Brutkey

Taggart
@mttaggart@infosec.exchange
Taggart
@mttaggart@infosec.exchange

Imho, our profession doesn't do nearly enough to protect individuals from this kind of activity. Look at the losses: $700M in 2024, with most of the losses in amounts over $100k. That's staggering. That's life-destroying. And it's preventable.

https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/08/false-alarm-real-scam-how-scammers-are-stealing-older-adults-life-savings

Taggart
@mttaggart@infosec.exchange

@90sScriptKiddiw@kolektiva.social I'll also point out that "demanding payment" is also going to be known as "requesting reasonable compensation" as advertising fails as a business model on the web. Buckle up.

Taggart
@mttaggart@infosec.exchange

This is happening, no matter what spin Google puts on click data. The fundamental economic agreement about the internet is now imperiled, and big tech has only themselves to blame.

https://www.economist.com/business/2025/07/14/ai-is-killing-the-web-can-anything-save-it

Taggart
@mttaggart@infosec.exchange

Most here understand, but perhaps do not yet fully practice, the extreme levels of scrutiny required for all forms of media now. The level of deception goes beyond anything we've known before, both in quality and in quantity. There is as much unreal as real presented to media consumers. That scale will flip soon, if it hasn't already.

And what do we do when the shared fabric of reality, made entirely of language and meaning, is stained through with slop?

This is why I will not simply accept this cancerous invention.

Taggart
@mttaggart@infosec.exchange

My daughter is big into space shuttles and astronauts right now, so I went to YouTube for videos of ISS EVAs. Of the first ten results, only one was a real video of ISS EVA activity; the rest were slop.

We have achieved hyperreality, and I don't know how we recover.

https://en.wikipedia.org/wiki/Hyperreality

Taggart
@mttaggart@infosec.exchange

For those who haven't seen it yet. The line of reasoning for the conclusion is similar to the argument that there is no safe way to code in Cβ€”an argument I've made.

But I will say that the prevalence of proxies like Cloudflare are part of why this flaw is so impactful.

https://portswigger.net/research/http1-must-die

Taggart
@mttaggart@infosec.exchange

Seeing as even Bruno has now monetized and become less useful, here's this for @Sempf@infosec.exchange and my other API testing pals.

https://github.com/darrenburns/posting

Taggart
@mttaggart@infosec.exchange
nuclear war

I grew up under the gospel of "The bomb was the lesser of two evils" to end WWII. If you still feel this way, this essay is essential reading.

That myth seduces us into believing there's a moral case for nuclear weapons. There is none.

https://www.lawfaremedia.org/article/the-world-learned-the-wrong-lesson-from-hiroshima

Taggart
@mttaggart@infosec.exchange

Delver (n): Someone, putatively human, who only responds in ways indistinguishable from generative modelsβ€”perhaps because every response is provided by them.

If we're gonna have a cyberpunk dystopia we might as well have fun lingo.

Taggart
@mttaggart@infosec.exchange

Let this be a warning to all companies (lookin' at you, healthcare) that trackers can be justified in any part of the user experience.

https://arstechnica.com/tech-policy/2025/08/jury-finds-meta-broke-wiretap-law-by-collecting-data-from-period-tracker-app/