• Seth Taylor@lemmy.world
    link
    fedilink
    English
    arrow-up
    26
    ·
    1 day ago

    “That thing you use for security? Disable it before you come in. Come on, live a little, huh? 😏 Nothing bad’s gonna happen. Pinky swear.”

  • archchan@lemmy.ml
    link
    fedilink
    English
    arrow-up
    113
    ·
    2 days ago

    Your browser is unsupported. Switch to Chrome to enjoy the full experience.

    Download our app to get the full experience.

    Please sign in to confirm you’re not a bot. This help protect our community.

    Turn off ad blockers to access our website and help fund our data mining blog.

    Access the full article for only $100 a month!

    “Something went wrong. Try again later” (turn off VPN)

    Xitter doesn’t support strict tracking protection in Firefox.

    Create an account to do this thing you don’t need an account for.

    Also we have 3 captchas and 7 MFA steps you must complete. Please verify your birthday and social security number.

    blank white page after sign in, with password manager pop-up attempting to save a passkey

    Upgrade” to Windows to use this website.

    This content is 18+ only and requires an ID/face/genital scan.

    “Ask me later”

    No, no, and have I mentioned no. Furthermore, fuck you.

      • dogs0n@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        13
        ·
        1 day ago

        That’s because THEY FOUND MALWARE IN A RELEASE i saw a post about it yesterday. Think the devs have fixed it now but BEWARE if you had sensitive info on your device.

        • saltesc@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 hours ago

          Could be one of the fake ones. Need to get it from the drv’s git, not the websites claiming to be him.

          • dogs0n@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            3
            ·
            5 hours ago

            SmartTube’s developer told me that the computer used to create the APKs for the project’s official GitHub page was compromised by malware. As a result, some official SmartTube releases were unintentionally released with malware.

            The news post going around: https://www.aftvnews.com/smarttubes-official-apk-was-compromised-with-malware-what-you-should-do-if-you-use-it/

            The new versions should be clean however:

            Users who may have installed the malware-infected versions of the app are recommended to reset their devices and take additional steps to review their YouTube and Google account information. https://www.androidauthority.com/smarttube-malware-fix-3620773/

            If you were logged into anything, probably best to change your password to be safe (and delete all sessions to unauth every device)!

            Next time you see an alert like that, definitely research it before trying to work around it and install possibly infected software (i know there possibly wasn’t any news when the alert went up, but i’d way a day then look it up again before continuing).

      • UltraMagnus0001@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        1 day ago

        Updated my shield and play protect disabled smartube, WTF. Fyi go to github and update smartube, because the original version signature was compromised and the developer has an alternate version.

    • Raffen@lemmy.zip
      link
      fedilink
      English
      arrow-up
      13
      ·
      2 days ago

      Those newsletters you never signed up to, you click “unsubscribe”, then the site you get directed to just happens to not function… block domain it is.

      This app does not allow rooted device. Click here to see how to unroot.

      Cookies: Click to accept all, or drop down where you painstakingly have to uncheck all bullets.

      Every gadget needing internet access. Forced firmware updates.

    • thermal_shock@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 days ago

      blank white page after sign in, with password manager pop-up attempting to save a passkey

      Haven’t seen this one, not surprised. Seems sketchy as fuck.

      • Potatar@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Try scientific journals, when the intended abuse target is publicly funded (universities), they go cray

  • tomiant@piefed.social
    link
    fedilink
    English
    arrow-up
    16
    ·
    1 day ago

    Yeah. Never you mind where the fuck I’m actually from. You don’t need to know. It’s funny how badly you want to know though.

    • WhyIHateTheInternet@lemmy.world
      link
      fedilink
      English
      arrow-up
      51
      ·
      2 days ago

      I instantly back out then block that site from showing in my news feeds or whatever. I am absolutely done playing this game. America sucks so hard its vacuum has consumed every aspect of most people’s digital life. Not just Americans either.

      I used to do email marketing analytics for JP Morgan like 15 years ago and the amount of resources being thrown at gaining personal info then using that to trick people into clicking a fucking advertisement or affiliate link for fractions of a penny is disgusting. And they would have me use heat maps to see where people hover their mouse while reading their shitty newsletter so they could place a clickable link in that spot just so accidental click through numbers could be inflated. I even regularly changed the color of a banner or a text so slightly you couldn’t perceive it because that particular shade of orange had more read time or clicks than the other with a subset of the targets.

      I had massive spreadsheets with shit on people like food allergies, household populations, and how that related to clicks or opens and then target those people with a particular color or layout on the emails to increase the success of the campaign. All because they clicked “I agree”.

      Disgusting shit and that was 15 years ago. I didn’t even live in the same country as the people I worked for and never once saw or talked to anyone I worked for. Good pay though.

      • Cruxifux@feddit.nl
        link
        fedilink
        English
        arrow-up
        14
        ·
        2 days ago

        That is the most horrifyingly dystopian shit I’ve heard all year man. And it’s been a hard fucking year for that shit. I don’t fault you for taking the money but I absolutely loathe what you’ve helped create.

        • WhyIHateTheInternet@lemmy.world
          link
          fedilink
          English
          arrow-up
          19
          ·
          2 days ago

          I was just labor. I didn’t do more than extract the data, compile it, then wait for the email telling me what color hex to put where and which group identifier to send it to. I wasn’t as much of a thinker back then and one day I was looking at the data as I organized it and was wondering why the hell do they know John Doe has 3 kids, rents, and had a shellfish allergy?

          Then I realized pretty quickly what my job really was. The real terrifying part was those spreadsheets just lived on my laptop. Not password protected or any proprietary software. Just Excel and gmail to send them to whoever I worked for so they could send me the next week’s campaign layout. Then I built the emails, added the links, sent them off to thousands and thousands of people grouped by whatever standards had been set that week. More than that, I obviously used a software for mass emailing, but my list of recipients was just another spreadsheet with countless people’s email, names, and phone numbers.

          I now realize why these huge data beaches occur everywhere from these giant corporations. You think they’ve got “security” or whatever and they protect your info. In reality a 26 year old stoner with a MacBook used for watching porn and pirating movies and games using whatever basic ass free antivirus software has all of it in a folder, labeled email list, literally on his desktop with an unbreakable pin of 1234, being employed by people who have never seen, heard, or talked to.

          And he doesn’t even realize the implications of having this at all. I’d like to think things have gotten more strict with security and whatnot, but if that was true it wouldn’t happen so often.

          • cheers_queers@lemmy.zip
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            1 day ago

            I am screenshotting and bookmarking this for next time someone ribs me for how mad i get over the incessant advertizing or the data harvesting. It is exhausting to be made felt like I’m overreacting when it should be the normal response for your own home and devices to be constantly raped by ad-gorithms. FUCK MARKETING.

          • Cruxifux@feddit.nl
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            Well if the reality of what we see daily is any indication then it has gotten exponentially worse.

            I don’t really know what we do about this besides just shutting down the internet. Kind of a lost cause. Capitalism has almost entirely ruined the internet. I don’t think it’s saveable at this point.

      • OhVenus_Baby@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        How is this even possible to do. Heat maps and knowing all of this data? Wildly new to me that this was even possible let alone 15 years ago.

        • WhyIHateTheInternet@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          2 days ago

          Like this usually. At least in my experience…

          “Sign up for your chance to attend “name event here” for you and 3 of your friends or family! You won’t want to miss this investment opportunity as our special guest “fuck head” talks about the investment potential of upcoming alternative energies! Just fill out this form below or click here to reserve your spot.”

          The form would obviously need things like, what are your investment goals, do you have dietary restrictions, would you like to receive future communications about other exciting opportunities…

          The heat map thing is nothing new and still def around. If you click I agree and don’t bother to spend 8 years reading the fine print I guarantee you have a profile similar to this. Same as me.

          The info is easy to get, people just need incentive but the better you can hide the reason for needing it (you might eat here if you win we need to know what you can’t eat) or you are interested in setting up a college fund for your X amount of kids… The easier it is to mine that info.

          I wish I was making this stuff up but I was an amateur back then and the capabilities nowadays are faaar beyond that. It’s manipulation plain and simple.

      • Cruxifux@feddit.nl
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Seems to work if you’re logged in to your Tv Tropes account. But why the fuck do I need a TV tropes account? Idk maybe your ad blocker is better than mine.

  • u/lukmly013 💾 (lemmy.sdf.org)@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 day ago

    And then there’s the mysteries like OneDrive, where I cannot upload without VPN. Either it keeps failing or it’s slow.

    With a graph, here’s what it does without and with VPN, and eventually fails without one:
    image hosted on catbox.moe image hosted on catbox.moe

    • causepix@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      Google drive/photos downloads also fail when I’m on vpn.

      I want to switch to self hosting but I’m only just getting to the point where I can think about doing projects like that and I have several priorities ahead of it. So don’t come at me for using google lmao.

  • DrDystopia@lemy.lol
    link
    fedilink
    English
    arrow-up
    31
    ·
    2 days ago

    Might as well require a log-in with a free* account (No monetary payment required, please don’t read the part about data sharing in the TOS).

    • causepix@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      1 day ago

      Reminds me of an article I scrolled past about Amazon generously “slashing away the margins” to sell their latest spyware “at cost” this cyber Monday.

    • henfredemars@infosec.pub
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 days ago

      How odd. I have never heard of .world filtering based on VPN usage, although it’s been some time since I used that instance regularly.

      • Z3k3@lemmy.world
        link
        fedilink
        English
        arrow-up
        11
        ·
        edit-2
        2 days ago

        I can read without issue but more often than not posting comments or indeed posts fails unless I pause for 5 mins.

        E. This went through without disconnecting as an example. Can’t figure out if threshold a pattern

        • io@piefed.blahaj.zoneOP
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 days ago

          maybe the particular server of the vpn haz problems? have your tried switching that around?

      • Mose13@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        In my experience, many Lemmy instances block what looks like bot traffic. I don’t think it’s as simple as VPN = blocked, but that’s probably one of the signals they pay attention to. I’ve noticed most comments will fail to post when I’m using Mullvad.

          • Mose13@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            1 day ago

            I’m totally guessing but I’m guessing it’s more similar to:

            • Accessing from a business owned IP: +20% risk of abuse
            • Accessing from C country: +10% risk of abuse
            • The rate that you’re making requests: +5% risk of abuse
            • Etc

            Block if risk of abuse exceeded X%

            I have no idea what I’m talking about, but I can’t imagine these companies aren’t using some pretty advanced detection of bot traffic

  • BenLeMan@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 days ago

    Joke’s on you when their website is wrapped in an app that you have to use.

    Happened to me recently with the app I use to buy train tickets.

    • Cousin Mose@lemmy.hogru.ch
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      On iOS I go into App Privacy Report and grab all those domains and put them into Tailscale to route through the correct exit nodes.

      Usually it’s just one or two domains like api.example.com, CDNs typically don’t care and I block the other third-party shit via DNS (Blocky).

  • tempest@lemmy.ca
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 days ago

    So, the problem with VPNs is that the cheap ones / resellers have known IPs.

    So if you use them you get lumped in with all the people using them maliciously.

    If you run a site with any kind of desirable the content the crawlers and scripters hound you endlessly and eventually if you don’t want it to be your full time job you just end up banning the entire IP/ ASN that the malicious traffic is coming from.

    It sucks and if anyone has any solutions I’m all ears.

    • io@piefed.blahaj.zoneOP
      link
      fedilink
      English
      arrow-up
      12
      ·
      2 days ago

      first, the ips of all vpn providers are known, the problem with the cheap/free ones is that they spy on you.

      instead of blocking ips use proof of work for those sus ips https://github.com/TecharoHQ/anubis

      (it’s the anime girl that checks if you are a bot. :3)

      it drives the cost of crawling at scale high up while being minor for individual, “legit” requests

      all the cool kids are using it

  • rook@lemmy.zip
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 days ago

    Stuff like this shows you who is just there to sell your data, and not sell you an experience.

      • Its a brave thing to fight, I admire it, but please don’t shame others for leaving. People have the right to choose.

        Sometimes you can save it. Sometimes it’s beyond saving.

        My family left China about 15 years ago, to be clear I didn’t choose it, I was just a kid, but I mean like… what the fuck was the point in “fighting”, nobody was fighting there, zero resistance.

        So, it really depends, how much of a hope there really is, sometimes shit is so fucked there is nothing left to fight for.

        I can’t blame people for leaving, even if I may or may not agree with their decisions.