checking to see if you’d give info away. If they were testing that, they could do it in other ways, like a fake email from your manager asking for the info. No need to click a link to fail that test. But with the phishing link, you fail the test when you click it because it ultimately doesn’t matter what loads after you click the link. That link exists in a quantum state where every single piece of malware that ever did/will exist can load as soon as you click it.
I got tricked by a phishing test once, because I had raised a ticket with IT about an unrelated issue. They sent me a fucking phishing test link that looked like it came from IT Help Desk, while I was on the phone with the IT Help Desk person that I had called. Like I literally initiated every single communication, so it’s not like a “hey this is {fake IT} calling and I need you to install this exe for me” cold call that happened to get lucky.
The Help Desk tech was like “okay I’m sending you a link to {program installer}, then once it’s downloaded I can remote into your laptop and install it with admin rights.” The “hey we need you to click this link” phishing email from {Fake IT Help Desk} chose that exact moment to hit my inbox. Again, I had called IT, using an internal company phone system, using a direct phone extension that I had looked up in our internal company directory. So it’s not like there was any reason for me to distrust the tech or suspect that he was actually a phisher. The actual email with the real link arrived like a minute after I had already failed the test.
Even the Help Desk tech was like “okay, that’s actually the first time I’ve ever heard of someone failing a phishing test while actively talking to IT… Did they really send that at the same time I said I was sending my email?? Bro you got swindled… At least the training videos will give you a chance to eat lunch at your desk?”
This is only really possible with modern game engines though. Older games were often using code that was written specifically for that game. So simply disabling the cheat codes could likely break things elsewhere in the game. But modern game engines that were written with those testing tools in mind are able to safely disable the cheats before release without breaking the rest of the game.
You shouldn’t even have Jellyfin on a reverse proxy, because it shouldn’t be externally available. There are several known security vulnerabilities (all marked as “closed” due to inactivity on git) that the devs have said will likely never be patched. Because patching them requires breaking away from the Emby fork that the entire project is built on.
It should only be externally available via a private VPN. And that alone excludes a lot of “I want to share my library with friends/family” scenarios, because step 0 will be getting their devices connected to your VPN.
At the very least, set up some form of access control/username+PW directly on your reverse proxy as a secondary security measure. Because if you can reach the JF landing page, you can exploit those vulnerabilities without needing a valid JF login. So you should configure your reverse proxy to act as a gatekeeper, and ensure attackers can’t even reach JF at all without having a valid login to your reverse proxy. But this will break most JF apps (except for browsers) because they likely won’t have any way to give an initial user+pass to the reverse proxy before they hit the JF server.
I mean, in terms of raw capability, it’s actually one of the better “turn a dumb TV into a smart TV” devices on the market. It has good hardware transcoding support to take the burden off of your server. It also has very little in the way of fluff. It was one of the few boxes that wasn’t packed full of ads by default (though I’m not sure if this is still true).
But yeah, it means you’re locked into Apple’s ecosystem. Which is… Not always the best. Apple is notoriously difficult/annoying if your app gets tied up in approvals, so native apps can sometimes be trapped in limbo for a while. And that’s assuming they even allow the native app.
I guess you could build an HTPC with similar functionality and hardware support, but then you’ll be stuck using a Bluetooth keyboard to navigate things, plus all of the “oh let me wait for my computer to boot up before I can watch anything” pains that go along with it. There are solutions for a lot of the complaints, but a lot of them are fiddly or require lots of extra stuff just to achieve the same basic functionality of “remote has power button that turns on TV and streaming box, and navigates menus as if it’s a native app.”
I mean, that’s true regardless of how it is running. If the service is externally available, it will be probed for vulnerabilities. At least with a container, you can ward off what files it has access to, so an attacker can’t just ransomware your entire NAS with a single vulnerable service.
I mean, the Black Panthers started because people realized that peaceful unarmed protests would be violently busted, but peaceful heavily armed protests were politely watched from across the street. Blindfiring into crowds is a lot less appealing for cops when the entire crowd can return fire.
Forums are great for being forums. Real-time instant messaging, voice chat, video chat, and screen sharing are all a very different use-case. They’re two entirely separate products, and comparing them is apples and oranges. People are looking to replace Discord with Discord-like services, because forums don’t fucking do what Discord does.
The big problem (and the reason everyone seems to compare the two) is that Discord started eating forums, as companies realized it was easier to create a Discord server instead of creating (and hosting, and maintaining) a support forum. And that’s a perfectly valid complaint. But that doesn’t mean forums are a valid replacement for Discord.
Getting old is mandatory, but falling behind isn’t. My mom is pushing 70, and installed Linux Mint on her laptop last week by herself because Windows was nagging her to upgrade to 11 but her laptop didn’t have the damned Secure Boot chip. She asked me about it like two weeks ago, and I mentioned that I could help her through it once I had some time. Then a week later, she called to say she had already researched it herself and installed Linux instead of waiting on me. When I got a VR headset, she was the first in line to try it out. When I started experimenting with 3D printing, she started trying to find ways to integrate prints into her daily life instead of buying things. I set up a Home Assistant for her to be able to automate her lights.
She understands that tech is iterative, and that learning concepts is better than learning hard processes. Because processes will change from one system to the next, but concepts will largely remain the same. One microwave may have a different method to input 90 seconds, (dial to 1.5 mins, push buttons to input 90, Quick Minute button + 30 Second button, etc), but the concept of “open door, put food inside, select time” to warm something up remains the same. The actual “select time” concept isn’t a single specific process, because different microwaves will have different face panels with different ways to interact with the appliance. But all of them will allow for the same end result of running the microwave for 90 seconds.
Contrast that with my dad, who struggles to find his phone’s Settings app. He treats tech as hard processes. To stretch the same microwave example, he’s the type of person to throw up his hands in defeat and go “this is just too hard for me” the first time he encounters a microwave that has the numbers at the top of the panel instead of the bottom. Because in his mind, the concept doesn’t really exist; he just knows a “if I touch this specific area, I get {x} result” process. So as soon as anything about the process changes, it’s like he has to start re-learning things from scratch.
To bring it back to computers, he’s the type to panic when his browser’s desktop icon gets moved across the screen, because now he can’t check his email. His browser is still accessible, and if he understood the concept of a desktop icon, he would be able to intuit “oh hey it moved but it’s still there. I can probably still use it the same, and/or move it back to where I prefer having it.” But instead, his entire workflow grinds to a halt. Because he doesn’t understand the concept behind how a desktop icon works. He just knows “the specific button in the specific place is different, therefore the entire process is broken.”
Which is ironic, because you’re statistically most likely to roll over your own child. Kids are dumb and will do things like run in front of your vehicle as you’re pulling out of the driveway. And if you’re driving one of those massive trucks with gigantic blind spots, you won’t see them.
It’s sort of like having a pool. Statistically, someone from your household (like your kid) is the most likely person to drown in your pool. Simply because kids are fucking stupid and they’ll inevitably spend a lot of time around it.
Unfortunately not. Japan has been very far-right (bordering on jingoistic) for a long time now. The country’s external facade is all cute anime characters and zany fashion… But that was an intentional rebrand (heavily subsidized by the country’s propaganda department) in the wake of WW2 to distance itself from the atrocities they had committed. But internally, the country has remained extremely hardline conservative and xenophobic. And it has only shifted farther right with recent elections.
I’ve seen child eating speculation, largely because child fucking is the current threshold. Like Trump is fighting for his life to only be called a child fucker. So what is so bad that he’s trying to keep buried? Eating kids was mentioned a few times in the files already, so people have started speculating that Trump was involved in that.
I remember seeing a pretty convincing “pro wrestling is just drag for people who are afraid of cross-dressers” argument, but I can’t remember the finer points.
Yeah, my complaints about Apple all stem from the fact that my industry has a standard program that only runs on Macs… And every Mac I’ve used has inevitably ended up taking 4x as long to do basically anything else when compared to Windows or Linux. The only reason I ever use a Mac is because my job requires it, and even then it is only begrudgingly; if there was a way to run the program on anything else, I would have done so a long time ago.
And yeah, I agree 100% about the “different first, better second” design choices. Lots of the most frustrating things about Macs are due to intentional design choices that Apple makes. Not because it is better for the user, but simply because it is different.
I mean, it took starvation for them to start burning shit the first time. But at least they learned from that, and haven’t let it get as bad since then.
This is simply Americans’ first time experiencing the wrong side of the “let them eat cake” thing, so of course it’ll take a long time for America to start lighting things on fire.
America may be constantly battling racism and xenophobia internally, but we recognize it for what it is: a shit behavior that should should be excised. European and Eastern cultures like Japan are so casually racist and xenophobic that they don't even recognize it in themselves.
The best way I’ve heard it described is that Americans consider racism something you do, while the rest of the world tends to view it as something you are.
To an American, if someone is a racist, it’s because they do racist things. So Americans are actually fairly good at recognizing and excising casual racism, because they recognize it as a behavior they can change. But this also means Americans are fairly quick to judge individual actions as racist, because they see it as something that should be improved upon in the future. To an American, a racist is racist because they have recognized their own racist behaviors and don’t see them as a problem.
Meanwhile, Europeans and Asians tend to think of racism as something you are. And that’s a big difference, because it makes them much less adept at identifying the more casual forms of racism. Because even if they’re casually racist, they’ll simply tell themselves “well I’m not a racist, therefore my actions weren’t racist.” Since that binary “is/is not a racist” flag hasn’t flipped in their brain, they’re able to tell themselves that their individual actions aren’t racist.
It’s like Europeans need to be at least 51% racist in order to be considered racist, so anything below that amount is excusable. Individual people will obviously have different thresholds for when that Boolean bit gets flipped from “not racist” to “racist”, but it still needs to hit that personal threshold before they’ll start calling out racism. And europeans will tend to judge their own actions much more leniently, like a zealot telling themselves that God is on their side so their bad deeds aren’t really bad.
But that causes interesting culture shocks whenever Americans interact with Europeans or Asians. Europeans are quick to jump on the “all Americans are racist” bandwagon, and the American will tend to nod along and agree because they recognize that everyone has the potential to be racist. Then the American will see the Europeans do/say some vile racist shit, and start to call it out. But then the European gets defensive and adamantly states that they’re not a racist… Because the European takes the “hey that was pretty fucked up and racist, don’tcha think” as a personal “you are a racist” attack, instead of a “that individual action was racist, and you should examine why you did it” behavioral check.
And the American will be confused on why the European immediately jumped all the way to “why are you calling me a racist? I’m not racist” argument. Because in their experience, the only people who immediately jump to that are the full blown reich-wing racists who don’t see their own racist actions as a problem, but want to continue existing in a civilized society. Labeling someone as a racist is a big deal for an American, because it means the person has refused to examine their own racist behaviors, or has done so and sees no problem with the racism. To an American, labeling someone a racist is basically the nuclear “I’ve exhausted all other possibilities, and can only conclude that they’re doing it on purpose” option.
So Americans will often walk away from the interactions thinking “holy fuck those Europeans were really goddamned racist” simply because the Europeans refused to acknowledge that their own individual actions had the potential to be racist. Meanwhile, the Europeans will think that Americans are really fucking racist because Americans are quick to call it out amongst themselves.
Never heard of drive-by malware attacks? Malicious ads? Zero-click attacks? That link is Schrödinger’s zero-day ransomware attack, which may or may not exist. And there’s no way for you to know which it is, until after you’ve already clicked it. Sandboxing your browser is fine, but they weren’t testing to see if your browser would allow an attack to happen. They were testing to see if you would allow an attack to happen.
The actual method of attack (and any protections you have set up for your browser) is irrelevant, because they’re not testing to see if your browser is hardened. If they were going to do a software audit to see if browsers were vulnerable, you probably wouldn’t ever even hear about it. Because IT would handle it directly, via the access they already have to your company computer.
Tricking you into disclosing sensitive info is only one specific type of attack. The phishing link isn’t checking to see if you’d give info away. If they were testing that, they could do it in other ways, like a fake email from your manager asking for the info. No need to click a link to fail that test. But with the phishing link, you fail the test when you click it because it ultimately doesn’t matter what loads after you click the link. That link exists in a quantum state where every single piece of malware that ever did/will exist can load as soon as you click it.
I got tricked by a phishing test once, because I had raised a ticket with IT about an unrelated issue. They sent me a fucking phishing test link that looked like it came from IT Help Desk, while I was on the phone with the IT Help Desk person that I had called. Like I literally initiated every single communication, so it’s not like a “hey this is {fake IT} calling and I need you to install this exe for me” cold call that happened to get lucky.
The Help Desk tech was like “okay I’m sending you a link to {program installer}, then once it’s downloaded I can remote into your laptop and install it with admin rights.” The “hey we need you to click this link” phishing email from {Fake IT Help Desk} chose that exact moment to hit my inbox. Again, I had called IT, using an internal company phone system, using a direct phone extension that I had looked up in our internal company directory. So it’s not like there was any reason for me to distrust the tech or suspect that he was actually a phisher. The actual email with the real link arrived like a minute after I had already failed the test.
Even the Help Desk tech was like “okay, that’s actually the first time I’ve ever heard of someone failing a phishing test while actively talking to IT… Did they really send that at the same time I said I was sending my email?? Bro you got swindled… At least the training videos will give you a chance to eat lunch at your desk?”
The email is a phishing test, and clicking the link automatically enrolls you in mandatory rudimentary cybersecurity awareness training.
This is only really possible with modern game engines though. Older games were often using code that was written specifically for that game. So simply disabling the cheat codes could likely break things elsewhere in the game. But modern game engines that were written with those testing tools in mind are able to safely disable the cheats before release without breaking the rest of the game.
You shouldn’t even have Jellyfin on a reverse proxy, because it shouldn’t be externally available. There are several known security vulnerabilities (all marked as “closed” due to inactivity on git) that the devs have said will likely never be patched. Because patching them requires breaking away from the Emby fork that the entire project is built on.
It should only be externally available via a private VPN. And that alone excludes a lot of “I want to share my library with friends/family” scenarios, because step 0 will be getting their devices connected to your VPN.
At the very least, set up some form of access control/username+PW directly on your reverse proxy as a secondary security measure. Because if you can reach the JF landing page, you can exploit those vulnerabilities without needing a valid JF login. So you should configure your reverse proxy to act as a gatekeeper, and ensure attackers can’t even reach JF at all without having a valid login to your reverse proxy. But this will break most JF apps (except for browsers) because they likely won’t have any way to give an initial user+pass to the reverse proxy before they hit the JF server.
I mean, in terms of raw capability, it’s actually one of the better “turn a dumb TV into a smart TV” devices on the market. It has good hardware transcoding support to take the burden off of your server. It also has very little in the way of fluff. It was one of the few boxes that wasn’t packed full of ads by default (though I’m not sure if this is still true).
But yeah, it means you’re locked into Apple’s ecosystem. Which is… Not always the best. Apple is notoriously difficult/annoying if your app gets tied up in approvals, so native apps can sometimes be trapped in limbo for a while. And that’s assuming they even allow the native app.
I guess you could build an HTPC with similar functionality and hardware support, but then you’ll be stuck using a Bluetooth keyboard to navigate things, plus all of the “oh let me wait for my computer to boot up before I can watch anything” pains that go along with it. There are solutions for a lot of the complaints, but a lot of them are fiddly or require lots of extra stuff just to achieve the same basic functionality of “remote has power button that turns on TV and streaming box, and navigates menus as if it’s a native app.”
I mean, that’s true regardless of how it is running. If the service is externally available, it will be probed for vulnerabilities. At least with a container, you can ward off what files it has access to, so an attacker can’t just ransomware your entire NAS with a single vulnerable service.
Read the rest of my comment.
I mean, the Black Panthers started because people realized that peaceful unarmed protests would be violently busted, but peaceful heavily armed protests were politely watched from across the street. Blindfiring into crowds is a lot less appealing for cops when the entire crowd can return fire.
Forums are great for being forums. Real-time instant messaging, voice chat, video chat, and screen sharing are all a very different use-case. They’re two entirely separate products, and comparing them is apples and oranges. People are looking to replace Discord with Discord-like services, because forums don’t fucking do what Discord does.
The big problem (and the reason everyone seems to compare the two) is that Discord started eating forums, as companies realized it was easier to create a Discord server instead of creating (and hosting, and maintaining) a support forum. And that’s a perfectly valid complaint. But that doesn’t mean forums are a valid replacement for Discord.
Getting old is mandatory, but falling behind isn’t. My mom is pushing 70, and installed Linux Mint on her laptop last week by herself because Windows was nagging her to upgrade to 11 but her laptop didn’t have the damned Secure Boot chip. She asked me about it like two weeks ago, and I mentioned that I could help her through it once I had some time. Then a week later, she called to say she had already researched it herself and installed Linux instead of waiting on me. When I got a VR headset, she was the first in line to try it out. When I started experimenting with 3D printing, she started trying to find ways to integrate prints into her daily life instead of buying things. I set up a Home Assistant for her to be able to automate her lights.
She understands that tech is iterative, and that learning concepts is better than learning hard processes. Because processes will change from one system to the next, but concepts will largely remain the same. One microwave may have a different method to input 90 seconds, (dial to 1.5 mins, push buttons to input 90, Quick Minute button + 30 Second button, etc), but the concept of “open door, put food inside, select time” to warm something up remains the same. The actual “select time” concept isn’t a single specific process, because different microwaves will have different face panels with different ways to interact with the appliance. But all of them will allow for the same end result of running the microwave for 90 seconds.
Contrast that with my dad, who struggles to find his phone’s Settings app. He treats tech as hard processes. To stretch the same microwave example, he’s the type of person to throw up his hands in defeat and go “this is just too hard for me” the first time he encounters a microwave that has the numbers at the top of the panel instead of the bottom. Because in his mind, the concept doesn’t really exist; he just knows a “if I touch this specific area, I get {x} result” process. So as soon as anything about the process changes, it’s like he has to start re-learning things from scratch.
To bring it back to computers, he’s the type to panic when his browser’s desktop icon gets moved across the screen, because now he can’t check his email. His browser is still accessible, and if he understood the concept of a desktop icon, he would be able to intuit “oh hey it moved but it’s still there. I can probably still use it the same, and/or move it back to where I prefer having it.” But instead, his entire workflow grinds to a halt. Because he doesn’t understand the concept behind how a desktop icon works. He just knows “the specific button in the specific place is different, therefore the entire process is broken.”
Which is ironic, because you’re statistically most likely to roll over your own child. Kids are dumb and will do things like run in front of your vehicle as you’re pulling out of the driveway. And if you’re driving one of those massive trucks with gigantic blind spots, you won’t see them.
It’s sort of like having a pool. Statistically, someone from your household (like your kid) is the most likely person to drown in your pool. Simply because kids are fucking stupid and they’ll inevitably spend a lot of time around it.
He always looks like someone is slowly but steadily sliding hardboiled eggs into his ass, and he’s trying not to react.
Steam’s business model of “do nothing and watch every single competitor repeatedly shoot their own feet” seems to work really well.
Unfortunately not. Japan has been very far-right (bordering on jingoistic) for a long time now. The country’s external facade is all cute anime characters and zany fashion… But that was an intentional rebrand (heavily subsidized by the country’s propaganda department) in the wake of WW2 to distance itself from the atrocities they had committed. But internally, the country has remained extremely hardline conservative and xenophobic. And it has only shifted farther right with recent elections.
I’ve seen child eating speculation, largely because child fucking is the current threshold. Like Trump is fighting for his life to only be called a child fucker. So what is so bad that he’s trying to keep buried? Eating kids was mentioned a few times in the files already, so people have started speculating that Trump was involved in that.
I remember seeing a pretty convincing “pro wrestling is just drag for people who are afraid of cross-dressers” argument, but I can’t remember the finer points.
Yeah, my complaints about Apple all stem from the fact that my industry has a standard program that only runs on Macs… And every Mac I’ve used has inevitably ended up taking 4x as long to do basically anything else when compared to Windows or Linux. The only reason I ever use a Mac is because my job requires it, and even then it is only begrudgingly; if there was a way to run the program on anything else, I would have done so a long time ago.
And yeah, I agree 100% about the “different first, better second” design choices. Lots of the most frustrating things about Macs are due to intentional design choices that Apple makes. Not because it is better for the user, but simply because it is different.
I mean, it took starvation for them to start burning shit the first time. But at least they learned from that, and haven’t let it get as bad since then.
This is simply Americans’ first time experiencing the wrong side of the “let them eat cake” thing, so of course it’ll take a long time for America to start lighting things on fire.
The best way I’ve heard it described is that Americans consider racism something you do, while the rest of the world tends to view it as something you are.
To an American, if someone is a racist, it’s because they do racist things. So Americans are actually fairly good at recognizing and excising casual racism, because they recognize it as a behavior they can change. But this also means Americans are fairly quick to judge individual actions as racist, because they see it as something that should be improved upon in the future. To an American, a racist is racist because they have recognized their own racist behaviors and don’t see them as a problem.
Meanwhile, Europeans and Asians tend to think of racism as something you are. And that’s a big difference, because it makes them much less adept at identifying the more casual forms of racism. Because even if they’re casually racist, they’ll simply tell themselves “well I’m not a racist, therefore my actions weren’t racist.” Since that binary “is/is not a racist” flag hasn’t flipped in their brain, they’re able to tell themselves that their individual actions aren’t racist.
It’s like Europeans need to be at least 51% racist in order to be considered racist, so anything below that amount is excusable. Individual people will obviously have different thresholds for when that Boolean bit gets flipped from “not racist” to “racist”, but it still needs to hit that personal threshold before they’ll start calling out racism. And europeans will tend to judge their own actions much more leniently, like a zealot telling themselves that God is on their side so their bad deeds aren’t really bad.
But that causes interesting culture shocks whenever Americans interact with Europeans or Asians. Europeans are quick to jump on the “all Americans are racist” bandwagon, and the American will tend to nod along and agree because they recognize that everyone has the potential to be racist. Then the American will see the Europeans do/say some vile racist shit, and start to call it out. But then the European gets defensive and adamantly states that they’re not a racist… Because the European takes the “hey that was pretty fucked up and racist, don’tcha think” as a personal “you are a racist” attack, instead of a “that individual action was racist, and you should examine why you did it” behavioral check.
And the American will be confused on why the European immediately jumped all the way to “why are you calling me a racist? I’m not racist” argument. Because in their experience, the only people who immediately jump to that are the full blown reich-wing racists who don’t see their own racist actions as a problem, but want to continue existing in a civilized society. Labeling someone as a racist is a big deal for an American, because it means the person has refused to examine their own racist behaviors, or has done so and sees no problem with the racism. To an American, labeling someone a racist is basically the nuclear “I’ve exhausted all other possibilities, and can only conclude that they’re doing it on purpose” option.
So Americans will often walk away from the interactions thinking “holy fuck those Europeans were really goddamned racist” simply because the Europeans refused to acknowledge that their own individual actions had the potential to be racist. Meanwhile, the Europeans will think that Americans are really fucking racist because Americans are quick to call it out amongst themselves.