Menu
Log in


  • 28 May 2026 7:30 AM | Terry Findlay (Administrator)

    ADAM ENGST 15 May 2026

    I’m a big fan of Apple’s Dictation on the iPhone because typing is so slow and error-prone. But Dictation introduces its own frustrations, particularly with regard to proper nouns. I’ve identified three separate problems:

    • Capitalization: Common words that are part of a proper noun, such as FLRC Challenge or Brooklyn Public Library, won’t be capitalized properly in dictated text. Improperly capitalized words give me conniptions.
    • Unpredictable recognition: You never know how Dictation will recognize proper names that aren’t in Contacts, something I often encounter with building names at Cornell, like Teagle Hall.
    • Contact conflicts: Dictation often prefers names in Contacts to common words that sound the same. When I dictate the word “ride” in Strava, I often get “Ryd,” because a friend’s last name is Ryd.

    What to do? Apple doesn’t provide a user-editable list where you can add special words, but there is a back-door way to train Dictation—on all your Apple devices—to work more the way you prefer: through the Contacts app.

    Add Custom Words to Contacts

    The first two issues can be solved by adding entries to Contacts. Now that I’ve created a contact for “FLRC Challenge,” Dictation capitalizes “Challenge” correctly every time. Similarly, a contact for “Teagle” ensures that I no longer end up with wild guesses like “Thiago” or “Tego” (which aren’t in my Contacts either).

    Regardless of the number of words in the name or phrase, I put them all in the First Name field, with the hear-no-evil monkey emoji in the Last Name field. That way, these spurious contacts sort to the very bottom of Contacts and don’t clutter the display. I also add them to a Proper Noun-Contacts list (mentally removing the “u” amuses me).

    Dictation picks up some of these entries quickly, such that you don’t have to do anything more. However, in other cases, it requires more training. For instance, the Finger Lakes Runners Club hosts a race called the Thom B. Trail Runs. I frequently need to use that name in dictated text, but Dictation usually writes it as “Tom B” or “Toby” instead. I created a “Thom B.” contact, went to Notes, and dictated a few sentences like “I will be timing at Thom B. tomorrow” and “The Thom B. course is part of the FLRC Challenge.” They came out wrong the first few times, but iOS usually underlined “Tom B,” enabling me to tap it and choose “Thom B.” from the replacements. After correcting mistakes in a variety of sentences, Dictation improved.

    Even so, however, it didn’t like the trailing “B.” in the name, often recognizing it as “be” or failing to include the period in the middle of a sentence. I believe I addressed that by editing the contact in Contacts on my Mac to use a non-breaking Option-space between “Thom” and “B.” in the hopes that it would cause Dictation to see it as a unit. It’s too early to know if it works universally, but my test sentences are now being recognized every time.

    Insert a Zero-Width Space in Conflicting Names

    The third problem, when a proper name in Contacts conflicts with a common word, is more difficult to solve. Sometimes, you can work around it using your sentence structure. For instance, if I say “Ride into Teagle” in a Strava post, I’ll often get “Ryd into Teagle.” But if I say “Bike ride into Teagle,” Dictation usually gets it right because “ride” makes more sense than “Ryd” after “bike.” It’s worth trying, but you’ll likely still end up with the wrong word some of the time.

    The nuclear solution would be to delete the contact, and that may be a good excuse for getting rid of unnecessary or unknown contacts—I certainly have a bunch of people in Contacts whose names I barely recognize, much less use. What if you want to keep your contacts and continue using them normally, without their names overriding common words in Dictation?

    Here’s a solution: the zero-width Unicode space. My friend’s last name is “Ryd,” but if Contacts sees it spelled “Ry d” with a space, that’s a very different string. A regular space or non-breaking space would look strange, but a zero-width space is invisible and shouldn’t affect how the name appears anywhere else, including mailing labels. Inserting a zero-width space in the middle of the word did indeed prevent Dictation from recognizing it. Unfortunately, the zero-width space also gets in the way of searching on the full name, so it’s best to put it as far back in the word as possible. That way, searches on the first few letters will continue to work, and the name will continue to sort where you expect.

    Unfortunately, it’s a little fussy to insert a zero-width space. Here’s the easiest general technique I’ve come up with—please suggest any easier alternatives you can develop. As with the Option-space above, this can only be done in the Mac version of Contacts.

    1. Open System Settings > Keyboard > Input Sources, and click the + icon at the bottom left to add a new input source.
    2. Scroll to the bottom of the list, click Others, select Unicode Hex Input, and click Add.Adding Unicode Hex Input in the Input Sources dialog
    3. Switch to Contacts, select the contact to edit, click the Edit button, click the name field to edit, and position the insertion point where you want to insert a zero-width space.
    4. From the Input Source menu in the menu bar (which may have an A icon), choose Unicode Hex Input to switch to that keyboard. The icon will change to U+.
      Unicode Hex Input in the Input Sources menu
    5. Working carefully, since nothing appears on the screen, press and hold the Option key and type 200b to insert the Unicode character code U+200B. (You don’t need to press the Shift key when typing the B, but it won’t hurt if you do.)
    6. Click the Done button to save your changes. If you want to verify that they took, copy the text of the name and paste it into BBEdit, which will display an upside-down question mark where the invisible character is. You can also copy that character from BBEdit and paste it into other apps in the future, if that’s easier. Your regular input source should take over again right away, but remember that you’ve enabled Unicode Hex Input if anything weird starts happening with your keyboard (see “Mysterious Mac Login Failures? Check Your Input Source,” 20 March 2026).
    7. Wait for Contacts to sync your change to the iPhone. I sometimes change the Company field so I can tell the sync has happened. If you’re not using iCloud to sync Contacts, you’ll have to perform a USB sync.
    8. Dictate some more sentences to Notes to see if your change was sufficient. If not, you may need to search in Contacts to see if any other people share the offending name.

    I’ve used this technique successfully with several names, so I have high hopes that it will work more generally for others as well. The only downside is that an invisible space could have unintended consequences down the line, so I strongly recommend adding a note to any contact you modify in this way, explaining what you’ve done so Future You can figure it out. Let me know how it works in the comments!

  • 28 May 2026 7:29 AM | Terry Findlay (Administrator)

    ADAM ENGST 19 May 2026

    At New Hampshire Public Radio, Todd Bookman writes:

    New Hampshire appears to be the epicenter of a global criminal operation involving stolen gift cards, rented warehouses, and millions of dollars’ worth of Apple products, authorities say.

    The scale of the scheme is mind-boggling: Apple, working with police, determined that the company shipped 46,364 products to a single warehouse in Windham, New Hampshire during a 10-week window last summer, with a total value of $47 million. That works out to an average of $600,000 a day in Apple products to a single location. A separate facility in Amherst received another $35 million in iPhones over the same period.

    At what point does Apple stop offering gift cards because they enable too much harm?

    Bookman’s dramatic story provides yet another reason to avoid physical gift cards. Thieves steal gift cards from retail store shelves, extract the card numbers and PINs, then return the cards to the racks. When an unsuspecting customer later buys and loads money onto the card, the thieves—monitoring remotely—immediately drain the funds and use them to purchase Apple products. Those products ship to warehouses in New Hampshire (chosen for its lack of sales tax), where workers repackage them for export overseas. It’s brilliantly evil.

    The consequences for individuals who unknowingly purchase the tampered cards can also be severe. As I covered in “Compromised Apple Gift Card Saga Ends Well, but Risks Remain” (18 December 2025), attempting to redeem a compromised card can trigger Apple’s fraud-detection systems and lock you out of your Apple Account. My recommendation stands: avoid physical gift cards entirely, and if you must use one, redeem it at an Apple Store for physical merchandise rather than adding the balance to your Apple Account.

    Read original article

  • 28 May 2026 7:28 AM | Terry Findlay (Administrator)
     20 comments

    “You’re invited!”

    Not really, but that’s the message scammers are now using to steal users’ login credentials with a greeting card scam that’s making the rounds. Here’s how it works.

    You receive an email from a friend, someone who has you in their contacts, inviting you to a party. The message appears to come from an invitation site like Paperless Post or Punchbowl, and there are few details beyond a suggestion to open the invitation. It’s a legitimate message, in the sense that it really does come from your friend, whose account has been hacked. But that’s all that’s legitimate about it.

    Examples of greeting card scams

    If you click the View the Card link or Open Invitation button, you’ll immediately be sent to a site that asks you to log in with your email credentials. Provide your username and password, and your email account will be the next one compromised. Once the scammer has access to your email account, they can also get into financial and other confidential accounts that allow passwords to be changed with email verification.

    How One Experienced User Got Caught

    I’ve seen three of these scams recently, and while all three came from intelligent, experienced Internet users, one was even from an old industry friend who was professionally mortified to have fallen for it (the middle screenshot above). He explained that four factors allowed the social engineering attack to succeed:

    • He was expecting an invitation from his sister, who’s having a significant birthday next year. The phishing email came from her account, so it seemed entirely plausible.
    • He and his partner were having a calendar meeting about their plans for the next few months, so the phishing email arrived at the “perfect” time. They were both eager to act on the invitation so they could plan around it.
    • Because they were in the middle of planning, he hurried through the process to learn more and respond. In his rush, he ignored warning signs like the non-Punchbowl URL, the slightly funky-looking email, and the solicitation for email credentials. Like so many people, he’s become accustomed to entering his username and password on certain websites and didn’t take the time to question it.
    • He was using his iPhone and either didn’t know or had forgotten that you can touch and hold any link in Safari to preview it. On his Mac, he likely would have hovered over the Open Invitation button, seen the fake URL, and stopped.

    How Can You Identify and Avoid Greeting Card Scams?

    The good news is that these scams are easy to spot if you take the time to look carefully. Red flags include:

    • Does the invitation make sense? Two of the three I received were from people on the other side of the country, so being invited to an Easter luncheon seemed unlikely. The third one was sent to a mailing list where the sender wouldn’t have known most of the subscribers, so that was also implausible.
    • Do you have to click to see any details about when the event is, where it’s being held, and so on? Legitimate invitations should make at least some of that information available up front.
    • Do the links go to any site other than the actual greeting card provider? Before clicking, preview the URL—on a Mac, hover over the link; on an iPhone or iPad, touch and hold it.
    • Are you asked to sign in with your email address and password? A greeting card service might ask you to create a service account or sign in to RSVP, but no legitimate service will ever ask for your email password.

    The most important advice I can give is to enable multifactor authentication for your email account, which will stop takeovers in their tracks.

    Otherwise, all you can do is slow down a little, pay attention, and exercise some caution, which is solid advice for all online activities these days.

    After initial publication, a rep from Paperless Post provided three ways to verify a legitimate Paperless Post invitation:

    • It will always come from a @paperlesspost.com email address
    • It will only link to paperlesspost.com
    • It will never ask you to log in or download anything to view a card

    Plus, if you get what looks like a suspicious Paperless Post invitation, you can forward it to phishing@paperlesspost.com so their team can investigate it.

    Paperless Post recently posted about this, and Punchbowl also offers advice on detecting scams.

    How Can You Help a Friend Whose Account Has Sent a Greeting Card Scam?

    Unfortunately, the more serious damage to the sender has likely already occurred, but it’s still important to alert them that their email account has been compromised and to urge them to change their password immediately.

    If possible, do that via text message, phone call, or an email to a different email address or to a friend or family member who might be able to get in touch more directly.

    What Should You Do If You Fall Prey to a Greeting Card Scam?

    First off, no judgment here. As with my industry friend, if all the factors align, anyone can be fooled. It may seem as though he was just unlucky, and while that’s true, I think many of the necessary factors can align more often than we expect. That’s why the scam works.

    If the compromised account was a Gmail account, immediately go to your Google Account’s Device Activity page. Sign out of any sessions you don’t recognize. This kicks the scammer out of your account before they can do further damage. (Other email providers may have equivalent security pages.)

    Next, change your password and enable multifactor authentication. Be aware that changing your password doesn’t automatically revoke access that the scammer may have granted to a third-party app while they were in your account. Gmail users should go to the Third-Party Apps & Services page, review the list carefully, and remove any unfamiliar entries.

    Regardless of your email provider, review your email settings to see if the scammer set up mail forwarding or filters that would redirect your messages. If so, delete them immediately.

    It’s worth looking through recent sent and received emails to see if there’s any indication of which accounts the scammer may have targeted, but they likely deleted such messages.

    You could try sending an email to all your contacts to alert them not to click the greeting card scam link, but if you have hundreds of contacts, it likely isn’t worth the significant effort involved. If you do this, it’s probably best to send in BCC’d batches of 10 to 20 at most to reduce the risk of triggering spam filters.

    Now comes the tedious part. You’re going to have to log in to every account in your password manager, starting with the most important (financial, government, tech giants like Amazon and Google, and so on). If your stored password doesn’t work, change it immediately, then review account activity to determine the ways it might have been compromised. Also, turn on multifactor authentication for any accounts where it’s available.

    If that sounds awful, consider it incentive to exercise caution out there!

  • 28 May 2026 7:27 AM | Terry Findlay (Administrator)

    ADAM ENGST 19 May 2026

    I’ve never been one for working at a coffee shop or in other public spaces, but lots of people—particularly students—often find themselves in situations where someone could be surreptitiously watching what you do over your shoulder. That could be a problem if you’re working with confidential or sensitive data, or just something that you would be embarrassed if someone else read. If shoulder surfing concerns you, there’s now a solution.

    EyesOff, a menu bar app by indie developer Yusuf Mohammad, uses your Mac’s webcam to detect whenever someone else is looking at your screen and alerts you instantly. It offers two detection modes: Face mode simply detects any face in view, while EyesOff mode goes further by detecting whether faces are actually looking at your screen. You can adjust detection sensitivity and specify how many additional faces are necessary to trigger the warning (perhaps you regularly work with a friend or colleague, so you’d be worried only about a third face being detected).

    Whenever EyesOff detects a face, it can show an unmissable alert in the center of your screen, post a standard notification, or launch another app. You can customize the alert’s size, text, color, and opacity, or switch to full-screen mode, which has the added advantage of obscuring whatever is on your screen. The alert can disappear automatically or require manual dismissal. EyesOff also offers a “rear view mirror” option that displays a small window of what the webcam sees when it detects a new face, and it can even launch another app in response to face detection. What you see below is the app’s main window; normally, whatever you’re working on would be underneath the EYES OFF alert, and the rear view mirror window would appear in the corner of the screen.

    EyesOff main screen

    What about an unattended Mac? In theory, if you’re working on confidential data, you should have the display turn off or start the screen saver after a few minutes of inactivity. But if you were called away from your desk and a nosy colleague came by before the inactive timer elapsed, they would have access to your Mac. We may not have Face ID for the Mac yet, but EyesOff offers a basic level of face authentication. You enroll your face, and whenever it detects someone other than you looking at the screen for more than about 5 seconds, it locks the screen. Since you wouldn’t know who was looking at your Mac when it was unattended, EyesOff offers an option to take snapshots whenever it triggers and keep them for a user-specified number of days.

    EyesOff settings

    Although I seldom compute in public, EyesOff worked fine during my testing, and when I was at the ACES Conference last week, it triggered correctly when someone was looking over my shoulder. Of course, I was working with them on something, so I had to quit the app temporarily, but Yusuf is considering adding a button that would let the user prevent the alert from appearing for a user-configurable number of minutes to address legitimate co-working situations.

    EyesOff relies on a lightweight AI model for face and gaze detection, but I noticed no performance slowdowns, admittedly on an M4 Pro MacBook Pro. All processing takes place on the Mac—no data ever leaves the machine—and the app doesn’t record or store video.

    Yusuf has been extremely responsive to feedback, converting the initial version he showed me into a menu bar app, adding face authentication, and fixing bugs associated with my somewhat unusual three-camera Mac (a MacBook Pro with two Studio Displays). Nonetheless, EyesOff is still young and in active development, so I’ve encountered a few glitches, and you might too. Yusuf has resolved all of mine so far, but EyesOff will undoubtedly continue to mature in the coming months. If EyesOff would give you some peace of mind while working in public or leaving your Mac unattended in your office, I encourage you to give it a try. It offers a 14-day free trial—no credit card necessary—after which it costs £13.99 (about $19) per year. There’s also a Windows version.

Powered by Wild Apricot Membership Software