Frustrating, Frightening, even Dangerous!

A thread from my Bluesky. The first post in the thread is linked below.

It’s frustrating when I call my ISP’s tech support and ๐—œ have to walk ๐˜๐—ต๐—ฒ๐—บ through the process of getting me to the right person (usually by proving them wrong). I can live with ๐Ÿ๐ซ๐ฎ๐ฌ๐ญ๐ซ๐š๐ญ๐ข๐ง๐ . ๐…๐ซ๐ฎ๐ฌ๐ญ๐ซ๐š๐ญ๐ข๐ง๐  is probably not going to kill me. But this thread isn’t about my ISP, it’s about my doctorsโฌ‡๏ธ

https://bsky.app/profile/anthonyscardina.com/post/3lhvwvdrn7c2d

โฌ†๏ธWhen I call in to my doctor’s office because part of MyChart isn’t working, it’s not my health care provider (et al)’s job to fix it. No one in that office is their because of their IT training – they’re there to provide healthcare, not technical support. HOWEVER, since they are compelling their โฌ‡๏ธ

โฌ†๏ธ patients to use MyChart, it ๐’Š๐’” their job to gอŸeอŸtอŸ อŸiอŸtอŸ อŸfอŸiอŸxอŸeอŸdอŸ. Not to fix it, but to get it fixed. Why? Because they are the healthcare provider, and this is how they are providing healthcare. So when I call in to a doc’s office, and ๐‘ฐ have to walk ๐’•๐’‰๐’†๐’Ž through the process of how ๐’•๐’‰๐’†๐’š open a โฌ‡๏ธ

โฌ†๏ธ support ticket with MyChart, it’s more than just frustrating. See, I don’t know the “qualifications” of the person that answered the phone, and it doesn’t matter. They did not know their office’s procedure for when a ๐’‘๐’‚๐’•๐’Š๐’†๐’๐’• cannot access this ๐—บ๐—ฎ๐—ป๐—ฑ๐—ฎ๐˜๐—ผ๐—ฟ๐˜† part of ๐’‰๐’†๐’‚๐’๐’•๐’‰๐’„๐’‚๐’“๐’† that they are ๐’‘๐’“๐’๐’—๐’Š๐’…๐’Š๐’๐’ˆ.โฌ‡๏ธ

โฌ†๏ธ Who’s fault is that? Leadership. It’s the managers’ jobs to make sure that the people are trained, and middle management’s job to make sure the managers have the training material and time to train, and upper management’s job to make sure that the resources (money) are available for training. Butโฌ‡๏ธ

โฌ†๏ธWhat am I getting at? If the entire office staff (this is the case) does not know that they are supposed to open a support ticket, what else don’t they know? What if a patient has symptoms so bad that the doctor said “we need to watch this like a hawk. wear this monitor for x amount of time โฌ‡๏ธ

โฌ†๏ธ starting today because we need results as soon as possible.” and the nurse gives the patient the wrong monitor AND wrong instructions, delaying subsequent tests and procedures when TIME IS A FACTOR? This is what happened to me in January. What if it wasn’t a heart monitor but the wrong med or โฌ‡๏ธ

โฌ†๏ธ medication instructions? What if certain meds were supposed to be stopped before a test, but the instructions were incomplete and ambiguous so the meds weren’t stopped and the test results were skewed? That also happened to me. It’s the provider’s OBLIGATION to make these instructions clear โฌ‡๏ธ

โฌ†๏ธand educate patients on their medication usage. So now back to the office that doesn’t know their proper procedures. One can make assumptions, but, how do I ๐‘ฒ๐‘ต๐‘ถ๐‘พ that my cardiologist isn’t also unaware of procedures? He could be performing heart surgery on me one day! So it’s beyond ๐’‡๐’“๐’–๐’”๐’•๐’“๐’‚๐’•๐’Š๐’๐’ˆ โฌ‡๏ธ

โฌ†๏ธ it’s dangerous. Dangerous to the patients health/well-being/life. It’s literally a matter of life or death for patients with life-threatening illnesses. American Government: This is not how you build a country that wins. If your citizens are all sick and dying, sure it helps them stay indebted โฌ‡๏ธ

โฌ†๏ธ to your “interests”, but what about when TheBoogiemanโ„ข finally comes and invades with millions of people? Who’s gonna protect your little bunkers once the military is overrun? Not the general population! they will all be too sick, or already dead, or just exhausted. ๐Ÿ”š

DATA STUDY: Harassment on Nextdoor; Demographics of the Harassers

1. Introduction

I’ve been on the Nextdoor app for several years. It seemed to me that there was a lot more harassment than I would have expected. Harassment, unfortunately, exists on every social media platform. But the amount on Nextdoor surprised me, not because there was more than other platforms, no, but because Nextdoor is (was) less anonymous than other platforms like Facebook or Twitter.

When I joined Nextdoor, the requirements for a user’s profile were more strict. At the time, you needed an invite from an established user, you were required to use your government first and last name, your profile picture could not be of someone other than you (it could blank or be a picture of the user’s face), and there were strict requirements for technical controls to verify that you are in the location you claim to be.

There was a lot more harassment than I would have expected! In my experience, people, in general, are less likely to bully when they know they can’t hide behind their keyboard. If you called your neighbor a butthead, your neighbor would know exactly who said it! This usually dissuades people from doing things like that, but not always.

Over the years, Nextdoor rolled those above mentioned requirements back. As those requirements all became more and more lax, the harassment increased proportionally.

2. Study Methodology and Synopsis

The goal was to identify demographic characteristics of Nextdoor users participating in online harassment. Because of the sheer volume, I limited this study to only include disproportionately aggressive behavior (example: User B threatens bodily harm because User A dyed their hair).

To make matters more complicated, many of these users did not include a face picture for their profile picture, thus negating facial recognition as an avenue of discovery, and also set their display names to First Name, Last Name Initial (e.g. I would appear as Tony S.)

This left some dots to be connected

Once I found someone exhibiting disproportionately aggressive behavior, I started with their first name and last name initial. The second piece of information is the name of the Nextdoor Neighborhood that the user belongs to. Nextdoor Neighborhoods are divisions within a location, and are at least partially created by Nextdoor users. This has lead to “neighborhoods” that don’t always match up with real world neighborhoods, districts, boroughs, or other administrative divisions. Their borders also appear to me to be mostly arbitrary.

Nevertheless, these Nexdoor Neighborhoods are useful. Nextdoor provides a map that shows each of these. So, when there was a user not showing their full name, I would re-create the neighborhood on Google’s MyMaps. These are maps that are private and, because of my security settings, only viewable by me.

The next step was to get all the addresses of real people with that first name and whose last name starts with that initial. If I were searching myself, I’d need to know all of the “Tony S.”s that live in my city.

To do this, I utilized the State of Ohio’s voter database. State law requires that each county make available to the public data about voters and voting activity for various accountability reasons. The people in the study were primarily located in two counties, so I downloaded those data sets and imported them into a private database server.

A Note on Data Privacy

The network, servers, databases, and end-points all adhere to strict data security regulations and practices as outlined in NIST FIPS and NIST SP 800-53, and are aligned with SOC2 requirements. In addition, the data was deleted at the conclusion of the study, eliminated residual risk to the people in the data set. The MyMaps were also deleted at the end of the study for the same reason.

My next step was to query the data set for the partial names, and have it output a file of names, addresses, and dates of birth that match. This file was then imported into the private MyMaps map for the study.
Sample database output
Often times, several pins would appear on the map, but only one of those pins would appear in the Nextdoor Neighborhood that I added to the map. This in essence deanonymized the username, revealing the user’s age.
Sample Map with pins and neighborhood

As for determining a user’s gender, this was mostly self-reported by the user, either by stating it in other posts or profiles on social media, or including their pronouns in their social media profile bio. When that information was missing, I would use whatever clues I could find and make an educated guess.

Once the study was completed, the database, database outputs, and maps were deleted.

The final step was simple: Each row of a spreadsheet contained the age and gender of each person exhibiting disproportionately aggressive behavior. The precision of the ages was then changed from years to decades. Finally, spreadsheet formulas were used to tabulate the number of mean in each decade and women in each decade.

Then I made a chart!

Data collection was done whenever I saw an example over the course of a few weeks. Gathering the additional information took about an hour. Tabulating the data took about 20 minutes.

3. Key Findings and Conclusion

The most likely person to Disproportionately Aggressive Behavior is a woman in her 60s.

I was planning on gathering other demographic information such as political affiliation and property ownership status, but honestly, I got bored with it and moved on to something else.

LINUX: I wanna set the record straight (This is about Linux)

Bluesky (https://bsky.app) is supressing this message for some silly reasson. I was able to copy/paste it from Clearsky at https://clearsky.app/anthonyscardina.com/history

I wanna set the record straight (maybe I make it a blog post as well) IDGAF personally what desktop operating system someone chooses. Period. If I see someone complaining about something stressing them the hell out, I would be remiss if I DIDN’T recommend an operating system that would solve thatโฌ‡๏ธ
https://bsky.app/profile/anthonyscardina.com/post/3lhjkxxbpec26

โฌ†๏ธproblem they’re having AND I’m happy to walk them through the switch. As someone with years of training, education, experience, and expertise, it is my DUTY to reach out. It’s EVERYONE’S CIVIC DUTY to help their fellow human, and this is just one of the ways I do that. If this makes me a โฌ‡๏ธ
https://bsky.app/profile/anthonyscardina.com/post/3lhjl4rglvk26

โฌ†๏ธ “reply guy” , then the professional in me says “so be it” but honestly the correct answer to me being labeled a “reply guy” is actually”eat shit and die” because A RISING TIDE LIFTS ALL SHIPS! Do not fucking keep that tide low and think that there are not repercussions to harming the overall โฌ‡๏ธ
https://bsky.app/profile/anthonyscardina.com/post/3lhjla3q3kk26

โฌ†๏ธmental health of those individuals by suppressing the solutions to their problems, and thus harming the over all health of society! But what DOES piss me off? What fills me with righteous indignation? Is asshole mother fuckers that spread misinformation and misinformation about those solutions. โฌ‡๏ธ
https://bsky.app/profile/anthonyscardina.com/post/3lhjld77knk26

โฌ†๏ธ Sometimes it’s not intentional, sometimes it is, but it is always someone implying that they are an expert when all they know is that it did not work for them flawlessly on the first try. This does not paint a complete picture, and dissuades people from using the solution that’s going to in the โฌ‡๏ธ
https://bsky.app/profile/anthonyscardina.com/post/3lhjlgqabys27

โฌ†๏ธ long run better their mental health. and why do they do this? to boost their own ego? either consciously or subconsciously. they think that’s a good enough reason to further someone else’s suffering, no matter how minor? For those people, IT’S ON SIGHT! (where’s the Minecraft legal disclaimer?)๐Ÿ”š
https://bsky.app/profile/anthonyscardina.com/post/3lhjlje5kpk27

DATA STUDY: Online Scammers _TEMP

This is a place holder. I’m holding myself accountable by putting this here so that I remember to fill this post in with the data and conclusions I’ve collected as of January 2024 (when I completed the last phase of the first part of the study. The second part will just be a continuation of the first part, and then comparing and contrasting the two to find trends. part two will conclude when I have enough data)

Bonkers customer support

This was just bonkers

Hi, you’re in the right place for customer service support.
You can tell us what you need in your own words. How can we help you today?

T i want to talk to a human

We understand your need to speak with a human representative. Would you like me to connect you with a customer service associate?

T Yes, that’s right

Got it.
We can still solve a lot of issues quickly. Please give us a try to see how we can help. If we canโ€™t solve your problem here, weโ€™ll be happy to get you to an associate.

T Connect with a Customer Service Associate

There are a few ways you can get help. You can visit Customer Service Home, or we can connect you to an associate. What would you like to do?

T Chat with an associate now

An associate will join the chat.

A Anmol has joined the chat

A Hello There, Hope you are doing well. My name is Anmol and I’ll be glad to assist you today.

T An Amazon driver parked in the road at my driveway, messaged me asking how to access my address, and then left before I could reply
i don’t understand the problem
it’s just a driveway
there’s no gate or anything

A I’m sorry for the inconvenience cause to you.

T Amazon was here two days ago with no issues

A We certainly did not expect this to happen with our valuable customer.
But please be assured I will put my all efforts to make you happy and satisfied in this case.
Could you please help me with the order Id?

T i’m looking for it

A Yes sure.

T Ordered on January 21, 2025 Order# [REDACTED]

A Thank you for the information.
Please allow me a moment to check this for you.
CENTROPOWER 5-Pack 4K HDMI Cable 6 Foot – 18Gbps High Speed HDR, 2160P, 1080P, Ethernet – @60Hz 2.0 HDMI Cord Black – Audio Return(ARC) Compatible UHD TV, Blu-Ray, Xbox, PS3/4, PC, Apple TV
Is this the item?

T That’s one of the items

A Thank you for confirming.
Please allow me a moment.

T Order # [REDACTED]
that is another number for the same delivery
I don’t know why there’s two numbers

A Thank you for the information.

T It’s very frustrating

A Please allow me a moment.
As I have checked the details and found that your item is delayed in transit and you can expect the item to be delivered within 24 hours
However, as you are our valuable customer and got inconvenience So in this case we will help you with the full refund of the item once its delivered as an apology and you can keep the item as well
Would that be fine?

T hold on
let’s look at this problem again
the driver parked his car at the end of my driveway and said he could not find it
does that sound realistic to you?

A Yes, I can understand your concern

T do you think he will decide to “find” it tomorrow?

A Also Iโ€™ll take this as a feedback and will make sure so that this will not happen again with you.

T how do I know the next attempt he isn’t going to do the same thing?

A Please be rest assured

T how do I know the next attempt he isn’t going to do the same thing?

A You can expect the item within 24 hours
Please be rest assured

T how do I know the next attempt he isn’t going to do the same thing?
i have video of him just sitting there

A Within 24 hours

T he said he couldn’t find it which I don’t believe
because he was right there
tell me how you know he won’t do the same thing again tomorrow stop repeating the same thing over and over i want a real answer

A Please do not worry
Please donยดt worry team will try to deliver the item as soon as its possible
Please be rest assured
And once your item is delivered reach out to us back and we will help you with the full refund of the item and you.
Would that be fine?

T Stop saying “Please be rest assured” because you’ve done nothing to assure me

A We will issue full refund of the item and you can keep the item for free
As an apology

T that does not help if he refuses to deliver it!

A Please do not worry team will try to deliver the item as soon as its possible
Also Iโ€™ll take this as a feedback and will make sure so that this will not happen again with you.

T you are not helping me

A I am sorry for the inconvenience

T please connect me to someone that can help me

A Even if I transfer this chat to my supervisor, they will be having the same resolution, as we all share the same resources.
Do you still want me to transfer?

T i said connect me to someone that can help me. if your supervisor cannot help me, then connect me to someone else

A Do you still want me to transfer?

T transfer me to someone that can actually help me


Anmol has left the chat

N Neha has joined the chat

N Hello Tony,This is Neha. I am one of the available supervisors. Please allow me a moment so that I can check the previous conversation and help you in best possible manner.
Thank you for waiting.
I am sorry to hear that you have not received your order yet.
I can sense your disappointment in this regard,I am so sorry for this experience

T that’s not the point.
it is NOT because it’s late

N That’s definitely not what we want our customers to experience, even I am personally feeling embarrassed due to the driver error we are losing the valuable customer and I know you’ll be so disappointed.
I can understand your concern.

T it is because the driver sat at the end of my driveway and said he could not find it. I NEED A SOLUTION TO COMMUNICATE TO THE DRIVER
NEED A SOLUTION TO COMMUNICATE TO THE DRIVER
NEED A SOLUTION TO COMMUNICATE TO THE DRIVER

N just to confirm, have you face the same issue with any of your previous orders these days?

T Yes.

N Did the carrier mentioned the same thing during the delivery?

T yes

N My apologies that you’ve had this experience. But I request you to keep faith in me as I’m going to do my best to resolve the matter for you.
Please allow me a moment

T it was Amazon both times. And both times other Amazon deliveries were delivered by amazon drivers the days before and after

N Thank you for the information.
Please allow me a moment
I am working on it
Please allow me a moment
Thank you for your patience.
I am sending you a link via email please click on that link ad pin your location once

T ok

N Have you received the Email?

T no

N Please allow me a moment
[REDACTED]
you can use this link to update it
please update it now while we are on chat and confirm once done

T the pin is already in the correct place
it’s pointed at my house

N have you updated the delivery instructions as well?

T I put in the instructions that it’s just a normal driveway directly across from [REDACTED] Road

N Okay
Please allow me a moment
I am working on your issue
Being a supervisor ,I have taken your feedback on this and We will make sure that this will not happen again and carrier should follow all the delivery instructions added in your registered account so the future orders will get delivered at the correct shipping address and you will not face the same issue again in future
In this case I can reschedule the delivery for the order for Jan 24 also I will add the note for the carrier mentioned to deliver the order as early as possible followed by the delivery instructions
Also
In order to compensate for the inconvenience caused,I can issue $30 refund on the card you have used to pay prime
Would that be helpful?

T I need some extra steps to be taken. I want the driver to contact me BEFORE he arrives so that I can go outside and flag him down because evidently he is blind

N Have you added the phone number in your amazon registered account?

T yes

N Thank you
I am working on it
Please allow me a moment
I am working on your issue
I have added the note for the carrier mentioned to contact you before the delivery also I would request you to update the same in your delivery instructions as well
so on each and every delivery the carrier will contact you once they will reach at your address for delivery

T If I don’t answer will they still deliver? What if I miss the call because I’m on a work call?

N No

T i DO NOT want to be contacted on each delivery
just this one with the troubled driver

N Ok
Kindly allow me a moment

T so if they call while i’m on a work call then I can’t get my package? That’s insane. I do not want that
I don’t understand what the problem is
it’s just a normal driveway with two signs on each side that say my address
it even has reflectors and drive way markers
no one can miss this driveway
what did the driver say was the problem?

N I completely understand your concern

T what did the driver say was the problem?

N In this case I will add the note for the carrier

T what did the driver say was the problem?

N I have mentioned the tracking updated as Carrier is unable to gain access to front door to deliver the package.

T that’s what it said? Unable to gain access to front door to deliver the package?

N Yes, thats what the carrier updated for this order

T How can I talk to the driver? Or the driver’s office? So I can tell him how to find me

N In this case I have added the note for the carrier mentioned to call you once the order will be out for the delivery also I mentioned them to strictly follow the delivery instructions

T wait wait wait

N Sure

T you said if I don’t answer the phone they won’t deliver the package and then I told you that won’t work because if i’m in a meeting or on a work call i cannot answer the phone and I asked you to un do that

N where did I mentioned that?

T
#################################
so if they call while i’m on a work call then I can’t get my package? That’s insane. I do not want that I don’t understand what the problem is it’s just a normal driveway with two signs on each side that say my address it even has reflectors and drive way markers no one can miss this driveway what did the driver say was the problem?
###################################
just scroll up to find it in the chat but i copied / pasted it for you

N Tony, have you checked what I have just mentioned above?

T ***so if they call while i’m on a work call then I can’t get my package? That’s insane. I do not want that ***
checked what?

N I mentioned the carrier will follow the delivery instructions and incase you wont answer the call the order will still get delivered

T that’s not what you said. I’m looking right at what you said and that isn’t it

N please dont worry we will surely work on it and take care the order will surely get delivered by tomorrow

T so if i don’t answer the call they will still deliver it?

N Yes
they will

T ok

N Also
Being a Supervisor, I never share any wrong information with our customer and never speculate.

T you’re not perfect so don’t tell me you never make mistakes

N I am sorry if you feel that way.
But I am doing my best to help you with this

T are you saying that you never make mistakes?

N I mentioned I am doing my best to resolve the issue in best way
In order to compensate for the inconvenience caused,I can issue $30 refund on the card you have used to pay prime
Would that be helpful?
I can assure you that such instance does not occur usually. But we take each instance very seriously and try our best to avoid it happening in future.

T You said ” I never share any wrong information” which implies you don’t make mistakes

N we will try to improve our services and will try that this will not happen again

T i don’t care if you think you’re perfect or not that does not help me

NTony, that means I never share any wrong information with any of our amazon customers
I always share the accurate information which I can see on my end

T not even by accident?

N I’m the supervisor and working here with Amazon from very long. You can mark my word as a surety.

T You actually think that because you’re an Amazon supervisor that you are incapable of making mistakes? WHY IS AMAZON SUPPORT SPEAKING TO ME LIKE THIS??? Am I in the Twilight Zone or something?
HUMANS MAKE MISTAKES are you human? Yes? Then you are capable of making mistakes.

N Yes, I’m a human being and I do commit mistakes sometimes but here now I am working and assisting you as supervisor and I am sharing the exact details I am getting on my end regarding this order
Also as you didnt confirm for $30 refund on the card you have used to pay for prime , I am not adding it without your consent as here in amazon we never take any action on customers account without their consent

T I’m glad you can admit that you are human just like everyone else and can make mistakes. This conversation is absurd

N My apologies again for this situation; I sincerely hope you give us another chance to prove the quality of our service.

T sure send me a refund but my main concern is that I get the packages

N I am also a customer at some point and I understand completely After paying extra for any service and when we don’t get that service, it hurts emotionally and financially to everyone, I do respect your hard earn money.
and your precious time as well*
Please be assured, we will take care you that you won’t face the delivery issues with any of your future delivery also your order will surely get delivered by tomorrow
without any further delay
we will surely take care of it
As a one time exception and token of apology I have issued the $30 refund on the card you have used to pay prime.You will receive the refund in 3-5 business days.{Please note that 3-5 days is the time bank take to issue refund in your account}
shall I also send you the confirmation Email?

T Sure

N Please allow me a moment
I have sent you the Email
Could you please check and confirm?

T i have the email

N Great!
I’m again sorry for all the delay and the trouble that you’ve to face due to this issue.
I hope my efforts to help you were to your satisfaction?

T no

N On a personal level, I highly appreciate your patience, cooperation and understanding in this matter.
If there’s something that I missed to mention or to do, or if there’s something else I can do further to help you on this concern, please let me know and I’m more than pleased to assist you further.

T pay closer attention and do not imply that you are beyond human imperfection
goodbye

Nextdoor and Conversation around Business Card QR Codes

Conversations around QR codes on business cards (not QR codes in delivered packages) and if the QR code on that business card is safe (spoiler alert: yes it is safe)

Narrative:

There is currently conversation on Nextdoor around scams utilizing QR codes, as well as a company placing business cards with a QR code under windshield wipers. At least one Nextdoor user accused the business placing cards on cars of being one of the scammers/hackers. A Nextdoor user posted a photo of the QR code. I decided to use that QR code to run tests to see if the business cards with the QR codes are malicious or not.

Procedure:

I fired up an Android test device that’s isolated from the rest of my network. I used a program called tcpdump on my firewall in order to monitor and record traffic coming to and from that test device. I piped the output from that into a utility called tree so that I could save it and monitor it in real time at the same time. Then piped that back into tcpdump and piped that output into tree again as plaintext and monitored and saved that. I was left with two files: a dump file that could be opened in WireShark, and a txt file that listed all of the output as regular plain text.

This gave me a baseline of activity that my android device was doing before scanning any QR codes. I repeated the steps above while scanning the QR code.

My next step was to take the plain text output of both and pipe the output through filtering utilities like grep and sed to have only IP addresses and not the other information. I piped those through the utilities sort and uniq and so all that was left was a list of IP addresses BEFORE scanning the QR code, and IP addresses AFTER scanning the QR code. Then I piped everything through diff and was left with ONLY ip addresses that were not a part of the baseline (i.e. the IP addresses of servers visitied by scanning the QR code)

Those IP addresses were run through ip2location.io and infobyip.com for some basic information like location, hosting, and domain names.

Next I ran the domain in the QR code, as well as the domain the first one links to, through dnslytics.com for some more domain information.

Then, I ran the QR code link, and the destination link through virustotal.com.

Finally I examined the dumps in WireShark after filtering out IP addresses from the baseline checks.

Results:

It is not malicious

The servers contacted are all web hosts.

The first link is to a company that creates QR codes for you to link to, and then shares information such as “How many people scanned my QR code this week?” “Are there more people scanning this with Android or with iOS?” “What cities are the people scanning my QR code in?”

The second link is just the company website.

Neither website was shown to be malicious in virustotal.com‘s URL scanner


list for https://www.infobyip.com/ipbulklookup.php:

vqr.vc
tigersden.co
18.211.201.92
18.238.25.116
18.238.25.3
18.238.25.31
18.238.25.38
3.160.5.110
3.160.5.25
3.160.5.47
3.160.5.68
3.214.242.45
34.149.206.255
34.149.87.45
34.49.229.81
35.171.58.3
44.193.186.194
50.17.183.161
54.175.126.84

Nextdoor Credit Card Stealing Scammers

Re-posted from a post I made on Nextdoor

Whoever is in control of the Nextdoor account “Jared H.” in “Mill Hill” is a scammer. I’m not saying Jared H. is a scammer, but whoever has control of that account is.

Thank you to the Nextdoor Neighbors that brought this account to my attention. If you come across suspicious posts or chat messages (especially from that user, please report them to Nextdoor).

There are some red flags in the message and the link. To me, the most telling part is the fact that these DMs came from a seemingly random user impersonating Nextdoor Support. Nextdoor Support does not reach out to end users in this manner.

Additionally, the domain of the link in the DM is NOT a Nextdoor website. All the website does is re-route whoever clicks on it to another website. That website, also not a Nextdoor owned website, impersonates Nextdoor and asks for credit card information, ostensibly to verify your identity.

The wesbites were both registered today. As we all know, Nextdoor is older than one-day-old.

I looked at the source-code, and it contains publicly available code for credit-card stealing webpages, as well as some writing in Cyrillic. I put the Cyrillic into Google Translate, and it was identified as Russian (Nextdoor is not based in Russia, nor programmed in Russian).

Finally, at the bottom of the source-code, was a link to a Rick Roll (a YouTube video of “Never Gonna Give You Up, which used to be a common prank)

I then looked to the webservers hosting these websites. They each have unique IP adresses, but other than that, they appear identical. Running them through some OsInt tools didn’t yield any useful results either, except that they are now beginning to slowly classify these sites as threats.

Additionally, each link to the first website is unique, which leads to a link to the second website which is also unique, and the reason for this is that the final page is customized with the target’s name to lend credibility. Using a link that goes to another link, or layering, aids in hiding the scammer websites, as well as helping to keep the scamming sites around longer, because the first link, essentially a decoy, will not flag most malware detectors because they’re just a re-direct, so even with anti-virus, the link will appear to be “safe”

Please let me know if you have any questions!

Example Message sent to potential victims
Some source code with some Cyrillic
It was Russian
There was also a Rick Roll in there
Credit Card Steeler

https://verifyingordr.lol/6b4f4b -> https://nextdoor.7562587027.cfd/1770969236 -> Martin Chaney

http://verifyingordr.lol/dc11af -> https://nextdoor.7562587027.cfd/6047719614 -> Kathy Henson

The creepy creeper camera that I found

I looked at one of those websites for finding devices. I wanted to find traffic cameras in my town. They’re there, but evidently not accessible to the public. But on this website, I found a bunch of cameras that were from the DOT. Yay! The bad news is that these cameras weren’t in my state after all. They were in a different state. I identified the city, and found out that they are public on purpose, so I called it a day.

Except… there was one camera that didn’t match the others. It was blurry. I wanted to try and focus it, so I logged in. There was no manual focus. Bummer. But it had a PTZ function. So I panned, tilted, and zoomed, and what I found shocked the hell out of me. The camera is attached to some little switch, a Cradlepoint cellular bridge, and an uninterruptible power supply. It’s in a tiny little box, the inside of which is painted black. There’s a window, held in place with electrical tape. Not an ordinary window, though, but a very familiar one. It’s a Faraday cage from a microwave oven. My guess is that even when the sun is shining directly on this box, it is impossible to see what’s inside it.

Sometimes I find the camera pointed at cars in the street. Sometimes it’s zoomed in on the windows of the apartments across the alleyway.

I find this very, very, disturbing. One the one hand, say that it is an legal surveillance. Then the cops are inept at InfoSec and OpSec (par for the course, but something that should be improved). Say that it’s not the cops… who is the scumwad creeper doing this?

I didn’t attempt to gain root. That’s too intrusive, and probably illegal, so not for me.

Geolocating the IP points to a default location for Verizon wireless hot spots. All I could figure out based on daylight is that it’s in the Western timezone.

Maybe I can use weather images and daily satellite images to figure out a more specific locale based on whether or not there’s snow on the ground.

I reached out to Super Tech Support on Reply All – no response so far.

I don’t like this. I get a bad vibe from this. It feels like some one is up to something creepy.

So you’re going to buy some security cameras…

This was a post that I posted to Nextdoor on 15JAN2020, and then updated on 19FEB2020

So you’re going to buy some security cameras…

There’s a lot to consider. First, you have to determine what level of skill you have and how much effort you want to put into it. You must also look into how reputable the manufacturer is, and whether or not you’re going to monitor this yourself, or have a company monitor it for you. Are you going to host at home, in the cloud, or both? Constant recording, or just when there’s an event? And finally, cost.

About eight years ago when I lived on Highland Ave, my house was broken into. We decided that having conspicuous cameras on the outside of the house *๐˜ฎ๐˜ช๐˜จ๐˜ฉ๐˜ต* be a deterrent to 90% of criminals, and cameras inside the houses would help to identify culprits should anyone break in. I first accomplished this with – I kid you not – an IBM ThinkPad that was pulled out of the trash, a copy of Debian Linux, a USB hub, some USB webcams and repurposed Android phones that were headed for the trash, and LOTS of time writing bash scripts, cron jobs, free webcam software for Linux and Android, an email server for notifications, and a secure website for management. A pain in the butt, but very cheap.

My next system came with several weather proof cameras with built in night vision, an NVR/DVR that sat in my bedroom, and an accompanying app for remote access that could be achieved through a remote connection to my house OR the manufacturer’s cloud server. Both of the above systems recorded continuously. Only the first one had alerts.

My third system is a popular name brand. Each camera is 100% wireless with the option to wire in power, records only on events, and can detect and identify the difference between motion, people, cars, packages, animals, and smoke alarms, with options for sounding an alarm, e911, two-way audio, monitoring service, record only on event or continuously, cloud storage, etc etc.

My current set-up uses the last option as well as the second option. 90% of burglars are looking for the “low hanging fruit” such as houses without cameras or signage. The indoor cams will get a good look at anyone that enters. So it’s a deterrent, as well as a way to hopefully identify any burglars.

When considering where to place the cameras, I visited the Summit County GIS website and printed up photos of my yard and house. I got some graph paper and determine a scale and mapped it on the graph paper, and added in the foot print of the house. I then used a protractor to determine each camera’s field of vision. Then I cut out some stencils that I created with a ruler and compass based on that measurement. I was able to place these stencils on the graph paper to determine where the cameras would be able to see.

Finally, there are two big name camera companies in the news right now for all the wrong reasons. Wyze’s customer database was recently breached https://www.cnn.com/2019/12/30/tech/wyze-data-breach/index.html and Ring cameras have seen a rash of breaches https://www.popularmechanics.com/technology/security/a30242264/ring-doorbell-hack/ These issues can be mitigated against with a couple of important steps. (1) ๐—ก๐—˜๐—ฉ๐—˜๐—ฅ re-use a password ever, anywhere and (2) ๐—”๐—Ÿ๐—ช๐—”๐—ฌ๐—ฆ use long passwords with Two-Factor Authentication or Multi-Factor Authentication.

I’m not saying those brands should be avoided for ever, but maybe wait until they have a chance to learn from their mistakes and make improvements. Whatever you decide, make sure that you consider single-points of failure, and build in redundancy.

I will gladly answer any questions that DO NOT have to do with any of the following: *Details on my specific set-up, such as brands (for my safety) *Whether or not some one should or should not have surveillance of their own property or things in plain view of the public (this is not the place for that conversation)

(How did I learn about CCTV technology, security, and safety? I’ve worked in security, armed protection, and private law enforcement on and off from 2006 to 2012. I have about five years experience as a senior network engineer, and six years in information security. Currently I’m my company’s Information Security Officer)

http://summitmaps.summitoh.net/

(P.S. Password complexity is less important than overall password entropy. So, instead of a complicated password like P@$$w0rd!, consider a pass๐˜ฑ๐˜ฉ๐˜ณ๐˜ข๐˜ด๐˜ฆ such as CorrectHorseBatteryStaple)

Update:

๐˜•๐˜ฐ๐˜ธ I can ๐˜ง๐˜ช๐˜ฏ๐˜ข๐˜ญ๐˜ญ๐˜บ add Ring to my list of recommended brands.

UPDATE: I have removed Ring once again. They share all of your footage and live feeds with law enforcement without court order or subpoena, AND any Ring engineer employees/contractors have full access to not only the footage and live feed, but also the devices.

  • Wyze
  • Arlo
  • ADT
  • Spectrum
  • Zosi

(In no particular order, and with varying levels of challenges and features)