849 karma · joined September 23, 2021
Anecdotal, but once I sold a GPU to a buyer (which I knew was working), who reported it as defective. He initiated a return and I accepted, as is part of the normal selling process. I then randomly received a toe ring from Amazon addressed to someone that was not me but at my address (luckily it was the name of my parents' dog, so I held onto the package). The buyer then called ebay and said the return was complete and provided the tracking to show it was delivered to me.
I was made aware of this when I got an email saying that the return was complete and the buyer had been refunded. I called ebay to dispute it, since I hadn't received a package. I looked up the posted tracking number, and it represented a shipment from FL to me (PNW) whereas I sent the gpu to NY. It also said the package was 1 lbs, which would have been impossible because the gpu was listed as over 2 lbs by the manufacturer. I explained this to the nice customer service rep. We agreed the buyer could have relocated in the past week but the weight was unexplainable. She couldn't undo the transaction but escalated my issue. A couple days later I got an email saying my case was closed and ebay was siding with the buyer, so I was out the $400 they paid for the gpu since ebay wouldn't release the funds. I was in shock, but I called usps because I thought I must have been missing something. Usps takes pictures of all mail, and the nice man on the phone that called me back looked up the package and described it to me. I then realized it was the nose ring Amazon shipped to me that I thought was a weird Halloween joke from my parents related to their dog. I then emailed every first.last@ebay.com explaining my issue, stating that I, as a seller, could no longer take on the risk of selling on ebay because I had no protection in the case of an obvious scam. The next day I got a call from a secretary, and I explained everything to her, including that, had this been my work, my president would have called me and others into her office and played the recording of this phone call, concluding with, "Go fix this and make sure it can't happen again."
I got lucky and was given the payout. Ymmv.
Can't you just enroll your kid's devices in your home corporate and leverage MDM to force the network to call through your proxy, which denies or downgrades all ECH and then can actively filter to an allowlist or screen the material through your personal or contracted LLM?
This seems relatively solved to me.
Nowadays it seems a lot easier because there seems to be a separate profile isolater you can run in the main profile, which I would choose if I was installing today.
The only hiccup I've had is that sometimes group messages don't send correctly and send individual messages to everyone, but I think that's because I'm on a secondary profile, and it only happens when the phone is receiving a bunch of messages all at once while I try to send to the same group. But I deny network access to my installed swype keyboard, so it may have something to do with that too.
I've been running this for years, since the Pixel 7 came out, which I'm still using.
I love it. I can confidently go through customs knowing that if they yank my phone during some weird checkpoint and try to celbrite it, I'm as secure as can be.
I threaten to kill and rape them all the time, but that usually doesn't do much.
I've found that politely asking them to kill themselves elicits much more engagement, and I hope it at least implants some lasting memory.
Only slightly better than this would be to break in, install a root kit, and then leave everything else untouched so as to try and minimize the knowledge that I was there, but I'd still be concerned that my c2 server would eventually point to me.
Maybe I should read about these actual crimes or get meds. The first couple years of my first kid's life were full of anxiety that someone would break in and steal my kid while I was sleeping at night.
Isn't this rather trivial? You gen a keyfile, register it with luksAddKey, then update /etc/crypttab, no? The real concern is making sure that keyfile is stored securely, but you can simply symmetrically encrypt it and upload it to your favorite cloud storage provider.
My primary concern is a robbery while I'm not home. It's trivial to break in, steal hard drives, and then go pop them into another machine on your own time to scan the files looking for tax or other sensitive docs.
While encryption keys are a risk, you can always save the random key file or passphrase in cloud storage (using symmetric encryption) and/or in your password manager.
Hedge funds already know broad based mutuals will have to purchase these so can sneak in before them and then sell to them for a marginal gain. Mayhaps the newest strategy for exiting is generating so much hype that you're guaranteed an exit by retail retirement funds?
In my view, anyone participating in these markets does so knowing that the outcomes are within the control of other participants. I can't think of any other reason individual account activity is public.
My personal preference would be to allow nearly unlimited legal immigration but strip welfare programs for all. In this way we allow anyone and everyone to become an economic participant, voting participant after the naturalization process, and mitigate those immigrating purely for handouts.
But I haven't thought through this policy well. Maybe there is something this seemingly solution is missing.
- The feds show up
- A bugular breaks in and grabs your computer
- You're selling your house and host an open house
- You have curious children and want to keep them from live booting and reading your tax returns
My hypothesis is that this would lead to demands for policy changes to prevent that, which can realistically only be done via actual identification or hardware based attlestation (which is identification).
Does that seem wrong? If we didn't care if people could bypass the system, there is no reason to force even privacy preserving barriers, since parents literally have all the tools necessary to deal with this now, from router guards, to parental controls on computers, to device enrollment for iPhone and android systems.
I recognize, in some capacity, that this isn't the norm and in the US "professional engineer" is protected and not simply "engineer", but it feels akin to stolen valor to me.
You probably risk some legal fallout though, so be cautious.