tqwhite
tqwhite.mastodon.social.ap.brid.gy
tqwhite
@tqwhite.mastodon.social.ap.brid.gy
Old computer programmer with penchant for cocktails, technology and left wing politics. I read a lot. I have a lot of opinions.

[bridged from https://mastodon.social/@tqwhite on the fediverse by https://fed.brid.gy/ ]
Elon Musk is funding her opponent’s campaign for Wisconsin Supreme Court to the tune of millions. He is trying to buy Wisconsin like he did Donald Trump.

Flood her with money. Donate Donate Donate.

https://secure.actblue.com/donate/nope4judge-crawford
I just gave to Judge Susan Crawford
Join me in defending Democratic control of the Wisconsin Supreme Court. The election is on April 1.
secure.actblue.com
March 6, 2025 at 4:31 AM
Spread this around. Nobody needs to hear my opinion about how badly it is. Here is testimonials of what is being left undone by people who are being harmed.

Pass this around as far as you can. This is resistance.

https://youtube.com/shorts/sfcV4wfS4LI?si=z_1z4xd2e2Pbcc40
February 27, 2025 at 12:29 AM
Super duper informative article. Facts and authoritative debunk. Big win.

"I wanted to have fact-checking for those sources at my (and others’) fingertips."

https://absolutelymaybe.plos.org/2024/12/28/getting-ready-for-more-mrna-vaccine-fear-mongering-a-compendium/
absolutelymaybe.plos.org
December 30, 2024 at 4:08 PM
Think AI is just dumb-ass plagiarism? Read this announcement and tell me you still think that.

"a way of automatically taking what can be quite vague human thoughts and ideas, and making them crisp and structured—by expressing them computationally" […]
Original post on mastodon.social
mastodon.social
December 9, 2024 at 8:27 PM
I've been seeing tons of this. Turns out you can buy a kit to do this phishing.

"“Your package is on hold for an invalid recipient address. Fill in the correct address info by the link.” "

https://krebsonsecurity.com/2023/10/phishers-spoof-usps-12-other-natl-postal-services/
<div class="wp-caption alignright" id="attachment_65265" style="width: 234px"><img alt="" aria-describedby="caption-attachment-65265" class="wp-image-65265" decoding="async" height="334" src="https://krebsonsecurity.com/wp-content/uploads/2023/10/uspsphish-sms.png" width="224"/><p class="wp-caption-text" id="caption-attachment-65265">The fake USPS phishing page.</p></div> <p>Recent weeks have seen a sizable uptick in the number of phishing scams targeting <strong>U.S. Postal Service</strong> (USPS) customers. Here’s a look at an extensive SMS phishing operation that tries to steal personal and financial data by spoofing the USPS, as well as postal services in at least a dozen other countries.</p> <p>KrebsOnSecurity recently heard from a reader who received an SMS purporting to have been sent by the USPS, saying there was a problem with a package destined for the reader’s address. Clicking the link in the text message brings one to the domain <strong>usps.informedtrck[.]com</strong>.</p> <p>The landing page generated by the phishing link includes the USPS logo, and says “Your package is on hold for an invalid recipient address. Fill in the correct address info by the link.” Below that message is a “Click update” button that takes the visitor to a page that asks for more information.</p> <p>The remaining buttons on the phishing page all link to the real USPS.com website. After collecting your address information, the fake USPS site goes on to request additional personal and financial data.</p> <p>This phishing domain was recently registered and its WHOIS ownership records are basically nonexistent. However, we can find some compelling clues about the extent of this operation by loading the phishing page in Developer Tools, a set of debugging features built into Firefox, Chrome and Safari that allow one to closely inspect a webpage’s code and operations.</p> <p>Check out the bottom portion of the screenshot below, and you’ll notice that this phishing site fails to load some external resources, including an image from a link called <strong>fly.linkcdn[.]to</strong>.</p> <div class="wp-caption aligncenter" id="attachment_65257" style="width: 760px"><a href="https://krebsonsecurity.com/wp-content/uploads/2023/10/linkcdn-to.png" rel="noopener" target="_blank"><img alt="" aria-describedby="caption-attachment-65257" class="wp-image-65257" decoding="async" height="231" loading="lazy" sizes="(max-width: 750px) 100vw, 750px" src="https://krebsonsecurity.com/wp-content/uploads/2023/10/linkcdn-to.png" srcset="https://krebsonsecurity.com/wp-content/uploads/2023/10/linkcdn-to.png 1474w, https://krebsonsecurity.com/wp-content/uploads/2023/10/linkcdn-to-768x237.png 768w, https://krebsonsecurity.com/wp-content/uploads/2023/10/linkcdn-to-782x241.png 782w" width="750"/></a><p class="wp-caption-text" id="caption-attachment-65257">Click the image to enlarge.</p></div> <p>A search on this domain at the always-useful <a href="https://URLscan.io" rel="noopener" target="_blank">URLscan.io</a> shows that <strong>fly.linkcdn[.]to</strong> is <a href="https://urlscan.io/search/#fly.linkcdn.to" rel="noopener" target="_blank">tied to a slew of USPS-themed phishing domains</a>. Here are just a few of those domains (links defanged to prevent accidental clicking):</p> <p>usps.receivepost[.]com<br/> usps.informedtrck[.]com<br/> usps.trckspost[.]com<br/> postreceive[.]com<br/> usps.trckpackages[.]com<br/> usps.infortrck[.]com<br/> usps.quicktpos[.]com<br/> usps.postreceive].]com<br/> usps.revepost[.]com<br/> trackingusps.infortrck[.]com<br/> usps.receivepost[.]com<br/> usps.trckmybusi[.]com<br/> postreceive[.]com<br/> tackingpos[.]com<br/> usps.trckstamp[.]com<br/> usa-usps[.]shop<br/> usps.infortrck[.]com<br/> unlistedstampreceive[.]com<br/> usps.stampreceive[.]com<br/> usps.stamppos[.]com<br/> usps.stampspos[.]com<br/> usps.trckmypost[.]com<br/> usps.trckintern[.]com<br/> usps.tackingpos[.]com<br/> usps.posinformed[.]com</p> <p>As we can see in the screenshot below, the developer tools console for informedtrck[.]com complains that the site is unable to load a <strong>Google Analytics</strong> code — <strong>UA-80133954-3 </strong>— which apparently was rejected for pointing to an invalid domain.</p> <div class="wp-caption aligncenter" id="attachment_65260" style="width: 760px"><a href="https://krebsonsecurity.com/wp-content/uploads/2023/10/ua-usps.png" rel="noopener" target="_blank"><img alt="" aria-describedby="caption-attachment-65260" class="wp-image-65260" decoding="async" height="321" loading="lazy" sizes="(max-width: 750px) 100vw, 750px" src="https://krebsonsecurity.com/wp-content/uploads/2023/10/ua-usps.png" srcset="https://krebsonsecurity.com/wp-content/uploads/2023/10/ua-usps.png 1890w, https://krebsonsecurity.com/wp-content/uploads/2023/10/ua-usps-768x329.png 768w, https://krebsonsecurity.com/wp-content/uploads/2023/10/ua-usps-1536x657.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2023/10/ua-usps-782x335.png 782w" width="750"/></a><p class="wp-caption-text" id="caption-attachment-65260">Notice the highlighted Google Analytics code exposed by a faulty Javascript element on the phishing website. Click to enlarge. That code actually belongs to the USPS.</p></div> <p>The valid domain for that Google Analytics code is the official usps.com website. According to <strong>dnslytics.com</strong>, that same analytics code has shown up on at least six other nearly identical USPS phishing pages dating back nearly as many years, including <strong>onlineuspsexpress[.]com</strong>, which <strong>DomainTools.com</strong> says was registered way back in September 2018 to an individual in Nigeria.</p> <p>A different domain with that same Google Analytics code that was registered in 2021 is <strong>peraltansepeda[.]com</strong>, which <strong>archive.org</strong> <a href="https://web.archive.org/web/20211220213251/http://peralatansepeda.com/" rel="noopener" target="_blank">shows</a> was running a similar set of phishing pages targeting USPS users. DomainTools.com indicates this website name was registered by <a href="https://krebsonsecurity.com/2023/08/karma-catches-up-to-global-phishing-service-16shop/" rel="noopener" target="_blank">phishers based in Indonesia</a>.</p> <p>DomainTools says the above-mentioned USPS phishing domain <strong>stamppos[.]com</strong> was registered in 2022 via Singapore-based <strong>Alibaba.com</strong>, but the registrant city and state listed for that domain says “Georgia, AL,” which is not a real location.</p> <p>Alas, running a search for domains registered through Alibaba to anyone claiming to reside in Georgia, AL reveals nearly 300 recent postal phishing domains ending in “.top.” These domains are either administrative domains obscured by a password-protected login page, or are .top domains phishing customers of the USPS as well as postal services serving other countries.</p> <p>Those other nations include the <a href="https://urlscan.io/result/6a07d4ee-da58-4073-af57-b35a50443c1b/" rel="noopener" target="_blank">Australia Post,</a> <a href="https://urlscan.io/result/d1e65a1b-83ab-4336-b08e-238228b76816/" rel="noopener" target="_blank">An Post</a> (Ireland), <a href="https://urlscan.io/result/625dbe0a-014d-43b3-a186-8b0a289b72aa/" rel="noopener" target="_blank">Correos.es</a> (Spain), the <a href="https://urlscan.io/result/f8597d60-6c51-4703-abf3-c38738124fff/" rel="noopener" target="_blank">Costa Rican post</a>, the <a href="https://urlscan.io/result/3e467dac-5972-4e2c-ab36-52b783c6b59f/" rel="noopener" target="_blank">Chilean Post</a>, the <a href="https://urlscan.io/result/1677e4c5-f22a-4a5c-a5d3-98f4d3b940bf/" rel="noopener" target="_blank">Mexican Postal Service</a>, <a href="https://urlscan.io/result/1eaba8e4-10be-49fc-9770-f44b87133dd6/" rel="noopener" target="_blank">Poste Italiane</a> (Italy), <a href="https://urlscan.io/result/5805064e-4fc9-43bf-8c02-a30ac0056d9e/" rel="noopener" target="_blank">PostNL</a> (Netherlands), <a href="https://urlscan.io/result/ae756c37-5ce0-47bf-934b-3c9f217f8ae2/" rel="noopener" target="_blank">PostNord</a> (Denmark, Norway and Sweden), and <a href="https://urlscan.io/result/151c049e-d475-4cad-89c0-ef9cd383cd48/" rel="noopener" target="_blank">Posti</a> (Finland). A complete list of these domains is available <a href="https://krebsonsecurity.com/wp-content/uploads/2023/10/alibaba-postal-phishing-al-ga.pdf" rel="noopener" target="_blank">here</a> (PDF).<span id="more-65255"></span></p> <div class="wp-caption aligncenter" id="attachment_65273" style="width: 680px"><img alt="" aria-describedby="caption-attachment-65273" class="size-full wp-image-65273" decoding="async" height="651" loading="lazy" src="https://krebsonsecurity.com/wp-content/uploads/2023/10/anpostphish.png" width="670"/><p class="wp-caption-text" id="caption-attachment-65273">A phishing page targeting An Post, the state-owned provider of postal services in Ireland.</p></div> <p>The Georgia, AL domains at Alibaba also encompass several that spoof sites claiming to collect outstanding road toll fees and fines on behalf of the governments of <a href="https://urlscan.io/result/3a8729af-379c-408a-9623-66b619125e82/" rel="noopener" target="_blank">Australia</a>, <a href="https://urlscan.io/result/c552d0d2-d698-4b0d-8644-88b1938ff173/" rel="noopener" target="_blank">New Zealand</a> and <a href="https://urlscan.io/result/ea135a70-c1b1-43be-ae50-2386c67befcc/" rel="noopener" target="_blank">Singapore</a>.</p> <p>An anonymous reader wrote in to say they submitted fake information to the above-mentioned phishing site usps.receivepost[.]com via the malware sandbox <strong>any.run</strong>. A <a href="https://app.any.run/tasks/fc79e00c-a26c-4bfa-b658-4a7009ac4682/" rel="noopener" target="_blank">video recording of that analysis</a> shows that the site sends any submitted data via an automated bot on the Telegram instant messaging service.</p> <p>The traffic analysis just below the any.run video shows that any data collected by the phishing site is being sent to the Telegram user <a href="https://t.me/chenlun" rel="noopener" target="_blank">@chenlun</a>, who offers to sell customized source code for phishing pages. From a review of @chenlun’s other Telegram channels, it appears this account is being massively spammed at the moment — possibly thanks to public attention brought by this story.</p> <p><a href="https://krebsonsecurity.com/wp-content/uploads/2023/10/chenlun.png" rel="noopener" target="_blank"><img alt="" class="aligncenter wp-image-65291" decoding="async" height="381" loading="lazy" sizes="(max-width: 750px) 100vw, 750px" src="https://krebsonsecurity.com/wp-content/uploads/2023/10/chenlun.png" srcset="https://krebsonsecurity.com/wp-content/uploads/2023/10/chenlun.png 991w, https://krebsonsecurity.com/wp-content/uploads/2023/10/chenlun-768x390.png 768w, https://krebsonsecurity.com/wp-content/uploads/2023/10/chenlun-782x397.png 782w" width="750"/></a></p> <p>Meanwhile, researchers at DomainTools recently <a href="https://www.domaintools.com/resources/blog/return-to-sender-a-brief-analysis-of-a-us-postal-service-smishing-campaign/" rel="noopener" target="_blank">published a report</a> on an apparently unrelated but equally sprawling SMS-based phishing campaign targeting USPS customers that appears to be the work of cybercriminals based in Iran.</p> <p>Phishers tend to cast a wide net and often spoof entities that are broadly used by the local population, and few brands are going to have more household reach than domestic mail services. In June, the <strong>United Parcel Service</strong> (UPS) disclosed that fraudsters were <a href="https://krebsonsecurity.com/2023/06/sms-phishers-harvested-phone-numbers-shipment-data-from-ups-tracking-tool/" rel="noopener" target="_blank">abusing an online shipment tracking tool in Canada</a> to send highly targeted SMS phishing messages that spoofed the UPS and other brands.</p> <p>With the holiday shopping season nearly upon us, now is a great time to remind family and friends about the best advice to sidestep phishing scams: Avoid clicking on links or attachments that arrive unbidden in emails, text messages and other mediums. Most phishing scams invoke a temporal element that warns of negative consequences should you fail to respond or act quickly.</p> <p>If you’re unsure whether the message is legitimate, take a deep breath and visit the site or service in question manually — ideally, using a browser bookmark so as to avoid <a href="https://krebsonsecurity.com/?s=typosquatting&amp;x=0&amp;y=0" rel="noopener" target="_blank">potential typosquatting sites</a>.</p> <p>Update: Added information about the Telegram bot and any.run analysis.</p>
krebsonsecurity.com
December 3, 2024 at 8:45 PM
The third of the four horseman just showed up.

Trump, Musk and now...

https://enron.com/pages/newsroom
Newsroom
We're back and we have something to say
enron.com
December 2, 2024 at 3:25 PM
Another Blue Sky handle change. I am now:

@tq.tqwhite.com

My wife and I both use tqwhite.com and now she will be able to have a bsky identity someday.

Come on over!!

https://bsky.app/profile/tq.tqwhite.com
November 26, 2024 at 4:30 PM
I owe Facebook a little for this. It started showing me this guy and it turns out he is wonderful. Very funny and smart. Apparently he has a thing coming on youtube. I expect it to be good.

https://www.youtube.com/results?search_query=josh+johnson
November 26, 2024 at 4:30 PM
November 25, 2024 at 9:42 PM
After Heather Cox Richardson, I have had to mitigate my belief that the American people seek to do us harm. In fact, they are credulous idiots who believe that harming us is the only way for the rest to survive.

"The biggest challenge of our lifetime will be figuring out how to combat the […]
Original post on mastodon.social
mastodon.social
November 25, 2024 at 7:19 PM
This is what happens when one eschews reading about current events. I have become tragic.

"Beef tallow’s primary appeal lies in its natural composition, which closely mimics the skin’s sebum"

https://www.thecut.com/article/beef-tallow-benefits-review-risks.html
November 24, 2024 at 10:51 AM
Look who just showed up on Blue Sky

https://bsky.app/profile/schwarzenegger.bsky.social
November 20, 2024 at 4:58 PM
"I’m also big on Bluesky because I think it signals a shift in how social media works on a more fundamental level."

I'm tqwhite.bsky.social there.

https://www.newscientist.com/article/2456782-bluesky-is-ushering-in-a-pick-your-own-algorithm-era-of-social-media/
November 20, 2024 at 3:51 PM
I claim that this post is not backsliding into current events because it is about AI. At least that's how it got to me. Pretty funny in an awful way.

https://fortune.com/2024/11/14/grok-musk-misinformation-spreader/
November 17, 2024 at 6:36 PM
November 9, 2024 at 6:20 PM
I’ve quite enjoyed my media experience since I ditched cable years ago. Today I realized even more why. I was not able to turn on cable news and be driven insane by the bloviators. I will not be able to do so tomorrow. Que sera, sera. I might try to avoid the news until Thursday. Sounds soothing.
November 5, 2024 at 6:04 AM
This is so much more than I expected. May be the best conversation I've read. Both people are smart, sensitive and insightful.

https://www.nytimes.com/2024/11/04/opinion/ezra-klein-podcast-jon-stewart.html
November 4, 2024 at 4:49 PM
And another truism of our youth founders on the rocky slopes of science as continents get the Pluto treatment.

"Other experts contend that five, six and seven are wrong and argue in favor of eight continents. There are even those who go as far as to say there are only two." […]
Original post on mastodon.social
mastodon.social
November 4, 2024 at 3:31 PM
Me? I prefer collaboration rather than submission but this is an interesting experiment that expanded my idea of how to use AI.

"Generative A.I. had made decent decisions more quickly than I would have on my own and hadn’t made any terrible mistakes, but it also hadn’t wowed me." […]
Original post on mastodon.social
mastodon.social
November 3, 2024 at 4:00 PM
Send this to some young people.

"No one is coming to save us. We have to save ourselves, and each other. Any of the issues you care about will be impossible to fight for under a Trump administration."

https://www.teenvogue.com/story/kamala-harris-but-a-donald-trump-win-would-be-catastrophic
November 2, 2024 at 5:10 PM
Cruising, as I like to do, the right-wing-o-sphere, I ran into this concern. Kamala will BAN THESE CRUCIAL DRUGS!!! What drugs? Trump faves, Ivermectin and Hydroxychloroquine.

What to do? The article includes a helpful link to the Contagion Emergency Kit. Hilarious […]
Original post on mastodon.social
mastodon.social
November 2, 2024 at 5:01 PM
We all have our moments of frustration with the NY Times but in this moment where the other big news outlets show their fecklessness, the Times is standing proud for decency and America. This editorial is shocking and powerful. Vote for Kamala […]
Original post on mastodon.social
mastodon.social
November 2, 2024 at 3:24 PM
This is fascinating. It's about sugar but what other things have a lifelong influence. Glad I don't have children to worry about.

"People who were restricted to limited amounts of sugar in the first few years of life were less likely to develop diabetes and high blood pressure decades later, a […]
Original post on mastodon.social
mastodon.social
November 1, 2024 at 2:04 PM
Wishing you had actual, specific information to support the obvious reality that women don't carry a baby for nine months and then change their mind?

"Yet these [anti-abortion] researchers, too, say their work has been misinterpreted and does not support the claim that many late abortions […]
Original post on mastodon.social
mastodon.social
October 31, 2024 at 2:51 PM