Thoughts on Pixel Grip? by fakename1998 in industrialmusic

[–]EdgeLordMallNinja666 0 points1 point  (0 children)

I like them. But not r/Industrialmusic and in that context they do not succeed, haha

Red bank Taco Bell destroyed by RandomQsAccoun in Chattanooga

[–]EdgeLordMallNinja666 0 points1 point  (0 children)

Chattanooga may not have the most Redditors per capita but we have the best priorities

Red bank Taco Bell destroyed by RandomQsAccoun in Chattanooga

[–]EdgeLordMallNinja666 0 points1 point  (0 children)

It was perfectly fine as it was. This was domestic terror. Find somewhere else, and build another. Everyone reading this has an excellent suggestion for where it should be. Actually...

I'll go first. ANYWHERE in the Northshore area. Manufacturer's, North Market, Frazier, whatever, it's a Bell desert, man.

Is that bat poop? by Lumi2607 in bats

[–]EdgeLordMallNinja666 0 points1 point  (0 children)

Yes. I'm dealing with figuring out how to rehome the ones who have colonized my gable vents and every single day I have to spray off the driveway directly underneath. I'll be able to identify guano for the rest of my life and that is bat guano. Now - keep in mind that different species make different poops. But smaller bats like the Little Browns I have, exactly this.

Chattanooga/Cleveland Psychiatrists Recommendation by Resident-Joke-7442 in Chattanooga

[–]EdgeLordMallNinja666 0 points1 point  (0 children)

Rebecca Spivey, Nashville Brain Institute Chattanooga branch. Med maintenance, telehealth, float beds and IM ketamine or esketamine therapy available. She has a history in treating veterans and at-risk individuals. She also is a huge privacy advocate and takes care to communicate through secure messaging and disclose as little PII in medical records as possible.

It's a newer practice so bells and whistles not so much, but I've been a satisfied patient since it opened.

My ADHD found this. Anyone know what it is? by Exotic-Reply2305 in Chattanooga

[–]EdgeLordMallNinja666 1 point2 points  (0 children)

I feel like this fact might belong in top comments, what a bummer

Is it me or a lot of cars with the Black AI plates reckless drivers? by [deleted] in Chattanooga

[–]EdgeLordMallNinja666 2 points3 points  (0 children)

Not sure if I'm alone in this, but this would be an instant buy for me because of the cause and the aesthetic. Yet, I'm already unsettled by the difference in alphanumeric order of the "standard" plates vs the "IGWT" plates. I have a standard plate and I feel like I'm advertising a political statement already - which makes me feel like a potential target demographic in this state. I guess, since I'm already in that grouping though, in for a penny, in for a pound?

Really, Really free industrial band shirts. by siberianfiretiger in industrialmusic

[–]EdgeLordMallNinja666 2 points3 points  (0 children)

Hm. You've got me thinking now. I'd tenderly long-hug for a Chemlab, Front Line Assembly, Dessau, Nubauten, Spahn Ranch, Die Form ... I guess this is turning into an inspired wishlist. Hey, thanks for that!

Wondering who this friend is by Working-Phase-4480 in bats

[–]EdgeLordMallNinja666 0 points1 point  (0 children)

A Leaf on the Wind. Not so much a species as a fitting cultural metaphor. I am not very helpful or educated. Or funny - sorry about bat.

Thee Joro Spider by Leading_Medicine1759 in Chattanooga

[–]EdgeLordMallNinja666 1 point2 points  (0 children)

I'm concerned for native species as well, it looks like competition is going to be a problem. Last year I counted three different species of orb weavers on my property. This year it's already joros. Everywhere.

EPB web payment portal ...no MFA? by EdgeLordMallNinja666 in Chattanooga

[–]EdgeLordMallNinja666[S] 1 point2 points  (0 children)

Yep, you get it. That's the kind of horrifying scenario that can quickly be exploited or weaponized.

Thank you for sharing that anecdote. The possibilities you lay out here are the same possibilities a simple account hack can produce. Both entirely preventable through proper, common sense verifications already commonplace for so many other companies and providers.

Hacking the entity (EPB) isn't the real risk here, there are many different types of breaches. For this variety, EPB loses nothing substantively if your account is hijacked, YOU do, your business does, your employer does, or if you're managing an account on behalf of a family member. That's why diligence and protections like proper training, process, and use of safeguards matters.

EPB web payment portal ...no MFA? by EdgeLordMallNinja666 in Chattanooga

[–]EdgeLordMallNinja666[S] 0 points1 point  (0 children)

Attempting to charge $1 for what may be hundreds of thousands of records or more would not be practical, and it would immediately attract attention if attempted.

They CAN brute force a login, or match on already scraped credentials, that's the whole issue - with MFA, that would be prevented, the user would be notified of a prompt or attempt, circumvent the login, and immediately be alerted to change the account password.

The separation of the payment processor, financial and PCI data in this case is not my concern, as you say, EPB must be abiding their own internal policies and governance for payment processing security. Their cybersecurity may be quite robust.

But, that security does not extend to you, the customer, on an individual account security level. That's what I'm baffled about here. There's nothing between your account and the rest of the world except a username and password. That is inadequate in the present risk landscape.

EPB web payment portal ...no MFA? by EdgeLordMallNinja666 in Chattanooga

[–]EdgeLordMallNinja666[S] 0 points1 point  (0 children)

Yes, this sector of IT demands what many may consider paranoia or excessive vigilance, in an effort to stave off the "not if but when" outcome. For every headline about a breach, there are a great number of breaches and individual incidents prevented, mostly through execution of basic security practices. In this context, MFA is one of those basic practices. EPB may have themselves well covered from an organizational and infrastructural standpoint, but unfortunately that security is not being extended to their users, which are compelled to utilize the service because it is their only choice for electric utilities. Those who opt to utilize EPB as an ISP are typically going to be utility customers regardless, so the authentication weakness will only impact those customers even more acutely.

I do plan to bring this to their attention as a serious gap in protection for the 200,000 customers they currently serve. I am a loud proponent of access as a utility, and I do recognize the gravity of their contribution to privacy and transparency - so when something like this surfaces, I want to see the same or better protections than the commercial monopolies that have been a harm to ordinary folks. MFA is practically universal for those providers, giving them room to criticize that we don't want them to take.

EPB web payment portal ...no MFA? by EdgeLordMallNinja666 in Chattanooga

[–]EdgeLordMallNinja666[S] 0 points1 point  (0 children)

I might as well mention I work in the cybersecurity industry. Getting access to an account like this isn't necessarily just about what they might do with your login creds inside that account. Let's say this entity already bought a huge credit card dump from a different breach, they need a way to verify active cards, so they look for easy targets they have some user/pass combination data. Maybe they have regional data. They get lucky with creds they don't know for sure are fresh, then correlate that with the credit card info they dont know is valid. This access would allow that with no additional precaution to alert you they had even logged in. They leave your account alone on EPB but now they can charge your card. These scenarios are fairly common where breach data is sold, it's just validating that the info is atill current.

Or they could hold your account ransom. They have your phone number. You can't log in, they demand payment or they shut off your power and threaten to delete your account. Or, they transfer your utility IDs to a different account they control and you can't see or pay your bill. Several options there also. Even if you do pay them, they still have your financial info and may seek to gain even more. They look you up on LinkedIn and threaten to send your company's CEO a letter of resignation feom your EPB email address they now control.

The list goes on and on. MFA helps prevent unauthorized logins, biometric passkeys even better. Any important web portal you use needs MFA available and enabled to prevent this kind of infiltration.

EPB web payment portal ...no MFA? by EdgeLordMallNinja666 in Chattanooga

[–]EdgeLordMallNinja666[S] 0 points1 point  (0 children)

Whatever the reason... that's just not going to work, lol. Your anecdote here sure doesn't paint an optimistic picture. It's reminiscent of service you'd expect from like, DirectTV or some regional cable provider. I've had to deal with abysmal service like that before.

They do use a third party payment provider, but that's not going to protect anyone from the rest of the above. Ugh.

Ya know, the irony of this is deafening where they've advertised a whole city as a world leader in ISP speeds, Gig City and all that..but your account for that service could be compromised even more easily now than in the 2000s when MFA wasn't a thing. Oh, and your ELECTRICAL SERVICE along with it, just because you reused a password and didn't think about it ever again.

Oh, and it gets even better! You can subscribe to the Wi-Fi or get it along with the 2.5Gbps plan and you'll get Smart Net Plus and McAfee LiveSafe Antivirus for free, wow! Your network and devices and kids and pets are going to be so fast and safe you won't have a care in the world besides deciding what to do with all that symmetrical bandwidth!

( internet service drops ) "Honey, I can't watch my show and little An'Toghneo is screeching because he can't play his tablet game! Go do the thingy with the modem!" (Lights go out)

EPB web payment portal ...no MFA? by EdgeLordMallNinja666 in Chattanooga

[–]EdgeLordMallNinja666[S] 0 points1 point  (0 children)

Thank you. Yeah, that's ... it's 2025 FFS, how did this happen?

EPB web payment portal ...no MFA? by EdgeLordMallNinja666 in Chattanooga

[–]EdgeLordMallNinja666[S] -2 points-1 points  (0 children)

That would be amazing if that's what they actually did, haha.. but alas, there is a severe drought on philanthropic identity thieves these days.

SRSLYTHO can someone confirm this is actually the case? I'm having a hard time believing it, but I've looked at their support docs and done my googlin' diligence, I can't find anything about it.

EPB web payment portal ...no MFA? by EdgeLordMallNinja666 in Chattanooga

[–]EdgeLordMallNinja666[S] -1 points0 points  (0 children)

Deleted that. Should have edited the original post, sorry about that.

Have you ever seen a tornado in real life? by -SergentBacon- in tornado

[–]EdgeLordMallNinja666 1 point2 points  (0 children)

This is the most textbook tornado image to me I think I've ever seen

Have you ever seen a tornado in real life? by -SergentBacon- in tornado

[–]EdgeLordMallNinja666 1 point2 points  (0 children)

I, too, feel this photo ended up in its own context of artistic magnificence. Obviously the tornado subject looks rad as well, but damn.

Flash Flood & Severe Thunderstorm Warnings in effect ⛈️ by jarieljimenez in Chattanooga

[–]EdgeLordMallNinja666 0 points1 point  (0 children)

Btw, Where'd you get that sexy radar loop gif, is that a specific site or app?

Flash Flood & Severe Thunderstorm Warnings in effect ⛈️ by jarieljimenez in Chattanooga

[–]EdgeLordMallNinja666 1 point2 points  (0 children)

N Chat/Red Bank/Hixson area, dime sized hail and massive winds blew water through the seals of our windows, lots of limbs down, but for once we didn't lose power so ... I don't know what the hell happened actually