<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Digital Safety Series]]></title><description><![CDATA[Learn about digital safety & technology]]></description><link>https://www.yania.me</link><image><url>https://www.yania.me/img/substack.png</url><title>Digital Safety Series</title><link>https://www.yania.me</link></image><generator>Substack</generator><lastBuildDate>Tue, 21 Jul 2026 10:13:10 GMT</lastBuildDate><atom:link href="https://www.yania.me/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Yania]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[yania.me@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[yania.me@substack.com]]></itunes:email><itunes:name><![CDATA[Yania]]></itunes:name></itunes:owner><itunes:author><![CDATA[Yania]]></itunes:author><googleplay:owner><![CDATA[yania.me@substack.com]]></googleplay:owner><googleplay:email><![CDATA[yania.me@substack.com]]></googleplay:email><googleplay:author><![CDATA[Yania]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[(3/10) Sharenting: Finding the Balance Between Proud Parenting and Digital Privacy]]></title><description><![CDATA[Digital Safety Series: Ep. 3]]></description><link>https://www.yania.me/p/310-sharenting-finding-the-balance</link><guid isPermaLink="false">https://www.yania.me/p/310-sharenting-finding-the-balance</guid><dc:creator><![CDATA[Yania]]></dc:creator><pubDate>Tue, 14 Jul 2026 17:56:55 GMT</pubDate><content:encoded><![CDATA[<p>Humans have always needed a village to raise a child. Now that families have scattered across cities and time zones, social media has become the village square. A 2021 Security.org survey of 1,000 parents found something like three-quarters of them post photos or stories of their kids online. Most use their real names doing it. They&#8217;re not posting to show off. They&#8217;re posting because they&#8217;re proud, and because they&#8217;re looking for somewhere to put that pride.</p><p>The internet parents are posting into today is not the internet they started posting into. Something&#8217;s shifted under everyone&#8217;s feet and most haven&#8217;t even noticed there&#8217;s a question to ask. Nobody handed them the memo that the ground has moved. The actual question underneath it is harder: how do you celebrate a kid without handing tomorrow&#8217;s version of them a problem you are creating today? Most parents haven&#8217;t sat with that question yet. They don&#8217;t know they should be sitting with it. They&#8217;re still operating on &#8220;cute photo or not.&#8221;<span>.</span></p><p>The internet parents are posting into today is not the internet they started posting into. Something&#8217;s shifted under everyone&#8217;s feet and most haven&#8217;t even noticed there&#8217;s a question to ask. Nobody handed them the memo that the ground has moved. The actual question underneath it is harder: how do you celebrate a kid without handing tomorrow&#8217;s version of them a problem you are creating today? Most parents haven&#8217;t sat with that question yet. They don&#8217;t know they should be sitting with it. They&#8217;re still operating on &#8220;cute photo or not.&#8221; </p><h2>The internet got hungrier.</h2><p>If you&#8217;ve never heard the word &#8220;sharenting&#8221; before, here&#8217;s what it means. It&#8217;s the name for something you&#8217;ve probably watched happen constantly, or done yourself without a second thought. It&#8217;s a blend of &#8220;sharing&#8221; and &#8220;parenting.&#8221; It showed up around 2012 to describe parents posting photos, videos, or stories about their kids online. Most people doing it regularly have never heard the term. That makes sense. Nobody sat anyone down and said, &#8220;This thing you do constantly has a name, and researchers study it.&#8221;</p><p>It&#8217;s easy for someone online to throw the word around like it&#8217;s a diagnosis. Like admitting to it means admitting to doing something wrong. I don&#8217;t think that&#8217;s fair. When digital photo albums first showed up, they felt exactly like the sticky-page albums grandparents kept on the coffee table. Just easier to send across the world.</p><p>So no, I don&#8217;t think parents got reckless. I think the technology got more invasive underneath them. Data scraping. Facial recognition. AI tools that can build a profile out of nothing but a few years of birthday posts. A photo isn&#8217;t just a photo anymore. It&#8217;s data. What feels like a sweet update reads, to something built to harvest it, as raw material. Barclays forecast that by 2030, &#8220;sharenting&#8221; could be behind close to two-thirds of identity fraud hitting young people.</p><p>If that phrase doesn&#8217;t mean much yet, here&#8217;s the plain version. Identity theft isn&#8217;t someone breaking into an account that already exists. It&#8217;s someone collecting enough real details &#8212; full name, birthdate, hometown, mother&#8217;s maiden name &#8212; to convincingly <em>become</em> that person on paper. With those pieces, someone can open a credit card in a child&#8217;s name. Take out a loan. Pass a security check meant to confirm they&#8217;re really them. It usually doesn&#8217;t surface for years. A kid&#8217;s identity sits unused and unchecked until they&#8217;re old enough to apply for their first credit card or apartment. That&#8217;s exactly when they find out someone&#8217;s already been using their name.</p><p>That&#8217;s what the Barclays forecast is actually about. Not some vague future risk &#8212; the birthdays, hometowns, and mother&#8217;s maiden names sitting in years of posts, becoming the exact toolkit someone needs. Pulled together patiently, one caption at a time.</p><p>None of this is a case for paranoia. It&#8217;s a case for noticing that the ground has moved.</p><h2>Here&#8217;s what nobody quite spells out</h2><p>&#8220;Be careful what you post&#8221; gets repeated so often it&#8217;s stopped meaning anything. So let&#8217;s actually sit with why. Most people aren&#8217;t connecting these dots automatically. Two things are happening at once, and they&#8217;re different problems.</p><p>The identification problem, explained plainly. Once a company can reliably match a photo of a face to a name, it can find that same face anywhere else it turns up online &#8212; in someone else&#8217;s photo, on a different platform, in a context the original poster never imagined. A birthday photo posted for grandma stops being a private moment between family and becomes a searchable entry point into a person&#8217;s whole identity. That&#8217;s what &#8220;identification&#8221; means here: not that a stranger saw one photo, but that one tagged photo can now unlock everything else connected to that face.</p><p>Here&#8217;s how it already happened, not hypothetically. A company called Clearview AI scraped billions of photos off public social media &#8212; Facebook, Instagram, wherever a face happened to show up. It used them to build a facial-recognition tool, then sold access to that tool to police departments and businesses. Nobody whose face was in there knew it was happening. The UK&#8217;s data regulator, the ICO, fined the company &#163;7.5 million in 2022. Clearview challenged the fine, and the case has moved through UK tribunals since; a 2025 ruling restored the ICO&#8217;s authority to pursue it, though a lower tribunal is still finalizing the fine itself as of this writing. France, Italy, and Greece have each fined Clearview roughly &#8364;20 million outright &#8212; and, notably, none of those regulators have actually collected a cent. Australia investigated the company too. This isn&#8217;t a hypothetical. It already happened, to real people&#8217;s photos, quietly.</p><p>And that&#8217;s really the point Clearview proves: it&#8217;s not a one-off villain, it&#8217;s a demonstration of what&#8217;s possible. Clearview only became visible because journalists and regulators eventually caught up to it. For every company regulators catch, there&#8217;s no way to know how many others are running the same quiet collection and simply haven&#8217;t gotten caught yet &#8212; smaller data brokers, apps with vague terms of service, tools nobody&#8217;s heard of that exist specifically to scrape and resell what&#8217;s public. None of them need permission to start. They just need a public photo and time.</p><p>That&#8217;s what makes this different from a one-time risk. A stranger downloading a single photo creates a bad moment. An unknown company patiently building a profile on a child for years, unnoticed, creates something else entirely &#8212; because that profile doesn&#8217;t do anything today. It just sits there, complete and waiting, until the day that child is old enough to open a bank account or sign a lease. Nobody sends a warning when someone finally uses it. The years of quiet collection and the moment of misuse can sit a decade apart, which is exactly why it doesn&#8217;t feel urgent now. The absence of visible harm today doesn&#8217;t prove nobody&#8217;s collecting anything &#8212; it&#8217;s often exactly what unauthorized collection looks like while it&#8217;s happening.</p><p>The permanence problem, explained plainly. Normally, if you regret posting something, you delete it and it&#8217;s gone. Training data doesn&#8217;t work that way. Once a company has trained an AI model on a photo, deleting the original post doesn&#8217;t undo what the model already learned from it. The lesson the model absorbed &#8212; this is what a face looks like, this is how it ages, this is the pattern of a name attached to a place &#8212; stays baked into the system whether or not the photo is still online. You can take back the post. You can&#8217;t take back what it taught.</p><p>In 2024, Meta changed its policy to let its AI train on public Facebook and Instagram posts and photos. It made the opt-out process complicated enough that most people never got around to it, and even where opt-outs exist, they&#8217;ve mostly covered EU and UK users under stronger local privacy law &#8212; US users have much weaker footing to object at all. Even the people who did opt out found the request only covered what happens going forward. Whatever the model had already used, stayed used.</p><p>A photo someone posts is a moment. It has a beginning and an end. You can delete it if you regret it. The training data that photo becomes isn&#8217;t a moment anymore. It&#8217;s a permanent ingredient in something else &#8212; something a company built for a purpose nobody agreed to, and can&#8217;t undo. A kid&#8217;s birthday photo, posted for grandma, doesn&#8217;t just sit there. It can become one small piece of a system that learns to recognize faces, target ads, or predict behavior &#8212; a system a company built without ever having a conversation with that child, using a face they didn&#8217;t get a vote on.</p><p>Most people are used to thinking about who can see a post. Almost nobody&#8217;s used to thinking about what that post can turn into, simply because nobody framed it as the real question</p><h2>Things people say to wave this off</h2><p><strong>1.&#8220;They already have everything anyway.&#8221;</strong> </p><p>This is understandable. There&#8217;s some truth buried in it. Data brokers already hold huge amounts on all of us. A single new photo probably isn&#8217;t the difference between private and not private in some absolute sense. So why bother?</p><p>Here&#8217;s where that logic quietly breaks. &#8220;They have some of your data&#8221; and &#8220;they have your face, matched to your name, matched to your child&#8217;s face, matched to a decade of locations and routines&#8221; are not the same category of exposed. Most of what&#8217;s already out there is scattered. Fragments. Probabilities. Patterns. A clear, tagged photo of a specific child&#8217;s face is not a fragment. It&#8217;s a key. It turns everything else scattered about them into something matchable, searchable, identifiable in a crowd. A stranger could theoretically piece together a kid&#8217;s school, routine, and face from scraps across the internet, if they tried hard enough. A tagged, named, dated photo now can do that work for them quite conveniently. Every post doesn&#8217;t just add to a pile. It makes the pile easier to search.</p><p>There&#8217;s also a version of this argument that quietly gives up on a child&#8217;s choice. &#8220;There&#8217;s nothing to hide anyway&#8221; assumes the decision has already been made for them. Even if total privacy isn&#8217;t on the table anymore for anyone, the amount of searchable, identifiable material tied to a specific child, by the time they&#8217;re old enough to have an opinion about it, is still something being actively chosen. One photo at a time.</p><p><strong>2.&#8220;There&#8217;s nothing worth stealing.&#8221;</strong> </p><p>The instinct behind it is understandable. Most people grew up thinking of &#8220;valuable&#8221; as money in an account, or an expensive thing someone could physically take. Data doesn&#8217;t feel like that. It doesn&#8217;t feel like property in the same way. Losing control of it doesn&#8217;t register as a loss. However, a child&#8217;s data doesn&#8217;t need to be worth anything to their parent for it to be worth something to somebody else. </p><p>A name, a birthdate, a school, a face &#8212; none of that pays for itself directly. But it&#8217;s the raw material for things that do make money. Data brokers buy and sell exactly this kind of information in bulk. Not because any single kid&#8217;s birthday is valuable, but because a complete, accurate profile of a real person is. </p><p>Remember the identification and permanence problems from earlier. Identity theft isn&#8217;t about stealing money directly out of an account. It&#8217;s about stealing enough real information about a person to convincingly <em>become</em> them. The Barclays forecast isn&#8217;t warning about someone hacking a bank. It&#8217;s warning about someone using a kid&#8217;s own birthday, hometown, and mother&#8217;s maiden name &#8212; collected patiently over years of posts &#8212; to impersonate them later. The theft isn&#8217;t of data. The data is just the tool. What gets stolen at the end is money, credit, or reputation, using pieces that child never knew had been handed over.</p><p>So &#8220;there&#8217;s nothing valuable to steal&#8221; isn&#8217;t really the right question. The better one is this: does this information make it easier for someone to become this child, or to profit off knowing everything about them, without that child ever getting a say?</p><p>Not every post is a catastrophe. There&#8217;s room to be wrong about exactly where the real risk sits. &#8220;it&#8217;s already out there&#8221; or &#8220;it&#8217;s not worth anything&#8221; have always felt like reasons to stop trying, not actual arguments that trying doesn&#8217;t matter.</p><h2>The gift kids aren&#8217;t being given</h2><p>There is a different way to look at the situation, not as a restriction but as something parents are actually capable of giving.</p><p>Think back to anyone&#8217;s own late teens. There was room to mess up. To change your whole personality twice. To walk into adulthood mostly unwritten. That blank slate was a privilege, even if nobody called it that at the time.</p><p>Kids today are inheriting a version of themselves they didn&#8217;t write. A 2017 study, referenced by the American Academy of Pediatrics, found that teens judge their parents&#8217; posts about them far more harshly than they judge posts from friends. </p><p>Long before they apply for a job or open a bank account, there&#8217;s already a searchable record of their tantrums, their milestones, sometimes their medical stuff. Put there with love, without a second thought. Pulling back on what gets posted isn&#8217;t hiding a kid. It&#8217;s leaving them room to tell their own story later, in their own words.</p><h2>Nobody has to disappear. There&#8217;s a middle ground.</h2><p>None of this means going dark. Privacy isn&#8217;t all-or-nothing. Plenty of families are finding a version that works:</p><ol><li><p><strong>Post the vibe, not the face.</strong> Hands, muddy boots, the back of a small head at the park.</p></li><li><p><strong>Cover the face with an emoji</strong> if the moment should be public but the biometrics shouldn&#8217;t.</p></li><li><p><strong>Move the real archive somewhere closed, </strong> a private group chat, a family-only app and save the public feed for the parts anyone would be fine with someone finding in ten years.</p></li></ol><h2>Before hitting share &#8212; three seconds</h2><p>Next time a thumb&#8217;s hovering over the share button, ask yourself three question with no judgment attached.</p><ol><li><p>Is there operational information in this &#8212; a school uniform, a house number, a full birthdate?</p></li><li><p>Would this be okay on a billboard outside your own office?</p></li><li><p>Is this being shared for the kid, or for the parent?</p></li></ol><p>This is the first generation figuring it out in real time. There&#8217;s room to be wrong about exactly where the line should sit. There&#8217;s no clean answer here, but the shift is simple, even if the questions aren&#8217;t: share the moment, not the identity.</p><div><hr></div><p><strong>References</strong></p><ul><li><p>Security.org, <em>Parents&#8217; Social Media Habits: 2021</em> &#8212; <a href="https://www.security.org/digital-safety/parenting-social-media-report/">security.org/digital-safety/parenting-social-media-report</a></p></li><li><p>Barclays / Techmonitor, <em>Sharenting to Reach &#163;676 Million by 2030</em> (2018) &#8212; <a href="https://techmonitor.ai/technology/cybersecurity/sharenting-barclays-identitytheft">techmonitor.ai</a></p></li><li><p>Blum-Ross, A., &amp; Livingstone, S. (2017). <em>&#8220;Sharenting,&#8221; parent blogging, and the boundaries of the digital self.</em> Popular Communication, referenced via American Academy of Pediatrics &#8212; <a href="https://www.aap.org/en/patient-care/media-and-children/center-of-excellence-on-social-media-and-youth-mental-health/qa-portal/qa-portal-library/qa-portal-library-questions/sharing-photos-and-videos-of-children-on-social-media/">aap.org</a></p></li><li><p>TIME, <em>Why Regulators Can&#8217;t Stop an AI Company That Scraped Billions of Photos</em> &#8212; <a href="https://time.com/6182177/clearview-ai-regulators-uk/">time.com</a></p></li><li><p>The Conversation, <em>Australia&#8217;s privacy regulator just dropped its case against Clearview AI</em> &#8212; <a href="https://theconversation.com/australias-privacy-regulator-just-dropped-its-case-against-troubling-facial-recognition-company-clearview-ai-now-what-237231">theconversation.com</a></p></li><li><p>MIT Technology Review, <em>How to opt out of Meta&#8217;s AI training</em> (2024) &#8212; <a href="https://www.technologyreview.com/2024/06/14/1093789/how-to-opt-out-of-meta-ai-training/">technologyreview.com</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[(2/10) Cyberbullying: Why Good People Become Cyberbullies]]></title><description><![CDATA[Digital Safety Series: Ep. 2]]></description><link>https://www.yania.me/p/cyberbullying-psychology-evolution</link><guid isPermaLink="false">https://www.yania.me/p/cyberbullying-psychology-evolution</guid><dc:creator><![CDATA[Yania]]></dc:creator><pubDate>Thu, 09 Jul 2026 11:30:00 GMT</pubDate><content:encoded><![CDATA[<h2>What Cyberbullying Actually Is</h2><p style="text-align: justify;">Most people hear "cyberbullying" and picture teenage drama. Someone posts a mean comment, everyone moves on, it sorts itself out. That's not what it is. It's calculated. It's varied. It&#8217;s willful, repeated harm. Not a one-off insult and it's evolved into something a lot bigger than a mean comment.</p><p style="text-align: justify;">Here's what it actually looks like:</p><p style="text-align: justify;"><strong>Harassment</strong>: a relentless stream of hostile or threatening messages. What makes it bullying instead of a fight is that it doesn't stop.</p><p style="text-align: justify;"><strong>Outing</strong>: someone shares your private information without your consent. Your sexuality. Your mental health history. Something you told them in confidence, now weaponized.</p><p style="text-align: justify;"><strong>Exclusion</strong>: deliberately cutting someone out of group chats or online communities. It sounds small. For a teenager, it's social exile.</p><p style="text-align: justify;"><strong>Impersonation</strong>: a fake account using your name and your photos, posting things you never said, so you get blamed for them.</p><p style="text-align: justify;"><strong>Cyberstalking</strong>: tracking someone's location tags, check-ins, and activity across platforms to intimidate them.</p><p style="text-align: justify;"><strong>Sextortion and image-based abuse</strong>: sharing, threatening to share, or morphing intimate images of someone without their consent to blackmail or humiliate them.</p><p style="text-align: justify;"><strong>Coordinated pile-on</strong>: someone screenshots you out of context, rallies a crowd, and hides behind it while you get buried under hundreds of strangers who think they're doing justice.</p><p style="text-align: justify;">When the internet started, cyberbullying was a mean email or a harsh message on MSN. You closed the laptop and it was gone. Then social media gave it a permanent audience, a bad post from 2018 can still be the first thing that comes up when someone Googles your name today. Now we're in the AI phase. Perpetrators can morph someone's photos, clone their voice, build an entire fake digital footprint of things they never said or did. The tools have gotten sophisticated.</p><h2>Why Ordinary People Do This</h2><p style="text-align: justify;">Here's the part that surprises most people. Majority of cyberbullying isn't done by career criminals or pathological monsters. It's done by classmates, coworkers, ex-partners - regular people. </p><p style="text-align: justify;">So why do ordinary people do something so mean online when they wouldn&#8217;t do it in person?</p><p style="text-align: justify;">The answer is in a concept called <strong>moral disengagement</strong>, and psychologist Albert Bandura mapped it out decades ago. It describes how a person can switch off their own conscience without even realizing they're doing it. They don't feel like they're doing something wrong. They've quietly convinced themselves they aren't.</p><p style="text-align: justify;">There are five switches that flip to make this possible.</p><p style="text-align: justify;"><strong>Moral justification: </strong><span>This is the reframe. &#8220;I mocked someone&#8221; becomes &#8220;I was calling out bad behavior.&#8221; &#8220;They deserved it.&#8221; &#8220;It&#8217;s just honesty.&#8221; This happens </span><em><span>before</span></em><span> the bullying, not after. The person&#8217;s conscience is still active, so they need the justification first. Once they have it, dressed up as fair or necessary or even righteous, they move forward.</span></p><p style="text-align: justify;"><strong>Dehumanization:</strong> <span>When you see a face, hear a voice, watch someone&#8217;s reaction in pain, your brain automatically triggers empathy. That&#8217;s the natural brake on cruelty. Dehumanization removes that brake. </span>Online, that brake disappears. <span>A username isn&#8217;t a person. A profile picture isn&#8217;t a face. The person on the other end becomes an idea instead of a human, and ideas are a lot easier to hurt than people.</span></p><p style="text-align: justify;"><strong>Diffusion of responsibility: </strong><span>When a lot of people are piling on at once on a target, each person&#8217;s sense of personal responsibility shrinks. The math in their head goes something like: &#8220;I&#8217;m one of sixty people. I only said one thing. The blame is spread across all of us.&#8221; The bigger the crowd, the lighter each person feels. Nobody&#8217;s fully responsible, so nobody stops. </span></p><p style="text-align: justify;"><strong>Displacement of responsibility: </strong>This is different from diffusion, it's not spreading the blame, it's handing it off. "My friends started it." "I was just going along." The person tells themselves they had no real choice. They're a participant, not someone who chose this.</p><p style="text-align: justify;"><strong>Disregard of consequences: </strong>The perpetrator sends the message and closes the app. They never see the person at 3 am, unable to sleep. The harm only exists in the victim's world, and because they can't see it, some part of their brain decides it isn't real. &#8220;If it was really that bad, I would have seen evidence of it.&#8221; This allows them to maintain the belief that they didn&#8217;t actually cause harm, even though they did and the harm is real.</p><p style="text-align: justify;"><strong>Put those five together and the cycle closes. </strong></p><p style="text-align: justify;">Justification gets it moving. Dehumanization removes empathy. Displacement and diffusion strip away responsibility. Disregard makes it all invisible. By the end, the person hasn't lost a fight with their conscience, they've rewritten what their conscience is willing to accept.</p><h2>How You Actually Break the Cycle</h2><p style="text-align: justify;">If moral disengagement is a system, set of switches, that means they can be flipped back. There's real research on exactly how.</p><p style="text-align: justify;"><strong><span>Dismantle moral justification by questioning the reasoning, not attacking the person.</span></strong><span> When someone says &#8220;they&#8217;re annoying so I can mock them,&#8221; the counter isn&#8217;t anger, it&#8217;s a question: </span><em><span>would you accept that logic if it were used on you?</span></em><span> Research on moral reasoning shows that when people are forced to apply their own excuse to themselves, </span>the inconsistency destabilizes the excuse.<span> You can&#8217;t hold &#8220;mocking is fine when someone annoys me&#8221; and &#8220;I&#8217;d hate to be mocked&#8221; at the same time.</span></p><p style="text-align: justify;"><strong><span>Dismantle dehumanization by making the person impossible to forget.</span></strong><span> This is why victim impact statements work in courtrooms. It&#8217;s why anti-bullying programs that show real testimonials, an actual face, an actual voice, saying &#8220;this is what it did to me&#8221; work better than ones that just list rules. If you&#8217;re a bystander, simply asking a perpetrator &#8220;do you know how that person actually felt?&#8221; is more disruptive than it sounds.</span></p><p style="text-align: justify;"><strong><span>Dismantle diffusion of responsibility by naming individuals.</span></strong><span> In Latan&#233; and Darley&#8217;s classic 1968 research on bystander behavior, the single most effective way to break up mob behavior was one person stepping out and naming what was happening, specifically, by name. &#8220;The group did it&#8221; collapses the moment someone says &#8220;you did this.&#8221; Suddenly everyone in the crowd has to decide, individually, whether they&#8217;re actually in.</span></p><p style="text-align: justify;"><strong><span>Dismantle displacement by naming complicity.</span></strong><span> </span>Research on complicity is clear on this: joining in makes you responsible too, even if you didn&#8217;t start it. <span>&#8220;My friends started it, I just went along&#8221; is the classic move. The counter is direct: you chose to participate, and that&#8217;s on you.</span></p><p style="text-align: justify;"><strong><span>Dismantle disregard of consequences by making the harm concrete.</span></strong><span> There are two ways to do this, and they work differently. </span></p><p style="text-align: justify;">Understanding consequences: <span>Showing someone the </span><em><span>real</span></em><span> impact - the tears, the sleepless nights - </span>the abstract harm becomes concrete. This creates genuine guilt, shame about the action and desire to repair<span>. </span></p><p style="text-align: justify;">Experiencing consequences: <span>Legal or formal consequences - a police complaint, a school record - make the harm undeniable. </span>A bully who faces an FIR, a court appearance, or a documented complaint can no longer tell themselves nothing happened. The consequence is suddenly real in their world, not just the victim&#8217;s.</p><p style="text-align: justify;"><span>Fear of consequences can stop the behavior but it doesn&#8217;t resolve the disengagement underneath.</span></p><p style="text-align: justify;">You need both. <span>Fear stops the behavior. Understanding stops the disengagement.</span></p><div class="callout-block" data-callout="true"><h2>This might be the most important point in the whole thing:</h2><p style="text-align: justify;">How you confront someone matters as much as whether you confront them. When a perpetrator faces accountability, they feel something and what they feel matters enormously.</p></div><h2>Shame Vs. Guilt</h2><p style="text-align: justify;">Shame says &#8220;you are a bad person.&#8221; When someone feels shame, their brain goes into defense mode. They double down on justifications, blame the victim harder, find reasons they&#8217;re actually the victim. Shame triggers moral disengagement deeper, not reversal of it. This is why public callouts and humiliation-based consequences often backfire, the person becomes more entrenched into the behavior you&#8217;re trying to stop.</p><p style="text-align: justify;">Guilt is different. It&#8217;s shame about the action, not the self. Guilt says &#8220;what you did was wrong, and I know you as someone better than this.&#8221; That&#8217;s a completely different feeling. It creates a cognitive dissonance - the action doesn&#8217;t match who they think they are - and that dissonance is destabilizes moral disengagement. This triggers desire to repair, to correct course, to be who they think they are again.</p><p style="text-align: justify;">Psychologist June Price Tangney&#8217;s research on moral emotions backs this up clearly: <strong>shame leads to defensiveness, denial, and further interpersonal hostility, whereas guilt leads to real change</strong>. &#8220;You&#8217;re a monster&#8221; gets you nothing. &#8220;This isn&#8217;t who you are. You&#8217;re capable of better. So why did you do this?&#8221; triggers guilt and the possibility of actual change. It&#8217;s also why a private conversation with someone they respect often works better than public pile-on. Public consequences create shame. Private accountability creates guilt.</p><p style="text-align: justify;">That last point connects to something Karl Aquino's research on moral identity found: when people are reminded of their own values, of who they actually believe themselves to be, disengaged behavior drops fast. "Is this who you actually are?" destabilizes someone far more than "this is wrong" because most people already know it's wrong. What they haven't asked themselves is whether it fits who they think they are.</p><p style="text-align: justify;">None of this works as a one-time conversation. Moral disengagement doesn't reverse in a single talk. It takes repetition, ongoing reminders of identity, ongoing exposure to the humanity of the person on the other end, ongoing accountability. This is why schools and platforms need to build this in as a system, not a lecture they give once.</p><p style="text-align: justify;">That's how you help someone stop. But if you're the one being targeted right now, dismantling their psychology isn't your job. Protecting yourself is.</p><h2>What You Actually Do If This Is Happening to You</h2><p style="text-align: justify;"><strong>Document everything, first.</strong> Before you block. Before you report. Before you even respond. Screenshots of messages, profiles, timestamps, usernames, the URL if it's public. Once a perpetrator knows they've been reported, they often delete everything. Get the evidence before they do.</p><p style="text-align: justify;"><strong>Do not engage.</strong> This is harder than it sounds. Every response feeds the cycle, it tells them their behavior is working. Silence isn't weakness here. It's a strategic choice that starves the whole mechanism.</p><p style="text-align: justify;"><strong>Report it, and document that too.</strong> Every major social media platform has mechanisms to report harassment, fake profiles, and non-consensual intimate images. Use them. Note the date, what you reported, and any reference number they give you. In India, you can file complaints directly through the national cybercrime portal at <a href="https://cybercrime.gov.in/">cybercrime.gov.in</a>, women and children have the option to do it anonymously. Your documented screenshots serve as the foundational evidence required to initiate action.</p><p style="text-align: justify;"><strong>Loop in someone you trust.</strong> Isolation is exactly what sustained harassment is designed to produce. It wants you alone. Counter that by showing someone the full picture, not "someone's being mean," but the actual pattern, so they understand the real scale of what's happening.</p><p style="text-align: justify;">Cyberbullying is not a personality conflict. It's not drama that sorts itself out. It's a psychological attack, built on features of our digital world, sustained by mechanisms that let perpetrators feel fine while the person on the other end falls apart.</p><p style="text-align: justify;">If you know someone this is happening to: take it seriously. Being online doesn't make it less real. </p><p style="text-align: justify;">If it's happening to you: document, don't engage, report, and reach out. The law exists for exactly this. Use it.</p><p style="text-align: justify;"></p><p>Reference materials:</p><ul><li><p style="text-align: justify;"><a href="https://www.sfu.ca/~kathleea/docs/Mechanisms%20of%20Moral%20Disengagement.pdf">Read Bandura&#8217;s foundational 1996 study on the mechanisms of moral disengagement</a></p></li><li><p style="text-align: justify;"><a href="https://thedecisionlab.com/reference-guide/psychology/diffusion-of-responsibility">About Latan&#233; and Darley&#8217;s classic 1968 research on group size and the diffusion of responsibility</a></p></li><li><p style="text-align: justify;"><a href="https://www.researchgate.net/publication/6835963_Moral_Emotions_and_Moral_Behavior">Research on moral emotions by June Price Tangney</a></p></li><li><p style="text-align: justify;"><a href="https://pubmed.ncbi.nlm.nih.gov/12500822/">Karl Aquino&#8217;s research on the self-importance of moral identity</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[(1/10) Phishing: Why Smart People Fall for It]]></title><description><![CDATA[Digital Safety Series: Ep. 1]]></description><link>https://www.yania.me/p/phishing-why-smart-people-fall-for</link><guid isPermaLink="false">https://www.yania.me/p/phishing-why-smart-people-fall-for</guid><dc:creator><![CDATA[Yania]]></dc:creator><pubDate>Mon, 06 Jul 2026 22:04:44 GMT</pubDate><content:encoded><![CDATA[<p style="text-align: justify;">You've probably seen a "your package couldn't be delivered" text at some point. Maybe you almost clicked it. Maybe you did. Phishing isn't built for careless people. It's built for busy, smart, distracted people. That's you. That's me. That's basically everyone with a phone.</p><p style="text-align: justify;">It isn't some complicated technical break-in that only happens to people who "don't know better." It's actually the opposite of technical. It's psychological.</p><h2>So Why Do Smart People Actually Fall For It?</h2><p style="text-align: justify;">There's a real myth that phishing only catches people who are careless or not tech-savvy. The data says otherwise. Doctors, tech executives, finance controllers, highly trained, highly intelligent people fall for this constantly. Why? Because phishing was never designed to beat your IQ. It's designed to beat your biology.</p><p style="text-align: justify;">Psychologist Daniel Kahneman, who won a Nobel Prize for his work on human judgment, spent decades showing that your brain runs on two different modes:</p><ul><li><p><strong>System 1:</strong> fast, automatic, intuitive. It runs on autopilot, scanning for familiar patterns so you can decide in a split second without burning energy.</p></li><li><p><strong>System 2</strong>: slow, deliberate, analytical. It's the part that actually double-checks a URL, questions a request, catches the thing that feels "off." It takes real effort to switch on.</p></li></ul><p style="text-align: justify;">When you're calm and unhurried, System 2 is right there, ready to spot a lookalike link. The problem is, scammers have gotten very good at making sure you never get to use it. </p><p style="text-align: justify;">They do that by pulling three specific levers.</p><ol><li><p style="text-align: justify;"><strong>The urgency lever (amygdala hijack): </strong>"Your account will be frozen in 30 minutes." "Your card is about to be blocked." Your brain reads that as a threat, and a threat triggers what's called an amygdala hijack - a real physical stress response, cortisol and adrenaline flooding your system. When that happens, System 2 goes quiet. Your brain isn't being lazy, it's prioritizing speed over accuracy, because that's what a threat response is built to do. You're not choosing to skip the check. Your biology is skipping it for you.</p></li><li><p style="text-align: justify;"><strong>The familiarity lever (cognitive ease): </strong>We're wired to trust what feels familiar, and scammers know it. That's why they research their targets - the right formatting, the right tone, the right internal jargon, mentioning your actual boss or a project you're actually working on. When something requires zero effort to process because it already "looks right," System 1 waves it through without ever calling in System 2 to check. The scam isn't fighting your judgment. It's making sure your judgment never gets involved.</p></li><li><p style="text-align: justify;"><strong>The authority lever (conditioned obedience): </strong>This one hits hardest at work. If an email looks like it's from your CEO, a senior vendor, or a tax official, most people's instinct is to respond fast and respect the hierarchy - not to question whether the sender is really who they say they are. The desire to be efficient and professional overrides the instinct to verify.</p></li></ol><p style="text-align: justify;">Stack those three together - urgency, familiarity, authority, and you've got a message that never gives your analytical brain a chance to show up. That's the actual answer to "why smart people fall for it." It was never about intelligence. It's about which system got to make the decision.</p><h2><strong>It's Not a Hack. It's a Trap Dressed Up as Something Official</strong></h2><p style="text-align: justify;">The word "phishing" comes from the same place as fishing. You cast a hook, bait it with something convincing, and wait for someone to bite. Except instead of fish, attackers are after your data - your full name, your date of birth, your Aadhaar or PAN number, your net-banking login, your card details. Enough pieces, and they can walk straight into your bank account or if you work for a company, straight into its network.</p><p style="text-align: justify;">We used to say "just check for bad grammar and you'll spot the fake." Not anymore. Attackers are using AI to write these messages now. The grammar is flawless. The formatting is perfect. The urgency feels real, because it's engineered to feel real.</p><p style="text-align: justify;">It's also not just email anymore. There's <strong>smishing</strong> - phishing through text messages. There's <strong>vishing</strong> - phishing through phone calls, usually someone claiming to be your bank. There's <strong>quishing</strong> - phishing through QR codes that quietly send your money out instead of bringing money in. The attack surface is everywhere your phone touches. Different channel, same three levers.</p><h2>When a Global Cricket Body Lost &#8377;20 Crore to One Email</h2><p style="text-align: justify;">If you think this only happens to careless individuals, look at the International Cricket Council (ICC) - the body that governs cricket worldwide and drives a massive part of the sport's ecosystem in India.</p><p style="text-align: justify;">In 2022, the ICC lost close to $2.5 million (roughly &#8377;20 crore) to what's been widely reported as a business email compromise, or BEC, attack. In a BEC scam, criminals don't hack their way in through code. They study an organization's email patterns, then send a message that looks like it's coming from someone trusted, a vendor, an executive, a finance contact and convince an employee to authorize a payment or wire transfer. Notice which levers that pulls: familiarity, because the message mirrors something the employee already trusts, and authority, because it appears to come from someone whose request you don't stop to question. The ICC reported the incident to law enforcement in the US, and the exact mechanics of how the fraudsters got in were never fully made public. But the outcome was blunt: real money, sent by real people who believed they were dealing with a real, trusted party, gone.</p><p style="text-align: justify;">This is the high-stakes version of spear phishing, not a wide net thrown at millions of random people. A targeted, researched message aimed at one person or one role, built to look exactly like something they'd already trust.</p><h2>The Everyday Version: Real Scams Hitting Indian Phones Right Now</h2><p style="text-align: justify;">You don't have to run a global cricket body to be a target. This same playbook runs at massive scale on ordinary phones across India, every single day.</p><h3>Smishing - the fake delivery text.</h3><p style="text-align: justify;">Over the past couple of years, India Post has had to repeatedly warn people, through the government's own fact-checking body, that a viral text message is fake. It reads something like: "Your package couldn't be delivered due to incomplete address information. Update your details within 12-48 hours or it will be returned." There's a link. The link leads to a cloned website that looks almost identical to the real one. Some versions ask for a small "redelivery fee" of &#8377;25 to &#8377;100 and quietly harvest your card details the moment you enter them. Others plant something worse on your device the moment you tap the link. India Post has said, plainly and repeatedly: they never send messages like this. If you get one, that's your answer already.</p><h3>Vishing - the call that already knows your card number.</h3><p style="text-align: justify;">This is the one that catches people off guard, because the caller sounds like they know you. They'll state your actual card details back to you, or reference a real recent transaction, to win your trust fast. Then comes the pressure: your card is about to be blocked, unless you "verify" by reading out an OTP right now. The moment you do, the money's not being verified, it's being moved. No real bank will ever call you and ask you to read out an OTP. That single fact is the whole scam, once you know it.</p><h3>Quishing - the QR code that takes instead of gives.</h3><p style="text-align: justify;">This one is especially sharp because it plays on a mistaken assumption. In India's UPI-driven world, a QR code shows up claiming to be a "cashback," a "refund," or a "lottery win." People scan it expecting money to land in their account. But a QR code is built to send money, not receive it. The second you scan it and enter your UPI PIN, you've authorized an outgoing payment, straight to the scammer. There is no such thing as "scan this QR code to receive money." If a code implies otherwise, that's the tell.</p><h3>Why None of This Is About Being Careless</h3><p style="text-align: justify;">Look at the pattern across all three. The ICC case. The fake delivery text. The "your card will be blocked" call. None of them hacked anything. Each one just pulled the same three levers - urgency, familiarity, authority, and let biology do the rest.</p><p style="text-align: justify;">That's the real skill scammers have built: manufacturing a feeling, not writing better code.</p><h2>Your Practical Checklist - Use This Every Time</h2><ol><li><p style="text-align: justify;"><strong> Pause on urgency: </strong>Any message demanding instant action, "24 hours or your account is suspended," "12 hours or your package is returned"  is a signal to stop, not to comply. Real organizations, banks included, don't threaten instant account closure over a text message.</p></li><li><p style="text-align: justify;"><strong>Check the actual domain, not the logo: </strong>Scammers can copy a logo, a font, an entire page design in minutes. What they can't do is legally own a company's real domain. If a message claims to be from your bank or India Post but the link doesn't match their official domain exactly, that's your answer. Look at the URL bar, not the pretty design around it.</p></li><li><p style="text-align: justify;"><strong>Go direct, every time: </strong>Never act through the link or number inside an unsolicited message. If you're worried about a delivery or an account, close the message, open a fresh browser tab, and type in the official website yourself. Or open the company's app directly. You're bypassing their fake doorway entirely, and this one habit alone blocks most of these attacks.</p></li><li><p style="text-align: justify;"><strong>Hang up, then call back yourself: </strong>If someone calls claiming to be your bank, a government office, or any company asking you to "verify" details or read an OTP, hang up. Find the real number from your bank statement, your card, or the official app, and call that number yourself. You're the one initiating the verification now, not them.</p></li><li><p style="text-align: justify;"><strong>Report it: </strong>India has a dedicated portal for this: <strong>cybercrime.gov.in</strong>, and a national helpline at 1930. Reporting a scam doesn't just protect you, it helps shut the operation down before it reaches someone else who might not pause in time.</p></li></ol><p style="text-align: justify;">The goal here is to build one habit: trust after you've checked, not trust by default. That's it. That's the whole shift. You're smart enough to spot the patterns. You just have to remember to actually look.</p><p style="text-align: justify;"></p><p><em>Reference materials:</em></p><p><em><strong>ICC &#8377;20 crore business email compromise (2022)</strong></em></p><ul><li><p><em>ESPNcricinfo report as covered by The Daily Star: <a href="https://www.thedailystar.net/sports/cricket/news/icc-loses-25m-phishing-scam-3226706">https://www.thedailystar.net/sports/cricket/news/icc-loses-25m-phishing-scam-3226706</a></em></p></li><li><p><em>The Federal: <a href="https://thefederal.com/sports/icc-lost-close-to-2-5-million-in-phishing-scam-in-2022-report">https://thefederal.com/sports/icc-lost-close-to-2-5-million-in-phishing-scam-in-2022-report</a></em></p></li><li><p><em>Business Standard (via TBS News, same wire pickup): <a href="https://www.tbsnews.net/sports/icc-falls-prey-online-scam-loses-close-25-million-usd-571586">https://www.tbsnews.net/sports/icc-falls-prey-online-scam-loses-close-25-million-usd-571586</a></em></p></li></ul><p><em><strong>India Post smishing scam</strong></em></p><ul><li><p><em>Press Information Bureau (PIB) Fact Check, via Business Standard: <a href="https://www.business-standard.com/finance/personal-finance/that-india-post-parcel-message-on-your-phone-it-s-a-scam-says-pib-125101300283_1.html">https://www.business-standard.com/finance/personal-finance/that-india-post-parcel-message-on-your-phone-it-s-a-scam-says-pib-125101300283_1.html</a></em></p></li><li><p><em>PIB Fact Check follow-up, via Business Standard: <a href="https://www.business-standard.com/finance/personal-finance/another-delivery-scam-surfaces-pib-flags-fake-india-post-sms-125102000484_1.html">https://www.business-standard.com/finance/personal-finance/another-delivery-scam-surfaces-pib-flags-fake-india-post-sms-125102000484_1.html</a></em></p></li><li><p><em>Business Standard (case detail, &#8377;23.26 lakh Hyderabad victim): <a href="https://www.business-standard.com/india-news/new-india-post-scam-targets-citizens-what-is-it-and-how-to-be-safe-124091700490_1.html">https://www.business-standard.com/india-news/new-india-post-scam-targets-citizens-what-is-it-and-how-to-be-safe-124091700490_1.html</a></em></p></li></ul><p><em><strong>Daniel Kahneman - System 1 / System 2</strong></em></p><ul><li><p><em>APA Monitor on Psychology, official summary of Kahneman's work: <a href="https://www.apa.org/monitor/2012/02/conclusions">https://www.apa.org/monitor/2012/02/conclusions</a></em></p></li><li><p><em>The Decision Lab (academic reference guide): <a href="https://thedecisionlab.com/reference-guide/philosophy/system-1-and-system-2-thinking">https://thedecisionlab.com/reference-guide/philosophy/system-1-and-system-2-thinking</a></em></p></li></ul><p><em>A note on the rest: "amygdala hijack" and "cognitive ease" are established psychological terms (the former coined by Daniel Goleman, the latter from Kahneman's own book)</em></p>]]></content:encoded></item></channel></rss>