<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Lydia’s Substack]]></title><description><![CDATA[My thoughts on cybersecurity, privacy, entrepreneurship, and technology.]]></description><link>https://www.lydiaoncybersecurity.com</link><image><url>https://substackcdn.com/image/fetch/$s_!HiSn!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7829d887-468a-496b-9fb2-585d89161211_1123x1123.png</url><title>Lydia’s Substack</title><link>https://www.lydiaoncybersecurity.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 05 May 2026 11:30:36 GMT</lastBuildDate><atom:link href="https://www.lydiaoncybersecurity.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Lydia Stepanek]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[lydiaoncybersecurity@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[lydiaoncybersecurity@substack.com]]></itunes:email><itunes:name><![CDATA[Lydia Stepanek]]></itunes:name></itunes:owner><itunes:author><![CDATA[Lydia Stepanek]]></itunes:author><googleplay:owner><![CDATA[lydiaoncybersecurity@substack.com]]></googleplay:owner><googleplay:email><![CDATA[lydiaoncybersecurity@substack.com]]></googleplay:email><googleplay:author><![CDATA[Lydia Stepanek]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Yes, even celebrities and billionaires get tricked by phishing emails.]]></title><description><![CDATA[Note: This blog post is a write up of my recent talk at BSides NYC.]]></description><link>https://www.lydiaoncybersecurity.com/p/how-three-celebrity-scandals-started</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/how-three-celebrity-scandals-started</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Sun, 19 Jan 2025 20:45:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Khy0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5277bd4-0f7a-45ac-9c63-ceb4e915bf74_619x486.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Note: This blog post is a write up of my recent <a href="https://www.youtube.com/watch?v=XlzOYh5HPOQ">talk</a> at BSides NYC. </em></p><p>Do you remember the 2014 Sony hack, when North Korean hackers hacked into Sony?</p><p>Or how about the 2016 hack when a Russian hacking group leaked all of the Clinton campaign&#8217;s emails to WikiLeaks right before the U.S. presidential election? </p><p>Finally, what about the 2020 hack when the <em>National Enquirer</em> used Jeff Bezos's personal photos photos to blackmail him?</p><h2>What do these stories all have in common?</h2><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5277bd4-0f7a-45ac-9c63-ceb4e915bf74_619x486.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01b0e0f9-fda4-4780-886d-707b0439c781_556x681.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/daf5c840-9aa2-4e40-817c-16d991251e39_425x494.png&quot;}],&quot;caption&quot;:&quot;Remember these?&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a7cb7b7-3356-4d53-8acd-e2c8d21dddaa_1456x474.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>They all began with phishing attacks.</p><p>In today's blog post, we're going to walk through these three examples, starting from the least sophisticated phishing attack (Podesta) to the most sophisticated (Bezos). And we&#8217;ll learn how you can protect yourself from similar hacks happening to you. (Spoiler alert: I built an anti-phishing plugin to protect people against attacks like this. But more on that later.)</p><p>Let's start with the least sophisticated attack.</p><h2><strong>The John Podesta Email Leak: A Bit.ly Blunder</strong></h2><p>In 2016, a Russian hacking group wanted to sow discord in the 2016 presidential election, so they decided to target John Podesta, Hilary Clinton&#8217;s campaign manager. Here is the actual email that Fancy Bear &#8212; the hacking group &#8212; sent to Podesta:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4lfj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4lfj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png 424w, https://substackcdn.com/image/fetch/$s_!4lfj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png 848w, https://substackcdn.com/image/fetch/$s_!4lfj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png 1272w, https://substackcdn.com/image/fetch/$s_!4lfj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4lfj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png" width="1235" height="694" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:694,&quot;width&quot;:1235,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:220331,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4lfj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png 424w, https://substackcdn.com/image/fetch/$s_!4lfj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png 848w, https://substackcdn.com/image/fetch/$s_!4lfj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png 1272w, https://substackcdn.com/image/fetch/$s_!4lfj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b85379-10ea-4dc5-9355-8afb62989fed_1235x694.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://www.cbsnews.com/news/the-phishing-email-that-hacked-the-account-of-john-podesta/">CBS News</a></figcaption></figure></div><p>Right away, you may notice something weird about this email: if Google wanted you to reset your password, they probably would not send you to a Bitly link. (Bitly happens to be one of the top phishing sites in the world.)</p><p>John Podesta is a smart guy: he knew the email looked fishy, so he emailed IT and asked if it was real. <br><br>This was the response from <a href="https://slate.com/technology/2016/12/an-interview-with-charles-delavan-the-it-guy-whose-typo-led-to-the-podesta-email-hack.html">Charles Delevan</a>, head of IT:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Uv_M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Uv_M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp 424w, https://substackcdn.com/image/fetch/$s_!Uv_M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp 848w, https://substackcdn.com/image/fetch/$s_!Uv_M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp 1272w, https://substackcdn.com/image/fetch/$s_!Uv_M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Uv_M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp" width="620" height="313" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:313,&quot;width&quot;:620,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:53920,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Uv_M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp 424w, https://substackcdn.com/image/fetch/$s_!Uv_M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp 848w, https://substackcdn.com/image/fetch/$s_!Uv_M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp 1272w, https://substackcdn.com/image/fetch/$s_!Uv_M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e61b93-59c4-4003-a406-4721743f51bf_620x313.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://www.cbsnews.com/news/the-phishing-email-that-hacked-the-account-of-john-podesta/">CBS News</a></figcaption></figure></div><p>You read that right: &#8220;This is a legitimate email.&#8221; (If even IT department heads fall for scams like this, nobody is safe.) </p><p>In Delevan&#8217;s defense, Delevan&#8217;s response email contains the correct google password reset link: <a href="http://myaccount.google.com/security">myaccount.google.com/security</a>. The problem is that John Podesta went back and clicked the link in his <em>original</em> email: the Bitly link, which redirected to a cloned Google login site. Within seconds of Podesta typing his password into the cloned site, Fancy Bear snagged his password &#8212; and soon after, all of his emails too.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!30fN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!30fN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png 424w, https://substackcdn.com/image/fetch/$s_!30fN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png 848w, https://substackcdn.com/image/fetch/$s_!30fN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png 1272w, https://substackcdn.com/image/fetch/$s_!30fN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!30fN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png" width="1242" height="697" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:697,&quot;width&quot;:1242,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:314128,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!30fN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png 424w, https://substackcdn.com/image/fetch/$s_!30fN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png 848w, https://substackcdn.com/image/fetch/$s_!30fN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png 1272w, https://substackcdn.com/image/fetch/$s_!30fN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97293d81-2c06-4e6a-9c16-fa385cd195b7_1242x697.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The John Podesta email leak used a fake password reset link, the lowest-sophistication type of attack we&#8217;ll be discussing.</figcaption></figure></div><h3>So how could this have been prevented? Enter Too Phishy.</h3><p>Last year, I built a tool called <a href="https://workspace.google.com/marketplace/app/too_phishy/802749066565">Too Phishy</a>: a Gmail plugin that attaches to your Gmail inbox. </p><p>If I could go back in time and force John Podesta to use my plugin prior to getting hacked, here&#8217;s what he would have seen when he opened the email from Fancy Bear:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6yu1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6yu1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png 424w, https://substackcdn.com/image/fetch/$s_!6yu1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png 848w, https://substackcdn.com/image/fetch/$s_!6yu1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png 1272w, https://substackcdn.com/image/fetch/$s_!6yu1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6yu1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png" width="890" height="490" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:490,&quot;width&quot;:890,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:165296,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6yu1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png 424w, https://substackcdn.com/image/fetch/$s_!6yu1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png 848w, https://substackcdn.com/image/fetch/$s_!6yu1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png 1272w, https://substackcdn.com/image/fetch/$s_!6yu1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04843a43-f366-4991-ad05-5f4d43cd45e4_890x490.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Depicted: a recreation of the famous Fancy Bear hacking email, had fate been kinder to John Podesta.</figcaption></figure></div><p>In short, Too Phishy analyzes all the links in an email and highlights the well known phishing sites. Had Podesta used my plugin, Clinton&#8217;s emails might have remained safe, she might have won the election, and 2016 wouldn&#8217;t have marked the end of democr&#8230; nevermind, that&#8217;s a blog post for another time&#8230;</p><h2>Now for a medium sophistication attack: the 2014 Sony hack.</h2><p>Like the Clinton hack, the Sony hack also began with a phishing link.</p><p>In 2014, North Korean wanted revenge for Sony&#8217;s release of the movie <em>The Interview</em>, a satirical movie that depicted the assassination of Kim Jung Un. So North Korea&#8217;s preeminent hacking group, Lazarus Group (also famous for the Bangladesh Bank <a href="https://www.lydiaoncybersecurity.com/p/the-38-most-important-dates-in-cybersecurity#:~:text=central">heist</a> and the <a href="https://www.lydiaoncybersecurity.com/p/the-38-most-important-dates-in-cybersecurity#:~:text=hospital">WannaCry hack</a>), began a spear phishing attack that targeted Sony executives. This was one of the many phishing emails that Lazarus Group sent to various Sony executives:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!12Hl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!12Hl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png 424w, https://substackcdn.com/image/fetch/$s_!12Hl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png 848w, https://substackcdn.com/image/fetch/$s_!12Hl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png 1272w, https://substackcdn.com/image/fetch/$s_!12Hl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!12Hl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png" width="590" height="650" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:650,&quot;width&quot;:590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:284822,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!12Hl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png 424w, https://substackcdn.com/image/fetch/$s_!12Hl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png 848w, https://substackcdn.com/image/fetch/$s_!12Hl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png 1272w, https://substackcdn.com/image/fetch/$s_!12Hl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4efd1e83-57cf-4816-b433-e1399a682f8a_590x650.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Email source: the DOJ criminal <a href="https://www.justice.gov/opa/press-release/file/1092091/dl">complaint</a> against Park Jin Hyok, a Lazarus Group hacker.</figcaption></figure></div><p>Like the Podesta email, Lazarus Group&#8217;s email purports to be from a legitimate tech company, Facebook. But you&#8217;ll quickly notice that the &#8220;Log In&#8221; button links to <a href="http://fancug.com">fancug.com</a>, a domain name that is registered in South Korea. That's a red flag; since Facebook is a United States-based company, all of Facebook's &#8220;.com&#8221; URL domain names should be registered in the United States. Another red flag: fancug.com is not a top million link, i.e. one of the top million most commonly visited websites in the world.</p><p>When clicked, the fancug.com link directed the email recipient to a site hosted in South Korea, which, when visited, downloaded malware on the recipient&#8217;s computer and initiated a command-and-control relationship with two servers in North Korea. </p><p>Knowing this, I designed Too Phishy to show email recipients the country of registration for every link an email. And it also checks if the link is a top million link:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vZwN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vZwN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png 424w, https://substackcdn.com/image/fetch/$s_!vZwN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png 848w, https://substackcdn.com/image/fetch/$s_!vZwN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png 1272w, https://substackcdn.com/image/fetch/$s_!vZwN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vZwN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png" width="1027" height="815" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:815,&quot;width&quot;:1027,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:174995,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vZwN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png 424w, https://substackcdn.com/image/fetch/$s_!vZwN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png 848w, https://substackcdn.com/image/fetch/$s_!vZwN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png 1272w, https://substackcdn.com/image/fetch/$s_!vZwN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb177913-b87f-48f5-a670-e1f74c28478a_1027x815.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foiled again, hackers!</figcaption></figure></div><p>As you&#8217;re probably aware, hackers love causing two things: financial damage (usually accomplished by wiping victims&#8217; hard drives), and embarrassment (by leaking personal information). Just like in the Clinton campaign hack, the Sony hackers leaked victims&#8217; personal emails in order to cause maximum embarrassment. Amy Pascal, the executive who had arguably the <a href="https://www.theguardian.com/film/2015/feb/05/amy-pascal-leaving-sony-pictures-email-leak">most</a> cringe-worthy emails, promptly resigned (it&#8217;s always the highest-ranking woman who gets fired, isn&#8217;t it?).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JN4b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JN4b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png 424w, https://substackcdn.com/image/fetch/$s_!JN4b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png 848w, https://substackcdn.com/image/fetch/$s_!JN4b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png 1272w, https://substackcdn.com/image/fetch/$s_!JN4b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JN4b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png" width="619" height="486" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:486,&quot;width&quot;:619,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:507759,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JN4b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png 424w, https://substackcdn.com/image/fetch/$s_!JN4b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png 848w, https://substackcdn.com/image/fetch/$s_!JN4b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png 1272w, https://substackcdn.com/image/fetch/$s_!JN4b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b79442-122d-4266-b4b2-ddd4f3ddff6e_619x486.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This <a href="https://www.usmagazine.com/celebrity-news/news/angelina-jolie-chats-with-amy-pascal-after-leaked-spoiled-brat-diss-20141112/">article</a> makes reference to one of Pascal&#8217;s many cringe-worthy emails. </figcaption></figure></div><p>Ironically, <em>The Interview </em>got so much press from the Sony hack that despite the cancellation of its wide theater release, it still made $40 million, earning back its budget. And, perhaps even more surprisingly, Amy Pascal bounced back to produce the billion-dollar <em>Spider-Man: Homecoming</em> only two years later in 2017 and the Oscar-nominated <em>Little Women</em> in 2019. <em>Take that, Lazarus Group.</em></p><h2>And finally, the most advanced attack: the Jeff Bezos hack.</h2><p>Often, when I speak about Jeff Bezos at conferences, no one has heard about his enormous phishing scandal. </p><p>Here are the bare facts: Jeff Bezos was (and still is, unfortunately) the owner of <em>The Washington Post</em>. Around the beginning of 2018, Mohammed bin Salman (MBS), the Crown Prince of Saudi Arabia, became frustrated with the <em>Post</em>&#8217;s unfavorable coverage of the Middle East. So, as world leaders are wont to do, MBS decided to hack into Bezos&#8217; phone and blackmail Bezos into more favorable coverage. </p><p>As part of his plan, MBS sent Bezos the following WhatsApp message after the two met at a party:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HgK6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HgK6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png 424w, https://substackcdn.com/image/fetch/$s_!HgK6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png 848w, https://substackcdn.com/image/fetch/$s_!HgK6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png 1272w, https://substackcdn.com/image/fetch/$s_!HgK6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HgK6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png" width="594" height="549" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:549,&quot;width&quot;:594,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:300904,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HgK6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png 424w, https://substackcdn.com/image/fetch/$s_!HgK6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png 848w, https://substackcdn.com/image/fetch/$s_!HgK6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png 1272w, https://substackcdn.com/image/fetch/$s_!HgK6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cc54e23-c19b-45d0-8039-39161f92e47d_594x549.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://embed.documentcloud.org/documents/6668313-FTI-Report-into-Jeff-Bezos-Phone-Hack/?embed=1">FTI Consulting report</a> into Jeff Bezos Phone Hack</figcaption></figure></div><p>MBS then sent a follow-up message to Bezos that contained a video. Embedded within the video was a zero-click exploit &#8212; that is, malware that silently installs itself on the recipient device without the recipient needing to click anything &#8211; which siphoned all the photos from Bezos&#8217; phone to servers in the Middle East. </p><p>Then, suddenly, in January 2019, Bezos and his wife McKenzie Scott announced their divorce. Following the news, the <em>National Enquirer</em> published a cover story that mentioned &#8220;the cheating photos that ended his marriage&#8221;:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Z4S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Z4S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png 424w, https://substackcdn.com/image/fetch/$s_!5Z4S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png 848w, https://substackcdn.com/image/fetch/$s_!5Z4S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png 1272w, https://substackcdn.com/image/fetch/$s_!5Z4S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Z4S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png" width="425" height="494" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:494,&quot;width&quot;:425,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:405158,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Z4S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png 424w, https://substackcdn.com/image/fetch/$s_!5Z4S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png 848w, https://substackcdn.com/image/fetch/$s_!5Z4S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png 1272w, https://substackcdn.com/image/fetch/$s_!5Z4S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca7230a-936a-4887-af0a-8dd2054bfa62_425x494.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When Bezos saw the article, he knew that someone had hacked his phone.</p><p>Now, unlike the other two phishing hacks in this post, the Bezos hack was <a href="https://www.businessinsider.com/fbi-no-proof-saudi-arabia-hacked-jeff-bezos-phone-report-2021-12">never</a> investigated by the FBI, so we&#8217;ll have to trust the FTI Consulting <a href="https://embed.documentcloud.org/documents/6668313-FTI-Report-into-Jeff-Bezos-Phone-Hack/?embed=1">report</a> that Bezos commissioned. </p><p>One month after the <em>Enquirer</em> article was published, Bezos penned <a href="https://medium.com/@jeffreypbezos/no-thank-you-mr-pecker-146e3922310f">this</a> blog post, revealing that he had been hacked and that the National Enquirer was using these hacked photos to blackmail him. He even published the blackmail letter itself, with the itemized list of photos they had stolen from his phone (including a &#8220;below the belt selfie&#8221;).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0a-M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0a-M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png 424w, https://substackcdn.com/image/fetch/$s_!0a-M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png 848w, https://substackcdn.com/image/fetch/$s_!0a-M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png 1272w, https://substackcdn.com/image/fetch/$s_!0a-M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0a-M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png" width="1456" height="431" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:431,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121061,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0a-M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png 424w, https://substackcdn.com/image/fetch/$s_!0a-M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png 848w, https://substackcdn.com/image/fetch/$s_!0a-M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png 1272w, https://substackcdn.com/image/fetch/$s_!0a-M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271c76eb-6c26-450b-a16c-4cd6201565f7_1890x560.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The famous blog post: &#8220;If in my position I can&#8217;t stand up to this kind of extortion, how many people can?&#8221; - <a href="https://medium.com/@jeffreypbezos/no-thank-you-mr-pecker-146e3922310f">@jeffreypbezos</a></figcaption></figure></div><h3>How could Bezos have protected himself? </h3><p>The truth is that if someone is willing to pay a <a href="https://web.archive.org/web/20210615000000*/https://www.newyorker.com/magazine/2021/02/08/the-next-cyberattack-is-already-under-way">million dollars</a> for a zero-click exploit to get into your phone, it&#8217;s pretty hard to stop them. But there&#8217;s one obvious thing Bezos could have done: turned off automatic downloads in WhatsApp (in fact, in all of his messaging apps). This would have prevented from the zero click exploit from getting onto his phone in the first place.</p><p>Are you thinking, &#8220;Eh, I&#8217;m not worried about this happening to me. I&#8217;m not a billionaire&#8221;? Think again: a recent study from iVerify <a href="https://www.wired.com/story/iverify-spyware-detection-tool-nso-group-pegasus/">found</a> that seven out of 2,500 investigated phones had similar spyware installed on them, and that those phones belonged to a &#8220;cross section of society&#8221; &#8212; not just billionaires and politicians. Indeed, it&#8217;s never a bad idea to install a spyware scanner, no matter who you are. </p><h2>I&#8217;m still not convinced. Who cares about phishing anymore? It&#8217;s 2025. </h2><p>When I read cybersecurity news these days, there&#8217;s less coverage of phishing than there was ten years ago. Many people think phishing is a solved problem: in 2022, Gmail started <a href="https://blog.google/products/gmail/gmail-security-authentication-spam-protection/">requiring</a> domain authentication for bulk email senders; subsequently, they saw a 75% drop in unauthenticated emails. (Microsoft adopted a similar authentication requirement at the same time, and saw a similar drop.) Indeed, according to the FBI Internet Crime Report, phishing dipped slightly in 2022, likely as a result of these bulk email sender authentication measures:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zFO4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zFO4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png 424w, https://substackcdn.com/image/fetch/$s_!zFO4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png 848w, https://substackcdn.com/image/fetch/$s_!zFO4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png 1272w, https://substackcdn.com/image/fetch/$s_!zFO4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zFO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png" width="1071" height="658" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b018a017-be1c-445f-a110-00c92c0fa013_1071x658.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:658,&quot;width&quot;:1071,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94558,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zFO4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png 424w, https://substackcdn.com/image/fetch/$s_!zFO4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png 848w, https://substackcdn.com/image/fetch/$s_!zFO4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png 1272w, https://substackcdn.com/image/fetch/$s_!zFO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb018a017-be1c-445f-a110-00c92c0fa013_1071x658.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: 2023 FBI Internet Crime <a href="https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf">Report</a></figcaption></figure></div><p>But if you look at the above graph, you probably notice that phishing is still &#8212; even in 2023 &#8212; five times more common than the next most common internet crime. Hackers can still get people to click links. (In fact, SPF and DKIM are actually kind of easy to get around.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>) There are always going to be vulnerable users. </p><p>Furthermore, no phishing filter is perfect, because hackers are always innovating and coming up with new tricks for getting email users to click links. As recently as 2022, Gmail&#8217;s seemingly impervious phishing filter was found to miss 626 phishing emails per 100,000:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ctrY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ctrY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png 424w, https://substackcdn.com/image/fetch/$s_!ctrY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png 848w, https://substackcdn.com/image/fetch/$s_!ctrY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png 1272w, https://substackcdn.com/image/fetch/$s_!ctrY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ctrY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png" width="625" height="382" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:382,&quot;width&quot;:625,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:40552,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ctrY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png 424w, https://substackcdn.com/image/fetch/$s_!ctrY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png 848w, https://substackcdn.com/image/fetch/$s_!ctrY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png 1272w, https://substackcdn.com/image/fetch/$s_!ctrY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc201737f-00c1-4134-b7fd-2ba4ca67f989_625x382.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: 2022 Check Point <a href="https://www.avanan.com/hubfs/2022-Defender-Report/WP_Avanan_Keeping_Your_Emails_Secure_Who_Does_It_Best.pdf">Report</a> on Microsoft Defender</figcaption></figure></div><p>Sure, 626 is a small number, but as we've seen today, it only takes one phishing email for a catastrophe to happen. So stay vigilant! (And install Too Phishy.)</p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Just look at the lookalike attack email example from <a href="https://gimletmedia.com/shows/reply-all/rnhoww">Reply All</a>, when one of the employees of Gimlet Media tricks the CEO into clicking a phishing email by sending him an email from replyall@gi<strong>rn</strong>letmedia.com (because the &#8220;r&#8221; and &#8220;n&#8221; in &#8220;gi<strong>rn</strong>elt&#8221; look like an &#8220;m&#8221; in email provider font).</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Why don't more people apply to speak at conferences?]]></title><description><![CDATA[Doubling your user base overnight is possible &#8212; if you speak at conferences.]]></description><link>https://www.lydiaoncybersecurity.com/p/why-dont-more-people-apply-to-speak</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/why-dont-more-people-apply-to-speak</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Thu, 14 Nov 2024 14:32:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BenM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Doubling your user base overnight is possible &#8212; if you speak at conferences.</p><p>I&#8217;d long had my Too Phishy app in the Google Workspace Store, languishing at around 300 users. This August, I gave my first ever conference <a href="https://www.youtube.com/watch?v=BZFy1Jx7sAk&amp;list=PLxeenGqMmmw_CXKRZxA8RmcsFZcmWsf_E&amp;index=5">talk</a> at the Carolina Codes Conference. The next day, Too Phishy had 200 new users, and I met ten IT practitioners who agreed to let me interview them for product research. 66% user growth in one day? And exponential growth in the number of customer interviews I&#8217;d been able to secure??&nbsp;</p><p>I felt like I&#8217;d hit a gold mine.&nbsp;</p><p>So why aren&#8217;t more developers applying to speak at conferences?</p><p>My guess: They don&#8217;t know how. So I want to demystify the process and help more people get accepted to conferences.</p><h1>Why Diversity in Tech Conferences Matters</h1><p>This blog post is for my own benefit. I want to see spicier content at tech conferences. More hot takes. More outside perspectives. More &#8211; gasp, since DEI initiatives have been in freefall on my Linkedin feed recently (to say nothing of the past week) &#8211; diversity.</p><p>Tech conferences are still full of white men giving repetitive talks. I&#8217;ve been to 14 meetups that featured a guy who made a subway app using public transit APIs. As someone who&#8217;s built my fair share of unoriginal apps, I&#8217;m not one to judge, but I do notice that the apps getting presented at tech conferences become a LOT more interesting when the speakers come from more diverse backgrounds.</p><p>In short, I want more people to apply to conferences.</p><h1>The Problem: People Are Too Intimidated to Apply</h1><p>Applying to speak at conferences is intimidating. The term used to describe the conference application itself &#8211; a conference &#8220;paper&#8221; &#8211; is inherently intimidating, reminiscent of the academic-style papers from college that required careful citations and an appendix the length of one&#8217;s arm.&nbsp;</p><p>The surprising truth is that applying to conferences is far easier than most things you have to do in your regular job, and far easier than any of the papers you had to write in college&#8230;</p><h1>Step-by-Step Guide to Getting Accepted to Conferences</h1><h2>Write a 250-Word Conference Proposal</h2><p>You only need to write 250 words to submit a &#8220;conference paper.&#8221; In fact, most tech conference applications have a 250-word limit so you couldn&#8217;t write more even if you wanted to. Here&#8217;s an example of <a href="https://bsidesnova2024.sessionize.com/session/709527">a paper</a> I recently submitted to a couple of conferences; as you can see, it&#8217;s nothing crazy.&nbsp;</p><p>And, in the spirit of transparency, that 250-word &#8220;paper&#8221; was written by ChatGPT.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BenM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BenM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png 424w, https://substackcdn.com/image/fetch/$s_!BenM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png 848w, https://substackcdn.com/image/fetch/$s_!BenM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png 1272w, https://substackcdn.com/image/fetch/$s_!BenM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BenM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png" width="817" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:817,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142154,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BenM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png 424w, https://substackcdn.com/image/fetch/$s_!BenM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png 848w, https://substackcdn.com/image/fetch/$s_!BenM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png 1272w, https://substackcdn.com/image/fetch/$s_!BenM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb676bc1a-75ad-4e63-9a38-0eb211774050_817x832.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The first time I asked ChatGPT to write a conference paper for me: the beginning of a beautiful partnership.</figcaption></figure></div><p>And if you&#8217;re wondering whether you need to train ChatGPT on examples of real conference papers, it&#8217;s not necessary to do so: conferences repurpose the accepted conference papers as the talk descriptions on conference schedules (which are publicly available on the web), so OpenAI has already scraped them all for you.</p><h2>Include Links to Past Speaking Experience</h2><p>My acceptance rate to conferences dramatically increased once I included links to past speaking experience, something I did upon the advice of my friend <a href="https://akirabrand.substack.com/">Akira</a>, a conference veteran who told me, &#8220;Conference committees like to see videos of past speaking just to make sure you can speak in public and won&#8217;t get stage fright.&#8221;&nbsp;</p><p>Taking their advice, I added more links to my application, even though none of this speaking experience was &#8220;technical.&#8221; Specifically, I&#8217;d <a href="https://www.youtube.com/watch?v=CeFP3Gm7aGc&amp;list=PL4RCxklHWZ9ubJ-RLYZ5GFnu23ccml_Cq&amp;index=3">spoken</a> at a large tech conference about building a Green Team at MongoDB in 2021. I&#8217;d also given a <a href="https://www.hopkins.edu/news-detail?pk=1149201">short talk</a> to students at my former high school about learning to code in my mid-twenties. Yes, this talk was literally targeted at 15-year-olds, and I included it anyway. (And it seems to have helped my acceptance rate a lot, but we&#8217;ll get to that later.)</p><h2>Use the STAR Framework in Your Session Outline&nbsp;</h2><p>Secondly, on the suggestion of my friend <a href="https://www.joshuakgoldberg.com/">Josh</a>, I wrote a supplemental description for my talk using the STAR (situation, task, action, and results) framework.&nbsp;</p><p>Josh&#8217;s exact words when I first sent him my initial GPT-written conference paper draft were &#8220;This was clearly written by AI.&#8221; Hah! He was right.&nbsp;</p><p>Heeding Josh&#8217;s advice, I begrudgingly rewrote the talk description myself (yes, without the use of generative AI) using STAR. You can see the new version <a href="https://gist.github.com/lydiastepanek/c1d7729fa63e69ed2c54f2f39cdb7bb3">here</a>. I liked this new version a lot better, but it felt weird to reference myself so much (I used the word &#8220;I&#8221; eight times) in the talk description. Most conference papers use the term &#8220;we&#8221; instead of &#8220;I&#8221;, because the speaker usually works for an actual company (whereas at the time of writing these proposals, I was a solopreneur).</p><p>Faced with a time crunch, I eventually decided to stick with my GPT-written conference paper. Most conference paper application portals have an &#8220;optional&#8221; section, so I wrote &#8220;Here is my talk outline:&#8221; and pasted the STAR description. Again, not perfect, but it worked in a pinch.</p><h2>Prepare for Rejection, but Keep Applying</h2><p>Here&#8217;s the truth. Carolina Codes Conference was the first conference to accept me after nine months of applying to conferences. Prior to this summer, I&#8217;d gotten at least 75 conference talk rejections.&nbsp;</p><p>Persistence pays off. Keep tweaking things and keep applying.</p><h1>The Two Key Changes That Led to My Acceptance</h1><p>When I finally started getting accepted to conferences, I reached out to my marketing mentor, <a href="https://www.youtube.com/channel/UCpuorOa1icrmvwSRB9TN_gQ">Omari</a> &#8211; &#8220;You know that app I built last December, Too Phishy? Well, I applied to a bunch of conferences earlier this year, and now all of a sudden, it&#8217;s getting accepted!&#8221;</p><p>&#8220;Well,&#8221; Omari asked, &#8220;What changed?&#8221;</p><p>Funnily enough, it was only the two simple changes above &#8211; adding links to past speaking experience and adding the STAR framework description in the optional section &#8211; that brought my acceptance rate from 0% to 30%. Since then, I&#8217;ve spoken at four conferences &#8211; Carolina Codes Conference (300+ attendees), BSides Nova (700+ attendees), BSides NYC (1,000+ attendees), and Triangle InfoSeCon (1,650+ attendees), and had a heck of a time doing it. I&#8217;ve met 100+ IT practitioners and learned more from them in-person than I ever could from online sources. That&#8217;s what made me want to write this blog post.</p><h1>Start Applying Today</h1><p>Don't let rejection stop you. The hardest part of applying to conferences is finding conferences. Here's the conference application site I use: <a href="https://sessionize.com/app/speaker/discover">https://sessionize.com/app/speaker/discover</a>. Once you're logged in, it&#8217;s surprisingly useful, because it sorts conferences by their application deadline and/or conference date.&nbsp;</p><p>Good luck!</p>]]></content:encoded></item><item><title><![CDATA[Starting Over]]></title><description><![CDATA[This post was originally published on February 2, 2024.]]></description><link>https://www.lydiaoncybersecurity.com/p/starting-over</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/starting-over</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:55:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9aGz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This post was originally published on February 2, 2024.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9aGz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9aGz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9aGz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9aGz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9aGz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9aGz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg" width="1456" height="1124" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1124,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:807220,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9aGz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9aGz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9aGz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9aGz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cfeb46-946e-4126-beac-ac8f54aaf148_2931x2262.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br>I&#8217;ve said it once and I&#8217;ll say it again: I&#8217;m really proud of my most recent app, <a href="https://workspace.google.com/marketplace/app/too_phishy/802749066565">Too Phishy</a>. It&#8217;s by far the best anti-phishing add-on I&#8217;ve seen in the Google Workspace store. That being said, it hasn&#8217;t caught on as much as I would have hoped or as fast as I would have hoped.&nbsp;</p><p>In an effort to build one app per month, I have to be more ruthless than other app builders in terms of timing. Things have to take off fast, or it&#8217;s time to pivot. So I&#8217;ve decided to pivot into new ventures. Here&#8217;s my blog post explaining why.</p><h2>Too Phishy&#8217;s launch</h2><p>A few weeks ago, Too Phishy <a href="https://www.producthunt.com/products/too-phishy-for-gmail#too-phishy-for-gmail">launched</a> on Product Hunt. In its first few days, it got no page clicks. No subscribers. No comments. No reviews on Product Hunt (except, as usual, from my dad). And no downloads in Google Workspace. Admittedly, with my marketing budget of $0, I had told no one about this app, and Product Hunt doesn&#8217;t market your apps for you. But it was disheartening nonetheless.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ixXq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ixXq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png 424w, https://substackcdn.com/image/fetch/$s_!ixXq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png 848w, https://substackcdn.com/image/fetch/$s_!ixXq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png 1272w, https://substackcdn.com/image/fetch/$s_!ixXq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ixXq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png" width="844" height="610" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:610,&quot;width&quot;:844,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!ixXq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png 424w, https://substackcdn.com/image/fetch/$s_!ixXq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png 848w, https://substackcdn.com/image/fetch/$s_!ixXq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png 1272w, https://substackcdn.com/image/fetch/$s_!ixXq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f520a15-e289-441f-a8a0-de564a7018bc_844x610.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">From dad.</figcaption></figure></div><p>I spent the next three weeks reaching out to bloggers, and trying to get signups. I even posted to 19 reddit communities, earning me more than a thousand website visits to toophishy.com. Along the way, I managed to get <strong>12 free trial users</strong>, who would become paid users once the two week free trial period ended. Woohoo!&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!15Xu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!15Xu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png 424w, https://substackcdn.com/image/fetch/$s_!15Xu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png 848w, https://substackcdn.com/image/fetch/$s_!15Xu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png 1272w, https://substackcdn.com/image/fetch/$s_!15Xu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!15Xu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png" width="641" height="417" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:417,&quot;width&quot;:641,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!15Xu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png 424w, https://substackcdn.com/image/fetch/$s_!15Xu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png 848w, https://substackcdn.com/image/fetch/$s_!15Xu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png 1272w, https://substackcdn.com/image/fetch/$s_!15Xu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F892a461b-4718-400d-b05e-b5d3ae10ade8_641x417.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I got 472 page views from <a href="https://www.reddit.com/r/webdev/comments/184da66/learned_to_code_8_years_ago_and_finally_launching/">this</a> reddit post alone.</figcaption></figure></div><p>But looking more critically, I had to wonder why my website had such a low ratio of website visits to app signups. My posts on reddit were getting real attention, but somehow my app did not address enough of a real problem to get people to sign up.</p><p>By the end of December, six of those trial users churned, and six became paid users. I had to accept two things: I had 50% turnover, and I gained one user for every three days of marketing. Ultimately, I wondered if the time investment per user acquisition was sustainable. It was time to take a pause and figure out what to do.&nbsp;</p><p>First, in an effort to remove the most obvious friction point of user acquisition &#8211; cost &#8211; <strong>I decided to make Too Phishy free. </strong>I sent the following email to my users:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rWpT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rWpT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png 424w, https://substackcdn.com/image/fetch/$s_!rWpT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png 848w, https://substackcdn.com/image/fetch/$s_!rWpT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png 1272w, https://substackcdn.com/image/fetch/$s_!rWpT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rWpT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png" width="1456" height="651" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:651,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!rWpT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png 424w, https://substackcdn.com/image/fetch/$s_!rWpT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png 848w, https://substackcdn.com/image/fetch/$s_!rWpT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png 1272w, https://substackcdn.com/image/fetch/$s_!rWpT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdafcfce8-7993-4ccd-80ee-7230d02fc320_1600x715.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This was one of the hardest emails I&#8217;ve ever written. Goodbye, subscription income. Hello, more work.</figcaption></figure></div><p>Making my app free got me another 24 users, bringing my user count to 30.</p><p>Next, I emailed 93 cybersecurity practitioners across the world, telling them about my five-star free anti-phishing app and asking if I could speak to them for advice. (I got six meetings out of this outreach, but most practitioners I spoke to already had an anti-phishing tool in place and preferred to spend their budget on post-breach response rather than pre-breach defense.)&nbsp;</p><p>As Yvon Chouinard, the founder of Patagonia, once <a href="https://www.cnbc.com/2016/12/23/founder-of-patagonia-fishes-half-the-year-tells-his-employees-to-surf.html">said</a>:</p><blockquote><p>If I get an idea, I immediately take a step forward and see how that feels. If it feels good, I take another. If it feels bad, I take a step back.</p></blockquote><p>At this point, I felt bad.&nbsp;</p><p>An object in motion stays in motion, which is to say, it&#8217;s sometimes easier to keep going than to stop.&nbsp;</p><p>So instead of diving into my next app right away, I&#8217;ve decided to take a pause, write this blog post about what I learned, and start over.</p><h2>The elephant in the room: the lack of publicly available phishing data</h2><p>I mentioned this in my launch <a href="https://lydiaoncybersecurity.substack.com/p/launching-too-phishy">post</a> for Too Phishy, but there is a dearth of example phishing emails in the public domain. This makes it really, really hard to come up with correct algorithms, and to identify &#8220;bad actors&#8221; in real time. Without the ability to see the millions of phishing emails making their way across the internet and into Gmail&#8217;s inboxes, it&#8217;s hard to immediately flag bad actors. So in the end, I wonder if my biggest issue was not having enough email data to work with. This is the biggest lesson I take away from this experience.</p><h2>Things I got right</h2><p>First, I&#8217;d like to reflect on what went well in the Too Phishy launch. I learned a ton.</p><p>Things I learned:</p><ul><li><p>Hey, I launched an app! That was exciting. And it got approved by the Google Workspace Review team (which took a month of back and forth).</p></li><li><p>I found a paying audience &#8211; 12 free trial users! That&#8217;s way better than zero free trial users.</p></li><li><p>And I found a non-paying audience - 30 users.</p></li></ul><p>Things I got wrong:</p><ul><li><p>I launched a relatively expensive ($6/month) subscription app on a platform (Product Hunt) that doesn&#8217;t specialize in paid apps.</p></li><li><p>Somehow I built an app that people wanted to learn about but didn&#8217;t want to install.</p></li><li><p>I didn&#8217;t research the customer for my product before building.</p></li><li><p>I built in a vacuum without talking to people along the way, compounding my above missteps.</p></li></ul><p>So what am I planning on doing going forward? Let&#8217;s dive into it.</p><h2>Know thy customer</h2><p>As someone who was very social in college, I joined my first software engineering job at the age of 25 and soon realized that my social skills learned in college did not translate to the startup world. I vividly remember my first day on the job, when all the male software engineers (and one product manager) walked by my desk on the way to lunch without acknowledging me. <em>I&#8217;ll show them</em>, I thought, <em>I&#8217;ll learn to code so well that they invite me to lunch</em>. Well, I did learn a lot of code, and eventually I got invited to lunch. But I turned down the invite. By then, I had fully transitioned into an introvert.</p><p>These days, I feel very comfortable around a compiler and a debugger, but I&#8217;m terrified to go to Meetup events. (If you&#8217;re wondering how I managed to spam 19 reddit communities as an &#8220;introvert,&#8221; I have the sweat stains to prove how difficult that was for me.) Hell, I&#8217;m scared to even send a single LinkedIn message.&nbsp;</p><p>So over the past few weeks, I&#8217;ve forced my rusty social skills into shape. I&#8217;ve gone to two (count &#8216;em) Meetups, and I&#8217;ve forced myself to talk about my product ideas to one new person at each event. And, as mentioned above, I&#8217;ve sent 93 Linkedin messages this month &#8211; mostly with my eyes closed, and hyperventilating while doing it. (Don&#8217;t block me, please.)</p><p>In an effort to be a woman of the people, and not just a cyborg working remotely in rural Brooklyn, I even went to Rockefeller Center and interviewed tourists on the sidewalk outside of an Equinox. &#8220;I&#8217;m starting a cybersecurity <a href="https://www.tiktok.com/@lydiaoncybersecurity">TikTok</a>,&#8221; I told them, &#8220;Would you mind if I asked you a few questions about cybersecurity?&#8221; (Most people took pity on me because I do not look like a TikToker and they probably knew I was desperate; over two hours, only two people said no.)</p><p>&#8220;Do you ever worry about your data on Tiktok being used?&#8221; I asked.&nbsp;</p><p>&#8220;No,&#8221; they said.</p><p>&#8220;Do you ever worry about being hacked?&#8221;&nbsp;</p><p>&#8220;Yes.&#8221;</p><p>&#8220;Do you use a password manager and/or VPN?&#8221;&nbsp;</p><p>&#8220;No,&#8221; they said. Some said that they had VPNs, not because of privacy concerns, but for watching Netflix abroad.</p><p>&#8220;Do you do anything to protect yourself from phishing emails?&#8221;&nbsp;</p><p>&#8220;Yes, but <strong>only for my work email</strong>.&#8221;</p><p>Hm. <em>Well that&#8217;s interesting</em>, I thought. <em>None of these people even uses a phishing app for their personal email. </em>(To you, this may seem very obvious; to me, it was genuinely a surprise. Again, I do not talk to people very often.)</p><p><em>Who is my customer?</em> I wondered.<em> And what do they want? </em>The truth was, I didn&#8217;t even know.&nbsp;</p><p>I had 30 customers, so <em>someone</em> clearly wanted my app. There are people who are scared of being hacked, but I didn&#8217;t know yet how to translate that into an app.</p><h2>Conduct market validation&nbsp;</h2><p>Not only had I been avoiding people for many years; I&#8217;d also been avoiding conducting market research. Most advice on the internet seems to be &#8220;build the app that ~you~ want!&#8221; Well, I&#8217;m a strange person. I&#8217;m not sure the world wants the apps that I want.&nbsp;</p><p>To figure out what the world wants, I realized I should probably do this thing called &#8220;market research.&#8221; So I signed in to Google Keyword Planner to see how often people search for terms relating to my app ideas.</p><p>My search revealed that only 50 people in the world search for the term "phishing gmail" every month. In comparison, 500 people search for &#8220;free parking app,&#8221; which explains why there are <a href="https://loving-newyork.com/best-parking-apps-nyc/">so</a> many successful parking apps.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R6gC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R6gC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png 424w, https://substackcdn.com/image/fetch/$s_!R6gC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png 848w, https://substackcdn.com/image/fetch/$s_!R6gC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png 1272w, https://substackcdn.com/image/fetch/$s_!R6gC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R6gC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png" width="620" height="287" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:287,&quot;width&quot;:620,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!R6gC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png 424w, https://substackcdn.com/image/fetch/$s_!R6gC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png 848w, https://substackcdn.com/image/fetch/$s_!R6gC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png 1272w, https://substackcdn.com/image/fetch/$s_!R6gC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85bae971-24bd-4ce1-a175-2fee5b785f29_620x287.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">An anti-phishing add-on for Gmail was <em>not</em> what the world was searching for.</figcaption></figure></div><p>Again, many people probably do want a phishing plugin, but it&#8217;s useful for me to quantify how many people want a phishing plugin versus a free parking app, so that I can spend my time most productively.</p><h2>Launch on paid platforms</h2><p>Right after my Product Hunt launch, I called up my friend Bosen, an indie game developer, and cried (metaphorically) about how few paid users I had. &#8220;Of course you&#8217;re not making any money,&#8221; he told me, &#8220;You launched on Product Hunt!&#8221; He pointed out that Product Hunt apps rarely charge money, whereas iPhone and Android apps can charge money and still go viral. The iPhone Store, the Google Play Store, and Steam platforms all market your apps for you by sending out marketing emails and making your app searchable. (They want their 30% cut after all.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-9gm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-9gm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png 424w, https://substackcdn.com/image/fetch/$s_!-9gm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png 848w, https://substackcdn.com/image/fetch/$s_!-9gm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png 1272w, https://substackcdn.com/image/fetch/$s_!-9gm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-9gm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png" width="1456" height="753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:753,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!-9gm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png 424w, https://substackcdn.com/image/fetch/$s_!-9gm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png 848w, https://substackcdn.com/image/fetch/$s_!-9gm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png 1272w, https://substackcdn.com/image/fetch/$s_!-9gm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a48539-2c03-42d8-97c6-b0364cdfd942_1600x828.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Steam even has a revenue calculator that helps you estimate how much a game makes. A simple game priced at $14.99 with 1,540 reviews can make $245k in one year. Product Hunt, tellingly, does not provide a revenue calculator tool, since most of the apps that it launches are free.</figcaption></figure></div><h2>Make a free tier if you want to go viral</h2><p>I charged $6/month for Too Phishy because I was following the <a href="https://www.lydiaoncybersecurity.com/p/starting-over/#:~:text=Andreessen">advice</a> of Marc Andreessen, who said that startup founders always charge too little for their products. (And, as mentioned above, you can make real money selling apps.) But free versions are what go viral.&nbsp;</p><p>Instagram and Calendly were free when they launched. Free versions are how you get free marketing. Because, shocker: a small team can&#8217;t afford a full time sales team, let alone <em>one</em> sales person, so Product Hunt and Twitter clicks are their only way to market an app.</p><h2>Then how will I make money?</h2><p>I&#8217;m not trying to be a billionaire here, but I need to pay rent. I&#8217;ve spent the past few months trying to figure out how I can survive as an indie app developer.</p><p>Eventually, I came to a fairly obvious conclusion. No, not getting a real job &#8211; life is too short for that &#8211; but becoming a freelance cybersecurity consultant and web developer.&nbsp;</p><p>Funny story: a week ago, I added &#8220;CEO&#8221; to my Linkedin title (mostly inspired by my <a href="https://www.linkedin.com/in/claire-stepanek/">sister</a>, an incredible startup founder). The second I did, I started getting tons of inbound messages from other executives on Linkedin. In fact, from that Linkedin interest, I set up a few calls, and I already have my first sales leads! So my plan is to spend 20 hours per week consulting, and the other 20 hours building products. Plus, this way, I&#8217;ll be able to find people with actual problems that I can build products for.</p><h2>Conclusion</h2><p>To sell my apps going forward, I&#8217;m going to have to talk to people a lot more (and having freelance clients should definitely help). I&#8217;m going to have to find customers <em>before</em> I build. And I&#8217;m going to need to ask other developers for ideas and feedback. With a new system in place &#8211; that is, focusing more heavily on early market research and customer feedback &#8211; I&#8217;m actually excited to start <s>building</s> researching my next product. First stop, Reddit.</p><h2>&#127775; Acknowledgements</h2><p>I&#8217;d like to give credit to Lior Neu-ner&#8217;s great <a href="https://liorn.substack.com/p/starting-over">blog post</a> that inspired me to write about starting over.</p>]]></content:encoded></item><item><title><![CDATA[The 37 most important events in American cybersecurity history]]></title><description><![CDATA[I've never been one for remembering important dates and names.]]></description><link>https://www.lydiaoncybersecurity.com/p/the-38-most-important-dates-in-cybersecurity</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/the-38-most-important-dates-in-cybersecurity</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:55:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MohW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I've never been one for remembering important dates and names. Many years ago, when the Edward Snowden leaks came out, I determined that someone was watching everything I did online, so I might as well know who they were and why they were doing it. Since then, I started writing down noteworthy events in the history of hacking, cybersecurity, and government oversight. This is not an exhaustive list of everyone and everything that has ever happened; this is a list by me, for me, to remember significant events.</p><h3>1920</h3><p>Herbert O. Yardley, the founder of the Black Chamber (a government agency that proceeds the NSA), <a href="https://www.nybooks.com/articles/2013/08/15/nsa-they-know-much-more-you-think/">convinces</a> Newcomb Carlton, the president of Western Union, to grant him access to all telegraphs going through Western Union. <em>The overreach of government oversight begins.</em></p><h3>1945</h3><p>The Soviet Union gifts <a href="https://en.wikipedia.org/wiki/The_Thing_(listening_device)">The Thing</a>, a secret electromagnetic listening device disguised within a commemorative plaque, to Averell Harriman, the U.S. Ambassador to the Soviet Union. British radio operators discover it in 1951. <em>This is the first electromechanical bug ever discovered.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-dMQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-dMQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-dMQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-dMQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-dMQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-dMQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg" width="220" height="257" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:257,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!-dMQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-dMQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-dMQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-dMQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40105d73-a0bd-479d-b9d6-23bb7cf975df_220x257.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Secret listening device? No way.</figcaption></figure></div><h3>1967</h3><p>The Supreme Court holds in <a href="https://en.wikipedia.org/wiki/Katz_v._United_States">Katz v. United States</a> that the monitoring and recording of private conversations within the United States constitutes a "search" for Fourth Amendment purposes, and therefore requires a warrant. (Prior to this, the 1928 ruling from <a href="https://en.wikipedia.org/wiki/Olmstead_v._United_States">Olmstead v. The United States</a> held that wiretapping a private phone conversation did not violate the Fourth Amendment.) <em>This is the beginning of courts requiring police to obtain search warrants for telecommunications data.</em></p><h3>1978</h3><p>The NSA's eavesdropping on Vietnam War protesters and civil rights activists motivates Congress to pass the <a href="https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act">Foreign Intelligence Surveillance Act</a>. This act requires the NSA to have search warrants approved by a secret F.I.S.A. court in order to spy on Americans. <em>Domestic spying ends for a brief moment.</em></p><h3>1979</h3><p>The Supreme Court holds in <a href="https://en.wikipedia.org/wiki/Smith_v._Maryland">Smith v. Maryland</a> that a warrant is required for the government to acquire the content of electronic communications. However, only subpoenas are required for the business records (metadata) of these communications. "Metadata" includes the phone numbers that an individual has dialed, and the location of phone communications.</p><h3>1985</h3><p>During <a href="https://media.defense.gov/2021/Jul/13/2002761779/-1/-1/0/LEARNINGFROMTHEENEMYGUNMAN.PDF">Project GUNMAN</a>, the NSA finds a Soviet bug attached to a typewriter inside the U.S. embassy in Russia, capturing every keystroke. <em>This is the second electromechanical bug ever discovered.</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YmY2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YmY2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png 424w, https://substackcdn.com/image/fetch/$s_!YmY2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png 848w, https://substackcdn.com/image/fetch/$s_!YmY2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png 1272w, https://substackcdn.com/image/fetch/$s_!YmY2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YmY2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png" width="398" height="214" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:214,&quot;width&quot;:398,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!YmY2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png 424w, https://substackcdn.com/image/fetch/$s_!YmY2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png 848w, https://substackcdn.com/image/fetch/$s_!YmY2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png 1272w, https://substackcdn.com/image/fetch/$s_!YmY2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148b25bc-6b26-41d2-8974-127da95d29eb_398x214.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">The U.S. embassy in Moscow <a href="https://media.defense.gov/2021/Jul/13/2002761779/-1/-1/0/LEARNINGFROMTHEENEMYGUNMAN.PDF">at the time</a> of Project GUNMAN. I would not have minded being a U.S. ambassador here, even if all my correspondence was being secretly watched.</figcaption></figure></div><h3>1986&nbsp;</h3><ul><li><p>Karl Koch, A German hacker, is <a href="https://en.wikipedia.org/wiki/Karl_Koch_(hacker)">caught</a> selling hacked information from United States military computers to the KGB.&nbsp;<em>This is the first known cyberattack by Russia on American soil.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZO1l!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZO1l!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZO1l!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZO1l!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZO1l!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZO1l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg" width="287" height="445" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:445,&quot;width&quot;:287,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!ZO1l!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZO1l!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZO1l!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZO1l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59421ea0-415a-4036-a34a-d992ef44a7b6_287x445.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>The Cuckoo's Eg</em>g, probably the best hacking book ever written, details the hunt for Karl Koch.</figcaption></figure></div></li><li><p>The <a href="https://en.wikipedia.org/wiki/Electronic_Communications_Privacy_Act">Electronic Communications Privacy Act of 1986</a> is enacted by Congress to extend restrictions on government wiretaps to include the transmission of electronic data.</p></li></ul><h3>1988</h3><p>The <a href="https://en.wikipedia.org/wiki/Morris_worm">Morris Worm</a> takes down 60,000 computers. <em>This is the first worm to take down more than 10% of the internet. </em>Robert Morris Jr., the creator of the worm, is a fascinating individual: the son of NSA chief scientist Robert Morris Sr., he co-founds Y Combinator in 2005.</p><h3>1996</h3><p>The CIA&#8217;s CITO unit, the predecessor to the CIA's Information Operations Center, starts training spies to put NSA hardware &#8211; like spyware spiked microchips &#8211; in corporate supply chains. </p><h3>1998</h3><p>The CIH virus infects sixty million computers internationally, especially impacting countries that don't have widespread antivirus software. <em>This virus hugely accelerates the awareness of the need for antivirus software.</em></p><h3>2001</h3><ul><li><p>Congress passes the <a href="https://en.wikipedia.org/wiki/Patriot_Act">Patriot Act</a>, allowing the U.S. government to store phone records, including call logs (but <strong>not</strong> recordings), along with internet activity and text messages, for purposes of antiterrorism.</p></li><li><p>The <a href="https://en.wikipedia.org/wiki/ILOVEYOU">ILoveYou</a> worm spreads globally. <em>This is the first email worm to combine social engineering </em>(who doesn't want to open an email that says "I love you"?)<em> and a Windows vulnerability in order to spread quickly.</em></p></li></ul><h3>2002&nbsp;</h3><ul><li><p>Symantic buys Bugtraq, a public bug tracker, and makes it private. <em>This is the beginning of private companies and governments paying hackers for exploits instead of publicizing known vulnerabilities. </em>In 2007, Charles Miller, a security researcher, publishes <a href="https://www.ise.io/wp-content/uploads/2018/04/0daymarket.pdf">a paper</a> that reveals that government agencies like the NSA will pay hackers very high prices (usually $5,000 to $250,000) for discovering security vulnerabilities.</p></li><li><p>The Pentagon announces the <a href="https://en.wikipedia.org/wiki/Total_Information_Awareness">Total Information Awareness</a> project. Funding is cut off one year later,&nbsp; but the NSA continues to use its software to mine telephone conversations and web searches as part of <a href="https://en.wikipedia.org/wiki/Stellar_Wind">Stellar Wind</a>. <em>This enables the NSA &#8211; with George W. Bush&#8217;s knowledge and consent &#8211; total, unsupervised <a href="https://en.wikipedia.org/wiki/NSA_warrantless_surveillance_(2001%E2%80%932007)">access</a> to all fiber-optic communications in the U.S. until 2004, when domestic communication data collection is deauthorized.</em></p></li><li><p>The NSA <a href="https://www.sj-r.com/story/news/2008/02/16/holmes-secrets-room-641a/48130015007/&nbsp;">installs</a> a listener in Room 641A of the San Francisco AT&amp;T building &#8211; <a href="https://www.nybooks.com/articles/2013/08/15/nsa-they-know-much-more-you-think/">along with</a> more than ten other telecom buildings across the country &#8211; to collect all metadata relating to NSA-provided search terms. <em>This later becomes public knowledge in 2013 when Snowden reveals the existence of Project UPSTREAM.</em></p></li></ul><h3>2005</h3><p>China begins its Titan Rain espionage attacks on the networks of NASA and Lockheed Martin. <em>This is the beginning of Chinese hacking on American soil.</em></p><h3>2007</h3><p>Russia conducts DDOS cyberattacks on Estonia, marking the beginning of what cybersecurity researchers often refer to as Web War 1.</p><h3>2008</h3><ul><li><p>The NSA deploys the Stuxnet worm to infiltrate an Iranian nuclear plant. <em>This is the first cyberattack to use multiple zero days.</em> (It uses four.)</p></li><li><p>The <a href="https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act_of_1978_Amendments_Act_of_2008">Foreign Intelligence Surveillance Act of 1978 Amendments Act of 2008</a> expands the government&#8217;s ability to conduct electronic surveillance domestically without court orders, basically codifying what the NSA has been doing illegally. Congress grants telecom officials immunity not only from prosecution but also from civil suits.</p></li></ul><h3>2009&nbsp;</h3><p>Charlie Miller <a href="https://www.intego.com/mac-security-blog/hacker-contest-mac-hacked-in-10-seconds/">jailbreaks</a> an iPhone, MacBook Air, and Android by directing users to a malicious website that allows him to see every keystroke. Google ignores his bug report so he <a href="https://www.intego.com/mac-security-blog/interview-with-mac-hacker-charlie-miller/">starts</a> a &#8220;no more free bugs&#8221; campaign. (In 2014, Google reverses its decision by starting <a href="https://en.wikipedia.org/wiki/Project_Zero">Project Zero</a>, an internal team that publicizes all bugs that Google knows about, and encourages other tech companies to do the same.)</p><h3>2010</h3><p>NSO, an Israeli cybersecurity firm that sells spyware &#8211; built using vulnerabilities found in popular mobile phone technologies like iPhone and Android &#8211; is founded. <em>This is the beginning of the commercialization of the zero day industry.</em></p><h3>2012&nbsp;</h3><p>Iran deploys the Shamoon cyberattack on Saudi Aramco to retaliate for Stuxnet.</p><h3>2013</h3><ul><li><p>Edward Snowden reveals that the NSA is storing U.S. citizens' phone records. His revelations unearth NSA programs like PRISM and <a href="https://en.wikipedia.org/wiki/MUSCULAR">MUSCULAR</a> (which proved the NSA had hacked into Google without even Google knowing). <em>A Pew report soon after the scandal shows that 46% of Americans are still not concerned about American surveillance.</em></p></li><li><p>Der Spiegel <a href="https://venturebeat.com/security/the-iphone-has-reportedly-been-fully-hacked-by-the-nsa-since-2008/">releases</a> a report that NSA TAO unit hackers have developed a program called DROPOUTJEEP that allows the NSA to track every keystroke on an iPhone. Next, Der Spoegel publishes a 50 page list of NSA exploits that journalists call "way more revealing" than the Snowden leaks.&nbsp;</p></li><li><p>Under pressure after Snowden, the Foreign Intelligence Surveillance Court <a href="https://www.theguardian.com/commentisfree/2013/may/03/fisa-court-rubber-stamp-drones">reveals</a> that, in 2012 alone, it approved 1,748 of the 1,789 applications it received to survey Americans.</p></li></ul><h3>2014&nbsp;</h3><ul><li><p>Google finds a bug in SSL called Heartbleed that allows 17% of the internet&#8217;s web server&#8217;s private keys to be stolen. <em>This is the first vulnerability to affect as much as 17% of the internet.</em></p></li></ul><h3>2016&nbsp;</h3><ul><li><p>A group of hackers calling themselves the &#8220;Shadow Brokers&#8221; leak several NSA zero days, <a href="https://www.politico.com/story/2018/12/31/nsa-hacking-case-twitter-1077013">thought</a> to be stolen from the home of an NSA employee. <em>This is the first time the NSA is publicly hacked.</em> The next year, the Shadow Brokers <a href="https://arstechnica.com/information-technology/2017/04/nsa-leaking-shadow-brokers-just-dumped-its-most-damaging-release-yet/">leak</a> one of the most virulent of these vulnerabilities, nicknamed Eternal Blue, which is then used in two subsequent worldwide cyberattacks: WannaCry (see below) and NotPetya (also below).</p></li><li><p>Russia hacks the Democratic National Committee through the famous John Podesta <a href="https://en.wikipedia.org/wiki/Podesta_emails">phishing</a> email.</p></li><li><p>The F.B.I. buys a zero day to <a href="https://www.washingtonpost.com/technology/2021/04/14/azimuth-san-bernardino-apple-iphone-fbi/">jailbreak</a> the phone of the San Bernadino shooting suspects. <em>This is the first time the F.B.I. publicly acknowledges paying for a zero day.</em></p></li><li><p>A North Korean hacking group <a href="https://www.wsj.com/articles/u-s-preparing-cases-linking-north-korea-to-theft-at-n-y-fed-1490215094">steals</a> $81 million from Bangladesh&#8217;s central bank. <em>This increases public awareness of North Korea's hacking expertise; many say that North Korea trails only the U.S., Russia, and China in hacking capabilities.</em></p></li></ul><h3>2017&nbsp;</h3><ul><li><p>Chinese hackers commit the Equifax <a href="https://www.fbi.gov/news/stories/chinese-hackers-charged-in-equifax-breach-021020">data breach</a>.</p></li><li><p><a href="https://en.wikipedia.org/wiki/WannaCry_ransomware_attack">Wannacry</a>, built using Eternal Blue, shuts down the U.K. hospital system.</p></li><li><p>Russia conducts the NotPetya cyberattack on Ukraine (&#8220;Web War 2&#8221;) that cuts power across Ukraine in 5 hours. One year later, the U.S. Treasury announces sanctions against nineteen Russians organizations thought to be involved.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MohW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MohW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MohW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MohW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MohW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MohW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg" width="1280" height="1242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1242,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!MohW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MohW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MohW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MohW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79707e37-9b67-4124-93a2-edea59882100_1280x1242.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The J.P. Morgan hack was <a href="https://www.wsj.com/articles/data-breaches-that-upended-the-c-suite-a-history-1506450045">nowhere</a> near the largest hack at that time.</figcaption></figure></div><h3>2018</h3><p>NSO spyware called Pegasus is used to hack the phone of Jeff Bezos. His personal photos end up in the hands of the National Enquirer, which then threatens to blackmail him. In response, he releases the photos himself. <em>This is the first scandal that puts NSO's phone hacking capabilities on the front page of the news.</em></p><h3>2020</h3><p>The SolarWinds cyberattack &#8211; likely the work of Russia's FSB security service &#8211; penetrates thousands of organizations globally, including multiple parts of the United States federal government. It spreads through these organizations via the Orion network management software, a product of SolarWinds. SolarWinds' development server's password was "solarwinds123," which allowed the hackers to get into the server and place malicious code in Orion's software toolchain. Brad Smith, President of Microsoft, <a href="https://www.cbsnews.com/news/solarwinds-hack-russia-cyberattack-60-minutes-2021-02-14/">calls</a> it the "most sophisticated attack the world has ever seen.&#8221; He estimates that the attack required thousands of engineers to build and deploy.</p><h3>2021</h3><p>Russian hackers use an employee's leaked password to hack into Colonial Pipeline's servers, shutting down their servers until a ransom was paid. Since Colonial Pipeline supplies nearly half of the East Coast's liquid fuels, this becomes one of the most famous ransomware attacks on the United States. Luckily, Colonial Pipeline restores service within a day.</p><h2>Sources</h2><p><em><a href="https://www.goodreads.com/book/show/18154.The_Cuckoo_s_Egg">The Cuckoo's Egg</a></em> (Clifford Stoll)</p><p><em><a href="https://www.goodreads.com/en/book/show/41436213">Sandworm</a></em> (Andy Greenberg)</p><p><a href="https://www.nybooks.com/articles/2013/08/15/nsa-they-know-much-more-you-think/">They Know Much More Than You Think</a>, <em>The New York Review</em> (James Bamford)</p><p><em><a href="https://www.goodreads.com/en/book/show/49247043">This Is How They Tell Me the World Ends</a></em> (Nicole Perlroth)</p><p><em><a href="https://www.goodreads.com/book/show/31216093-unwarranted">Unwarranted: Policing Without Permission</a></em> (Barry Friedman)</p>]]></content:encoded></item><item><title><![CDATA[Launching Too Phishy]]></title><description><![CDATA[This post was originally published on November 11, 2023.]]></description><link>https://www.lydiaoncybersecurity.com/p/launching-too-phishy</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/launching-too-phishy</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:54:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!f-2J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This post was originally published on November 11, 2023. </em></p><p>To reduce procrastination and become faster at launching my projects, I&#8217;ve set the <a href="https://lydiaoncybersecurity.substack.com/p/im-building-12-cybersecurity-startups">goal</a> to launch 12 cybersecurity startups in 12 months. A few weeks after every launch, I do a debriefing on what I learned. Yesterday, I launched my third project, <a href="https://workspace.google.com/marketplace/app/too_phishy/802749066565">Too Phishy</a>, an anti-phishing Gmail add-on. <br><br>I created Too Phishy to improve my ability to detect cleverly made phishing scams. I needed a tool &#8212; one that was easy and intuitive &#8212; to help when my better judgement wasn't enough.</p><p>I expected to build this project in two months. In the end, it took four months. Here&#8217;s what happened.</p><h3>&#127786;&#65039; Wait, didn&#8217;t I already launch a product called Is This Phishy? What happened to that?</h3><p>Despite boasting 400 monthly active users in its first two months, my first project, <a href="https://www.producthunt.com/products/is-this-phishy">Is This Phishy</a>, saw its active user base drop down to one by its third month. (Hi dad!)&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f-2J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f-2J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg 424w, https://substackcdn.com/image/fetch/$s_!f-2J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg 848w, https://substackcdn.com/image/fetch/$s_!f-2J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!f-2J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f-2J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg" width="1456" height="716" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:716,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!f-2J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg 424w, https://substackcdn.com/image/fetch/$s_!f-2J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg 848w, https://substackcdn.com/image/fetch/$s_!f-2J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!f-2J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d5fdf28-618a-4cb5-b416-a84d7903aaeb_2000x983.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Please bow your heads for a moment of silence.</figcaption></figure></div><p>It turns out that recognizing phishing emails is really hard.&nbsp;</p><p>Too Phishy endeavors to be an improvement on Is This Phishy, using the lessons learned from Is This Phishy to provide better email analysis.</p><p>For example, Is This Phishy told you that an attachment might be suspicious, but it didn&#8217;t show you that someone <a href="https://toophishy.com/how-it-works#:~:text=Delacroix">named</a> John Delacroix last edited the attachment. Similarly, Is This Phishy told you that an email contained a rarely seen link, but it didn&#8217;t show you that the link was <a href="https://toophishy.com/how-it-works#:~:text=Korea">hosted in Korea</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bS-j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bS-j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png 424w, https://substackcdn.com/image/fetch/$s_!bS-j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png 848w, https://substackcdn.com/image/fetch/$s_!bS-j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png 1272w, https://substackcdn.com/image/fetch/$s_!bS-j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bS-j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png" width="1238" height="608" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:608,&quot;width&quot;:1238,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!bS-j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png 424w, https://substackcdn.com/image/fetch/$s_!bS-j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png 848w, https://substackcdn.com/image/fetch/$s_!bS-j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png 1272w, https://substackcdn.com/image/fetch/$s_!bS-j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32aa837-2798-4c34-9510-8f882fc6b111_1238x608.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Check out my terrible attempts at writing funny marketing copy at <a href="https://toophishy.com/how-it-works">toophishy.com/how-it-works</a>.</figcaption></figure></div><p>In short: Is This Phishy showed you beige flags; Too Phishy shows you red flags.<br><br>Also, I want to be funny with Too Phishy. Humor is a big part of my life and Is This Phishy was a little boring. Who says we can&#8217;t have a little fun while making sure someone hasn't stolen those 9 golden SSN digits?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bowb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bowb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png 424w, https://substackcdn.com/image/fetch/$s_!bowb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png 848w, https://substackcdn.com/image/fetch/$s_!bowb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png 1272w, https://substackcdn.com/image/fetch/$s_!bowb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bowb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png" width="629" height="629" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:629,&quot;width&quot;:629,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!bowb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png 424w, https://substackcdn.com/image/fetch/$s_!bowb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png 848w, https://substackcdn.com/image/fetch/$s_!bowb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png 1272w, https://substackcdn.com/image/fetch/$s_!bowb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1595acb-c297-4b3e-935c-7ef1ee7a9335_629x629.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This meme taught me what a beige flag was, so now I&#8217;m using the term in an effort to sound cool.&nbsp;</figcaption></figure></div><h3>&#128302; So if Too Phishy is super fast, and super awesome, it must use AI, right?</h3><p>Well, no. Too Phishy uses human-defined rules (defined by me) to analyze the two vectors of attack contained in an email: links and attachments. Building an AI &#8212; specifically an LLM model like OpenAI &#8212; requires millions (or billions) of data points from which a machine can learn, so building an AI model for recognizing phishing would take millions of phishing emails. Currently, there isn&#8217;t a big enough corpus of example phishing emails in the public domain to build such a model.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>&nbsp;</p><p>I'm planning to build a corpus of phishing emails with the aim of developing my own LLM. Right now I'm brainstorming the best way to achieve this &#8212; potentially incorporating this into the rollout and growth of Too Phishy itself. (Maybe I should offer a free month of Too Phishy for every phishing example sent to support@toophishy.com? Ideas are welcome.)&nbsp;</p><p>Either way, I&#8217;m really proud of the human-defined model I created for Two Phishy: it is the only email plugin I&#8217;ve seen that shows you so much information in so little time, and lets YOU see all the hidden metadata in your emails that email providers hide from you.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jIMU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jIMU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jIMU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jIMU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jIMU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jIMU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!jIMU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jIMU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jIMU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jIMU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169c510d-5bbc-4069-9898-8625510d5857_1024x683.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Imagine a world in which phishing corpuses could be created, updated, and researched online for free. It would probably look like this.</figcaption></figure></div><h3>I&#8217;d like to thank the Academy and ChatGPT for not helping.</h3><p>ChatGPT is really useful, it turns out (who knew??)&#8230;for really specific coding questions. Like: <em>How do i run the "node-exiftool" library on a Gmail email attachment in NodeJS?</em> Or, <em>What are the allowable values for memory in an ECS task definition?</em> Those questions yielded me perfect cut-and-paste answers.</p><p>But if you need help with high level questions like which technology to use for a given problem, look elsewhere.&nbsp;</p><p>I asked ChatGPT, <em>How do I get my Stripe app to use HTTPS?</em> It told me to sign up for Stripe Enterprise and use their partner solutions team (a.k.a. paid consultants). I&#8217;m an indiepreneur eating reheated quinoa for the fourth day in a row &#8211; I don&#8217;t have that kind of money.</p><p>Next: <em>Is there an easy way to set up a Stripe payments site?</em> Answer: &#8220;Why yes! Use Wix or WooCommerce for WordPress!&#8221; Again, I&#8217;m flying economy here, why does ChatGPT keep asking me if I want more champagne.&nbsp;</p><p>(I ended up building a Stripe payments React app from scratch and hosting it in Amazon ECS. And it still costs me $76.44/month to run, which was more than I anticipated spending.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> So maybe ChatGPT had the last laugh here.)</p><p>Worst of all was asking ChatGPT for help writing a Gmail add-on because &#8211; surprise! &#8211; there&#8217;s hardly any information online about building Gmail add-ons. Asking ChatGPT questions like <em>What does a google workspace addon mainfest file look like for Gmail?</em> yielded completely nonsense answers. Without the help of cutting-edge AI, I used the second-best scientific approach known to man &#8211; that is, typing hundreds of random lines of code until one of them worked &#8211; which eventually yielded results (and a lot of swear words on my end).</p><h3>Also, I hate Stripe's documentation</h3><p>Whenever I interview with a startup (for when I imminently run out of savings, or until my secret trust fund finally materializes&#8230;), they say &#8220;we&#8217;re the Stripe of home delivery&#8221; or &#8220;we&#8217;re the Stripe of dog food.&#8221;&nbsp; In other words, Stripe is the gold standard of startups.&nbsp;</p><p>However, once you start building a website that uses Stripe payments, you quickly realize that Stripe&#8217;s docs are <a href="https://stackoverflow.com/questions/72919950/how-can-i-fetch-the-client-secret-in-stripe-reactjs-and-why-cant-i-render-a-pay">famously chaotic</a>, a result of building lots of features over the years and not updating their docs accordingly. For example, it took me an entire week to turn my payments form (yes, one form) from the one shown below to a more modern design because Stripe <a href="https://stackoverflow.com/questions/64109065/stripe-reactjs-could-not-find-elements-context/76995660#76995660">hasn&#8217;t</a> yet written documentation for their new checkout page React component:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!29PK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!29PK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png 424w, https://substackcdn.com/image/fetch/$s_!29PK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png 848w, https://substackcdn.com/image/fetch/$s_!29PK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png 1272w, https://substackcdn.com/image/fetch/$s_!29PK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!29PK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png" width="926" height="834" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:834,&quot;width&quot;:926,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!29PK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png 424w, https://substackcdn.com/image/fetch/$s_!29PK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png 848w, https://substackcdn.com/image/fetch/$s_!29PK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png 1272w, https://substackcdn.com/image/fetch/$s_!29PK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5498c4e-f1a4-4922-8956-a1f1d5e2f9c1_926x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Before</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oGan!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oGan!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png 424w, https://substackcdn.com/image/fetch/$s_!oGan!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png 848w, https://substackcdn.com/image/fetch/$s_!oGan!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png 1272w, https://substackcdn.com/image/fetch/$s_!oGan!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oGan!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png" width="926" height="836" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:836,&quot;width&quot;:926,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!oGan!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png 424w, https://substackcdn.com/image/fetch/$s_!oGan!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png 848w, https://substackcdn.com/image/fetch/$s_!oGan!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png 1272w, https://substackcdn.com/image/fetch/$s_!oGan!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e0fb82-445f-4c7d-a387-2b7ebc2713b1_926x836.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">One week and fourteen gray hairs later, tada!</figcaption></figure></div><h3>How was the app approval process for Google Marketplace?</h3><p>I knew that the app approval process for Apple can take months (although they <a href="https://www.macrumors.com/2021/03/22/apple-surprised-developer-concerns-app-review/">claim</a> it&#8217;s now down to a day). But I&#8217;d never developed a Google add-on before, so I was curious how long it would take to get my app reviewed and approved by Google.</p><p>In the end, Google rejected my add-on <strong>eight</strong> times before finally approving it 31 days later.</p><h3>&#127991;&#65039; Why I&#8217;m Charging $6/month for it</h3><p>As I ate microwaveable quinoa for the seventh time this week, I made the decision to price my app at $6/month.</p><p>At first, I had decided to price Too Phishy at a low price point in order to attract as many users as possible, so that I could build the AI model of my dreams. $1/month seemed reasonable to me, and would make Too Phishy a steal when compared to Gmail&#8217;s other add-on offerings, which go for <a href="https://workspace.google.com/marketplace/app/gqueues_for_google_workspace/672546833824">$3</a> to <a href="https://workspace.google.com/marketplace/app/social_insights_for_gmail/398227766523">$10</a> a pop per month. But then I read <a href="https://www.mimiran.com/raise-prices-marc-andressen-says-you-should/">this</a> advice from Marc Andreessen:</p><blockquote><p>&#8220;The number one thing &#8211; just the theme and we see it everywhere &#8211; the number one theme with our companies have when they get really struggling is they are not charging enough for their product.&#8221;&nbsp;</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QfO-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QfO-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png 424w, https://substackcdn.com/image/fetch/$s_!QfO-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png 848w, https://substackcdn.com/image/fetch/$s_!QfO-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png 1272w, https://substackcdn.com/image/fetch/$s_!QfO-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QfO-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!QfO-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png 424w, https://substackcdn.com/image/fetch/$s_!QfO-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png 848w, https://substackcdn.com/image/fetch/$s_!QfO-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png 1272w, https://substackcdn.com/image/fetch/$s_!QfO-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7110c8-84f7-407a-a4e7-32fdc17cdb41_1024x683.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I listened, Marc.</figcaption></figure></div><h2>&#127775; Acknowledgements</h2><p>I&#8217;d like to thank Aixsha, my college suitemate, who was generous enough to share her enormous corpus of phishing emails with me (while she was under constant attack from some crazy people who hate WGA members), which I used as a basis as my phishing corpus for Too Phishy. Up until very recently, Aixsha was in the middle of experiencing constant phishing attacks while she was on strike. But don&#8217;t feel too bad for her &#8211; she&#8217;s getting vengeance on her attackers as we speak by writing a television pilot about it.</p><p>I&#8217;d also like to thank my friends Mona and David who also contributed their phishing emails.</p><h2>Appendix/Optional Reading&nbsp;</h2><h3>&#128368;&#65039; How I spent my time</h3><p>In this section, I&#8217;ll show you how I spent each week and describe the problems I addressed.</p><p>Why? Because it&#8217;s messy, and seeing someone else&#8217;s mess can be encouraging. Also, it&#8217;s useful for me to keep track of the time I spent building an app. I learn a lot by seeing how wrong my estimates are: how quickly I complete &#8220;difficult&#8221; things and how slowly I complete &#8220;easy&#8221; things (ahem, Stripe payments).</p><p><strong>Week 1</strong></p><ul><li><p>Figure out: Are Gmail add-ons even profitable?&nbsp;</p></li><li><p>Found existing add-ons on the Google <a href="https://workspace.google.com/marketplace/category/popular-apps">Marketplace</a>, then searched for their Linkedin company pages, then determined how many employees they maintain over time to assess profitability potential</p></li><li><p>Turns out that <a href="https://www.linkedin.com/company/gqueues/people/">a few</a> add-ons are full fledged companies! A good sign.</p></li></ul><p><strong>Weeks 2 &amp; 3</strong>: Decide which payments provider to use to build Too Phishy.com in order to handle user payments&nbsp;</p><ul><li><p>These weeks featured many, many tutorials</p></li><li><p>For a payments solution, I went with Stripe because it&#8217;s the industry standard</p></li><li><p>For a user authentication solution. I looked at Velvet, Stytch, AWS Amplify, Google Firebase, and others</p></li><li><p>Realized halfway through that I don&#8217;t actually need an authentication solution in order to track customers, I can just use Stripe&#8217;s <a href="https://stripe.com/docs/api/customers/object">API</a> to collect and track my customer info</p></li></ul><p><strong>Weeks 5 and 6</strong>: Productionize Too Phishy.com</p><ul><li><p>Figured out which cloud solution to use for running a web app (chose AWS ECS).</p></li><li><p>I forgot how hard this is. Serving static pages on Cloudflare is one thing, getting an app running and making outside requests is another. This required piecing together 4 Stripe tutorials, along with 5 AWS tutorials, picking and choosing which parts to follow.</p></li><li><p>Set up a CI system so that all code changes get automatically deployed to Too Phishy.com (went with AWS Codecatalyst because their tutorial was good)</p></li></ul><p><strong>Week 7</strong>:</p><ul><li><p>Tried to find online phishing corpuses to run tests on</p></li><li><p>Realize a good corpus doesn&#8217;t exist</p></li><li><p>Identified real life phishing emails for future examples</p></li><li><p>(Thanks Aixsha!)</p></li></ul><p><strong>Week 8</strong></p><ul><li><p>Took vacation</p></li></ul><p><strong>Weeks 9, 10 &amp; 11</strong></p><ul><li><p>Wrote Gmail add-on logic to parse and analyze email body and attachments</p></li></ul><p><strong>Week 12</strong></p><ul><li><p>Submitted add-on it to Google for app review (OMFG so many <a href="https://developers.google.com/workspace/marketplace/about-app-review#areas">requirements</a>).</p></li><li><p>Wrote Privacy Policy</p><ul><li><p>Created graphic assets including screenshots</p></li></ul></li></ul><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>There are some older, oft-researched phishing email corpuses &#8211; like <a href="https://www.cs.cmu.edu/~enron/">this</a> 2004 Enron email corpus and <a href="https://www.kaggle.com/datasets/rtatman/fraudulent-email-corpus">this</a> 1998-2007 "Nigerian&#8221; fraud email corpus &#8211; but they&#8217;re pretty out of date. Since phishing emails are changing from day to day, these corpuses from the mid-2000s aren&#8217;t very useful.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Funnily enough, I just listened to an <a href="https://ma.tt/2022/03/guy-razs-how-i-built-this/">interview</a> with the founder of Wordpress and learned that it cost him $99/month to run the original Wordpress server back in 2005. 18 years later, my costs are pretty much the same for compute power. (The more we evolve, the more we stay the same, yadda yadda&#8230;)</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Why haven't password complexity rules gone away yet?]]></title><description><![CDATA[I've long suspected that password complexity rules were invented by computers to torture us.]]></description><link>https://www.lydiaoncybersecurity.com/p/why-havent-password-complexity-rules</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/why-havent-password-complexity-rules</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:53:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dGl7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I've long suspected that password complexity rules were invented by computers to torture us. So I investigated: does adding special characters make passwords safer? And if not, why do so many systems require it?</p><p>The short answer is a) no, and b) because of an accident of history.</p><p>The longer answer involves an obscure government agency, the passage of time, and the universal struggle to keep up with change.</p><h3>Does adding complexity to passwords stop hackers?</h3><p>In theory, a hacker can write an automated program that will guess thousands of passwords per second, so adding special characters to passwords makes them harder for a hacker to guess.</p><p>But ever since the early 2010s, when reCAPTCHA (and other innovations like rate limiting and multi-factor authentication) spread onto almost every web login imaginable, password-guessing attacks became impossible, because hackers would quickly run into a login attempt wall. For a long time I&#8217;ve wondered why password complexity rules still exist nowadays.&nbsp;So I decided to investigate.</p><h3>Who came up with these password rules anyway?</h3><p>If you&#8217;ve ever spent time in Boulder, CO, with a dad who admires government agencies that set the time for the rest of the United States (just me?) then you should be familiar with the National Institute of Standards and Technology (NIST). The basis for NIST&#8217;s existence goes way back to 1781, when the Articles of Confederation determined that Congress had the power to determine standard weights and measurements. Since then, NIST has been responsible for setting measurements like the <a href="https://en.wikipedia.org/wiki/Standard_temperature_and_pressure">exact</a> standard of temperature (0 &#176;C = 32 &#176;F).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AoaK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AoaK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AoaK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AoaK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AoaK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AoaK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg" width="271" height="360" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:360,&quot;width&quot;:271,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!AoaK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AoaK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AoaK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AoaK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c9e283-299b-4e46-b735-b11f97359bb8_271x360.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Up until 2014, all the clocks in the United States <a href="https://www.nist.gov/timeline#event-774276">synchronized</a> their time to<a href="https://en.wikipedia.org/wiki/NIST-F1"> NIST&#8217;s atomic clock</a> in Boulder.</figcaption></figure></div><p>In addition to measurements, NIST also determines password guidelines for all U.S. government agencies. (Yes, I also found it astonishing that a government agency established in the 1700s now decides IT practices for the entire country.) All organizations that work with the federal government are required to <a href="https://www.rhombus.com/blog/nist-compliance-and-video-security-%E2%80%93-what-you-need-to-know/">adhere</a> to NIST's guidelines in order to be considered for government contracts. NIST's influence has spread into the private sector too, where its guidelines are considered the gold standard by most IT practitioners.</p><p>NIST manager Bill Burr wrote <a href="https://csrc.nist.gov/publications/detail/sp/800-63/archive/2004-09-27">SP 800-63: Electronic Authentication Guideline</a>, the agency&#8217;s first authentication guidelines, in 2004, introducing password complexity rules to the world. Burr&#8217;s guiding theory behind complexity rules? If a password is easy for a user to remember, then it&#8217;s also easy for a hacker to guess:</p><blockquote><p>Passwords chosen by users probably roughly reflect the patterns and character frequency distributions of ordinary English text, and are chosen by users so that they can remember them. Experience teaches us that many users, left to choose their own passwords, will choose passwords that are easily guessed.<br><br>Composition rules&#8230; can eliminate many obvious choices and therefore we believe that they generally improve the &#8220;practical entropy&#8221; of passwords.</p></blockquote><p>The idea follows a certain kind of logic&#8230;albeit one backed by zero evidence. &#8220;Much of what I did I now regret,&#8221; Burr <a href="https://www.wsj.com/articles/the-man-who-wrote-those-password-rules-has-a-new-tip-n3v-r-m1-d-1502124118">told</a> the WSJ in 2017. Burr hadn&#8217;t had time to test any of his theories on actual passwords, and administrators at NIST had refused his request to look at the actual passwords on their network for empirical purposes. In fact, &#8220;they were appalled [he] even asked.&#8221;</p><p>In the absence of any other guidelines to follow, government agencies and private companies alike followed Burr's advice. Even today, <a href="https://www.usenix.org/conference/soups2022/presentation/lee">45%</a> of the 120 most popular websites still require complex passwords.</p><p>Empirical evidence, finally available in 2017, showed that complex character rules make passwords no less easy to guess. Per NIST document <a href="https://csrc.nist.gov/pubs/sp/800/63/3/final">SP 800-63-3</a> (first published in 2017):</p><blockquote><p>Research has shown... that users respond in very predictable ways to the requirements imposed by composition rules. For example, a user that might have chosen &#8220;password&#8221; as their password would be relatively likely to choose &#8220;Password1&#8221; if required to include an uppercase letter and a number, or &#8220;Password1!&#8221; if a symbol is also required.</p></blockquote><p>So adding a 1 or a ! to the end of your password isn&#8217;t going to make your password that much harder to guess. </p><p>What will? It turns out that it&#8217;s far more effective to make passwords long than to make them complex:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dGl7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dGl7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png 424w, https://substackcdn.com/image/fetch/$s_!dGl7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png 848w, https://substackcdn.com/image/fetch/$s_!dGl7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png 1272w, https://substackcdn.com/image/fetch/$s_!dGl7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dGl7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png" width="740" height="601" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:601,&quot;width&quot;:740,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!dGl7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png 424w, https://substackcdn.com/image/fetch/$s_!dGl7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png 848w, https://substackcdn.com/image/fetch/$s_!dGl7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png 1272w, https://substackcdn.com/image/fetch/$s_!dGl7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95d91563-7266-4e1e-98b5-49ef205c71a2_740x601.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://xkcd.com/936/">xkcd</a></figcaption></figure></div><p>An 11-character password containing complex characters would take a computer 3 days to guess; a 25-character password containing no complex characters would take 550 years to guess.</p><p>In a nutshell: long and simple passwords are better than short and complex passwords.</p><h3>Just how often does NIST change their password guidelines?</h3><p>As I started reading these password guidelines documents, I became as fascinated by NIST as my dad, although my interest had less to do with time measurements than with the history of password guidelines.</p><p>Luckily for me, all of the password guidelines ever written by NIST are available online. (Kids, don&#8217;t let ChatGPT write your history papers. It told me that &#8220;NIST first recommended two factor auth&#8221; in 2006, but I already knew from the WSJ article that the first 2FA guidelines had been published in 2004.)</p><p>To make it easier for my future self to track these guideline changes over time (reading them wasn't thrilling enough) I made this table:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g9of!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g9of!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png 424w, https://substackcdn.com/image/fetch/$s_!g9of!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png 848w, https://substackcdn.com/image/fetch/$s_!g9of!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png 1272w, https://substackcdn.com/image/fetch/$s_!g9of!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g9of!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png" width="961" height="468" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:468,&quot;width&quot;:961,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:109080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.lydiaoncybersecurity.com/i/145725863?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g9of!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png 424w, https://substackcdn.com/image/fetch/$s_!g9of!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png 848w, https://substackcdn.com/image/fetch/$s_!g9of!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png 1272w, https://substackcdn.com/image/fetch/$s_!g9of!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9774dc3-e927-4b26-be16-9770d5db1b57_961x468.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Sources: <a href="https://csrc.nist.gov/publications/detail/sp/800-63/archive/2004-09-27">SP 800-63</a>, <a href="https://csrc.nist.gov/publications/detail/sp/800-63/1/archive/2011-12-12">SP 800-63-1</a>, <a href="https://csrc.nist.gov/publications/detail/sp/800-63/2/archive/2013-08-29">SP 800-63-2</a>, <a href="https://csrc.nist.gov/publications/detail/sp/800-63/3/archive/2017-06-22">SP 800-63-3</a>, and <a href="https://pages.nist.gov/800-63-4/">SP 800-63-4</a>.</figcaption></figure></div><p>Reassuringly, NIST&#8217;s most useless password rules &#8211; like the 90-day reset rule and the password complexity rule, both written in 2004 &#8211; were out of fashion by 2017. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hinm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hinm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png 424w, https://substackcdn.com/image/fetch/$s_!hinm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png 848w, https://substackcdn.com/image/fetch/$s_!hinm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png 1272w, https://substackcdn.com/image/fetch/$s_!hinm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hinm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png" width="328" height="198" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:198,&quot;width&quot;:328,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!hinm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png 424w, https://substackcdn.com/image/fetch/$s_!hinm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png 848w, https://substackcdn.com/image/fetch/$s_!hinm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png 1272w, https://substackcdn.com/image/fetch/$s_!hinm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b8a532-77fd-4bfb-aefc-e9af15254a1c_328x198.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Ninety-day password reset rules: not cool since 2017. One Direction: still cool today.</figcaption></figure></div><p>On the other hand, guidelines that make intuitive sense, like MFA, which was first recommended by NIST in 2004, have stuck around for ages. Some types of MFA, like text-message codes, have turned out to be <a href="https://www.wsj.com/articles/you-need-two-factor-authentication-but-some-types-are-safer-than-others-11648930708">susceptible</a> to various attacks like SIM swapping. But others, like MFA that relies on biometric data or physical security keys (both mentioned in NIST&#8217;s 2004 guidelines), have proven quite safe over time.</p><h3>Do companies keep up with these rule changes?</h3><p>NIST&#8217;s tendency to change rules over time introduces an obvious problem: the rest of the world has trouble keeping up. <a href="https://www.adp.com/">ADP</a>, the global HR company that managed payroll for my former employer, made me reset my password TEN times in four years.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S4Bi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S4Bi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png 424w, https://substackcdn.com/image/fetch/$s_!S4Bi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png 848w, https://substackcdn.com/image/fetch/$s_!S4Bi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png 1272w, https://substackcdn.com/image/fetch/$s_!S4Bi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S4Bi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png" width="1456" height="672" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:672,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!S4Bi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png 424w, https://substackcdn.com/image/fetch/$s_!S4Bi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png 848w, https://substackcdn.com/image/fetch/$s_!S4Bi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png 1272w, https://substackcdn.com/image/fetch/$s_!S4Bi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e5e5e90-b52d-4cac-8192-5453edbe35f6_2000x923.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">My password to this website is &#8220;f*%!_ADP&#8221;.</figcaption></figure></div><p>So I asked my friend Reba, who works in IT for the government, why so many websites remain out of compliance with NIST guidelines. She explained that many government agencies &#8211; and non-government agencies &#8211; don't have the time or money to follow NIST guidelines. &#8220;It&#8217;s a matter of not having enough budget to rebuild an agency's entire authentication system,&#8221; she says.</p><p>Since password rules change faster than organizations can afford to implement them, outdated rules are here to stay. So, for the foreseeable future, we'll just have to keep adding &#8220;N!ST&#8221; to the end of our passwords (...just me?).</p>]]></content:encoded></item><item><title><![CDATA[ I spent $855.77 on Google Ads and got my ads banned five times.]]></title><description><![CDATA[This post was originally published on July 9, 2023.]]></description><link>https://www.lydiaoncybersecurity.com/p/launching-my-startup-incubator</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/launching-my-startup-incubator</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:53:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KCIH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This post was originally published on July 9, 2023.</em><br><br>When people hear the word &#8220;startup,&#8221; they usually think of a software-as-a-service product. But startups can be anything: a clothing brand, a cat sitting service, a lemonade stand &#8211; they&#8217;re all startups in my mind, as long as they don&#8217;t yet have product market fit.</p><p>So this month&#8217;s startup &#8211; startup #2 of my <a href="https://lydiaoncybersecurity.substack.com/p/im-building-12-cybersecurity-startups">12 startups in 12 months</a> &#8211; is not a software product: it&#8217;s a startup incubator.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>When I launched my first startup, <a href="https://isthisphishy.io/">isthisphishy.io</a>, last month, reddit commenters almost immediately <a href="https://www.reddit.com/r/msp/comments/13oy0kr/roast_my_landing_page/">asked</a> me to turn it into an Outlook plugin, because they wanted a single click solution:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!agkV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!agkV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png 424w, https://substackcdn.com/image/fetch/$s_!agkV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png 848w, https://substackcdn.com/image/fetch/$s_!agkV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png 1272w, https://substackcdn.com/image/fetch/$s_!agkV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!agkV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png" width="618" height="246" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:246,&quot;width&quot;:618,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!agkV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png 424w, https://substackcdn.com/image/fetch/$s_!agkV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png 848w, https://substackcdn.com/image/fetch/$s_!agkV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png 1272w, https://substackcdn.com/image/fetch/$s_!agkV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdddfb3e5-72a1-4c26-b195-0b76893ccb90_618x246.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Reddit users demand an Outlook plugin.</figcaption></figure></div><p>The problem was, I didn&#8217;t want to build an Outlook plugin. I tried to build one for a few weeks (which I detail below), but I&#8217;ve used Gmail for the past 17 years and didn&#8217;t want to switch to Outlook now. So I decided to ask the internet for guidance. I ran a marketing experiment of sorts: I made landing pages for all of my startup ideas, added A/B experiments to each landing page (i.e. &#8220;Download for Gmail&#8221; versus &#8220;Download for Outlook&#8221;), created Google Ad campaigns, and then waited to see which product idea got the most traction.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KCIH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KCIH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png 424w, https://substackcdn.com/image/fetch/$s_!KCIH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png 848w, https://substackcdn.com/image/fetch/$s_!KCIH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png 1272w, https://substackcdn.com/image/fetch/$s_!KCIH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KCIH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!KCIH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png 424w, https://substackcdn.com/image/fetch/$s_!KCIH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png 848w, https://substackcdn.com/image/fetch/$s_!KCIH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png 1272w, https://substackcdn.com/image/fetch/$s_!KCIH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122b0f56-a7cc-450a-bb14-4232a10275c3_1919x1053.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Tada! Here are my three marketing landing pages side by side: <a href="https://toophishy.com/">toophishy.com</a>, <a href="https://spamcallkiller.com/">spamcallkiller.com</a>, and <a href="https://webpageexplained.com/">webpageexplained.com</a>.</figcaption></figure></div><p>Thus, My Startup Incubator was born. It&#8217;s a place to test and stack rank nascent startup ideas:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U7f1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U7f1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png 424w, https://substackcdn.com/image/fetch/$s_!U7f1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png 848w, https://substackcdn.com/image/fetch/$s_!U7f1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png 1272w, https://substackcdn.com/image/fetch/$s_!U7f1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U7f1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png" width="728" height="369" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:369,&quot;width&quot;:728,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69765,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U7f1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png 424w, https://substackcdn.com/image/fetch/$s_!U7f1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png 848w, https://substackcdn.com/image/fetch/$s_!U7f1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png 1272w, https://substackcdn.com/image/fetch/$s_!U7f1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b6a363f-15a5-4ab3-beda-15ff4118f633_728x369.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>&#9194; Rewind to trying to build an Outlook plugin</h2><p>Seven weeks ago, inspired by my Reddit commenters, I started building an Outlook plugin.</p><p>Then, three weeks ago, deep in the trenches of Outlook plugin development, I awoke in a cold sweat because I was four weeks into this project and had very little to show for it. Using Microsoft&#8217;s developer ecosystem was slowing me down. Just to get a Microsoft 365 Developer Account had taken me seven days of back and forth with various Microsoft support teams. And getting a free VS Code developer license had taken another three days of back and forth.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k1g2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k1g2!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif 424w, https://substackcdn.com/image/fetch/$s_!k1g2!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif 848w, https://substackcdn.com/image/fetch/$s_!k1g2!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif 1272w, https://substackcdn.com/image/fetch/$s_!k1g2!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k1g2!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif" width="320" height="320" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:192,&quot;width&quot;:192,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!k1g2!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif 424w, https://substackcdn.com/image/fetch/$s_!k1g2!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif 848w, https://substackcdn.com/image/fetch/$s_!k1g2!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif 1272w, https://substackcdn.com/image/fetch/$s_!k1g2!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565646db-780c-41bc-8211-7fb85a22e1f8_192x192.gif 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">This song was actually written by me about developing in the Microsoft developer ecosystem.</figcaption></figure></div><p>Along with my new stack slowing me down, one question kept echoing in the back of my mind:<em> Is building a Microsoft Outlook plugin even the right thing to be doing?</em></p><p>That afternoon, I called my friend William &#8211; a fellow entrepreneur &#8211; to get his advice. I told him that building an Outlook plugin had taken me four weeks and I was only halfway done. I missed the Google and AWS developer ecosystem I was used to.</p><p>&#8220;If you want to build something people will use, don&#8217;t build anything,&#8221; he said. &#8220;Build an ad and see if people click it. Then only build something once it gets a lot of clicks.&#8221;</p><p><em>Hm</em>, I thought, <em>Ads? Will that really work? </em><br><br>I&#8217;d never built ads before, although I had heard of Google Ads.</p><h2>Pivoting to Google Ads</h2><p>Even though Google Ads is usually something you pay someone online $5k to do for you, I decided to build Google Ads campaigns myself. I knew I wasn't experienced enough to build an effective Google Ads campaign, but I was inexperienced enough to build three terrible Google Ads campaigns. And the point of an experiment wasn't to run <em>good</em> ad campaigns, but rather to compare product ideas using similar (-ly bad) ad campaigns.</p><p>Also, I figured that using Google Ads might end up saving me a lot of work in the long run. Last month, when I launched <a href="https://isthisphishy.io/">isthisphishy.io</a>, I skipped ads entirely (for $$$ reasons). I launched the startup by posting about it on Reddit, Hacker News, Product Hunt, and twenty other sites. Posting on all those websites had been a lot of work. I had to track where all my users were coming from on my own, and retarget my future launch strategy accordingly. <em>Google Ads will save me time</em>, I figured. (Hah! Hah! Says future me.)</p><p>In the end, Google Ads did not save me time (see ad bans mentioned below). But I learned a lot, at least.</p><p>So here we are. And the experiment has worked: Too Phishy for Gmail is the idea that has gotten the most clicks so far, so expect to see a blog post on that startup next!</p><h2>What I learned about Google Ads</h2><p>In a nutshell: AI has not yet taken over the world. Setting up a Google Ads campaign is the most manual process in the world. When I launched my bare minimum campaigns using the default settings, I got absolutely <strong>no</strong> ad clicks. And yes, I even used the Performance Max campaign type which claims to use AI. </p><p>It was only after I manually defined the search terms I wanted my campaign to be shown with (e.g. &#8220;spam call&#8221;) that I finally started seeing some ad clicks and conversions. Considering that spamcallkiller.com contains the word &#8220;spam call&#8221; in the name, it doesn&#8217;t seem too crazy to think that some search terms should have been attached to my campaign by default. (I later learned that Performance Max campaigns have <a href="https://web.archive.org/web/20231106193224/https://www.businessinsider.com/google-ai-boosts-ad-performance-but-some-advertisers-push-back-2023-11?r=US&amp;IR=T">a lot</a> of issues, and that many ad agencies have stopped using the tool.)</p><p>That being said, Performance Max, though expensive and buggy, did have some nice features. Its AI algorithm created polished Youtube ads for no additional cost:</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;3065f312-0b01-4c6d-9afa-2d9bd41ecd7f&quot;,&quot;duration&quot;:null}"></div><h2>Let&#8217;s talk money</h2><p>I spent a godforsaken amount of money ($819) on my campaigns. Google Ads likes to proudly claim &#8220;you only pay for the clicks you get,&#8221; but as someone who got very few clicks, I quickly learned that Google Ads has a minimum spend they&#8217;ll charge you just for impressions. So they put my ads on a bunch of websites that no one clicked and charged me $40/day for it. Ugh.</p><p>ALSO, it&#8217;s really hard to get people in the United States and Canada to click your ads. When I set up my campaigns, this was the default audience Google Ads chose for me. Over time, since I was getting so few ad clicks, I expanded the audience to all <a href="https://worldpopulationreview.com/country-rankings/first-world-countries">first world countries</a>, and got way more clicks, especially in India, Kazakhstan, Costa Rica and Argentina. I guess not a lot of companies pay for ads in those countries, so there's less competition for clicks? Who knows.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XhyA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XhyA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png 424w, https://substackcdn.com/image/fetch/$s_!XhyA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png 848w, https://substackcdn.com/image/fetch/$s_!XhyA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png 1272w, https://substackcdn.com/image/fetch/$s_!XhyA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XhyA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png" width="826" height="705" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:705,&quot;width&quot;:826,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!XhyA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png 424w, https://substackcdn.com/image/fetch/$s_!XhyA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png 848w, https://substackcdn.com/image/fetch/$s_!XhyA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png 1272w, https://substackcdn.com/image/fetch/$s_!XhyA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9ac1456-e055-4ff1-b574-f49f8233e2a5_826x705.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Such a headache.</figcaption></figure></div><p>And oh yeah, Google banned all of my ads multiple times. Reddit tells me that ad bans happen <a href="https://www.reddit.com/r/PPC/comments/11mqimo/circumventing_systems_policy/">to a lot of people</a>. And when I set up appointments with Google Ads' support team, thinking that they&#8217;d actually show up given that I spent more than $500/month on their product, both support agents ghosted me. (Which has become common since the pandemic, I <a href="https://www.reddit.com/r/PPC/comments/11l2gvw/is_google_ads_support_gone/">hear</a>.)</p><p>After speaking with my friend Ron, a marketing executive, I realized that these bans likely happened because my landing pages had no organic online reputation (e.g. links from other websites), and basically just collected email addresses, so it's not shocking that Google thought they were scams. I've also learned recently that Facebook Ads, since it doesn't track websites' reputations, is much less likely to ban ads. (Good to know for next time!)</p><h2>Going Forward</h2><p>I hope that by being transparent about my first experiment running Google Ads campaigns, it&#8217;ll encourage readers to share your tips and help me fill in any gaps in my knowledge.</p><p>Do I think it was truly worth it to spend $819 to learn that there&#8217;s more market demand for a Gmail plugin rather than an Outlook plugin? Honestly, maybe: that&#8217;s how much two hours talking to a marketing consultant would probably cost anyway.</p><p>Plus, I learned a lot. Going forward, I feel more confident about how to estimate product market fit <em>before</em> building products. And next time I'll use Facebook Ads, instead of Google Ads, for marketing not-yet-existing products.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;5dc954ea-b1b6-409c-903d-8892ea0ac9a3&quot;,&quot;duration&quot;:null}"></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><br>Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p>]]></content:encoded></item><item><title><![CDATA[Launching Is This Phishy 🎣📩]]></title><description><![CDATA[This post was originally published on May 17, 2023.]]></description><link>https://www.lydiaoncybersecurity.com/p/launching-is-this-phishy</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/launching-is-this-phishy</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:48:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QLAP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This post was originally published on May 17, 2023.</em></p><p>And here we are! One startup done, six weeks passed. (Yes, the plan was originally one startup per month, but have you tried to create a minimum viable product in only a month?!?)</p><p>For each startup I launch, I&#8217;ll be writing a post like this, and explaining how it achieves <a href="https://lydiaoncybersecurity.substack.com/p/im-building-12-cybersecurity-startups">my broader goal this year</a> to make cybersecurity products more accessible to a wider audience. Since this was my first startup, I wanted to make something that would be useful for everyone from your kid brother to your grandma: an elegant email server that can identify phishing emails.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QLAP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QLAP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png 424w, https://substackcdn.com/image/fetch/$s_!QLAP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png 848w, https://substackcdn.com/image/fetch/$s_!QLAP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png 1272w, https://substackcdn.com/image/fetch/$s_!QLAP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QLAP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png" width="1456" height="699" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:699,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!QLAP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png 424w, https://substackcdn.com/image/fetch/$s_!QLAP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png 848w, https://substackcdn.com/image/fetch/$s_!QLAP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png 1272w, https://substackcdn.com/image/fetch/$s_!QLAP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F716d9393-593b-438e-b18e-461f3008eeb2_2000x960.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I made a friendly email address to which you can forward sketchy emails (for free) and it tells you whether the email is a phishing scam &#127907;&#128233;. Check it out on <a href="https://www.producthunt.com/products/is-this-phishy">Product Hunt</a>.</figcaption></figure></div><h3>&#129300; <strong>The Problem</strong></h3><p>The problem is that every time I get a sketchy email, I never know whether it's a phishing scam. When I google &#8220;how to identify a phishing email," hundreds of websites offer one hundred different answers. My cousin works at a big bank, and she told me that bank customers can send suspicious-looking emails to the security team, and they&#8217;ll tell you whether it&#8217;s a phishing attempt. That&#8217;s what made me realize there needs to be a similar service for any person, for any email, anywhere.</p><h3>&#128736;&#65039; <strong>Solution</strong></h3><p>Say hello to <a href="mailto:help@isthisphishy.io">help@isthisphishy.io</a>, a friendly email address that you can forward any and all emails to (for free), and you&#8217;ll get a response telling you why or why not the email is a phishing scam. &#127907;&#128233; Check it out at <a href="https://isthisphishy.io/">isthisphishy.io</a>.</p><h2>&#128680; The Launch</h2><p>One month after its launch, Is This Phishy was featured on prominent blogs like <a href="https://newsletter.insanelyusefulwebsites.com/p/iuw-78">Insanely Useful Websites</a>, the <a href="https://blog.onelaunch.com/new-email-scams-to-watch-for/">OneLaunch blog</a>, the <a href="https://mike-taylor.org/blog-2/">Mike Taylor blog</a>, and <a href="https://betalist.com/startups/is-this-phishy">Beta List</a>. It also reached <strong>403 monthly active users in its first month.</strong></p><p>Since this was my first launch ever, I followed the advice of <a href="https://readmake.com/">Read Make</a> and took a "spray and pray" approach, posting about my launch everywhere from <a href="https://twitter.com/LydiaStepanek/status/1658856651368144897">Twitter</a> and <a href="https://www.reddit.com/r/msp/comments/13oy0kr/roast_my_landing_page/">Reddit</a> to <a href="https://www.indiehackers.com/post/what-is-your-april-startup-aa764cb7bf?commentId=-NVfP57or6m4i4OGfkn6">Indie Hackers</a>.</p><p>The single biggest social media response came from my <a href="https://www.reddit.com/r/msp/comments/13oy0kr/roast_my_landing_page/">post</a> to <strong>Reddit's r/msp (managed service provider) community, which garnered 23,200 impressions</strong> and a big uptick in users. Before posting, I didn't realize that the group had 148k members worldwide; I simply wanted good feedback on my landing page. I started laughing incredulously when I noticed that the post had 4,000 impressions only a few minutes after I'd posted it. In the end, I got <strong>39 comments</strong> from people who cumulatively had decades of IT experience. (I know this because I DM'd some of them to get feedback on future product ideas.) Many commenters, unsurprisingly, wanted more security transparency before they used my service. This feedback inspired me to add a security notification to the top every email:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7Rmh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7Rmh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png 424w, https://substackcdn.com/image/fetch/$s_!7Rmh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png 848w, https://substackcdn.com/image/fetch/$s_!7Rmh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png 1272w, https://substackcdn.com/image/fetch/$s_!7Rmh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7Rmh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png" width="704" height="379" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:379,&quot;width&quot;:704,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!7Rmh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png 424w, https://substackcdn.com/image/fetch/$s_!7Rmh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png 848w, https://substackcdn.com/image/fetch/$s_!7Rmh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png 1272w, https://substackcdn.com/image/fetch/$s_!7Rmh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2249e943-2e1d-4ea4-9992-765fb8384a03_704x379.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Additionally, my <a href="https://www.linkedin.com/feed/update/urn:li:activity:7064628717188210688/">post</a> to <strong>LinkedIn fetched 3,422 impressions and 96 likes</strong>, by far the most "likes" I got anywhere. (By comparison, my <a href="https://news.ycombinator.com/item?id=35976876">post</a> to Hacker News got only 4 likes.) I was surprised and pleased by the number of friends and former coworkers who saw the post on LinkedIn and reached out to say they'd shared Is This Phishy with their IT team. Some even sent me the feedback from their IT teams which was especially helpful.</p><p>In the first week of launch, Is This Phishy made it to <strong><a href="https://www.producthunt.com/posts/is-this-phishy?ref=lydiaoncybersecurity.com">#45</a> on Product Hunt </strong>(out of 144 total product launches that day), and <strong>over 400 people</strong> viewed it:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G-qE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G-qE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png 424w, https://substackcdn.com/image/fetch/$s_!G-qE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png 848w, https://substackcdn.com/image/fetch/$s_!G-qE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png 1272w, https://substackcdn.com/image/fetch/$s_!G-qE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G-qE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png" width="787" height="405" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:405,&quot;width&quot;:787,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!G-qE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png 424w, https://substackcdn.com/image/fetch/$s_!G-qE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png 848w, https://substackcdn.com/image/fetch/$s_!G-qE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png 1272w, https://substackcdn.com/image/fetch/$s_!G-qE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3062ed55-02a9-4bd4-9072-3c2e8845cbaf_787x405.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128176; Biggest win: IsThisPhishy.io costs only $26.66/month to build and maintain</h2><p>I&#8217;m most comfortable with AWS, so I decided to use AWS for this project. Whenever I researched email server solutions, AWS was always much cheaper than competitors like Mailgun: AWS SES <a href="https://deliciousbrains.com/ses-vs-mailgun-vs-sendgrid/">only costs</a> $0.10 cents per 1,000 emails sent, while Mailgun costs eight times more. This means that my costs for running <a href="https://isthisphishy.io/">isthisphishy.io</a> are REALLY low, so I can offer it for free.</p><p>Expenses to maintain the <a href="https://isthisphishy.io/">isthisphishy.io</a> site:</p><ul><li><p><strong>$89/year</strong>: <a href="https://cruip.com/unlimited-access/">cruip.com</a> for static website design template (this was a one time purchase but for simplicity I&#8217;ll record it as an annual purchase)</p></li><li><p><strong>$36/year</strong>: Registering domain name <a href="https://isthisphishy.io/">isthisphishy.io</a> on Cloudflare</p></li><li><p><strong>$0</strong>: <a href="https://pages.cloudflare.com/">Cloudflare pages</a> for hosting</p></li></ul><p>Expenses to maintain the email server:</p><ul><li><p><strong>$16/month</strong> &#8211; Amazon Workmail (for an email client interface to read the emails sent to my four @isthisphishy.io email addresses)</p></li><li><p><strong>$1.39/month</strong> &#8211; Amazon Simple Email Service (for receiving and sending automated emails)</p></li><li><p><strong>$0.09/month</strong> &#8211; Amazon Simple Storage Service (for storing emails in the cloud)</p></li><li><p><strong>$0.01/month</strong> &#8211; AWS Lambda (for running arbitrary code in a container when an email is sent to isthisphishy.io)</p></li><li><p><strong>$0.07/month</strong> - Amazon Elastic Container Registry (for hosting container images containing the email server code)</p></li><li><p><strong>$0.01/month</strong> - Amazon Cloudwatch and Simple Notification Service (for getting alerts when things go wrong)</p></li></ul><p>Total: <strong>$27.99/month</strong></p><h2>&#8987; How I managed my time</h2><p>I started this app on Monday, April 3. I posted it to Product Hunt on Wednesday, May 17. Total time to launch: six weeks.</p><p>The approximate time breakdown of the 6 weeks was spent as follows:</p><p><strong>Week 1</strong>: Researched which stack I&#8217;ll use</p><ul><li><p>Spent time figuring out the cheapest way to send emails (Answer: AWS SES)</p></li><li><p>Spent time figuring out the cheapest way to make a landing page (Answer: cheap online templates + Cloudflare pages)</p></li></ul><p><strong>Week 2</strong>: Took vacation!</p><p><strong>Week 3</strong>: Made a bare-bones MVP (minimum viable product) to see if the stack would work</p><ul><li><p>Basically, at first I made an AWS Lambda function that responds &#8220;Hi&#8221; when you send it an email.</p></li><li><p>Then I added some simple rules.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!42nt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!42nt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png 424w, https://substackcdn.com/image/fetch/$s_!42nt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png 848w, https://substackcdn.com/image/fetch/$s_!42nt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png 1272w, https://substackcdn.com/image/fetch/$s_!42nt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!42nt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png" width="1456" height="530" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:530,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!42nt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png 424w, https://substackcdn.com/image/fetch/$s_!42nt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png 848w, https://substackcdn.com/image/fetch/$s_!42nt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png 1272w, https://substackcdn.com/image/fetch/$s_!42nt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9822b41a-d8f7-4ff0-8db3-5b5e5d0f976d_1491x543.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This is what my email service looked like halfway through Week 3.</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YBXS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YBXS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png 424w, https://substackcdn.com/image/fetch/$s_!YBXS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png 848w, https://substackcdn.com/image/fetch/$s_!YBXS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png 1272w, https://substackcdn.com/image/fetch/$s_!YBXS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YBXS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png" width="1456" height="557" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:557,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!YBXS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png 424w, https://substackcdn.com/image/fetch/$s_!YBXS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png 848w, https://substackcdn.com/image/fetch/$s_!YBXS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png 1272w, https://substackcdn.com/image/fetch/$s_!YBXS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff68bea34-037a-47a1-b6c4-1266d0fee45a_1492x571.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Aaaand this is what it looked like at the end of Week 3.</figcaption></figure></div><p><strong>Week 4</strong>: Created a landing page for <a href="https://isthisphishy.io/">the website</a></p><ul><li><p>Competitive research: what products existed and how they marketed themselves.</p></li><li><p>Came up with a vision for the landing page and found an online template to match it.</p></li><li><p>Wrote copy for the landing page (which was surprisingly difficult and time intensive).</p></li></ul><p><strong>Week 5</strong>: Solicited feedback from beta users (a.k.a. found bugs and fixed them)</p><ul><li><p>At this point, I sent out my beta version to a few close friends and mentors. They found inevitable issues and bugs, so this time was spent addressing those.</p></li></ul><p><strong>Week 6</strong>: Added a feature where the email server checks the top one million most popular domains</p><ul><li><p>This feature wasn&#8217;t a must-have for launch, so I was torn. Adding it flew in the face of my bare-bones ethos, but I felt strongly that it should be included. In the end, I think I made the right choice here.</p></li></ul><h2>&#128170; Reflection on Productivity</h2><p>Ever since reading The 4-Hour Workweek, my life goal has been to accomplish as much as possible in as few hours as possible. (Ideally, 4 hours of work per week.)</p><p>For the past six weeks, I worked around 5 hours per day, 6 days a week, so I worked a 30-hour week. Certainly, I came nowhere close to Ferris&#8217;s 4-hour per week target, but he was selling muscle supplements, and I&#8217;m building a web app, so I&#8217;ll forgive myself the 26 extra hours.</p><p>These are the things I did well productivity-wise that I will continue:</p><ul><li><p><strong>Only do what feels fun on a given day</strong>: This philosophy was inspired by advice from my friend <a href="https://www.linkedin.com/in/vpooja">Pooja</a>. I always try to have 3 pots cooking simultaneously: blog drafts I&#8217;m working on, app code I&#8217;m writing, and business activities like tracking costs or signing papers. Some days I wake up and want to work on code, while others, I wake up, and write. To keep myself motivated, I do whatever feels like fun that day. That way, I keep my energy and motivation levels up. (In the spirit of honesty, signing business forms is something I never wake up wanting to do. So I force myself to do that one, but only when I have lots of energy/coffee.)</p></li><li><p><strong>Use a coworking space</strong>: As someone who used to work from home most of the time, splurging on a coworking space has been a game changer. Having a separation of home and work keeps me more motivated because I get time to relax every day when I&#8217;m in my &#8220;home&#8221; space. (And by &#8220;relax,&#8221; I mean watch <em>Love is Blind</em>.)</p></li></ul><p>Things I could do better next time:</p><ul><li><p><strong>Get to my coworking space earlier:</strong> I now realize it takes me about 1.5 hours to actually start coding after I sit down at my computer &#8211; after all, there&#8217;s <em>Architectural Digest</em> to read, and Harry Styles&#8217; love life to track. It takes a really long time to warm up my brain. I need to just accept this, plan for it, and sit at my desk sooner in the day.</p></li><li><p><strong>Go straight to the docs: </strong>Instead of wasting time watching tutorials on youtube, I wish I&#8217;d gone straight to the AWS docs sooner. <a href="https://aws.amazon.com/blogs/messaging-and-targeting/forward-incoming-email-to-an-external-destination/">This</a> was the main AWS tutorial I used for building the MVP of my email server, and I wish I&#8217;d started with it. There&#8217;s a lot of bad training content on the internet, and I need to ensure I&#8217;m using the most trusted online sources. (Yes, this is a jab at ChatGPT.)</p></li></ul><h2>Biggest technical learning: Parsing forwarded emails is surprisingly hard &#128232;</h2><p>I built my MVP in Python first, only to realize three weeks in that Python does not have any libraries to parse forwarded emails. Different email clients &#8211; Gmail, Yahoo Mail, Outlook, etc. &#8211; all format forwarded emails in different ways, so it&#8217;s actually <a href="https://stackoverflow.com/questions/2168719/parsing-forwarded-emails">really complicated</a> to parse something as simple as the &#8220;from&#8221; sender on a forwarded email. And I didn't want to build a parsing library from scratch in Python &#8211; I only had one month! The only code I could find online that could parse forwarded emails for all email clients was written in Javascript: <a href="https://github.com/crisp-oss/email-forward-parser#how-does-it-work">email-forward-parser</a>, which is an amazing library from Crisp. This meant that halfway into this project after I&#8217;d built my MVP in Python, I had to rewrite everything in Javascript, which I hadn't coded in since 2019.</p><p>The silver lining: being an independent developer allows me to choose my own technical stack, which I&#8217;ve never been able to do before. I was able to switch to JavaScript on a dime to best serve my development needs, which was very liberating!</p><h2>The most valuable way you can help me is by providing feedback and ideas&#128066;</h2><p>Please comment below.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[I'm building 12 (cybersecurity) startups in 12 months]]></title><description><![CDATA[This post was originally published on May 17, 2023.]]></description><link>https://www.lydiaoncybersecurity.com/p/im-building-12-cybersecurity-startups</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/im-building-12-cybersecurity-startups</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:46:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6Qyh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This post was originally published on May 17, 2023.<br></em><br>Earlier this year, I felt stuck in my job at a large tech company, so I quit. After eight years as a software engineer, I knew two things: 1) I wanted to work on cybersecurity problems, and 2) I wanted to build apps.</p><p>I&#8217;d been interested in cybersecurity ever since the Cambridge Analytica scandal in 2018 when I discovered that Facebook advertisers had free access to my private messages without my knowledge. Ever since then, I&#8217;ve believed that people should have the right to know where their data is and who&#8217;s using it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In fact, I originally became a software engineer to make technology more accessible to people. But after almost a decade of solving difficult technical problems, I suddenly realized that I&#8217;d lost track of the thing I had originally set out to do.</p><p>As I considered my options this past Spring, my friend Amir texted me, &#8220;You should read this!&#8221; He sent me the blog post <em><a href="https://levels.io/12-startups-12-months/">I'm Launching 12 Startups in 12 Months</a></em> by indie developer <a href="https://twitter.com/levelsio?ref=levels.io">Pieter Levels</a>.</p><p>In the post, Levels argues that indie developers should push themselves to release &#8220;startups,&#8221; which he describes as simple apps to which you can add more features later.</p><p>Levels makes the case for building 12 startups in 12 months. His theory is that building something new every month ensures you don&#8217;t spend too much time focusing on perfection: &#8220;AirBnB started as a company selling Obama-themed cereal, while Dropbox was just Drew Houston building a graphical user interface for rsync as a side-project.&#8221; Many amazing businesses have humble beginnings as one-off apps.</p><p>Upon reading the post, I realized, <em>This is what I want to do.</em> Specifically, I want to build cybersecurity startups.</p><p>The cybersecurity field genuinely requires deep technical knowledge, but still, I&#8217;ve been astounded by how much the literature uses obscure industry-speak to explain simple concepts. Someone needs to demystify cybersecurity for consumers and developers, so why not me?</p><p>Thus, I&#8217;ll create and post one new cybersecurity startup each month for the next year.</p><h3>Cybersecurity apps should be built for individuals, not just companies.</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6Qyh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6Qyh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp 424w, https://substackcdn.com/image/fetch/$s_!6Qyh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp 848w, https://substackcdn.com/image/fetch/$s_!6Qyh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp 1272w, https://substackcdn.com/image/fetch/$s_!6Qyh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6Qyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp" width="500" height="399" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:399,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!6Qyh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp 424w, https://substackcdn.com/image/fetch/$s_!6Qyh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp 848w, https://substackcdn.com/image/fetch/$s_!6Qyh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp 1272w, https://substackcdn.com/image/fetch/$s_!6Qyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2c7c864-315e-49d5-bad4-a8025bcba902_500x399.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#8220;Cybercrimes&#8221; are the new Regina George. Hackers have hurt so many of my friends: stolen their social security numbers, ruined credit scores, or posted personal photos online. Yet most cybersecurity protection apps are built for companies and are inaccessible to the average person.</p><h3>Women are cybersecurity customers too.</h3><p>You know what the average cybersecurity app looks like: dark gray background, lime green color scheme, sans serif font, and an overall aesthetic that screams, <em>I&#8217;m a character in a David Fincher film.</em></p><p>Instead of a design scheme that speaks to a precocious, terminally online 12 year old, I want cybersecurity products with pink logos. Or funny, approachable emojis. Or really anything that doesn&#8217;t revolve around making the user feel secure in their masculinity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QD0o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QD0o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png 424w, https://substackcdn.com/image/fetch/$s_!QD0o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png 848w, https://substackcdn.com/image/fetch/$s_!QD0o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png 1272w, https://substackcdn.com/image/fetch/$s_!QD0o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QD0o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png" width="1251" height="851" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:851,&quot;width&quot;:1251,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!QD0o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png 424w, https://substackcdn.com/image/fetch/$s_!QD0o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png 848w, https://substackcdn.com/image/fetch/$s_!QD0o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png 1272w, https://substackcdn.com/image/fetch/$s_!QD0o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd752aa2f-be92-4665-8c4a-60e7621ba5c6_1251x851.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This is the search results page of one of the most popular cybersecurity websites in the world, <a href="https://www.shodan.io/?ref=lydiaoncybersecurity.com">shodan.io</a>. Needlessly intimidating, right?</figcaption></figure></div><p>When a hack is worldwide news, it targets women more than 50% of the time (see: <a href="https://en.wikipedia.org/wiki/Gamergate_(harassment_campaign)#:~:text=Gamergate%20has%20been%20described%20as%20an%20expression%20of%20sexism%20and,threat%20to%20traditional%20video%20games.">Gamergate</a>, <a href="https://en.wikipedia.org/wiki/2014_celebrity_nude_photo_leak">Celebgate</a>, and even the <a href="https://en.wikipedia.org/wiki/Sony_Pictures_hack">Sony Pictures Hack</a>, which was most famous for leaking all of Amy Pascal&#8217;s emails). Yes, famous men <a href="https://www.theguardian.com/technology/2020/jan/21/amazon-boss-jeff-bezoss-phone-hacked-by-saudi-crown-prince">get hacked</a> too, but it isn&#8217;t the rule. It&#8217;s women who tend to be victimized by rote, everyday hacking like revenge porn.</p><p>I myself live in terror of what&#8217;s published online about me. When I first heard about the website <a href="http://haveibeenpwned.com">haveibeenpwned.com</a>, which tells you if your email address has been in any security breaches, I waited two months before having the courage to check it. Sure enough, my data had been leaked in TWELVE different breaches.</p><p>I truly believe that if <a href="http://haveibeenpwned.com">haveibeenpwned.com</a> had a less intimidating interface, and looked more like the websites I already use, then I wouldn&#8217;t have been so afraid to use it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nbyz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nbyz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png 424w, https://substackcdn.com/image/fetch/$s_!nbyz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png 848w, https://substackcdn.com/image/fetch/$s_!nbyz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png 1272w, https://substackcdn.com/image/fetch/$s_!nbyz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nbyz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png" width="1456" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!nbyz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png 424w, https://substackcdn.com/image/fetch/$s_!nbyz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png 848w, https://substackcdn.com/image/fetch/$s_!nbyz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png 1272w, https://substackcdn.com/image/fetch/$s_!nbyz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb927e-6f58-42d1-9c93-3bd30d0778f4_2318x1316.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Especially at younger ages, women worry about their online data more than men do. Source: <a href="https://datareportal.com/reports/digital-2023-global-overview-report?ref=lydiaoncybersecurity.com">2023 Global Digital Report</a></figcaption></figure></div><p>Interestingly, women are actually more willing to spend money on cybersecurity than men. Recent survey results show that women are more concerned about their online data being misused than men are, meaning that by subtly gendering cybersecurity design, there&#8217;s a huge market left completely untapped.</p><h3><strong>Customers are smart. They deserve to know how things work.</strong></h3><p>So many cybersecurity tools use artificial intelligence and machine learning to detect issues. These tools are amazingly powerful, but they obscure the mechanics at play. I want to build apps that explain not just the <em>what</em> but the <em>how</em>.</p><h3><strong>Apps need to prioritize looking nice on mobile devices.</strong></h3><p>I'm amazed at the number of security apps I use that look ten times better on desktops than on mobile devices. You know what I mean: huge fonts, pictures that get cut off sideways, and spacing that looks like it&#8217;s from the original Space Jam website. Given that 60% of the world now accesses the internet on a phone, it&#8217;s time to build for mobile devices from the get-go. Especially as mobile devices <a href="https://www.nytimes.com/wirecutter/blog/how-iphone-apps-track-you/">increasingly</a> prioritize transparency around user apps and privacy, which desktop computers don&#8217;t.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!km_0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!km_0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png 424w, https://substackcdn.com/image/fetch/$s_!km_0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png 848w, https://substackcdn.com/image/fetch/$s_!km_0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png 1272w, https://substackcdn.com/image/fetch/$s_!km_0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!km_0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!km_0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png 424w, https://substackcdn.com/image/fetch/$s_!km_0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png 848w, https://substackcdn.com/image/fetch/$s_!km_0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png 1272w, https://substackcdn.com/image/fetch/$s_!km_0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b45b77-9349-4c97-95f6-e64794470fd1_2324x1304.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Mobile use has been climbing ever since mobile phones were invented. (Well, except for whatever happened in 2018.) Source: <a href="https://datareportal.com/reports/digital-2023-global-overview-report?ref=lydiaoncybersecurity.com">2023 Global Digital Report</a></figcaption></figure></div><h3><strong>Finally, your operating system shouldn&#8217;t matter at all&#8212; apps should be built for the browser.</strong></h3><p>Your data deserves to be protected no matter which operating system you&#8217;re using. With cybersecurity software, there&#8217;s usually one tool for Windows, and one for Linux. Coming from a background in building database software, which has slowly but surely moved to a browser-based model, it surprises me that cybersecurity apps are rarely developed for the browser. You know, that thing we invented in the 1990s?</p><p>Since browsers are built to run on any operating system, any app built for the browser gets operating system compatibility for free.</p><h2>Ready, Set, Go.</h2><p>I want to build products that speak to a broader audience: that appeal to all genders, work in the browser, and look good on mobile devices. Can't be that hard, right?</p><p>And with that, we're off! See you at app #1!</p><h2>My progress report</h2><h3><strong>#1</strong>: <a href="https://isthisphishy.io/">Is This Phishy</a></h3><p>Read my recap <a href="https://lydiaoncybersecurity.substack.com/p/launching-is-this-phishy">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NVYd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NVYd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png 424w, https://substackcdn.com/image/fetch/$s_!NVYd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png 848w, https://substackcdn.com/image/fetch/$s_!NVYd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png 1272w, https://substackcdn.com/image/fetch/$s_!NVYd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NVYd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png" width="1456" height="699" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9a3c5247-7959-4193-a623-d4880652235e_2000x960.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:699,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!NVYd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png 424w, https://substackcdn.com/image/fetch/$s_!NVYd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png 848w, https://substackcdn.com/image/fetch/$s_!NVYd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png 1272w, https://substackcdn.com/image/fetch/$s_!NVYd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a3c5247-7959-4193-a623-d4880652235e_2000x960.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I made a friendly email address to which you can forward sketchy emails (for free) and it tells you whether the email is a phishing scam &#127907;&#128233;. Check it out on <a href="https://www.producthunt.com/products/is-this-phishy">Product Hunt</a>.</figcaption></figure></div><h3><strong>#2: My Startup Incubator</strong></h3><p>Read my recap <a href="https://lydiaoncybersecurity.substack.com/p/launching-my-startup-incubator">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-W23!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-W23!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png 424w, https://substackcdn.com/image/fetch/$s_!-W23!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png 848w, https://substackcdn.com/image/fetch/$s_!-W23!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png 1272w, https://substackcdn.com/image/fetch/$s_!-W23!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-W23!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!-W23!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png 424w, https://substackcdn.com/image/fetch/$s_!-W23!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png 848w, https://substackcdn.com/image/fetch/$s_!-W23!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png 1272w, https://substackcdn.com/image/fetch/$s_!-W23!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d45a8e6-5e81-4947-8317-e205a9ab9819_1919x1053.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This startup was an incubator for all of my nascent product ideas.</figcaption></figure></div><h3><strong>#3: <a href="https://workspace.google.com/marketplace/app/too_phishy/802749066565">Too Phishy</a></strong></h3><p>Read my recap <a href="https://lydiaoncybersecurity.substack.com/p/launching-too-phishy">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HFT3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HFT3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png 424w, https://substackcdn.com/image/fetch/$s_!HFT3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png 848w, https://substackcdn.com/image/fetch/$s_!HFT3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png 1272w, https://substackcdn.com/image/fetch/$s_!HFT3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HFT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png" width="1221" height="558" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:558,&quot;width&quot;:1221,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!HFT3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png 424w, https://substackcdn.com/image/fetch/$s_!HFT3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png 848w, https://substackcdn.com/image/fetch/$s_!HFT3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png 1272w, https://substackcdn.com/image/fetch/$s_!HFT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d0723f5-a5c2-41ed-8d4c-74ffe8c72b22_1221x558.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Harnessing cutting-edge technology, Too Phishy performs real-time analysis of attachments and sender information so that your online security is never compromised. Check it out on <a href="https://www.producthunt.com/posts/too-phishy-for-gmail">Product Hunt</a>.</figcaption></figure></div><h3><strong>#4: Starting Over/Becoming a Software Engineer Contractor</strong></h3><p>Read the whole story <a href="https://lydiaoncybersecurity.substack.com/p/starting-over">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j7Js!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j7Js!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png 424w, https://substackcdn.com/image/fetch/$s_!j7Js!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png 848w, https://substackcdn.com/image/fetch/$s_!j7Js!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png 1272w, https://substackcdn.com/image/fetch/$s_!j7Js!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j7Js!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png" width="814" height="412" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:412,&quot;width&quot;:814,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!j7Js!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png 424w, https://substackcdn.com/image/fetch/$s_!j7Js!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png 848w, https://substackcdn.com/image/fetch/$s_!j7Js!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png 1272w, https://substackcdn.com/image/fetch/$s_!j7Js!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f75736-7476-44ea-873d-a8d27aa1e510_814x412.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">See my new Linkedin title.</figcaption></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Behind WhatsApp's Slowing Growth]]></title><description><![CDATA[Phone messaging is one of the most competitive markets there is.]]></description><link>https://www.lydiaoncybersecurity.com/p/behind-whatsapps-slowing-growth</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/behind-whatsapps-slowing-growth</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:45:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uPiv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Phone messaging is one of the most competitive markets there is. That&#8217;s why WhatsApp&#8217;s growth for thirteen straight years has been so insane to watch. How has this one messaging app managed to add an average of 208 million new users every year since 2012?</p><p>The short answer: it's free and super accessible to everyone, everywhere. (We&#8217;ll get more into WhatsApp&#8217;s merits soon.)</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>But this blog post isn&#8217;t about WhatsApp&#8217;s explosive growth. It&#8217;s about a privacy notification in the year 2021 that told users that their data was being shared with Facebook, and how that caused WhatsApp&#8217;s growth to slow to its slowest rate since 2012, and pushed Telegram to the #1 position as most downloaded app of January 2021.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uPiv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uPiv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png 424w, https://substackcdn.com/image/fetch/$s_!uPiv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png 848w, https://substackcdn.com/image/fetch/$s_!uPiv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png 1272w, https://substackcdn.com/image/fetch/$s_!uPiv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uPiv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png" width="1456" height="885" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8166d763-1511-430f-b442-450404d3c44a_1600x972.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:885,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;Chart&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="Chart" srcset="https://substackcdn.com/image/fetch/$s_!uPiv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png 424w, https://substackcdn.com/image/fetch/$s_!uPiv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png 848w, https://substackcdn.com/image/fetch/$s_!uPiv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png 1272w, https://substackcdn.com/image/fetch/$s_!uPiv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8166d763-1511-430f-b442-450404d3c44a_1600x972.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">WhatsApp added 80 million users in 2021, its slowest growth since 2012. (No data available for 2019.) Source: <a href="https://www.demandsage.com/whatsapp-statistics/#:~:text=WhatsApp%20Monthly%20Active%20Users%202023,1%20billion%20monthly%20active%20users.">DemandSage</a> &amp; <a href="https://techcrunch.com/2018/01/31/whatsapp-hits-1-5-billion-monthly-users-19b-not-so-bad/">TechCrunch</a></figcaption></figure></div><p>Why didn&#8217;t WhatsApp&#8217;s growth slow in 2014, when Facebook acquired WhatsApp? Or in 2016 when WhatsApp started sharing user data with Facebook? Why was one privacy notification enough to send away hundreds of millions of users?</p><p>To answer those questions, let&#8217;s go back to 2014&#8230;</p><h3>The $19 billion Acquisition</h3><p>Ah, 2014, those were the days &#8211; before I&#8217;d ever heard the term &#8220;millennial dread&#8221;, lived without a roommate, learned what encryption was, tasted rolled ice cream, or fully registered that all of my internet data was being stored by the NSA. I miss 2014.</p><p>I still remember the day that Facebook bought WhatsApp for $19 billion, 19 times the price it paid for Instagram. At the time, I was working as a junior web developer at a small startup and learned about the acquisition over lunch. &#8220;Can you believe it, $19 billion?&#8221; my teammate Arjun asked me. &#8220;They have only 55 employees. Those must be the richest employees in history.&#8221;</p><p>&#8220;Wait, what&#8217;s WhatsApp?&#8221; I replied, while chewing my sushi.</p><h3>What&#8217;s WhatsApp?</h3><p>WhatsApp, it turns out, is a cell phone app that allows you to send messages through a smartphone app, avoiding SMS fees. Usually, when someone with an Android phone texts someone using an iPhone, they pay an SMS fee. Those fees can be quite high in places like Europe and the developing world where telecommunications companies have monopolies.</p><p>Starting in 2009 with iMessage, messaging apps started to surge in popularity because they avoided SMS fees. By 2014, WhatsApp was the only free mobile messaging app that was available on all phones including feature phones.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wqyv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wqyv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png 424w, https://substackcdn.com/image/fetch/$s_!wqyv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png 848w, https://substackcdn.com/image/fetch/$s_!wqyv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png 1272w, https://substackcdn.com/image/fetch/$s_!wqyv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wqyv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png" width="611" height="336" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:336,&quot;width&quot;:611,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:44705,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wqyv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png 424w, https://substackcdn.com/image/fetch/$s_!wqyv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png 848w, https://substackcdn.com/image/fetch/$s_!wqyv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png 1272w, https://substackcdn.com/image/fetch/$s_!wqyv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37c9aea3-c116-4fc3-83bd-68d6336abefb_611x336.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At the time of the Facebook acquisition, though, WhatsApp was much more than just a tool to avoid SMS fees. It was the only messaging app in the market that offered a truly global product, running on all major mobile operating systems from its inception: iPhones, Androids, Blackberrys, as well as the feature phones that are popular in developing countries. (This part will become important later.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J_PB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J_PB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg 424w, https://substackcdn.com/image/fetch/$s_!J_PB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg 848w, https://substackcdn.com/image/fetch/$s_!J_PB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!J_PB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J_PB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!J_PB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg 424w, https://substackcdn.com/image/fetch/$s_!J_PB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg 848w, https://substackcdn.com/image/fetch/$s_!J_PB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!J_PB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd857ac7-ac1b-4475-935b-96245a4d4ac6_1600x1066.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">If you&#8217;re wondering what a feature phone is, imagine a 2000s-era Nokia or Razr phone that uses WiFi. (In other words, a smartphone with a smaller, cheaper operating system than an iPhone or Android phone.)</figcaption></figure></div><p>Plus, WhatsApp offered tons of languages since its founding, helping it to spread globally: &#8220;In the startup&#8217;s first year, they offered the service in German, Spanish, French, and Italian, among other languages,&#8221; Wired <a href="https://web.archive.org/web/20170826072315mp_/https://www.wired.com/2016/04/forget-apple-vs-fbi-whatsapp-just-switched-encryption-billion-people/">explained</a> at the time.</p><p>It's true that WhatsApp's competitors, like iMessage and Telegram, offered features that WhatsApp didn't, like encryption (more on that later). But iMessage only worked &#8211; and still only works &#8211; on iPhones, a limiting factor that means that only <a href="https://gs.statcounter.com/vendor-market-share/mobile/worldwide/#monthly-201003-202302">30%</a> of smartphone users can ever use it. And Telegram was brand new to the market.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZQil!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZQil!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZQil!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZQil!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZQil!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZQil!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!ZQil!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZQil!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZQil!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZQil!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04326e0f-ee4c-454a-a4b9-ffefe6297ced_1600x1066.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Look at all the foreign languages WhatsApp offers! (This is definitely not the only WhatsApp free image I could find online.)</figcaption></figure></div><h3><strong>19 billion dollars</strong></h3><p>The acquisition was a true Cinderella story. WhatsApp&#8217;s founders, Jan Koum and Brian Acton, had applied to be engineers at Facebook in 2007 ("We're part of the Facebook reject club," they later <a href="https://www.forbes.com/sites/parmyolson/2014/02/19/exclusive-inside-story-how-jan-koum-built-whatsapp-into-facebooks-new-19-billion-baby/?sh=2ac8ee42fa19">said</a>), only to be acquired by Facebook seven years later for the largest acquisition of a venture-capital-backed company in history.</p><p>The 19 billion dollar price tag seemed crazy at the time. It came out that Google had also <a href="https://siliconangle.com/2014/02/21/google-offered-more-than-19b-for-whatsapp-heres-why-it-got-turned-down/">sought to buy</a> WhatsApp, which certainly drove up the price. Most significant, though, was how badly Facebook wanted to continue its breakneck speed of growth in developing countries, and how much it was willing to pay to gain entry to countries where WhatsApp was already quite popular. WhatsApp had 450 million monthly active users in countries that Facebook didn't, and Facebook wanted to understand these users: specifically their behavior, cell phone characteristics, and feature requests.</p><p>From an ethos standpoint, you may be wondering what exactly the WhatsApp founders gained from being owned by Facebook &#8211; besides the obvious 19 billion things &#8211; since Facebook&#8217;s business strategy was always surveillance-at-all-costs, and WhatsApp doesn&#8217;t even store your name. Koum, who grew up in the USSR during the 1980s, famously <a href="https://web.archive.org/web/20181223152552/http://blog.whatsapp.com/529/Setting-the-record-straight">wrote</a> during the acquisition, &#8220;Respect for your privacy is coded into our DNA, and we built WhatsApp around the goal of knowing as little about you as possible: You don't have to give us your name and we don't ask for your email address. We don&#8217;t know your birthday.&#8221; (To this day, you don&#8217;t need a name to sign up for WhatsApp.)</p><p>But Koum and Acton seemingly chose to ignore the obvious: that Facebook was going to get these users' data eventually.</p><h3>Enter: WhatsApp&#8217;s Encrypted conversations</h3><p>When Facebook bought WhatsApp, WhatsApp was in the middle of a multi-year effort to build end-to-end encryption, something its users frequently requested, and something the founders cared deeply about. (Plus, as we&#8217;ve discussed, competitor apps like iMessage and Telegram already offered encryption.) Finally, in 2016, WhatsApp <a href="https://web.archive.org/web/20190107153845/https://blog.whatsapp.com/index.php/page/3">launched</a> end-to-end encryption, which meant that all WhatsApp conversations were disguised into machine-readable text that people like the NSA wouldn&#8217;t be able to read (without a warrant). Acton <a href="https://web.archive.org/web/20170826072315mp_/https://www.wired.com/2016/04/forget-apple-vs-fbi-whatsapp-just-switched-encryption-billion-people/">told</a> Wired at the time, &#8220;I don&#8217;t really want to be in the business of observing conversations.&#8221;</p><p><em>Wait, doesn&#8217;t total freedom of speech online often breed extremist, criminal, or outright gross thought spaces?</em> you might be thinking.</p><p>Well, yes&#8230; good point&#8230; but we&#8217;re talking about 2016, back when popular opinion was SUPER on the side of encryption. This was right after the Edward Snowden leaks, and people associated encryption with journalists and whistleblowers (like Snowden), not yet drug lords and arms dealers.</p><p>Zuckerburg, unsurprisingly, was <a href="https://web.archive.org/web/20190320081947/https://www.forbes.com/sites/parmyolson/2018/09/26/exclusive-whatsapp-cofounder-brian-acton-gives-the-inside-story-on-deletefacebook-and-why-he-left-850-million-behind/">supportive</a> of end-to-end encryption throughout the acquisition. He even added a feature called "secret conversations" to Facebook Messenger that used the same encryption protocol as WhatsApp. And of course he was supportive: encryption kept Facebook free of responsibility for illegal activity conducted on their apps. If Facebook couldn't read the messages that were sent by users, they couldn't be held liable. (Even back then, Facebook <a href="https://archive.nytimes.com/bits.blogs.nytimes.com/2015/03/16/facebook-explains-what-it-bans-and-why/">struggled</a> with ferreting out revenge porn and other illegal content.)</p><p>End-to-end encryption for messages is still used in WhatsApp to this day, and has certainly helped WhatsApp continue to grow. But that doesn&#8217;t mean that all of your WhatsApp data is safe, as we'll soon see&#8230;</p><h3>The new privacy policy</h3><p>In late 2016, the inevitable happened. WhatsApp changed its terms and privacy policy so that Facebook could make ads more personalized. As the founders explained in their blog (was a gun pointed at them when they wrote this?), &#8220;by coordinating more with Facebook, we'll be able to do things like track basic metrics about how often people use our services and better fight spam on WhatsApp. And by connecting your phone number with Facebook's systems, Facebook can offer better friend suggestions and show you more relevant ads if you have an account with them.&#8221; From this point onwards, WhatsApp data would be an input to Facebook&#8217;s ad targeting.</p><p>Koum and Acton fought this change tooth and nail, but eventually conceded defeat. After the privacy policy was announced, they left Facebook, famously leaving behind $400 and $180 million, respectively, in unvested stock. To his credit, Acton admitted that he'd chosen money over his privacy ethos, <a href="https://web.archive.org/web/20190320081947/https://www.forbes.com/sites/parmyolson/2018/09/26/exclusive-whatsapp-cofounder-brian-acton-gives-the-inside-story-on-deletefacebook-and-why-he-left-850-million-behind/">saying</a> &#8220;I am a sellout. I acknowledge that.&#8221;</p><h3>Enter: Telegram</h3><p>Telegram has been around since 2013, and in many ways it&#8217;s a clone of WhatsApp if WhatsApp had never been acquired by Facebook. Telegram&#8217;s founders, like WhatsApp&#8217;s, were born in the Soviet Union and built the app to protect people&#8217;s data from authoritarian governments. Telegram even uses a green color scheme that looks like WhatsApp, including green double-check-mark read receipts.</p><p>But Telegram is a not-for-profit company. It is based in the British Virgin Islands. It doesn&#8217;t want to get acquired by anybody, and it even stores all its data in <a href="https://techcrunch.com/2013/10/27/meet-telegram-a-secure-messaging-app-from-the-founders-of-vk-russias-largest-social-network/">offshore servers</a> to avoid government data requests.</p><p>Because Telegram was founded four years after WhatsApp, it was always second fiddle. Then 2021 happened.</p><h3>The Privacy Policy Notification</h3><p>In January 2021, Facebook&#8217;s parent company, Meta, launched WhatsApp Business, a new service that would allow users to message directly with businesses through WhatsApp. Meta sent out an <a href="https://faq.whatsapp.com/595724415641642/?locale=en_US">official announcement</a> that laid out WhatsApp's existing privacy policy &#8211; which had been in effect since 2016 &#8211; along with a caveat that businesses would now be able to see "what you're saying" and use it for their own "marketing purposes":</p><blockquote><p>Some large businesses need to use hosting services to manage their communication. Which is why we&#8217;re giving businesses the option to use secure hosting services from Meta to manage WhatsApp chats with their customers, answer questions, and send helpful information like purchase receipts. But whether you communicate with a business by phone, email, or WhatsApp, it can see what you&#8217;re saying and may use that information for its own marketing purposes, which may include advertising on Meta.</p></blockquote><p>In addition to the confusing wording about businesses having access to your message contents, the announcement didn't explicitly explain what was changing. It only explained what Meta <em>wouldn&#8217;t </em>collect, and didn&#8217;t explain what Meta <em>would</em> collect, so users probably assumed that anything not mentioned in the policy would be collected. (Events like Cambridge Analytica hadn't exactly built trust).</p><p>After the announcement, users flocked to competitor apps like Telegram. A week after WhatsApp sent out the privacy change notification, Telegram <a href="https://www.nytimes.com/2021/01/13/technology/telegram-signal-apps-big-tech.html">added</a> more than 25 million users over the previous three days, pushing it to over 500 million users.</p><p>Telegram officially <a href="https://in.mashable.com/tech/20166/telegram-tops-the-list-of-most-downloaded-apps-in-the-world-report">became</a> the most downloaded app in the world for January 2021, officially dethroning WhatsApp.</p><h3>Can Telegram maintain its hold over WhatsApp?</h3><p>But not everyone cares about security. People are turning 13 and getting new phones, and they&#8217;re installing the apps that their parents use. While Telegram was the most popular Android messaging app of 2021, WhatsApp <a href="https://www.similarweb.com/blog/research/market-research/worldwide-messaging-apps/">regained first place</a> in 2022, according to Meltwater's <a href="https://datareportal.com/reports/digital-2023-global-overview-report">2023 Digital Report</a>:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ukSF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ukSF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png 424w, https://substackcdn.com/image/fetch/$s_!ukSF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png 848w, https://substackcdn.com/image/fetch/$s_!ukSF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png 1272w, https://substackcdn.com/image/fetch/$s_!ukSF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ukSF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png" width="801" height="453" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:453,&quot;width&quot;:801,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!ukSF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png 424w, https://substackcdn.com/image/fetch/$s_!ukSF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png 848w, https://substackcdn.com/image/fetch/$s_!ukSF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png 1272w, https://substackcdn.com/image/fetch/$s_!ukSF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ce1918-abe0-4398-a4d7-23592f5359fb_801x453.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Looks like 2021&#8217;s privacy changes are a distant memory, with WhatsApp back in the #1 spot on the "Favorite social media platforms" list.&#8204; &#8204;</figcaption></figure></div><p>WhatsApp might very well keep its #1 spot for the foreseeable future (until TikTok adds better messaging, hah). But we saw something interesting happen in 2021: that WhatsApp sacrificed a significant corner of its market by revealing its lenient stance on privacy. To this day, Telegram is the most popular messaging app in <a href="https://www.similarweb.com/blog/research/market-research/worldwide-messaging-apps/">ten countries</a>, including Cambodia and Iraq, the majority of which have authoritarian governments. So Telegram hasn't completely lost its market hold.</p><p>It will be interesting to see if WhatsApp and Telegram diverge further in their privacy feature set over time, and how users respond to these changes.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[From the NY Times to Netflix: a Brief History of Paywalls]]></title><description><![CDATA[This post was originally published on February 12, 2023.]]></description><link>https://www.lydiaoncybersecurity.com/p/a-brief-history-of-paywalls</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/a-brief-history-of-paywalls</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:43:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QJf1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>This post was originally published on February 12, 2023.</em> </p><p>As a fancy technologist who enjoys looking at celebrity real estate, my three favorite websites are <a href="https://www.wired.com/">wired</a>, <a href="https://www.architecturaldigest.com/">architectural digest</a>, and <a href="https://www.curbed.com">curbed</a>, and all of them allow me to read a few articles per month before a paywall goes up. Occasionally, I send article links from these sites to my nearest and dearest, and often get the same response: &#8220;I can&#8217;t see the article, it&#8217;s behind a paywall.&#8221;</p><p><em>You must be joking me!!</em> I scream internally. <em>College graduation rates are the highest they&#8217;ve ever been and no one knows how to get around a paywall.</em> (I&#8217;m looking at you, mom.)</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>That was mean, sorry.</p><p>It&#8217;s unfair of me to complain that people don&#8217;t know how to get around paywalls, when paywalls are so annoying (and expensive) in the first place. I find it crazy that wired.com expects my mom to also buy a subscription to wired.com just to read the articles I send her. I get annoyed whenever I think about paywalls, because they're preventing us from sharing information.</p><p>On the other hand, I&#8217;m a realist and I know that content can&#8217;t be free. Someone has to pay for fun articles, whether it&#8217;s readers, advertisers, or benevolent billionaires (oh wait those don&#8217;t exist). I&#8217;ve watched the tug of war between content creators and paywall evaders for the past ~10 years, and I&#8217;ve noticed a few interesting things.</p><p><strong>Cookies</strong></p><p>First, I should explain what cookies are, and how websites use them for paywalls.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QJf1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QJf1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png 424w, https://substackcdn.com/image/fetch/$s_!QJf1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png 848w, https://substackcdn.com/image/fetch/$s_!QJf1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png 1272w, https://substackcdn.com/image/fetch/$s_!QJf1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QJf1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png" width="353" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:353,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!QJf1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png 424w, https://substackcdn.com/image/fetch/$s_!QJf1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png 848w, https://substackcdn.com/image/fetch/$s_!QJf1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png 1272w, https://substackcdn.com/image/fetch/$s_!QJf1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80acdd11-3aa4-4118-9ffa-41cafd43f38b_353x500.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">No one said getting around paywalls was painless.</figcaption></figure></div><p>Let&#8217;s say you visit <a href="https://www.wired.com/">wired.com</a>, and <a href="https://www.wired.com/">wired.com</a> only allows you to view one article per month before you have to sign up for a subscription. So when you visit the site in a Chrome browser, <a href="https://www.wired.com/">wired.com</a> will add a cookie in that browser saying you visited their site. Next time you visit, <em>tada!</em>, you&#8217;ll see a &#8220;You&#8217;ve hit your monthly limit on free articles, please subscribe now&#8221; popup. But &#8211; excitingly for those of us who spend way too much time avoiding paywalls &#8211; if you visit <a href="https://www.wired.com/">wired.com</a> in a Chrome Incognito browser, the cookie from your non-Incognito browser won&#8217;t carry over, allowing you to view one article anew. (The same will happen if you switch to Firefox, or to Firefox Private Browser, or to Internet Explorer, and so on and so forth.) There&#8217;s also a somewhat harder solution, which is to delete the cookies manually in the &#8220;inspect&#8221; page of any browser:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a7Ca!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a7Ca!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png 424w, https://substackcdn.com/image/fetch/$s_!a7Ca!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png 848w, https://substackcdn.com/image/fetch/$s_!a7Ca!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png 1272w, https://substackcdn.com/image/fetch/$s_!a7Ca!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a7Ca!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png" width="1456" height="739" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:739,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!a7Ca!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png 424w, https://substackcdn.com/image/fetch/$s_!a7Ca!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png 848w, https://substackcdn.com/image/fetch/$s_!a7Ca!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png 1272w, https://substackcdn.com/image/fetch/$s_!a7Ca!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7534a0a-5a16-4494-8a02-ab7cb574eba9_1600x812.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There are also other, more complicated, workarounds for avoiding cookie-based paywalls, like <a href="https://www.reddit.com/r/uBlockOrigin/comments/vufe4n/how_to_bypass_nyts_timesmachine_paywall/?ref=lydia-on-cybersecurity">using</a> the Wayback Time Machine, or the Reader Mode browser <a href="https://readermode.io/?ref=producthunt">extension</a>, or others that you can find online.</p><h3><strong>Paywall History Exhibit A: The New York Times</strong></h3><p>Remember 2011, when you could delete everything after the &#8220;&amp;gwh&#8221; in a <a href="https://www.nytimes.com/">nytimes.com</a> url, and the paywall would just disappear? Those were the good days.</p><p>By now, the New York Times has caught on to my &#8212; and everyone else&#8217;s &#8212; paywall evasion schemes, so <a href="https://www.niemanlab.org/2019/11/newsonomics-ceo-mark-thompson-on-offering-more-and-more-new-york-times-and-charging-more-for-it/">as of</a> 2019, they&#8217;ve stopped allowing ANY free visits to their site. You visit, you subscribe, you read. So in late 2019, I grudgingly signed up for a digital subscription to the Times. And so did the rest of the world.</p><p>In the first half of 2020 alone, the Times added one million users:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1YBL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1YBL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1YBL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1YBL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1YBL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1YBL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg" width="1200" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!1YBL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1YBL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1YBL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1YBL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140be5b0-1258-4b75-86e7-a928f276e7ec_1200x1200.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I&#8217;d bet that <em>The Boston Globe</em>, the <em>Los Angeles Times</em>, and everyone else are likely to copy the no-free-articles system in the next few years (unfortunately for me).</p><h4><strong>If cookies weren&#8217;t Big Brother enough for you, don&#8217;t worry, there&#8217;s always IP addresses</strong></h4><p>Okay cool, so we&#8217;ve seen how companies can work around the cookies-don&#8217;t-really-work problem.</p><p>Streaming services have a slightly different problem. They&#8217;ve already done what the Times has done, requiring you to subscribe before you can view their content. But human beings are conniving things, and they quickly figured out a low-tech way to get around having to pay: password sharing.</p><p>I&#8217;m sure the Times has suffered from lots of password sharing over the years, but they  don&#8217;t have the hundreds-of-millions-of-dollars in engineering resources to address it. Netflix, on the other hand, has an unlimited R&amp;D budget, and they recently caught on to how much money they&#8217;re losing to password sharing, <a href="https://s22.q4cdn.com/959853165/files/doc_financials/2022/q1/FINAL-Q1-22-Shareholder-Letter.pdf">saying</a> in their 2022 Q1 that &#8220;In addition to our 222m paying households, we estimate that Netflix is being shared with over 100m additional households.&#8221; 100 million households is a lot of lost money; if we assume that Netflix makes around $11 per customer, that means they&#8217;re losing out on $1.1 billion per month.</p><p>So Netflix decided to crack down on password sharing, and they decided to do it using the concept of "households". Households cannot share accounts, and by <a href="https://help.netflix.com/en/node/124925#:~:text=A%20Netflix%20account%20is%20for,more%20about%20sharing%20your%20Netflix">their</a> definition, one IP address constitutes a &#8220;household.&#8221; </p><p>Just last month, Netflix added a footnote to their subscription plan page that explains &#8220;Only people who live with you may use your account.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gk2H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gk2H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png 424w, https://substackcdn.com/image/fetch/$s_!Gk2H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png 848w, https://substackcdn.com/image/fetch/$s_!Gk2H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png 1272w, https://substackcdn.com/image/fetch/$s_!Gk2H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gk2H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png" width="780" height="835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:780,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Gk2H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png 424w, https://substackcdn.com/image/fetch/$s_!Gk2H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png 848w, https://substackcdn.com/image/fetch/$s_!Gk2H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png 1272w, https://substackcdn.com/image/fetch/$s_!Gk2H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7da3184d-3504-4d91-90e2-0836bc088c1c_780x835.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ominous&#8230;</figcaption></figure></div><h4><strong>Too lazy to fake my IP address</strong></h4><p>Now, it should be stated that it&#8217;s possible to fake your IP &#8211; one popular option is to use a VPN, for example &#8211;but Netflix has started <a href="https://www.pcmag.com/news/netflix-vpn-crackdown-ensnares-those-who-arent-even-using-vpns">cracking down</a> on VPNs, and I'm too lazy to play cat and mouse with Netflix, especially when their cheapest subscription is only $6.99/month. Cheaper than Hulu and HBOMax!</p><p>So once again, I&#8217;ve given up on playing cat and mouse with large corporations who want me to upgrade from their freemium plan.</p><h3><strong>In conclusion</strong></h3><p>Why do we live in a world where it's impossible to share content online? Why can&#8217;t my Times subscription allow me access to the Post, or my Netflix subscription allow me to watch a few episodes of HBO Max? Instead, internet content has only bifurcated over time, with TV companies creating their own online subscription services to compete with Netflix, and more and more news websites adding paywalls of their own. In the pre-internet age, we had to share articles by clipping them and sending them via snail mail; it feels like with all the technological innovation we&#8217;ve seen in the past decade, we&#8217;re right back where we were in the first place.</p><h1>FAQ</h1><h3>What are the ethical implications of using methods like cookie deletion or IP address manipulation to bypass paywalls?</h3><p>Ethical implications of circumventing paywalls involve considerations of fairness and sustainability in content creation. While it may seem innocuous to delete cookies or use VPNs to access free content, these actions undermine the financial model that supports journalism and creative industries. Content creators rely on subscriptions and ad revenue to fund their work, and bypassing paywalls reduces their ability to sustain quality journalism and entertainment. Moreover, such actions may violate terms of service agreements, potentially leading to legal consequences. Therefore, while frustrations with paywalls are understandable, ethical users often opt to support content creators through legitimate subscriptions or other authorized means.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><h3><br>How do paywall strategies differ between different types of content providers, such as news websites versus streaming services like Netflix?</h3><p>Paywall strategies vary significantly between news websites and streaming services like Netflix, reflecting the distinct nature of their content and revenue models. News outlets often employ metered paywalls, allowing limited free access before requiring a subscription. This approach aims to balance audience reach with revenue generation from dedicated readers. In contrast, streaming services typically offer no free content, relying solely on subscriptions for access. Strategies also differ in how they combat password sharing; while Netflix restricts account sharing based on IP addresses, news sites face different challenges with user authentication. These differences highlight how paywall strategies are tailored to the specific needs and dynamics of each industry.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><h3><br>What are the broader implications of the trend towards exclusive content and paywalls on accessibility to information and cultural exchange?</h3><p>The trend towards exclusive content and paywalls raises concerns about the accessibility and democratization of information and entertainment. As more publishers and platforms adopt paywalls and exclusive content models, access to diverse viewpoints and cultural content may become increasingly restricted based on economic means. This trend could exacerbate digital divides, limiting access to crucial information and cultural exchange among different socioeconomic groups. Moreover, the fragmentation of content across multiple subscription services may lead to consumer frustration and higher costs, potentially reshaping how individuals consume and share digital content. Addressing these broader implications requires balancing the financial sustainability of content creation with ensuring equitable access to information and cultural expression in the digital age.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>This entire section is an SEO <a href="https://www.linkedin.com/posts/stevenlmacdonald_using-chatgpt-i-updated-21-blog-posts-on-activity-7167805610892247040-BIgA/?utm_source=share&amp;utm_medium=member_ios">experiment</a> I&#8217;m running.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>See footnote 1.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>See footnote 1 (again).</p></div></div>]]></content:encoded></item><item><title><![CDATA[Yes, the FBI can use your Google search records to convict you. And so can Google.]]></title><description><![CDATA[Until recently, I didn&#8217;t realize that police could use my Google search history to convict me of a crime.]]></description><link>https://www.lydiaoncybersecurity.com/p/yes-the-fbi-can-use-your-google-search</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/yes-the-fbi-can-use-your-google-search</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:33:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!11dN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!11dN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!11dN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg 424w, https://substackcdn.com/image/fetch/$s_!11dN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg 848w, https://substackcdn.com/image/fetch/$s_!11dN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!11dN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!11dN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg" width="1456" height="910" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:910,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!11dN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg 424w, https://substackcdn.com/image/fetch/$s_!11dN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg 848w, https://substackcdn.com/image/fetch/$s_!11dN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!11dN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F723b8f4a-163a-4eec-9d5a-015be03f28e6_2000x1250.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">FBI Headquarters in Washington, D.C. Really beautiful on the outside. Apparently kind of gnarly on the inside.</figcaption></figure></div><p>Until recently, I didn&#8217;t realize that police could use my Google search history to convict me of a crime. I also didn&#8217;t realize that Google itself can use my search history to sue me. This post is about my slow wake up call to the Big Brother world of Big Data.</p><p>As a United States citizen, I know how search warrants work: if the police request a search warrant, and if the court system approves it, the police can enter my home and search through my personal belongings. But in terms of my internet browsing history, I've always assumed that the data I create is so vast that it was untraceable. Really, who&#8217;s going to record the 500 celebrity gossip pages I visit per day? (And which government agency actually cares enough to store that information?) I know, call me naive, but logging onto a computer and visiting different pages of the internet felt sacred to me.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Alas, my idealism was misplaced. The government can access people&#8217;s search histories any time. Don&#8217;t believe me? Look no further than the 2012 LinkedIn hack, the hack that taught me how far the FBI's tendrils extend.</p><h3>How the FBI finds hackers using search warrants</h3><p>If you, like me, got a password reset <a href="https://blog.linkedin.com/2012/06/06/linkedin-member-passwords-compromised">notice</a> from LinkedIn circa 2012, then you may already know about the LinkedIn hack of 2012. In it, a Russian hacker named Yevgeniy Nikulin stole 6.5 million LinkedIn users&#8217; email addresses, usernames, and passwords, and then subsequently used those credentials to hack into other companies like Dropbox (from whom he stole <a href="https://darknetdiaries.com/transcript/86/">20 million</a> users' data) and Formspring (from whom he stole 420,000 users' data).</p><p>But no matter how many databases Nikulin hacked, he was never going to have as much data about LinkedIn users as the FBI had about him. After the hack, the FBI spent four years collecting Nikulin's online data so that they could <a href="https://regmedia.co.uk/2020/04/28/russian-hacker-case.pdf">charge</a> him for identity theft and computer intrusion. First, the FBI traced the original hack to the email address r00talka@gmail.com. Next, they asked Google for the search history associated with r00talka@gmail.com, and Google gave them everything, including google searches for a dentist near Moscow. And it wasn't just Google that complied with the warrant. Microsoft, Vimeo, and Automattic (the parent company of Wordpress) also complied.</p><h3>Enter: The Fourth Amendment</h3><p>In some ways, I&#8217;m okay with the government being able to retrieve information from Google in order to solve crimes. After all, the Fourth Amendment protects U.S. citizens unreasonable searches and seizures by the government. If the FBI wants someone's data, they probably have a good reason, right?</p><p>But I&#8217;m beginning to realize just how often government search warrants stretch the definition of "reasonable." Just a few months ago, police in Nebraska <a href="https://techcrunch.com/2022/08/09/facebook-helps-cops-prosecute-17-year-old-for-abortion/">prosecuted</a> a 17-year-old girl for getting an abortion, all using data acquired from Facebook through search warrants. And how did they get a search warrant for the girl&#8217;s Facebook message history? They told Facebook that they had evidence that she had burned and buried the baby (because they found the fetus discarded in a bag). <br><br>However, once the police read the Facebook messages, they realized that she had aborted the baby, not burned it, which changed the investigation from a murder investigation to an abortion investigation.</p><p>I am disturbed by Facebook's willingness to hand over the girl's records so readily. In fact, Facebook has stated publicly to the <em>New York Times</em> that, in the first half of 2020, they complied with <a href="https://www.nytimes.com/2021/06/14/technology/personal-data-apple-google-facebook.html">89%</a> of search warrants received. By comparison, Google complied with 83%, and Apple only complied with 43%. </p><h3>Tech companies also use their records to sue employees</h3><p>Even more disturbing than tech companies handing over records to the government so readily is that they also use these records to sue their own employees.</p><p>In 2017, Google sued two top self-driving car engineers, who had quit Google and started working at Uber, for stealing Google&#8217;s self-driving car research. In the lawsuit, Google claimed that one of these engineers had &#8211; prior to leaving Google &#8211; <a href="https://www.vox.com/2017/10/3/16411184/uber-alphabet-waymo-self-driving-lawsuit-anthony-levandowski-timeline">googled</a> things like "how to permanently delete google drive files from my computer." </p><p>If Google deems it necessary to publicize its employees' search history (like if 245 million dollars&#8217; worth of AI car research is on the line), they will.</p><p>And for those of you who were reassured by Google&#8217;s <a href="https://blog.google/technology/safety-security/keeping-private-information-private/">new security policy</a> that allows users to automatically delete all of their Google data &#8211; including search history &#8211; every three months, listen up. That policy only applies to Google search history, not Gmail emails themselves, which are still stored indefinitely, and which Google clearly hands over fairly freely. (See the aforementioned 83%.)</p><h3>Sleep tight!</h3><p>My point is, for those of you &#8211; like me &#8211; who long thought that your personal data is sitting pretty in a data center, not being used by anyone, or only being used for ad targeting purposes, just know that it can be used by law enforcement at the drop of a hat. And, if you're a tech worker like me, potentially by your future employer.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lydia&#8217;s Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Coming soon]]></title><description><![CDATA[This is Lydia&#8217;s Substack.]]></description><link>https://www.lydiaoncybersecurity.com/p/coming-soon</link><guid isPermaLink="false">https://www.lydiaoncybersecurity.com/p/coming-soon</guid><dc:creator><![CDATA[Lydia Stepanek]]></dc:creator><pubDate>Mon, 17 Jun 2024 14:31:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HiSn!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7829d887-468a-496b-9fb2-585d89161211_1123x1123.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is Lydia&#8217;s Substack.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.lydiaoncybersecurity.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.lydiaoncybersecurity.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item></channel></rss>