<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Tai Lam in Science</title>
    <link>https://infosec.press/tailamscience/</link>
    <description>Tai Lam&#39;s adventures in science</description>
    <pubDate>Sat, 11 Apr 2026 23:28:56 +0000</pubDate>
    <item>
      <title>How to add custom font into Bambu Studio</title>
      <link>https://infosec.press/tailamscience/0016-how-to-add-custom-font-into-bambu-studio</link>
      <description>&lt;![CDATA[I believed I would have to make a &#34;sign&#34; from a PNG screenshot, convert it into an SVG, and lastly create an STL file for 3D printing.&#xA;&#xA;However, I realized I can simply add custom fonts into Bambu Studio.&#xA;&#xA;!--more--&#xA;&#xA;This Bambu Lab forum thread&#xA;set me off in the correct direction.&#xA;&#xA;Conclusion: Reddit is not always helpful&#xA;&#xA;Again, there are Reddit threads that are not helpful:&#xA;&#xA;This thread from February 2023, and&#xA;This thread from December 2022.]]&gt;</description>
      <content:encoded><![CDATA[<p>I believed I would have to make a “sign” from a PNG screenshot, convert it into an SVG, and lastly create an STL file for 3D printing.</p>

<p>However, I realized I can simply add custom fonts into Bambu Studio.</p>



<p>This Bambu Lab <a href="https://forum.bambulab.com/t/adding-custom-fonts-to-bambu-studio/5936/51" rel="nofollow">forum thread</a>
set me off in the correct direction.</p>

<h2 id="conclusion-reddit-is-not-always-helpful">Conclusion: Reddit is not always helpful</h2>

<p>Again, there are Reddit threads that are <strong>not</strong> helpful:</p>
<ul><li>This <a href="https://old.reddit.com/r/BambuLab/comments/117jlba/add_custom_fonts_to_bambu_studio/" rel="nofollow">thread</a> from February 2023, and</li>
<li>This <a href="https://old.reddit.com/r/BambuLab/comments/zsrlzu/fonts_in_bambu_studio/" rel="nofollow">thread</a> from December 2022.</li></ul>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0016-how-to-add-custom-font-into-bambu-studio</guid>
      <pubDate>Fri, 14 Nov 2025 17:00:00 +0000</pubDate>
    </item>
    <item>
      <title>15: Considering really small resin 3D printers</title>
      <link>https://infosec.press/tailamscience/0015-considering-really-small-resin-3d-printers</link>
      <description>&lt;![CDATA[This was originally written on November 7, 2025.&#xA;&#xA;So I was wondering about 3D resin printing, as I saw a video from 3D Printing Nerd.&#xA;&#xA;(Random: I think Joel of 3D Printing Nerd is basically like Markiplier in 3D printing, with some of Mark&#39;s hyperactivity toned down.)!--more--&#xA;&#xA;Some thoughts&#xA;&#xA;So, I&#39;ve seen the acronym SLA, which is associated with resin 3D printing, which comes from stereolithography.&#xA;&#xA;I was interested in the TinyMaker, which was the very small resin 3D printer showcased in the video.  There was initially a Kickstarter crowdfunding campaign, and then a continued open-end timeline campaign on IndieGoGo.&#xA;&#xA;The video mentioned that the TinyMaker files are available, and TinyMaker states that it is open source hardware.  However, I had no luck finding the files, at least easily.  The only result I found was this GitHub repository, which was last active in 2018.&#xA;&#xA;Currently I&#39;m a bit wary, as some backers are only recently receiving the TinyMaker 2 years after the campaign ended.  Yes, I know there&#39;s an inherent risk with crowdfunding.  So, I&#39;ll wait until TinyMaker reaches steady public availability.&#xA;&#xA;Alternatives: maybe just get a &#34;normal&#34; sized resin printer?&#xA;&#xA;I might as well consider the currently only option from Prusa for consumers: the Original Prusa SL1S SPEED 3D Printer and CW1S (cure and wash station) bundle.&#xA;&#xA;There is a MSLA (masked SLA) printer from Prusa: Prusa Pro SLX.  However, that looks like a professional industrial machine, and it is still &#34;coming soon&#34; (as of November 2025).&#xA;&#xA;Conclusion&#xA;&#xA;Currently, a comparable product is the Lite3DP Gen 2, which is available on Crowd Supply.]]&gt;</description>
      <content:encoded><![CDATA[<p><em>This was originally written on November 7, 2025.</em></p>

<p>So I was wondering about 3D resin printing, as I saw a <a href="https://youtu.be/3u0idTuaJSo" rel="nofollow">video</a> from 3D Printing Nerd.</p>

<p>(Random: I think Joel of 3D Printing Nerd is basically like Markiplier in 3D printing, with some of Mark&#39;s hyperactivity toned down.)</p>

<h2 id="some-thoughts">Some thoughts</h2>

<p>So, I&#39;ve seen the acronym SLA, which is associated with resin 3D printing, which comes from <a href="https://en.wikipedia.org/wiki/Stereolithography" rel="nofollow">stereolithography</a>.</p>

<p>I was interested in the <a href="https://tinymaker3d.com/" rel="nofollow">TinyMaker</a>, which was the very small resin 3D printer showcased in the video.  There was initially a Kickstarter crowdfunding <a href="https://www.kickstarter.com/projects/tinymaker/tinymaker-3d-printer/description" rel="nofollow">campaign</a>, and then a continued open-end timeline <a href="https://www.indiegogo.com/en/projects/tinymaker/tinymaker-open-source-3d-printer--2" rel="nofollow">campaign</a> on IndieGoGo.</p>

<p>The video mentioned that the TinyMaker files are available, and TinyMaker states that it is open source hardware.  However, I had no luck finding the files, at least easily.  The only result I found was this GitHub <a href="http://github.com/impakho/TinyMaker" rel="nofollow">repository</a>, which was last active in 2018.</p>

<p>Currently I&#39;m a bit wary, as some backers are only recently receiving the TinyMaker 2 years after the campaign ended.  Yes, I know there&#39;s an inherent risk with crowdfunding.  So, I&#39;ll wait until TinyMaker reaches steady public availability.</p>

<h3 id="alternatives-maybe-just-get-a-normal-sized-resin-printer">Alternatives: maybe just get a “normal” sized resin printer?</h3>

<p>I might as well consider the currently only <a href="https://www.prusa3d.com/product/original-prusa-sl1s-speed-3d-printer-cw1s-bundle/" rel="nofollow">option</a> from Prusa for consumers: the Original Prusa SL1S SPEED 3D Printer and CW1S (cure and wash station) bundle.</p>

<p>There is a MSLA (masked SLA) <a href="https://www.prusa3d.com/applications/prusa-pro-slx_236051/" rel="nofollow">printer</a> from Prusa: Prusa Pro SLX.  However, that looks like a professional industrial machine, and it is still “coming soon” (as of November 2025).</p>

<h2 id="conclusion">Conclusion</h2>

<p>Currently, a comparable product is the Lite3DP Gen 2, which is available on <a href="https://www.crowdsupply.com/lite3dp/lite3dp-gen-2" rel="nofollow">Crowd Supply</a>.</p>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0015-considering-really-small-resin-3d-printers</guid>
      <pubDate>Fri, 07 Nov 2025 17:00:00 +0000</pubDate>
    </item>
    <item>
      <title>14: Privacy of mail and deliveries</title>
      <link>https://infosec.press/tailamscience/0014-privacy-of-mail-and-deliveries</link>
      <description>&lt;![CDATA[I need to figure out how to reasonably deal mail and deliveries privately.&#xA;&#xA;How it started&#xA;&#xA;I donated to a local nonprofit in 2024, and I really shouldn&#39;t say this, but I honestly wish I never did.  However, this is not due to a reason you probably expect.&#xA;&#xA;I started to receive significantly more junk mail from charitable nonprofits and groups, more so than usual (at least since the 2020 COVID-19 pandemic).  I won&#39;t name specific names, but this was a local nonprofit which has a total annual budget size between the order of $1 million and $10 million.!--more--&#xA;&#xA;(To the reader: if we know each other IRL, then I&#39;ll tell you who the offending org is; and if your savvy with implementing an actionable fix with the issue below, then maybe we can work out a way for me to get out of this rut of a &#34;situation&#34; -- as if this is or should be by highest priority project to take on right now.  Let&#39;s just say that some of you will be surprised by the org I have in mind, which either intentionally uses the services of data brokers, or at least has some heuristic workflow that is leaking donor info to data brokers.  The overall situation has a bit of a tragic irony.)&#xA;&#xA;I&#39;m (usually) not a vengeful person, at least when it comes to nonprofit orgs genuinely acting in good faith; but I am keeping a running list of these others orgs that engage in buying/selling/sharing snail mail lists as orgs I won&#39;t donate money to in the future, due to their respective disregard for mail privacy.  However, there are 3 national-level orgs that have (so far) never sold out to physical mail lists: the ACLU, including state chapters; the EFF; and the Freedom of the Press Foundation.  I am purposefully excluding comparatively technical groups that would respect the privacy and security of others in general, such as the Signal Foundation and The Tor Project.&#xA;&#xA;On the other hand, the only other way to avoid excessive physical mail list tracking is to donate to small local nonprofits.  (Any method is fine -- if you&#39;re super concerned about protecting your membership info, using a PO box for your mailing address and renewing your member dues via paper check is more than sufficient for most local community members.)  This is because these groups literally don&#39;t have the money to spend for mass mail solicitations or blanket marketing.&#xA;&#xA;After this happened, I expressed to a local activist about how I&#39;m going to go straight for a paid plan on Privacy.com (at least the lower tier) and skip the free plan.  Additionally, I commented that I reaction was essentially the &#34;I can&#39;t believe you&#39;ve done this&#34; meme.  (Somehow, I was initially confused this with the &#34;Charlie bit my finger&#34; meme.)&#xA;&#xA;How it&#39;s going (and the future)&#xA;&#xA;I no longer think it&#39;s safe for me to order computers and ship the delivery to my residential address, using my own debit card.  (That does remind me - I really should get a credit card for better payment protection and everything else that encompasses.)&#xA;&#xA;I remembered that I ordered the HP Dev One in 2022 and the box&#39;s outer shipping box wasn&#39;t even taped closed when it arrived on my doorstep.  Due to my living situation since 2020, I no longer trust anything that goes through the mail, and after Andrew &#34;bunnie&#34; Huang&#39;s assessment of overall supply chain security after the 2024 exploding pager incident in Lebanon, I think it&#39;s about high time I figure out the logistics of shipping to a private mail box (PMB) - or maybe I use a friend&#39;s address and/or credit card to purchase an online only computer (while I pay my friend for the cost, of course).&#xA;&#xA;However, quite a few large computer manufacturers, who primarily have B2B (business-to-business) though also some minor B2C (business-to-consumer) sales, will tell customers that sending deliveries to a PO Box is not allowed during checkout.  This includes Lenovo, HP, and even Framework.  (I have to double check for System76.)  This is partly why I was sad when Costco no longer sold any in-store ThinkPad laptops anymore (one probable cause might be the pandemic, but that&#39;s another matter).&#xA;&#xA;If you have any somewhat serious considerations to become a Linux distro maintainer or even a package manager (such as the AUR/MPR), you should at least consider this while threat modeling.  I recall Ariadne Conill tweeting about how a Lenovo ThinkPad laptop that they tried ordering online was suspiciously redirected to Langely, Virginia while en route to their home in early 2022, which was symptomatic of mail interdiction.  However, those tweets were deleted around late 2022 or early 2023.]]&gt;</description>
      <content:encoded><![CDATA[<p>I need to figure out how to reasonably deal mail and deliveries privately.</p>

<h2 id="how-it-started">How it started</h2>

<p>I donated to a local nonprofit in 2024, and I really shouldn&#39;t say this, but I honestly wish I never did.  However, this is not due to a reason you probably expect.</p>

<p>I started to receive significantly more junk mail from charitable nonprofits and groups, more so than usual (at least since the 2020 COVID-19 pandemic).  I won&#39;t name specific names, but this was a local nonprofit which has a total annual budget size between the order of $1 million and $10 million.</p>

<p>(To the reader: if we know each other IRL, then I&#39;ll tell you who the offending org is; and if your savvy with implementing an actionable fix with the issue below, then maybe we can work out a way for me to get out of this rut of a “situation” — as if this is or should be by highest priority project to take on right now.  Let&#39;s just say that some of you will be surprised by the org I have in mind, which either intentionally uses the services of data brokers, or at least has some heuristic workflow that is leaking donor info to data brokers.  The overall situation has a bit of a tragic irony.)</p>

<p>I&#39;m (usually) not a vengeful person, at least when it comes to nonprofit orgs genuinely acting in good faith; but I am keeping a running list of these others orgs that engage in buying/selling/sharing snail mail lists as orgs I won&#39;t donate money to in the future, due to their respective disregard for mail privacy.  However, there are 3 national-level orgs that have (so far) never sold out to physical mail lists: the <a href="https://www.aclu.org/" rel="nofollow">ACLU</a>, including state chapters; the <a href="https://www.eff.org/" rel="nofollow">EFF</a>; and the <a href="https://freedom.press/" rel="nofollow">Freedom of the Press Foundation</a>.  I am purposefully excluding comparatively technical groups that would respect the privacy and security of others in general, such as the <a href="https://en.wikipedia.org/wiki/Signal_Foundation" rel="nofollow">Signal Foundation</a> and <a href="https://en.wikipedia.org/wiki/The_Tor_Project" rel="nofollow">The Tor Project</a>.</p>

<p>On the other hand, the only other way to avoid excessive physical mail list tracking is to donate to small local nonprofits.  (Any method is fine — if you&#39;re super concerned about protecting your membership info, using a PO box for your mailing address and renewing your member dues via paper check is more than sufficient for most local community members.)  This is because these groups literally don&#39;t have the money to spend for mass mail solicitations or blanket marketing.</p>

<p>After this happened, I expressed to a local activist about how I&#39;m going to go straight for a paid plan on Privacy.com (at least the lower tier) and skip the free plan.  Additionally, I commented that I reaction was essentially the “I can&#39;t believe you&#39;ve done this” <a href="https://knowyourmeme.com/memes/i-cant-believe-youve-done-this" rel="nofollow">meme</a>.  (Somehow, I was initially confused this with the “Charlie bit my finger” <a href="https://en.wikipedia.org/wiki/Charlie_Bit_My_Finger" rel="nofollow">meme</a>.)</p>

<h2 id="how-it-s-going-and-the-future">How it&#39;s going (and the future)</h2>

<p>I no longer think it&#39;s safe for me to order computers and ship the delivery to my residential address, using my own debit card.  (That does remind me – I really should get a credit card for better payment protection and everything else that encompasses.)</p>

<p>I remembered that I ordered the <a href="https://hpdevone.com/" rel="nofollow">HP Dev One</a> in 2022 and the box&#39;s outer shipping box wasn&#39;t even taped closed when it arrived on my doorstep.  Due to my living situation since 2020, I no longer trust anything that goes through the mail, and after Andrew “bunnie” Huang&#39;s <a href="https://www.bunniestudios.com/blog/2024/turning-everyday-gadgets-into-bombs-is-a-bad-idea/" rel="nofollow">assessment</a> of overall supply chain security after the 2024 exploding pager <a href="https://en.wikipedia.org/wiki/2024_Lebanon_electronic_device_attacks" rel="nofollow">incident</a> in Lebanon, I think it&#39;s about high time I figure out the logistics of shipping to a private mail box (PMB) – or maybe I use a friend&#39;s address and/or credit card to purchase an online only computer (while I pay my friend for the cost, of course).</p>

<p>However, quite a few large computer manufacturers, who primarily have B2B (business-to-business) though also some minor B2C (business-to-consumer) sales, will tell customers that sending deliveries to a PO Box is not allowed during checkout.  This includes Lenovo, HP, and even Framework.  (I have to double check for System76.)  This is partly why I was sad when Costco no longer sold any in-store ThinkPad laptops anymore (one probable cause might be the pandemic, but that&#39;s another matter).</p>

<p>If you have any somewhat serious considerations to become a Linux distro maintainer or even a package manager (such as the AUR/MPR), you should at least consider this while threat modeling.  I recall <a href="https://ariadne.space/" rel="nofollow">Ariadne Conill</a> tweeting about how a Lenovo ThinkPad laptop that they tried ordering online was suspiciously redirected to <a href="https://en.wikipedia.org/wiki/Langley,_Virginia" rel="nofollow">Langely, Virginia</a> while en route to their home in early 2022, which was symptomatic of mail <a href="https://en.wikipedia.org/wiki/Interdiction#United_States" rel="nofollow">interdiction</a>.  However, those tweets were deleted around late 2022 or early 2023.</p>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0014-privacy-of-mail-and-deliveries</guid>
      <pubDate>Sat, 16 Nov 2024 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>13: Bitwarden KDF settings</title>
      <link>https://infosec.press/tailamscience/0013-bitwarden-kdf-settings</link>
      <description>&lt;![CDATA[There was a guide from early 2023 on what to change in the default KDF settings of Bitwarden.!--more--&#xA;&#xA;(The guide has been saved on the Wayback Machine and archive&amp;period;today.)&#xA;&#xA;You must log in via browser to edit these settings.  (Neither the desktop apps nor the mobile apps can change the following settings.)&#xA;&#xA;From the main screen in Bitwarden, navigate through the following menus: Security (vertical menu)   Keys (horizontal)&#xA;Select Argon2id for &#34;KDF algorithm&#34; and enter 10 for &#34;KDF iterations&#34;.&#xA;Enter 64 for &#34;KDF memory (MB)&#34; and 8 for &#34;KDF parallelism&#34; (number of threads).&#xA;If you changed any settings, then click on the &#34;Change KDF&#34; button to save any changes (and Bitwarden will log you out of your account on all devices).&#xA;    Otherwise, if no changes were made, then you can leave the &#34;Keys&#34; menu.&#xA;&#xA;Personal context&#xA;&#xA;I need to make sure I have something I can reference when I set up organization accounts on Bitwarden for colleagues and friends.&#xA;&#xA;I vaguely remember that this was discussed roughly around the same about how the default KDF for LUKS (full disk encryption on Linux) was set up.  Back in April-May 2023, the sources for episode 132 of the the Surveillance Report podcast was released during the time when the podcast released roughly biweekly - so the podcast lagged at least 1-2 weeks behind current events.&#xA;&#xA;This forum thread helped to date this news story, as well as this assessment.]]&gt;</description>
      <content:encoded><![CDATA[<p>There was a <a href="https://artemislena.eu/posts/2023/04/bitwarden-kdf.html" rel="nofollow">guide</a> from early 2023 on what to change in the default <a href="https://en.wikipedia.org/wiki/Key_derivation_function" rel="nofollow">KDF</a> settings of <a href="https://en.wikipedia.org/wiki/Bitwarden" rel="nofollow">Bitwarden</a>.</p>

<p>(The guide has been saved on the <a href="https://web.archive.org/web/20240915133321/https://artemislena.eu/posts/2023/04/bitwarden-kdf.html" rel="nofollow">Wayback Machine</a> and <a href="https://archive.is/ze8IL" rel="nofollow">archive.today</a>.)</p>

<p>You must log in via browser to edit these settings.  (Neither the desktop apps nor the mobile apps can change the following settings.)</p>
<ol><li>From the main screen in Bitwarden, navigate through the following menus: Security (vertical menu) &gt; Keys (horizontal)</li>
<li>Select <code>Argon2id</code> for “KDF algorithm” and enter <code>10</code> for “KDF iterations”.</li>
<li>Enter 64 for “KDF memory (MB)” and 8 for “KDF parallelism” (number of threads).</li>
<li>If you changed any settings, then click on the “Change KDF” button to save any changes (and Bitwarden will log you out of your account on all devices).
<ul><li>Otherwise, if no changes were made, then you can leave the “Keys” menu.</li></ul></li></ol>

<h2 id="personal-context">Personal context</h2>

<p>I need to make sure I have something I can reference when I set up organization accounts on Bitwarden for colleagues and friends.</p>

<p>I vaguely remember that this was discussed roughly around the same about how the default KDF for LUKS (full disk encryption on Linux) was set up.  Back in April-May 2023, the <a href="https://sr.weblog.lol/2023/05/sr132" rel="nofollow">sources</a> for <a href="https://www.youtube.com/watch?v=U-YeDGfINXs" rel="nofollow">episode 132</a> of the the <em>Surveillance Report</em> <a href="https://sr.omg.lol/" rel="nofollow">podcast</a> was released during the time when the podcast released roughly biweekly – so the podcast lagged at least 1-2 weeks behind current events.</p>

<p>This forum <a href="https://mjg59.dreamwidth.org/66429.html" rel="nofollow">thread</a> helped to date this news story, as well as this <a href="https://dys2p.com/en/2023-05-luks-security.html" rel="nofollow">assessment</a>.</p>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0013-bitwarden-kdf-settings</guid>
      <pubDate>Thu, 14 Nov 2024 20:00:00 +0000</pubDate>
    </item>
    <item>
      <title>12: Secure Boot on Surface Pro 4 with Pop!\_OS</title>
      <link>https://infosec.press/tailamscience/0012-secure-boot-on-surface-pro-4-with-pop-os</link>
      <description>&lt;![CDATA[I think I&#39;m overthinking this.  I think I&#39;ll follow the instructions for Secure Boot for the Linux Surface project and see how that goes.!--more--&#xA;&#xA;The GH project&#39;s wiki references following steps outlined in the ArchWiki.&#xA;&#xA;Additionally, I came across the following sources:&#xA;&#xA;Super User thread from Stack Exchange&#xA;GitHub gist from July 2022&#xA;A blog post from January 2022&#xA;&#xA;I haven&#39;t been able to sit down and try this -- but expect that this worked if I don&#39;t come back to follow up.&#xA;&#xA;]]&gt;</description>
      <content:encoded><![CDATA[<p>I think I&#39;m overthinking this.  I think I&#39;ll follow the instructions for Secure Boot for the <a href="https://github.com/linux-surface/linux-surface/wiki/Secure-Boot" rel="nofollow">Linux Surface</a> project and see how that goes.</p>

<p>The GH project&#39;s wiki references following steps outlined in the <a href="https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot#shim" rel="nofollow">ArchWiki</a>.</p>

<p>Additionally, I came across the following sources:</p>
<ul><li>Super User <a href="https://superuser.com/questions/1446182/how-to-boot-pop-os-in-uefi-mode-without-disabling-secure-boot-on-my-computer" rel="nofollow">thread</a> from Stack Exchange</li>
<li>GitHub <a href="https://gist.github.com/sudo-panda/11c80b20ff84bc18b5982614f189d5c0" rel="nofollow">gist</a> from July 2022</li>
<li>A blog <a href="https://blog.clarence-mesina.com/2022/01/06/secure-boot-pop-os" rel="nofollow">post</a> from January 2022</li></ul>

<p>I haven&#39;t been able to sit down and try this — but expect that this worked if I don&#39;t come back to follow up.</p>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0012-secure-boot-on-surface-pro-4-with-pop-os</guid>
      <pubDate>Thu, 15 Aug 2024 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>11: Identifying online job scams</title>
      <link>https://infosec.press/tailamscience/0011-identifying-online-job-scams</link>
      <description>&lt;![CDATA[About three days ago, I was reading federal government online sources about online job scams.!--more--&#xA;&#xA;There is resource page from the FTC and another FTC page to report online scams, as well as the the Internet Crime Complaint Center (IC3) page from the FBI.&#xA;&#xA;Conclusion&#xA;&#xA;Most traditional jobs don&#39;t advertise on Craigslist.  I almost got burned, but luckily I smoked this scam out before I could even apply for it.&#xA;&#xA;The particular one I was looking at struck me as strange, as it has been the only Craigslist posting (of any type) that didn&#39;t use Craigslist&#39;s prviate e-mail relay/address option.  Due to this, I kept looking at the e-mail address (as it was a Yahoo e-mail address, instead of from an official e-mail address from a real American healthcare corporation) until I realized I was looking at a scam -- it was very much like looking at a very well camoflauged animal for a long time before spotting it.&#xA;&#xA;An offer that&#39;s &#34;too good to be true&#34; doesn&#39;t have to be hyperbolically exaggerated to the point of being comical and super obvious -- it can also be a toned-down, realistic decoy.&#xA;&#xA;Also, it is a good rule of thumb to cross-reference and check if the same online job listing you&#39;ve stumbled upon on an aggregate site (such as Craigslist or Indeed) can be found on a better first-party source, such as the company website.&#xA;&#xA;]]&gt;</description>
      <content:encoded><![CDATA[<p>About three days ago, I was reading federal government online sources about online job scams.</p>

<p>There is resource <a href="https://consumer.ftc.gov/jobs-and-making-money/jobs" rel="nofollow">page</a> from the FTC and another FTC <a href="https://reportfraud.ftc.gov/" rel="nofollow">page</a> to report online scams, as well as the the Internet Crime Complaint Center (IC3) <a href="https://www.ic3.gov/" rel="nofollow">page</a> from the FBI.</p>

<h2 id="conclusion">Conclusion</h2>

<p>Most traditional jobs don&#39;t advertise on Craigslist.  I almost got burned, but luckily I smoked this scam out before I could even apply for it.</p>

<p>The particular one I was looking at struck me as strange, as it has been the only Craigslist posting (of any type) that didn&#39;t use Craigslist&#39;s prviate e-mail relay/address option.  Due to this, I kept looking at the e-mail address (as it was a Yahoo e-mail address, instead of from an official e-mail address from a real American healthcare corporation) until I realized I was looking at a scam — it was very much like looking at a very well camoflauged animal for a long time before spotting it.</p>

<p>An offer that&#39;s “too good to be true” doesn&#39;t have to be hyperbolically exaggerated to the point of being comical and super obvious — it can also be a toned-down, realistic decoy.</p>

<p>Also, it is a good rule of thumb to cross-reference and check if the same online job listing you&#39;ve stumbled upon on an aggregate site (such as Craigslist or Indeed) can be found on a better first-party source, such as the company website.</p>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0011-identifying-online-job-scams</guid>
      <pubDate>Wed, 14 Aug 2024 12:00:00 +0000</pubDate>
    </item>
    <item>
      <title>10: eBay&#39;s rate-limiting when logging in</title>
      <link>https://infosec.press/tailamscience/0010-ebays-rate-limiting-when-logging-in</link>
      <description>&lt;![CDATA[eBay is sometimes tedious to deal with.  I use the site to buy electronic parts for repair, but some aspects of the site are annoying to deal with.!--more--&#xA;&#xA;For example, if you use a password manager, then you should wait a few seconds (at least 5 seconds, if I had to pick name a number) before submitting your password.  (Then, you will be prompted with an hCaptcha, if you are using a VPN; followed by an SMS message for 2FA.)&#xA;&#xA;I received an error message, identical to that described in an EcommerceBytes article from January 2021.  I think this was because I tried to log in very quickly, assisted by KeePassXC.&#xA;&#xA;This YouTube video from August 2023 also shows the rate limiting.&#xA;&#xA;This is sort of annoying, as checking my order status on eBay is currently my only way to check the shipping status of orders, since even the U.S. Postal Service completely blocks VPNs (at least Mullvad VPN) when I tried doing this about two days ago.]]&gt;</description>
      <content:encoded><![CDATA[<p>eBay is sometimes tedious to deal with.  I use the site to buy electronic parts for repair, but some aspects of the site are annoying to deal with.</p>

<p>For example, if you use a password manager, then you should wait a few seconds (at least 5 seconds, if I had to pick name a number) before submitting your password.  (Then, you will be prompted with an hCaptcha, if you are using a VPN; followed by an SMS message for 2FA.)</p>

<p>I received an error message, identical to that described in an EcommerceBytes <a href="https://www.ecommercebytes.com/2021/01/15/ebay-thwarts-shoppers-it-says-are-searching-too-fast/" rel="nofollow">article</a> from January 2021.  I think this was because I tried to log in very quickly, assisted by KeePassXC.</p>

<p>This YouTube <a href="https://www.youtube.com/watch?v=BVc6rzI0Fxw" rel="nofollow">video</a> from August 2023 also shows the rate limiting.</p>

<p>This is sort of annoying, as checking my order status on eBay is currently my only way to check the shipping status of orders, since even the U.S. Postal Service completely blocks VPNs (at least Mullvad VPN) when I tried doing this about two days ago.</p>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0010-ebays-rate-limiting-when-logging-in</guid>
      <pubDate>Wed, 14 Aug 2024 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>9: Virgo laptop from System76</title>
      <link>https://infosec.press/tailamscience/0009-virgo-laptop-from-system76</link>
      <description>&lt;![CDATA[There probably hasn&#39;t been much concrete and confirmed info about the upcoming Virgo laptop from System76.  There&#39;s some more, but I wanted to get into the basics, and then I can follow up later, as this will be out of date anyways once Virgo is officially released.!--more--&#xA;&#xA;Louis Rossmann made a video on Virgo in mid-July 2023.  However, not all the details he discussed was correct, according to paper.  Whatever applicable software and firmware will be using GPLv3, but the hardware will be using the strongly reciprocal version of the CERN Open Hardware Licence (CERN-OHL-S).&#xA;&#xA;Bryan Lunduke also made a video about Virgo in late July 2023.  Lunduke&#39;s reporting had more accurate details.  (Yes, I know Lunduke has gone off the deep end, but he is one of the few people online who can accurately report on Virgo.)&#xA;&#xA;Virgo&#39;s project files can be found on System76&#39;s GitHub repo.&#xA;&#xA;There hasn&#39;t been much activity since 2023.  I suppose it&#39;s because System76 has preparing to release its Rust-based COSMIC desktop environment (DE) in 2024.  The alpha should be released in August 2024... is it August 8th?  (I believe this is true?  However, I can&#39;t seem to find the date anymore.  Maybe I should listen to episode 10 of the System76 podcast...)]]&gt;</description>
      <content:encoded><![CDATA[<p>There probably hasn&#39;t been much concrete and confirmed info about the upcoming Virgo laptop from System76.  There&#39;s some more, but I wanted to get into the basics, and then I can follow up later, as this will be out of date anyways once Virgo is officially released.</p>

<p>Louis Rossmann made a <a href="https://www.youtube.com/watch?v=-4KoUAW3kyI" rel="nofollow">video</a> on Virgo in mid-July 2023.  However, not all the details he discussed was correct, according to paper.  Whatever applicable software and firmware will be using GPLv3, but the hardware will be using the strongly reciprocal version of the CERN Open Hardware Licence (CERN-OHL-S).</p>

<p>Bryan Lunduke also made a <a href="https://www.youtube.com/watch?v=SGxOcUynqwk" rel="nofollow">video</a> about Virgo in late July 2023.  Lunduke&#39;s reporting had more accurate details.  (Yes, I know Lunduke has gone off the deep end, but he is one of the few people online who can accurately report on Virgo.)</p>

<p>Virgo&#39;s project files can be found on System76&#39;s GitHub <a href="https://github.com/system76/virgo/" rel="nofollow">repo</a>.</p>

<p>There hasn&#39;t been much activity since 2023.  I suppose it&#39;s because System76 has preparing to release its Rust-based <a href="https://github.com/pop-os/cosmic-epoch" rel="nofollow">COSMIC</a> desktop environment (DE) in 2024.  The alpha should be released in August 2024... is it August 8th?  (I believe this is true?  However, I can&#39;t seem to find the date anymore.  Maybe I should listen to <a href="https://system76.transistor.fm/10" rel="nofollow">episode 10</a> of the System76 podcast...)</p>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0009-virgo-laptop-from-system76</guid>
      <pubDate>Sat, 27 Jul 2024 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>8: COSMIC DE and apps</title>
      <link>https://infosec.press/tailamscience/0008-cosmic-de-and-apps</link>
      <description>&lt;![CDATA[Here are some links regarding the COSMIC desktop environment (DE) from System76 and desktop apps being designed with the COSMIC framework in mind.!--more--&#xA;&#xA;Library libcosmic repo&#xA;    Reddit announcement&#xA;    Documentation&#xA;This cosmic-epoch repo is for the COSMIC DE itself&#xA;iced GUI library in Rust&#xA;    GH repo&#xA;    iced documentation&#xA;Just framework for running custom commands&#xA;    GH [repo](https://github.com/casey/just}&#xA;COSMIC application (and applet) template repo&#xA;COSMIC Project Collection list&#xA;Catppuccin&#39;s pastel theme for COSMIC]]&gt;</description>
      <content:encoded><![CDATA[<p>Here are some links regarding the COSMIC desktop environment (DE) from System76 and desktop apps being designed with the COSMIC framework in mind.</p>
<ul><li>Library <code>libcosmic</code> <a href="https://github.com/pop-os/libcosmic" rel="nofollow">repo</a>
<ul><li>Reddit <a href="https://old.reddit.com/r/pop_os/comments/xs87ed/is_iced_replacing_gtk_apps_for_the_new_cosmic" rel="nofollow">announcement</a></li>
<li><a href="https://pop-os.github.io/libcosmic/cosmic" rel="nofollow">Documentation</a></li></ul></li>
<li>This <code>cosmic-epoch</code> <a href="https://github.com/pop-os/cosmic-epoch" rel="nofollow">repo</a> is for the COSMIC DE itself</li>
<li><code>iced</code> GUI <a href="https://iced.rs" rel="nofollow">library</a> in Rust
<ul><li>GH <a href="https://github.com/iced-rs/iced" rel="nofollow">repo</a></li>
<li><code>iced</code> <a href="https://docs.rs/iced/latest/iced" rel="nofollow">documentation</a></li></ul></li>
<li><a href="https://just.systems" rel="nofollow">Just</a> framework for running custom commands
<ul><li>GH [repo](<a href="https://github.com/casey/just%7D" rel="nofollow">https://github.com/casey/just}</a></li></ul></li>
<li>COSMIC application (and applet) template <a href="https://github.com/edfloreshz/cosmic-app-template" rel="nofollow">repo</a></li>
<li>COSMIC Project Collection <a href="https://github.com/edfloreshz/cosmic-project-collection" rel="nofollow">list</a></li>
<li>Catppuccin&#39;s pastel <a href="https://github.com/catppuccin/cosmic-desktop" rel="nofollow">theme</a> for COSMIC</li></ul>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0008-cosmic-de-and-apps</guid>
      <pubDate>Thu, 25 Jul 2024 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>7: Using Ffmpeg to edit videos</title>
      <link>https://infosec.press/tailamscience/0007-using-ffmpeg-to-edit-videos</link>
      <description>&lt;![CDATA[Originally collected July 6, 2024&#xA;&#xA;I&#39;m saving links I&#39;ll use for editing videos with Ffmpeg.!--more--&#xA;&#xA;Here are some of those links:&#xA;&#xA;Convert video from 4K to 1080p on Video StackExchange or (SE)&#xA;Cut video based on timestamps on Stack Overflow (or SO)&#xA;Several strategies to merge videos&#xA;    Article from Stockstack&#xA;    Q&amp;A from SO&#xA;    Q&amp;A from Super User&#xA;    Article from Creatomate]]&gt;</description>
      <content:encoded><![CDATA[<p><em>Originally collected July 6, 2024</em></p>

<p>I&#39;m saving links I&#39;ll use for editing videos with Ffmpeg.</p>

<p>Here are some of those links:</p>
<ul><li>Convert video from 4K to 1080p on <a href="https://video.stackexchange.com/questions/14907/how-to-downsample-4k-to-1080p-using-ffmpeg-while-maintaining-the-quality" rel="nofollow">Video StackExchange</a> or (SE)</li>
<li>Cut video based on timestamps on <a href="https://stackoverflow.com/questions/18444194/cutting-multimedia-files-based-on-start-and-end-time-using-ffmpeg" rel="nofollow">Stack Overflow</a> (or SO)</li>
<li>Several strategies to merge videos
<ul><li>Article from <a href="https://shotstack.io/learn/use-ffmpeg-to-concatenate-video/" rel="nofollow">Stockstack</a></li>
<li>Q&amp;A from <a href="https://stackoverflow.com/questions/7333232/how-to-concatenate-two-mp4-files-using-ffmpeg" rel="nofollow">SO</a></li>
<li>Q&amp;A from <a href="https://superuser.com/questions/1059245/ffmpeg-join-two-mp4-files-with-ffmpeg-on-command-line" rel="nofollow">Super User</a></li>
<li>Article from <a href="https://creatomate.com/blog/how-to-join-multiple-videos-into-one-using-ffmpeg" rel="nofollow">Creatomate</a></li></ul></li></ul>
]]></content:encoded>
      <guid>https://infosec.press/tailamscience/0007-using-ffmpeg-to-edit-videos</guid>
      <pubDate>Thu, 25 Jul 2024 03:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>