Lorry

@lorry@infosec.exchange
1.2K Followers
1.6K Following
340 Posts

Leading online #policy & #enforcement for 40 years. I left as head of Safety and Advocacy for #OkCupid after 9 years with #MatchGroup where I worked in T&S, data governance, legal compliance, DEI, realistic wellness, and ethics then became a #Whistleblower

Formerly worked in IT Security. Probably the world's first non-US-government hacker-catcher, head of commercial security for British Telecom, 2nd (and longest serving) #IRC Operator outside of Finland - And all that #MUD & #MIST stuff.

My pinned posts are on: https://mstdn.social/@Lorry/
It seems weird to repost them on this switched account :)

Why I left Match Group?

. https://bit.ly/okcupid-safety-1
. https://bit.ly/okcupid-safety-2
. https://bit.ly/okcupid-safety-3
. https://bit.ly/dating-site-ripoff

You get the idea!

. First article I wrote online that still exists: 1988
. Oldest email address I use daily: 1989
. First Phrack hate: 1991 (Phrack 35)
. Oldest domain name: 1992
. First academic paper on social media: 1992

My Webloghttps://superhighwayman.com
Landing Pagehttps://eastnet.ca/lorry
Github (emptyish!)https://github.com/Hacklet
Twitter (Unused)https://twitter.com/lorry
Just my tootshttps://justmytoots.com/@lorry@infosec.exchange
Old mstdn.social tootshttps://justmytoots.com/@lorry@mstdn.social

I watched the parade in all its glory so you don’t have to.
(abc coverage on YouTube)

How bizarre.

It started with what appeared to be a military museum presentation of historical military uniforms.

The fashion show commentary over the loudspeakers was definitely a thing.

If Trump was going for something similar to one of those parades in Moscow or Pyongyang, I’m not sure he hit the mark. For one thing, no flag-waving crowds lining the parade. It looked like a double barricade and a line of police blocking what crowds did show up.

Most participants marching or driving down the street look… ashamed, or disappointed, to be there. It has more of an ancient world feel of a defeated army being paraded before the victor.

The tank parade was a bit more ominous, accompanied by some instrumental guitar rock music.

It didn’t look like many people showed up, with a lot of the shots showing empty space on both sides of the street. When they showed the people who did turn up, they looked bored. The officials looked bored too. Whatever was on their phones was often more important. Trump looked utterly disappointed. Most of the soldiers looked like they just wanted it all to be over.

I noted the Australian AC/DC song played patriotically by the live band.

I’m sure the phone calls to Kim Jong Un and Putin is going to go badly when they ask about the lack of ICBMs on display.

They didn’t even acknowledge The Cold War! (Which makes sense, I suppose. It was “cold”.)

Drones were paraded along with the other vehicles. I’m sure there weren’t any DJI drones. Surely not.

Robots made an appearance in the parade. Robot dogs, unmanned tanks, marching bands… no Atlas units yet. Don’t worry, Boston Dynamics will sell them a Terminator one day.

The fashion show commentary recommenced for a final display of dress uniforms.

Trump had West Point graduates swear their allegiance to him. Prepared propaganda promoting West Point, and an upcoming movie about the Rangers was played.

Some live country music rounded out the end of the two hour display of military patriotism. The singer said “good night” in the middle of the day.

Oh.

And it started raining.

Literally, it rained on his parade.

lol

That led Salon's Davis to contribute, "It is not easy to accept that 'it' is actually happening here — that the descent into right-wing authoritarianism could be so rapid, the institutions of democracy so weak, the orchestrator of it all such an obvious and venal perversion of the American ideal — and harder still to quit one’s economic dependence on a superpower, however much it may be imploding. But, a decade from now, it might also be hard to believe that countries didn’t pursue their own rational self-interest and isolate a man who befriended their enemies, threatened their homes and sent their citizens to Guantánamo Bay."

https://archive.is/20250612184754/https://www.salon.com/2025/06/12/ban-trump-top-genocide-scholar-issues-dire-warning/

#Trump #Genocide #Nazis #USA #USPol #MAGA #Authoritarianism #Salon #Democracy

The contact form on my website is basically only ever filled out by robots, so I added a checkbox that says, "I am a robot. Only check this box if you are a robot." https://stevendbrewer.com/contact-me/

Robots appear to find it irresistible.

Denmark’s Ministry of Digital Government is phasing out its use of Microsoft Office.. to switch to open source alternatives like LibreOffice instead.

Why? Because relying too heavily on a US tech giant for your nation’s digital infrastructure is starting to feel a bit... well, risky.

Denmark's relationship with the US is under strain, following Donald Trump's clearly stated ambition to seize control of Greenland, and recent reports of increased spying by the States on Greenland and Denmark.

@dianea The irony is that a lot of what I would describe as very poorly designed psychometric tests, especially the ones used for employment and screening, are quite the opposite. I really expected to see more adaptive testing these days, where the test is fluid and digs into ambiguous response data. I guess if you asked an LLM to test somebody, that's exactly what it would do.

But most of these screening tests are just on a different level. They measure compliance, and the candidate's ability to predict the role and the required mindset, mould themselves to it, and importantly, make a mental call to commit to putting it down on paper. In cynical pop-psychology sales terms, it's their first "yes" on the ongoing yes-ladder.

To me, it's a depressing insult to science. To a recruiter and an HR department, it's a great addition to their toolbox.

Are you a journalist who needs advice for how to prepare your electronic devices for travel across the US border?

EFF and Freedom of the Press have you covered: https://freedom.press/digisec/blog/border-security/

Preparing devices for travel through a US border

US border searches of electronic devices put journalists’ work at risk. But there’s a lot you can do to be prepared

Freedom of the Press

I was informally (mis)diagnosed as "probably psychopathic" by my supervisor when I did my Social Psychology postgraduate at the University of Leicester psychiatric teaching hospital back in 1989. Now I realise that I was really diagnosed with adult autism by a psychologist who didn't have the tools to differentiate.

It's interesting because it started me on my path to computerising the psychiatric investigation part of the DSM (well, initially Hare PCL) evaluation for my Master's degree. The psychometric question-and-answer model and demo I came up with had me firmly psychopathic in PCL's diagnostic terms, whereas these days it would be easily diagnosed as autism.

I went on to expand the idea from psychometrics, to behaviour analysis in virtual worlds, which I figured would be a better capture than psychometric questions - Would the person co-operate to attain a goal, would they show altruism, would they be quick to anger - There's a lot you can measure in the virtual world as we know very well now, but didn't in 1991. Sadly, the lack of modern technology and the need to feed myself brought this PhD to an end without a write-up - But it's no wonder I ended up working for OkCupid, I guess :D

The sad thing about that is that although it didn't impact my life at all, other than having an interesting topic to discuss at parties, the PCL is used as a tool by US prisons in their parole calculations. A PCL diagnosis is a heavy weighting against parole, even though Hare himself has said that isn't the way this should be used. I dread to think how many autistic people are stuck in prisons for evermore because of misdiagnosed psychopathy.

The psychopathy test puts a lot more emphasis on masking and social interactions than on kidnapping people and putting them in wells to skin them later, I feel.

I can't be bothered to write a blog post about this, so I will scream into the #Mastodon #Void instead - Except now I have to think of some other #Hashtags which is always the hard part, I get carried away, autism you see!

#Medicine #Psychology #Psychiatry #MentalHealth #Education #Diagnosis #Psychopathy #HarePCL #DSM #Psychometrics #Statistics #Autism #ADHD #RetroComputing #Gaming #Online #Worlds #MUD #Leicester #UniversityofLeicester #Prison #Parole #HannibalLecter #SilenceoftheLambs #OkCupid #Tinder #Hinge #MatchGroup #Algorithms #BigData

This is insane.

#Trump’s Secretary of the #Army thinks
that currently there is a US soldier on the moon.

Embarrassing AF.

#USpol #military #MilitaryPreparedness #kakistocracy #idiocracy

The orange shit-gibbon is doing very well with his "no war on my watch!" promise., I see.

#GPT #AI #AIArt #SorryGibbons #Trump #War #Israel #Iran #IranIsraelWar

AI & CHATGPT | TOOLS | TECHNOLOGY on Instagram: "The AI deepfake threat just leveled up. What you’re about to see isn’t real but it looks and feels like it is. @thetravisbible used Google Veo 3 to show how fast realistic fakes are evolving. He made this video as a warning to his parents. Maybe yours need it too. Glitches are harder to spot. Faces look real. Movements feel natural. And when tools like this end up in the wrong hands, the consequences could be serious. Watch until the end. Then send it to someone who still thinks, “I’d never fall for that.”"

41K likes, 441 comments - ai.technews on June 6, 2025: "The AI deepfake threat just leveled up. What you’re about to see isn’t real but it looks and feels like it is. @thetravisbible used Google Veo 3 to show how fast realistic fakes are evolving. He made this video as a warning to his parents. Maybe yours need it too. Glitches are harder to spot. Faces look real. Movements feel natural. And when tools like this end up in the wrong hands, the consequences could be serious. Watch until the end. Then send it to someone who still thinks, “I’d never fall for that.”".

Instagram
×

The contact form on my website is basically only ever filled out by robots, so I added a checkbox that says, "I am a robot. Only check this box if you are a robot." https://stevendbrewer.com/contact-me/

Robots appear to find it irresistible.

@stevendbrewer This is honestly brilliant.
@stevendbrewer At least they're honest (even if only accidentally).
@stevendbrewer Hopefully you’re using that checkbox to identify which IP net blocks to ban at the firewall. :)
@JustinDerrick My website is hosted at a hosting service, so it isn't behind a firewall. I guess I could write a script that would write the ip address into a .htaccess file or something, but that sounds like sysadmin work. And I don't do sysadmin work anymore. 🙂

@stevendbrewer Software firewalls are available on most OS's now. When I built my last mail/web server, I set up a series of tables in files. I just add netblocks to a text file, and within an hour or so, the firewall picks up the changes and the bad actors are blocked forever...

It should be about as easy as modifying your .htaccess file. :)

... but believe me, I get it.

@stevendbrewer used to have that as a spam filter on my blog back when I was using WordPress. Was working well for a while, but at some point most bots figured it out. 😭
@stevendbrewer A honeypot field! They've been around for quite a while, good to see they're still effective!
@max
I've always been a fan of the seemingly-normal field hidden with CSS.
@stevendbrewer
@stevendbrewer I have a pre-checked checkbox for "do not send" and humans realise they have to uncheck it, robots don't. I've tried so many tricks like this and it's the first one that really seems to work. Of course the robots wll read this and I'm doomed now…
@synx508 maybe something double, like uncheck this box and next screen: are you sure? @stevendbrewer
@energisch_ @stevendbrewer Perhaps, I feel that It might work against robots but at the cost of annoying humans even more than my uncheck box alone.

@synx508 @energisch_ Maybe you could have a whole series of screens:

Are you sure you're not a robot?

Are you really sure?

Are you really really sure?

It would certainly cut down on submissions…

@stevendbrewer @energisch_ Once you've decided it's a robot it's only fair that it gets the full ELIZA treatment.
@synx508
Ooh, have a honeypot that just infinitely loops forms to fill, discarding results?
@stevendbrewer @energisch_

@synx508 @stevendbrewer @energisch_@troet.cafe now I am loving the idea that AI, roving for content to add to training databases, gets routed to intentionally frustrating and time wasting interactive AIs. We are in the super early days of an arms race that will do nothing but use up resources as humans dive into the apocalypse.

We will soon be at that point where aliens find a automated, but dead, world.

@synx508 @stevendbrewer

The mailto: URL on my WWW site has had a pre-filled subject field instructing the recipient to delete the mail unread, for well over a decade, now.

#UnsolicitedBulkMail

@stevendbrewer

Hold on *put on Die Roboter by Kraftwerk*

@stevendbrewer honeypot fields are the best (used them a lot), and this one doesn’t even need to be CSS-concealed from humans—clever & nifty! 👍🔥
@stevendbrewer also never ever setup any #Mailforwared as #CatchAll, becaise #Spammers will hammer postmaster@ all day long...

@kkarhan

I keep hearing this, but I've had a catch-all on our domain(s) for over a decade and it hasn't been the overwhelming volume of spam I'd expected. I guess some are more attractive targets than others? Or maybe we're just more judicious on sharing it? 🤷

(I do occasionally get a mass-mailing or backscatter spam from hosts that are too dumb to respect SPF, but they all have the same subject line or sender, so mutt makes quick work of deleting all the matching messages)

@stevendbrewer

@stevendbrewer Isn't the honeypot field normally hidden. 😁
@stevendbrewer Maybe you should clarify "non-biologic".

@stevendbrewer I have two thoughts:

1) A regular captcha checkbox has all of those words, in that order. Sure, one's missing, but modern AI is going to be ~94% sure that's fine, actually.

2) *I* find that button irresistible, not because I'm a robot, but because I'm a snarky bitch. 😅

@TranshumanBlues Are you the one that sent the message, "Beep boop"? 🙂
@stevendbrewer I was not, but I have the utmost respect for whoever did. 😂
@stevendbrewer As a human, I find it pretty irresistible too. Though I'd probably be quoting some Kraftwerk lyrics in the message body.
@stevendbrewer
Genius-level pricking. Love it.

@stevendbrewer I have a honeypot field that's marked as required but set to visibility:none with CSS. If there's a value in it on submission, I know that's a bot and discard it. If it's null I remove the required attribute and allow the form to submit.

I haven't bothered checking the logs to see if they're biting. I only look if the boss's assistant complains about fake submissions.

@oheso @stevendbrewer My blog's comment submission form has a hidden-with-CSS text field (with a "don't put anything in this" label for the people using lynx/etc) that my software uses as a honeypot. My logs say it's extremely reliable at tripping up automated stuff, although I still get a few human spam comments every so often.
@stevendbrewer JWZ has a "herp derp" box that I assume serves the same purpose. Superintelligence will destroy us as soon as it figures out not to check those boxes.
@stevendbrewer you may still get humans checking it, because some (in fact, many!) humans just don't read 🥲😅

@stevendbrewer

Great! 🥰
Seems we finally got the solution™. 🍿

@stevendbrewer we've long used honeypot traps (as a nice alternative to reCaptcha) and have found them incredibly effective at blocking bots - and simple too.
@stevendbrewer So funny! 😂 you are my new God Creator... (no sense on it, joke activated)