Who is Nicole really? Who got messages from Nicole? Who is behind the messages? What is the resolution of Nicole’s profile images? Do I really have to be a racist to join her server? This comment section’s purpose is to collect all that information.

  • j4k3@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    1 day ago

    First time for me happened last night. Posted it here already, but for the sake of compiling information I’ll repeat it here. I run a DNS whitelist firewall and logged a blocked address https://cdn-discuss-online.s3.us-east-005.backblazeb2.com/ upon opening Lemmy with the message notification. LW cached and served the image for me when the connection to this link was unavailable. I cannot say anything further about what is happening in this connection. I can only confirm that it exists. The moment I saw the message I checked my logs and am certain that this is correlated.

      • j4k3@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        16 hours ago
        I'm no expert. In life I am very much a knockoff swiss army knife. I can technically do a lot, but I am the shittiest pair of scissors ever made.

        I dislike how obtuse networking stuff can seem. I run a whitelist firewall because it is the easy way to control exactly what I connect to my computer. I have written bad code and will continue to do so. I download sketchy stuff some times, but it cannot escape. Telemetry stuff all gets blocked too.

        It is a pain in the ass to initially setup and maintain a DNS whitelist. It must be on a third party device or you’ll need to be super meticulous about how your system is setup. Lots of packages can and do try to bypass a local firewall on the same device they run on. I have to log in and add addresses and ports manually for everything I visit. Still, I can let an AI write code I barely understand and run it knowing it cannot escape. Scripting and configuring your own whitelist setup on a device is not fun. Once option that is reasonable and fairly easy is PC WRT. That is a small business commercial version of OpenWRT. It is just an Asian guy in Texas, but his stuff works pretty well and he maintains it long term. I modify all of my routers to add an external USB to TTL serial module to the port on the PCB. For most routers, the internal UART serial port gives access to the bootloader and OS in ways that are nearly impossible to hide what is happening. I’ve screwed around with PC WRT stuff a good bit and it seems legit. If you are really concerned about aquariums for sharks, this will get you an interface for Open VPN, all the adblock options, and most add on features people configure in OpenWRT.

        Ultimately, such a DNS filter is your digital front door to your home. If you run adblock, someone else is closing your front door to old familiar bad actors only. With a white list, I’m only opening my door to those I wish to enter.

        It is pretty clear that Nicole is not what they appear to present. It is fishing. If they were relevant they would not spam. The main litmus test for anyone is if they have a diverse and mostly positive post and comment history. Anyone that has a monolithic presence in any one space is fake or potentially dangerous.

      • Ada@lemmy.blahaj.zone
        link
        fedilink
        arrow-up
        2
        ·
        16 hours ago

        In the short term, you can use a client that doesn’t load inline images in DMs. Our tesseract front end is one such client if you’re using a browser.

  • Dem Bosain@midwest.social
    link
    fedilink
    English
    arrow-up
    9
    ·
    1 day ago

    Has anybody contacted George Brown University, particularly the Dean of the health sciences department? If “Nicole” actually exists, and someone is using her images without her knowledge, this seems like the quickest way to let someone know it’s happening.

  • JackbyDev@programming.dev
    link
    fedilink
    English
    arrow-up
    33
    arrow-down
    3
    ·
    28 days ago

    Hey y’all, I know this theory might be a stretch, but remember that this could be someone using someone’s name/face without their permission to harass them or frame them or something. Please just keep that in mind as you dig.

    • Ilovethebomb@lemm.ee
      link
      fedilink
      arrow-up
      9
      arrow-down
      2
      ·
      28 days ago

      It probably is, it looks like a frame grab from a webcam video.

      With what appears to be a bong in shot. I can’t imagine someone using such an unflattering photo if they were using their own face.

      • cool@lemmings.world
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        1
        ·
        edit-2
        26 days ago

        Eh, it’s more than likely a pig-butchering scam.

        The groups that do these are rather unsophisticated and mostly don’t speak english. It would make sense that their poor internet connections only have low quality photos and this is likely just one of many scams with equally-bad photos.

        • Ilovethebomb@lemm.ee
          link
          fedilink
          arrow-up
          6
          arrow-down
          2
          ·
          26 days ago

          A decent quality photo isn’t that big, even over dialup you can send a better one.

          • *Walter SPIEGEL ☑️@infosec.pub
            link
            fedilink
            arrow-up
            3
            ·
            12 days ago

            For a pig butchering scam, a bad photo might actually make a lot of sense. If it looks like it might be a scam, only the most naive people will answer. That way, they can filter out anyone not in their target audience.

            • Ilovethebomb@lemm.ee
              link
              fedilink
              arrow-up
              3
              arrow-down
              1
              ·
              12 days ago

              Yeah, they supposedly make deliberate spelling mistakes as well, to filter out the smart ones.

  • injuredcat@discuss.tchncs.de
    link
    fedilink
    arrow-up
    29
    ·
    15 days ago

    I felt I need to contribute something to the “massive” quest to uncover more about Nicole.

    I went through all my messages (from my main account, this one is a burner) and found an interesting name that kept coming up, from a couple of messages that were about 2 months old, “beyorkisan”. This was a PeerTube username she included, which does not exist anymore. But I scoured the internet and found another interesting PeerTube instance which is still running and on which she has uploaded a video.

    Screenshot from PeerTube video titled Chilling at work .
    Federated link on hitchtube.fr, if the site is not loading. Also there is no audio

    Also, there was another live-stream.
    Just hanging out - Dalek Zone

    Going through the video and live-stream comments, seems like she had quite a following and from there I deduced a couple of things,

    • She was doing some sort of engagement on a chatting website called stumblechat.com.
    • She liked Krashboyz Bordel Krew Live Show 24/7
    • @lnxtx@feddit.nl comments in this thread might be correct, she might indeed be living in Canada.
    • If she is really the one who was doing all that, then she was active on PeerTube, federating on Fediverse and thus making herself a Fediverse Chick (pun intended).

    Also there seems to be a twitch account named beyorkisan with her picture. Might be hers.

    • driving_crooner@lemmy.eco.br
      link
      fedilink
      English
      arrow-up
      12
      ·
      28 days ago

      I think is a funny meme and everything but I feel uncomfortable with people sharing her pictures. I doubt the real person on the pictures gave concent to this.

  • Lvxferre [he/him]@mander.xyz
    link
    fedilink
    arrow-up
    7
    ·
    24 days ago

    Got Nicole’d twice, last time ~a hour ago.

    My guess is that the scammer is simply hitting random Fediverse people, with no meaningful pattern besides “some post/comment activity”.

  • lnxtx (xe/xem/xyr)@feddit.nl
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    28 days ago

    Topic from the Matrix room:

    I work at ***, *** ** **, Woodbridge, ON L4L 1A7, Canada. Come say hi sometime!
    I work in the *** section, so just ask for Nicole!

    Does somebody live nearby?

  • Kraiden@kbin.earth
    link
    fedilink
    arrow-up
    7
    ·
    17 days ago

    Just posting here as well to make sure it’s documented.

    I just got Nicole Classic™ without crypto links. I’m beginning to suspect there are Niclones out there as well

    • Fungah@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      1 day ago

      I got a message from the username but without an image.

      I live in Toronto.

      Not sure there’s much else I’d be willing to divulge. I’d bet that this whole thing is somebody trying to harass this poor woman though.

      • CrayonRosary@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        1 day ago

        without an image

        I thought so, too, but I switched to “Private Browsing”—which disables most of my extension—and opened my inbox there, and there was the image. Went I went back to my normal browser where the tab was still open, there was the image, too. So it just seemed like it took a very long time to load.

        The image URL was https://quokk.au/pictrs... which is another Lemmy instance, and the message was from bogymanstout(at)quokk.au. So the image wasn’t hosted externally to the Lemmiverse, so it can’t really be a deanonymization attack like some people were theorizing. There’s nothing else in the message. No tracking pixels or anything.

        On the other hand, it’s a very small instance with only 8 communities. The largest of which, world news, has almost 1,000 subscribers. Not impossible to be a fake instance designed for spying, but seems unlikely.

        Update:

        I just opened my inbox in a normal window again, and Firefox simply refuses to load that image in my inbox. I don’t know why. It loads fine if I open that URL in a new tab.

        • Fungah@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          23 hours ago

          I recently read an article that broke down a webp vulnerability that was being actively exploited. Which of course I can’t find right now.

          If I had access to my PC at the moment I’d pop open the image itself and see if I could find any odd strings anywhere inside of it. I’m sure someone better at this stuff than I could take a deeper dive into the image itself if so inclined.

          • CrayonRosary@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            edit-2
            23 hours ago

            The only webp exploits for which I can find articles are from 2023. Some new articles, but still about the 2023 exploit. Both in Chrome and in iOS.

            The first step would be to see if the “PNG” file is actually a webp file. To see if what you’re saying is plausible.

            However, if there were a new, unpatched webp exploit, there’s zero reason to spam users with DMs when you can just post the image in popular communities. It could be any image and there’d be no reason to keep sending images pretending to be a girl looking for friends.

            It’s the links in the image which are important to the attacker. Originally they weren’t in the image and it was easy for admins to filter them out, so the attacker took the time to embed them in the image. This points to traditional catfishing and pig butchering as the attack.

            Then again they could be playing 4D chess and masquerading the real attack as simple catfishing.

            Update

            Oh. My. God.

            Byte Ox000cbb7f contains the word “Cum”!

            They’re trying to poison our minds!

            It’s just a normal PNG file.

            • Fungah@lemmy.world
              link
              fedilink
              arrow-up
              2
              ·
              18 hours ago

              Thanks for the insight.

              The article I read was recent - within the last week or so. Maddening that I can’t find it again. Should have bookmarked it.

              Anyway, that all scans. Figured it was a possibility even if it wasn’t likely.

    • stoy@lemmy.zip
      link
      fedilink
      arrow-up
      1
      ·
      7 days ago

      I believe I have got three messages from Nicole, two in the last few weeks, one just this morning.

      • Peter_Arbeitslos@feddit.orgOP
        link
        fedilink
        arrow-up
        3
        ·
        28 days ago

        Of course, but people who aren’t active seem to get fewer spam. But they might just don’t post it, because they are inactive.

        • Agosagror@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          13 days ago

          Yeah I only started getting them when I posted/commented

          I thought it was because they are reading comments and posts that people share and spamming those people.

          Had something similar on reddit a long time ago, got added to a private subreddit because they saw me comment in a community

    • DoomProphet@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      24 days ago

      Received it after leaving a comment in gonewild. Prime hunting grounds for lonely guys I guess. Was my second comment ever and my first was way earlier therefore I’m sure that it was the gonewild comment that triggered the bot to send me the message.

      • Fungah@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        1 day ago

        I comment on literally anything and I’ve left some comments on porn posts so that could be it.

    • dutchkimble@lemy.lol
      link
      fedilink
      English
      arrow-up
      1
      ·
      27 days ago

      I got one, and I saw it being referenced somewhere else on some post, so I decided to search Nicole and found this community and your message then. Any idea what this means? What’s going on haha

    • rarWars@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      1
      ·
      28 days ago

      I only got one after I mentioned somewhere that I hadn’t gotten one yet. It wasn’t immediately after, but close enough to make me suspicious.

  • Ilovethebomb@lemm.ee
    link
    fedilink
    arrow-up
    4
    ·
    29 days ago

    I’ve had three, all identical messages, all from different usernames and accounts. I haven’t followed any of the links.