Show newer

The e-mail purports to be from a supplier, more specifically a contractor; it has all the right business speak that a contractor might actually use when trying to gently remind you of an unpaid invoice.

The "end of fiscal year" adds further pressure; it sets a deadline for the payment of the invoice, and crucially makes that deadline something that is imposed by a third party; that way, the scammer discourages attempts to argue about the payment term and makes faster payments happen.

Perhaps you *do* reply, though, to inquire about the line items, despite your "colleague"s approval - the e-mail will go to an e-mail that's *wrong*, but not obviously so!

A lot of companies legitimately use Sendcloud for their internal e-mail affairs, and so it going through a Sendcloud address is a credible thing. This domain, sendcloud-management.com, is probably not actually owned by Sendcloud, but it will *appear* to be to a hurried accounting employee trying to keep a supplier happy!

Show thread

This is an excellently-written attempt. First of all, the headers. The subject line is crucial here - "Overdue since January" puts on the pressure, trying to make the reader panic, believing that they've somehow overlooked an invoice for months. This makes it likely for them to overlook small things that aren't quite right.

The sender, for example; it's worth noting that the person named here, Kris Marszalek, *does not exist*. It's a randomly generated name! This takes advantage of the fact that in most companies, most departments have *no idea* who actually works there, and will just assume "oh, that must be the new hire".

The e-mail address for both the From and Reply-To headers may be wrong, but the name (which in some e-mail clients is the only thing that shows!) explicitly includes "via cryto.net" (my domain), making it look like it came from someone inside of the "company".

This is important for the scam; having it be forwarded by someone internal, or at least appearing that way, serves as an implicit 'approval'; it will lead the reader to assume that "oh, someone else already checked this and concluded it's legit".

Show thread

Ever wondered how those corporate invoice scams work, where companies are tricked into paying bullshit invoices for services they've never purchased? Well, I just received one of those, so let's look at it!

I just rediscovered something poetic I wrote in a private forum dedicated to nude photography of ordinary people (not models!). I'm reposting it here, because it's worth remembering:

"A normal body is beautiful in its banality. It is the result of genetics and the physical labors and ordeals that this body has endured. The fact that an ordinary person is willing to let the world see their banal or 'imperfect' naked body celebrated in art is a gift to us all."

#bodypositivity #bodypositive

Watching the Federated feed and looking up unfamiliar terms is like a 50/50 split of "oh huh, interesting topic" versus "oh god I am instantly exhausted just from reading what this is about"

segregation in sports is unjustified by all metrics. it's unjustified by physical parameters — all people have different ones, and there are men, women (both trans and not) and others who can be both strong and heavy or more agile and light. it's unjustified by psychological parameters — there's no gender-specific differences in brain function. the only reason why sports are gender segregated is because men feel humiliated when they see other genders win

political party, bigotry (2) 

And like, we're talking "literally was one of the main presenters of a fascist TV broadcaster and runs a crowdfunding platform that all the fascists use" here. Their bigotry is not exactly a secret.

Show thread

political party, bigotry 

So it looks like the Dutch Pirate Party still harbours right-wing bigots (Ahmed Aarad, in this case), or at least still tolerates their involvement.

This sort of shit is why I can't take the Pirate Party seriously here.

Kitsune Tails is OUT NOW!! Run, jump, and dash across a land inspired by Japanese mythology and untangle the love triangle between three young women on a journey of self discovery. Explore the complicated relationships between kitsune and humans through classic platforming action.

get it now on steam store.steampowered.com/app/132 or itch eniko.itch.io/kitsunetails

we're a small underfunded team with a majority queer developers, and while we're punching way above our weight class we need the support of our community if this game is going to be a success. please boost this post, and if you can afford it buy it on steam and leave a positive review on the first day (the text doesn't matter, only the thumbs up, so "i like gay fops" is totally valid as a review)

i also want to prove fedi is powerful enough to make an indie game succeed, so even if you're not personally that into the game, please boost this post? 🙏

#KitsuneTails #QueerGames #GameDev #PixelArt

something that i like about the fediverse culturally is that it's... instances going offline is not something we love but it's something we are used to, it's something that is Known by everyone, and i think that's important.

one of my strongest philosophical stances is that we should look at the ends of things with unafraid eyes

You will never advocate politely enough about social justice to please someone whose lifestyle depends on social injustice.

Wanted to look up where the word "critter" comes from so I just absent-mindedly typed in etymology.com into my address bar and apparently that website is just an emoji of an orange and nothing else.

Time for the periodic "how are ESM-only modules on npm doing" update:

Looked at some arbitrarily selected popular sindresorhus modules (delay, p-event), and >90% of installs continues to be of (now at least 4 years old) CommonJS versions.

Yeah, I don't think this qualifies as a success for ESM.

Two years ago, I experienced Sudden Sensorineural Hearing Loss (SSNHL), and am now almost completely deaf in one ear. This year, one of my colleagues had the same thing. Now I see there's a study out showing a strong correlation between COVID and SSNHL.
I guess that explains a lot. But, shit.
BTW If you find you suddenly lose hearing in one ear, get yourself to a specialist *immediately*. You have a 24-36 hour window to save your hearing before it becomes permanent.
thelancet.com/journals/eclinm/

hey dont tell people "holy shit your phone is old you should get a new one, the security issues!!!!"

do you really think i am happy that my phone that ive only had for six years doesnt get security updates despite working fine?

do you think i can afford to replace it?

"well then you should get a dumb phone and use your laptop for other things"

are you fucking kidding me? really? 1) my laptop is even older, it's 17", and takes like 5 minutes to start up, im not carrying that everywhere and 2) MOST THINGS DONT HAVE FUNCTIONAL WEBSITES ANYMORE

and really, do you think i should have to afford to replace it?

there is no reason my Pixel 3, which runs apps PERFECTLY FINE, should be abandoned to the ages. it's also one of the few Pixel models that cant even be given a new OS, since no one has worked out all the model-specific issues with it.

there is no reason i shouldnt still be getting updates, and no reason i shouldnt be able to easily switch to GrapheneOS or something else.

stop calling me a bad user for being 1) poor and 2) unwilling to give in to manipulative capitalist planned obsolesence. yell at the people making these decisions. my phone is intact after six years. im proud of that and i will use this until it goes spicy pillow.

PS give us back battery replacing, SD cards, and headphone jacks

(And this is not even going into the governance issues which somehow always seem to get left out from the security discussion, even though that is *absolutely* a security-relevant factor.)

Show thread

The thing with "just use Signal" is that it isn't actually suitable for larger (public) rooms, and so isn't a wholesale replacement for other messenger and chat platforms.

Like, sure, re-encrypting the message for every individual recipient, which AFAIK is what Signal does, is easier to implement right than having a shared room key. But it also hard-caps how many people you can plausibly be messaging at once.

Wie bij alleen al het idee van duurdere brandstof naar zijn gele hesje grijpt, doet er goed aan zich te verdiepen in de Canada Carbon Rebate. Het geld dat de Canadezen hieraan kwijt zijn wordt op de eenvoudigst mogelijke manier teruggegeven aan de bevolking. groene.nl/artikel/klimaatbonus

Please boost for reach! :boost_requested:

A friend of mine (currently based in NL) is looking for a remote job. They're looking for something related to web development, or maintenance of legacy codebases (web or otherwise).

They have experience with web/software development (Java, JS, assorted other web things), as well as reverse-engineering Java software, but no employment experience yet. Also a few years of basic NixOS experience.

They can pick up and learn new things very quickly, but they do need a work environment that is friendly to queer neurodivergent folks.

If you have a suitable job available (or something that's close enough - they're flexible!), please send me either a DM on here, or an e-mail at admin@cryto.net. I'll get you in touch with them.

griping about hadware store 

It baffles me how the local hardware always manages to not have the thing I need. Absolutely terrible stock management.

Like, how do you run a hardware store in a middle-class neighbourhood, in the middle of summer, and *not* carry some sort of airco-safe cleaning agent?

And it's not like I won't be able to find it elsewhere, it's not a *problem*. I just don't understand how they get things like this so consistently wrong, because I bet they're leaving a lot of money on the table.

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.