Tumgik
#What about the people who have no credit card
melyzard · 3 days
Text
Okay, look, they talk to a Google rep in some of the video clips, but I give it a pass because this FREE course is a good baseline for personal internet safety that so many people just do not seem to have anymore. It's done in short video clip and article format (the videos average about a minute and a half). This is some super basic stuff like "What is PII and why you shouldn't put it on your twitter" and "what is a phishing scam?" Or "what is the difference between HTTP and HTTPS and why do you care?"
It's worrying to me how many people I meet or see online who just do not know even these absolute basic things, who are at constant risk of being scammed or hacked and losing everything. People who barely know how to turn their own computers on because corporations have made everything a proprietary app or exclusive hardware option that you must pay constant fees just to use. Especially young, somewhat isolated people who have never known a different world and don't realize they are being conditioned to be metaphorical prey animals in the digital landscape.
Anyway, this isn't the best internet safety course but it's free and easy to access. Gotta start somewhere.
Here's another short, easy, free online course about personal cyber security (GCFGlobal.org Introduction to Internet Safety)
Bonus videos:
youtube
(Jul 13, 2023, runtime 15:29)
"He didn't have anything to hide, he didn't do anything wrong, anything illegal, and yet he was still punished."
youtube
(Apr 20, 2023; runtime 9:24 minutes)
"At least 60% use their name or date of birth as a password, and that's something you should never do."
youtube
(March 4, 2020, runtime 11:18 minutes)
"Crossing the road safely is a basic life skill that every parent teaches their kids. I believe that cyber skills are the 21st century equivalent of road safety in the 20th century."
140 notes · View notes
goldkirk · 4 months
Text
I'm so proud of myself about finances in the past couple months. I still struggle with money but I did enough meditation and journaling and practicing about it to make myself able to actually face my loans and credit cards and savings and bills and start really truly organizing and addressing them for the first time in years instead of just flying by the seat of my pants.
Like. This is a huge deal for me. I've felt like I'm in deadly danger every time I've tried to think about money for years and years. I'm finally able to look it in the face and stare it down and start to organize and plan on purpose instead of just keeping up with the minimum to stay afloat. I'm so proud of myself.
It's still a refrain of "GUILT (funny link)" every time I think about money but I'm able to actually make spreadsheets and face the numbers and monthly tracking again, and even make a new full budget which I haven't been able to do in ages.
still feel guilt, overwhelm, and helplessness, but no longer feel as much deep elemental shame and terror. that's progress baby
#we don't need to talk about how many months and months of therapy visits and doctor appointments I put on credit cards#among other things#but I had to put my foot down about it a couple months ago and shout at myself a little saying HEY#I AM SHAKING YOU BY THE SHOULDERS I AM SHOUTING FOR YOU TO HEAR#OF COURSE IT WAS A TERRIBLE FINANCIAL DECISION BUT YOU WEREN'T EVEN EXPECTING TO BE ALIVE#THE CREDIT CARD DEBT WAS NECESSARY TO KEEP YOU ALIVE AND IT DID AND EVERYTHING ELSE IS WAY LESS IMPORTANT THAN THAT#why the FUCK are you feeling SO ASHAMED for making the best decision you knew how to make at the time???#just because you know NOW that you could have tried some other options doesn't mean you did THEN#you may have known enough to feel shame and guilt yes but you would never in a million years have gotten the help you needed fast enough#by attempting to go another route#you didn't trust anyone besides a very few handfuls of people and even them it wasn't fully#and the stress of running it through parental insurance was so terrifying to you bc you didn't know what that would do#and you never had cosigners for anything your whole adult life. it's OKAY#you fucking DID YOUR BEST#YOU HAVE LEARNED. YOU HAVE MADE CHANGES. YOU HAVE ALREADY DONE BETTER#YOU WILL CONTINUE TO LEARN AND IMPROVE OVER TIME#it is not the end of the world. even the utilities sending you to debt collections etc etc#YOU ARE FIGURING IT OUT ONE PIECE AT A TIME#MORE PEOPLE ARE ASHAMED AND AFRAID OF THEIR OWN FINANCES THAN YOU THINK#if the people who fought and argued with and shamed you for considering student loans much less taking them out#had wanted you to actually be financially safer and healthier#they could have just fucking helped out or cosigned your loans or actively helped you find other solutions#instead of spending months and months telling you it was the worst decision ever and would ruin you financially for decades and such#you made the best decisions you could with the level of terror and knowledge that you had. it was enough to keep you alive.#isn't that enough?#isn't it a victory to survive?? isn't that enough??????#god i'm cringing at sharing this but if it's been this hard for me surely at LEAST one of you has also made financial mistakes or regrets#and seeing me be honest that I fucked it all up too and it's a mess and I'm just climbing back through it as best as I can as I go#will hopefully make at least one of you feel a tiny bit less alone
37 notes · View notes
resident-gay-bitch · 7 months
Text
little rich boy sirius who gets disowned and can barely survive without his expensive brands and the basic human need to eat at least once a day meeting the entirely too generous james potter who just falls for the vanity and sincerity of the reformed rich boy and decides that once sirius stops caring about brands and status and rich boy things and just cares about what matters in life he decides to spoil his boyfriend to pieces because he’s secretly sitting on a fucking fortune
#idk i just think it’s funny#like james would find sirius when he’s struggling with money because he’s so bad at saving and prioritising his spendings because he’s never#had too before and so james would teach him how to do all that stuff and emotionally support sirius through it all and sirius just falls in#love with this beautiful guy who’s just so generous and who teaches him so many things and finds value in kindness and sincerity and#compassion and all that jazz and james falls in love with sirius helplessly because he might be stuck up and vein and kind of selfish and#is stuck up and cares all too much about status but he’s trying so hard to be better and he finds empathy because sirius got kicked out for#the worst reasons because he’s always been the black sheep of his highly cultist christian family or whatver and he’s also outwardly queer#and james decides that he wants to give sirius everything and loves the way he looks in expensive makeup and designer faux fur coats and#heels and divine jewellery and all that jazz but makes sirius sell it all and learn what it means to be human and not rely on money and#status and brands and stuff and sirius learns what it’s like to be decent and in touch with humanity and only then does james take sirius on#a surprise luxury holiday for his birthday or something and then just buys him thousands of dollars worth of all these glamorous looking#things and sirius is like omg what the fuck jamie and then he just becomes sirius’ sugar daddy because he can’t help himself but they’re#also in love and much better people because of it and when sirius buys things now it’s not because of brands or because they have big price#tags like he used too. he now buys things with james’ credit card he keeps in his own wallet because he thinks he’ll feel pretty in them or#because he thinks james will loose it if he sees sirius walking around in it or if he sees a really cute toaster that sends him into a#frenzy that has him spending all way too much on an impromptu kitchen renovation but james doesn’t care because as long as his boyfriend is#happy and actually paying attention to the price of things and calculating the best value and taking james’ opinion as well and just being#happy and safe and accepted in his new home and family here with his jamie#please i think they’d be so cute ugh!!!#prongsfoot#bambibelle#drabble#fic idea#marauders#james potter#sirius black#jay talks
56 notes · View notes
friendrat · 8 months
Text
But I don't wanna live in a dystopian world!!!
#i just saw this video about amazon having this pay with your palm technology#guys why would you give away your biometric data for convenience?!?!#we're really at this point where we will sell our privacy to save 30 seconds#and i know people have been saying this for forever#but what happens when that becomes the only way to pay?#like we are getting so close to what they describe in revelations it's scary#and yeah i get that people said that about barcodes and credit cards#but having your payment method be your literal hand?#that's too close for comfort#and it's literally not smart to give these companies that info#if they have a data breach who knows what a hacker can do with that?#i know this is a crazy scenario but what if a hacker gets ahold of your fingerprints and currupts the digital record for a crime?#on top of that you only need your fingerprints registered with the police for a few reasons like if you are a criminal or work with kids#you have the right to not have the government have your info without reason#but what happens when the government demands that Amazon (or Apple or any other company pulling this crap) give over their records?#now they have that whether you are a criminal or gave your permission or not#that would be a violation of your 4th amendment rights: to be secure in your person houses papers and effects against unreasonable seizures#don't think the government would do that? police in my area will absolutely violate that right by running plates#to see if you have an expired registration even if you weren't doing anything that required they run your plates#so yeah i fully believe the government would violate the 4th amendment#and what's more... i don't even think that they would have to demand the info i think amazon or apple would offer to sell that info to them#ok sorry for the rant#this world is just getting scary y'all
8 notes · View notes
bugbuoyx · 2 months
Text
going through some tags and seeing the most insane shit. people will literally believe anything about anyone with literally no proof, no screenshots no links, as long as its the negative hot topic.
"x is a zionist" x is a jewish person who has literally called for palestine to be free.
"x is a pedophile" x is a trans woman and a minor
"x sexually harasses people" x is a nb transfem sex worker but like you were very nice so i believe you i wont even check their account ill just block them thank you so much!!
"x has a detrans rape kink" x is a transmasc sex worker whos private account and dialogue with a transfem client were leaked but like youre so fuckin g right ill block them right now
like are you serious??? these are actual posts i have seen. transphobes have literally admitted to sending asks like this to divide the trans community. all this talk about how separating a trans person from their community can kill them and yall still fall for obvious bullshit. it is NOT that hard to do your own research. go to the mentioned blog. hit the fucking search icon. and type in words. look up their name, are there any reciepts for this or simply alot of *anonymous* asks proclaiming the evil nature of this trans person. and even if there are "receipts" look at them. can you find the post in question? look at the account posting it, are they trans? how old is their account? what kind of discussions do they engage in, might they have a bias against this person? it is incredibly easy to not only doctor screenshots, but to crop them in order to erase nuance or even present something they were using as an example (as i did above) as evidence of this persons "beliefs"
tldr if you believe anonymous messages please dm me your bank account information i promise im just gonna send you money ❤️
3 notes · View notes
bl00dw1tch · 4 months
Text
Ive been having lots of talks lately with my mom abt politics n the state of the world, Good conversations to be sure, and theyre great bc we both make good points and can compare different experiences and all -- but good God the fact that she's still seems to have. More subconscious faith in the moral integrities of the nebulous concept of a government or corporation More than she has faith in the the moral integrity of the nebulous concept of our societal peers. She talks about it like the Second a group like that is founded, its set of ethics just Miraculously appears out from the ether + just happens to Always be morally sound by default. I cant seem to find a way to word things that with like... idk. Help it Click that those corporations are still run by People and are therefore just as fallible 💀 technically More so but she's convinced capitalism is Never going to go away so she doesn't care about the whole "company's and governments in power, as they exist today, Have A Monetary Incentive To Lie To Us As Much As They Can" thing cuz shes such a damn pessimist and assumes All people have been doing that Forever 💀💀💀 SIGH it's nbd i just needed to put it in words bc its been on my mind on and off
#horse.txt#vent //#not extremely sad just like. huffy.#i love my mom to pieces but. man. we all have our issues ig 😔 it would just be nice if she wouldn't talk to me about how#the world is only every going to get worse within my lifetime#with a shrug and a laugh like 'what can ya do?' like ma. to your own adult child's face? when im already clearly upset with the state of#the world? not when im trying to talk about the kind of changes that other people are proposing we make to our overall society?#she gets so bitchy at me for always complaining but never Doing anything to change the world#but then She complains and agrees with me?? and then ALSO denounces all the Suggestions i tell her abt bc 'oh that would never work lol'#and then when i ask her 'ok well what would You do?' and she go well i think we need to get rid of credit cards and the debt system we have#and im like ok sick!!! keep going!!!#and then she goes OH but we cant get Rid of the debt system Completely bc people still need to borrow from lenders to get houses n cars#and im just. MA#shes been stuck on this metaphor of America being 'a house'#and she says all the ideas of overthrowing the government and replacing it with Anything else would be 'burning it down'#and that if America is already On fire then we should just put it out and try to rebuild it#like 1.) America is not a House it is a Cult. America is a group of people on an area of land. not a fucking House.#2.) THERE ARE PEOPLE RUNNING AROUND THE CULTHOUSE WITH FLAMETHROWERS AND GUNS TO SCARE AWAY AND/OR KILL ANYONE WHO TRIES TO PUT IT OUT.#ITS GOING TO BURN DOWN ANYWAY
6 notes · View notes
gibbearish · 4 months
Text
oh psa but if you're in an industry that checks IDs and the person in front of you is clearly trans, don't make comments about anything on that ID. for instance saying "OMG your middle name's Danielle? that's my name too!!!" to someone 5 feet tall with a full beard is perhaps not the best choice one could make if one didn't want to put a neon glowing sign above that person's head saying "THIS IS A TRANSGENDER" to everyone they're with
#it is p funny tho going out places with cis / nb-and-always-presented-as-agab friends and always getting singles out abt my#id in Some Way and them always being like ??? wtf that was so weird what was up with that#and i have to be the one to be like 'remember that my id has an f on it' and theyre like :0 ....... >:0!!!!#like fuckin. the time i got id'd at goddamn jack in the box????#she was like 'yeah we have to check it on all orders over $25' which had never happened before and has never happened since because#its fucking jack in the box so every stupid order is over $25#for important context i was driving and bf in passenger seat was paying so id handed her his card and was way less passing than now#so once we left travis was like yo wtf that was so weird why on earth would they id someone at jack in the box?????#and im like well because i look like this and i handed her a credit card with the name travis on it and people making#up reasons to check trans-looking peoples ids to verify if theyre trans or not is unfortunately not an uncommon occurance#and he was completely floored that that was even a possibility#which like mood when i was doing bev steward literally the only thing i was thinking about on those ids was birthdays#course i was working at a theme park so we had ids from all over the country#and world but nonamericans had passports which are much more consistent than state ids#so id get handed someones id and just be like ugh ok where do they hide it on this one i have 50 people in line i dont have time for this#like why would i be wasting time casually perusing their gender marker yknow i have shit to do#so the fact that there are people who will feel the need to know that so bad that theyll do that is just wild to me and presumably him too#(working there was how we met and he ended up being bars lead then full water park sup after i left the job)#but yeah after he had his 'wait people actually do that?' realization he was just like '....well then good thing it was my card so we had to#give her my id so she'll never get to know for sure‚ get fucked' LMAO#ooh or when me and a friend went to trader joes and bought drinks cause i collect cool drink cans and when the cashier was checking#my id i made a joke to ny friend abt my picture looking like bobby hill and the cashier was like 'GASP dont say that about yourself youre#beautiful!!' which i believe i did have the beard by this point so it was a pretty obvious dig#and the picture super does look like bobby hill by the way like ill show yall if anyone's curious but literally no one irl has disagreed#except this one random woman lmao. but we get out and my friends like ????????? that was so weird#why did she say that????? and im like. well it has an f on it remember#and once again the :0 -> >:0 transformation#like it sucks having it happen but there is smth really funny abt watching friends so inclusive something like that never even#occured to them realize that thats a thing people will do and it just happened right in front of them#shoutout to my roommates friend tho who has worked at a sex shop and weed shop and changed my rewards account name for both to chosen name
5 notes · View notes
yamikawas · 2 years
Text
today i learned that im the yandere yoomtah girl even to the haters<3love and light
13 notes · View notes
rohirric-hunter · 2 years
Text
Angry and I want to Yell about it but I’m Tired
7 notes · View notes
swiftful-thinking13 · 2 years
Text
when I tell you that the guests today were directly from the pits of hell I’m not even exaggerating…why was every person the absolute WORST
#usually there’s a nightmare guest every other shift#but today was EVERY single guest#i don’t even know where to begin#some dude describing his girlfriend’s body to me in the most unnecessarily grotesque and disrespectful manner#the lady who claimed that she had credit from a return on a RECEIPT…and that she *lost* her gift card#she stayed at our store for two hours.#or the lady explaining to me how I am technically not petite after I threw that word around to describe what length I like my leggings GDKDH#or the THREE guests who explained to me how ugly and atrocious our patterns are as if I came up with them😩😩l#or this person who tried to return $600 worth of stolen clothes and I had to grab my manager#oh and my personal favorite#there were only two people on cash and so obvi the line was long#and this bitch walks up to the counter and throws her jacket on the table and she’s VIBRATING with fury#about how she almost walked because of the line and she wouldn’t respond to anything I said lmaoo I even wished her a good day at the end#and she looked like she wanted to murder my ass#I was fr having a mini panic attack at the register#everyone needs to click their personal reset button bc what the fuck was that#you know I’m pissed when my retail voice drops 😵‍💫#I do not get paid enough for this shit#I was disassociating on my drive home hskdhdk#I honestly don’t think I’m ready for holiday season#on top of this our new assistant manager is a fucking useless incompetent CLOWN#but that’s a story for another time🫣
3 notes · View notes
foldingfittedsheets · 2 months
Text
Since everyone seems to love my sex shop stories, here’s another one.
Phone calls were literally a game for us. Not all phone calls, but there was a specific brand of call where guys would creep on us. 90% of the workforce at the sex shops was women. So we’d get dudes calling jacking off or trying to get their jollies from us.
The game: make them hang up. We could have hung up. On a few occasions I did, but for the most part we made a sport out of getting creeps to go flaccid. It really depended on a caller.
You couldn’t just go in for belittling them straight off- some guys wanted that. You had to tailor your strategy to the perv. Overall it was pretty fun and it turned an aspect of the job that could’ve become a major bummer into a fun sport. We’d get excited when the phones rang.
So one day the phone rings. I pick up and it was very clearly a young teen who was putting on a deep voice. I was utterly delighted, I’d never had a crank call before. He said, “I have a dildo emergency! Can you deliver 5 boxes of dildos to my home?!”
It took everything in me not to crack in that moment. It was so funny. It was like three kids had walked through the door in a trench coat and the phrase “dildo emergency” was one of the funniest things I’d ever heard.
But I kept it together. In smooth customer service tones I replied, “Oh, I’m sorry to hear you’re having an emergency, but due to the nature of our product we do require people to come pick it up themselves.”
The caller audibly deflated. Some of the deep voice he was putting on bled away when he said plaintively, “But it’s an emergency…”
“I’m sorry, sir, rules are rules.”
He hung up. I burst out laughing and told my coworker what had happened. She said, “I will buy you lunch if you call back and pretend you can deliver something.”
This sounded like an all around win for me, and the kid hadn’t used anything to block his number. So I called back.
“Hello!” This was before caller ID was common for home phones and so he picked up in his totally normal voice, several octaves higher than before.
“Hello, I’m calling regarding your dildo emergency?”
“Oh! Hem hem,” he coughed, getting his voice back into character for me. “Yes! The emergency!”
“Well I’ve spoken to my manager and it’s your lucky day. We’ll be able to make a delivery after all. Five boxes you said? We can swing it by later, we’ll just need your name, address, and credit card number.”
He was thrown by needing to provide info and was silent for a moment then said, “Well how much is it for five boxes?”
“About five hundred dollars, sir.”
He slipped out of his character voice to exclaim, “Five hundred dollars?! What kind of dildos are they?!”
“Just standard six inches with balls, sir.”
This was his breaking point. He started wheezing with laughter trying to repeat the phrase “six inches with balls” incoherently.
“So your address and card info?”
He hung up and I broke down laughing too. We both got a kick out of it, and I won the game twice in one day.
14K notes · View notes
pinolitas · 23 days
Text
i hate being my parents' parent
1 note · View note
pokilicious · 4 months
Text
Can we as a society stop infantilizing short people? I'm 161cm tall with a babyface and people don't take me seriously and treat me like a child. I'm in my early twenties, I go to college and have bills to pay, don't treat me like I'm your little sister or whatever, I'm a grown ass adult and you should treat me as such
0 notes
Text
How I got scammed
Tumblr media
If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
https://pluralistic.net/2024/02/05/cyber-dunning-kruger/#swiss-cheese-security
Tumblr media
I wuz robbed.
More specifically, I was tricked by a phone-phisher pretending to be from my bank, and he convinced me to hand over my credit-card number, then did $8,000+ worth of fraud with it before I figured out what happened. And then he tried to do it again, a week later!
Here's what happened. Over the Christmas holiday, I traveled to New Orleans. The day we landed, I hit a Chase ATM in the French Quarter for some cash, but the machine declined the transaction. Later in the day, we passed a little credit-union's ATM and I used that one instead (I bank with a one-branch credit union and generally there's no fee to use another CU's ATM).
A couple days later, I got a call from my credit union. It was a weekend, during the holiday, and the guy who called was obviously working for my little CU's after-hours fraud contractor. I'd dealt with these folks before – they service a ton of little credit unions, and generally the call quality isn't great and the staff will often make mistakes like mispronouncing my credit union's name.
That's what happened here – the guy was on a terrible VOIP line and I had to ask him to readjust his mic before I could even understand him. He mispronounced my bank's name and then asked if I'd attempted to spend $1,000 at an Apple Store in NYC that day. No, I said, and groaned inwardly. What a pain in the ass. Obviously, I'd had my ATM card skimmed – either at the Chase ATM (maybe that was why the transaction failed), or at the other credit union's ATM (it had been a very cheap looking system).
I told the guy to block my card and we started going through the tedious business of running through recent transactions, verifying my identity, and so on. It dragged on and on. These were my last hours in New Orleans, and I'd left my family at home and gone out to see some of the pre-Mardi Gras krewe celebrations and get a muffalata, and I could tell that I was going to run out of time before I finished talking to this guy.
"Look," I said, "you've got all my details, you've frozen the card. I gotta go home and meet my family and head to the airport. I'll call you back on the after-hours number once I'm through security, all right?"
He was frustrated, but that was his problem. I hung up, got my sandwich, went to the airport, and we checked in. It was total chaos: an Alaska Air 737 Max had just lost its door-plug in mid-air and every Max in every airline's fleet had been grounded, so the check in was crammed with people trying to rebook. We got through to the gate and I sat down to call the CU's after-hours line. The person on the other end told me that she could only handle lost and stolen cards, not fraud, and given that I'd already frozen the card, I should just drop by the branch on Monday to get a new card.
We flew home, and later the next day, I logged into my account and made a list of all the fraudulent transactions and printed them out, and on Monday morning, I drove to the bank to deal with all the paperwork. The folks at the CU were even more pissed than I was. The fraud that run up to more than $8,000, and if Visa refused to take it out of the merchants where the card had been used, my little credit union would have to eat the loss.
I agreed and commiserated. I also pointed out that their outsource, after-hours fraud center bore some blame here: I'd canceled the card on Saturday but most of the fraud had taken place on Sunday. Something had gone wrong.
One cool thing about banking at a tiny credit-union is that you end up talking to people who have actual authority, responsibility and agency. It turned out the the woman who was processing my fraud paperwork was a VP, and she decided to look into it. A few minutes later she came back and told me that the fraud center had no record of having called me on Saturday.
"That was the fraudster," she said.
Oh, shit. I frantically rewound my conversation, trying to figure out if this could possibly be true. I hadn't given him anything apart from some very anodyne info, like what city I live in (which is in my Wikipedia entry), my date of birth (ditto), and the last four digits of my card.
Wait a sec.
He hadn't asked for the last four digits. He'd asked for the last seven digits. At the time, I'd found that very frustrating, but now – "The first nine digits are the same for every card you issue, right?" I asked the VP.
I'd given him my entire card number.
Goddammit.
The thing is, I know a lot about fraud. I'm writing an entire series of novels about this kind of scam:
https://us.macmillan.com/books/9781250865878/thebezzle
And most summers, I go to Defcon, and I always go to the "social engineering" competitions where an audience listens as a hacker in a soundproof booth cold-calls merchants (with the owner's permission) and tries to con whoever answers the phone into giving up important information.
But I'd been conned.
Now look, I knew I could be conned. I'd been conned before, 13 years ago, by a Twitter worm that successfully phished out of my password via DM:
https://locusmag.com/2010/05/cory-doctorow-persistence-pays-parasites/
That scam had required a miracle of timing. It started the day before, when I'd reset my phone to factory defaults and reinstalled all my apps. That same day, I'd published two big online features that a lot of people were talking about. The next morning, we were late getting out of the house, so by the time my wife and I dropped the kid at daycare and went to the coffee shop, it had a long line. Rather than wait in line with me, my wife sat down to read a newspaper, and so I pulled out my phone and found a Twitter DM from a friend asking "is this you?" with a URL.
Assuming this was something to do with those articles I'd published the day before, I clicked the link and got prompted for my Twitter login again. This had been happening all day because I'd done that mobile reinstall the day before and all my stored passwords had been wiped. I entered it but the page timed out. By that time, the coffees were ready. We sat and chatted for a bit, then went our own ways.
I was on my way to the office when I checked my phone again. I had a whole string of DMs from other friends. Each one read "is this you?" and had a URL.
Oh, shit, I'd been phished.
If I hadn't reinstalled my mobile OS the day before. If I hadn't published a pair of big articles the day before. If we hadn't been late getting out the door. If we had been a little more late getting out the door (so that I'd have seen the multiple DMs, which would have tipped me off).
There's a name for this in security circles: "Swiss-cheese security." Imagine multiple slices of Swiss cheese all stacked up, the holes in one slice blocked by the slice below it. All the slices move around and every now and again, a hole opens up that goes all the way through the stack. Zap!
The fraudster who tricked me out of my credit card number had Swiss cheese security on his side. Yes, he spoofed my bank's caller ID, but that wouldn't have been enough to fool me if I hadn't been on vacation, having just used a pair of dodgy ATMs, in a hurry and distracted. If the 737 Max disaster hadn't happened that day and I'd had more time at the gate, I'd have called my bank back. If my bank didn't use a slightly crappy outsource/out-of-hours fraud center that I'd already had sub-par experiences with. If, if, if.
The next Friday night, at 5:30PM, the fraudster called me back, pretending to be the bank's after-hours center. He told me my card had been compromised again. But: I hadn't removed my card from my wallet since I'd had it replaced. Also, it was half an hour after the bank closed for the long weekend, a very fraud-friendly time. And when I told him I'd call him back and asked for the after-hours fraud number, he got very threatening and warned me that because I'd now been notified about the fraud that any losses the bank suffered after I hung up the phone without completing the fraud protocol would be billed to me. I hung up on him. He called me back immediately. I hung up on him again and put my phone into do-not-disturb.
The following Tuesday, I called my bank and spoke to their head of risk-management. I went through everything I'd figured out about the fraudsters, and she told me that credit unions across America were being hit by this scam, by fraudsters who somehow knew CU customers' phone numbers and names, and which CU they banked at. This was key: my phone number is a reasonably well-kept secret. You can get it by spending money with Equifax or another nonconsensual doxing giant, but you can't just google it or get it at any of the free services. The fact that the fraudsters knew where I banked, knew my name, and had my phone number had really caused me to let down my guard.
The risk management person and I talked about how the credit union could mitigate this attack: for example, by better-training the after-hours card-loss staff to be on the alert for calls from people who had been contacted about supposed card fraud. We also went through the confusing phone-menu that had funneled me to the wrong department when I called in, and worked through alternate wording for the menu system that would be clearer (this is the best part about banking with a small CU – you can talk directly to the responsible person and have a productive discussion!). I even convinced her to buy a ticket to next summer's Defcon to attend the social engineering competitions.
There's a leak somewhere in the CU systems' supply chain. Maybe it's Zelle, or the small number of corresponding banks that CUs rely on for SWIFT transaction forwarding. Maybe it's even those after-hours fraud/card-loss centers. But all across the USA, CU customers are getting calls with spoofed caller IDs from fraudsters who know their registered phone numbers and where they bank.
I've been mulling this over for most of a month now, and one thing has really been eating at me: the way that AI is going to make this kind of problem much worse.
Not because AI is going to commit fraud, though.
One of the truest things I know about AI is: "we're nowhere near a place where bots can steal your job, we're certainly at the point where your boss can be suckered into firing you and replacing you with a bot that fails at doing your job":
https://pluralistic.net/2024/01/15/passive-income-brainworms/#four-hour-work-week
I trusted this fraudster specifically because I knew that the outsource, out-of-hours contractors my bank uses have crummy headsets, don't know how to pronounce my bank's name, and have long-ass, tedious, and pointless standardized questionnaires they run through when taking fraud reports. All of this created cover for the fraudster, whose plausibility was enhanced by the rough edges in his pitch - they didn't raise red flags.
As this kind of fraud reporting and fraud contacting is increasingly outsourced to AI, bank customers will be conditioned to dealing with semi-automated systems that make stupid mistakes, force you to repeat yourself, ask you questions they should already know the answers to, and so on. In other words, AI will groom bank customers to be phishing victims.
This is a mistake the finance sector keeps making. 15 years ago, Ben Laurie excoriated the UK banks for their "Verified By Visa" system, which validated credit card transactions by taking users to a third party site and requiring them to re-enter parts of their password there:
https://web.archive.org/web/20090331094020/http://www.links.org/?p=591
This is exactly how a phishing attack works. As Laurie pointed out, this was the banks training their customers to be phished.
I came close to getting phished again today, as it happens. I got back from Berlin on Friday and my suitcase was damaged in transit. I've been dealing with the airline, which means I've really been dealing with their third-party, outsource luggage-damage service. They have a terrible website, their emails are incoherent, and they officiously demand the same information over and over again.
This morning, I got a scam email asking me for more information to complete my damaged luggage claim. It was a terrible email, from a noreply@ email address, and it was vague, officious, and dishearteningly bureaucratic. For just a moment, my finger hovered over the phishing link, and then I looked a little closer.
On any other day, it wouldn't have had a chance. Today – right after I had my luggage wrecked, while I'm still jetlagged, and after days of dealing with my airline's terrible outsource partner – it almost worked.
So much fraud is a Swiss-cheese attack, and while companies can't close all the holes, they can stop creating new ones.
Meanwhile, I'll continue to post about it whenever I get scammed. I find the inner workings of scams to be fascinating, and it's also important to remind people that everyone is vulnerable sometimes, and scammers are willing to try endless variations until an attack lands at just the right place, at just the right time, in just the right way. If you think you can't get scammed, that makes you especially vulnerable:
https://pluralistic.net/2023/02/24/passive-income/#swiss-cheese-security
Tumblr media
Image: Cryteria (modified) https://commons.wikimedia.org/wiki/File:HAL9000.svg
CC BY 3.0 https://creativecommons.org/licenses/by/3.0/deed.en
10K notes · View notes
heart-bones · 1 year
Text
man every time I think I could not feel Worse, I am proven wrong ⚰️
0 notes
ew-selfish-art · 9 months
Text
Dp x Dc AU: It’s not the usual suspects trying to summon the undead this time, and it’s proving to be a massive headache for John Constantine. They seem...Competent. 
When John sniffed out a new plot to summon a ghost, he kind of laughed it off. Ghosts were not more than shades of the people/creatures they used to be, without all the right resources and enough buy in from the greater spirits of the Infinite Realms, most entities that came thought might scare some kids at a slumber party but that was at most. Plus, kids were scary resilient these days thanks to the internet, so really, John’s not worried. 
Then he hears about the gathering of artifacts and he has to care a little more. He learns that one Jasmine Fenton is involved and he’s... Surprised. She’s got a public record of dismissing her parent’s inventions and causing stirs at supernatural conventions (not to mention a great reputation as a research focused psychologist). Jasmine’s credit cards report a great deal of cash (refunded to her account by an unknown off-shore account) being taken out and her location is right next to the last place anyone could find a shard of the Crown. 
Yeah, that Crown. The Infinite, ancient blessed and deity cursed one. John had meant to get around to investigating if the shard of obsidian (fire forged) was legit, so he begins to set his sights on Jasmine for a ‘chat’. 
Then Sam Manson, a scary ass Heiress, pulls up in a limousine and all but kidnaps him and dumps him outside city limits. She tells him that he’s been cursed for the next 48 hours to stay out of their city- If he comes close, any plant will identify him in a heartbeat and come to life to kill him. (Fun fact: there are a goddamn lot of plants surrounding this stupid town, even the dandelions are forging knives to kill him.)
THEN worse, Red Robin gets on his ass about cybersecurity of all things. Turns out another player, identified by the moniker TooFineTooFurious has been tracking John’s phone and has been rummaging around official JLD documents- How was John supposed to know that keeping his passwords on the notes app could be hackable? Red Robin declares him incompetent and John can only sigh, crush his phone and move on. 
That all leads him to the summoning portal in front of him in this weird ghost themed high school gymnasium. It’s far too competent. It gives him goosebumps even before he can read out that they’re summoning the King of the Infinite Realms himself. John clicks the panic alarm on his JL communicator before engaging with the Trio before him. 
They’re not wearing any capes, no candles are lit, but this is the scariest cult he’s ever seen. Jasmine Fenton, ghost denier, Sam Manson, Heiress and Plant Witch (?), Some other dude with a beret and fucking DRONES (he considers this might be the man who hacked him). John pleads with them, they don’t know what they’re trying to do. Pariah Dark will kill them all, eat their entire planet for breakfast!! Everyone rolls their eyerolls at him, and he’s taken aback by their nonchalance. 
Plant guards grab him and a drone has a laser sight on his forehead. He fights but is subdued- They’re almost done chanting when Superman, Green Lantern, Red Robin and Cyborg all appear. Despite their disruption- the chanting ends with the green illumination of the circle. Despair fills the air. 
And then- Poof- a groaning young man appears. 
“Dudes you have no idea how unhelpful the Infi-map is sometimes. I was lost for like weeks and CW was being such a bitch ab- What. Wait, who are all- Holy shit did you guys summon the Justice League?” The Ghost King in full Regalia stared back at them in questioning concern. The three summoners start bitching  at the monarch and John... isn’t sure if this is going to be an interdimensional incident yet. 
4K notes · View notes