th3raid0r

joined 2 years ago
MODERATOR OF
 

Hello all,

With the increasing sightings of ICE agents in Tucson, we've created /c/ICEWatch.

This is a local only community.

It is local only to ensure community trust and safety.

If you are a fedizen who resides in Tucson, but have not created an account with us yet, I encourage signing up.

Please be aware that our instance is unique in that we go an extra mile to ensure that all local users are residents of Tucson. If your application is declined it is likely because we noticed something in your sign up that indicates you aren't local or unlikely to be human. If you feel that your signup was declined in error, please email admin@tucson.social with your appeal.

Edit: additionally, any posts serving similar purposes in in the Tucson politics community or any other federated community will be removed. This is to ensure community trust, safety, and quality of information.

[–] th3raid0r@tucson.social 5 points 2 months ago (3 children)

I certainly don't doubt the top line trends here in this study. However, I wonder how the fediverse might differ. Anyone can set up a Lemmy or Mastodon instance, regardless of their technical aptitude and desire to secure the instance from toxic content. It's also inherently more anonymous. A more direct comparison might be 4chan not Reddit.

Both of the platforms they studied on have more sophisticated methods to determine bad actors because of their dominance. Particularly Facebook, where a profile is supposed to be mappable to a single, real identity.

That being said, there's a very real concern about how algorithms end up placing these "loud mouths" in other people's feeds. After all, outrage is still something that is preferred by algorithms. So those 3 to 7% of users creating the toxic content, might represent an outsized proportion of views.

It's good to know the reality on these platforms is that most people are reasonable. I guess the bigger question is why people come to the opposite conclusion. And I think that algorithms overly indexing on outrage are part of that.

[–] th3raid0r@tucson.social 1 points 2 months ago

Well, You're more than welcome to reach out on more secure comms, such as matrix to get the proof! It's strange how that's basically standard for most of the other respectable instances, but not here.

[–] th3raid0r@tucson.social 3 points 2 months ago (3 children)

Do I know if they are the exact same individual - no - I can't know that because I don't have IP information from other instances. To use this limitation as a bludgeon is dishonest. Admins that host sockpuppets and know it aren't likely to ever reveal this information.

Do I have clear evidence that the UM/CM0002/BarryGoldWater user(s) that attempted signup on my instance are bots - Oh definitely yes.

Now, I see you are a mod not an admin. I do not typically share my methods with non-admins, and definitely not over a public forum like this.

If the dbzer0 admin wants my supporting information, they may DM me with their preferred matrix handle/server, and i will happily discuss there.

[–] th3raid0r@tucson.social -1 points 2 months ago (1 children)

Give the documents then? And am I a bot now too?

Interesting how you continue to leave out the security implications of posting this publicly.

Odd that.

I know not if you are a bot, you aren't on my instance, nor would it be likely you could get through my process.

I do know that you are awfully defensive of sockpuppet like behavior though.

[–] th3raid0r@tucson.social 3 points 2 months ago (8 children)

Nooope, I have IP data, email logs, and other things. However, much of the data had fallen off my WAF retention period. Oddly convenient how you just assume I don't have these things rather than keeping them close because I don't want the bots to figure out how I'm catching them.

When you conveniently leave out that providing proof reduces an admins ability to re-use certain detection methods, it makes me pretty convinced you're complicit.

[–] th3raid0r@tucson.social 4 points 2 months ago* (last edited 2 months ago)

How do you identify sock puppets? Are they all the same IP?

From an Admin perspective, most botnets do a good job of distributing most of their traffic. But the key is they don't distribute ALL of their traffic.

From a user perspective my advice is generally "if it quacks like a duck"...

That is, is the persona that of an extreme stereotype? Are they overly contrarian? Is what they are doing destructive to those who claim similar identities? Then it's likely a sockpuppet.

And if it isn't - oh well, treat them like one anyways - it's better for society that way.

[–] th3raid0r@tucson.social -2 points 2 months ago (6 children)

CM0002 may not be shaking the cage as hard, but he is still a bot - and associated with the same botnet when I got a burst of signups for UM and his alts.

[–] th3raid0r@tucson.social 5 points 2 months ago

Barrygoldwater is a bot associated with UM. UM also is associated with CM0002 from an IP standpoint given the last "bot signup attack" I experienced. (Fun fact they use barrygoldwater in their email they use to sign up from)

[–] th3raid0r@tucson.social 5 points 2 months ago

Or rather, this admin, do they have a WAF? Are they analyzing the traffic that comes in? Are the sure they're checking every point of interaction for consistency? If no, then they didn't really "Check".

[–] th3raid0r@tucson.social 2 points 2 months ago (21 children)

This admin will state that UM is a bot. And wouldn't ya know it some of the other signup attempts used the alt names. Weird that.

I don't think many admins know infosec practices very well to be frank.

[–] th3raid0r@tucson.social 5 points 2 months ago (6 children)

Fuck all, but luckily TrickDacy is here to instantly believe any baseless accusation.

As an admin who had to fend off UM's bot signups - it's definitely not unfounded.

[–] th3raid0r@tucson.social -1 points 2 months ago (2 children)

I have a more effective way of confirming things like this if interested…

Probably not more effective than my method - but you need to be an instance admin to be able to use my method.

 

Take Action Tucson is your Central Hub for Tucson Activism.

If you are a part of this organization please reach out to me. I'd like to have a deeper partnership with them.

 

This is pissing me the fuck off.

So let me make this utterly clear - henceforth any news article title that is erroneously using "deport" must be re-titled to use "exile" at the very least.

I'll do my part by editing the titles for any newsbot postings since that's all automated.

Language is important, deport has a very specific meaning. You cannot deport a citizen to a different country. The word the media seems to have difficulty using is "Exile" and "Salvadoran Death Camp".

So, I, as server admin will do it for them - because I'm not a fucking spineless coward.

 

cross-posted from: https://tucson.social/post/1320798

Hi Folks!

With all the recent hysteria around drones/orbs right now. I wanted to offer a clear guide on how to get the best results when attempting to photo or video something you see.

If someone thinks they see a UFO - please know that quality is paramount right now. You should treat it like such. This isn't something folks can just whip out a phone and try and capture without contributing to the already-bad data. Given how long this mystery has persisted, I've been really surprised at how low effort most evidence is. Is this not important? Don't we want to get to the bottom of things? Well then, read on, here's how:

  1. ALWAYS- Validate what you are seeing with public data. Use AR Astronomy apps to rule out bright stars and planets. Use AR Flight Radar apps to rule out commercial planes. Also ensure you aren't looking at a lens flair by comparing against other light patterns in the image.
  2. ALWAYS- Use a tripod or stabilization of some sort and film from a stationary area. Even a mini tripod is better than nothing. Oh, and pull over if you're driving or ask to pull over if you are a passenger. This is important enough to pull over for right?
  3. ALWAYS- Lock your focus to infinity. You might need a 3rd party app to do it. Anything further than a few hundred feet doesn't need a focus wheel - just go straight to "infinity" or as far out focus as you can and lock it.
  4. TRY - To get as much data as possible. Is the orb still there? Do you have battery? Don't stop recording! 6 second snippets are a trend worth fighting against.
  5. TRY - Astrophotography mode if your phone supports it. It stacks thousands of exposures and tries to increase detail. Stop the capture if the subject moves to avoid streaks.
  6. TRY - Lucky imaging if you don't have an Astro mode on your phone. This means locking your shutter speed to 1 second, with a moderate-high ISO (about 3/4 of the way to max ISO) and taking images continuously. This can later be stacked in a photo editor or astronomy stacker where you can fine tune the image and get insane amounts of detail.
  7. TRY - To use a telescopic lens OR mount your camera to a telescope of some type. Many of the videos suggest that these anomalies are often stationary for long enough to be viewable in astronomy telescopes.

If you follow these tips, you'll get better photos than 90% of what's being shared recently. Even if you're using a smartphone.

Anyone else have good tips?

 

Hi Folks!

With all the recent hysteria around drones/orbs right now. I wanted to offer a clear guide on how to get the best results when attempting to photo or video something you see.

If someone thinks they see a UFO - please know that quality is paramount right now. You should treat it like such. This isn't something folks can just whip out a phone and try and capture without contributing to the already-bad data. Given how long this mystery has persisted, I've been really surprised at how low effort most evidence is. Is this not important? Don't we want to get to the bottom of things? Well then, read on, here's how:

  1. ALWAYS- Validate what you are seeing with public data. Use AR Astronomy apps to rule out bright stars and planets. Use AR Flight Radar apps to rule out commercial planes. Also ensure you aren't looking at a lens flair by comparing against other light patterns in the image.
  2. ALWAYS- Use a tripod or stabilization of some sort and film from a stationary area. Even a mini tripod is better than nothing. Oh, and pull over if you're driving or ask to pull over if you are a passenger. This is important enough to pull over for right?
  3. ALWAYS- Lock your focus to infinity. You might need a 3rd party app to do it. Anything further than a few hundred feet doesn't need a focus wheel - just go straight to "infinity" or as far out focus as you can and lock it.
  4. TRY - To get as much data as possible. Is the orb still there? Do you have battery? Don't stop recording! 6 second snippets are a trend worth fighting against.
  5. TRY - Astrophotography mode if your phone supports it. It stacks thousands of exposures and tries to increase detail. Stop the capture if the subject moves to avoid streaks.
  6. TRY - Lucky imaging if you don't have an Astro mode on your phone. This means locking your shutter speed to 1 second, with a moderate-high ISO (about 3/4 of the way to max ISO) and taking images continuously. This can later be stacked in a photo editor or astronomy stacker where you can fine tune the image and get insane amounts of detail. If you find that the subject is too bright, reduce ISO first, then reduce shutter speed.
  7. TRY - To use a telescopic lens OR mount your camera to a telescope of some type. Many of the videos suggest that these anomalies are often stationary for long enough to be viewable in astronomy telescopes.

If you follow these tips, you'll get better photos than 90% of what's being shared recently. Even if you're using a smartphone.

Anyone else have good tips?

EDIT: Added note about what to do if lucky imaging subject is too bright.

 

So first off, let me set this straight.

I actually like GenAI music. It offers me a way to er... "create" tracks that resonate with a particular moment in my life. It's more personal and relevant than anything most artists produce. But that's where it ends - I don't want to hear GenAI mass market slop. Heck, I don't want to hear MOST folk's AI Generated stuff. That's for them. The music I generate is for me.

Moving on from that - I primarily use Spotify currently for music discovery, and up until a few months ago it's been the most reliable way to find new Artists that might interest me. Their algorithm, while not perfect, generally hooked me up with artists that were in the ballpark of what I like and were REAL.

Today, about half of my "Release Radar" is AI generated slop. Some of it is published under their own names and labels which is fine, but others are transparently attempting to dupe listeners by imitating or outright impersonating known bands. However, even in the "nice" case of well labeled and non-impersonating AI tunes, it's significantly getting in the way of finding new stuff.

I think I'm done with Spotify, recent statements from the CEO has me thinking that they don't consider this to be a problem. They aren't looking to fix this issue, and aren't even pretending to.

But the problem is, none of the other music streaming services are in a better situation. None have sought to deal with the artist impersonation problem or general labeling of AI generated music.

I feel like I have to go back to CD's and word-of-mouth like back in the "old days" - at least if I'm to be sure that the music was actually made by a human. But how long would it be before we start getting CD's with AI generated music on them? My hope is that the fad is too "low effort" to bother with pressing vinyl or burning CD's.

How are you discovering new (human) music in this rapidly changing landscape?

 

As in title, my father is an American nomad, and he just recently got a spot with good internet signal for a few months.

He hasn't really played in years, and the last game he really enjoyed was Warface and Novalogic's Joint Operations: Combined Arms.

There is a bit of a twist though, his vision certainly isn't what it used to be, so whatever game I suggest needs accessibility options galore.

I found a really good "singleplayer only" experience in Ravenfield and the style lends itself very well to my father's limited vision.

Is there something like Ravenfield but with a well supported online component? Perhaps Battlebit: Remastered is pretty close?

EDIT: I suppose the genre is better described a "mil-sim" than "tactical shooter".

UPDATE: Someone recommended the latest Insurgency game. After realizing my father had over 1K hours in the previous Insurgency game I realized that this was the game to get. Turns out it was a good choice! That's where most of my father's online buddies ended up! Thanks all! Feel free to keep recommending things, but we already seem to have a winner!

 

Obviously this is still a Pixel issue - but at least I can connect to my home Wifi again.

I previously posted saying that Wifi was broken in general, but I mistook my ongoing Xfinity outage as being unable to connect to any wifi. Thus I removed the post.

When the outage ended, I could connect to some other networks and couldn't figure out why.

It wasn't until after a painful factory reset process that I tried going from WPA3/WPA2 mode to just WPA2 on both of my APs and suddenly everything is able to connect again.

It seems that the recent OTA update borked WPA3-Personal in a way that doesn't allow it to navigate the "compatibility mode" of WPA3/WPA2 either.

Edit - Looks like this might even be something Verizon specific - UQ1A-20231205.015.A1

Edit2 - Also mine is a Pixel 7 Pro - a Pixel 6 Pro user reports no such issue - YMMV.

 

I just realized that every streaming platform seems to have a couple heavy-hitter big-budget sci-fi series these days. Most of them turn out to be critically acclaimed as well.

Sure, we all know that there are Star Trek fans who dislike Discovery and Picard, or Foundation fans who dislike Apple's adaptation. Even though much of what is on TV is still decades-old franchises, it seems that we're getting more original sci-fi along with it.

  • Scavengers Reign
  • For All Mankind
  • Invasion
  • Cyberpunk: Edgeruners
  • Tales from the Loop

I could go on...

No longer is it simply a single channel on cable tv that was also 50/50 with horror content, plus Star Trek and a handful of others that other networks syndicated.

Today there's a rich tapestry of new ideas, concepts, and just plain art in media that was normally reserved for paperbacks published by Tor and others.

Don't get me wrong, I still love me some SG1, TNG, DS9, B5, and others - all shows I grew up with; but I'm so happy that we get so much more now!

 

Other Arch Flavors I've tried (some are no longer with us) include:

  • ArchBang
  • EndeavourOS
  • Manjaro
  • Chakra

So with that out of the way, I've found my Garuda experience incredibly painful. From messy repositories (Chaotic-AUR plus their own stuff), to an overly involved upgrade process (when using the helper) - the distro screams of a team that has no freakin' clue how to maintain an actual distribution.

It's basically Arch on hard mode with so many settings rolled into their own packages which need to be removed before customization.

Then we get to the purported performance enhancements and, honestly, this is the worst performing distro I've ever used, by multiple miles. I'm not sure if its the scheduler settings, or something with the zram settings - but this distro hitches and hangs constantly. (5950x, 64GB of Ram, Samsung 980 Pro drives, NVIDIA RTX 3080Ti - NOT a weak machine by any standards)

I'd normally chalk it up to compositor issues on Wayland (yes, I prefer Wayland and it works fine for most Arch derivitaves even with Nvidia). However the performance issues even crop up on basic terminal commands on a TTY with lots of weird hangs and lags.

The ONLY thing that was easier on this distro was installing the various Proton GE builds and other specialty stuff found in the Chaotic-AUR. But given the above, it's definitely not worth it when one can configure an Arch box to do the same things without all of the problems.

Perhaps I'm not doing something right? Given all the praise for this distro, perhaps it shouldn't perform like this?

To be completely and utterly clear - I'm an advanced user trying out these distros for fun and discovery. I can indeed "just use a different distro" but wanted to give this one a fair shake before moving on.

 

As an AuDHD person with Echolalalalalalalalalia 🙃, I find that my accent/idiolect has changed as I've aged and been exposed to different accents of all types in the U.S.. I just kinda pick up certain things I like.

For example I like:

  • The British pronunciation/spelling of Aluminium and Banana
  • The Irish pronunciation of three (my grandfather who was not at all born in Ireland also used it though)
  • Upper Midwest sayings and phrases - Ope!, Oh ya sure!
  • Extended "Wwweeeelp"s
  • I bounce ALL around my register in speaking sometimes. I've sometimes been described as sing-songy.

But also dislike certain aspects of things and seek to avoid them at all costs....

  • Cot/Caught, Pen/Pin - NO MERGERS! Ever. They must be different sounds.
  • Glottal Stops in place of consonants are a no go - pronounce the whole thing dang it!

There's a whole lot more of course, but I need to finish this post so I can go be an unregulated mess after a long (and particularly annoying) day of work.

So what about y'all? I'm super curious to know!

 

A bit more context there since you might wonder why customers can cause Sev1's.

Well, I work for a Database Technology company and we provide a managed service offering. This managed service offering has SLA's that essentially enforce a 5 minute response time for any "urgent" issue.

Well, a common urgent issue is that the customer suddenly wants to load in a bunch of new data without informing us which causes the cluster to stop accepting write loads.

It's to the point where most if not all urgent pages result in some form of scaling of the cluster.

Since this is a customer driven behavior, there is no real ability to plan for it - and since these particular customers have special requirements (and thus, less ability to automate scaling operations), I'm unsure if there is any recourse here.

It's to the point that it doesn't even feel like an SRE team anymore - we should just instead be called "On-demand scaling agents". Since we're constantly trying to scale ahead of our customers.

All in all, I'm starting to feel like this is a management/sales level issue that I cannot possibly address. If we're selling this managed service offering as essentially "magic" that can be scaled whenever they need then it seems like we're being setup for failure at the organizational level. Not to mention, not being smart about costs behind scaling and factoring that into these contracts.

So, fellow SRE's have you had to have this conversation with a larger org? What works for something like this? What doesn't? Should I just seek greener pastures at this point?

P.S. - Posted c/Programming due to lack of a c/SRE

view more: next ›