• 1 Post
  • 1.42K Comments
Joined 2 years ago
cake
Cake day: June 30th, 2023

help-circle
  • I consider myself technically apt.

    I was expecting a parcel from abroad so was expecting to have to pay customs.
    Received an SMS that looked fairly legit, from a named SMS number that didn’t set off an alarm bell, asking for additional information. The only red flag that got me were some unusually personal questions, like date of birth. I was close to giving away a bunch of personal details.

    Another one was a “your parking permit is about to expire”. We recently had permitted parking introduced, and I figured I’d messed something up. But thankfully I looked into that via the councils parking permit page, and knew I was months away from an expiry.

    My parents received a “help, I’ve flushed my phone down the toilet and need a new one for work tomorrow. Sorry for the strange number, I’ve borrowed a friend’s phone. Can you send me $$$ to [account details] so I can get a new phone?” from a scammer pretending to be my sister.
    Apparently they made it up to a “this is a new account number, are you sure this isn’t a scam?” prompt in their banking app when they finally decided to try and contact her. She immediately picked up and said “stop, it’s a scam”.

    It doesn’t take much to make you vulnerable to social engineering.
    An expectation of events and something that would normally red flag suddenly doesn’t seem suspicious.
    An emotional manipulation, time pressure, all that stuff, and it’s easy to ignore red flags.

    I always say “if you ever feel pressure, take a moment and analyse the situation”. Time pressure, emotional pressure. And analyse looking for anything that seems odd, then pick at that thread.







  • You’d need a service contract with a battery supplier.
    No fuel station would risk a competitor driving in with their old batteries and swapping them with good batteries.
    So you would likely be locked in with a fuel station brand.
    As a consumer, you also risk picking up a dud.
    Fuel stations would also need to be considered in insurance claims, as they would own the battery.

    It’s a great idea, however. I’d rather see more public transport and less cars. But electric cars, easier “refueling” of electric cars, and more solar/wind/hydro/nuclear power is a good hold over










  • accessed from the internet

    Accessed only by you and close family/friends who you are also hosting services for?
    Or accessed by anyone?

    “Accessed by anyone” carries more risk.

    “Accessed by users you host for”, the risks can be eliminated (well, other than risks from those users) by using a VPN. As in, only the people authorised to be on the VPN can access the services.
    Wireguard is the go-to these days.
    Tailscale is much easier and free for 3 users and 100 nodes.

    If it absolutely has to be “accessed by anyone” I would look into a “reverse proxy over VPN/tunnel” or just straight tunnel style approach like chisel (or crowbar, or corkscrew), rathole, frp, or cloudflare tunnels.

    Basically, don’t point a domain at your home public IP and don’t forward ports on your home router/firewall