<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Computing on Conceptual Orthogonality</title><link>https://blog.cotti.com.br/en/categories/computing/</link><description>Recent content in Computing on Conceptual Orthogonality</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Thu, 16 Apr 2026 17:10:57 -0300</lastBuildDate><atom:link href="https://blog.cotti.com.br/en/categories/computing/index.xml" rel="self" type="application/rss+xml"/><item><title>Copasa is killing my hopes</title><link>https://blog.cotti.com.br/en/2026/04/16/copasa-is-killing-my-hopes/</link><pubDate>Thu, 16 Apr 2026 17:10:57 -0300</pubDate><guid>https://blog.cotti.com.br/en/2026/04/16/copasa-is-killing-my-hopes/</guid><description>&lt;img src="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/cover.png" alt="Featured image of post Copasa is killing my hopes" /&gt;&lt;p&gt;Today the missus sent me an image of an SMS sent to my father-in-law, wanting to know if I had received any water bills lately.&lt;/p&gt;
&lt;p&gt;The SMS had that classic scam vibe: trying to convey that sense of urgency. Sending a link with a little hash of an address that couldn&amp;rsquo;t possibly be real: copasa.&lt;strong&gt;net&lt;/strong&gt;.br. Well, Copasa is obviously .&lt;strong&gt;com&lt;/strong&gt;.br, of course.&lt;/p&gt;
&lt;p&gt;&amp;hellip;Right?&lt;/p&gt;
&lt;p&gt;I was just about to reply that &lt;em&gt;it&amp;rsquo;s a scam, obviously! Just look at the domain&lt;/em&gt;&amp;hellip; But then I thought, &amp;ldquo;wow, Copasa is really struggling with &lt;em&gt;infosec&lt;/em&gt;, huh? They let some nutjob snatch up a .net.br with their name perfectly&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;Out of curiosity, I went to do a WHOIS on the domains.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/whois-copasacombr.png"
width="637"
height="483"
srcset="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/whois-copasacombr_hu_75d17f55eac9546f.png 480w, https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/whois-copasacombr_hu_2bb08f1de51c6eca.png 1024w"
loading="lazy"
alt="Copasa.com.br"
class="gallery-image"
data-flex-grow="131"
data-flex-basis="316px"
&gt;&lt;/p&gt;
&lt;p&gt;OK, everything seems fine. And the scam one?&lt;/p&gt;
&lt;p&gt;&lt;img src="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/whois-copasanetbr.png"
width="656"
height="534"
srcset="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/whois-copasanetbr_hu_ee4f22bbb2537bab.png 480w, https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/whois-copasanetbr_hu_6e64d18aad8b79e4.png 1024w"
loading="lazy"
alt="Copasa.net.br"
class="gallery-image"
data-flex-grow="122"
data-flex-basis="294px"
&gt;&lt;/p&gt;
&lt;p&gt;&amp;hellip;Huh?&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Okay, apparently Copasa has completely separated the institutional side from the customer service side, including not using the same domain. I don&amp;rsquo;t really agree with it, but who knows how decisions are made there, aside from making my mother go without water for about 10 days out of pure procedural spite.&lt;/p&gt;
&lt;p&gt;But then you look at the certificate for the .net.br domain.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/cert.png"
width="827"
height="722"
srcset="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/cert_hu_eb85992873dd39c0.png 480w, https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/cert_hu_cb3befd42254c33c.png 1024w"
loading="lazy"
alt="Copasa.net.br’s certificate"
class="gallery-image"
data-flex-grow="114"
data-flex-basis="274px"
&gt;&lt;/p&gt;
&lt;p&gt;Dude, are they seriously using the same certificate for staging and production? Seriously, they expose staging like this?&lt;/p&gt;
&lt;p&gt;You search for the domain on ye olde Googley, and their SEO is a degree worse than nonexistent, it&amp;rsquo;s negligent. This is the first page:&lt;/p&gt;
&lt;p&gt;&lt;img src="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/copasa-p1.png"
width="551"
height="923"
srcset="https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/copasa-p1_hu_c3bb96be036427cf.png 480w, https://blog.cotti.com.br/2026/04/16/a-copasa-tira-minhas-esperancas/copasa-p1_hu_c35e8e74d4030724.png 1024w"
loading="lazy"
alt="First page results for Copasa.net.br"
class="gallery-image"
data-flex-grow="59"
data-flex-basis="143px"
&gt;&lt;/p&gt;
&lt;p&gt;Practically nothing added to facilitate a search result. But beyond that, you find a link on the first page to the admin panel of the SaaS they use for their customer service system. And beyond that, which is above the other, you also find a link to the admin panel in staging. I&amp;rsquo;m not going any further with anything else for fear of knowing that this is also part of the structural decay, just to sell this state company for peanuts later.&lt;/p&gt;
&lt;p&gt;They use &lt;a class="link" href="https://wetalkie.com/" target="_blank" rel="noopener"
&gt;WeTalkie&lt;/a&gt;. Poor folks, paying for their sins by having a client like this. Copasa has been giving us headaches every now and then around here. The sad fate of the march of institutional decay is for it to become another CEMIG to convince the population that it&amp;rsquo;s worthless. Lamentable.&lt;/p&gt;
&lt;p&gt;I remember going on a field trip to a treatment plant when I was a kid. I remember the filtration tanks, the settling tanks. But I don&amp;rsquo;t remember when it was anymore, who I had as a classmate, things like that.&lt;/p&gt;
&lt;p&gt;It would be good if they &amp;ldquo;treated&amp;rdquo; the data security of the population that depends on them, because all this exposure is scary.&lt;/p&gt;</description></item></channel></rss>