Cybercriminals are abusing Google’s infrastructure, creating emails that appear to come from Google in order to persuade people into handing over their Google account credentials. This attack, first flagged by Nick Johnson, the lead developer of the Ethereum Name Service (ENS), a blockchain equivalent of the popular internet naming convention known as the Domain Name System (DNS). Nick received a very official looking security alert about a subpoena allegedly issued to Google by law enforcement to information contained in Nick’s Google account. A URL in the email pointed Nick to a sites.google.com page that looked like an exact copy of the official Google support portal.
As a computer savvy person, Nick spotted that the official site should have been hosted on accounts.google.com and not sites.google.com. The difference is that anyone with a Google account can create a website on sites.google.com. And that is exactly what the cybercriminals did. Attackers increasingly use Google Sites to host phishing pages because the domain appears trustworthy to most users and can bypass many security filters. One of those filters is DKIM (DomainKeys Identified Mail), an email authentication protocol that allows the sending server to attach a digital signature to an email. If the target clicked either “Upload additional documents” or “View case”, they were redirected to an exact copy of the Google sign-in page designed to steal their login credentials. Your Google credentials are coveted prey, because they give access to core Google services like Gmail, Google Drive, Google Photos, Google Calendar, Google Contacts, Google Maps, Google Play, and YouTube, but also any third-party apps and services you have chosen to log in with your Google account. The signs to recognize this scam are the pages hosted at sites.google.com which should have been support.google.com and accounts.google.com and the sender address in the email header. Although it was signed by accounts.google.com, it was emailed by another address. If a person had all these accounts compromised in one go, this could easily lead to identity theft.
Don’t follow links in unsolicited emails or on unexpected websites.
Carefully look at the email headers when you receive an unexpected mail.
Verify the legitimacy of such emails through another, independent method.
Don’t use your Google account (or Facebook for that matter) to log in at other sites and services. Instead create an account on the service itself.
Technical details Analyzing the URL used in the attack on Nick, (https://sites.google.com[/]u/17918456/d/1W4M_jFajsC8YKeRJn6tt_b1Ja9Puh6_v/edit) where /u/17918456/ is a user or account identifier and /d/1W4M_jFajsC8YKeRJn6tt_b1Ja9Puh6_v/ identifies the exact page, the /edit part stands out like a sore thumb. DKIM-signed messages keep the signature during replays as long as the body remains unchanged. So if a malicious actor gets access to a previously legitimate DKIM-signed email, they can resend that exact message at any time, and it will still pass authentication. So, what the cybercriminals did was: Set up a Gmail account starting with me@ so the visible email would look as if it was addressed to “me.” Register an OAuth app and set the app name to match the phishing link Grant the OAuth app access to their Google account which triggers a legitimate security warning from no-reply@accounts.google.com This alert has a valid DKIM signature, with the content of the phishing email embedded in the body as the app name. Forward the message untouched which keeps the DKIM signature valid. Creating the application containing the entire text of the phishing message for its name, and preparing the landing page and fake login site may seem a lot of work. But once the criminals have completed the initial work, the procedure is easy enough to repeat once a page gets reported, which is not easy on sites.google.com. Nick submitted a bug report to Google about this. Google originally closed the report as ‘Working as Intended,’ but later Google got back to him and said it had reconsidered the matter and it will fix the OAuth bug.
Leo XIV was closest without going over, now he gets to play Papal Plinko
Antipope JD Vance is waiting in the Showcase Showdown
the Conclave turning a large dial labelled Woke and looking at the audience like in The Price is Right
I assume that’s basically how it goes yeah
i hate seeing people now making fun of those who care about privacy online. i've seen people saying things like "well they already have your data. what are companies going to do with it" and it's like, that's not the point. it's that companies /shouldn't/ be able to have my data and sell it. am i aware they probably already have my data? yes, absolutely. but i'm still going to try and keep them from monetizing it any further, why are we defending companies selling data they shouldn't have to begin with though?
why do people think victorian orphans were like. the peak of sheltered pure innocence
Y'all ever make the mistake of trying to buy a taco and going to O'Tacos?
For a while in my life I legitimately considered moving to Germany. There’s multiple reasons I inevitably ended up staying in the US but one of the big ones was that one time when I was in Germany and wanted some salsa the closest thing I could find was basically just tomato sauce.
Friends go watch this! Conceptually interesting, beautifully drawn (it's just an animatic so far, but we all love Kiana's style, let's be real), and genuinely funny. I can't wait to see where this goes!
FEBRUARY 28TH 10AM PST!!!!!!!
Today (19 Aug), I'm appearing at the San Diego Union-Tribune Festival of Books. I'm on a 2:30PM panel called "Return From Retirement," followed by a signing:
https://www.sandiegouniontribune.com/festivalofbooks
It's a breathtaking fraud: SoCal Gas, the largest gas company in America, spent millions secretly paying people to oppose California environmental regulations, then illegally stuck its customers with the bill. We Californians were forced to pay to lobby against our own survival:
https://www.sacbee.com/news/politics-government/capitol-alert/article277266828.html
The criminal scheme is spelled out in eye-watering detail in a superb investigative report by Joe Rubin and Ari Plachta for the Sacramento Bee, which names the law firms and individual lawyers involved in the scam.
Here's the situation: SoCal Gas is California's private, regulated gas monopoly. They are allowed to lobby, but are legally required to charge their lobbying activities to their shareholders, and are prohibited from raising customer rates to pay for lobbying.
The company spent years secretly violating this rule, in the sleaziest way possible: working with corporate cartels like the California Restaurant Association and BizFed, the monopoly paid BigLaw white-shoe firms to procure people who posed as concerned citizens in order to oppose climate regulations that are essential to the state's very survival.
The bill topped $36 million – and it was illegally charged to its customers, the Californians whose immediate health and long-term survival these efforts opposed. SoCal Gas refuses to disclose the full extent of the spending, as do its lawyer-procurers, who cite legal confidentiality and a First Amendment right to secretly seek to influence policy in their refusal to disclose their profits from this illegal conduct.
The law firms involved are a who's-who of California's most prominent corporate fixers, including Reichman Jorgensen and Holland & Knight. The partners involved have a long rap sheet for anti-climate dirty tricking, most notably Jennifer Hernandez, notorious in climate justice history for an incident where activists claim she posed as one of them, infiltrating a campaign to force corporate despoilers to clean up their pollution in order to sabotage it, while secretly on a wealthy, prominent landowner's payroll.
Hernandez claims to care about the environment and says that her longstanding, corporate-funded, extensive campaigns and lawsuits against state environmental regulations are motivated by concern over their impact on working people. Her firm, Holland & Knight, denies serving SoCal Gas in opposing gas regulations, but it received $594k in ratepayer dollars, and submitted comments opposing the rules on its own behalf. Those comments were nearly identical to the comments submitted by SoCal Gas.
Hernandez also represents an obscure organization called The Two Hundred for Home Ownership in "a flurry of lawsuits" over California Air Resources Board rules on pollution, seeking to overturn the state's landmark climate change regulations.
Two Hundred for Home Ownership was founded by Robert Apodaca, who told the Bee that Hernandez's work for him is pro bono and not funded by SoCal Gas, but his entry into the fray occurred just as SoCalGas was founding an astroturf group called Californians for Fair and Balanced Energy (C4BES), which pretended to be an independent organization, disguising its relationship with SoCal Gas.
Apodaca is also founder of United Latinos Vote, an organization that had been largely dormant for seven years, not receiving any donations, until 2018, when the California Building Industry Association gave it $99k. The CBIA is a large-dollar recipient of donations from SoCal Gas, and its CEO insists that it was not acting on SoCal Gas's behalf when it made its unpredented donation to Apodaca.
The CBIA donation to United Latinos Vote was forerunner to a flood of corporate donations from the likes of Chevron, Marathon and Phillips 66. Shortly after receiving this cash, United Latinos Vote ran a full page ad in the LA Times, accusing the Sierra Club of pushing for anti-gas appliance rules that would harm working class Latino families.
This ad, in turn, featured prominently in advocacy by the SoCal Gas front group C4BES, funded with $29.1m in ratepayer money, which it then spent seeking to link clean appliance rules with anti-Latino racism. A quarter of California's carbon emissions come from home gas use.
SoCal Gas is regulated by the California Public Utility Commission (CPUC), which tolerated this mounting illegal conduct for many years, even as the company circulated internal memos as early as 2015 discussing its plans to oppose electrification in the state on the basis that it constituted "a significant risk to our business."
But last year, CPUC fined SoCal Gas $10m. Now, CPUC's Public Advocate office has filed a damning, extensive report on SoCal Gas's unlawful conduct, seeking $80m in rate cuts to compensate Californians for the funds misappropriated to protect the company's shareholder interests:
https://docs.cpuc.ca.gov/PublishedDocs/Efile/G000/M517/K407/517407314.PDF
Additionally, the Public Advocate is demanding $233m in fines for the company's refusal to allow investigators to audit its books and discover the full extent of the fraud.
SoCal Gas is the nation's largest utility, but (incredibly), it's not the dirtiest. That prize goes to Ohio's FirstEnergy, which handed $60m in ratepayer dollars to state politicians in illegal bribes in exchange for coal and nuclear subsidies and cancellation of state climate rules. That scandal led to GOP speaker of the Ohio House Larry Householder being sentenced to 20 years in prison:
https://en.wikipedia.org/wiki/Ohio_nuclear_bribery_scandal
There is something extraordinarily sleazy about using ratepayers' own money to lobby against their interests. SoCal Gas and its Big Law enablers have funneled millions in Californian's money into campaigns to poison us and boil us alive, and they did it while using workers and racialized people as human shields.
I'm kickstarting the audiobook for "The Internet Con: How To Seize the Means of Computation," a Big Tech disassembly manual to disenshittify the web and make a new, good internet to succeed the old, good internet. It's a DRM-free book, which means Audible won't carry it, so this crowdfunder is essential. Back now to get the audio, Verso hardcover and ebook:
http://seizethemeansofcomputation.org
If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
https://pluralistic.net/2023/08/19/cooking-the-books-with-gas/#reichman-jorgensen
Image: Maryland GovPics (modified) https://www.flickr.com/photos/mdgovpics/6635539089/
Jackie (modified) https://www.flickr.com/photos/79874304@N00/197532792
CC BY 2.0 https://creativecommons.org/licenses/by/2.0/
Hey, here’s a concept. What if we stopped saying “but autistic people CAN do all those things” (erasing high support needs) and instead started saying “not being able to do those things doesn’t impact someone’s value as a person nor does it make it okay to commit eugenics”.
i hate this stupid fucking video my girlfriend keeps playing it when we’re sharing comfortable moments of silence and it’s ruined by this stupid fucking orange slut getting water boarded by toothpaste