• 0 Posts
  • 19 Comments
Joined 2 years ago
cake
Cake day: October 24th, 2023

help-circle





  • Sure, here’s an opinion.

    Banning is permanent and shouldn’t be first or immediate response. Repeat offenders that cross some quality or quanity threshhold may deserve that, but you should adopt power rangers rules and seek proportional responses, and only escalate as a response where possible.

    Bans should be transparent, contestable, and consistent in their application. However fair or unfair the rules you settle on, the perception of that consistency and impartiality influences the communitiea reaction. Too gentle and your community’s purpose blurs into something unintended, too harsh and your users will flee for greener pastures.

    Asking instead of dictating is the right approach in my opinion so I think you’re aimed in a good direction.

    Three strikes is where I would start, but maybe some strikes count for more than others? This is a hard problem and the answer will change over time. In cases where you can’t be consistent though, you must be transparent to salvage the trust you’re eroding.


  • Text wall incoming, no offense taken for walking away:

    People always talk about distributed denial of service attacks but this is not distributed. It’s concentrated in that one farm, and that informs the types of denial of service attacks it’s suited to carry out without help and influence the govt agencies which might give a shit. A simbox is a machine that can initiate one simultaneous call for each provisioned sim card in it, or whatever other cellular network operations the towers in range support. Look downstream of that for a second though, how many 911 operators are there for that area? Denying service can be more than knocking machines offline! Do I have enough sims to drown them in prerecorded panicked AI calls so they send all their firefighters to the wrong locations? Maybe I want to knife a guy and watch everyone on that block fail to reach 911 while he bleeds out. But they said ‘disable towers’ so let’s focus on denying telephony rather than the service telephony gets you to.

    Bullshit scenario to illustrate a point:

    Healthy customers operating a phone normally may call a variety of internal services once each until their session is established with the appropriate permissions, and then they’re allowed to make calls or touch websites. What if I pick one of those important steps and just hammer the dick off of it so nobody else can make new connections to the network for a period? If their security teams had the idea before me maybe they built some defenses, but maybe not, or maybe the simbox has sims from many carriers so they can get help. Does MobileX even agree that they carry the obligation to respond to this? Do they even know how since they don’t own all the network devices involved? Did they willfully put their thumb up their ass and ignore so they could continue to get money from the bad actor without caring about the consequences? No of course not companies always act morally!

    Imagine my phone attaches to one of three towers in an area. Imagine there’s a back end process that lets a device tell a tower “I’m bcovertigo, so start me a session and look up my plan permissions, then report back with what I’m allowed to access” with a unique identity for the provisioned sim card. What happens when a phone starts that process but just ignores the response and never goes to the next step? What if I repeatedly chain together those half opened requests, and then 100 or so of those processes are just waiting on a response, still consuming resources. Do that for each of 32 sim cards in those pictured simboxes. Now give me a 300 strong swarm of those screaming hydras. 100/minute32sims300simboxes. Can your iphone ever get online if that critical step never completes to tell you your session is allowed to make calls and visit websites? We’re not even considering disruption of IoT security systems. Maybe they found some other flaw that lets them break existing network connections or exhaust something that’s needed for very specific functions to work. Through the magic of computing, anything can go wrong!

    But enough about the attack itself. What are you going to do to stop all this?

    Ban the identifiers of the sim bank? Fuck you they randomize it. Deprovision the sims as you see them used? Fuck you they have 100k of them as reserve ammo. No you have to physically find it and go there in person, which means plying some investigative govt agency for help.









  • Yeah just start your own instance on a different planet with situations that only provoke your preferred amount of existential dread!

    Barring that you’re going to be stuck identifying the sources of this widespread misery and trying to help people overcome it. For most people that might be difficult but I don’t know your budget so I won’t assume. There’s also the option of interacting with machines that pose as happier humans but your goal overall seems contrary to growing that 80% by adding yourself unless I misread your intent.



  • In dungeons and dragons there is a type of hybrid character you can play called an Artificer who treats magic more like technology, and there are a ton of examples in popular media that others have mentioned. I do think you have to determine how and if you’ll keep them distinct if that’s important to your plot, but if they developed alongside eachother maybe the technology of that world relies on magic to work.

    Or maybe your magic relies on elder gods that don’t like the mortal hubris of critiquing the gods works so attempts to unravel magic gets you cursed or worse.

    I think they can go together and the way you fit them can even become a plot point!



  • It sounds like they found themselves in a situation they are not prepared to handle, and they are attempting to rush you through a major decision to compensate. It may not be malicious or a scam, and it may be a fluke that is not indicative of the normal pace and handling of their business, but it does not signal a healthy well run organization. If you do choose to proceed, do so with some level of caution and awareness of that fact. Do not give them any money, and if they give you any information that alarms or frightens you, slow the process down to give your self more time to evaluate.