new_otters_raft

joined 6 months ago
[–] new_otters_raft@piefed.ca 3 points 16 hours ago* (last edited 16 hours ago)

I went through a similar line of thinking when deciding whether to post this. I'm hoping this last bit is true for anyone that is affected by this, maybe it can be an off-ramp towards finding more positive sources of happiness:

Some people, she says, are realizing through these sites that their shopping habits aren’t serving them — and are looking for ways to consume less and make more intentional choices.

 

cgLhGbpiqgUZqRa.avif

FoodNeverComes is one of a growing number of fake online shopping sites where users can place a pretend food order. (CBC)

Rhia Catapano, an assistant professor at the University of Toronto who studies consumer behaviour and psychology, says online shopping simulators can activate “the same parts of our brain that doing the actual activity would.”

That's particularly appealing for budget-conscious young people.

“Like playing a video game or dreaming about a vacation that you're never actually going to take, we can imagine a thing,” she said. “In some way, it gives us some of the same psychological benefits.”

The sudden popularity of these sites, says Catapano, shows just how deeply consumerism has become integrated into our everyday lives, with people willing to spend time and effort browsing and “shopping” even when they know nothing will ever arrive.

But she sees a glimmer of resistance, too.

Some people, she says, are realizing through these sites that their shopping habits aren’t serving them — and are looking for ways to consume less and make more intentional choices.

“They recognize that what they're doing is not good for them, so they're trying to make changes.”

 

As journalists are shut out of conflict zones, investigators are using satellite imagery, social media and 3D modelling to document atrocities. But evidence alone cannot deliver accountability.

 

The article is long but comprehensive, please see if for the full discussion.

Agencies tout very high success rates, but some experts compare it to “crime control theatre”

On Sunday, March 22 of this year, a large swath of the population in Quebec was woken up at 4:25 a.m. as cellphones lit up and screamed. An Amber alert had been broadcast. Less than four hours later, the two missing children were thankfully found, unharmed, and the alert was cancelled.

Amber alerts cast wide nets in an effort to find abducted children and teenagers, but each time one is transmitted in Canada, we go through a predictable cycle. Many complain that these alerts cannot be turned off or muted, even in sleep mode, and that waking people up in the middle of the night to help them find a specific car that was last spotted 200 kilometres away is unnecessarily disruptive—with some even calling 911 to complain. Meanwhile, law enforcement officials remind us through the media that these alerts are only used when necessary and that they save lives.

Any subject tied to the safety of children is bound to evoke the deepest emotions. In fact, the crime that led to the creation of Amber alerts—and to their name—was monstrous enough that it’s no wonder it rallied influential people into building a system that could potentially prevent this kind of crime.

But warranted emotions aside, do Amber alerts even work? What little data we do have point to a system that has likely been oversold to us.

 

TLDR on the history side of the article

In 1804, a French weaver named Joseph-Marie Jacquard patented a loom that could weave intricate patterns using punch cards — paper cards with encoded holes.

Once they pass through the loom, the presence or absence of a hole tells the loom which warp thread to raise or lower, acting as the earliest form of binary code programming. Weaving that once required a master weaver and an assistant could now be done by craft hobbyists.

 

This feels like bad design

Smart pet-feeder company Petlibro suffered an outage on Tuesday, giving users a harsh reminder of the risks of relying on smart devices.

Petlibro makes pet feeders that connect to Wi-Fi and, for setup with Petlibro’s mobile companion app, Bluetooth. Users can set the feeders to automatically dispense food at scheduled times, which is handy for pet care when the owner is out of the home.

In a statement to The Verge, Petlibro CEO York Wu said this week’s outage was “related to how the Petlibro app communicates with devices through its online servers.”

Some user reports have also conflicted with Petlibro’s claims about offline functionality. As The Verge pointed out, various users online claimed that during the outage, their devices did not perform any scheduled feedings, performed some feedings but not others, or performed feedings late (examples here, here, here, here, and here).

 

Terabytes worth of credentials, many belonging to the world's biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines A- driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AlI provider keys that could allow attackers to gain access to more than 2,500 organizations.

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

[–] new_otters_raft@piefed.ca 0 points 2 weeks ago

That's my bad for writing it poorly. I meant to say that about the premise of not needing internet, since someone who has internet on both devices might have better ways to transfer the files.

Someone would need to plan ahead and install the PWA (or some compatible tool) in order for this to work

[–] new_otters_raft@piefed.ca 7 points 2 weeks ago* (last edited 2 weeks ago) (3 children)

I wouldn't use this day to day, but what I found cool was:

  • it doesn't require cables or any additional equipment (including routers, cell towers)
  • it can't be detected by anything, assuming you toss a blanket over the transfer

The downside is that if you wanted to get it truly offline, you would need to have ~~the~~ an app installed on both devices ahead of time, if I understood it correctly. (Edit: bolded bits are new)

It did lead to some fun discussion in this thread :)

 

I'm not sure when I'd use this, but its a neat concept

Decimen is an open-source web app that moves files between devices through an animated QR stream, requiring no direct network connection, pairing, account, or native app.

 

CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency