#travel check list
Explore tagged Tumblr posts
Text
im travelling internationally for the first time in a couple of days, if anyone has any advice please send (:
#travel#international#international travel#travel tips#travel checklist#travel check list#advice please
0 notes
Text





Carlos Sainz | F1 London Live in 2017 | x x x x x
#carlos sainz#autumn posts#explored this event last eve and omg so many wonderful moments!!!!#oh to be able to time travel 🚀 surfing the web will have to do!!#also I'll still reblog and post RBR of old and Max related content in 2025 but#wow they have made some immensely frustrating decisions as a company#I do sure despise their upper management!#also tbh I am glad newbies get chances but it seems like 2025 is going to be maybe too many rookies maybe o.o idk I just got here#and I know F1 teams are probably trying some succession planning and lots of new brands hopping on seem geared to younger fans#and I love Gabi and Jack and I'm sure Ollie and Kimi are great! idk them as well yet! and I miss Franco :(((#but idk I'm already missing the older drivers we lost like what do you mean Carlos is fourth oldest he's my age 🥲#idk I like grizzled old men!!!! and drivers who are still in their prime!! 30s isnt old!!! (I know it is in the world of f1 but...)#idk I know big F1 is trying to plant seeds but they're pulling up perfectly gorgeous trees to do so....I just got here too!!!!!!#hmmmm rambling balogna from a new fan#also I dont like watching cars crash so really really hoping the races next year with all these green drivers aren't too bad 🫣#idk I get worried!! and all the engineers and bts folks have to deal with wrecks so#mannifesting safe drives and good starts 🙏✨#and rbr and vcarb are on my shit list for now but the Max blogging will not cease#he and I will both be in our sixties and I'll be here salivating hehe 😵💫✨#gosh dad bod Max 😵💫❤️✨ heaven help me the thirst blogging will be off the charts here#okay enough yapping!!!#wishing everyone a v excellent Friday!! ☀️☁️🌙✨#brb soon to spam F1 Live in London content bc oh gosh what a rich well#also I won't spam too much hehe I'll space it out#also the Little Mix girlies (gn) were OUT at this event so that was fun!!#an insta feed of F1 drivers and a ton of Little Mix bloggers since they performed there! and I like Jade!! I gotta check when her albums out#okay autumn out!!! 🫡❤️✨ bye for now!
75 notes
·
View notes
Text
#one piece#sanji#black leg sanji#everysanji#dressrosa#ch701#first chapter being queued in 2025 babey#some work life updates ig... i have started officially learning both the pasta bar and the sushi bar#truly becoming more and more like sanji every day /j#but im sooooooo ready to be done with this job#i enjoy working in restaurants enough and it'll always be smth i can fall back on but#i'd much rather be in museums and education type fields...#ive got a seasonal work site bookmarked so i'll check that around july and august#and see if i can find anything. there are so many interesting summer jobs listed righ tnow#like if i wasnt attached to my current summer job or wanted to try smth new i could just#move to maryland and learn how to sail historic sailing vessels for 4 months#or go to alaska and do day boat tours/cruises#which i just might someday idk they both sound really interesting and right up my alley#and thats kinda what i love about seasonal work... able to travel a lot and get paid to do it#and you can find jobs that provide housing so you dont even have to worry about that#the downside is that my legal address is still my parents place and none of these places provide insurance#so once i turn 26 next year i'm sol there. i'll cross that bridge when i get there ig
9 notes
·
View notes
Text

TIME TRAVEL ACHIEVED
#Check that one off the bucket list#Next up is teleportation#Humor#River rambles#Time travel#daylight savings
11 notes
·
View notes
Text
.
#tag talk#been exploring the pessimism and nihilism subreddits and honestly? not vibing.#I was hoping to relate some since I've been really mulling over the question of meaning and purpose in the world but nah.#feels like it's just average depression posting.#feels like people say “nothing matters” when really they mean “I find no meaning in things normally considered good”#like.. bro you're denying value to “good” things while still according value to “bad” things#you're still caught up in the game of assigning worth and value arbitrarily#if nothing matters then who cares if you're sad? why does that matter?#I'm tired of being sad. so what? life continues until it doesn't. who gives a shit?#I really need to read up on more philosophy shit. stoicism is next on my list to check out#if life is worth dying from then it's worth living for. neither path is more valuable than the other. pick one and travel it#r/nihilism is so fucking funny actually#I should have checked out this sub ages ago
2 notes
·
View notes
Text
If you're wondering how much I hate travelling. My brother is getting married in a month and today I got so nervous about it I packed my entire suitcase.
#its gonna stay packed im just gonna use other stuff#im going to have to fix some shorts and trousers tomorrow otherwise i will have no outside clothes#life of dan#packing and checking my lists makes me feel in control over the inherently uncontrollable state of travel#at least i wont have to do an atlantic crossing this time#hes not having a destination wedding its just gonna be in his wifes country#so its a destination for me but not for most of the guests
4 notes
·
View notes
Text
aaaand a ranni meme made the front page of reddit time to seethe forever.
loveless marriage????
LOVELESS MARRIAGE???????
DID WE EVEN PLAY THE SAME GAME?????
DO STRAIGHT CIS MEN JUST NOT KNOW WHAT LOVE EVEN IS?????
Ranni is so down bad for the Tarnished from the beginning that even fucking SELUVIS notices, my fucking god
#LOVELESS MARRIAGE???? LOVELESS MARRIAGE?????#ARE YOU BLIND AND DEAF AS WELL AS DUMB AND JUST PLAIN STUPID??????#should i add thee to the list? another kind of heart#as kind of heart as they?#...Ach. this form hath loosened my tongue. I've let slip too much. Forget what thou hast heard. *Forget.*#beautifully fought. 'twas more difficult than i envisioned. my thanks. now i can finally stand before them.#this is farewell#my dear#tell blaidd and iji... i love them#so it was thee who would become my lord#perhaps i neednt have warned thee#i am pleased however; thou'rt a fitting choice#i go now to the night sky it is there i shall find mine order#i bid thee travel the path of lord#and once all is done#we shall see each other#once more#wouldst thou come to me even now?#my one and only lord?#let us go together#my dear consort eternal.#mooost of that was done from memory but i did check the wiki for some wordings and hilariously the wiki is wrong for some while im right#robins eldring tag
6 notes
·
View notes
Text
Man being rich, you really just get to actual enjoy what the world can offer, that’s actually fucking bizzare & cruel.
#ofc i’ve always been aware of this#but they get to just travel??? everywhere???#seing everything their could be to offer?#check off all their bucket list#and regular people MAYBE get to check 1 thing of their bucket list off#and even that’s not guaranted#megaras thoughts
3 notes
·
View notes
Text
Headcanon time: Coran has made a travel guide, Coran’s compendium, detailing the best tourist spots to visit on many of the planets he has visited.
#rambling into the ether#there’s so much rambling in this one. sorry guys#vld#Coran#vld Coran#coran coran the gorgeous man#Or headcoran if you will *badum tss* that was bad#He makes instruction videos. Seems like something he’d do. He wants to update the guide. Having learned from mall#fiasco that things. kinda sort may be different in *checks calendar* 10000 years. When they do#have downtime he tries. It’s a shame. So many places on his list. So so different. Maybe even nonexistent. He’ll never go again.#The universe has forgotten them. Think Aang travelling around and finding places to be run down. They’re both so out of time.#Allura too#So anyway this headcanon came to me from a dream. Vld brainrot so bad it has entered my dreams. Wasn’t even a vld themed dream. But boom.#Suddenly I’m looking at this electronic travel guide. And there’s Coran. Smiling in a photo at one of these locations#(there was also this kinda spooky location he’d drawn himself into. That whoever I was with wanted to visit. Anyway).#Love that Coran jump scare. Also of note. Many of the locations had lions in them.#I distinctly remember at least 3 images with lion statues. Staying on brand. Nice
3 notes
·
View notes
Text
going "why'd i feel like it was monday for a sec" earlier & immediately answering it with "oh yeah b/c the summer stock performances 'weekend' is mondays & tuesdays off" and going Whoah just now refreshing myself on the exact schedule when this is the first wednesda & thursday of performances, like, kicking off both days w/2 pm matinees
#having this Enrichment when not only is it [i want to see it] but also feeling more liable to Have Posts than like#casually checking up on a recent off broadway limited engagement like Where's The Posts. where's someone's filmed curtain call. hewwo#even a limited broadway production w/its own dedicated twitter account like Hewwo you never finished your thread hellooo#meanwhile out here Regionally like. erika amato our number one poster it seems....checking up on those fb or ig accounts....etc#it's the revelations that can come through these glimpses like ''idk why the guy in ireland with a pbs travel series had some professional#involvement with the show but he posted the pics ft. the first page of Director Notes & scenes / musical numbers list''#or an ensemble member with a cropped pic of a page of sheet music which confirms [orville gets to sing at all including in a song i already#guessed he'd get to participate in based on detective legwork re: that ireland travel series guy's tweet] ft. harmonizing lyrics w/phil#fun to have something that's at a balance of like; i can't be thee most comprehensive but i can And Will do some fairly thorough digging#and i'll do it more than once especially when like [exhaustively checking for all listed cast & creative team's instagrams] done once can#confirm that not all of them as posting regularly (mostly just erika) (but a few others with Any Recent behind the scenes summerstocking)#don't have to try checking in all thee time on the accounts who haven't / don't post recently or at all regularly#and then of course the scraps of info / glimpses are nice for the Yearning To See It experience#summer stock
3 notes
·
View notes
Note
Please if you check out mad rat dead let me know cuz it's one of my favourite games on this planet
Will do!!! I investigated the gameplay mechanics & it’s the first rhythm-based game that actually looks like it’ll keep my attention, which would be a HUGE achievement.
And while I didn’t run into full spoiler territory, I already know I’m gonna love the characters (and will probably get emotional over this reanimated rat and his heart, I just know it).
And THE AESTHETIC!!! Oh gosh, the art is fantastic!
So thanky!!! I’ll for sure check it out sooner than later!
#🎃 cryptid sighting#Plokshouse#Mad Rat Dead#Admittedly I have such a long list of games to check out but my curiosity may bump MRD to the top#The story & look of the characters already have me interested- and the time travel mechanic too!#Already knew the Rat God has something going on- that she’s not quite what she appears -but haven’t had that spoiled yet#So yeah! Looks fun! And possibly deeper than it lets on- which I always enjoy a good emotional gut punch in my games!
4 notes
·
View notes
Text
I absolutely despise this era of AI written website slop
So I've taken care of betta fish for years and this last one I got from my LFS is probably an 'alien' betta based on colors and short fins. Alien bettas are a mix of a wild type betta with the more common petstore genes (if I'm remembering correctly cuz I SURE CAN'T FACT CHECK THAT ANYMORE). Anyways, this guy is the most skittish betta I've ever owned and recently stopped eating. I'm running through my betta health check list to figure out what's wrong and nothing is matching up to what I know. So I'm thinking maybe this is something unique to alien betta behavior. Dude is always hiding more than any other fish I've had so maybe he struggles with the human = food association. Especially since I suspect he nibbled on a shrimp while I wasn't looking. I go to look up alien betta behavior.
In the SAME PARAGRAPH ABOUT BETTAS I get information about alien bettas being passive peaceful fish but also they're super aggressive fish that can't be with other tank mates. Um...
And don't even get me started on betta illnesses. They'll be like 'bettas can get ich, dropsy, and fin rot. Consult your veterinarian on how to treat your betta'
Guys. I have never seen any fish site EVER refer to veterinarians until now. Most fish vets, in my experience, are on call for the big boys. Think city aquarium or fish farms. Betta fish vet care has usually fallen on the fish owner to carry out themselves. But a good chunk of websites on the front page of google are now telling me to take my fish to the vet. Or other VERY inaccurate treatment methods like simply treating ich by turning up the heater (that's only one step of treatment. It also involves understanding the life cycle of ich and the severity. My past treatment of ich has been moving the fish to a hospital tank for a month where I can safely medicate with specific ich treatments while letting the parasite die out in the show tank without a host)
Anyways I came out of this experience learning absolutely nothing because, of course, only forums are giving real answers and the one person who asked a similar question to me never reported their results. Oh and the only website that might've had real person input was selling their own specific betta tea product and jumped right into a shop. I only suspect it was human written because they made a ton of jokes about throwing actual tea bags into blackwater tanks when the leaves just aren't enough. Mood tho.
#vent because WHY#s2g if it gets to a point that I can't pull up fish illness check lists and it all refers to vets Ill scream#I had to learn how to cure bettas of ich fin rot swim bladder constipation and velvet#also taking a fish to the vet is often impractical since you cant take the whole tank#a lot of problems are rooted in the tank itself and you cant bring that with you#like water changes are step one with sick fish for a reason#but a water test kit is essential to get that quick reading of how much ammonia and such is present for your fish#and stuff like ich is a parasite living in your tank water so a vet can't fix that other than tell you to go buy meds from a store#not to mention how much travel can stress a fish out and make it more ill with the change in parameters#fish can die from shock if their water conditions change suddenly#man and there arent ANY resources for nerite snail illnesses so I can only imagine how bad ai slop is there
2 notes
·
View notes
Text
How to write smut ?
(@urfriendlywriter | req by @rbsstuff @yourlocalmerchgirl anyone under the appropriate age, please proceed with caution :') hope this helps guys! )
writing smut depends on each person's writing style but i think there's something so gut-wrenchingly beautiful about smut when it's not very graphic and vivid. like., would this turn on a reader more?
"he kissed her, pulling her body closer to him."
or this?
"His lips felt so familiar it hurt her heart. His breathing had become more strained; his muscles tensed. She let herself sink into his embrace as his hands flattened against her spine. He drew her closer."
(Before proceeding further, these are all "in my opinion" what I think would make it better. Apply parts of the advice you like and neglect the aspects you do not agree with it. Once again I'm not saying you have to follow a certain type of style to write smut! Creative freedom exists for a reason!)
One may like either the top or the bottom one better, but it totally depends on your writing to make it work. Neither is bad, but the second example is more flattering, talking literally. (Here is me an year after writing this post, i think, either is amazing, depending on the context. the type of book you're writing, your writing style and preferences!)
express one's sensory feelings, and the readers will automatically know what's happening.
writing, "her walls clenched against him, her breath hitching with his every thrust" is better than writing, "she was about to cum".
(edit: once again, hi, it's me. Either is amazing depending on ur writing style. Everything at the end is about taste.)
here are some vocabulary you can introduce in your writing:
whimpered, whispered, breathed lightly, stuttered, groaned, grunted, yearned, whined, ached, clenched, coaxed, cried out, heaved, hissed
shivering, shuddering, curling up against one's body, squirming, squirting, touching, teasing, taunting, guiding, kneeling, begging, pining, pinching, grinding,
swallowing, panting, sucking in a sharp breath, thrusting, moving gently, gripped, biting, quivering,
nibbling, tugging, pressing, licking, flicking, sucking, panting, gritting, exhaling in short breaths,
wet kisses, brushing soft kisses across their body (yk where), licking, sucking, teasing, tracing, tickling, bucking hips, forcing one on their knees
holding hips, guiding the one on top, moving aimlessly, mindlessly, sounds they make turn insanely beautiful, sinful to listen to
some adverbs to use: desperately, hurriedly, knowingly, teasingly, tauntingly, aimlessly, shamelessly, breathlessly, passionately, delicately, hungrily
he sighed with pleasure
her skin flushed
he shuddered when her body moved against his
he planted kisses along her jawline
her lips turned red, messy, kissed and flushed.
his hands were on his hair, pulling him.
light touches traveled down his back
words were coiled at his throat, coming out as broken sobs, wanting more
he arched his back, his breath quivering
her legs parted, sinking into the other's body, encircling around their waist.
+ mention the position, how they're being moved around---are they face down, kneeling, or standing, or on top or on bottom--it's really helpful to give a clear picture.
+ use lustful talk, slow seduction, teasing touches, erratic breathing, give the readers all while also giving them nothing. make them yearn but DO NOT PROLONG IT.
sources to refer to for more:
gesture that gets me on my knees !!
(more to comeee, check out my hot or kisses prompts on my master list!)
#otp prompts#romance writing#imagine your otp#writeblr#writing prompts#urfriendlywriter#writing inspiration#writing help#writing scenarios#how to write a kiss#how to write smut#physical gestures#romantic gestures#hot gestures#hot prompts#love prompts#smut prompts#kisses prompts#types of kisses#kisses#otp writing#otp things#imagine your characters#imagine your ship#tips to write smut#writing tips#writersociety#writers of tumblr#prompt list#writing
28K notes
·
View notes
Text
It is also 1 in 5 men who have experienced sexual assault
Everyone needs to stop attacking each other. And the the AI-p**n should be considered sexual assault no questions asked. Because this hole thing could have gone an extremely different route. It can very easily end someone’s career, and I think the people who did this should never be able to work again (at the very least).
All the old men a football games (and everyone else who is attacking her) need to stop attacking her because they can’t stand the fact that a woman could take up more attention than men. And they clearly can’t seem to wrap their tiny brains around the fact that a man would date someone who is richer and more successful than himself.
Ok I’m done ranting do the fearless heart of you made it to this point you are amazing!!!🫶



#protect taylor swift#bad parenting#AI#i love how this post is about how men will always find a way to blame a woman for not taking enough care not to be attacked#and your response is basically “well yes women should be more careful surely they are just not aware of the risks”#like if we don't live our lives as some sort of prey animal always on a look out for a predator we are not taking enough precautions#don't post your face on the internet!#don't go out after the dark!#don't go to the club alone! don't travel alone!#carry a pepper spray! carry a gun!#don't go out on a date without doing an fbi-worthy background check first!#shall we go ahead and add “don't date men! run into the woods and join a women commune! don't exist!” to the list?
6K notes
·
View notes
Text
How I got scammed

If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
https://pluralistic.net/2024/02/05/cyber-dunning-kruger/#swiss-cheese-security
I wuz robbed.
More specifically, I was tricked by a phone-phisher pretending to be from my bank, and he convinced me to hand over my credit-card number, then did $8,000+ worth of fraud with it before I figured out what happened. And then he tried to do it again, a week later!
Here's what happened. Over the Christmas holiday, I traveled to New Orleans. The day we landed, I hit a Chase ATM in the French Quarter for some cash, but the machine declined the transaction. Later in the day, we passed a little credit-union's ATM and I used that one instead (I bank with a one-branch credit union and generally there's no fee to use another CU's ATM).
A couple days later, I got a call from my credit union. It was a weekend, during the holiday, and the guy who called was obviously working for my little CU's after-hours fraud contractor. I'd dealt with these folks before – they service a ton of little credit unions, and generally the call quality isn't great and the staff will often make mistakes like mispronouncing my credit union's name.
That's what happened here – the guy was on a terrible VOIP line and I had to ask him to readjust his mic before I could even understand him. He mispronounced my bank's name and then asked if I'd attempted to spend $1,000 at an Apple Store in NYC that day. No, I said, and groaned inwardly. What a pain in the ass. Obviously, I'd had my ATM card skimmed – either at the Chase ATM (maybe that was why the transaction failed), or at the other credit union's ATM (it had been a very cheap looking system).
I told the guy to block my card and we started going through the tedious business of running through recent transactions, verifying my identity, and so on. It dragged on and on. These were my last hours in New Orleans, and I'd left my family at home and gone out to see some of the pre-Mardi Gras krewe celebrations and get a muffalata, and I could tell that I was going to run out of time before I finished talking to this guy.
"Look," I said, "you've got all my details, you've frozen the card. I gotta go home and meet my family and head to the airport. I'll call you back on the after-hours number once I'm through security, all right?"
He was frustrated, but that was his problem. I hung up, got my sandwich, went to the airport, and we checked in. It was total chaos: an Alaska Air 737 Max had just lost its door-plug in mid-air and every Max in every airline's fleet had been grounded, so the check in was crammed with people trying to rebook. We got through to the gate and I sat down to call the CU's after-hours line. The person on the other end told me that she could only handle lost and stolen cards, not fraud, and given that I'd already frozen the card, I should just drop by the branch on Monday to get a new card.
We flew home, and later the next day, I logged into my account and made a list of all the fraudulent transactions and printed them out, and on Monday morning, I drove to the bank to deal with all the paperwork. The folks at the CU were even more pissed than I was. The fraud that run up to more than $8,000, and if Visa refused to take it out of the merchants where the card had been used, my little credit union would have to eat the loss.
I agreed and commiserated. I also pointed out that their outsource, after-hours fraud center bore some blame here: I'd canceled the card on Saturday but most of the fraud had taken place on Sunday. Something had gone wrong.
One cool thing about banking at a tiny credit-union is that you end up talking to people who have actual authority, responsibility and agency. It turned out the the woman who was processing my fraud paperwork was a VP, and she decided to look into it. A few minutes later she came back and told me that the fraud center had no record of having called me on Saturday.
"That was the fraudster," she said.
Oh, shit. I frantically rewound my conversation, trying to figure out if this could possibly be true. I hadn't given him anything apart from some very anodyne info, like what city I live in (which is in my Wikipedia entry), my date of birth (ditto), and the last four digits of my card.
Wait a sec.
He hadn't asked for the last four digits. He'd asked for the last seven digits. At the time, I'd found that very frustrating, but now – "The first nine digits are the same for every card you issue, right?" I asked the VP.
I'd given him my entire card number.
Goddammit.
The thing is, I know a lot about fraud. I'm writing an entire series of novels about this kind of scam:
https://us.macmillan.com/books/9781250865878/thebezzle
And most summers, I go to Defcon, and I always go to the "social engineering" competitions where an audience listens as a hacker in a soundproof booth cold-calls merchants (with the owner's permission) and tries to con whoever answers the phone into giving up important information.
But I'd been conned.
Now look, I knew I could be conned. I'd been conned before, 13 years ago, by a Twitter worm that successfully phished out of my password via DM:
https://locusmag.com/2010/05/cory-doctorow-persistence-pays-parasites/
That scam had required a miracle of timing. It started the day before, when I'd reset my phone to factory defaults and reinstalled all my apps. That same day, I'd published two big online features that a lot of people were talking about. The next morning, we were late getting out of the house, so by the time my wife and I dropped the kid at daycare and went to the coffee shop, it had a long line. Rather than wait in line with me, my wife sat down to read a newspaper, and so I pulled out my phone and found a Twitter DM from a friend asking "is this you?" with a URL.
Assuming this was something to do with those articles I'd published the day before, I clicked the link and got prompted for my Twitter login again. This had been happening all day because I'd done that mobile reinstall the day before and all my stored passwords had been wiped. I entered it but the page timed out. By that time, the coffees were ready. We sat and chatted for a bit, then went our own ways.
I was on my way to the office when I checked my phone again. I had a whole string of DMs from other friends. Each one read "is this you?" and had a URL.
Oh, shit, I'd been phished.
If I hadn't reinstalled my mobile OS the day before. If I hadn't published a pair of big articles the day before. If we hadn't been late getting out the door. If we had been a little more late getting out the door (so that I'd have seen the multiple DMs, which would have tipped me off).
There's a name for this in security circles: "Swiss-cheese security." Imagine multiple slices of Swiss cheese all stacked up, the holes in one slice blocked by the slice below it. All the slices move around and every now and again, a hole opens up that goes all the way through the stack. Zap!
The fraudster who tricked me out of my credit card number had Swiss cheese security on his side. Yes, he spoofed my bank's caller ID, but that wouldn't have been enough to fool me if I hadn't been on vacation, having just used a pair of dodgy ATMs, in a hurry and distracted. If the 737 Max disaster hadn't happened that day and I'd had more time at the gate, I'd have called my bank back. If my bank didn't use a slightly crappy outsource/out-of-hours fraud center that I'd already had sub-par experiences with. If, if, if.
The next Friday night, at 5:30PM, the fraudster called me back, pretending to be the bank's after-hours center. He told me my card had been compromised again. But: I hadn't removed my card from my wallet since I'd had it replaced. Also, it was half an hour after the bank closed for the long weekend, a very fraud-friendly time. And when I told him I'd call him back and asked for the after-hours fraud number, he got very threatening and warned me that because I'd now been notified about the fraud that any losses the bank suffered after I hung up the phone without completing the fraud protocol would be billed to me. I hung up on him. He called me back immediately. I hung up on him again and put my phone into do-not-disturb.
The following Tuesday, I called my bank and spoke to their head of risk-management. I went through everything I'd figured out about the fraudsters, and she told me that credit unions across America were being hit by this scam, by fraudsters who somehow knew CU customers' phone numbers and names, and which CU they banked at. This was key: my phone number is a reasonably well-kept secret. You can get it by spending money with Equifax or another nonconsensual doxing giant, but you can't just google it or get it at any of the free services. The fact that the fraudsters knew where I banked, knew my name, and had my phone number had really caused me to let down my guard.
The risk management person and I talked about how the credit union could mitigate this attack: for example, by better-training the after-hours card-loss staff to be on the alert for calls from people who had been contacted about supposed card fraud. We also went through the confusing phone-menu that had funneled me to the wrong department when I called in, and worked through alternate wording for the menu system that would be clearer (this is the best part about banking with a small CU – you can talk directly to the responsible person and have a productive discussion!). I even convinced her to buy a ticket to next summer's Defcon to attend the social engineering competitions.
There's a leak somewhere in the CU systems' supply chain. Maybe it's Zelle, or the small number of corresponding banks that CUs rely on for SWIFT transaction forwarding. Maybe it's even those after-hours fraud/card-loss centers. But all across the USA, CU customers are getting calls with spoofed caller IDs from fraudsters who know their registered phone numbers and where they bank.
I've been mulling this over for most of a month now, and one thing has really been eating at me: the way that AI is going to make this kind of problem much worse.
Not because AI is going to commit fraud, though.
One of the truest things I know about AI is: "we're nowhere near a place where bots can steal your job, we're certainly at the point where your boss can be suckered into firing you and replacing you with a bot that fails at doing your job":
https://pluralistic.net/2024/01/15/passive-income-brainworms/#four-hour-work-week
I trusted this fraudster specifically because I knew that the outsource, out-of-hours contractors my bank uses have crummy headsets, don't know how to pronounce my bank's name, and have long-ass, tedious, and pointless standardized questionnaires they run through when taking fraud reports. All of this created cover for the fraudster, whose plausibility was enhanced by the rough edges in his pitch - they didn't raise red flags.
As this kind of fraud reporting and fraud contacting is increasingly outsourced to AI, bank customers will be conditioned to dealing with semi-automated systems that make stupid mistakes, force you to repeat yourself, ask you questions they should already know the answers to, and so on. In other words, AI will groom bank customers to be phishing victims.
This is a mistake the finance sector keeps making. 15 years ago, Ben Laurie excoriated the UK banks for their "Verified By Visa" system, which validated credit card transactions by taking users to a third party site and requiring them to re-enter parts of their password there:
https://web.archive.org/web/20090331094020/http://www.links.org/?p=591
This is exactly how a phishing attack works. As Laurie pointed out, this was the banks training their customers to be phished.
I came close to getting phished again today, as it happens. I got back from Berlin on Friday and my suitcase was damaged in transit. I've been dealing with the airline, which means I've really been dealing with their third-party, outsource luggage-damage service. They have a terrible website, their emails are incoherent, and they officiously demand the same information over and over again.
This morning, I got a scam email asking me for more information to complete my damaged luggage claim. It was a terrible email, from a noreply@ email address, and it was vague, officious, and dishearteningly bureaucratic. For just a moment, my finger hovered over the phishing link, and then I looked a little closer.
On any other day, it wouldn't have had a chance. Today – right after I had my luggage wrecked, while I'm still jetlagged, and after days of dealing with my airline's terrible outsource partner – it almost worked.
So much fraud is a Swiss-cheese attack, and while companies can't close all the holes, they can stop creating new ones.
Meanwhile, I'll continue to post about it whenever I get scammed. I find the inner workings of scams to be fascinating, and it's also important to remind people that everyone is vulnerable sometimes, and scammers are willing to try endless variations until an attack lands at just the right place, at just the right time, in just the right way. If you think you can't get scammed, that makes you especially vulnerable:
https://pluralistic.net/2023/02/24/passive-income/#swiss-cheese-security
Image: Cryteria (modified) https://commons.wikimedia.org/wiki/File:HAL9000.svg
CC BY 3.0 https://creativecommons.org/licenses/by/3.0/deed.en
10K notes
·
View notes
Text
with spotify wrapped quickly approaching, thought i’d share a 2023 wrapped (even though nobody asked LOL)
picked up new hobbies
got a new job!
had a joint bday party w my best friend (known him for almost a decade but we’ve never celebrated tgt till now smh)
made new friends from said hobbies and bday party yay
went to japan and had the time of my life!!! but got sick and was down for the count OTL
#.ako#2023 had its share of ups and downs#but i definitely pushed myself to be ‘out there’ more and meet new people / try new things#the highlight was definitely finally checking ‘japan trip’ off my bucket list T_T#and to add to that i had the luck of travelling w my sister and my best friend? like whaaat#anyway…. europe when…. japan 2.0 when…….
1 note
·
View note