Avatar

Me? Gongaga

@peevishpants / peevishpants.tumblr.com

Hi. I'm Weiwei and I got exiled from tumblr 2018-2021 LOL
Anonymous asked:

I’ve been following you for a long time now (I’m talking like, fe:a era long) I think my old iPod (yes, IPOD) still has one of your old drawings as it’s wallpaper ^_^ I wanna say that I’ve always loved your drawings but I **LOVE** the stuff you’ve been posting lately, especially your diaspora comic!!!! It’s so compelling!!! It’s already been a while, but I’m happy you’ve made your return!!!

Omg hello, we meet again then!!! That's wild. That's so wild. That's so cool. Whatever you're up to, I hope you're doing well!! And if you're not, I hope you have the energy and support to climb out of wherever you are!! I'm pinning this message when I decide the "i got unbanned from tumblr" message has outlived its purpose wow omg fe:a.... i should draw the lonq again maybe... his iconic character design pout is actually what got me into drawing mouths like = instead of just — LOOOL anyway also I'm glad you like my recent stuff too!!

ALSO if you see this do you remember what the drawing was? I'd love to know, no matter how well the drawing has aged LOL

just played 5 hours of totk and ive done 2 shrines so im still in Tutorial Land technically and i died in the 2nd shrine about 3 times. is this normal am i on track to success or about to never get out of tutorial land alive

upd8: i love ultrahand i love rotating and combining stuff i love Link Blender Sim!!!! every time i see a steering wheel lying around i get an emotional high and a gentle buzz of excitement

absolutely tragic for me specifically that f1 races occur on weekends and not weekdays! weekends are prime friend hangout times AND parent visiting times so i have to schedule all that AND somehow watch snippets of the qualy/race but only in intermittent bits

every word out of guillermo del toro’s mouth is the most hardcore thing i’ve ever heard and he says it all so casually like he doesn’t even realize how much of a gothic visionary he is 

Since childhood, I’ve been faithful to monsters. I have been saved and absolved by them, because monsters, I believe, are patron saints of our blissful imperfection, and they allow and embody the possibility of failing

I STILL THINK ABOUT THIS EVERY DAY OF MY LIFE

Yo okie Guillermo has some of the best quotes and lines I’ve ever heard, here are just a few of his quotes that have me questioning life:

What is a ghost? A tragedy condemned to repeat itself time and again? A moment of pain, perhaps. Something dead which still seems to be alive. An emotion suspended in time. Like a blurred photograph. Like an insect trapped in amber.”

I knew that monsters were far more gentle and more desirable than the monsters living inside ‘nice people.’ Accepting that you are a monster gives you the leeway to not behave like one. When you deny being a monster, you behave like one.”

“When you see something or experience something extraordinary, you can’t go back to normal… I think that that’s the way I see the supernatural-as happening in mundane circumstances or to people who are unprepared”

“To learn what we fear is to learn who we are. Horror defines our boundaries and illuminates our souls”

“Any legend, any creature, any symbol we ever stumble on, already exists in a vast cosmic reservoir where archetypes wait. Shapes looming outside our Platonic cave. We naturally believe ourselves clever and wise, so advanced, and those who came before us so naïve and simple…when all we truly do is echo the order of the universe, as it guides us…”

And the last but certainly not the least:

“In fairy tales, monsters exist to be a manifestation of something that we need to understand, not only a problem we need to overcome, but also they need to represent, much like angels represent the beautiful, pure, eternal side of the human spirit, monsters need to represent a more tangible, more mortal side of being human: aging, decay, darkness and so forth. And I believe that monsters originally, when we were cavemen and you know, sitting around a fire, we needed to explain the birth of the sun and the death of the moon and the phases of the moon and rain and thunder. And we invented creatures that made sense of the world: a serpent that ate the sun, a creature that ate the moon, a man in the moon living there, things like that. And as we became more and more sophisticated and created sort of a social structure, the real enigmas started not to be outside. The rain and the thunder were logical now. But the real enigmas became social. All those impulses that we were repressing: cannibalism, murder, these things needed an explanation. The sex drive, the need to hunt, the need to kill, these things then became personified in monsters. Werewolves, vampires, ogres, this and that. I feel that monsters are here in our world to help us understand it. They are an essential part of a fable.”

Avatar

New Things to Beware on the Internet

On May 3rd, Google released 8 new top-level domains (TLDs) -- these are new values like .com, .org, .biz, domain names. These new TLDs were made available for public registration via any domain registrar on May 10th.

Usually, this should be a cool info, move on with your life and largely ignore it moment.

Except a couple of these new domain names are common file type extensions: ".zip" and ".mov".

This means typing out a file name could resolve into a link that takes you to one of these new URLs, whether it's in an email, on your tumblr blog post, a tweet, or in file explorer on your desktop.

What was previously plain text could now resolve as link and go to a malicious website where people are expecting to go to a file and therefore download malware without realizing it.

Folk monitoring these new domain registrations are already seeing some clearly malicious actors registering and setting this up. Some are squatting the domain names trying to point out what a bad idea this was. Some already trying to steal your login in credentials and personal info.

This is what we're seeing only 12 days into the domains being available. Only 5 days being publicly available.

What can you do? For now, be very careful where you type in .zip or .mov, watch what website URLs you're on, don't enable automatic downloads, be very careful when visiting any site on these new domains, and do not type in file names without spaces or other interrupters.

I'm seeing security officers for companies talking about wholesale blocking .zip and .mov domains from within the company's internet, and that's probably wise.

Be cautious out there.

Avatar

I really want to reiterate how this can go wrong frequently and fast, folks.

A malicious actor sets up a page with an auto-downloader squatting on a domain name that matches a common zip file name like photos DOT zip. This website is set up to start an auto downloader upon being visited, downloading a zip file with the same name as the URL which contains malicious software (virus, worm, keylogger, etc).

Scenario.

Someone you know well sends you an email or text with promised photos attached. The email even reads something like this.

Because .zip is now a TLD, that plain text is automatically formatted into a link to malicious actor's website without them having to send you anything.

Folk with family with iPhones or iPads that are sent multiple photos in one go might be familiar with iCloud's tendency to automatically compile them into zip file for the sender and less savvy tech users have trouble NOT doing that.

These same less savvy users, or even just someone just not thinking in the moment, will click that .zip link, not realizing it isn't the the same as clicking on the promised attachment.

They download a file that matches the name they expected. They open it because they were expecting that file and it's from a trusted source. Except the file they downloaded isn't the one that was sent by their trusted source and now they have malware.

Another Scenario.

An IT person tries to send you an email with instructions on how to resolve a problem with a commonly used filename like install-repair DOT zip or to install new software like microsoft-office DOT zip.

The email may start with instructions of where to go get the legitimate file to do the install or repair, but now a line later in the instructions is also has a link to a .zip URL. A user, already frazzled by IT problems, may click it to ensure they have the right file. Again, they download malicious code from a squatting website or it prompts them with a fake login and now the squatting website has stolen their login credentials for a legitimate site. All due to an expected email from a trusted source.

Above you can see microsoft-office DOT zip is already out there with a fake Microsoft login screen waiting to steal your credentials.

These risks are already out there now because the TLD has been activated.

Plain text on old post are already being resolved into links to the new websites.

Here you can see a tweet from 2021, long before .zip was a domain name, now resolves that plan text into a clickable link. You'll start seeing this everywhere, and malicious actors do not have to lift a finger to send it to you.

Yes, a lot of users aren't going to click that, but a lot of folk will. Whomever is squatting on photos DOT zip domain name has made a one time payment to have access to anyone that ever sees that file name typed out.

In an example of an existing squatter site, clientdocs DOT zip is exactly one such pre-setup .zip domain name that initiates an automatic download. This one may be harmless, but the set ups are already out there and waiting to catch folk.

It's an unnecessary and risky can of worms that's been opened up.

Holy Unforced Errors, Batman.