Avatar

Hello Discord My Old Friend

@stormphoenix / stormphoenix.tumblr.com

Hi, I'm Storm, and I spent 10 minutes picking this font but I'm too lazy to change my theme.

I think my asks and messaging are back! I found out I had access to my messages again because a pornbot messaged me :D

in honor of 4chan exploding, I want to remind you all that they used to do “raids” on Tumblr.

they tried to flood the popular tags with gore and porn. this was when Homestuck was at its peak, so they were a target too. (side note: tags barely functioned at all at this point so trying to make them useless was like throwing a molotov into an already burning building but try telling that to 4channers)

but the Homestuck fandom was ready and countered by flooding the tag with weirder, more explicit Homestuck porn and gore.

to the point that the trolls themselves got weirded out, fucked off, and never attempted a “raid” again.

everyone moved on but I stayed there because that is one of the funniest fucking things to happen on this website.

hey americans there is a recall on testosterone gel because they found benzene in it! please check the lot numbers on your batches, benzene is really not something you want to be rubbing into your skin, also you might be eligible for compensation because this is just insane what the fuck

more on this page:

I made it easier to back up your blog with tumblr-utils

Hey friends! I've seen a few posts going around about how to back up your blog in case tumblr disappears. Unfortunately the best backup approach I've seen is not the built-in backup option from tumblr itself, but a python app called tumblr-utils. tumblr-utils is a very, very cool project that deserves a lot of credit, but it can be tough to get working. So I've put together something to make it a bit easier for myself that hopefully might help others as well.

If you've ever used Docker, you know how much of a game-changer it is to have a pre-packaged setup for running code that someone else got working for you, rather than having to cobble together a working environment yourself. Well, I just published a tumblr-utils Docker container! If you can get Docker running on your system - whether Windows, Linux, or Mac - you can tell it to pull this container from dockerhub and run it to get a full backup of your tumblr blog that you can actually open in a web browser and navigate just like the real thing!

This is still going to be more complicated than grabbing a zip file from the tumblr menu, but hopefully it lowers the barrier a little bit by avoiding things like python dependency errors and troubleshooting for your specific operating system.

If you happen to have an Unraid server, I'm planning to submit it to the community apps repository there to make it even easier.

Drop me a message or open an issue on github if you run into problems!

Tesla accused of hacking odometers to weasel out of warranty repairs

A lawsuit filed in February accuses Tesla of remotely altering odometer values on failure-prone cars, in a bid to push these lemons beyond the 50,000 mile warranty limit:

The suit was filed by a California driver who bought a used Tesla with 36,772 miles on it. The car's suspension kept failing, necessitating multiple servicings, and that was when the plaintiff noticed that the odometer readings for his identical daily drive were going up by ever-larger increments. This wasn't exactly subtle: he was driving 20 miles per day, but the odometer was clocking 72.35 miles/day. Still, how many of us monitor our daily odometer readings?

In short order, his car's odometer had rolled over the 50k mark and Tesla informed him that they would no longer perform warranty service on his lemon. Right after this happened, the new mileage clocked by his odometer returned to normal. This isn't the only Tesla owner who's noticed this behavior: Tesla subreddits are full of similar complaints:

This isn't Tesla's first dieselgate scandal. In the summer of 2023, the company was caught lying to drivers about its cars' range:

Drivers noticed that they were getting far fewer miles out of their batteries than Tesla had advertised. Naturally, they contacted the company for service on their faulty cars. Tesla then set up an entire fake service operation in Nevada that these calls would be diverted to, called the "diversion team." Drivers with range complaints were put through to the "diverters" who would claim to run "remote diagnostics" on their cars and then assure them the cars were fine. They even installed a special xylophone in the diversion team office that diverters would ring every time they successfully deceived a driver.

These customers were then put in an invisible Tesla service jail. Their Tesla apps were silently altered so that they could no longer book service for their cars for any reason – instead, they'd have to leave a message and wait several days for a callback. The diversion center racked up 2,000 calls/week and diverters were under strict instructions to keep calls under five minutes. Eventually, these diverters were told that they should stop actually performing remote diagnostics on the cars of callers – instead, they'd just pretend to have run the diagnostics and claim no problems were found (so if your car had a potentially dangerous fault, they would falsely claim that it was safe to drive).

Most modern cars have some kind of internet connection, but Tesla goes much further. By design, its cars receive "over-the-air" updates, including updates that are adverse to drivers' interests. For example, if you stop paying the monthly subscription fee that entitles you to use your battery's whole charge, Tesla will send a wireless internet command to your car to restrict your driving to only half of your battery's charge.

This means that your Tesla is designed to follow instructions that you don't want it to follow, and, by design, those instructions can fundamentally alter your car's operating characteristics. For example, if you miss a payment on your Tesla, it can lock its doors and immobilize itself, then, when the repo man arrives, it will honk its horn, flash its lights, back out of its parking spot, and unlock itself so that it can be driven away:

Some of the ways that your Tesla can be wirelessly downgraded (like disabling your battery) are disclosed at the time of purchase. Others (like locking you out and summoning a repo man) are secret. But whether disclosed or secret, both kinds of downgrade depend on the genuinely bizarre idea that a computer that you own, that is in your possession, can be relied upon to follow orders from the internet even when you don't want it to. This is weird enough when we're talking about a set-top box that won't let you record a TV show – but when we're talking about a computer that you put your body into and race down the road at 80mph inside of, it's frankly terrifying.

Obviously, most people would prefer to have the final say over how their computers work. I mean, maybe you trust the manufacturer's instructions and give your computer blanket permission to obey them, but if the manufacturer (or a hacker pretending to be the manufacturer, or a government who is issuing orders to the manufacturer) starts to do things that are harmful to you (or just piss you off), you want to be able to say to your computer, "OK, from now on, you take orders from me, not them."

In a state of nature, this is how computers work. To make a computer ignore its owner in favor of internet randos, the manufacturer has to build in a bunch of software countermeasures to stop you from reconfiguring or installing software of your choosing on it. And sure, that software might be able to withstand the attempts of normies like you and me to bypass it, but given that we'd all rather have the final say over how our computers work, someone is gonna figure out how to get around that software. I mean, show me a 10-foot fence and I'll show you an 11-foot ladder, right?

All jokes about Tumblr being the social media platform of last resort every time another big player shits the bed are gonna stop being funny real fast if we end up getting a big influx of ex-4channers.

Clean it up hiro….

Former infosec worker here, my 2 cents on this:

>4chan was running on an EXTREMELY OLD version of php so it was vulnerable as fuck

>hacker found vulnerability back on 2021 and played the long game so they could take down the entire site

>alongside admin info, entire source code leaked

>site used deprecated connections to MySQL server, insecure as shit

>site had a file with whitelisted countries that could post freely while others needed to wait for 900 SECONDS TO GET THE CAPTCHA.

>whole code base needs to be updated in order to get the server running up again, which could take a long long time, and could be deemed not worthy by Hiro, so this may actually be the end of 4chan

Remember kids, update and patch vulnerabilities if you don't want to get nuked out of the face of the earth by the hacker known as 4chan

Avatar
Reblogged

Update: hack is confirmed, but it's unclear how much user info has been leaked. (4chan doesn't have many registered users)

According to bluesky, this was the last post made before the site went under:

You are using an unsupported browser and things might not work as intended. Please make sure you're using the latest version of Chrome, Firefox, Safari, or Edge.